summaryrefslogtreecommitdiff
path: root/doc
diff options
context:
space:
mode:
authorJeremy Harris <jgh146exb@wizmail.org>2020-01-28 21:10:17 +0000
committerJeremy Harris <jgh146exb@wizmail.org>2020-01-28 21:19:07 +0000
commit4381d60bc96bed88d96e8cc6b534dd0dcd48163f (patch)
tree2caf67a2bf51c80bed410030e148d503ec65cc7c /doc
parent6440616152c46002c71a3a6413adeeb0fe435db0 (diff)
Taint: slow-mode checking only
Diffstat (limited to 'doc')
-rw-r--r--doc/doc-txt/ChangeLog10
1 files changed, 3 insertions, 7 deletions
diff --git a/doc/doc-txt/ChangeLog b/doc/doc-txt/ChangeLog
index 43b306d3b..1b38268b4 100644
--- a/doc/doc-txt/ChangeLog
+++ b/doc/doc-txt/ChangeLog
@@ -100,13 +100,9 @@ JH/21 Bug 2501: Fix init call in the heimdal authenticator. Previously it
buffer was in use at the time. Change to a compile-time increase in the
buffer size, when this authenticator is compiled into exim.
-JH/22 Taint checking: move to a hybrid approach for checking. Previously, one
- of two ways was used, depending on a build-time flag. The fast method
- relied on assumptions about the OS and libc malloc, which were known to
- not hold for the BSD-derived platforms, and discovered to not hold for
- 32-bit Linux either. In fact the glibc documentation describes cases
- where these assumptions do not hold. The new implementation tests for
- the situation arising and actively switches over from fast to safe mode.
+JH/22 Taint-checking: move to safe-mode taint checking on all platforms. The
+ previous fast-mode was untenable in the face of glibs using mmap to
+ support larger malloc requests.
PP/01 Update the openssl_options possible values through OpenSSL 1.1.1c.
New values supported, if defined on system where compiled: