UPDATING revision 363496
1Updating Information for FreeBSD stable/11 users. 2 3This file is maintained and copyrighted by M. Warner Losh <imp@freebsd.org>. 4See end of file for further details. For commonly done items, please see the 5COMMON ITEMS: section later in the file. These instructions assume that you 6basically know what you are doing. If not, then please consult the FreeBSD 7handbook: 8 9 https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html 10 11Items affecting the ports and packages system can be found in 12/usr/ports/UPDATING. Please read that file before running portupgrade. 13 14NOTE: FreeBSD has switched from gcc to clang. If you have trouble bootstrapping 15from older versions of FreeBSD, try WITHOUT_CLANG and WITH_GCC to bootstrap to 16the tip of head, and then rebuild without this option. The bootstrap process 17from older version of current across the gcc/clang cutover is a bit fragile. 18 1920200723: 20 Clang, llvm, lld, lldb, compiler-rt, libc++, libunwind and openmp have 21 been upgraded to 10.0.1. Please see the 20141231 entry below for 22 information about prerequisites and upgrading, if you are not already 23 using clang 3.5.0 or higher. 24 2520200507: 26 Clang, llvm, lld, lldb, compiler-rt, libc++, libunwind and openmp have 27 been upgraded to 10.0.0. Please see the 20141231 entry below for 28 information about prerequisites and upgrading, if you are not already 29 using clang 3.5.0 or higher. 30 3120200430: 32 The root certificates of the Mozilla CA Certificate Store have been 33 imported into the base system and can be managed with the certctl(8) 34 utility. If you have installed the security/ca_root_nss port or package 35 with the ETCSYMLINK option (the default), be advised that there may be 36 differences between those included in the port and those included in 37 base due to differences in nss branch used as well as general update 38 frequency. Note also that certctl(8) cannot manage certs in the 39 format used by the security/ca_root_nss port. 40 4120190913: 42 ntpd no longer by default locks its pages in memory, allowing them 43 to be paged out by the kernel. Use rlimit memlock to restore 44 historic BSD behaviour. For example, add "rlimit memlock 32" 45 to ntp.conf to lock up to 32 MB of ntpd address space in memory. 46 4720190723: 48 Clang, llvm, lld, lldb, compiler-rt, libc++, libunwind and openmp have 49 been upgraded to 8.0.1. Please see the 20141231 entry below for 50 information about prerequisites and upgrading, if you are not already 51 using clang 3.5.0 or higher. 52 5320190426: 54 CARP now sets DSCP value CS7(Network Traffic) in the flowlabel field 55 of packets by default instead of only setting TOS_LOWDELAY in IPv4, 56 which was deprecated in 1998. Original behavior can be restored by 57 setting sysctl net.inet.carp.dscp=4. 58 5920190416: 60 Clang, llvm, lld, lldb, compiler-rt and libc++ have been upgraded to 61 8.0.0. Please see the 20141231 entry below for information about 62 prerequisites and upgrading, if you are not already using clang 3.5.0 63 or higher. 64 6520190226: 66 geom_uzip(4) depends on the new module xz. If geom_uzip is statically 67 compiled into your custom kernel, add 'device xz' statement to the 68 kernel config. 69 7020190220: 71 Co-existance for Forth and Lua interpreters in bootloaders has now been 72 merged to ease testing of lualoader. LOADER_DEFAULT_INTERP, documented 73 in build(7), may be used to control which interpreter flavor is used in 74 the default loader to be installed. For systems where Lua and Forth 75 coexist, this switch can also be made on a running system by creating a 76 link from /boot/loader{,.efi} to /boot/loader_${flavor}{,.efi} rather 77 than requiring a rebuild. 78 79 The default flavor in this branch will remain Forth. As indicated in 80 the 20190216 UPDATING entry, booting is a complex environment; it would 81 be prudent to assume that lualoader may not work for your setup and make 82 provisions for backup boot methods. 83 8420190220: 85 zfsloader's functionality has now been folded into loader. 86 zfsloader is no longer necesasary once you've updated your 87 boot blocks. For a transition period, we will install a 88 hardlink for zfsloader to loader to allow a smooth transition 89 until the boot blocks can be updated (hard link because old 90 zfs boot blocks don't understand symlinks). 91 9220190216: 93 Lualoader has been merged to facilitate testing on this branch. It's 94 purely opt-in for now by building WITH_LOADER_LUA and WITHOUT_FORTH in 95 /etc/src.conf, but co-existance will come shortly. Booting is a complex 96 environment and test coverage for Lua-enabled loaders has been thin, so 97 it would be prudent to assume it might not work and make provisions for 98 backup boot methods. 99 10020190216: 101 Clang, llvm, lld, lldb, compiler-rt and libc++ have been upgraded to 102 7.0.1. Please see the 20141231 entry below for information about 103 prerequisites and upgrading, if you are not already using clang 3.5.0 104 or higher. 105 10620181228: 107 r342562 modifies the NFSv4 server so that it obeys vfs.nfsd.nfs_privport 108 in the same as it is applied to NFSv2 and 3. This implies that NFSv4 109 servers that have vfs.nfsd.nfs_privport set will only allow mounts 110 from clients using a reserved port#. Since both the FreeBSD and Linux 111 NFSv4 clients use reserved port#s by default, this should not affect 112 most NFSv4 mounts. 113 11420181107: 115 The '%I' format in the kern.corefile sysctl limits the number of 116 core files that a process can generate to the number stored in the 117 debug.ncores sysctl. The '%I' format is replaced by the single digit 118 index. Previously, if all indexes were taken the kernel would overwrite 119 only a core file with the highest index in a filename. 120 Currently the system will create a new core file if there is a free 121 index or if all slots are taken it will overwrite the oldest one. 122 12320180818: 124 WITH_OFED option now only enables the build for the OFED libraries 125 and some fundamental client utilities. OpenSM and rest of the 126 debugging tools are enabled by WITH_OFED_EXTRA build switch. 127 WITH_OFED is turned on by default on amd64. 128 12920180714: 130 Clang, llvm, lld, lldb, compiler-rt and libc++ have been upgraded to 131 6.0.1. Please see the 20141231 entry below for information about 132 prerequisites and upgrading, if you are not already using clang 3.5.0 133 or higher. 134 13520180601: 136 The releng/11.2 branch has been created from stable/11@r334458. 137 13820180504: 139 The tz database (tzdb) has been updated to 2018e. This version more 140 correctly models time stamps in time zones with negative DST such as 141 Europe/Dublin (from 1971 on), Europe/Prague (1946/7), and 142 Africa/Windhoek (1994/2017). This does not affect the UT offsets, only 143 time zone abbreviations and the tm_isdst flag. 144 14520180409: 146 The use of RSS hash from the network card aka flowid has been 147 disabled by default for lagg(4) as it's currently incompatible with 148 the lacp and loadbalance protocols. 149 150 This can be re-enabled by setting the following in loader.conf: 151 net.link.lagg.default_use_flowid="1" 152 15320180331: 154 Clang, llvm, lld, lldb, compiler-rt and libc++ have been upgraded to 155 6.0.0. Please see the 20141231 entry below for information about 156 prerequisites and upgrading, if you are not already using clang 3.5.0 157 or higher. 158 15920180211: 160 The LOADER_FIREWIRE_SUPPORT build variable as been renamed to 161 WITH/OUT_LOADER_FIREWIRE. LOADER_{NO_,}GELI_SUPPORT has been renamed 162 to WITH/OUT_LOADER_GELI. 163 16420180210: 165 The geli password typed at boot is now hidden. To restore the previous 166 behavior, see geli(8) for configuration options. 167 168 The SW_WATCHDOG option is no longer necessary to enable the 169 hardclock-based software watchdog if no hardware watchdog is 170 configured. As before, SW_WATCHDOG will cause the software 171 watchdog to be enabled even if a hardware watchdog is configured. 172 17320180108: 174 lint(1) binaries and library are no longer built by default. To 175 enable building them, define WITH_LINT in src.conf. If you are using 176 a FreeBSD 12 or later system to build 11-stable, you may need to 177 install a lint(1) binary to use WITH_LINT. 178 17920171003: 180 When building multiple kernels using KERNCONF, non-existent KERNCONF 181 files will produce an error and buildkernel will fail. Previously 182 missing KERNCONF files silently failed giving no indication as to 183 why, only to subsequently discover during installkernel that the 184 desired kernel was never built in the first place. 185 18620170926: 187 Clang, llvm, lldb, compiler-rt and libc++ have been upgraded to 5.0.0. 188 Please see the 20141231 entry below for information about prerequisites 189 and upgrading, if you are not already using clang 3.5.0 or higher. 190 19120170822: 192 Since the switch to GPT disk labels, fsck for UFS/FFS has been 193 unable to automatically find alternate superblocks. As of r322806, 194 the information needed to find alternate superblocks has been 195 moved to the end of the area reserved for the boot block. 196 Filesystems created with a newfs of this vintage or later 197 will create the recovery information. If you have a filesystem 198 created prior to this change and wish to have a recovery block 199 created for your filesystem, you can do so by running fsck in 200 forground mode (i.e., do not use the -p or -y options). As it 201 starts, fsck will ask ``SAVE DATA TO FIND ALTERNATE SUPERBLOCKS'' 202 to which you should answer yes. 203 20420170629: 205 The releng/11.1 branch has been created from stable/11@r320475. 206 20720170518: 208 arm64 builds now use the base system LLD 4.0.0 linker by default, 209 instead of requiring that the aarch64-binutils port or package be 210 installed. To continue using aarch64-binutils, set 211 CROSS_BINUTILS_PREFIX=/usr/local/aarch64-freebsd/bin . 212 21320170529: 214 The ctl.ko module no longer implements the iSCSI target frontend: 215 cfiscsi.ko does instead. 216 217 If building cfiscsi.ko as a kernel module, the module can be loaded 218 via one of the following methods: 219 - `cfiscsi_load="YES"` in loader.conf(5). 220 - Add `cfiscsi` to `$kld_list` in rc.conf(5). 221 - ctladm(8)/ctld(8), when compiled with iSCSI support 222 (`WITH_ISCSI=yes` in src.conf(5)) 223 224 Please see cfiscsi(4) for more details. 225 22620170511: 227 The mmcsd.ko module now additionally depends on geom_flashmap.ko. 228 Also, mmc.ko and mmcsd.ko need to be a matching pair built from the 229 same source (previously, the dependency of mmcsd.ko on mmc.ko was 230 missing, but mmcsd.ko now will refuse to load if it is incompatible 231 with mmc.ko). 232 23320170414: 234 Binds and sends to the loopback addresses, IPv6 and IPv4, will now 235 use any explicitly assigned loopback address available in the jail 236 instead of using the first assigned address of the jail. 237 23820170413: 239 As of r316810 for ipfilter, keep frags is no longer assumed when 240 keep state is specified in a rule. r316810 aligns ipfilter with 241 documentation in man pages separating keep frags from keep state. 242 This allows keep state to specified without forcing keep frags 243 and allows keep frags to be specified independently of keep state. 244 To maintain previous behaviour, also specify keep frags with 245 keep state (as documented in ipf.conf.5). 246 24720170402: 248 Clang, llvm, lldb, compiler-rt and libc++ have been upgraded to 4.0.0. 249 Please see the 20141231 entry below for information about prerequisites 250 and upgrading, if you are not already using clang 3.5.0 or higher. 251 25220170323: 253 The code that provides support for ZFS .zfs/ directory functionality 254 has been reimplemented. It's not possible now to create a snapshot 255 by mkdir under .zfs/snapshot/. That should be the only user visible 256 change. 257 25820170319: 259 Many changes in the IPsec code have been merged from the FreeBSD-CURRENT 260 branch. The IPSEC_FILTERTUNNEL kernel option is removed in favour of 261 corresponding sysctl. The IPSEC_NAT_T kernel option is also removed, 262 and now NAT-T is supported by default. Security associations now use 263 the single namespace for SPI allocation, so if you use several manually 264 configured security associations with the same SPI, this configuration 265 needs modification. 266 26720161217: 268 Clang, llvm, lldb, compiler-rt and libc++ have been upgraded to 3.9.1. 269 Please see the 20141231 entry below for information about prerequisites 270 and upgrading, if you are not already using clang 3.5.0 or higher. 271 27220161124: 273 Clang, llvm, lldb, compiler-rt and libc++ have been upgraded to 3.9.0. 274 Please see the 20141231 entry below for information about prerequisites 275 and upgrading, if you are not already using clang 3.5.0 or higher. 276 27720161119: 278 The layout of the pmap structure has changed for powerpc to put the pmap 279 statistics at the front for all CPU variations. libkvm(3) and all tools 280 that link against it need to be recompiled. 281 28220161030: 283 isl(4) and cyapa(4) drivers now require a new driver, 284 chromebook_platform(4), to work properly on Chromebook-class hardware. 285 On other types of hardware the drivers may need to be configured using 286 device hints. Please see the corresponding manual pages for details. 287 28820161210: 289 Relocatable object files with the extension of .So have been renamed 290 to use an extension of .pico instead. The purpose of this change is 291 to avoid a name clash with shared libraries on case-insensitive file 292 systems. On those file systems, foo.So is the same file as foo.so. 293 29420160811: 295 The releng/11.0 branch has been created from stable/11@r303970. 296 29720160708: 298 The stable/11 branch has been created from head@r302406. 299 30020160622: 301 The libc stub for the pipe(2) system call has been replaced with 302 a wrapper that calls the pipe2(2) system call and the pipe(2) 303 system call is now only implemented by the kernels that include 304 "options COMPAT_FREEBSD10" in their config file (this is the 305 default). Users should ensure that this option is enabled in 306 their kernel or upgrade userspace to r302092 before upgrading their 307 kernel. 308 30920160527: 310 CAM will now strip leading spaces from SCSI disks' serial numbers. 311 This will effect users who create UFS filesystems on SCSI disks using 312 those disk's diskid device nodes. For example, if /etc/fstab 313 previously contained a line like 314 "/dev/diskid/DISK-%20%20%20%20%20%20%20ABCDEFG0123456", you should 315 change it to "/dev/diskid/DISK-ABCDEFG0123456". Users of geom 316 transforms like gmirror may also be affected. ZFS users should 317 generally be fine. 318 31920160523: 320 The bitstring(3) API has been updated with new functionality and 321 improved performance. But it is binary-incompatible with the old API. 322 Objects built with the new headers may not be linked against objects 323 built with the old headers. 324 32520160520: 326 The brk and sbrk functions have been removed from libc on arm64. 327 Binutils from ports has been updated to not link to these 328 functions and should be updated to the latest version before 329 installing a new libc. 330 33120160517: 332 The armv6 port now defaults to hard float ABI. Limited support 333 for running both hardfloat and soft float on the same system 334 is available using the libraries installed with -DWITH_LIBSOFT. 335 This has only been tested as an upgrade path for installworld 336 and packages may fail or need manual intervention to run. New 337 packages will be needed. 338 339 To update an existing self-hosted armv6hf system, you must add 340 TARGET_ARCH=armv6 on the make command line for both the build 341 and the install steps. 342 34320160510: 344 Kernel modules compiled outside of a kernel build now default to 345 installing to /boot/modules instead of /boot/kernel. Many kernel 346 modules built this way (such as those in ports) already overrode 347 KMODDIR explicitly to install into /boot/modules. However, 348 manually building and installing a module from /sys/modules will 349 now install to /boot/modules instead of /boot/kernel. 350 35120160414: 352 The CAM I/O scheduler has been committed to the kernel. There should be 353 no user visible impact. This does enable NCQ Trim on ada SSDs. While the 354 list of known rogues that claim support for this but actually corrupt 355 data is believed to be complete, be on the lookout for data 356 corruption. The known rogue list is believed to be complete: 357 358 o Crucial MX100, M550 drives with MU01 firmware. 359 o Micron M510 and M550 drives with MU01 firmware. 360 o Micron M500 prior to MU07 firmware 361 o Samsung 830, 840, and 850 all firmwares 362 o FCCT M500 all firmwares 363 364 Crucial has firmware http://www.crucial.com/usa/en/support-ssd-firmware 365 with working NCQ TRIM. For Micron branded drives, see your sales rep for 366 updated firmware. Black listed drives will work correctly because these 367 drives work correctly so long as no NCQ TRIMs are sent to them. Given 368 this list is the same as found in Linux, it's believed there are no 369 other rogues in the market place. All other models from the above 370 vendors work. 371 372 To be safe, if you are at all concerned, you can quirk each of your 373 drives to prevent NCQ from being sent by setting: 374 kern.cam.ada.X.quirks="0x2" 375 in loader.conf. If the drive requires the 4k sector quirk, set the 376 quirks entry to 0x3. 377 37820160330: 379 The FAST_DEPEND build option has been removed and its functionality is 380 now the one true way. The old mkdep(1) style of 'make depend' has 381 been removed. See 20160311 for further details. 382 38320160317: 384 Resource range types have grown from unsigned long to uintmax_t. All 385 drivers, and anything using libdevinfo, need to be recompiled. 386 38720160311: 388 WITH_FAST_DEPEND is now enabled by default for in-tree and out-of-tree 389 builds. It no longer runs mkdep(1) during 'make depend', and the 390 'make depend' stage can safely be skipped now as it is auto ran 391 when building 'make all' and will generate all SRCS and DPSRCS before 392 building anything else. Dependencies are gathered at compile time with 393 -MF flags kept in separate .depend files per object file. Users should 394 run 'make cleandepend' once if using -DNO_CLEAN to clean out older 395 stale .depend files. 396 39720160306: 398 On amd64, clang 3.8.0 can now insert sections of type AMD64_UNWIND into 399 kernel modules. Therefore, if you load any kernel modules at boot time, 400 please install the boot loaders after you install the kernel, but before 401 rebooting, e.g.: 402 403 make buildworld 404 make kernel KERNCONF=YOUR_KERNEL_HERE 405 make -C sys/boot install 406 <reboot in single user> 407 408 Then follow the usual steps, described in the General Notes section, 409 below. 410 41120160305: 412 Clang, llvm, lldb and compiler-rt have been upgraded to 3.8.0. Please 413 see the 20141231 entry below for information about prerequisites and 414 upgrading, if you are not already using clang 3.5.0 or higher. 415 41620160301: 417 The AIO subsystem is now a standard part of the kernel. The 418 VFS_AIO kernel option and aio.ko kernel module have been removed. 419 Due to stability concerns, asynchronous I/O requests are only 420 permitted on sockets and raw disks by default. To enable 421 asynchronous I/O requests on all file types, set the 422 vfs.aio.enable_unsafe sysctl to a non-zero value. 423 42420160226: 425 The ELF object manipulation tool objcopy is now provided by the 426 ELF Tool Chain project rather than by GNU binutils. It should be a 427 drop-in replacement, with the addition of arm64 support. The 428 (temporary) src.conf knob WITHOUT_ELFCOPY_AS_OBJCOPY knob may be set 429 to obtain the GNU version if necessary. 430 43120160129: 432 Building ZFS pools on top of zvols is prohibited by default. That 433 feature has never worked safely; it's always been prone to deadlocks. 434 Using a zvol as the backing store for a VM guest's virtual disk will 435 still work, even if the guest is using ZFS. Legacy behavior can be 436 restored by setting vfs.zfs.vol.recursive=1. 437 43820160119: 439 The NONE and HPN patches has been removed from OpenSSH. They are 440 still available in the security/openssh-portable port. 441 44220160113: 443 With the addition of ypldap(8), a new _ypldap user is now required 444 during installworld. "mergemaster -p" can be used to add the user 445 prior to installworld, as documented in the handbook. 446 44720151216: 448 The tftp loader (pxeboot) now uses the option root-path directive. As a 449 consequence it no longer looks for a pxeboot.4th file on the tftp 450 server. Instead it uses the regular /boot infrastructure as with the 451 other loaders. 452 45320151211: 454 The code to start recording plug and play data into the modules has 455 been committed. While the old tools will properly build a new kernel, 456 a number of warnings about "unknown metadata record 4" will be produced 457 for an older kldxref. To avoid such warnings, make sure to rebuild 458 the kernel toolchain (or world). Make sure that you have r292078 or 459 later when trying to build 292077 or later before rebuilding. 460 46120151207: 462 Debug data files are now built by default with 'make buildworld' and 463 installed with 'make installworld'. This facilitates debugging but 464 requires more disk space both during the build and for the installed 465 world. Debug files may be disabled by setting WITHOUT_DEBUG_FILES=yes 466 in src.conf(5). 467 46820151130: 469 r291527 changed the internal interface between the nfsd.ko and 470 nfscommon.ko modules. As such, they must both be upgraded to-gether. 471 __FreeBSD_version has been bumped because of this. 472 47320151108: 474 Add support for unicode collation strings leads to a change of 475 order of files listed by ls(1) for example. To get back to the old 476 behaviour, set LC_COLLATE environment variable to "C". 477 478 Databases administrators will need to reindex their databases given 479 collation results will be different. 480 481 Due to a bug in install(1) it is recommended to remove the ancient 482 locales before running make installworld. 483 484 rm -rf /usr/share/locale/* 485 48620151030: 487 The OpenSSL has been upgraded to 1.0.2d. Any binaries requiring 488 libcrypto.so.7 or libssl.so.7 must be recompiled. 489 49020151020: 491 Qlogic 24xx/25xx firmware images were updated from 5.5.0 to 7.3.0. 492 Kernel modules isp_2400_multi and isp_2500_multi were removed and 493 should be replaced with isp_2400 and isp_2500 modules respectively. 494 49520151017: 496 The build previously allowed using 'make -n' to not recurse into 497 sub-directories while showing what commands would be executed, and 498 'make -n -n' to recursively show commands. Now 'make -n' will recurse 499 and 'make -N' will not. 500 50120151012: 502 If you specify SENDMAIL_MC or SENDMAIL_CF in make.conf, mergemaster 503 and etcupdate will now use this file. A custom sendmail.cf is now 504 updated via this mechanism rather than via installworld. If you had 505 excluded sendmail.cf in mergemaster.rc or etcupdate.conf, you may 506 want to remove the exclusion or change it to "always install". 507 /etc/mail/sendmail.cf is now managed the same way regardless of 508 whether SENDMAIL_MC/SENDMAIL_CF is used. If you are not using 509 SENDMAIL_MC/SENDMAIL_CF there should be no change in behavior. 510 51120151011: 512 Compatibility shims for legacy ATA device names have been removed. 513 It includes ATA_STATIC_ID kernel option, kern.cam.ada.legacy_aliases 514 and kern.geom.raid.legacy_aliases loader tunables, kern.devalias.* 515 environment variables, /dev/ad* and /dev/ar* symbolic links. 516 51720151006: 518 Clang, llvm, lldb, compiler-rt and libc++ have been upgraded to 3.7.0. 519 Please see the 20141231 entry below for information about prerequisites 520 and upgrading, if you are not already using clang 3.5.0 or higher. 521 52220150924: 523 Kernel debug files have been moved to /usr/lib/debug/boot/kernel/, 524 and renamed from .symbols to .debug. This reduces the size requirements 525 on the boot partition or file system and provides consistency with 526 userland debug files. 527 528 When using the supported kernel installation method the 529 /usr/lib/debug/boot/kernel directory will be renamed (to kernel.old) 530 as is done with /boot/kernel. 531 532 Developers wishing to maintain the historical behavior of installing 533 debug files in /boot/kernel/ can set KERN_DEBUGDIR="" in src.conf(5). 534 53520150827: 536 The wireless drivers had undergone changes that remove the 'parent 537 interface' from the ifconfig -l output. The rc.d network scripts 538 used to check presence of a parent interface in the list, so old 539 scripts would fail to start wireless networking. Thus, etcupdate(3) 540 or mergemaster(8) run is required after kernel update, to update your 541 rc.d scripts in /etc. 542 54320150827: 544 pf no longer supports 'scrub fragment crop' or 'scrub fragment drop-ovl' 545 These configurations are now automatically interpreted as 546 'scrub fragment reassemble'. 547 54820150817: 549 Kernel-loadable modules for the random(4) device are back. To use 550 them, the kernel must have 551 552 device random 553 options RANDOM_LOADABLE 554 555 kldload(8) can then be used to load random_fortuna.ko 556 or random_yarrow.ko. Please note that due to the indirect 557 function calls that the loadable modules need to provide, 558 the build-in variants will be slightly more efficient. 559 560 The random(4) kernel option RANDOM_DUMMY has been retired due to 561 unpopularity. It was not all that useful anyway. 562 56320150813: 564 The WITHOUT_ELFTOOLCHAIN_TOOLS src.conf(5) knob has been retired. 565 Control over building the ELF Tool Chain tools is now provided by 566 the WITHOUT_TOOLCHAIN knob. 567 56820150810: 569 The polarity of Pulse Per Second (PPS) capture events with the 570 uart(4) driver has been corrected. Prior to this change the PPS 571 "assert" event corresponded to the trailing edge of a positive PPS 572 pulse and the "clear" event was the leading edge of the next pulse. 573 574 As the width of a PPS pulse in a typical GPS receiver is on the 575 order of 1 millisecond, most users will not notice any significant 576 difference with this change. 577 578 Anyone who has compensated for the historical polarity reversal by 579 configuring a negative offset equal to the pulse width will need to 580 remove that workaround. 581 58220150809: 583 The default group assigned to /dev/dri entries has been changed 584 from 'wheel' to 'video' with the id of '44'. If you want to have 585 access to the dri devices please add yourself to the video group 586 with: 587 588 # pw groupmod video -m $USER 589 59020150806: 591 The menu.rc and loader.rc files will now be replaced during 592 upgrades. Please migrate local changes to menu.rc.local and 593 loader.rc.local instead. 594 59520150805: 596 GNU Binutils versions of addr2line, c++filt, nm, readelf, size, 597 strings and strip have been removed. The src.conf(5) knob 598 WITHOUT_ELFTOOLCHAIN_TOOLS no longer provides the binutils tools. 599 60020150728: 601 As ZFS requires more kernel stack pages than is the default on some 602 architectures e.g. i386, it now warns if KSTACK_PAGES is less than 603 ZFS_MIN_KSTACK_PAGES (which is 4 at the time of writing). 604 605 Please consider using 'options KSTACK_PAGES=X' where X is greater 606 than or equal to ZFS_MIN_KSTACK_PAGES i.e. 4 in such configurations. 607 60820150706: 609 sendmail has been updated to 8.15.2. Starting with FreeBSD 11.0 610 and sendmail 8.15, sendmail uses uncompressed IPv6 addresses by 611 default, i.e., they will not contain "::". For example, instead 612 of ::1, it will be 0:0:0:0:0:0:0:1. This permits a zero subnet 613 to have a more specific match, such as different map entries for 614 IPv6:0:0 vs IPv6:0. This change requires that configuration 615 data (including maps, files, classes, custom ruleset, etc.) must 616 use the same format, so make certain such configuration data is 617 upgrading. As a very simple check search for patterns like 618 'IPv6:[0-9a-fA-F:]*::' and 'IPv6::'. To return to the old 619 behavior, set the m4 option confUSE_COMPRESSED_IPV6_ADDRESSES or 620 the cf option UseCompressedIPv6Addresses. 621 62220150630: 623 The default kernel entropy-processing algorithm is now 624 Fortuna, replacing Yarrow. 625 626 Assuming you have 'device random' in your kernel config 627 file, the configurations allow a kernel option to override 628 this default. You may choose *ONE* of: 629 630 options RANDOM_YARROW # Legacy /dev/random algorithm. 631 options RANDOM_DUMMY # Blocking-only driver. 632 633 If you have neither, you get Fortuna. For most people, 634 read no further, Fortuna will give a /dev/random that works 635 like it always used to, and the difference will be irrelevant. 636 637 If you remove 'device random', you get *NO* kernel-processed 638 entropy at all. This may be acceptable to folks building 639 embedded systems, but has complications. Carry on reading, 640 and it is assumed you know what you need. 641 642 *PLEASE* read random(4) and random(9) if you are in the 643 habit of tweaking kernel configs, and/or if you are a member 644 of the embedded community, wanting specific and not-usual 645 behaviour from your security subsystems. 646 647 NOTE!! If you use RANDOM_DUMMY and/or have no 'device 648 random', you will NOT have a functioning /dev/random, and 649 many cryptographic features will not work, including SSH. 650 You may also find strange behaviour from the random(3) set 651 of library functions, in particular sranddev(3), srandomdev(3) 652 and arc4random(3). The reason for this is that the KERN_ARND 653 sysctl only returns entropy if it thinks it has some to 654 share, and with RANDOM_DUMMY or no 'device random' this 655 will never happen. 656 65720150623: 658 An additional fix for the issue described in the 20150614 sendmail 659 entry below has been been committed in revision 284717. 660 66120150616: 662 FreeBSD's old make (fmake) has been removed from the system. It is 663 available as the devel/fmake port or via pkg install fmake. 664 66520150615: 666 The fix for the issue described in the 20150614 sendmail entry 667 below has been been committed in revision 284436. The work 668 around described in that entry is no longer needed unless the 669 default setting is overridden by a confDH_PARAMETERS configuration 670 setting of '5' or pointing to a 512 bit DH parameter file. 671 67220150614: 673 ALLOW_DEPRECATED_ATF_TOOLS/ATFFILE support has been removed from 674 atf.test.mk (included from bsd.test.mk). Please upgrade devel/atf 675 and devel/kyua to version 0.20+ and adjust any calling code to work 676 with Kyuafile and kyua. 677 67820150614: 679 The import of openssl to address the FreeBSD-SA-15:10.openssl 680 security advisory includes a change which rejects handshakes 681 with DH parameters below 768 bits. sendmail releases prior 682 to 8.15.2 (not yet released), defaulted to a 512 bit 683 DH parameter setting for client connections. To work around 684 this interoperability, sendmail can be configured to use a 685 2048 bit DH parameter by: 686 687 1. Edit /etc/mail/`hostname`.mc 688 2. If a setting for confDH_PARAMETERS does not exist or 689 exists and is set to a string beginning with '5', 690 replace it with '2'. 691 3. If a setting for confDH_PARAMETERS exists and is set to 692 a file path, create a new file with: 693 openssl dhparam -out /path/to/file 2048 694 4. Rebuild the .cf file: 695 cd /etc/mail/; make; make install 696 5. Restart sendmail: 697 cd /etc/mail/; make restart 698 699 A sendmail patch is coming, at which time this file will be 700 updated. 701 70220150604: 703 Generation of legacy formatted entries have been disabled by default 704 in pwd_mkdb(8), as all base system consumers of the legacy formatted 705 entries were converted to use the new format by default when the new, 706 machine independent format have been added and supported since FreeBSD 707 5.x. 708 709 Please see the pwd_mkdb(8) manual page for further details. 710 71120150525: 712 Clang and llvm have been upgraded to 3.6.1 release. Please see the 713 20141231 entry below for information about prerequisites and upgrading, 714 if you are not already using 3.5.0 or higher. 715 71620150521: 717 TI platform code switched to using vendor DTS files and this update 718 may break existing systems running on Beaglebone, Beaglebone Black, 719 and Pandaboard: 720 721 - dtb files should be regenerated/reinstalled. Filenames are the 722 same but content is different now 723 - GPIO addressing was changed, now each GPIO bank (32 pins per bank) 724 has its own /dev/gpiocX device, e.g. pin 121 on /dev/gpioc0 in old 725 addressing scheme is now pin 25 on /dev/gpioc3. 726 - Pandaboard: /etc/ttys should be updated, serial console device is 727 now /dev/ttyu2, not /dev/ttyu0 728 72920150501: 730 soelim(1) from gnu/usr.bin/groff has been replaced by usr.bin/soelim. 731 If you need the GNU extension from groff soelim(1), install groff 732 from package: pkg install groff, or via ports: textproc/groff. 733 73420150423: 735 chmod, chflags, chown and chgrp now affect symlinks in -R mode as 736 defined in symlink(7); previously symlinks were silently ignored. 737 73820150415: 739 The const qualifier has been removed from iconv(3) to comply with 740 POSIX. The ports tree is aware of this from r384038 onwards. 741 74220150416: 743 Libraries specified by LIBADD in Makefiles must have a corresponding 744 DPADD_<lib> variable to ensure correct dependencies. This is now 745 enforced in src.libnames.mk. 746 74720150324: 748 From legacy ata(4) driver was removed support for SATA controllers 749 supported by more functional drivers ahci(4), siis(4) and mvs(4). 750 Kernel modules ataahci and ataadaptec were removed completely, 751 replaced by ahci and mvs modules respectively. 752 75320150315: 754 Clang, llvm and lldb have been upgraded to 3.6.0 release. Please see 755 the 20141231 entry below for information about prerequisites and 756 upgrading, if you are not already using 3.5.0 or higher. 757 75820150307: 759 The 32-bit PowerPC kernel has been changed to a position-independent 760 executable. This can only be booted with a version of loader(8) 761 newer than January 31, 2015, so make sure to update both world and 762 kernel before rebooting. 763 76420150217: 765 If you are running a -CURRENT kernel since r273872 (Oct 30th, 2014), 766 but before r278950, the RNG was not seeded properly. Immediately 767 upgrade the kernel to r278950 or later and regenerate any keys (e.g. 768 ssh keys or openssl keys) that were generated w/ a kernel from that 769 range. This does not affect programs that directly used /dev/random 770 or /dev/urandom. All userland uses of arc4random(3) are affected. 771 77220150210: 773 The autofs(4) ABI was changed in order to restore binary compatibility 774 with 10.1-RELEASE. The automountd(8) daemon needs to be rebuilt to work 775 with the new kernel. 776 77720150131: 778 The powerpc64 kernel has been changed to a position-independent 779 executable. This can only be booted with a new version of loader(8), 780 so make sure to update both world and kernel before rebooting. 781 78220150118: 783 Clang and llvm have been upgraded to 3.5.1 release. This is a bugfix 784 only release, no new features have been added. Please see the 20141231 785 entry below for information about prerequisites and upgrading, if you 786 are not already using 3.5.0. 787 78820150107: 789 ELF tools addr2line, elfcopy (strip), nm, size, and strings are now 790 taken from the ELF Tool Chain project rather than GNU binutils. They 791 should be drop-in replacements, with the addition of arm64 support. 792 The WITHOUT_ELFTOOLCHAIN_TOOLS= knob may be used to obtain the 793 binutils tools, if necessary. See 20150805 for updated information. 794 79520150105: 796 The default Unbound configuration now enables remote control 797 using a local socket. Users who have already enabled the 798 local_unbound service should regenerate their configuration 799 by running "service local_unbound setup" as root. 800 80120150102: 802 The GNU texinfo and GNU info pages have been removed. 803 To be able to view GNU info pages please install texinfo from ports. 804 80520141231: 806 Clang, llvm and lldb have been upgraded to 3.5.0 release. 807 808 As of this release, a prerequisite for building clang, llvm and lldb is 809 a C++11 capable compiler and C++11 standard library. This means that to 810 be able to successfully build the cross-tools stage of buildworld, with 811 clang as the bootstrap compiler, your system compiler or cross compiler 812 should either be clang 3.3 or later, or gcc 4.8 or later, and your 813 system C++ library should be libc++, or libdstdc++ from gcc 4.8 or 814 later. 815 816 On any standard FreeBSD 10.x or 11.x installation, where clang and 817 libc++ are on by default (that is, on x86 or arm), this should work out 818 of the box. 819 820 On 9.x installations where clang is enabled by default, e.g. on x86 and 821 powerpc, libc++ will not be enabled by default, so libc++ should be 822 built (with clang) and installed first. If both clang and libc++ are 823 missing, build clang first, then use it to build libc++. 824 825 On 8.x and earlier installations, upgrade to 9.x first, and then follow 826 the instructions for 9.x above. 827 828 Sparc64 and mips users are unaffected, as they still use gcc 4.2.1 by 829 default, and do not build clang. 830 831 Many embedded systems are resource constrained, and will not be able to 832 build clang in a reasonable time, or in some cases at all. In those 833 cases, cross building bootable systems on amd64 is a workaround. 834 835 This new version of clang introduces a number of new warnings, of which 836 the following are most likely to appear: 837 838 -Wabsolute-value 839 840 This warns in two cases, for both C and C++: 841 * When the code is trying to take the absolute value of an unsigned 842 quantity, which is effectively a no-op, and almost never what was 843 intended. The code should be fixed, if at all possible. If you are 844 sure that the unsigned quantity can be safely cast to signed, without 845 loss of information or undefined behavior, you can add an explicit 846 cast, or disable the warning. 847 848 * When the code is trying to take an absolute value, but the called 849 abs() variant is for the wrong type, which can lead to truncation. 850 If you want to disable the warning instead of fixing the code, please 851 make sure that truncation will not occur, or it might lead to unwanted 852 side-effects. 853 854 -Wtautological-undefined-compare and 855 -Wundefined-bool-conversion 856 857 These warn when C++ code is trying to compare 'this' against NULL, while 858 'this' should never be NULL in well-defined C++ code. However, there is 859 some legacy (pre C++11) code out there, which actively abuses this 860 feature, which was less strictly defined in previous C++ versions. 861 862 Squid and openjdk do this, for example. The warning can be turned off 863 for C++98 and earlier, but compiling the code in C++11 mode might result 864 in unexpected behavior; for example, the parts of the program that are 865 unreachable could be optimized away. 866 86720141222: 868 The old NFS client and server (kernel options NFSCLIENT, NFSSERVER) 869 kernel sources have been removed. The .h files remain, since some 870 utilities include them. This will need to be fixed later. 871 If "mount -t oldnfs ..." is attempted, it will fail. 872 If the "-o" option on mountd(8), nfsd(8) or nfsstat(1) is used, 873 the utilities will report errors. 874 87520141121: 876 The handling of LOCAL_LIB_DIRS has been altered to skip addition of 877 directories to top level SUBDIR variable when their parent 878 directory is included in LOCAL_DIRS. Users with build systems with 879 such hierarchies and without SUBDIR entries in the parent 880 directory Makefiles should add them or add the directories to 881 LOCAL_DIRS. 882 88320141109: 884 faith(4) and faithd(8) have been removed from the base system. Faith 885 has been obsolete for a very long time. 886 88720141104: 888 vt(4), the new console driver, is enabled by default. It brings 889 support for Unicode and double-width characters, as well as 890 support for UEFI and integration with the KMS kernel video 891 drivers. 892 893 You may need to update your console settings in /etc/rc.conf, 894 most probably the keymap. During boot, /etc/rc.d/syscons will 895 indicate what you need to do. 896 897 vt(4) still has issues and lacks some features compared to 898 syscons(4). See the wiki for up-to-date information: 899 https://wiki.freebsd.org/Newcons 900 901 If you want to keep using syscons(4), you can do so by adding 902 the following line to /boot/loader.conf: 903 kern.vty=sc 904 90520141102: 906 pjdfstest has been integrated into kyua as an opt-in test suite. 907 Please see share/doc/pjdfstest/README for more details on how to 908 execute it. 909 91020141009: 911 gperf has been removed from the base system for architectures 912 that use clang. Ports that require gperf will obtain it from the 913 devel/gperf port. 914 91520140923: 916 pjdfstest has been moved from tools/regression/pjdfstest to 917 contrib/pjdfstest . 918 91920140922: 920 At svn r271982, The default linux compat kernel ABI has been adjusted 921 to 2.6.18 in support of the linux-c6 compat ports infrastructure 922 update. If you wish to continue using the linux-f10 compat ports, 923 add compat.linux.osrelease=2.6.16 to your local sysctl.conf. Users are 924 encouraged to update their linux-compat packages to linux-c6 during 925 their next update cycle. 926 92720140729: 928 The ofwfb driver, used to provide a graphics console on PowerPC when 929 using vt(4), no longer allows mmap() of all physical memory. This 930 will prevent Xorg on PowerPC with some ATI graphics cards from 931 initializing properly unless x11-servers/xorg-server is updated to 932 1.12.4_8 or newer. 933 93420140723: 935 The xdev targets have been converted to using TARGET and 936 TARGET_ARCH instead of XDEV and XDEV_ARCH. 937 93820140719: 939 The default unbound configuration has been modified to address 940 issues with reverse lookups on networks that use private 941 address ranges. If you use the local_unbound service, run 942 "service local_unbound setup" as root to regenerate your 943 configuration, then "service local_unbound reload" to load the 944 new configuration. 945 94620140709: 947 The GNU texinfo and GNU info pages are not built and installed 948 anymore, WITH_INFO knob has been added to allow to built and install 949 them again. 950 UPDATE: see 20150102 entry on texinfo's removal 951 95220140708: 953 The GNU readline library is now an INTERNALLIB - that is, it is 954 statically linked into consumers (GDB and variants) in the base 955 system, and the shared library is no longer installed. The 956 devel/readline port is available for third party software that 957 requires readline. 958 95920140702: 960 The Itanium architecture (ia64) has been removed from the list of 961 known architectures. This is the first step in the removal of the 962 architecture. 963 96420140701: 965 Commit r268115 has added NFSv4.1 server support, merged from 966 projects/nfsv4.1-server. Since this includes changes to the 967 internal interfaces between the NFS related modules, a full 968 build of the kernel and modules will be necessary. 969 __FreeBSD_version has been bumped. 970 97120140629: 972 The WITHOUT_VT_SUPPORT kernel config knob has been renamed 973 WITHOUT_VT. (The other _SUPPORT knobs have a consistent meaning 974 which differs from the behaviour controlled by this knob.) 975 97620140619: 977 Maximal length of the serial number in CTL was increased from 16 to 978 64 chars, that breaks ABI. All CTL-related tools, such as ctladm 979 and ctld, need to be rebuilt to work with a new kernel. 980 98120140606: 982 The libatf-c and libatf-c++ major versions were downgraded to 0 and 983 1 respectively to match the upstream numbers. They were out of 984 sync because, when they were originally added to FreeBSD, the 985 upstream versions were not respected. These libraries are private 986 and not yet built by default, so renumbering them should be a 987 non-issue. However, unclean source trees will yield broken test 988 programs once the operator executes "make delete-old-libs" after a 989 "make installworld". 990 991 Additionally, the atf-sh binary was made private by moving it into 992 /usr/libexec/. Already-built shell test programs will keep the 993 path to the old binary so they will break after "make delete-old" 994 is run. 995 996 If you are using WITH_TESTS=yes (not the default), wipe the object 997 tree and rebuild from scratch to prevent spurious test failures. 998 This is only needed once: the misnumbered libraries and misplaced 999 binaries have been added to OptionalObsoleteFiles.inc so they will 1000 be removed during a clean upgrade. 1001 100220140512: 1003 Clang and llvm have been upgraded to 3.4.1 release. 1004 100520140508: 1006 We bogusly installed src.opts.mk in /usr/share/mk. This file should 1007 be removed to avoid issues in the future (and has been added to 1008 ObsoleteFiles.inc). 1009 101020140505: 1011 /etc/src.conf now affects only builds of the FreeBSD src tree. In the 1012 past, it affected all builds that used the bsd.*.mk files. The old 1013 behavior was a bug, but people may have relied upon it. To get this 1014 behavior back, you can .include /etc/src.conf from /etc/make.conf 1015 (which is still global and isn't changed). This also changes the 1016 behavior of incremental builds inside the tree of individual 1017 directories. Set MAKESYSPATH to ".../share/mk" to do that. 1018 Although this has survived make universe and some upgrade scenarios, 1019 other upgrade scenarios may have broken. At least one form of 1020 temporary breakage was fixed with MAKESYSPATH settings for buildworld 1021 as well... In cases where MAKESYSPATH isn't working with this 1022 setting, you'll need to set it to the full path to your tree. 1023 1024 One side effect of all this cleaning up is that bsd.compiler.mk 1025 is no longer implicitly included by bsd.own.mk. If you wish to 1026 use COMPILER_TYPE, you must now explicitly include bsd.compiler.mk 1027 as well. 1028 102920140430: 1030 The lindev device has been removed since /dev/full has been made a 1031 standard device. __FreeBSD_version has been bumped. 1032 103320140424: 1034 The knob WITHOUT_VI was added to the base system, which controls 1035 building ex(1), vi(1), etc. Older releases of FreeBSD required ex(1) 1036 in order to reorder files share/termcap and didn't build ex(1) as a 1037 build tool, so building/installing with WITH_VI is highly advised for 1038 build hosts for older releases. 1039 1040 This issue has been fixed in stable/9 and stable/10 in r277022 and 1041 r276991, respectively. 1042 104320140418: 1044 The YES_HESIOD knob has been removed. It has been obsolete for 1045 a decade. Please move to using WITH_HESIOD instead or your builds 1046 will silently lack HESIOD. 1047 104820140405: 1049 The uart(4) driver has been changed with respect to its handling 1050 of the low-level console. Previously the uart(4) driver prevented 1051 any process from changing the baudrate or the CLOCAL and HUPCL 1052 control flags. By removing the restrictions, operators can make 1053 changes to the serial console port without having to reboot. 1054 However, when getty(8) is started on the serial device that is 1055 associated with the low-level console, a misconfigured terminal 1056 line in /etc/ttys will now have a real impact. 1057 Before upgrading the kernel, make sure that /etc/ttys has the 1058 serial console device configured as 3wire without baudrate to 1059 preserve the previous behaviour. E.g: 1060 ttyu0 "/usr/libexec/getty 3wire" vt100 on secure 1061 106220140306: 1063 Support for libwrap (TCP wrappers) in rpcbind was disabled by default 1064 to improve performance. To re-enable it, if needed, run rpcbind 1065 with command line option -W. 1066 106720140226: 1068 Switched back to the GPL dtc compiler due to updates in the upstream 1069 dts files not being supported by the BSDL dtc compiler. You will need 1070 to rebuild your kernel toolchain to pick up the new compiler. Core dumps 1071 may result while building dtb files during a kernel build if you fail 1072 to do so. Set WITHOUT_GPL_DTC if you require the BSDL compiler. 1073 107420140216: 1075 Clang and llvm have been upgraded to 3.4 release. 1076 107720140216: 1078 The nve(4) driver has been removed. Please use the nfe(4) driver 1079 for NVIDIA nForce MCP Ethernet adapters instead. 1080 108120140212: 1082 An ABI incompatibility crept into the libc++ 3.4 import in r261283. 1083 This could cause certain C++ applications using shared libraries built 1084 against the previous version of libc++ to crash. The incompatibility 1085 has now been fixed, but any C++ applications or shared libraries built 1086 between r261283 and r261801 should be recompiled. 1087 108820140204: 1089 OpenSSH will now ignore errors caused by kernel lacking of Capsicum 1090 capability mode support. Please note that enabling the feature in 1091 kernel is still highly recommended. 1092 109320140131: 1094 OpenSSH is now built with sandbox support, and will use sandbox as 1095 the default privilege separation method. This requires Capsicum 1096 capability mode support in kernel. 1097 109820140128: 1099 The libelf and libdwarf libraries have been updated to newer 1100 versions from upstream. Shared library version numbers for 1101 these two libraries were bumped. Any ports or binaries 1102 requiring these two libraries should be recompiled. 1103 __FreeBSD_version is bumped to 1100006. 1104 110520140110: 1106 If a Makefile in a tests/ directory was auto-generating a Kyuafile 1107 instead of providing an explicit one, this would prevent such 1108 Makefile from providing its own Kyuafile in the future during 1109 NO_CLEAN builds. This has been fixed in the Makefiles but manual 1110 intervention is needed to clean an objdir if you use NO_CLEAN: 1111 # find /usr/obj -name Kyuafile | xargs rm -f 1112 111320131213: 1114 The behavior of gss_pseudo_random() for the krb5 mechanism 1115 has changed, for applications requesting a longer random string 1116 than produced by the underlying enctype's pseudo-random() function. 1117 In particular, the random string produced from a session key of 1118 enctype aes256-cts-hmac-sha1-96 or aes256-cts-hmac-sha1-96 will 1119 be different at the 17th octet and later, after this change. 1120 The counter used in the PRF+ construction is now encoded as a 1121 big-endian integer in accordance with RFC 4402. 1122 __FreeBSD_version is bumped to 1100004. 1123 112420131108: 1125 The WITHOUT_ATF build knob has been removed and its functionality 1126 has been subsumed into the more generic WITHOUT_TESTS. If you were 1127 using the former to disable the build of the ATF libraries, you 1128 should change your settings to use the latter. 1129 113020131025: 1131 The default version of mtree is nmtree which is obtained from 1132 NetBSD. The output is generally the same, but may vary 1133 slightly. If you found you need identical output adding 1134 "-F freebsd9" to the command line should do the trick. For the 1135 time being, the old mtree is available as fmtree. 1136 113720131014: 1138 libbsdyml has been renamed to libyaml and moved to /usr/lib/private. 1139 This will break ports-mgmt/pkg. Rebuild the port, or upgrade to pkg 1140 1.1.4_8 and verify bsdyml not linked in, before running "make 1141 delete-old-libs": 1142 # make -C /usr/ports/ports-mgmt/pkg build deinstall install clean 1143 or 1144 # pkg install pkg; ldd /usr/local/sbin/pkg | grep bsdyml 1145 114620131010: 1147 The stable/10 branch has been created in subversion from head 1148 revision r256279. 1149 115020131010: 1151 The rc.d/jail script has been updated to support jail(8) 1152 configuration file. The "jail_<jname>_*" rc.conf(5) variables 1153 for per-jail configuration are automatically converted to 1154 /var/run/jail.<jname>.conf before the jail(8) utility is invoked. 1155 This is transparently backward compatible. See below about some 1156 incompatibilities and rc.conf(5) manual page for more details. 1157 1158 These variables are now deprecated in favor of jail(8) configuration 1159 file. One can use "rc.d/jail config <jname>" command to generate 1160 a jail(8) configuration file in /var/run/jail.<jname>.conf without 1161 running the jail(8) utility. The default pathname of the 1162 configuration file is /etc/jail.conf and can be specified by 1163 using $jail_conf or $jail_<jname>_conf variables. 1164 1165 Please note that jail_devfs_ruleset accepts an integer at 1166 this moment. Please consider to rewrite the ruleset name 1167 with an integer. 1168 116920130930: 1170 BIND has been removed from the base system. If all you need 1171 is a local resolver, simply enable and start the local_unbound 1172 service instead. Otherwise, several versions of BIND are 1173 available in the ports tree. The dns/bind99 port is one example. 1174 1175 With this change, nslookup(1) and dig(1) are no longer in the base 1176 system. Users should instead use host(1) and drill(1) which are 1177 in the base system. Alternatively, nslookup and dig can 1178 be obtained by installing the dns/bind-tools port. 1179 118020130916: 1181 With the addition of unbound(8), a new unbound user is now 1182 required during installworld. "mergemaster -p" can be used to 1183 add the user prior to installworld, as documented in the handbook. 1184 118520130911: 1186 OpenSSH is now built with DNSSEC support, and will by default 1187 silently trust signed SSHFP records. This can be controlled with 1188 the VerifyHostKeyDNS client configuration setting. DNSSEC support 1189 can be disabled entirely with the WITHOUT_LDNS option in src.conf. 1190 119120130906: 1192 The GNU Compiler Collection and C++ standard library (libstdc++) 1193 are no longer built by default on platforms where clang is the system 1194 compiler. You can enable them with the WITH_GCC and WITH_GNUCXX 1195 options in src.conf. 1196 119720130905: 1198 The PROCDESC kernel option is now part of the GENERIC kernel 1199 configuration and is required for the rwhod(8) to work. 1200 If you are using custom kernel configuration, you should include 1201 'options PROCDESC'. 1202 120320130905: 1204 The API and ABI related to the Capsicum framework was modified 1205 in backward incompatible way. The userland libraries and programs 1206 have to be recompiled to work with the new kernel. This includes the 1207 following libraries and programs, but the whole buildworld is 1208 advised: libc, libprocstat, dhclient, tcpdump, hastd, hastctl, 1209 kdump, procstat, rwho, rwhod, uniq. 1210 121120130903: 1212 AES-NI intrinsic support has been added to gcc. The AES-NI module 1213 has been updated to use this support. A new gcc is required to build 1214 the aesni module on both i386 and amd64. 1215 121620130821: 1217 The PADLOCK_RNG and RDRAND_RNG kernel options are now devices. 1218 Thus "device padlock_rng" and "device rdrand_rng" should be 1219 used instead of "options PADLOCK_RNG" & "options RDRAND_RNG". 1220 122120130813: 1222 WITH_ICONV has been split into two feature sets. WITH_ICONV now 1223 enables just the iconv* functionality and is now on by default. 1224 WITH_LIBICONV_COMPAT enables the libiconv api and link time 1225 compatibility. Set WITHOUT_ICONV to build the old way. 1226 If you have been using WITH_ICONV before, you will very likely 1227 need to turn on WITH_LIBICONV_COMPAT. 1228 122920130806: 1230 INVARIANTS option now enables DEBUG for code with OpenSolaris and 1231 Illumos origin, including ZFS. If you have INVARIANTS in your 1232 kernel configuration, then there is no need to set DEBUG or ZFS_DEBUG 1233 explicitly. 1234 DEBUG used to enable witness(9) tracking of OpenSolaris (mostly ZFS) 1235 locks if WITNESS option was set. Because that generated a lot of 1236 witness(9) reports and all of them were believed to be false 1237 positives, this is no longer done. New option OPENSOLARIS_WITNESS 1238 can be used to achieve the previous behavior. 1239 124020130806: 1241 Timer values in IPv6 data structures now use time_uptime instead 1242 of time_second. Although this is not a user-visible functional 1243 change, userland utilities which directly use them---ndp(8), 1244 rtadvd(8), and rtsold(8) in the base system---need to be updated 1245 to r253970 or later. 1246 124720130802: 1248 find -delete can now delete the pathnames given as arguments, 1249 instead of only files found below them or if the pathname did 1250 not contain any slashes. Formerly, the following error message 1251 would result: 1252 1253 find: -delete: <path>: relative path potentially not safe 1254 1255 Deleting the pathnames given as arguments can be prevented 1256 without error messages using -mindepth 1 or by changing 1257 directory and passing "." as argument to find. This works in the 1258 old as well as the new version of find. 1259 126020130726: 1261 Behavior of devfs rules path matching has been changed. 1262 Pattern is now always matched against fully qualified devfs 1263 path and slash characters must be explicitly matched by 1264 slashes in pattern (FNM_PATHNAME). Rulesets involving devfs 1265 subdirectories must be reviewed. 1266 126720130716: 1268 The default ARM ABI has changed to the ARM EABI. The old ABI is 1269 incompatible with the ARM EABI and all programs and modules will 1270 need to be rebuilt to work with a new kernel. 1271 1272 To keep using the old ABI ensure the WITHOUT_ARM_EABI knob is set. 1273 1274 NOTE: Support for the old ABI will be removed in the future and 1275 users are advised to upgrade. 1276 127720130709: 1278 pkg_install has been disconnected from the build if you really need it 1279 you should add WITH_PKGTOOLS in your src.conf(5). 1280 128120130709: 1282 Most of network statistics structures were changed to be able 1283 keep 64-bits counters. Thus all tools, that work with networking 1284 statistics, must be rebuilt (netstat(1), bsnmpd(1), etc.) 1285 128620130618: 1287 Fix a bug that allowed a tracing process (e.g. gdb) to write 1288 to a memory-mapped file in the traced process's address space 1289 even if neither the traced process nor the tracing process had 1290 write access to that file. 1291 129220130615: 1293 CVS has been removed from the base system. An exact copy 1294 of the code is available from the devel/cvs port. 1295 129620130613: 1297 Some people report the following error after the switch to bmake: 1298 1299 make: illegal option -- J 1300 usage: make [-BPSXeiknpqrstv] [-C directory] [-D variable] 1301 ... 1302 *** [buildworld] Error code 2 1303 1304 this likely due to an old instance of make in 1305 ${MAKEPATH} (${MAKEOBJDIRPREFIX}${.CURDIR}/make.${MACHINE}) 1306 which src/Makefile will use that blindly, if it exists, so if 1307 you see the above error: 1308 1309 rm -rf `make -V MAKEPATH` 1310 1311 should resolve it. 1312 131320130516: 1314 Use bmake by default. 1315 Whereas before one could choose to build with bmake via 1316 -DWITH_BMAKE one must now use -DWITHOUT_BMAKE to use the old 1317 make. The goal is to remove these knobs for 10-RELEASE. 1318 1319 It is worth noting that bmake (like gmake) treats the command 1320 line as the unit of failure, rather than statements within the 1321 command line. Thus '(cd some/where && dosomething)' is safer 1322 than 'cd some/where; dosomething'. The '()' allows consistent 1323 behavior in parallel build. 1324 132520130429: 1326 Fix a bug that allows NFS clients to issue READDIR on files. 1327 132820130426: 1329 The WITHOUT_IDEA option has been removed because 1330 the IDEA patent expired. 1331 133220130426: 1333 The sysctl which controls TRIM support under ZFS has been renamed 1334 from vfs.zfs.trim_disable -> vfs.zfs.trim.enabled and has been 1335 enabled by default. 1336 133720130425: 1338 The mergemaster command now uses the default MAKEOBJDIRPREFIX 1339 rather than creating it's own in the temporary directory in 1340 order allow access to bootstrapped versions of tools such as 1341 install and mtree. When upgrading from version of FreeBSD where 1342 the install command does not support -l, you will need to 1343 install a new mergemaster command if mergemaster -p is required. 1344 This can be accomplished with the command (cd src/usr.sbin/mergemaster 1345 && make install). 1346 134720130404: 1348 Legacy ATA stack, disabled and replaced by new CAM-based one since 1349 FreeBSD 9.0, completely removed from the sources. Kernel modules 1350 atadisk and atapi*, user-level tools atacontrol and burncd are 1351 removed. Kernel option `options ATA_CAM` is now permanently enabled 1352 and removed. 1353 135420130319: 1355 SOCK_CLOEXEC and SOCK_NONBLOCK flags have been added to socket(2) 1356 and socketpair(2). Software, in particular Kerberos, may 1357 automatically detect and use these during building. The resulting 1358 binaries will not work on older kernels. 1359 136020130308: 1361 CTL_DISABLE has also been added to the sparc64 GENERIC (for further 1362 information, see the respective 20130304 entry). 1363 136420130304: 1365 Recent commits to callout(9) changed the size of struct callout, 1366 so the KBI is probably heavily disturbed. Also, some functions 1367 in callout(9)/sleep(9)/sleepqueue(9)/condvar(9) KPIs were replaced 1368 by macros. Every kernel module using it won't load, so rebuild 1369 is requested. 1370 1371 The ctl device has been re-enabled in GENERIC for i386 and amd64, 1372 but does not initialize by default (because of the new CTL_DISABLE 1373 option) to save memory. To re-enable it, remove the CTL_DISABLE 1374 option from the kernel config file or set kern.cam.ctl.disable=0 1375 in /boot/loader.conf. 1376 137720130301: 1378 The ctl device has been disabled in GENERIC for i386 and amd64. 1379 This was done due to the extra memory being allocated at system 1380 initialisation time by the ctl driver which was only used if 1381 a CAM target device was created. This makes a FreeBSD system 1382 unusable on 128MB or less of RAM. 1383 138420130208: 1385 A new compression method (lz4) has been merged to -HEAD. Please 1386 refer to zpool-features(7) for more information. 1387 1388 Please refer to the "ZFS notes" section of this file for information 1389 on upgrading boot ZFS pools. 1390 139120130129: 1392 A BSD-licensed patch(1) variant has been added and is installed 1393 as bsdpatch, being the GNU version the default patch. 1394 To inverse the logic and use the BSD-licensed one as default, 1395 while having the GNU version installed as gnupatch, rebuild 1396 and install world with the WITH_BSD_PATCH knob set. 1397 139820130121: 1399 Due to the use of the new -l option to install(1) during build 1400 and install, you must take care not to directly set the INSTALL 1401 make variable in your /etc/make.conf, /etc/src.conf, or on the 1402 command line. If you wish to use the -C flag for all installs 1403 you may be able to add INSTALL+=-C to /etc/make.conf or 1404 /etc/src.conf. 1405 140620130118: 1407 The install(1) option -M has changed meaning and now takes an 1408 argument that is a file or path to append logs to. In the 1409 unlikely event that -M was the last option on the command line 1410 and the command line contained at least two files and a target 1411 directory the first file will have logs appended to it. The -M 1412 option served little practical purpose in the last decade so its 1413 use is expected to be extremely rare. 1414 141520121223: 1416 After switching to Clang as the default compiler some users of ZFS 1417 on i386 systems started to experience stack overflow kernel panics. 1418 Please consider using 'options KSTACK_PAGES=4' in such configurations. 1419 142020121222: 1421 GEOM_LABEL now mangles label names read from file system metadata. 1422 Mangling affect labels containing spaces, non-printable characters, 1423 '%' or '"'. Device names in /etc/fstab and other places may need to 1424 be updated. 1425 142620121217: 1427 By default, only the 10 most recent kernel dumps will be saved. To 1428 restore the previous behaviour (no limit on the number of kernel dumps 1429 stored in the dump directory) add the following line to /etc/rc.conf: 1430 1431 savecore_flags="" 1432 143320121201: 1434 With the addition of auditdistd(8), a new auditdistd user is now 1435 required during installworld. "mergemaster -p" can be used to 1436 add the user prior to installworld, as documented in the handbook. 1437 143820121117: 1439 The sin6_scope_id member variable in struct sockaddr_in6 is now 1440 filled by the kernel before passing the structure to the userland via 1441 sysctl or routing socket. This means the KAME-specific embedded scope 1442 id in sin6_addr.s6_addr[2] is always cleared in userland application. 1443 This behavior can be controlled by net.inet6.ip6.deembed_scopeid. 1444 __FreeBSD_version is bumped to 1000025. 1445 144620121105: 1447 On i386 and amd64 systems WITH_CLANG_IS_CC is now the default. 1448 This means that the world and kernel will be compiled with clang 1449 and that clang will be installed as /usr/bin/cc, /usr/bin/c++, 1450 and /usr/bin/cpp. To disable this behavior and revert to building 1451 with gcc, compile with WITHOUT_CLANG_IS_CC. Really old versions 1452 of current may need to bootstrap WITHOUT_CLANG first if the clang 1453 build fails (its compatibility window doesn't extend to the 9 stable 1454 branch point). 1455 145620121102: 1457 The IPFIREWALL_FORWARD kernel option has been removed. Its 1458 functionality now turned on by default. 1459 146020121023: 1461 The ZERO_COPY_SOCKET kernel option has been removed and 1462 split into SOCKET_SEND_COW and SOCKET_RECV_PFLIP. 1463 NB: SOCKET_SEND_COW uses the VM page based copy-on-write 1464 mechanism which is not safe and may result in kernel crashes. 1465 NB: The SOCKET_RECV_PFLIP mechanism is useless as no current 1466 driver supports disposeable external page sized mbuf storage. 1467 Proper replacements for both zero-copy mechanisms are under 1468 consideration and will eventually lead to complete removal 1469 of the two kernel options. 1470 147120121023: 1472 The IPv4 network stack has been converted to network byte 1473 order. The following modules need to be recompiled together 1474 with kernel: carp(4), divert(4), gif(4), siftr(4), gre(4), 1475 pf(4), ipfw(4), ng_ipfw(4), stf(4). 1476 147720121022: 1478 Support for non-MPSAFE filesystems was removed from VFS. The 1479 VFS_VERSION was bumped, all filesystem modules shall be 1480 recompiled. 1481 148220121018: 1483 All the non-MPSAFE filesystems have been disconnected from 1484 the build. The full list includes: codafs, hpfs, ntfs, nwfs, 1485 portalfs, smbfs, xfs. 1486 148720121016: 1488 The interface cloning API and ABI has changed. The following 1489 modules need to be recompiled together with kernel: 1490 ipfw(4), pfsync(4), pflog(4), usb(4), wlan(4), stf(4), 1491 vlan(4), disc(4), edsc(4), if_bridge(4), gif(4), tap(4), 1492 faith(4), epair(4), enc(4), tun(4), if_lagg(4), gre(4). 1493 149420121015: 1495 The sdhci driver was split in two parts: sdhci (generic SD Host 1496 Controller logic) and sdhci_pci (actual hardware driver). 1497 No kernel config modifications are required, but if you 1498 load sdhc as a module you must switch to sdhci_pci instead. 1499 150020121014: 1501 Import the FUSE kernel and userland support into base system. 1502 150320121013: 1504 The GNU sort(1) program has been removed since the BSD-licensed 1505 sort(1) has been the default for quite some time and no serious 1506 problems have been reported. The corresponding WITH_GNU_SORT 1507 knob has also gone. 1508 150920121006: 1510 The pfil(9) API/ABI for AF_INET family has been changed. Packet 1511 filtering modules: pf(4), ipfw(4), ipfilter(4) need to be recompiled 1512 with new kernel. 1513 151420121001: 1515 The net80211(4) ABI has been changed to allow for improved driver 1516 PS-POLL and power-save support. All wireless drivers need to be 1517 recompiled to work with the new kernel. 1518 151920120913: 1520 The random(4) support for the VIA hardware random number 1521 generator (`PADLOCK') is no longer enabled unconditionally. 1522 Add the padlock_rng device in the custom kernel config if 1523 needed. The GENERIC kernels on i386 and amd64 do include the 1524 device, so the change only affects the custom kernel 1525 configurations. 1526 152720120908: 1528 The pf(4) packet filter ABI has been changed. pfctl(8) and 1529 snmp_pf module need to be recompiled to work with new kernel. 1530 153120120828: 1532 A new ZFS feature flag "com.delphix:empty_bpobj" has been merged 1533 to -HEAD. Pools that have empty_bpobj in active state can not be 1534 imported read-write with ZFS implementations that do not support 1535 this feature. For more information read the zpool-features(5) 1536 manual page. 1537 153820120727: 1539 The sparc64 ZFS loader has been changed to no longer try to auto- 1540 detect ZFS providers based on diskN aliases but now requires these 1541 to be explicitly listed in the OFW boot-device environment variable. 1542 154320120712: 1544 The OpenSSL has been upgraded to 1.0.1c. Any binaries requiring 1545 libcrypto.so.6 or libssl.so.6 must be recompiled. Also, there are 1546 configuration changes. Make sure to merge /etc/ssl/openssl.cnf. 1547 154820120712: 1549 The following sysctls and tunables have been renamed for consistency 1550 with other variables: 1551 kern.cam.da.da_send_ordered -> kern.cam.da.send_ordered 1552 kern.cam.ada.ada_send_ordered -> kern.cam.ada.send_ordered 1553 155420120628: 1555 The sort utility has been replaced with BSD sort. For now, GNU sort 1556 is also available as "gnusort" or the default can be set back to 1557 GNU sort by setting WITH_GNU_SORT. In this case, BSD sort will be 1558 installed as "bsdsort". 1559 156020120611: 1561 A new version of ZFS (pool version 5000) has been merged to -HEAD. 1562 Starting with this version the old system of ZFS pool versioning 1563 is superseded by "feature flags". This concept enables forward 1564 compatibility against certain future changes in functionality of ZFS 1565 pools. The first read-only compatible "feature flag" for ZFS pools 1566 is named "com.delphix:async_destroy". For more information 1567 read the new zpool-features(5) manual page. 1568 Please refer to the "ZFS notes" section of this file for information 1569 on upgrading boot ZFS pools. 1570 157120120417: 1572 The malloc(3) implementation embedded in libc now uses sources imported 1573 as contrib/jemalloc. The most disruptive API change is to 1574 /etc/malloc.conf. If your system has an old-style /etc/malloc.conf, 1575 delete it prior to installworld, and optionally re-create it using the 1576 new format after rebooting. See malloc.conf(5) for details 1577 (specifically the TUNING section and the "opt.*" entries in the MALLCTL 1578 NAMESPACE section). 1579 158020120328: 1581 Big-endian MIPS TARGET_ARCH values no longer end in "eb". mips64eb 1582 is now spelled mips64. mipsn32eb is now spelled mipsn32. mipseb is 1583 now spelled mips. This is to aid compatibility with third-party 1584 software that expects this naming scheme in uname(3). Little-endian 1585 settings are unchanged. If you are updating a big-endian mips64 machine 1586 from before this change, you may need to set MACHINE_ARCH=mips64 in 1587 your environment before the new build system will recognize your machine. 1588 158920120306: 1590 Disable by default the option VFS_ALLOW_NONMPSAFE for all supported 1591 platforms. 1592 159320120229: 1594 Now unix domain sockets behave "as expected" on nullfs(5). Previously 1595 nullfs(5) did not pass through all behaviours to the underlying layer, 1596 as a result if we bound to a socket on the lower layer we could connect 1597 only to the lower path; if we bound to the upper layer we could connect 1598 only to the upper path. The new behavior is one can connect to both the 1599 lower and the upper paths regardless what layer path one binds to. 1600 160120120211: 1602 The getifaddrs upgrade path broken with 20111215 has been restored. 1603 If you have upgraded in between 20111215 and 20120209 you need to 1604 recompile libc again with your kernel. You still need to recompile 1605 world to be able to configure CARP but this restriction already 1606 comes from 20111215. 1607 160820120114: 1609 The set_rcvar() function has been removed from /etc/rc.subr. All 1610 base and ports rc.d scripts have been updated, so if you have a 1611 port installed with a script in /usr/local/etc/rc.d you can either 1612 hand-edit the rcvar= line, or reinstall the port. 1613 1614 An easy way to handle the mass-update of /etc/rc.d: 1615 rm /etc/rc.d/* && mergemaster -i 1616 161720120109: 1618 panic(9) now stops other CPUs in the SMP systems, disables interrupts 1619 on the current CPU and prevents other threads from running. 1620 This behavior can be reverted using the kern.stop_scheduler_on_panic 1621 tunable/sysctl. 1622 The new behavior can be incompatible with kern.sync_on_panic. 1623 162420111215: 1625 The carp(4) facility has been changed significantly. Configuration 1626 of the CARP protocol via ifconfig(8) has changed, as well as format 1627 of CARP events submitted to devd(8) has changed. See manual pages 1628 for more information. The arpbalance feature of carp(4) is currently 1629 not supported anymore. 1630 1631 Size of struct in_aliasreq, struct in6_aliasreq has changed. User 1632 utilities using SIOCAIFADDR, SIOCAIFADDR_IN6, e.g. ifconfig(8), 1633 need to be recompiled. 1634 163520111122: 1636 The acpi_wmi(4) status device /dev/wmistat has been renamed to 1637 /dev/wmistat0. 1638 163920111108: 1640 The option VFS_ALLOW_NONMPSAFE option has been added in order to 1641 explicitely support non-MPSAFE filesystems. 1642 It is on by default for all supported platform at this present 1643 time. 1644 164520111101: 1646 The broken amd(4) driver has been replaced with esp(4) in the amd64, 1647 i386 and pc98 GENERIC kernel configuration files. 1648 164920110930: 1650 sysinstall has been removed 1651 165220110923: 1653 The stable/9 branch created in subversion. This corresponds to the 1654 RELENG_9 branch in CVS. 1655 1656COMMON ITEMS: 1657 1658 General Notes 1659 ------------- 1660 Avoid using make -j when upgrading. While generally safe, there are 1661 sometimes problems using -j to upgrade. If your upgrade fails with 1662 -j, please try again without -j. From time to time in the past there 1663 have been problems using -j with buildworld and/or installworld. This 1664 is especially true when upgrading between "distant" versions (eg one 1665 that cross a major release boundary or several minor releases, or when 1666 several months have passed on the -current branch). 1667 1668 Sometimes, obscure build problems are the result of environment 1669 poisoning. This can happen because the make utility reads its 1670 environment when searching for values for global variables. To run 1671 your build attempts in an "environmental clean room", prefix all make 1672 commands with 'env -i '. See the env(1) manual page for more details. 1673 1674 When upgrading from one major version to another it is generally best 1675 to upgrade to the latest code in the currently installed branch first, 1676 then do an upgrade to the new branch. This is the best-tested upgrade 1677 path, and has the highest probability of being successful. Please try 1678 this approach before reporting problems with a major version upgrade. 1679 1680 When upgrading a live system, having a root shell around before 1681 installing anything can help undo problems. Not having a root shell 1682 around can lead to problems if pam has changed too much from your 1683 starting point to allow continued authentication after the upgrade. 1684 1685 This file should be read as a log of events. When a later event changes 1686 information of a prior event, the prior event should not be deleted. 1687 Instead, a pointer to the entry with the new information should be 1688 placed in the old entry. Readers of this file should also sanity check 1689 older entries before relying on them blindly. Authors of new entries 1690 should write them with this in mind. 1691 1692 ZFS notes 1693 --------- 1694 When upgrading the boot ZFS pool to a new version, always follow 1695 these two steps: 1696 1697 1.) recompile and reinstall the ZFS boot loader and boot block 1698 (this is part of "make buildworld" and "make installworld") 1699 1700 2.) update the ZFS boot block on your boot drive 1701 1702 The following example updates the ZFS boot block on the first 1703 partition (freebsd-boot) of a GPT partitioned drive ada0: 1704 "gpart bootcode -p /boot/gptzfsboot -i 1 ada0" 1705 1706 Non-boot pools do not need these updates. 1707 1708 To build a kernel 1709 ----------------- 1710 If you are updating from a prior version of FreeBSD (even one just 1711 a few days old), you should follow this procedure. It is the most 1712 failsafe as it uses a /usr/obj tree with a fresh mini-buildworld, 1713 1714 make kernel-toolchain 1715 make -DALWAYS_CHECK_MAKE buildkernel KERNCONF=YOUR_KERNEL_HERE 1716 make -DALWAYS_CHECK_MAKE installkernel KERNCONF=YOUR_KERNEL_HERE 1717 1718 To test a kernel once 1719 --------------------- 1720 If you just want to boot a kernel once (because you are not sure 1721 if it works, or if you want to boot a known bad kernel to provide 1722 debugging information) run 1723 make installkernel KERNCONF=YOUR_KERNEL_HERE KODIR=/boot/testkernel 1724 nextboot -k testkernel 1725 1726 To just build a kernel when you know that it won't mess you up 1727 -------------------------------------------------------------- 1728 This assumes you are already running a CURRENT system. Replace 1729 ${arch} with the architecture of your machine (e.g. "i386", 1730 "arm", "amd64", "ia64", "pc98", "sparc64", "powerpc", "mips", etc). 1731 1732 cd src/sys/${arch}/conf 1733 config KERNEL_NAME_HERE 1734 cd ../compile/KERNEL_NAME_HERE 1735 make depend 1736 make 1737 make install 1738 1739 If this fails, go to the "To build a kernel" section. 1740 1741 To rebuild everything and install it on the current system. 1742 ----------------------------------------------------------- 1743 # Note: sometimes if you are running current you gotta do more than 1744 # is listed here if you are upgrading from a really old current. 1745 1746 <make sure you have good level 0 dumps> 1747 make buildworld 1748 make kernel KERNCONF=YOUR_KERNEL_HERE 1749 [1] 1750 <reboot in single user> [3] 1751 mergemaster -Fp [5] 1752 make installworld 1753 mergemaster -Fi [4] 1754 make delete-old [6] 1755 <reboot> 1756 1757 To cross-install current onto a separate partition 1758 -------------------------------------------------- 1759 # In this approach we use a separate partition to hold 1760 # current's root, 'usr', and 'var' directories. A partition 1761 # holding "/", "/usr" and "/var" should be about 2GB in 1762 # size. 1763 1764 <make sure you have good level 0 dumps> 1765 <boot into -stable> 1766 make buildworld 1767 make buildkernel KERNCONF=YOUR_KERNEL_HERE 1768 <maybe newfs current's root partition> 1769 <mount current's root partition on directory ${CURRENT_ROOT}> 1770 make installworld DESTDIR=${CURRENT_ROOT} -DDB_FROM_SRC 1771 make distribution DESTDIR=${CURRENT_ROOT} # if newfs'd 1772 make installkernel KERNCONF=YOUR_KERNEL_HERE DESTDIR=${CURRENT_ROOT} 1773 cp /etc/fstab ${CURRENT_ROOT}/etc/fstab # if newfs'd 1774 <edit ${CURRENT_ROOT}/etc/fstab to mount "/" from the correct partition> 1775 <reboot into current> 1776 <do a "native" rebuild/install as described in the previous section> 1777 <maybe install compatibility libraries from ports/misc/compat*> 1778 <reboot> 1779 1780 1781 To upgrade in-place from stable to current 1782 ---------------------------------------------- 1783 <make sure you have good level 0 dumps> 1784 make buildworld [9] 1785 make kernel KERNCONF=YOUR_KERNEL_HERE [8] 1786 [1] 1787 <reboot in single user> [3] 1788 mergemaster -Fp [5] 1789 make installworld 1790 mergemaster -Fi [4] 1791 make delete-old [6] 1792 <reboot> 1793 1794 Make sure that you've read the UPDATING file to understand the 1795 tweaks to various things you need. At this point in the life 1796 cycle of current, things change often and you are on your own 1797 to cope. The defaults can also change, so please read ALL of 1798 the UPDATING entries. 1799 1800 Also, if you are tracking -current, you must be subscribed to 1801 freebsd-current@freebsd.org. Make sure that before you update 1802 your sources that you have read and understood all the recent 1803 messages there. If in doubt, please track -stable which has 1804 much fewer pitfalls. 1805 1806 [1] If you have third party modules, such as vmware, you 1807 should disable them at this point so they don't crash your 1808 system on reboot. 1809 1810 [3] From the bootblocks, boot -s, and then do 1811 fsck -p 1812 mount -u / 1813 mount -a 1814 cd src 1815 adjkerntz -i # if CMOS is wall time 1816 Also, when doing a major release upgrade, it is required that 1817 you boot into single user mode to do the installworld. 1818 1819 [4] Note: This step is non-optional. Failure to do this step 1820 can result in a significant reduction in the functionality of the 1821 system. Attempting to do it by hand is not recommended and those 1822 that pursue this avenue should read this file carefully, as well 1823 as the archives of freebsd-current and freebsd-hackers mailing lists 1824 for potential gotchas. The -U option is also useful to consider. 1825 See mergemaster(8) for more information. 1826 1827 [5] Usually this step is a noop. However, from time to time 1828 you may need to do this if you get unknown user in the following 1829 step. It never hurts to do it all the time. You may need to 1830 install a new mergemaster (cd src/usr.sbin/mergemaster && make 1831 install) after the buildworld before this step if you last updated 1832 from current before 20130425 or from -stable before 20130430. 1833 1834 [6] This only deletes old files and directories. Old libraries 1835 can be deleted by "make delete-old-libs", but you have to make 1836 sure that no program is using those libraries anymore. 1837 1838 [8] The new kernel must be able to run existing binaries used by 1839 an installworld. When upgrading across major versions, the new 1840 kernel's configuration must include the correct COMPAT_FREEBSD<n> 1841 option for existing binaries (e.g. COMPAT_FREEBSD11 to run 11.x 1842 binaries). Failure to do so may leave you with a system that is 1843 hard to boot to recover. A GENERIC kernel will include suitable 1844 compatibility options to run binaries from older branches. 1845 1846 Make sure that you merge any new devices from GENERIC since the 1847 last time you updated your kernel config file. 1848 1849 [9] When checking out sources, you must include the -P flag to have 1850 cvs prune empty directories. 1851 1852 If CPUTYPE is defined in your /etc/make.conf, make sure to use the 1853 "?=" instead of the "=" assignment operator, so that buildworld can 1854 override the CPUTYPE if it needs to. 1855 1856 MAKEOBJDIRPREFIX must be defined in an environment variable, and 1857 not on the command line, or in /etc/make.conf. buildworld will 1858 warn if it is improperly defined. 1859FORMAT: 1860 1861This file contains a list, in reverse chronological order, of major 1862breakages in tracking -current. It is not guaranteed to be a complete 1863list of such breakages, and only contains entries since September 23, 2011. 1864If you need to see UPDATING entries from before that date, you will need 1865to fetch an UPDATING file from an older FreeBSD release. 1866 1867Copyright information: 1868 1869Copyright 1998-2009 M. Warner Losh. All Rights Reserved. 1870 1871Redistribution, publication, translation and use, with or without 1872modification, in full or in part, in any form or format of this 1873document are permitted without further permission from the author. 1874 1875THIS DOCUMENT IS PROVIDED BY WARNER LOSH ``AS IS'' AND ANY EXPRESS OR 1876IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED 1877WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE 1878DISCLAIMED. IN NO EVENT SHALL WARNER LOSH BE LIABLE FOR ANY DIRECT, 1879INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES 1880(INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR 1881SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 1882HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, 1883STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING 1884IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 1885POSSIBILITY OF SUCH DAMAGE. 1886 1887Contact Warner Losh if you have any questions about your use of 1888this document. 1889 1890$FreeBSD: stable/11/UPDATING 363496 2020-07-24 20:54:07Z dim $ 1891