This README describes why you need to apply this SRU, caveats, and other important information that you might need to consider before applying or installing Oracle Solaris 11.3.35.6.0. It also contains general information about Oracle Solaris 11 Support Repository Update (SRU) and instructions about how to manage your local repository.
Contents
Why Apply Oracle Solaris 11.3.35.6.0
Oracle Solaris 11.3.35.6.0 provides improvements and bug fixes that are applicable for all the Oracle Solaris 11 systems. Some of the noteworthy improvements in this SRU include:
-
Solaris Enterprise Health Check (EHC) has been added to Oracle Solaris (Bugs 27137902, 27624790). For more information on EHC, see How to Install and Run the Pre-Update Enterprise Health Check Tool.
-
Explorer 18.3 is now available (Bug 28298093)
-
Oracle VM Server for SPARC has been updated to version 3.5.0.3. For more information including What's New, Bug Fixes, and Known Issues, see Oracle VM Server for SPARC 3.5.0.3 Release Notes.
-
The Java 8, Java 7, and Java 6 packages have been updated. See Note 5 for the location and details on how to update Java. For more information and bugs fixed, see Java 8 Update 181 Release Notes, Java 7 Update 191 Release Notes, and Java 6 Update 201 Release Notes.
-
python has been updated to 3.4.8, and addresses a security issue (Bugs 26697283, 27454435, 22661864)
-
gnu-gettext has been updated to 0.19.8 (Bug 25286837)
-
bison has been updated to 3.0.4 (Bug 15623772)
-
libepoxy has been added to Oracle Solaris (Bug 21395353)
-
BIND has been updated to 9.10.6-P1, and addresses a security issue (Bugs 27392591, 27392558)
-
at-spi2-atk has been updated to 2.24.0 (Bug 25977274)
-
at-spi2-core has been updated to 2.24.0 (Bug 25977275)
-
gtk+3 has been updated to 3.18.0 (Bug 23245320)
-
Apache Tomcat has been updated to 8.5.32, and addresses a security issue (Bugs 28266925, 28255210)
-
kerberos 5 has been updated to 1.16.1, and addresses a security issue plus a bug fix (Bugs 28213220, 27874383, 26247818)
-
Wireshark has been updated to 2.6.2, and addresses a security issue (Bugs 28371577, 28371605)
-
Thunderbird has been updated to 52.9.1, and addresses a security issue (Bugs 28352074, 28352034)
-
libvorbis has been updated to 1.3.6, and addresses security issues (Bugs 27708581, 28109201, 28109212, 27708561)
-
Fixed the missing magick/static.h header in ImageMagick manifest (Bug 28102123)
-
MySQL has been updated to 5.7.23, and addresses security issues (Bugs 28418265, 28371525, 25997996)
-
Security fixes for the following components:
-
gdk-pixbuf (Bug 28086383)
-
libtiff (Bugs 27209214, 28083090, 28083703)
End-of-Feature (EOF) Notices
EOFs Planned for Future Releases of the Oracle Solaris 11.3 SRU
This section comprises of features or components that will be removed in a future Oracle Solaris 11.3 SRU release. They are:
EOFs for Oracle Solaris 11.3.35.6.0
This section lists features or components that are no longer available in Oracle Solaris 11.3.35.6.0. There are no features or components listed at this time.
EOFs Summary for Oracle Solaris 11.3 SRU
Summary of EOFs in Oracle Solaris 11.3 SRU:
-
Oracle Solaris 11.3.18
-
Oracle Solaris 11.3.20
-
Oracle Solaris 11.3.24
-
Oracle Solaris 11.3.26
-
Oracle Solaris 11.3.27
-
Oracle Solaris 11.3.32
-
Oracle Solaris 11.3.33
Before Installing Oracle Solaris 11.3.35.6.0
This section provides some information about special installation and runtime instructions that you need to consider before installing or running Oracle Solaris 11.3.35.6.0.
Note 1: Oracle Solaris 11.3 and Java 6
The release of Oracle Solaris 11.3 has obsoleted the use of Java 6 packages such that they are removed upon installation. By default, Java 8 will be the active version of Java on the system. It is strongly advised that systems do not run Java 6 but move to using a newer release of Java which helps in utilizing many modern features and increasing performance. However, if there is still a need to use Java 6, the following steps can be performed to install it:
Unlock the package:
# pkg change-facet version-lock.consolidation/ub_javavm-6/ub_javavm-6-incorporation=false
Update the incorporation package to the older version:
# pkg update consolidation/ub_javavm-6/ub_javavm-6-incorporation@1.6.0.115
Note: The version of the package at the end of the FMRI may change when new versions of Java 6 becomes available.
Freeze the incorporation package to prevent it from being removed on subsequent updates:
# pkg freeze ub_javavm-6-incorporation@1.6.0.115
Install the Java 6 runtime package:
# pkg install runtime/java/jre-6
If required, set the default version of Java to be Java 6:
# pkg set-mediator -V 1.6 java
These steps will let you use Java 6 as the default version of Java. However, it is highly recommended to install and use the later versions of Java.
Note 2: Support for NVIDIA Legacy Drivers in Oracle Solaris
The NVIDIA graphics driver is updated to version 346.35, which supports the recent family of NVIDIA GPUs. The NVIDIA legacy drivers are available in the repository as
driver/graphics/nvidiaR340 and
driver/graphics/nvidiaR304 packages. For information about the support for legacy GPUs, see
http://www.nvidia.com/object/IO_32667.html.
For GPUs that need the R340 legacy driver, you can install R340 by using the following command:
# pkg install --reject driver/graphics/nvidia driver/graphics/nvidiaR340
For GPUs that need the R304 legacy driver, you can install R304 by using the following command:
# pkg install --reject driver/graphics/nvidia driver/graphics/nvidiaR304
For more information, see the
/usr/share/doc/NVIDIA/README.txt file.
Note 3: Package system/management/ocm updates the Java environment to Java 8
If the system/management/ocm package is installed, it will update the installed Java environment to Java 8. If you need to use an older version of Java, you will need to set the mediator to that version. The following example shows the mediator set for Java 7:
# pkg set-mediator -V 1.7 java
Note 4: squid.conf may need updating after installing squid 3.5.5 and later
As of Oracle Solaris 11.2.13, the squid package has been updated to incorporate the later version (squid 3.5.5) which includes vulnerability fixes. The names of some helper modules have changed, which means that the configuration file,
squid.conf, may need to be updated to use these new names.
The following example shows the names of the modules that are enabled:
/usr/squid/sbin/squid -v
For more information, see
http://artfiles.org/squid-cache.org/pub/archive/3.2/squid-3.2.0.12-RELEASENOTES.html.
Note 5: Installing updated Java versions
The latest Java packages are available in the support repository at
https://pkg.oracle.com/solaris/support. They are also available as a separate download at
Java Patches for Solaris Packages (Doc ID 1397756.1). If newer versions are listed in this document, proceed with performing the following steps to update to the latest versions of Java.
To update Java 8 packages:
# pkg change-facet version-lock.consolidation/java-8/java-8-incorporation=false
# pkg update jre-8
To update Java 7 packages:
# pkg change-facet version-lock.consolidation/java-7/java-7-incorporation=false
# pkg update jre-7
See
Note 1 for installing Java 6.
Note 6: Updating to OpenSSH 7.1p1 (Oracle Solaris 11.3.5) or OpenSSH 7.2p2 (Oracle Solaris 11.3.9)
The update to Oracle Solaris 11.3.5 makes important changes to the default list of allowed cryptographic mechanisms for OpenSSH. Since the default implementation of Secure Shell in Oracle Solaris 11.3 is sunssh, most systems will not be affected by this change.
However, if pkg mediator ssh shows openssh in use, then security changes to the default allowed behavior could prevent ssh in and/or out of the machine from older operating environments until either remote or local changes are made. These remote or local changes need to be made to keys, and/or configuration files.
If pkg mediator ssh shows sunssh as the implementation, or shows No matching mediators found, then these OpenSSH changes will not impact the system. OpenSSH and the ssh mediator were introduced in Oracle Solaris 11.3.
OpenSSH provides some ciphers that SunSSH does not provide. These ciphers are less common. If you are using any of these ciphers from OpenSSH, then temporarily switch to SunSSH using the mediator mechanism. You can then adjust the legacy systems. For more information and a list of OpenSSH-only ciphers, see 'Unsafe Algorithms Removed' below.
To switch to sunssh, use the following command:
# pkg set-mediator -I sunssh ssh
Please make sure that you investigate, test, and make the necessary changes before moving back to OpenSSH.
If you are using OpenSSH and are installing this SRU, please check for the following security considerations:
-
ssh-dss Keys Disabled by Default
The ssh-dss and ssh-dss-cert-* host and user key types are inherently weak and are disabled by default at run time.
If the ssh-rsa and ssh-dss host keys are not already present, use the svc:/network/ssh:default to create both the keys. It is unusual for Oracle Solaris servers to have the ssh-dss host keys but not the ssh-rsa keys.
If you have been using ssh-dss keys for public key authentication, you should create new ssh-rsa keys and remove the existing ssh-dss keys from all authorized_keys files. For information about creating new keys, see the ssh-keygen(1) man page.
-
diffie-hellman-group1-sha1 Key Exchange Disabled by Default
The diffie-hellman-group1-sha1 key exchange is no longer considered secure, and is disabled on both the client and the server.
If systems do not have a matching kex algorithm between the server and the client, you will receive the no kex alg error.
If your servers support only the diffie-hellman-group1-sha1 key exchange, you should upgrade them to support diffie-hellman-group-exchange-sha256. You can also upgrade Oracle Solaris to a version which supports the diffie-hellman-group14-sha1 key exchange.
If upgrading the peer is not an option, users connecting to systems that do not support the diffie-hellman-group-exchange-sha256, the diffie-hellman-group14-sha1, or the diffie-hellman-group-exchange-sha1 key exchanges can explicitly enable the diffie-hellman-group1-sha1 as follows:
root@source# ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 user@somehost
The server administrator can allow logins from systems that do not support secure key exchange methods by explicitly enabling insecure key exchange methods. Add the following lines to the /etc/ssh/ssh_config file (or a user's .ssh/ssh_config file) and restart the SSH server:
# Keep this file compatible with both sunssh and Openssh
IgnoreUnknown IgnoreIfUnknown
IgnoreIfUnknown IgnoreUnknown, KexAlgorithms
# Enable legacy algorithms -- remove when no longer needed.
KexAlgorithms
diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group-exchange-sha256
-
SSH Protocol 1 Support Removed
In Oracle Solaris 11.3.5, SSH-1 support has been removed on both the server side and the client side. Network entities that support only SSH-1 are mostly old network routers. You can no longer connect to such devices by using OpenSSH. However, you can still use SunSSH to access systems that use SSH-1.
-
Unsafe Algorithms Removed
The default list of enabled ciphers and MACs is reduced for sshd in OpenSSH 7.1p1 to remove unsafe algorithms, and further reduced for clients in OpenSSH 7.2p2, but the total list remains the same. Any ciphers or MACs needed can be re-enabled using the ciphers and MACs options to configure the files. For more information, see the man ssh_config(4) and man sshd_config(4) man pages.
If the ciphers needed at the site are also available in sunssh, then reverting to sunssh is another workaround that can be used until peer systems can be upgraded to use stronger algorithms.
The following OpenSSH ciphers are not available in sunssh:
aes128-gcm@openssh.com
aes256-gcm@openssh.com
chacha20-poly1305@openssh.com
rijndael-cbc@lysator.liu.se (not used in OpenSSH 7.1p1 by default)
Ciphers available in OpenSSH 7.1p1 by default. The recommended ciphers to be used are:
The default Ciphers list for sshd:
chacha20-poly1305@openssh.com
aes128-ctr
aes192-ctr
aes256-ctr
aes128-gcm@openssh.com
aes256-gcm@openssh.com
The default Ciphers list for ssh is the same as sshd plus:
aes128-cbc
3des-cbc
aes192-cbc
aes256-cbc
MACs:
MACs available in OpenSSH 7.1p1 sshd (server) by default. The recommended MACs to be used are:
The default MACs list for sshd:
umac-64-etm@openssh.com
umac-128-etm@openssh.com
hmac-sha2-256-etm@openssh.com
hmac-sha2-512-etm@openssh.com
hmac-sha1-etm@openssh.com
umac-64@openssh.com
umac-128@openssh.com
hmac-sha2-256
hmac-sha2-512
hmac-sha1
Formerly allowed ssh client additions to the above list are disabled by default in OpenSSH 7.2p2.
The impact on interoperability is minimal due to the use of other popular algorithms that remain enabled by default.
In particular, this change does not affect interoperability with older Oracle Solaris releases. Even SunSSH on Solaris 9 has a choice of common ciphers (aes128-cbc, 3des-cbc) and a common MAC (hmac-sha1) with the OpenSSH 7.2p2 client in default configuration.
OpenSSH 7.2p2 also re-enables Ed25519 based cryptography in OpenSSH. The curve25519-sha256@libssh.org key exchange method and ssh-ed25519 key type are also newly available for use after upgrading to this SRU.
You can use the following commands with OpenSSH to list all supported ciphers and MACs:
root@source# ssh -Q cipher
root@source# ssh -Q mac
-
Default Value of
UseDNS is No.
If no UseDNS value is specified in the sshd_config file, the default value of UseDNS is No. The former default value used to provide no security benefit.
A UseDNS value of No means that you cannot use host names when configuring an ssh service.
You have two options:
-
You can explicitly specify
UseDNS yes in the sshd_config file.
-
You can use IP addresses instead of host names in the
sshd_config file as shown in the following examples.
In the Match block section of the sshd_config file, use an Address criterion instead of a Host criterion. For example, you can replace Match Host somehost.domain with Match Address 192.168.0.10.
In the sshd_config entries for AllowUsers, AllowGroups, DenyUsers, and DenyGroups, use an IP address instead of the host name. For example, you can replace AllowUsers jsmith@somehost.domain with AllowUsers jsmith@192.168.0.10.
In /etc/ssh/shosts.equiv or ~/.shosts entries, use an IP address instead of a host name. For example, you can replace somehost.domain with 192.168.0.10.
In the ~/.ssh/authorized_keys entry, use an IP address instead of a host name if specifying the from option. For more information, see the man sshd(1M) man page. For example, you can replace from="somehost.domain" ssh-rsa AAAAB3...Q== jsmith@work with from="192.168.0.10" ssh-rsa AAAAB3...Q== jsmith@work
-
TCP Wrappers such as
hosts.deny and hosts.allow are not supported for OpenSSH
The openssh implementation of Secure Shell no longer supports TCP wrappers. You will need to modify the sshd_config file or use a firewall to preserve a configuration that was previously enforced by TCP wrappers.
(Note: The openssh implementation of Secure Shell continues to use TCP connections. However, the TCP wrapper function, libwrap, is no longer supported.)
If you use TCP wrappers, you are using /etc/hosts.allow or /etc/hosts.deny to allow or deny logins. Instead, you can use the Match block in the sshd_config file to set up an equivalent configuration.
For example, to allow logins only from the 10.163.0.0/16 subnet, you might have set up TCP wrappers as follows:
root@jsmith-cz:~# cat /etc/hosts.allow
sshd : 10.163.
root@jsmith-cz:~# cat /etc/hosts.deny
ALL : ALL
In a Match block in the sshd_config file, the following entry sets an equivalent restriction:
Match Address *,!10.163.0.0/16
MaxAuthTries 0
Another option is to use a firewall for access control. Settings similar to these examples can be applied on a firewall. Access control in the firewall occurs earlier, before the network connection is established in the kernel.
Note 7: Oracle Solaris 11.3.5 and OpenSSL 1.0.1r upgrade
In OpenSSL 1.0.1r, OpenSSL disallows the use of DH key smaller than 1024-bit. If the server is set up to use a DH key smaller than 1024-bit key, the SSL/TLS connection will fail with error messages similar to:
| Thu Feb 11 09:32:14.2501 Starting ldap_cachemgr, logfile
| /var/ldap/cachemgr.log
| Thu Feb 11 09:32:14.6968 sig_ok_to_exit(): parent exiting...
| Thu Feb 11 09:32:14.8270 Error: Unable to refresh
| profile:XXX-tls:Session error no available conn.
You may also see an error message like:
| error:14082174:SSL routines:ssl3_check_cert_and_algorithm:dh key too small
To resolve the issue, the server must be configured to use a stronger DH parameter where 2048-bit is the recommendation. Follow these steps for configuring the server:
Generate a 2048-bit DH parameter:
% openssl dhparam -out dhparams.pem 2048
Configure the server to use the new DH parameter,
dhparams.pem. Configuring the DH parameter differs depending on the server.
For more information, see
https://weakdh.org/sysadmin.html.
Note 8: Need a switch to turn off Exafusion/verb in Oracle Solaris (Bug 22027298)
The changes introduced in Bug 22027298 disables the use of userland RDMA through the InfiniBand stack using the OpenFabrics User Verbs APIs by default. This is necessary in order to prevent the Oracle Real Application Cluster (RAC) environment from using these interfaces which are pending certain new functionality.
If you have existing applications using OpenFabrics User Verbs APIs and are not running these applications on a node in an Oracle RAC, it is possible and necessary to re-enable the OpenFabrics User Verbs APIs by adding the following line to the /etc/system file and rebooting Oracle Solaris.
set sol_uverbs:__user_verbs_rdmacm_disabled=0x0
Note 9: sendfile not returning EOPNOTSUPP error for unsupported socket types (Bug 22609739)
In previous releases, sendfile would return an EOPNOTSUPP error on a UDP socket. Due to this bug, customers will no longer get this error. However, the behavior for TCP socket remains unchanged.
Note 10: Updating to the latest timezone package
The latest timezone package is available in the support repository at
https://pkg.oracle.com/solaris/support. It is also available as a separate download at
Timezone Data File Package for Oracle Solaris 11 (Doc ID 2135137.1. If a newer version is listed in this document, proceed with performing the following steps to update to the latest timezone package.
Unlock the timezone package from the constraints on the system:
# pkg change-facet version-lock.system/data/timezone=false
# pkg update timezone
Note: When a package is unlocked, it may no longer be updated when the system is updated depending upon how the update is performed. If the update is performed using the
pkg update entire@<sru number> command, then the timezone package will not be updated. If the update is performed using the
pkg update command, then the timezone package will be updated.
Once the SRU that contains the package is released, you can optionally relock the package:
# pkg change-facet version-lock.system/data/timezone=none
Note 11: rfs4_lo_state_destroy needs Sun Cluster hook for lock removal (Bug 18431888)
Network Lock Manager is a service that provides file and record locking in an NFS environment. To support this functionality within the Clustered File System (PXFS), please install Oracle Solaris 11.3.8.
Note 12: Default umask setting for Apache Tomcat 8 (Bug 24347227)
Apache Tomcat 8 is now started by default with a more strict umask value of 0027. If this value is inconvenient, a different umask value can be set by the UMASK variable in setenv.sh. For more information, see the tomcat8(1M) man page.
Note 13: Moving from non-encrypted swap to encrypted swap
If there is already an unencrypted swap device configured using the swap -l command, but you plan to use encryption, then follow these steps for moving to the encrypted swap:
-
Delete the swap device
-
Edit
/etc/vfstab to add the "encrypted" option
-
Reboot the system
Note 14: Updating to Samba 4.4.x
Samba has updated from 3.6.x release to 4.4.x release. Backup your data before the Samba update in "ASCII mode" using the -c option in cpio, as the ID mapping of the Active Directory (AD) domain users can change.
Note 15: New Solaris 11.3 constraint package
A new convenience package has been released in Oracle Solaris 11.3.14. It can be installed using the following command:
# pkg install solaris-11.3
The purpose of this package is to prevent the update of the system to a later major version of Oracle Solaris, but to allow the system to continue to be updated on the Oracle Solaris 11.3 SRU stream of changes.
Note 16: Updated /etc/ssh/moduli in Oracle Solaris 11.3.15
This update replaces /etc/ssh/moduli if it has not been modified. The new moduli file has the advantage of being unique to this release of Oracle Solaris, and has longer keys than the older version.
Shorter keys are provided for backward compatibility, but the two shortest key sizes are commented-out.
It is recommended that the keys be tested before putting it into production, in case the production environment needs to communicate with very old machines that might need to be updated to accommodate longer keys. This issue was not seen in testing with the still-supported Oracle Solaris versions, but that cannot replicate all possible customer environments.
Size 1023 entries are commented-out and should not be used, but are provided in case of urgent and temporary legacy needs.
Size 1535 entries are commented-out as they will likely become obsolete soon, but are provided for legacy needs.
Note 17: CGI functionality with Perl 5.22
Install the library/perl-5/CGI package to get full CGI functionality with Perl 5.22:
# pkg install library/perl-5/CGI
Note 18: pflog - a log daemon for the Packet Filter (PF)
The network/firewall/firewall-pflog package delivers the pflogd daemon, which allows Packet Filter (PF) to log packets to the regular file /var/log/firewall/pflog/pflog0.pkt by default. The file can be processed by tshark/wireshark only. The PF logs packet, which matches a rule with the 'log' action. The pflogd process is managed by the svc:/network/firewall/pflog:default SMF service instance, which creates the temporal capture link at start up. The capture link transmits logged packets from the kernel to the pflogd process running in user space. For more information, see the pf.conf(5) and dladm(1M) man pages.
Note 19: "getent ethers" output should follow the format described in ethers(4) (Bug 22514343)
Oracle Solaris 11.3.17 fixes a bug in getent where "getent ethers" did not follow the format defined in ethers(4), as it previously followed the output format of "official-host-name ethernet-address". It now follows the format in ethers(4) which is "ethernet-address official-host-name".
Note 20: hotplug poweroff sometimes hit "ERROR: devices or resources are busy." (Bug 25752894)
An attempt to offline a hotplug port with dependent devices that are currently in use by the system might fail with the following error message:
# hotplug poweroff /pci@13c/pci@1/SYS/RCSA/PCIE11
ERROR: devices or resources are busy.
You are advised to wait two minutes for the active holds to be released before retrying the
hotplug offline command:
# hotplug offline
This process must be repeated until the
hotplug offline command succeeds.
Note 21: Oracle Solaris 11.3.20 and glib 2.46.0
With the upgrade of
glib to 2.46.0 in Oracle Solaris 11.3.20,
G_CONST_RETURN is now deprecated and should not be used. For more information, see
https://developer.gnome.org/glib/stable/glib-Standard-Macros.html#G-CONST-RETURN:CAPS.
Note 22: Perl 5.22 and Perl 5.12 in Oracle Solaris 11.3.21
Oracle Solaris 11.3.21 contains a security fix for Perl 5.22 and Perl 5.12 (CVE-2016-1238). This fix affects how Perl scripts behave when loading the modules through the 'use' or 'require' directive. Before this fix was introduced, Perl loaded the module from the current path if it was not found in one of the standard directories. The fix removes this feature. In other words, @INC previously contained '.' as the last item, and now it does not. Unfortunately, this feature has been hard-coded in Perl for a very long time. Hence, the chance of introducing a regression is high.
There are several possibilities on how to make the scripts work depending on the old behavior:
Some Perl scripts are known to require modification due to the new fix. These are testing and benchmark scripts, which are included in these affected packages that are not installed by default:
benchmark/filebench
database/mysql-51/tests
database/mysql-55/tests
database/mysql-56/tests
database/mysql-57/tests
The required modifications are:
-
/usr/benchmarks/filebench/bin/filebench
You can override functionality defined in the /usr/benchmarks/filebench/config/... directory by creating a file in the current directory. This will also require you to update line 1045 in /usr/benchmarks/filebench/bin/filebench from require "$function.func"; to require "./$function.func";.
-
/usr/mysql/5.[1567]/mysql-test/mysql-test-run.pl
Add "use lib '.';" before "use strict;" in mysql-test-run.pl.
Note 23: Change in FIPS 140-2 Cryptographic Provider for Kerberos Changes Non-Compliant Application Behavior in Oracle Solaris 11.3.21
Applications that are running in FIPS 140-2 mode in a Kerberos environment may behave differently in this release as the cryptographic provider has changed.
In earlier Oracle Solaris 11.3 SRU releases, the Cryptographic Framework was the provider for Kerberos, and the administrator was instructed to configure Kerberos to use only
des3-cbc-sha1. If a Kerberos application did not use this
enctype, the Cryptographic Framework issued a warning but did not abort the application.
In Oracle Solaris 11.3.21, the Kerberos implementation is MIT Kerberos, which uses the OpenSSL crypto provider. OpenSSL applications that run in FIPS 140-2 mode end up failing, and are aborted when a non-validated
enctype is called. The following message is displayed in case of failure:
aes_misc.c(83): OpenSSL internal error, assertion failed: Low level API call to cipher AES forbidden in FIPS mode!
For instructions about how to configure Kerberos to use FIPS 140-2 validated
enctypes only, see
Managing Kerberos and Other Authentication Services in Oracle Solaris 11.3.
For information about the differences between the two FIPS 140-2 crypto providers, see
About OpenSSL in FIPS 140-2 Mode in Oracle Solaris and
About the Cryptographic Framework in FIPS 140-2 Mode.
Note 24: rpool/VARSHARE/zones missing in Oracle Solaris 11.3.22
If zonepath is not specified when creating Oracle Solaris 11 zones, the zoneadm install command will fail. The workaround is to set the canmount option and mount rpool/VARSHARE/zones, which will mount ./system/zones. Use the following commands:
# zfs set canmount=on rpool/VARSHARE/zones
# zfs mount rpool/VARSHARE/zones
You can now install Oracle Solaris 11 non-global zones that do not specify a zonepath.
This issue only affects systems that are freshly installed with Oracle Solaris 11.3.22 or higher. Systems that are updated from earlier Oracle Solaris 11 SRUs to Oracle Solaris 11.3.22 are unaffected.
Note 25: Openstack Horizon and Oracle Solaris 11.3.23
Openstack Horizon fails to launch in Oracle Solaris 11.3.23. The workaround is to replace 'sys.path.append("/usr/lib/horizon/")' with 'sys.path.insert(0, "/usr/lib/horizon/")' in /usr/lib/python2.7/vendor-packages/openstack_dashboard/wsgi/django.wsgi, and then restart apache using the following command:
# svcadm restart svc:/network/http:apache24
Note 26: Netifaces 2.7 Python module seqfaults on calling gateways()
Netifaces 2.7 python module segfaults on Oracle Solaris 11.3.20 and above. Oracle Solaris 11.3.24 corrects this issue on x86 platforms, but it might still be seen on SPARC. IDR3329.2 has been created to address this issue for SPARC servers. Please see
Adding and Updating Software in Oracle Solaris 11.3 for complete information on adding IDRs to your system.
1. Become an adminstrator
For more information, see
How to Use Your Assigned Administrative Rights in Securing Users and Processes in Oracle Solaris 11.3.
2. Add the package archive as a publisher origin.
$ pkg set-publisher -g idr3329.2.p5p solaris
3. Install the IDR
$ pkg install --backup-be-name pre-idr3329 idr3329
Note 27: Updating to OpenSSH 7.4p1 or later
This release includes a change that may affect existing configurations:
ssh(1): Remove 3des-cbc from the client's default proposal. 64-bit block ciphers are not safe in 2016 and we don't want to wait until attacks like SWEET32 are extended to SSH. As 3des-cbc was the only mandatory cipher in the SSH RFCs, this may cause problems connecting to older devices using the default configuration, but it's highly likely that such devices already need explicit configuration for key exchange and hostkey algorithms already anyway.
Note 28: Kernel Zones may fail to boot when upgrading T7 machines to Oracle Solaris 11.3.23 or later if system firmware is not up to date (Bug 24297395)
If you are running Kernel Zones on T7 machines installed with Oracle Solaris 11.3.23 or later, make sure the underlying hosts' firmware is up to date. If this is not performed, the Kernel Zones will fail to boot with:
zone '<name of zone>': hypervisor needs updating for DAX support in this zone
Note 29: Installing Oracle Instant Client
Oracle Solaris 11.3.26 comes with an updated version of the Oracle Instant Client packages and some package name changes. The package name changes enable installation of multiple concurrent versions of the Oracle Instant Client, which matches functionality available if downloading the Oracle Instant Client from Oracle Technical Network.
The original package names:
database/oracle/instantclient
database/oracle/instantclient/jdbc-supplement
database/oracle/instantclient/odbc-supplement
developer/oracle/instantclient/sdk
have been renamed to include the "-121" suffix, which contain Oracle Instant Client v12.1:
database/oracle/instantclient-121
database/oracle/instantclient/jdbc-supplement-121
database/oracle/instantclient/odbc-supplement-121
developer/oracle/instantclient/sdk-121
The new version of the Oracle Instant Client, v12.2, is available with these packages:
database/oracle/instantclient-122
database/oracle/instantclient/jdbc-supplement-122
database/oracle/instantclient/odbc-supplement-122
developer/oracle/instantclient/sdk-122
The utilities
sqlplus,
adrci,
uidrvci, and
wrc are now delivered to
usr/bin as mediated links to either the 12.1 or 12.2 versions. You can check which version is active by running the
pkg mediator command:
# pkg mediator instantclient
MEDIATOR VER. SRC. VERSION IMPL. SRC. IMPLEMENTATION
instantclient local 12.1 local vendor
For example:
$ man sqlplus
will give you the correct man page based on the mediator setting.
Note 30: ICU 59.1 in Oracle Solaris 11.3.26
For the list of changes between ICU 56.1 and 59.1, see the
ICU web site. The library is now built with the GNU project C++ compiler so make sure
icu-config(1) or
pkg-config(1) is used to determine the correct build flags.
Note 31: Oracle Solaris OCM package is no longer updated
The Oracle Solaris OCM package is no longer updated in the Oracle Solaris image. If you want to use the latest version please download it from MOS. See
OCM Package for Oracle Solaris 11 and Oracle Solaris 10 for further instructions.
Note 32: FMA topology incorrect, calls out IOS RP as an FRU (Bug 27083597)
SPARC Firmware misreports the FRU path in FMA error messages. This impacts the following platforms:
-
T7/S7/M7/T8/M8 Systems with system firmware prior to SysFW 9.8.5
-
T5 Systems with system firmware prior to SysFW 9.6.2
-
T4 Systems with system firmware prior to SysFW 8.9.10
The following tables provide, by platform, the impacted device names, the reported FRU path and the correct FRU path. This will be corrected by a firmware update.
Platform T8-1
Device
Name Reported FRU Path Mapped FRU Path
------ ------------------------ ------------------------
NET0-3 /SYS/MB/IOH/IOS2/RP0 /SYS/MB
Slot 1 /SYS/MB/IOH/IOS2/RP1 /SYS/MB/PCIE1
Slot 2 /SYS/MB/IOH/IOS3/RP1 /SYS/MB/PCIE2
Slot 3 /SYS/MB/IOH/IOS3/RP0 /SYS/MB/PCIE3
Slot 4 /SYS/MB/IOH/IOS1/RP0 /SYS/MB/PCIE4
Slot 5 /SYS/MB/IOH/IOS1/RP1 /SYS/MB/PCIE5
Slot 6 /SYS/MB/IOH/IOS0/RP0 /SYS/MB/PCIE6
Platform T8-2
Device
Name Reported FRU Path Mapped FRU Path
------ ------------------------ -----------------------
NET0-3 /SYS/MB/IOH0/IOS1/RP0 /SYS/MB
PCIeSlot1 /SYS/MB/IOH0/IOS3/RP0 /SYS/MB/PCIE1
PCIeSlot2 /SYS/MB/IOH0/IOS2/RP0 /SYS/MB/PCIE2
PCIeSlot3 /SYS/MB/IOH0/IOS1/RP1 /SYS/MB/PCIE3
PCIeSlot4 /SYS/MB/IOH0/IOS0/RP1 /SYS/MB/PCIE4
PCIeSlot5 /SYS/MB/IOH1/IOS3/RP1 /SYS/MB/PCIE5
PCIeSlot6 /SYS/MB/IOH1/IOS0/RP0 /SYS/MB/PCIE6
PCIeSlot7 /SYS/MB/IOH1/IOS2/RP0 /SYS/MB/PCIE7
PCIeSlot8 /SYS/MB/IOH1/IOS1/RP0 /SYS/MB/PCIE8
Platform T8-4
Device
Name Reported FRU Path Mapped FRU Path
------ ------------------------ -----------------------
NET 0-3 /SYS/MB/IOH1/IOS4/RP0 /SYS/RIO
Slot 1 /SYS/MB/IOH0/IOS0/RP1 /SYS/RCSA/PCIE1
Slot 2 /SYS/MB/IOH0/IOS0/RP0 /SYS/RCSA/PCIE2
Slot 3 /SYS/MB/IOH0/IOS3/RP0 /SYS/RCSA/PCIE3
Slot 4 /SYS/MB/IOH0/IOS2/RP0 /SYS/RCSA/PCIE4
Slot 5 /SYS/MB/IOH1/IOS0/RP1 /SYS/RCSA/PCIE5
Slot 6 /SYS/MB/IOH1/IOS0/RP0 /SYS/RCSA/PCIE6
Slot 7 /SYS/MB/IOH1/IOS3/RP0 /SYS/RCSA/PCIE7
Slot 8 /SYS/MB/IOH1/IOS2/RP0 /SYS/RCSA/PCIE8
Slot 9 /SYS/MB/IOH2/IOS0/RP1 /SYS/RCSA/PCIE9
Slot 10 /SYS/MB/IOH2/IOS0/RP0 /SYS/RCSA/PCIE10
Slot 11 /SYS/MB/IOH2/IOS3/RP0 /SYS/RCSA/PCIE11
Slot 12 /SYS/MB/IOH3/IOS1/RP0 /SYS/RCSA/PCIE12
Slot 13 /SYS/MB/IOH3/IOS0/RP1 /SYS/RCSA/PCIE13
Slot 14 /SYS/MB/IOH3/IOS0/RP0 /SYS/RCSA/PCIE14
Slot 15 /SYS/MB/IOH3/IOS3/RP0 /SYS/RCSA/PCIE15
Slot 16 /SYS/MB/IOH3/IOS2/RP0 /SYS/RCSA/PCIE16
Platform M8-8
Device
Name Reported FRU Path Mapped FRU Path
--------- ------------------------ --------------
CMIOU0 /SYS/CMIOU0/IOH/IOS3/RP0 /SYS/CMIOU0/PCIE1
CMIOU0 /SYS/CMIOU0/IOH/IOS0/RP0 /SYS/CMIOU0/PCIE2
CMIOU0 /SYS/CMIOU0/IOH/IOS1/RP0 /SYS/CMIOU0/PCIE3
CMIOU1 /SYS/CMIOU1/IOH/IOS3/RP0 /SYS/CMIOU1/PCIE1
CMIOU1 /SYS/CMIOU1/IOH/IOS0/RP0 /SYS/CMIOU1/PCIE2
CMIOU1 /SYS/CMIOU1/IOH/IOS1/RP0 /SYS/CMIOU1/PCIE3
CMIOU2 /SYS/CMIOU2/IOH/IOS3/RP0 /SYS/CMIOU2/PCIE1
CMIOU2 /SYS/CMIOU2/IOH/IOS0/RP0 /SYS/CMIOU2/PCIE2
CMIOU2 /SYS/CMIOU2/IOH/IOS1/RP0 /SYS/CMIOU2/PCIE3
CMIOU3 /SYS/CMIOU3/IOH/IOS3/RP0 /SYS/CMIOU3/PCIE1
CMIOU3 /SYS/CMIOU3/IOH/IOS0/RP0 /SYS/CMIOU3/PCIE2
CMIOU3 /SYS/CMIOU3/IOH/IOS1/RP0 /SYS/CMIOU3/PCIE3
CMIOU4 /SYS/CMIOU4/IOH/IOS3/RP0 /SYS/CMIOU4/PCIE1
CMIOU4 /SYS/CMIOU4/IOH/IOS0/RP0 /SYS/CMIOU4/PCIE2
CMIOU4 /SYS/CMIOU4/IOH/IOS1/RP0 /SYS/CMIOU4/PCIE3
CMIOU5 /SYS/CMIOU5/IOH/IOS3/RP0 /SYS/CMIOU5/PCIE1
CMIOU5 /SYS/CMIOU5/IOH/IOS0/RP0 /SYS/CMIOU5/PCIE2
CMIOU5 /SYS/CMIOU5/IOH/IOS1/RP0 /SYS/CMIOU5/PCIE3
CMIOU6 /SYS/CMIOU6/IOH/IOS3/RP0 /SYS/CMIOU6/PCIE1
CMIOU6 /SYS/CMIOU6/IOH/IOS0/RP0 /SYS/CMIOU6/PCIE2
CMIOU6 /SYS/CMIOU6/IOH/IOS1/RP0 /SYS/CMIOU6/PCIE3
CMIOU7 /SYS/CMIOU7/IOH/IOS3/RP0 /SYS/CMIOU7/PCIE1
CMIOU7 /SYS/CMIOU7/IOH/IOS0/RP0 /SYS/CMIOU7/PCIE2
CMIOU7 /SYS/CMIOU7/IOH/IOS1/RP0 /SYS/CMIOU7/PCIE3
Platform T7-1
Device
Name Reported FRU Path Mapped FRU Path
---------- ------------------------ -----------------------
NET0-3 /SYS/MB/IOH/IOS2/RP0 /SYS/MB
PCIeSlot1 /SYS/MB/IOH/IOS4/RP0 /SYS/MB/PCIE1
PCIeSlot2 /SYS/MB/IOH/IOS3/RP1 /SYS/MB/PCIE2
PCIeSlot3 /SYS/MB/IOH/IOS3/RP0 /SYS/MB/PCIE3
PCIeSlot4 /SYS/MB/IOH/IOS1/RP0 /SYS/MB/PCIE4
PCIeSlot5 /SYS/MB/IOH/IOS1/RP1 /SYS/MB/PCIE5
PCIeSlot6 /SYS/MB/IOH/IOS0/RP0 /SYS/MB/PCIE6
Platform T7-2
Device
Name Reported FRU Path Mapped FRU Path
--------- ------------------------ -----------------------
NET0 /SYS/MB/IOH0/IOS1/RP0 /SYS/MB
NET1 /SYS/MB/IOH0/IOS1/RP0 /SYS/MB
NET2 /SYS/MB/IOH1/IOS3/RP0 /SYS/MB
NET3 /SYS/MB/IOH1/IOS3/RP0 /SYS/MB
PCIeSlot1 /SYS/MB/IOH0/IOS3/RP0 /SYS/MB/PCIE1
PCIeSlot2 /SYS/MB/IOH0/IOS2/RP0 /SYS/MB/PCIE2
PCIeSlot3 /SYS/MB/IOH0/IOS1/RP1 /SYS/MB/PCIE3
PCIeSlot4 /SYS/MB/IOH0/IOS0/RP1 /SYS/MB/PCIE4
PCIeSlot5 /SYS/MB/IOH1/IOS3/RP1 /SYS/MB/PCIE5
PCIeSlot6 /SYS/MB/IOH1/IOS0/RP1 /SYS/MB/PCIE6
PCIeSlot7 /SYS/MB/IOH1/IOS2/RP0 /SYS/MB/PCIE7
PCIeSlot8 /SYS/MB/IOH1/IOS1/RP0 /SYS/MB/PCIE7
Platform T7-4
Device
Name Reported FRU Path Mapped FRU Path
---------- ------------------------ -----------------------
NET 0 /SYS/MB/IOH1/IOS4/RP0 /SYS/MB
NET 1 /SYS/MB/IOH2/IOS1/RP0 /SYS/MB
Slot 1 /SYS/MB/IOH0/IOS0/RP1 /SYS/RCSA/PCIE1
Slot 2 /SYS/MB/IOH0/IOS0/RP0 /SYS/RCSA/PCIE2
Slot 3 /SYS/MB/IOH0/IOS3/RP0 /SYS/RCSA/PCIE3
Slot 4 /SYS/MB/IOH0/IOS2/RP0 /SYS/RCSA/PCIE4
Slot 5 /SYS/MB/IOH1/IOS0/RP1 /SYS/RCSA/PCIE5
Slot 6 /SYS/MB/IOH1/IOS0/RP0 /SYS/RCSA/PCIE6
Slot 7 /SYS/MB/IOH1/IOS3/RP0 /SYS/RCSA/PCIE7
Slot 8 /SYS/MB/IOH1/IOS2/RP0 /SYS/RCSA/PCIE8
Slot 9 /SYS/MB/IOH2/IOS0/RP1 /SYS/RCSA/PCIE9
Slot 10 /SYS/MB/IOH2/IOS0/RP0 /SYS/RCSA/PCIE10
Slot 11 /SYS/MB/IOH2/IOS3/RP0 /SYS/RCSA/PCIE11
Slot 12 /SYS/MB/IOH3/IOS1/RP0 /SYS/RCSA/PCIE12
Slot 13 /SYS/MB/IOH3/IOS0/RP1 /SYS/RCSA/PCIE13
Slot 14 /SYS/MB/IOH3/IOS0/RP0 /SYS/RCSA/PCIE14
Slot 15 /SYS/MB/IOH3/IOS3/RP0 /SYS/RCSA/PCIE15
Slot 16 /SYS/MB/IOH3/IOS2/RP0 /SYS/RCSA/PCIE16
Platform M7-8
Device
Name Reported FRU Path Mapped FRU Path
---------- ------------------------ -----------------------
CMIOU0 /SYS/CMIOU0/IOH/IOS3/RP0 /SYS/CMIOU0/PCIE1
CMIOU0 /SYS/CMIOU0/IOH/IOS0/RP0 /SYS/CMIOU0/PCIE2
CMIOU0 /SYS/CMIOU0/IOH/IOS1/RP0 /SYS/CMIOU0/PCIE3
CMIOU1 /SYS/CMIOU1/IOH/IOS3/RP0 /SYS/CMIOU1/PCIE1
CMIOU1 /SYS/CMIOU1/IOH/IOS0/RP0 /SYS/CMIOU1/PCIE2
CMIOU1 /SYS/CMIOU1/IOH/IOS1/RP0 /SYS/CMIOU1/PCIE3
CMIOU2 /SYS/CMIOU2/IOH/IOS3/RP0 /SYS/CMIOU2/PCIE1
CMIOU2 /SYS/CMIOU2/IOH/IOS0/RP0 /SYS/CMIOU2/PCIE2
CMIOU2 /SYS/CMIOU2/IOH/IOS1/RP0 /SYS/CMIOU2/PCIE3
CMIOU3 /SYS/CMIOU3/IOH/IOS3/RP0 /SYS/CMIOU3/PCIE1
CMIOU3 /SYS/CMIOU3/IOH/IOS0/RP0 /SYS/CMIOU3/PCIE2
CMIOU3 /SYS/CMIOU3/IOH/IOS1/RP0 /SYS/CMIOU3/PCIE3
CMIOU4 /SYS/CMIOU4/IOH/IOS3/RP0 /SYS/CMIOU4/PCIE1
CMIOU4 /SYS/CMIOU4/IOH/IOS0/RP0 /SYS/CMIOU4/PCIE2
CMIOU4 /SYS/CMIOU4/IOH/IOS1/RP0 /SYS/CMIOU4/PCIE3
CMIOU5 /SYS/CMIOU5/IOH/IOS3/RP0 /SYS/CMIOU5/PCIE1
CMIOU5 /SYS/CMIOU5/IOH/IOS0/RP0 /SYS/CMIOU5/PCIE2
CMIOU5 /SYS/CMIOU5/IOH/IOS1/RP0 /SYS/CMIOU5/PCIE3
CMIOU6 /SYS/CMIOU6/IOH/IOS3/RP0 /SYS/CMIOU6/PCIE1
CMIOU6 /SYS/CMIOU6/IOH/IOS0/RP0 /SYS/CMIOU6/PCIE2
CMIOU6 /SYS/CMIOU6/IOH/IOS1/RP0 /SYS/CMIOU6/PCIE3
CMIOU7 /SYS/CMIOU7/IOH/IOS3/RP0 /SYS/CMIOU7/PCIE1
CMIOU7 /SYS/CMIOU7/IOH/IOS0/RP0 /SYS/CMIOU7/PCIE2
CMIOU7 /SYS/CMIOU7/IOH/IOS1/RP0 /SYS/CMIOU7/PCIE3
Platform S7-2
Device
Name Reported FRU Path Mapped FRU Path
--------- ------------------------ -----------------------
NET0 /SYS/MB/CMP0/IOS0/RP0 /SYS/MB
NET1 /SYS/MB/CMP0/IOS0/RP0 /SYS/MB
NET2 /SYS/MB/CMP0/IOS0/RP0 /SYS/MB
NET3 /SYS/MB/CMP0/IOS0/RP0 /SYS/MB
PCIeSlot1 /SYS/MB/CMP1/IOS0/RP0 /SYS/MB/RISER1/PCIE1
PCIeSlot2 /SYS/MB/CMP1/IOS0/RP0 /SYS/MB/RISER2/PCIE2
PCIeSlot3 /SYS/MB/CMP0/IOS0/RP1 /SYS/MB/RISER3/PCIE3
PCIeSlot4 /SYS/MB/CMP1/IOS0/RP1 /SYS/MB/RISER3/PCIE4
Platform S7-2L
Device
Name Reported FRU Path Mapped FRU Path
--------- ------------------------ -----------------------
NET0 /SYS/MB/CMP0/IOS0/RP0 /SYS/MB
NET1 /SYS/MB/CMP0/IOS0/RP0 /SYS/MB
NET2 /SYS/MB/CMP0/IOS0/RP0 /SYS/MB
NET3 /SYS/MB/CMP0/IOS0/RP0 /SYS/MB
PCIeSlot1 /SYS/MB/CMP0/IOS0/RP0 /SYS/MB/PCIE1
PCIeSlot2 /SYS/MB/CMP1/IOS0/RP0 /SYS/MB/PCIE2
PCIeSlot3 /SYS/MB/CMP1/IOS0/RP0 /SYS/MB/PCIE3
PCIeSlot4 /SYS/MB/CMP0/IOS0/RP1 /SYS/MB/PCIE4
PCIeSlot5 /SYS/MB/CMP0/IOS0/RP1 /SYS/MB/PCIE5
PCIeSlot6 /SYS/MB/CMP1/IOS0/RP1 /SYS/MB/PCIE6
PCIeSlot7 /SYS/MB/CMP1/IOS0/RP1 /SYS/MB/PCIE7
Note 33: Unable to use input method in Oracle Solaris 11.3.29 (Bug 27631731)
After updating to Oracle Solaris 11.3.29, the iBus input-method Frame Work icon shows "No input windows", and the available input-method choices do not appear when the toggle key is pressed. The workaround is to run the following commands as root in a gnome-terminal window:
# /usr/bin/gtk-query-immodules-2.0 --update-cache
# /usr/bin/64/gtk-query-immodules-2.0 --update-cache
Log out then log back in again to see the list of input methods.
Note 34: New GNU binutils in Oracle Solaris 11.3.33 (Bug 27028053)
The new GNU binutils in Oracle Solaris 11.3 delivers new gas which expects 64-bit asm by default. It could cause problem with older gcc versions like the following:
Error: invalid instruction suffix for `push`
You have to explicitly specify
-m32 for compilation. However, the recommendation is to use gcc5 for compilation to avoid this problem.
Note 35: Remote RAD and auto-generated SSL certificate in Oracle Solaris 11.3.34
If you are using remote RAD with auto-generated SSL certificate that was generated prior to Oracle Solaris 11.3.34, it is highly recommended that the certificate be regenerated with a stronger key. Perform the following steps for the regeneration:
# disable svc:/system/rad:remote
# rm /etc/rad/cert.pem
# rm /etc/rad/key.pem
# enable svc:/system/rad:remote
Use the following command for the verification:
# openssl x509 -in /etc/rad/cert.pem -text
Bugs Fixed
|
Bug
|
Synopsis
|
|
15125151
|
truss displays bogus resolvepath arguments
|
|
15298510
|
svm does not detect if disks are in use by zfs
|
|
15623772
|
SUNBT6927713 upgrade bison to 3.0.4
|
|
16329119
|
Sanity check of a parent's lgrpinfo latency failing, latency values not returned
|
|
17575040
|
Scheduler doesn't handle processor groups spread across psrsets correctly
|
|
19644963
|
panic, assertion failed, fss.c, line: 2596
|
|
20804942
|
Memory leak in net-snmp TCP/UDP MIB handlers
|
|
21395353
|
Ship libepoxy in Solaris
|
|
21797747
|
mpathadm show lu is too slow on system with 1k lu
|
|
22661864
|
py3 curses get_wch() returns char in int, upstream returns it in str
|
|
23245320
|
Move gtk+-3 to Userland and update to 3.18.0
|
|
23251296
|
Problem with library/jansson
|
|
23262722
|
Problem with kernel/gld-mac-dls
|
|
23553029
|
ldc channel can become wedged under heavy loads
|
|
24347679
|
truss(1M) prints wrong key numbers for shmget()
|
|
24415538
|
libadimalloc's calloc() should be optimized when ADI is in use
|
|
24711806
|
meld bus error on SPARC in S12 build #106
|
|
24944083
|
Increase log(7D) LOG_HIWAT value
|
|
25286837
|
Update gnu-gettext to 0.19.8
|
|
25758471
|
ovmtcreate - Deprecate use of SHA-1 hashing algorithms
|
|
25860961
|
datalink-management service in maintainance with many vlans
|
|
25875832
|
Upgrade the version of MySQL 5.7 to 5.7.22 on Solaris
|
|
25977274
|
update at-spi2-atk to 2.24.0
|
|
25977275
|
update at-spi2-core to 2.24.0
|
|
25989244
|
atomic_add_64 consumes excessive CPU cycles in interrupt context
|
|
25997996
|
Problem with database/mysql
|
|
26079593
|
stmfadm delete-lu lu hangs in offlining state
|
|
26247818
|
krb5kdc solaris audit plugin leaks like a sieve
|
|
26356492
|
should generate list.isolated if vdev_fault succeeds even if no retire
|
|
26384934
|
topo_node_devchassis_set() should use fru fmri for chassis_sn/nm
|
|
26384977
|
pci_fru_location() can return wrong node
|
|
26386021
|
shouldn't create bay under pciexfn if parent has remote-label set
|
|
26386105
|
ok2rm led on disk in ak cluster can get spuriously unset.
|
|
26584378
|
ftp dumps core when using special japanese characters with mput
|
|
26697283
|
Upgrade Python 3.4 line to 3.4.8
|
|
26721313
|
Problem with gnome/accessibility
|
|
26986612
|
svc:/network/ldap/client, ldap_cachemgr executes 'refresh' about every minute.
|
|
26992501
|
Solaris 11.3 dlmgmtd memory leak
|
|
27137902
|
Solaris Enterprise Health Check (EHC) API integration
|
|
27164867
|
bnxt_bitmask_setall uses wrong size in memset
|
|
27209214
|
Problem with library/libtiff
|
|
27219561
|
KZ takes a long time to boot
|
|
27229346
|
rebooting root domain results in PICL snmpplugin: cannot initialize snmp service
|
|
27284691
|
ovmtlibrary must determine digest method from template
|
|
27361276
|
cryptoadm enable fips-140 should create a new BE
|
|
27362042
|
Environmental data still not always present in prtdiag
|
|
27362371
|
cryptoadm should avoid calling system() for pkg
|
|
27367298
|
Server panicked while adding interface to link aggregation.
|
|
27392558
|
Problem with service/dns-server
|
|
27392591
|
Update to BIND 9.10.6-P1
|
|
27402372
|
x86 kernel-boot vs. hotplug disagree on ARI enable/disable
|
|
27425857
|
PM function does not work on S11.3 with SRU27.4
|
|
27443722
|
PROC_SENSITIVE not decoded by truss
|
|
27454435
|
Problem with utility/python
|
|
27506986
|
bnxt needs workaround for EVB dropping long VF to VF packets with vlan tag
|
|
27582053
|
Error attempting to communicate with KeySecure key manager via Solaris KMIP cli
|
|
27614651
|
zombie thread in KZ picld
|
|
27624790
|
Solaris Enterprise Health Check - Upgrade (UEHC)
|
|
27662881
|
thread in pollsys keeping webserver connections from being established
|
|
27689660
|
setting the rx_ring_nsize ("rx_ring_size" in bnxt.conf) to 2K for bnxt fails
|
|
27707155
|
pm-rm domain service still negotiated with PM disabled
|
|
27708561
|
Problem with gnome/multimedia
|
|
27708581
|
Update libvorbis to 1.3.6
|
|
27725340
|
ls-spconfig changes from [current] to [next poweron] after primary reboot
|
|
27733237
|
Severe anon cache depot lock contention creating a 5.16TB segment stops forks
|
|
27754061
|
bnxt should be able to auto-detect 10g transceiver
|
|
27754136
|
bnxt VF IDs start from 0x80
|
|
27754210
|
DEBUG version of bnxt driver should print more information about HWRM error
|
|
27777476
|
27506986 causes bnxt nicdrv's tests/functional/test17/static_mtu_runme failure
|
|
27804203
|
ldap_client_file output order needs work
|
|
27808388
|
pargs should be able to find the initial argv and envp from a core dump
|
|
27816193
|
bnxt PF logs unhandled completions during plumb/unplumb loop of VF
|
|
27822824
|
svc:/system/rcap:default in non-global zone goes to maintenance if enabled
|
|
27836260
|
pargs should not need to grab the process in lite mode
|
|
27874383
|
Problem with utility/kerberos
|
|
27896118
|
ovmtcreate man page needs to change for -w option to show compressed disk images
|
|
27897761
|
Adding get/set option in the bnxtnvm tool
|
|
27935119
|
ovmtcreate output dir space req not taking compressed img size into account
|
|
27937740
|
NFSv4 mount can fail or be slow when server is an IPv4 address
|
|
27938622
|
bnxt NULL pointer dereference after tx_hcksum_enable=0 in bnxt.conf
|
|
27939240
|
typo in bnxt_hwrm.c
|
|
27952673
|
Guest Ldom bad unexpected error from hypervisor call at TL 1
|
|
27991597
|
aclcall() should print mountpoint in "NFS server not responding" message
|
|
28000506
|
Dangling pointer in rfs_rddirfree of nfs_srv.c:3020
|
|
28000533
|
Dangling pointer in nfs_exportfini of nfs_export.c:878
|
|
28022816
|
NVME devices can end up unassigned after FW upgrade and new config saved to SP
|
|
28039529
|
Problem with utility/procmail
|
|
28059901
|
IO hang mptsas_ioc_task_management command completion failed after disk pull
|
|
28072669
|
IO hang due to processing of cflag_reset or cflag_abort is incomplete
|
|
28083090
|
Problem with library/libtiff
|
|
28083703
|
Problem with library/libtiff
|
|
28083716
|
high log file sync wait with kcrfw_slave_adaptive_updatemode
|
|
28084032
|
Problem with library/libexif
|
|
28086383
|
Problem with gnome/gtk+
|
|
28095095
|
truss: unable to say if output value is in hex or decimal
|
|
28102123
|
ImageMagick manifest is missing magick/static.h header
|
|
28109122
|
LDAP hang caused by Mozilla PR_Recv() timeout set to wait forever
|
|
28109201
|
Problem with gnome/multimedia
|
|
28109212
|
Problem with gnome/multimedia
|
|
28110974
|
NFSv4 mirror mount un-mounting too aggressive
|
|
28177420
|
Stale nce_fp_flow_tagok can cause reachability issues for multicast destinations
|
|
28201576
|
Problem with library/libgcrypt
|
|
28213220
|
upgrade to krb5-1.16.1
|
|
28225210
|
Problem with utility/tomcat
|
|
28229166
|
Update device ids data files to current versions as of 2018.06
|
|
28239750
|
ldmd is coreing on ldmosbench in Solaris
|
|
28266925
|
Upgrade Apache Tomcat to version 8.5.32
|
|
28275751
|
"fwflash" could not read Part number for Product in "root domains".
|
|
28298093
|
Load Explorer 18.3 in Oracle Solaris 11 SRU
|
|
28300654
|
Fix to 22695074 turns every program into an FP-using program
|
|
28328655
|
JDK7u191 and JDK8u181 integration into S11.3 SRU 35.2 Train
|
|
28329157
|
JDK6u201 integration into S11.3 SRU 35.2 Train
|
|
28341331
|
Redeliver userland packages that depend on GTK2 after CBE change
|
|
28352034
|
Upgrade Thunderbird to version 52.9.1
|
|
28352074
|
Problem with tbird/mailer
|
|
28357427
|
sync nroff files from man-page gate for s11.3SRU35
|
|
28371525
|
Problem with database/mysql
|
|
28371577
|
Upgrade Wireshark to version 2.6.2
|
|
28371605
|
Problem with utility/wireshark
|
|
28388043
|
gmake download fails with empty COMPONENT_ARCHIVE_URL
|
|
28388101
|
Disable visual-panels compilation
|
|
28396652
|
s11.3_sru32 package c++-runtime has bad dependency
|
|
28398115
|
UEHC: incomplete list of obsolete CPUs in EHC_HDW_00001
|
|
28398241
|
UEHC: wrong package name for trusted-stripe check in EHC_IPS_00009
|
|
28398497
|
UEHC: wrong instructions for pam.d/gdm in EHC_RAS_00004
|
|
28398580
|
UEHC: wrong description for SMB printing in EHC_SVC_00004
|
|
28398641
|
UEHC: libreoffice check in EHC_IPS_V0016 is wrong
|
|
28418265
|
Upgrade the version of MySQL 5.7 to 5.7.23 on Solaris
|
|
28419403
|
metacity dumps core in 11.3 SRU 35 build 4.
|
|
28428202
|
UEHC: Mozilla LDAP server test in EHC_IPS_00006 is wrong
|
|
28428378
|
UEHC: wrong package name for CDE Calendar Manager check in EHC_IPS_00013
|
|
28428455
|
UEHC: test for old gcc versions in EHC_IPS_00014 is wrong
|
|
28428630
|
UEHC: EHC_NFS_00001 only checks for sec=dh mounts, not shares
|
|
28428696
|
UEHC: Many tests could use improved text for descriptions & fixes
|
For the list of bugs that are fixed in the previous SRUs, see:
For the complete Oracle Solaris 11.3 release history, see
Oracle Solaris 11.3 SRU Index.
Packages Updated
The following packages are updated in this SRU:
|
Package
|
Summary
|
|
SUNWj6dev
|
Renamed to developer/java/jdk-6
|
|
SUNWj6rt
|
Renamed to runtime/java/jre-6
|
|
benchmark/filebench
|
FileBench
|
|
codec/ogg-vorbis
|
Ogg bitstream and Vorbis audio codec libraries
|
|
consolidation/osnet/osnet-message-files
|
Localizable ON message files
|
|
database/mysql-57
|
MySQL 5.7 Database Management System
|
|
database/mysql-57/client
|
MySQL 5.7 Client Executables
|
|
database/mysql-57/embedded
|
MySQL 5.7 embedded library
|
|
database/mysql-57/library
|
MySQL 5.7 client libraries and plugins
|
|
database/mysql-57/tests
|
MySQL 5.7 testsuite
|
|
developer/base-developer-utilities
|
Software development utilities
|
|
developer/debug/mdb
|
Modular Debugger (MDB)
|
|
developer/java/jdk
|
Java Platform Standard Edition Development Kit (VERSION) java -version will display 1.7.0_191-b08
|
|
developer/java/jdk-6
|
Java(TM) Platform Standard Edition Development Kit (1.6.0_201-b07)
|
|
developer/java/jdk-7
|
Java Platform Standard Edition Development Kit (1.7.0_191-b08)
|
|
developer/java/jdk-8
|
Java Platform Standard Edition Development Kit (1.8.0_181-b12)
|
|
developer/opensolaris/ldoms
|
Dependencies required to build the LDoms Consolidation.
|
|
developer/parser/bison
|
bison - A YACC Replacement
|
|
diagnostic/wireshark
|
Graphical network protocol analyzer
|
|
diagnostic/wireshark/tshark
|
Command-line network protocol analyzer
|
|
diagnostic/wireshark/wireshark-common
|
Libraries and Tools used by Wireshark and TShark Network protocol analyzers
|
|
driver/audio/audio810
|
Intel(R) ICH, NVIDIA nForce, AMD-8111 audio driver
|
|
driver/audio/audiocmi
|
C-Media 8738 family audio driver
|
|
driver/audio/audioemu10k
|
Creative EMU10K audio driver
|
|
driver/audio/audiohd
|
Intel(R) High Definition audio driver
|
|
driver/audio/audioixp
|
ATI IXP audio driver
|
|
driver/audio/audiols
|
Creative Audigy LS audio driver
|
|
driver/audio/audiop16x
|
Creative P16X audio driver
|
|
driver/audio/audiosolo
|
ESS Solo-1 audio driver
|
|
driver/audio/audiovia823x
|
VIA VT823x audio driver
|
|
driver/crypto/dca
|
DCA crypto accelerator
|
|
driver/crypto/n2cp
|
UltraSPARC-T2/T3 crypto provider
|
|
driver/crypto/n2rng
|
SPARC HW Random Number Provider
|
|
driver/crypto/ncp
|
UltraSPARC-T1/T2/T3 Crypto Provider
|
|
driver/crypto/tpm
|
Trusted Platform Module driver
|
|
driver/fc/emlxs
|
Emulex LightPulse Fibre Channel (emlxs)
|
|
driver/fc/qlc
|
QLogic ISP Fibre Channel device storage and NIC driver
|
|
driver/fc/socal
|
Sun Enterprise Network Array socal device driver
|
|
driver/graphics/agpgart
|
AGP GART driver
|
|
driver/graphics/mga
|
MGA Graphics for SPARC ILOM device driver
|
|
driver/graphics/usbvc
|
USB video class driver
|
|
driver/ieee-1394/dcam1394
|
IEEE 1394 video conferencing class driver
|
|
driver/infiniband/connectx
|
Mellanox ConnectX Family InfiniBand HCA and 10GbE NIC Drivers
|
|
driver/infiniband/sif
|
Oracle SIF Infiniband HCA driver
|
|
driver/management/ipmi
|
OpenIPMI compliant Baseboard Management Controller
|
|
driver/network/ethernet/bge
|
Broadcom 57xx 1GbE NIC Driver
|
|
driver/network/ethernet/bnx
|
QLogic 570x/571x Gigabit Ethernet Driver
|
|
driver/network/ethernet/bnxe
|
QLogic 57xxx 10/20GbE NIC Driver
|
|
driver/network/ethernet/bnxt
|
Oracle Dual Port 10/25Gb NIC Driver
|
|
driver/network/ethernet/chxge
|
Chelsio N110 10GbE NIC Driver
|
|
driver/network/ethernet/cxge
|
Chelsio Terminator 3 10GbE NIC Driver
|
|
driver/network/ethernet/e1000g
|
Intel(R) PRO/1000 NIC Driver
|
|
driver/network/ethernet/hme
|
SunSwift Adapter Drivers (fas, hme)
|
|
driver/network/ethernet/hxge
|
Sun Blade 6000 10 GbE NIC Driver
|
|
driver/network/ethernet/i40e
|
Oracle Quad 10GbE NIC Driver
|
|
driver/network/ethernet/igb
|
Intel(R) 82575/82576 1GbE NIC Driver
|
|
driver/network/ethernet/iprb
|
Intel Pro/100 family NIC driver
|
|
driver/network/ethernet/ixgbe
|
Intel(R) 82598 10GbE NIC Driver
|
|
driver/network/ethernet/myri10ge
|
Myricom 10GbE NIC Driver
|
|
driver/network/ethernet/nge
|
NVIDIA Gigabit NIC driver
|
|
driver/network/ethernet/ntxn
|
NetXen 10/1 GbE NIC Driver
|
|
driver/network/ethernet/nxge
|
Sun NIU Gigabit NIC driver
|
|
driver/network/ethernet/oce
|
Emulex OneConnect 10GbE Network Driver
|
|
driver/network/ethernet/qlcnic
|
QLogic P3+ 10GbE NIC Driver
|
|
driver/network/ethernet/rge
|
Realtek 8169 Ethernet Driver
|
|
driver/network/ethernet/sfe
|
SiS SiS900 NIC Driver
|
|
driver/network/ethernet/sxge
|
Sun Blade 6000 40/10 GbE NIC Driver
|
|
driver/network/ethernet/vr
|
VIA Rhine NIC driver
|
|
driver/network/ethernet/vxge
|
Neterion X3100 10GbE NIC Driver
|
|
driver/network/ethernet/xge
|
Neterion Xframe 10GbE NIC Driver
|
|
driver/network/ethernet/yge
|
Marvell Yukon-2 Gigabit NIC Driver
|
|
driver/network/wlan/arn
|
Atheros AR928X Wireless NIC driver
|
|
driver/network/wlan/ipw
|
Intel(R) PRO/Wireless 2100B Wireless NIC Driver
|
|
driver/network/wlan/iwh
|
Intel(R) WiFi Link 5100/5300 Wireless NIC Driver
|
|
driver/network/wlan/iwk
|
Intel(R) WiFi Link 4965AGN Wireless NIC Driver
|
|
driver/network/wlan/iwp
|
Intel(R) WiFi Link 1000/2000/6000/7000 series Wireless NIC driver
|
|
driver/network/wlan/pcan
|
Cisco Aironet Wireless NIC Driver
|
|
driver/network/wlan/pcwl
|
Lucent and PRISM-II Wireless NIC driver
|
|
driver/network/wlan/rwd
|
Ralink RT2561/RT2561S/RT2661 Wireless NIC Driver
|
|
driver/network/wlan/rwn
|
Ralink RT2700/2800 Wireless NIC Driver
|
|
driver/network/wlan/wpi
|
Intel(R) PRO/Wireless 3945ABG driver
|
|
driver/network/wlan/zyd
|
ZyDAS ZD1211/B USB wireless NIC driver
|
|
driver/pcmcia
|
PCMCIA Card Services
|
|
driver/serial/pcser
|
PCMCIA serial card driver
|
|
driver/storage/aac
|
Adaptec AdvanceRaid SCSI HBA driver
|
|
driver/storage/adpu320
|
Adaptec Ultra320 driver
|
|
driver/storage/ahci
|
Advanced Host Controller Interface (AHCI) SATA HBA driver
|
|
driver/storage/ata
|
ISA bus device driver
|
|
driver/storage/bcm_sata
|
Broadcom HT1000 SATA driver
|
|
driver/storage/cmdk
|
Common interface to ATA disk devices
|
|
driver/storage/cpqary3
|
HP Smart Array HBA driver
|
|
driver/storage/ifp
|
Sun Fibre Channel Arbitrated Loop Device Driver
|
|
driver/storage/imraid_sas
|
LSI MegaRAID FALCON SAS 2.0 HBA driver
|
|
driver/storage/lmrc
|
LSI MegaRAID SAS 3.0 3108 HBA driver
|
|
driver/storage/lsc
|
LSI MPT SAS 3.0 HBA driver
|
|
driver/storage/marvell88sx
|
Marvell 88sx SATA driver
|
|
driver/storage/mega_sas
|
LSI MegaRAID SAS HBA driver
|
|
driver/storage/mpt
|
LSI 53C1030/SAS1064/SAS1068/Dell SAS6i/R HBA driver
|
|
driver/storage/mpt_sas
|
LSI MPT SAS 2.0 HBA driver
|
|
driver/storage/mr_sas
|
LSI MegaRAID SAS 2.0 HBA driver
|
|
driver/storage/nv_sata
|
NVIDIA CK804 Pro / MCP55 Pro SATA driver
|
|
driver/storage/nvme
|
NVMExpress 1.0e driver
|
|
driver/storage/pcata
|
PCMCIA ATA card driver
|
|
driver/storage/pmcs
|
PMC-Sierra SAS 2.0 HBA driver
|
|
driver/storage/sbp2
|
Serial Bus Protocol 2 module
|
|
driver/storage/scsa1394
|
IEEE 1394 mass storage driver
|
|
driver/storage/scu
|
Intel SCU SAS/SATA HBA driver
|
|
driver/storage/sdcard
|
SD/MMC drivers
|
|
driver/storage/sf
|
Sun Enterprise Network Array sf device driver
|
|
driver/storage/si3124
|
Silicon Image 3124 SATA driver
|
|
driver/storage/ssd
|
SPARCstorage Array drivers
|
|
driver/storage/sv
|
Sun StorageTek Availability Suite Storage Volume driver
|
|
driver/x11/xsvc
|
Sun Xserver pseudo driver
|
|
driver/xvm/pv
|
xVM Paravirtualized Drivers
|
|
editor/gnu-emacs
|
GNU emacs core
|
|
editor/gnu-emacs/gnu-emacs-gtk
|
GNU emacs with X11 support (GTK toolkit)
|
|
editor/gnu-emacs/gnu-emacs-lisp
|
GNU emacs LISP (.el) files
|
|
editor/gnu-emacs/gnu-emacs-no-x11
|
GNU emacs without X Window System support
|
|
editor/gnu-emacs/gnu-emacs-x11
|
GNU emacs with X11 support (Xaw toolkit)
|
|
editor/gvim
|
Vi IMproved (GUI)
|
|
editor/vim
|
Vi IMproved
|
|
editor/vim/vim-core
|
Vi IMproved (core executables)
|
|
firmware/system/fallback-boot
|
Fallback Boot image
|
|
gnome/window-manager/metacity
|
GNOME window manager
|
|
image/gnuplot
|
gnuplot - plotting utility
|
|
image/graphviz
|
Graph visualization software
|
|
image/graphviz/graphviz-java
|
Java bindings for Graphviz
|
|
image/graphviz/graphviz-lua
|
Lua bindings for Graphviz
|
|
image/graphviz/graphviz-ocaml
|
OCaml bindings for Graphviz
|
|
image/graphviz/graphviz-perl-512
|
Perl 5.12 bindings for Graphviz
|
|
image/graphviz/graphviz-php
|
PHP bindings for Graphviz
|
|
image/graphviz/graphviz-python-27
|
Python 2.7 bindings for Graphviz
|
|
image/graphviz/graphviz-ruby
|
Ruby bindings for Graphviz
|
|
image/graphviz/graphviz-sharp
|
C# bindings for Graphviz
|
|
image/graphviz/graphviz-tcl
|
Tcl bindings for Graphviz
|
|
image/imagemagick
|
ImageMagick - Image Manipulation Utilities and Libraries
|
|
image/library/libexif
|
EXIF tag parsing library for digital cameras
|
|
image/library/libtiff
|
libtiff - library for reading and writing TIFF
|
|
library/desktop/at-spi2-atk
|
The Assistive Technology Service Provider Interface (AT-SPI) Accessibility Toolkit
|
|
library/desktop/at-spi2-core
|
The Assistive Technology Service Provider Interface (AT-SPI) Core
|
|
library/desktop/gdk-pixbuf
|
GdkPixbuf library for image loading and manipulation
|
|
library/desktop/gtk3
|
GTK+, or the GIMP Toolkit, is a multi-platform toolkit for creating graphical user interfaces
|
|
library/desktop/gtk3/gtk-backend-cups
|
GTK+ 3.x - GIMP toolkit libraries - CUPS Print Backend
|
|
library/jansson
|
Jansson - C library for working with JSON data
|
|
library/java/java-demo
|
Java Sample and Demonstration Applications (VERSION) java -version will display 1.7.0_191-b08
|
|
library/java/java-demo-6
|
Java(TM) Sample and Demonstration Applications (1.6.0_201-b07)
|
|
library/java/java-demo-7
|
Java Sample and Demonstration Applications (1.7.0_191-b08)
|
|
library/java/java-demo-8
|
Java Sample and Demonstration Applications (1.8.0_181-b12)
|
|
library/liblouis
|
Support for contracted braille
|
|
library/python/net-snmp-27
|
The Net-SNMP - Python 2.7 bindings
|
|
library/python/tkinter-34
|
Python 3.4 bindings to tcl/tk
|
|
mail/procmail
|
Mail processing program
|
|
mail/thunderbird
|
Mozilla Thunderbird Email/Newsgroup Client
|
|
mail/thunderbird/plugin/thunderbird-lightning
|
Mozilla Thunderbird Email/Newsgroup Client - Calendar
|
|
network/dns/bind
|
BIND DNS tools
|
|
network/firewall
|
Solaris Firewall Driver
|
|
network/ftp
|
FTP client command
|
|
network/ipfilter
|
Solaris IP Filter
|
|
runtime/java
|
Java(TM) Platform Standard Edition Runtime Environment (VERSION) java -version will display 1.6.0_201-b07
|
|
runtime/java/jre
|
Java Platform Standard Edition Runtime Environment (VERSION) java -version will display 1.7.0_191-b08
|
|
runtime/java/jre-6
|
Java(TM) Platform Standard Edition Runtime Environment (1.6.0_201-b07)
|
|
runtime/java/jre-7
|
Java Platform Standard Edition Runtime Environment (1.7.0_191-b08)
|
|
runtime/java/jre-8
|
Java Platform Standard Edition Runtime Environment (1.8.0_181-b12)
|
|
runtime/python-34
|
The Python interpreter, libraries and utilities
|
|
security/compliance
|
Compliance Command and Framework
|
|
security/kerberos-5
|
Kerberos V5 Support
|
|
security/kerberos-5/kdc
|
Kerberos V5 Key Distribution Center (KDC)
|
|
service/file-system/nfs
|
NFS server
|
|
service/file-system/smb
|
SMB/CIFS server libraries and commands
|
|
service/network/dns/bind
|
BIND DNS name server and configuration tools.
|
|
storage/avs/avs-cache-management
|
Sun StorageTek Availability Suite cache management
|
|
storage/avs/avs-point-in-time-copy
|
Sun StorageTek Availability Suite Point-In-Time Copy
|
|
storage/svm
|
Solaris Volume Manager (SVM)
|
|
support/critical-patch-update/solaris-11-cpu
|
Oracle Solaris 11.3.35.6.0 Critical Patch Update 2018.8-1
|
|
support/explorer
|
Oracle RDA/Explorer Data Collector
|
|
system/compliance/benchmark/update-check
|
Oracle Solaris Update Compliance
|
|
system/core-os
|
Core Solaris
|
|
system/data/hardware-registry
|
Hardware data files
|
|
system/device-administration
|
Kernel driver administration
|
|
system/dtrace
|
DTrace Clients
|
|
system/electronic-prognostics
|
Electronic Prognostics
|
|
system/embedded-fcode-interpreter
|
Embedded FCode Interpreter Drivers
|
|
system/fault-management
|
Fault Management Architecture (FMA)
|
|
system/file-system/nfs
|
NFS client file system
|
|
system/file-system/smb
|
SMB/CIFS client file system
|
|
system/file-system/udfs
|
UDFS file system
|
|
system/file-system/ufs
|
UFS file system
|
|
system/file-system/zfs
|
ZFS file system
|
|
system/fjcmi
|
Coherent Memory Interface (CMI) support for Fujitsu GCSM
|
|
system/header
|
Core C/C++ header files
|
|
system/io/audio
|
Core audio device drivers and configuration utility
|
|
system/io/fc/fc-port
|
Fibre Channel transport layer and port driver
|
|
system/io/fc/fc-san-management
|
Fibre Channel SAN Management driver
|
|
system/io/fc/fc-scsi
|
Fibre Channel Protocol Driver
|
|
system/io/fc/ip-over-fc
|
IP/ARP over Fibre Channel Driver
|
|
system/io/ieee-1394
|
IEEE 1394 framework and OpenHCI driver
|
|
system/io/infiniband
|
Sun InfiniBand Framework
|
|
system/io/infiniband/ethernet-over-ib
|
Ethernet over InfiniBand (EoIB) Driver
|
|
system/io/infiniband/ib-device-mgt-agent
|
InfiniBand Device Manager Agent
|
|
system/io/infiniband/ib-sockets-direct
|
Sun InfiniBand layered Sockets Direct Protocol
|
|
system/io/infiniband/ip-over-ib
|
IPoIB Driver
|
|
system/io/infiniband/open-fabrics
|
Open Fabrics kernel components
|
|
system/io/infiniband/ovn-virtual-io
|
Oracle OVN virtual io service
|
|
system/io/infiniband/reliable-datagram-sockets
|
Reliable Datagram Sockets
|
|
system/io/infiniband/reliable-datagram-sockets-v3
|
Reliable Datagram Sockets (RDSv3)
|
|
system/io/infiniband/rpc-over-rdma
|
InfiniBand RPC over RDMA Driver
|
|
system/io/infiniband/udapl
|
UDAPL library and commands
|
|
system/io/test-drivers
|
I/O test utilities and drivers
|
|
system/io/usb
|
Solaris USB Architecture (USBA) and USB Device Drivers
|
|
system/kernel
|
Core Kernel
|
|
system/kernel/cpu-counters
|
Kernel support for CPU Performance Counters
|
|
system/kernel/cpu/sun4v
|
UltraSPARC sun4v core kernel software
|
|
system/kernel/crypto
|
Solaris Kernel Cryptographic Framework
|
|
system/kernel/dynamic-reconfiguration/i86pc
|
Dynamic Reconfiguration Modules for i86pc
|
|
system/kernel/i86pc/fipe
|
Intel 5000/7300 memory power management driver
|
|
system/kernel/i86pc/ioat
|
Intel I/O Acceleration Technology (I/OAT) support
|
|
system/kernel/io-performance-counters
|
Kernel support for IO chip performance counters
|
|
system/kernel/platform
|
Core Solaris Kernel Architecture
|
|
system/kernel/secure-rpc
|
Kernel GSS-API services for ONC RPC (RPCSEC_GSS)
|
|
system/kernel/security/gss
|
kernel GSSAPI V2
|
|
system/kernel/suspend-resume
|
System suspend and resume support
|
|
system/ldoms
|
Solaris Logical Domains configuration and administration
|
|
system/ldoms/ldomsmanager
|
Logical Domains Manager
|
|
system/ldoms/mib
|
Oracle VM Server for SPARC MIB
|
|
system/ldoms/ovmtutils
|
Oracle VM Server for SPARC Template utilities
|
|
system/library
|
Core system libraries
|
|
system/library/bison-runtime
|
bison - A YACC Replacement (Runtime Libraries)
|
|
system/library/c++-runtime
|
Sun Workshop Compilers Bundled libC
|
|
system/library/platform
|
Core Architecture, (Kvm)
|
|
system/library/security/kmip
|
Core Solaris, (Shared Libs)
|
|
system/library/security/libgcrypt
|
libgcrypt - cryptographic library
|
|
system/library/storage/libdiskmgt
|
Disk management library
|
|
system/library/storage/snia-mpapi
|
SNIA multipath management API common library
|
|
system/library/storage/suri
|
Storage URI support
|
|
system/linker
|
Core linking support
|
|
system/management/snmp/net-snmp
|
Net-SNMP Agent files and libraries
|
|
system/management/snmp/net-snmp/addons
|
Net-SNMP addon libraries
|
|
system/management/snmp/net-snmp/documentation
|
Net-SNMP Agent manpages and html documentation files
|
|
system/network
|
Core Network Infrastructure
|
|
system/network/bpf
|
Berkeley Packet Filter
|
|
system/network/ipqos
|
IP Quality of Service (IP QoS)
|
|
system/network/llc2
|
LLC2 Driver and Utilities
|
|
system/picl
|
Platform Information and Control Library (PICL) framework
|
|
system/resource-mgmt/resource-caps
|
Solaris Resource Capping Daemon
|
|
system/resource-mgmt/resource-pools
|
Resource pools
|
|
system/storage/fcoe/fcoe-initiator
|
FCoE initiator driver
|
|
system/storage/iscsi/iscsi-initiator
|
Sun iSCSI management utilities
|
|
system/storage/iscsi/iscsi-iser
|
Sun iSCSI data mover
|
|
system/storage/iscsi/iscsi-target
|
Sun iSCSI COMSTAR port provider
|
|
system/storage/multipath-utilities
|
Solaris Multipathing CLI
|
|
system/storage/scsi-rdma/scsi-rdma-target
|
Sun SRP COMSTAR port provider
|
|
system/storage/scsi-target-mode-framework
|
Sun COmmon Multiprotocol SCSI Target
|
|
system/zones
|
Solaris Zones configuration and administration
|
|
system/zones/brand/brand-solaris-kz
|
Solaris Kernel Zones (solaris-kz branded zones)
|
|
system/zones/brand/brand-solaris10
|
Solaris 10 Zones (solaris10 branded zones)
|
|
text/gnu-gettext
|
GNU gettext
|
|
web/browser/w3m
|
A text-based web browser
|
|
web/java-servlet/tomcat-8
|
Tomcat Servlet/JSP Container
|
|
web/java-servlet/tomcat-8/tomcat-admin
|
Tomcat Servlet/JSP Container - admin applications
|
|
web/java-servlet/tomcat-8/tomcat-examples
|
Tomcat Servlet/JSP Container - example applications
|
|
x11/library/libepoxy
|
library for handling OpenGL function pointer management
|
Superseded IDRs
-
1924.1
-
1925.1
-
1939.1
-
1975.1
-
1976.1
-
2312.1
-
3155.1
-
3289.1
-
3400.1
-
3403.1
-
3404.1
-
3438.1
-
3451.1
-
3470.1
-
3518.1
-
3541.2
-
3544.3
-
3547.2
-
3559.1
-
3566.2
-
3572.1
-
3573.1
-
3579.1
-
3580.5
-
3581.1
-
3615.1
-
3620.1
-
3625.1
-
3627.1
-
3629.4
-
3630.1
-
3660.1
-
3663.1
-
3664.1
-
3667.1
-
3688.1
-
3700.1
-
3712.1
About Oracle Solaris 11 Support Repository Updates
Oracle Solaris 11 uses the Image Packaging System (IPS) repository to update all packages that are available in your system. Customers with a support contract have access to the support repository to periodically update their Oracle Solaris 11 systems. Updates from the Oracle Solaris 11 support repository are available as support repository updates (SRUs) and each SRU provides a comprehensive set of important bug fixes and enhancements. Oracle Solaris updates and SRUs together provide a high quality, long-term support train for all Oracle Solaris 11 customers.
The update path for Oracle Solaris 11 11/11 users is to update to Oracle Solaris 11.3 and apply subsequent SRUs. For the complete list of Oracle Solaris 11.3 SRUs and downloads, see
Oracle Solaris 11.3 SRU Index.
Some important points to consider before applying or installing SRUs:
-
SRUs can be installed on systems covered by an appropriate Oracle support contract.
-
SRUs are updates to Oracle Solaris, but are not complete images. They provide bug fixes and incremental changes that are relative to the preceding release, for example Oracle Solaris 11.3.
-
The SRU repository must include the base packages for the Oracle Solaris 11 Update that they apply to.
-
If a subset of the SRUs are added to a repository, only those SRUs can be installed provided that the corresponding Oracle Solaris 11 Update base packages are included in the repository.
-
If the base packages for the relevant Oracle Solaris 11 Update are not included in the repository containing the SRUs, failures will occur during various packaging operations.
-
SRUs are released and available for download on a monthly basis.
-
The release date of every third SRU coincides with Oracle's quarterly Critical Patch Update (CPU). The CPU Documentation references security vulnerabilities fixed in each SRU. This Critical Patch Update Advisory lists all relevant Oracle products.
To see the latest CPU, click the Critical Patch Update listed in the table. To see the security vulnerabilities that are fixed in recent Oracle Solaris SRUs, scroll down in the CPU document and click the "Oracle and Sun Systems Products Suite" link. This document also has a reference section to historical information for older Oracle Solaris SRUs.
-
SRUs must be applied during proactive maintenance to prevent issues, or when asked by Oracle Support for reactive break/fix maintenance situations. Customers should schedule such maintenance windows at least in line with the Oracle Critical Patch Update cycle, or more frequently as required by the industry and/or company compliance requirements. Note also that at times Oracle may release security vulnerability fixes outside of the normal Critical Patch Update cycle.
-
If a system has an Interim Diagnostic Relief (IDR) installed, check if the issues addressed by the IDR are fixed in the SRU that you plan to install. If the issues are not fixed, you need to request a new IDR for that SRU several weeks in advance of the planned maintenance window.
-
The SRU zip files on MOS provide an alternative download option to synchronize network based repository.
For latest support products news, and SRU availability email notifications, use the
My Oracle Support Hot Topics E-Mail feature.
For a complete list of Oracle Solaris 11.3 SRUs and downloads, see
Oracle Solaris 11.3 SRU Index.
For instructions about applying SRUs to a system and managing a package repository, see
Managing The Repository.
Determining the Oracle Solaris Version Installed on Your System
To check the Oracle Solaris version installed on your system, use the pkg list entire command.
# pkg list entire
NAME (PUBLISHER) VERSION
entire 0.5.11-0.175.3.1.0.5.0
Oracle Solaris SRU versions follow a naming convention similar to other Oracle applications such as MOS and BugDB. They follow the 5-digit
Release.Update.SRU.Build.Respin format. In the example,
0.5.11-0.175.3.1.0.5.0 indicates Oracle Solaris 11.3, SRU version 1, build 5, and no respin.
For more information, see the
Oracle Solaris 11 package branch version scheme.
Managing the Repository
Some important points to consider before applying or installing the repository zip file:
-
The minimum OS level required for the system to run this repository is Oracle Solaris 11.1.
-
The repository is provided as zip files. They contain only the latest revision of IPS packages that have been added or changed since the initial release of Oracle Solaris 11.3.
-
This SRU is provided in two parts: Oracle Solaris IPS Repository Installation Guide and Oracle Solaris IPS Repository. The Oracle Solaris IPS Repository Installation Guide contains the install script and readme files. The Oracle Solaris IPS Repository contains the zip files of the repository. You must download both the parts from the MOS to add the packages to an existing repository.
-
The zip file associated with this README must be used in conjunction with an existing local copy of the Oracle Solaris support repository.
-
It is necessary to have a valid
solaris publisher set before performing an update. For instructions to create an Oracle Solaris 11.3 package repository, see Copying and Creating Oracle Solaris 11.3 Package Repositories.
The example commands listed in this section should be executed with root privileges or by using sudo(1M) or pfexec(1) commands.
How to Update Your Local Repository
Download the SRU's IPS Repository Installation Guide and IPS Repository patches from MOS.
Perform the following steps to update your local system with the contents of the SRU zip file:
-
Become an administrator.
For more information, see How to Use Your Assigned Administrative Rights in Securing Users and Processes in Oracle Solaris 11.3.
-
Run the
install-repo.ksh script that is included in the IPS Repository Installation Guide patch to update your existing repository.
$ install-repo.ksh [-c] [-v] -d full_path_to_existing_s11_3_repo
For example:
$ install-repo.ksh -c -v -d /export/support-repo
-
If the repository is managed by
pkgserv, restart the appropriate service.
$ svcadm restart svc:/application/pkg/server:your_repo_instance
-
If an existing repository is not set, add the repository to the system.
$ pkg set-publisher -g file:///full_path_to_existing_s11_3_repo solaris
-
Update the packages.
$ pkg update
For more information about using the install-repo.ksh script, see the README-zipped-repo.txt file.
For more information about managing your repository, see the following resources:
Further Assistance
The documentation for Oracle Solaris 11.3 can be found at:
Oracle Solaris 11.3 Information Library
If you have a support plan with Oracle, please contact your service representative for further assistance. Community discussion of this product can be found at:
My Oracle Support Community - Oracle Solaris Installation, Booting, and Patching
Copyright © 2018, Oracle and/or its affiliates. All rights reserved.
This software and related documentation are provided under a license agreement containing restrictions on use and disclosure and are protected by intellectual property laws. Except as expressly permitted in your license agreement or allowed by law, you may not use, copy, reproduce, translate, broadcast, modify, license, transmit, distribute, exhibit, perform, publish, or display any part, in any form, or by any means. Reverse engineering, disassembly, or decompilation of this software, unless required by law for interoperability, is prohibited.
The information contained herein is subject to change without notice and is not warranted to be error-free. If you find any errors, please report them to us in writing.
If this is software or related documentation that is delivered to the U.S. Government or anyone licensing it on behalf of the U.S. Government, the following notice is applicable:
U.S. GOVERNMENT END USERS. Oracle programs, including any operating system, integrated software, any programs installed on the hardware, and/or documentation, delivered to U.S. Government end users are "commercial computer software" pursuant to the applicable Federal Acquisition Regulation and agency-specific supplemental regulations. As such, use, duplication, disclosure, modification, and adaptation of the programs, including any operating system, integrated software, any programs installed on the hardware, and/or documentation, shall be subject to license terms and license restrictions applicable to the programs. No other rights are granted to the U.S. Government.
This software or hardware is developed for general use in a variety of information management applications. It is not developed or intended for use in any inherently dangerous applications, including applications that may create a risk of personal injury. If you use this software or hardware in dangerous applications, then you shall be responsible to take all appropriate fail-safe, backup, redundancy, and other measures to ensure its safe use. Oracle Corporation and its affiliates disclaim any liability for any damages caused by use of this software or hardware in dangerous applications.
Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective owners.
Intel and Intel Xeon are trademarks or registered trademarks of Intel Corporation. All SPARC trademarks are used under license and are trademarks or registered trademarks of SPARC International, Inc. AMD, Opteron, the AMD logo, and the AMD Opteron logo are trademarks or registered trademarks of Advanced Micro Devices. UNIX is a registered trademark of The Open Group.
This software or hardware and documentation may provide access to or information on content, products, and services from third parties. Oracle Corporation and its affiliates are not responsible for and expressly disclaim all warranties of any kind with respect to third-party content, products, and services. Oracle Corporation and its affiliates will not be responsible for any loss, costs, or damages incurred due to your access to or use of third-party content, products, or services.