
















                                                      HP Tru64 UNIX



                 Patch Summary and Release Notes for Patch Kit 6















                 This manual describes the contents of  Patch Kit 6
                 for the 5.1A version of the Tru64 UNIX operating
                 system and TruCluster Server Software products.
                 It provides special instructions for installing
                 individual patches.

                 See the  _T_e_c_h_n_i_c_a_l _U_p_d_a_t_e_s _f_o_r _T_r_u_6_4 _U_N_I_X _P_a_t_c_h
                 _K_i_t_s for information about restrictions and
                 problems that may have been discovered since the
                 release of this kit. See the  _P_a_t_c_h _K_i_t
                 _I_n_s_t_a_l_l_a_t_i_o_n _I_n_s_t_r_u_c_t_i_o_n_s for information about
                 installing or removing patches, baselining, and
                 general patch management.





                 __________________________________________________

                 Hewlett-Packard Company
                 Palo Alto, California













               Copyright 2003 Hewlett-Packard Development Company,
               L.P.



                Microsoft(R), Windows(R), and Windows NT(R) are
               trademarks of Microsoft Corporation in the U.S.
               and/or other countries.  Intel(R) and Pentium(R) are
               trademarks of Intel Corporation in the U.S. and/or
               other countries.  Motif(R), OSF/1(R), The Open
               GroupTM, and UNIX(R) are trademarks of The Open Group
               in the U.S. and/or other countries.  All other
               product names mentioned herein may be trademarks or
               registered trademarks of their respective companies.

               Confidential computer software. Valid license from
               Compaq Computer Corporation, a wholly owned
               subsidiary of Hewlett-Packard Company, required for
               possession, use, or copying. Consistent with FAR
               12.211 and 12.212, Commercial Computer Software,
               Computer Software Documentation, and Technical Data
               for Commercial Items are licensed to the U.S.
               Government under vendor's standard commercial
               license.

               None of Compaq, HP, or any of their subsidiaries
               shall be liable for technical or editorial errors or
               omissions contained herein. The information in this
               document is provided "as is" without warranty of any
               kind and is subject to change without notice. The
               warranties for Compaq products are set forth in the
               express limited warranty statements accompanying such
               products. Nothing herein should be construed as
               constituting an additional warranty.


































                                                            Contents







        About This Manual


        Audience  ............................................  viii

        Organization  ........................................  viii

        Related Documentation  ...............................  viii

        Patch Process Resources  .............................  ix

        Reader's Comments  ...................................  ix


        1   Tru64 UNIX Patches


        1.1   Release Notes  .................................  1-1

           1.1.1   Required Storage Space  ...................  1-1
           1.1.2   Changes to Reference Pages  ...............  1-2
           1.1.3   Potential NFS Duplicate Request Cache
                 Scalability Limitation with High Loads and
                 Uncharacteristic File Access Behavior on
                 Clustered NFS Servers (new)  ................  1-3
           1.1.4   Tuning the NFS Server Duplicate Request
                 Cache (new)  ................................  1-5

               1.1.4.1   Moving Files in DMAPI-Enabled
                     Filesets Across Partitions &#151; Patch
                     2084.00 (new)  ..........................  1-6

           1.1.5   Performance of hwmgr Commands on Large
                 System Configurations (new)  ................  1-6

               1.1.5.1   Packetfilter Enhancements &#151;
                     Patch 2084.00 (new)  ....................  1-7
               1.1.5.2   Changes to vdump and vrestore Allow
                     Larger Record Sizes &#151; Patch 2064.00 . 1-7

           1.1.6   Potential Problem Patching a System with
                 WLS Subsets Installed  ......................  1-8














               1.1.6.1   Security Feature &#151; Patch 2084.00..1-8
               1.1.6.2   Changes to tar, pax, and cpio
                     Behavior &#151; Patch 2088.00  ..........  1-10
               1.1.6.3   Ignore Special Instruction for Patch
                     1924.00  ................................  1-10
               1.1.6.4   Russian Keyboard &#151; Patch 1197.00..1-10

           1.1.7   Problem Seen on Systems with Smart Array
                 Controller  .................................  1-11
           1.1.8   Problem with lockmode=4 on AlphaServers
                 with QLogic SCSI Disk Controllers  ..........  1-12
           1.1.9   Updates to sys_check  .....................  1-12

               1.1.9.1   TMPDIR Variable  ....................  1-12
               1.1.9.2   sys_check Version 125 Web Kit  ......  1-12

           1.1.10   Support for SDLT160 Tape Device  .........  1-13

                  1.1.10.0.1   New libots3 Library &#151;
                        Patches 1146.00 and 1148.00  .........  1-14

               1.1.10.1   New esmd Daemon &#151; Patch 252.00 . 1-15
               1.1.10.2   Command Updates and Other Changes
                     &#151; Patch 2084.00  ...................  1-15
               1.1.10.3   Updates to sh, csh, and ksh  .......  1-15
               1.1.10.4   sh noclobber Option and >| , >>|
                     Constructs Added  .......................  1-15
               1.1.10.5   ksh noclobber Behavior Clarified  ..  1-16
               1.1.10.6   csh noclobber Behavior Clarified  ..  1-16
               1.1.10.7   Updated mkdir System Call and
                     Command  ................................  1-16
               1.1.10.8   Enabling the /dev/poll Function  ...  1-17
               1.1.10.9   Removal of Version-Switched Patch  .  1-17
               1.1.10.10   New ee Attribute  .................  1-18
               1.1.10.11   Support for Network Link
                     Aggregation  ............................  1-18


        1.2   Summary of Base Operating System Patches  ......  1-18


        2   TruCluster Server Patches


        2.1   Release Notes  .................................  2-1

           2.1.1   Required Storage Space  ...................  2-1
           2.1.2   Removing Some Patches Can Cause Problems  .  2-2
           2.1.3   Patch Removal Causes Login Error  .........  2-2
           2.1.4   Updates for Rolling Upgrade Procedures  ...  2-2

               2.1.4.1   Problem When Undoing Roll with
                     Worldwide Languages Installed




        iv Contents








                                                    ..........



















































                                                                2-3




                                                          Contents v








               2.1.4.2   Order for Rolling NHD6 and Patch Kit
                     6  ......................................  2-3
               2.1.4.3   Unrecoverable Failure Procedure  ....  2-3
               2.1.4.4   During Rolling Patch, Do Not Add or
                     Delete OSF, TCR, IOS, or OSH Subsets  ...  2-3
               2.1.4.5   Undoing a Rolling Patch  ............  2-4

                  2.1.4.5.1   Ignore Message About Missing
                        ladebug.cat File During Rolling
                        Upgrade  .............................  2-4

               2.1.4.6   clu_upgrade undo of Install Stage Can
                     Result in Incorrect File Permissions  ...  2-4
               2.1.4.7   Missing Entry Messages Can Be Ignored
                     During Rolling Patch  ...................  2-5
               2.1.4.8   Relocating AutoFS During a Rolling
                     Upgrade on a Cluster  ...................  2-6

           2.1.5   When Taking a Cluster Member to Single-User
                 Mode, First Halt the Member  ................  2-7
           2.1.6   Additional Steps Required When Installing
                 Patches Before Cluster Creation  ............  2-7
           2.1.7   Problems with clu_upgrade switch Stage  ...  2-8

               2.1.7.1   Cluster Information for Tru64 UNIX
                     Patch 2084.00  ..........................  2-8
               2.1.7.2   Change to gated Restriction &#151;
                     Patch 336.00  ...........................  2-8
               2.1.7.3   Version Switch Warning Added &#151;
                     Patch 351.00  ...........................  2-10
               2.1.7.4   Information for Patch 371.00  .......  2-11
               2.1.7.5   Enablers for EVM  ...................  2-11
               2.1.7.6   Rolling Upgrade Version Switch  .....  2-11
               2.1.7.7   Restrictions Removed  ...............  2-12
               2.1.7.8   CAA and Datastore &#151; Patch 338.00..2-12


        2.2   Summary of TruCluster Software Patches  ........  2-13


        A   Revised Reference Pages


        A.1   envconfig(8) Update  ...........................  A-1

        A.2   sys_check(8) Update  ...........................  A-4

        A.3   sys_attrs_netrain(5), nifftmt(7), and
              niffconfig(8) Updates  .........................  A-12

           A.3.1   sys_attrs_netrain(5)  .....................  A-12






        vi Contents








           A.3.2   nifftmt(7)  ...............................  A-13
           A.3.3   niffconfig(8)  ............................  A-15


        A.4   wol(8) Update  .................................  A-16




















































                                                        Contents vii










                                                              About This Manual






 This manual contains information specific to Patch Kit 6 of the Tru64 UNIX
 operating system and TruCluster Server software products for Version 5.1A.  It
 provides a list of the patches contained in each kit and describes the
 information you need to know when installing specific patches.


 _A_u_d_i_e_n_c_e

 This manual is for the person who installs and removes the patch kit and for
 anyone who manages patches after they are installed.


 _O_r_g_a_n_i_z_a_t_i_o_n

 This manual is organized as follows:

 ______________________________________________________________________________

 Chapter 1                   Provides information about the Tru64 UNIX patches
                             included in this kit.

 Chapter 2                   Provides information about the TruCluster Server
                             software patches included in this kit.

 Appendix A                  Provides changes to reference pages that occur as
                             a result of patches included in this kit.

 ______________________________________________________________________________




 _R_e_l_a_t_e_d _D_o_c_u_m_e_n_t_a_t_i_o_n

 In addition to this manual, the following documentation may be helpful in the
 patching process:


 +o  _T_e_c_h_n_i_c_a_l _U_p_d_a_t_e_s _f_o_r _T_r_u_6_4 _U_N_I_X _P_a_t_c_h _K_i_t_s

    This document reports any information about restrictions and problems that
    may have been discovered since the release of this and other patch kits.

 +o  Tru64 UNIX and TruCluster Server _P_a_t_c_h _K_i_t _I_n_s_t_a_l_l_a_t_i_o_n _I_n_s_t_r_u_c_t_i_o_n_s













 +o  _P_a_t_c_h_i_n_g _B_e_s_t _P_r_a_c_t_i_c_e

 +o  The dddduuuuppppaaaattttcccchhhh(8) reference page, which describes the use of dddduuuuppppaaaattttcccchhhh from the
    command line.  This reference page is installed when you install the
    dddduuuuppppaaaattttcccchhhh tools.

 +o  Tru64 UNIX _I_n_s_t_a_l_l_a_t_i_o_n _G_u_i_d_e

 +o  Tru64 UNIX _S_y_s_t_e_m _A_d_m_i_n_i_s_t_r_a_t_i_o_n

 +o  TruCluster Server _C_l_u_s_t_e_r _I_n_s_t_a_l_l_a_t_i_o_n

 +o  TruCluster Server _C_l_u_s_t_e_r _A_d_m_i_n_i_s_t_r_a_t_i_o_n

 +o  Release-specific installation documentation




 _P_a_t_c_h _P_r_o_c_e_s_s _R_e_s_o_u_r_c_e_s

 We provide Web sites to help you with the patching process:


 +o  To obtain the latest patch kit for your operating system and cluster:

    hhhhttttttttpppp::::////////wwwwwwwwwwww....iiiittttrrrrcccc....hhhhpppp....ccccoooommmm////sssseeeerrrrvvvviiiicccceeee////ppppaaaattttcccchhhh////mmmmaaaaiiiinnnnPPPPaaaaggggeeee....ddddoooo

 +o  To view or print the latest version of the _P_a_t_c_h _K_i_t _I_n_s_t_a_l_l_a_t_i_o_n
    _I_n_s_t_r_u_c_t_i_o_n_s or the _P_a_t_c_h _S_u_m_m_a_r_y _a_n_d _R_e_l_e_a_s_e _N_o_t_e_s for a specific patch
    kit:

    hhhhttttttttpppp::::////////hhhh33330000000099997777....wwwwwwwwwwww3333....hhhhpppp....ccccoooommmm////ddddooooccccssss////ppppaaaattttcccchhhh////iiiinnnnddddeeeexxxx....hhhhttttmmmmllll

 +o  To visit our main support page:

    hhhhttttttttpppp::::////////hhhh77771111000022225555....wwwwwwwwwwww7777....hhhhpppp....ccccoooommmm////ssssuuuuppppppppoooorrrrtttt////hhhhoooommmmeeee////iiiinnnnddddeeeexxxx....aaaasssspppp

 +o  To visit the Tru64 UNIX homepage:

    hhhhttttttttpppp::::////////hhhh33330000000099997777....wwwwwwwwwwww3333....hhhhpppp....ccccoooommmm////




 _R_e_a_d_e_r'_s _C_o_m_m_e_n_t_s

 We welcome any comments and suggestions you have on this and other Tru64 UNIX
 manuals.

 You can send your comments in the following ways:


 +o  Fax: 603-884-0120 Attn: HCTO Information Development, ZK03-3/Y32



                                                About This Manual ix








 +o  Internet electronic mail:

    rrrreeeeaaaaddddeeeerrrrssss____ccccoooommmmmmmmeeeennnntttt@@@@zzzzkkkk3333....ddddeeeecccc....ccccoooommmm

    A Reader's Comment form is located on your system in the following
    location:  ////uuuussssrrrr////ddddoooocccc////rrrreeeeaaaaddddeeeerrrrssss____ccccoooommmmmmmmeeeennnntttt....ttttxxxxtttt

 +o  Mail:

    Hewlett-Packard Company
    HCTO Information Development Manager
    ZK03-3/Y32
    110 Spit Brook Road
    Nashua, NH 03062-9987



 Please include the following information along with your comments:


 +o  The full title of this document.

 +o  The section numbers and page numbers of the information on which you are
    commenting.

 +o  The version of Tru64 UNIX that you are using.

 +o  If known, the type of processor that is running the Tru64 UNIX software.


 The Tru64 UNIX Publications group cannot respond to system problems or
 technical support inquiries.  Please address technical questions to your local
 system vendor or to the appropriate technical support office.  Information
 provided with the software media explains how to send problem reports.























 x About This Manual










                                                    Tru64 UNIX Patches        1






 This chapter provides information about the patches included in Patch Kit 6
 for the base operating system.  It also includes any general information about
 working with these patches.

 This chapter is organized as follows:


 +o  Section 1.1 provides release notes that are specific to the Tru64 UNIX
    patches in this kit, as well as release notes that are of general interest.

 +o  Section 1.2 provides brief descriptions of the purpose of the Tru64 UNIX
    patches included in this kit.


 Tru64 UNIX patch kits are cumulative.  For this kit, this means that the
 patches and related documentation from patch kits 1 through 5 are included,
 along with patches that are new to this kit.  To aid you in using this
 document, release notes that are new with this release are listed as (New) in
 the section head.  The beginning of Section 1.2 provides a key for
 understanding the history of individual patches.


 _1._1  _R_e_l_e_a_s_e _N_o_t_e_s

 This section provides release notes that are specific to the Tru64 UNIX
 patches in this kit, as well as release notes that are of general interest.


 _1._1._1  _R_e_q_u_i_r_e_d _S_t_o_r_a_g_e _S_p_a_c_e

 Approximately 250 MB of temporary storage space is required to untar the base
 and TruCluster components of this patch kit.  We recommend that this kit not
 be placed in the ////, ////uuuussssrrrr, or ////vvvvaaaarrrr file systems because doing so may unduly
 constrain the available storage space for the patching activity.

 The following permanent storage space is required to successfully install the
 base component of the patch kit:


 +o  Approximately 87.9 MB of storage space in ////vvvvaaaarrrr////aaaaddddmmmm////ppppaaaattttcccchhhh////bbbbaaaacccckkkkuuuupppp may be
    required for archived original files if you choose to install and revert
    all patches.  See the _P_a_t_c_h _K_i_t _I_n_s_t_a_l_l_a_t_i_o_n _I_n_s_t_r_u_c_t_i_o_n_s for more
    information.

 +o  Approximately 90.6 MB of storage space in ////vvvvaaaarrrr////aaaaddddmmmm////ppppaaaattttcccchhhh may be required
    for original files if you choose to install and revert all patches.  See











    the _P_a_t_c_h _K_i_t _I_n_s_t_a_l_l_a_t_i_o_n _I_n_s_t_r_u_c_t_i_o_n_s for more information.

 +o  Approximately 2.4 MB of storage space is required in ////vvvvaaaarrrr////aaaaddddmmmm////ppppaaaattttcccchhhh////ddddoooocccc for
    patch abstract and README documentation.

 +o  Approximately 184 KB of storage space is needed in ////uuuussssrrrr////ssssbbbbiiiinnnn////dddduuuuppppaaaattttcccchhhh for
    the patch management utility.


 See Section 2.1.1 for information on space needed for the TruCluster Server
 patches.


 _1._1._2  _C_h_a_n_g_e_s _t_o _R_e_f_e_r_e_n_c_e _P_a_g_e_s

 The following table lists reference pages that have been revised since the
 Version 5.1A release of the operating system and are installed by patches in
 this kit.  Changes to several reference pages that are not revised via patches
 are described in Appendix A.



 ______________________________________________________________________________

 RRRReeeeffffeeeerrrreeeennnncccceeee PPPPaaaaggggeeee                        PPPPaaaattttcccchhhh IIIIDDDD oooorrrr SSSSeeeeccccttttiiiioooonnnn
 ______________________________________________________________________________

 cccchhhhaaaattttrrrr(1)                              Patch 1624.00

 cccckkkkffffsssseeeecccc(1)                             Patch 824.00

 ddddiiiirrrrcccclllleeeeaaaannnn(8)                           Patch 763.00

 eeeennnnvvvvccccoooonnnnffffiiiigggg(8)                          Section A.1

 eeeexxxxppppoooorrrrttttffffssss(2)                           Patch 763.00

 iiiiffffccccoooonnnnffffiiiigggg(8)                           Patch 1370.00

 jjjjaaaavvvvaaaaeeeexxxxeeeeccccuuuutttteeeeddddaaaattttaaaa(8)                    Patch 1701.00

 kkkkddddbbbbxxxx(8)                               Patch 1611.00

 llllaaaagggg(7)                                Patch 1651.00

 llllaaaaggggccccoooonnnnffffiiiigggg(8)                          Patch 1755.00

 mmmmkkkktttteeeemmmmpppp(1)                             Patch 701.00

 mmmmkkkktttteeeemmmmpppp(3)                             Patch 705.00

 nnnneeeettttssssttttaaaatttt(1)                            Patch 2066.00





 1-2 Tru64 UNIX Patches








 nnnniiiiffffffffccccoooonnnnffffiiiigggg(8)                         Section A.3.3

 nnnniiiiffffffffttttmmmmtttt(7)                            Section A.3.2

 ppppoooollllllll(7)                               Patch 765.00

 rrrroooouuuutttteeee(8)                              Patch 2066.00

 ssssaaaaffffeeee____ooooppppeeeennnn(3)                          Patch 731.00

 ssssyyyyssss____aaaattttttttrrrrssss____eeeeeeee(5)                       Patch 1717.00

 ssssyyyyssss____aaaattttttttrrrrssss____ddddlllliiii(5)                      Patch 1669.00

 ssssyyyyssss____aaaattttttttrrrrssss____iiiinnnneeeetttt(5)                     Patch 2066.00

 ssssyyyyssss____aaaattttttttrrrrssss____nnnneeeetttt(5)                      Patch 2066.00

 ssssyyyyssss____aaaattttttttrrrrssss____nnnneeeettttrrrraaaaiiiinnnn(5)                  Section A.3.1

 ssssyyyyssss____aaaattttttttrrrrssss____pppprrrroooocccc(5)                     Patch 1701.00

 ssssyyyyssss____cccchhhheeeecccckkkk(8)                          Section A.2

 vvvvoooollllrrrreeeessssttttoooorrrreeee(8)                         Patch 2072.00

 vvvvoooollllssssaaaavvvveeee(8)                            Patch 2072.00

 wwwwoooollll(8)                                Section A.4

 ______________________________________________________________________________




 _1._1._3  _P_o_t_e_n_t_i_a_l _N_F_S _D_u_p_l_i_c_a_t_e _R_e_q_u_e_s_t _C_a_c_h_e _S_c_a_l_a_b_i_l_i_t_y _L_i_m_i_t_a_t_i_o_n _w_i_t_h _H_i_g_h
        _L_o_a_d_s _a_n_d _U_n_c_h_a_r_a_c_t_e_r_i_s_t_i_c _F_i_l_e _A_c_c_e_s_s _B_e_h_a_v_i_o_r _o_n _C_l_u_s_t_e_r_e_d _N_F_S
        _S_e_r_v_e_r_s (_n_e_w)

 Repeated simultaneous overwriting of many files can cause retransmitted writes
 to be processed after recent writes of a file to the same location.  This
 problem occurs more often on systems configured with a LAN cluster
 interconnect than on those configured with Memory Channel.

 This behavior is inherent in the "stateless" design of NFS.  Although the
 behavior has been mitigated via a "duplicate request cache" that replays old
 replies instead of reexecuting retransmitted requests, extremely heavy loads
 on large systems can overwhelm the cache when requests are stalled.  Customers
 are unlikely to see problems because applications rarely rewrite files almost
 immediately.

 If the problem occurs, the NFS server displays the following message several
 times a minute on the system console, indicating that the NFS server is being
 overwhelmed with requests :



                                              Tru64 UNIX Patches 1-3








 "NFS server xxx not responding"

 When an "overwhelmed duplicate request cache" condition has occurred, the NFS
 client will display multiple occurrences of either of the following messages:

 NFS3 server xxx not responding still trying
 NFS3 server xxx ok

 NFS2 server xxx not responding still trying
 NFS2 server xxx ok

 This indicates that the client is observing transient unresponsive periods at
 the server.  This is the only notification that the client will display if the
 server's duplicate request cache becomes overwhelmed.  When the client detects
 this behavior, it increases the retransmission interval until it gets a
 response from the server.  This behavior is generally undistinguishable from
 the server going up and down, except that the messages are displayed with such
 frequency that the server system/member cannot have gone down and then come
 back up in that short an interval.

 You can minimize the likelihood of these problems as follows:


 +o  Avoid congestion on your LAN and cluster interconnect.

 +o  Ensure your servers have enough excess capacity to respond quickly to NFS
    requests that modify the file system (writes, file and directory creation,
    and so forth.)

 +o  Increase the size of the server's duplicate request cache when the nnnnffffssssssssttttaaaatttt
    command shows a large number of retransmits to clients.  For instructions
    on increasing the size of the cache, see Section 1.1.4.


 You can monitor the number of NFS retransmissions using the nnnnffffssssssssttttaaaatttt ----cccc
 command.  \&.  The rrrreeeettttrrrraaaannnnssss field indicates the number of retransmissions.  A
 retransmission rate higher than 2% indicates a potential problem.

 The following example shows the output from the nnnnffffssssttttaaaatttt ----cccc command.  The
 retransmission fields are marked with asterisks (*).  This example is of a
 client workstation in a typical environment.


 %%%% nnnnffffssssssssttttaaaatttt ----cccc

 Client rpc:
 tcp:       calls    badxids   badverfs   timeouts   newcreds
                 0          0          0          0          0
           creates   connects   badconns     inputs     avails interrupts
                 0          0          0          0          0          0
 udp:       calls    badxids   badverfs   timeouts   newcreds    *retrans*
         224518870        959          0            101985          0                   0
          badcalls     timers      waits
           102013     110894          0



 1-4 Tru64 UNIX Patches









 Client nfs:
        calls        * retrans*   badcalls     nclget   nclsleep  ndestroys ncleans
    224414222      4248                28   224414282          0       6219         224408063 \


 If an overwhelmed duplicate request cache condition occurs, we recommend you
 perform one or more of the following tasks:


 +o  Ensure that there are short periods of idle time on the I/O subsystem and
    network links.

 +o  After a file is written, do not rewrite it for a few minutes.

 +o  Delete and recreate files instead of overwriting the same file repeatedly.

 +o  Use Memory Channel cluster interconnect.


 To avoid overwhelming the duplicate request cache:


 +o  Do not run hundreds of simultaneous processes that write files

 +o  Do not operate the system under so heavy a load that NFS operations
    frequently take several seconds to complete.


 Use the nnnneeeettttssssttttaaaatttt command to determine if your network is saturated.  For
 Ethernet networks, a high number of collisions indicates that the network may
 be saturated.  The following example shows the output from the nnnneeeettttssssttttaaaatttt ----IIII ttttuuuu0000
 command:

 Name  Mtu   Network     Address               Ipkts Ierrs    Opkts      Oerrs  *Coll*
 tu0   1500        xx:xx:xx:xx:xx      840386045     0   254319298  5121    5014223
 tu0   1500  network    client                 840386045     0    254319298   5121  5014223
 tu0   1500  DLI             none                840386045     0     254319298   5121  5014223




 _1._1._4  _T_u_n_i_n_g _t_h_e _N_F_S _S_e_r_v_e_r _D_u_p_l_i_c_a_t_e _R_e_q_u_e_s_t _C_a_c_h_e (_n_e_w)

 The NFS server maintains a list of recently completed nonrepeatable requests.
 This list is used to reply to client retransmissions of the request in the
 event that the initial request transmission's reply was lost or that the
 server took too long to satisfy the request.

 Problems may occur with the duplicate request cache in some cases, under heavy
 NFS server load and over high aggregate network bandwidth involving changes to
 file systems (changes caused by the use of the ccccrrrreeeeaaaatttt,,,, lllliiiinnnnkkkk,,,, uuuunnnnlllliiiinnnnkkkk,,,, mmmmkkkkddddiiiirrrr,,,,
 rrrrmmmmddddiiiirrrr,,,, ttttrrrruuuunnnnccccaaaatttteeee,,,, uuuuttttiiiimmmmeeeessss,,,, and wwwwrrrriiiitttteeee commands).  These problems can occur if all
 the elements in the duplicate request cache are cycled between an initial



                                              Tru64 UNIX Patches 1-5








 client transmission and subsequent retransmission.  If this occurs, the NFS
 server cannot detect that the retransmission is in fact a retransmission.
 This may result in the repetition of a request and may cause out-of-order
 writes or truncation and subsequent retruncation of a file.

 Patch 1062.00 provides a tuning variable to control the size of the NFS
 server's duplicate request cache:


 +o  nnnnffffssss____dddduuuuppppccccaaaacccchhhheeee____ssssiiiizzzzeeee &#151; Controls the absolute size of the NFS server
    duplicate request cache.  This is measured in the number of elements that
    are allocated at NFS server initialization.


 If it is determined that the size of the duplicate cache needs to be modified,
 you should change nnnnffffssss____dddduuuuppppccccaaaacccchhhheeee____ssssiiiizzzzeeee.  The new value for nnnnffffssss____dddduuuuppppccccaaaacccchhhheeee____ssssiiiizzzzeeee
 should be set to equal two times the value of nnnnffffssss____dddduuuuppppccccaaaacccchhhheeee____eeeennnnttttrrrriiiieeeessss.

 You must use the ddddbbbbxxxx command to modify nnnnffffssss____dddduuuuppppccccaaaacccchhhheeee____ssssiiiizzzzeeee.  There is no
 sysconfig interface to this tuning variable.


 _1._1._4._1  _M_o_v_i_n_g _F_i_l_e_s _i_n _D_M_A_P_I-_E_n_a_b_l_e_d _F_i_l_e_s_e_t_s _A_c_r_o_s_s _P_a_r_t_i_t_i_o_n_s &#_1_5_1; _P_a_t_c_h
          _2_0_8_4._0_0 (_n_e_w)

 When moving files in DMAPI-enabled filesets across partitions, the mmmmvvvv command
 will preserve only the default and access control list (ACL) attributes.


 _1._1._5  _P_e_r_f_o_r_m_a_n_c_e _o_f _h_w_m_g_r _C_o_m_m_a_n_d_s _o_n _L_a_r_g_e _S_y_s_t_e_m _C_o_n_f_i_g_u_r_a_t_i_o_n_s (_n_e_w)

 On large system configurations, certain hhhhwwwwmmmmggggrrrr commands may take a long time to
 run and can produce voluminous output.  For example, on a system connected to
 a large storage area network, the hhhhwwwwmmmmggggrrrr ----vvvviiiieeeewwww ddddeeeevvvviiiicccceeeessss command can take a long
 time to begin displaying output, because it must first select devices from all
 of the hardware components in the system and then retrieve, format, and sort
 the output report.

 The output from these commands is gathered and sorted in memory before the
 report begins to be displayed.  In a system with hundreds or thousands of
 attached storage units, the processing stage can take several minutes and you
 will not see any output during that time.

 When using the command hhhhwwwwmmmmggggrrrr ----vvvviiiieeeewwww ddddeeeevvvviiiicccceeeessss ----cccclllluuuusssstttteeeerrrr, the time can be even
 longer and the size of the report can be larger because in most clustered
 configurations, mass storage devices are reported by every member and thus
 appear multiple times in the generated report.  Therefore, you may need to
 relax the memory limits for the process running the command, because with such
 a large number of devices in the configuration, the system may be unable to
 gather all of the data with the default memory limit.

 We recommend that you run commands that generate large reports in the
 background (for example, in a batch job) and save their output into a file or
 set of files for subsequent examination or historical comparison.



 1-6 Tru64 UNIX Patches








 _1._1._5._1  _P_a_c_k_e_t_f_i_l_t_e_r _E_n_h_a_n_c_e_m_e_n_t_s &#_1_5_1; _P_a_t_c_h _2_0_8_4._0_0 (_n_e_w)

 Patch 2084.00 provides enhancements with the following dbx kernel flags to
 control packetfilter-written packets:


 +o  ppppffffiiiilllltttt____llllooooooooppppbbbbaaaacccckkkk====[[[[_0|_1]

    Setting this flag to 0 prevents a loop back of any packetfilter-written
    multicast or broadcast packet.

    When set to 1, the packetfilter loops back both broadcast and multicast
    packets.  This is the default

 +o  ppppffffiiiilllltttt____pppphhhhyyyyssssaaaaddddddddrrrr====[[[[_0|_1]

    Setting this flag to 0 allows the application to fill in the source
    Ethernet address for packetfilter-written packets.  If the source address
    is all 0's, the address is set to the proper hardware address by the
    packetfilter code as a safety precaution.

    When set to 1, the packetfilter sets the Ethernet source address in the
    outgoing packet.  This is the default.


 _R_e_s_t_r_i_c_t_i_o_n

 The ppppffffiiiilllltttt____llllooooooooppppbbbbaaaacccckkkk and ppppffffiiiilllltttt____pppphhhhyyyyssssaaaaddddddddrrrr tunable variables are only accessible in
 the kernel by using dbx.

 In a future patch kit, these tunable variables will be implemented as kernel
 subsystem configurable attributes, accessible through the ssssyyyyssssccccoooonnnnffffiiiigggg command.



 _1._1._5._2  _C_h_a_n_g_e_s _t_o _v_d_u_m_p _a_n_d _v_r_e_s_t_o_r_e _A_l_l_o_w _L_a_r_g_e_r _R_e_c_o_r_d _S_i_z_e_s &#_1_5_1; _P_a_t_c_h
          _2_0_6_4._0_0

 The vvvvdddduuuummmmpppp and vvvvrrrreeeessssttttoooorrrreeee programs have been tuned to disallow block sizes
 greater than 64 KB blocks.  This is to avoid forward compatibility problems.
 With this patch, the valid range is 2 through 64 KB blocks.

 Currently the maximum for the -b option is 64 1024-byte blocks.  With this
 patch, the byte-block size is changed to 2048.  By default, the -b option of
 60 blocks per record remains unchanged.

 The vvvvrrrreeeessssttttoooorrrreeee program still has the capability to autosize vvvvdddduuuummmmpppp archives.
 Also, it is backward compatible, which means it can restore archives created
 by earlier versions of vvvvdddduuuummmmpppp.

 _N_o_t_e

 If you create an archive using this version of vvvvdddduuuummmmpppp, uninstalling Patch
 2064.00 will prevent you from restoring that archive.  This occurs because



                                              Tru64 UNIX Patches 1-7








 removing Patch 2064.00 would revert vvvvdddduuuummmmpppp and vvvvrrrreeeessssttttoooorrrreeee to earlier versions,
 which do not recognize archives created by the later versions.  If this
 occurs, you will have to reinstall Patch 2064.00 to restore the archive.



 _1._1._6  _P_o_t_e_n_t_i_a_l _P_r_o_b_l_e_m _P_a_t_c_h_i_n_g _a _S_y_s_t_e_m _w_i_t_h _W_L_S _S_u_b_s_e_t_s _I_n_s_t_a_l_l_e_d

 If you will be installing or removing patches on a system with Worldwide
 Language Subsets installed, you may encounter a shell limitation on the size
 of the shell environment.  This is due to the large number of installed
 subsets.  If you encounter this situation, your system may hang or you may see
 an error message similar to the following:

 ////uuuussssrrrr////ssssbbbbiiiinnnn////sssseeeettttlllldddd:::: aaaarrrrgggg lllliiiisssstttt ttttoooooooo lllloooonnnngggg.

 To prevent this from occurring, enter the following command to relax the
 command-line limits prior to running dddduuuuppppaaaattttcccchhhh:

 # ssssyyyyssssccccoooonnnnffffiiiigggg ----rrrr pppprrrroooocccc eeeexxxxeeeecccc____ddddiiiissssaaaabbbblllleeee____aaaarrrrgggg____lllliiiimmmmiiiitttt====1111

 _N_o_t_e

 Do not use this kernel setting as a default; enable it only when you encounter
 a problem where the eeeexxxxeeeecccc(((()))) argument size limit has been approached.

 This vulnerability will be fixed in a future patch kit.


 _1._1._6._1  _S_e_c_u_r_i_t_y _F_e_a_t_u_r_e &#_1_5_1; _P_a_t_c_h _2_0_8_4._0_0

 Patch 2084.00 provides a new security feature to prevent the execution of
 instructions that reside in heap or other data areas of process memory.  The
 result is additional protection against buffer overflow exploits.  This
 feature is similar in concept to Tru64 UNIX executable stack protection.

 The new feature is implemented as a dynamic ssssyyyyssssccccoooonnnnffffiiiigggg tunable attribute,
 eeeexxxxeeeeccccuuuuttttaaaabbbblllleeee____ddddaaaattttaaaa, in the pppprrrroooocccc subsystem.  The supported settings allow system
 administrators to cause requests from privileged processes for writable and
 executable memory to fail, or to be treated as a request for writable memory
 and to optionally generate a message when such a request occurs.

 In a buffer overflow exploitation, an attacker feeds a privileged program an
 unexpectedly large volume of carefully constructed data through inputs such as
 command line arguments and environment variables.  If the program is not coded
 defensively, the attacker can overwrite areas of memory adjacent to the
 buffer.

 Depending upon the location of the buffer (stack, heap, data area), the
 attacker can deceive these programs into executing malicious code that takes
 advantage of the program's privileges or alters a security-sensitive program
 variable to redirect program flow.

 With some expertise, such an attack can be used to gain root access to the



 1-8 Tru64 UNIX Patches








 system.

 Enabling the eeeexxxxeeeeccccuuuuttttaaaabbbblllleeee____ddddaaaattttaaaa tunable changes a potential system compromise
 into, at worst, a denial-of-service attack.  A vulnerable program may still
 contain a buffer overflow, but an exploit that writes an instruction stream
 into the buffer and attempts to transfer control to those instructions will
 fail, because memory protection will prohibit instruction execution from that
 area of memory.

 Many applications never execute from the memory even though they unnecessarily
 request write-execute memory directly or as a result of an underlying function
 acting on their behalf.  By substituting writable memory for the requested
 write-execute memory, the eeeexxxxeeeeccccuuuuttttaaaabbbblllleeee____ddddaaaattttaaaa tunable allows such applications to
 benefit from the additional protection without requiring application
 modification.  See ssssyyyyssss____aaaattttttttrrrrssss____pppprrrroooocccc(5) for more information.

 Before enabling eeeexxxxeeeeccccuuuuttttaaaabbbblllleeee____ddddaaaattttaaaa (changing it from the default value of 0), you
 must run the ////uuuussssrrrr////ssssbbbbiiiinnnn////jjjjaaaavvvvaaaaeeeexxxxeeeeccccuuuutttteeeeddddaaaattttaaaa script.  Otherwise, privileged Java
 applications will fail in unpredictable ways.  See jjjjaaaavvvvaaaaeeeexxxxeeeeccccuuuutttteeeeddddaaaattttaaaa(8) for more
 information.

 _N_o_t_e

 The Java language interprets bytecode at run time.  Unless marked as exempt,
 privileged applications written in Java will receive an error when they
 attempt to execute instructions residing in the unexecutable memory.  The
 manner in which these errors are handled is application specific and thus
 unpredictable.  This is why you must run the ////uuuussssrrrr////ssssbbbbiiiinnnn////jjjjaaaavvvvaaaaeeeexxxxeeeeccccuuuutttteeeeddddaaaattttaaaa before
 you enable eeeexxxxeeeeccccuuuuttttaaaabbbblllleeee____ddddaaaattttaaaa.

 The following example demonstrates the failing behavior to expect for a
 privileged processes if eeeexxxxeeeeccccuuuutttteeee____ddddaaaattttaaaa is set to 53 but runs the
 ////uuuussssrrrr////ssssbbbbiiiinnnn////jjjjaaaavvvvaaaaeeeexxxxeeeeccccuuuutttteeeeddddaaaattttaaaa script.  Other Java applications run with privilege
 may exhibit different (but still failing) behavior.

 # java -classic -jar SwingSet2.jar
 Process 1185 Invalid write/execute mmap call denied.
 Process 1185 Invalid write/execute mmap call denied.
 Process 1185 Invalid write/execute mmap call denied.
 (...)
 Process 1185 Invalid write/execute mmap call denied.
 Process 1185 Invalid write/execute mmap call denied.
 **Out of memory, exiting**

 The following example demonstrates the failing behavior to expect for a
 privileged processes if eeeexxxxeeeeccccuuuutttteeee____ddddaaaattttaaaa is set to 37 but runs the
 ////uuuussssrrrr////ssssbbbbiiiinnnn////jjjjaaaavvvvaaaaeeeexxxxeeeeccccuuuutttteeeeddddaaaattttaaaa script.  Other Java applications run with privilege
 may exhibit different (but still failing) behavior.

 # java -classic -jar SwingSet2.jar
 Process 1185 Invalid write/execute mmap call modified.
 Process 1185 Invalid write/execute mmap call modified.
  (...)
 Process 1185 Invalid write/execute mmap call modified.



                                              Tru64 UNIX Patches 1-9








 Process 1185 Invalid write/execute mmap call modified.
 Process 1185 Invalid write/execute mmap call modified.
 SIGSEGV   11*  segmentation violation
 (...)
 Abort (core dumped)

 Certain privileged Pascal programs may also fail when eeeexxxxeeeeccccuuuuttttaaaabbbblllleeee____ddddaaaattttaaaa is
 enabled.  Such programs should also be marked as exempt, using the new cccchhhhaaaattttrrrr
 utility, included in Patch 872.00 and described as follows:

 $chatr +ed enable priv_pascal_executable
   current values:
      64-bit COFF executable
      execute from data: disabled
   new values:
      64-bit COFF executable
      execute from data: enabled

 For more information see cccchhhhaaaattttrrrr(1).


 _1._1._6._2  _C_h_a_n_g_e_s _t_o _t_a_r, _p_a_x, _a_n_d _c_p_i_o _B_e_h_a_v_i_o_r &#_1_5_1; _P_a_t_c_h _2_0_8_8._0_0

 When extracting or listing an archive using the ttttaaaarrrr, ppppaaaaxxxx, or ccccppppiiiioooo commands,
 specifying a slash (/) at the end of argument will cause the command to act
 upon the directory and not the contents in the directory.  For example:

 # ttttaaaarrrr xxxxvvvvffff ffffiiiilllleeeennnnaaaammmmeeee....ttttaaaarrrr ddddiiiirrrr1111////

 When creating an archive with these commands, specifying multiple slashes will
 result in the placement of one slash for any directory entry in the archive
 header.  Previously, specifying multiple slashes would put these slashes in
 the archive header.  For example:

 # ttttaaaarrrr ccccvvvvffff ffffiiiilllleeeennnnaaaammmmeeee....ttttaaaarrrr ddddiiiirrrr1111////////////////////////////////////////

 Specifying a single slash when creating the archive will cause ttttaaaarrrr, ppppaaaaxxxx, or
 ccccppppiiiioooo to pick up all of the directory's contents.  For example:

 # ttttaaaarrrr ccccvvvvffff ffffiiiilllleeeennnnaaaammmmeeee....ttttaaaarrrr ddddiiiirrrr1111////



 _1._1._6._3  _I_g_n_o_r_e _S_p_e_c_i_a_l _I_n_s_t_r_u_c_t_i_o_n _f_o_r _P_a_t_c_h _1_9_2_4._0_0

 When installing this kit, the dddduuuuppppaaaattttcccchhhh utility incorrectly indicates a Special
 Instruction for Patch 1924.00.  You can safely disregard this notice.


 _1._1._6._4  _R_u_s_s_i_a_n _K_e_y_b_o_a_r_d &#_1_5_1; _P_a_t_c_h _1_1_9_7._0_0

 The Russian 3R-LKQ48-BT keyboard, for which Patch 1197.00 provides an updated
 keyboard map, comes with five extra keycaps.  To enable any of those extra
 keycaps, you will need to modify the file



 1-10 Tru64 UNIX Patches








 ////uuuussssrrrr////lllliiiibbbb////XXXX11111111////xxxxkkkkbbbb////ssssyyyymmmmbbbboooollllssss////ddddiiiiggggiiiittttaaaallll////rrrruuuussssssssiiiiaaaannnn.  For example:

 //    KEY  can be replaced by an extra keycap.
 //    If you replace it with the extra keycap, please uncomment
 //    the following definition and comment out the original one.
 //
 //    key  {
 //      symbols[Group1]=3D [               o,               O ],
 //      symbols[Group2]=3D [     Ukrainian_i,     Ukrainian_I ]
 //    };
     key  {
         symbols[Group1]=3D [               o,               O ],
         symbols[Group2]=3D [  Cyrillic_shcha,  Cyrillic_SHCHA ]
     };






 _1._1._7  _P_r_o_b_l_e_m _S_e_e_n _o_n _S_y_s_t_e_m_s _w_i_t_h _S_m_a_r_t _A_r_r_a_y _C_o_n_t_r_o_l_l_e_r

 This section describes the steps you should take if your system is configured
 with a Smart Array controller and you see the following event logged.

 Host name: unx104
 SCSI CAM ERROR PACKET
 SCSI device class: CISS (Smart Array)
 Bus Number: 6
 Target Number: 4
 Lon Number: 0
 \&...
 \&...
 Event Information:  Command timed out...resetting controller




 If this occurs, take the following steps:


 1. Create a file named cccciiiissssssss....tttteeeemmmmpppp with the following lines:

    ciss:
    ciss_throttle_threshold=5



 2. Execute the following command:

    # ssssyyyyssssccccoooonnnnffffiiiiggggddddbbbb ----mmmm ----ffff cccciiiissssssss....tttteeeemmmmpppp


 3. Reboot your system:



                                             Tru64 UNIX Patches 1-11








    # sssshhhhuuuuttttddddoooowwwwnnnn ----rrrr nnnnoooowwww





 _1._1._8  _P_r_o_b_l_e_m _w_i_t_h _l_o_c_k_m_o_d_e=_4 _o_n _A_l_p_h_a_S_e_r_v_e_r_s _w_i_t_h _Q_L_o_g_i_c _S_C_S_I _D_i_s_k
        _C_o_n_t_r_o_l_l_e_r_s

 When an AlphaServer GS Series system with a QLogic SCSI disk controller is set
 to lockmode=4, the system may panic on boot.  We will provide a fix for this
 in the near future.


 _1._1._9  _U_p_d_a_t_e_s _t_o _s_y_s__c_h_e_c_k

 This section describes updates to the ssssyyyyssss____cccchhhheeeecccckkkk command.  See Section A.2 for
 the revised ssssyyyyssss____cccchhhheeeecccckkkk reference page.


 _1._1._9._1  _T_M_P_D_I_R _V_a_r_i_a_b_l_e

 If the TMPDIR environment variable is not defined, then ssssyyyyssss____cccchhhheeeecccckkkk ----eeeessssccccaaaallllaaaatttteeee
 will always put the eeeessssccccaaaallllaaaatttteeee....ttttaaaarrrr files in ////vvvvaaaarrrr////ttttmmmmpppp even if you specify an
 alternate directory.  To work around this problem, you must first set and
 export the TMPDIR environment variable to the directory where you want
 ssssyyyyssss____cccchhhheeeecccckkkk to put the eeeessssccccaaaallllaaaatttteeee....ttttaaaarrrr files.  For example, if you want ssssyyyyssss____cccchhhheeeecccckkkk
 to put the eeeessssccccaaaallllaaaatttteeee....ttttaaaarrrr files in ////vvvvaaaarrrr////aaaaddddmmmm, then you must execute the following
 commands before running ssssyyyyssss____cccchhhheeeecccckkkk ----eeeessssccccaaaallllaaaatttteeee.

 # kkkksssshhhh
 # eeeexxxxppppoooorrrrtttt TTTTMMMMPPPPDDDDIIIIRRRR====////vvvvaaaarrrr////aaaaddddmmmm
 # ssssyyyyssss____cccchhhheeeecccckkkk ----eeeessssccccaaaallllaaaatttteeee



 _1._1._9._2  _s_y_s__c_h_e_c_k _V_e_r_s_i_o_n _1_2_5 _W_e_b _K_i_t

 The following information is for users who have installed ssssyyyyssss____cccchhhheeeecccckkkk Version
 125 Web kit or higher and are currently using that version of ssssyyyyssss____cccchhhheeeecccckkkk in the
 Web kit as the system default version.

 This patch kit contains ssssyyyyssss____cccchhhheeeecccckkkk Version 124.  If you have already installed
 the ssssyyyyssss____cccchhhheeeecccckkkk Version 125 Web kit or higher, then installing this patch kit
 will downgrade the version of ssssyyyyssss____cccchhhheeeecccckkkk that is being used by the system.
 However, you can easily set the system default back to the version of
 ssssyyyyssss____cccchhhheeeecccckkkk that you downloaded from the Web by using the
 ////uuuussssrrrr////ssssbbbbiiiinnnn////uuuusssseeee____ssssyyyyssss____cccchhhheeeecccckkkk script.  For example, type uuuusssseeee____ssssyyyyssss____cccchhhheeeecccckkkk 111122225555 at the
 command line prompt to set ssssyyyyssss____cccchhhheeeecccckkkk Version 125 as the system default.

 If you wish to delete the ssssyyyyssss____cccchhhheeeecccckkkk patch (that is, ssssyyyyssss____cccchhhheeeecccckkkk Version 124)
 then you should make sure that Version 124 is the system default version
 before deleting the patch.  You can verify this by examining the output of the
 ssssyyyyssss____cccchhhheeeecccckkkk ----vvvv command.  If 124.0 is not the default version, then you should



 1-12 Tru64 UNIX Patches








 run the ////uuuussssrrrr////ssssbbbbiiiinnnn////uuuusssseeee____ssssyyyyssss____cccchhhheeeecccckkkk 111122224444 command to set the system default version
 of ssssyyyyssss____cccchhhheeeecccckkkk to version 124.  Setting the system default to 124 ensures that
 the Version 124 ssssyyyyssss____cccchhhheeeecccckkkk files are removed when the patch is deleted.

 After you delete the patch, the system default version of ssssyyyyssss____cccchhhheeeecccckkkk will
 automatically be set to the version of ssssyyyyssss____cccchhhheeeecccckkkk that you downloaded from the
 Web.  This is because dddduuuuppppaaaattttcccchhhh saves the symbolic links that point to the Web
 kit location when the patch gets installed and will restore these symbolic
 links when the patch gets deleted.

 If you delete the patch and the system default version is not set to 124, then
 Version 124 will remain on the system because ssssyyyyssss____cccchhhheeeecccckkkk Version 124 has been
 backed up by the Web kit (for example, ////uuuussssrrrr////ssssbbbbiiiinnnn////ssssyyyyssss____cccchhhheeeecccckkkk....111122224444....0000).

 You will encounter problems if you delete the ssssyyyyssss____cccchhhheeeecccckkkk Web kit and then
 delete this patch kit, because dddduuuuppppaaaattttcccchhhh will restore the symbolic links to the
 Web kit location when the patch is deleted.  If you have deleted the Web kit,
 then the symbolic links will point to non-existent files.  You can fix this
 problem by reinstalling the ssssyyyyssss____cccchhhheeeecccckkkk Web kit.


 _1._1._1_0  _S_u_p_p_o_r_t _f_o_r _S_D_L_T_1_6_0 _T_a_p_e _D_e_v_i_c_e

 You must add the following entries in the ////eeeettttcccc////ddddddddrrrr....ddddbbbbaaaasssseeee and then run
 ////ssssbbbbiiiinnnn////ddddddddrrrr____ccccoooonnnnffffiiiigggg for the new SDLT160 tape device to be recognized.


 1. Add the following to ////eeeettttcccc////ddddddddrrrr....ddddbbbbaaaasssseeee:

    scsi_density_table_size = 0x4a

        scsi_tape_density[0x42] =   "density_code_42"       0           0
        scsi_tape_density[0x43] =   "density_code_43"       0           0
        scsi_tape_density[0x44] =   "density_code_44"       0           0
        scsi_tape_density[0x45] =   "density_code_45"       0           0
        scsi_tape_density[0x46] =   "density_code_46"       0           0
        scsi_tape_density[0x47] =   "density_code_47"       0           0
        scsi_tape_density[0x48] =   "131000_bpi"            131000      0
        scsi_tape_density[0x49] =   "190000_bpi"            190000      0

    SCSIDEVICE
        #
        # Matches SDLT320
        #
        Type = tape
        Name = "COMPAQ" "SDLT320"
        #
        #
        PARAMETERS:
            TypeSubClass        = tk
            TagQueueDepth       = 0
            MaxTransferSize     = 0x0fffffb         # (16MB - 4)
            ReadyTimeSeconds    = 120               # seconds




                                             Tru64 UNIX Patches 1-13








        DENSITY:
            #
            DensityNumber = 0
            DensityCode = 0x48
            CompressionCode = 0x1
            Buffered = 0x1

        DENSITY:
            #
            DensityNumber = 1,5
            DensityCode = default
            CompressionCode = 0x1
            Buffered = 0x1

        DENSITY:
            #
            DensityNumber = 2,4,6,7
            DensityCode = default
            CompressionCode = 0x0
            Buffered = 0x1

        DENSITY:
            #
            DensityNumber = 3
            DensityCode = 0x48
            CompressionCode = 0x0
            Buffered = 0x1


 2. Run ////ssssbbbbiiiinnnn////ddddddddrrrr____ccccoooonnnnffffiiiigggg (see ddddddddrrrr____ccccoooonnnnffffiiiigggg(8) for more information).




 _1._1._1_0._0._1  _N_e_w _l_i_b_o_t_s_3 _L_i_b_r_a_r_y &#_1_5_1; _P_a_t_c_h_e_s _1_1_4_6._0_0 _a_n_d _1_1_4_8._0_0 - Patches
 1146.00 and 1148.00 deliver version V2.0-094d of the lllliiiibbbboooottttssss3333 library.  If your
 system has the Compaq FORTRAN Compiler, the Developer's Tool Kit (DTK)
 (OTABASE subset), or a patch that installs a newer version of this library, do
 not apply this patch.  If a new revision of the lllliiiibbbboooottttssss3333 library is already
 installed on your system, and you install this patch, you will receive the
 following informational message:

 Problem installing:

 - Tru64_UNIX_V5.1A / Threads Patches

       Patch 00xxx.00 - Shared libots3 library fix


        ./usr/shlib/libots3.so:

                  is installed by:

                                  OTABASE212



 1-14 Tru64 UNIX Patches








                and cannot be replaced by this patch.

 This patch will not be installed.

 To determine what version of the lllliiiibbbboooottttssss3333 library is installed on your system,
 enter the following command:

 # wwwwhhhhaaaatttt ////uuuussssrrrr////sssshhhhlllliiiibbbb////lllliiiibbbboooottttssss3333....ssssoooo lllliiiibbbboooottttssss3333....ssssoooo::::

 libots3.a       V2.0-094 GEM 27 Feb 2001



 _1._1._1_0._1  _N_e_w _e_s_m_d _D_a_e_m_o_n &#_1_5_1; _P_a_t_c_h _2_5_2._0_0

 The Essential Services Monitor (ESM) daemon, eeeessssmmmmdddd, improves the availability
 of essential system daemons by automatically restarting them if they
 terminate.  The daemon monitors the Event Manager daemon, eeeevvvvmmmmdddd, and in a
 cluster environment, the CAA daemon, ccccaaaaaaaadddd.  Restart activity is reported in
 the ssssyyyysssslllloooogggg ddddaaaaeeeemmmmoooonnnn....lllloooogggg file.


 _1._1._1_0._2  _C_o_m_m_a_n_d _U_p_d_a_t_e_s _a_n_d _O_t_h_e_r _C_h_a_n_g_e_s &#_1_5_1; _P_a_t_c_h _2_0_8_4._0_0

 The following sections describe updates to commands delivered in Patch
 2084.00.


 _1._1._1_0._3  _U_p_d_a_t_e_s _t_o _s_h, _c_s_h, _a_n_d _k_s_h

 The updated shells in this kit all implement the following changes when
 processing shell inline input files:


 +o  File permissions allow only read and write for owner.

 +o  If excessive inline input file name collisions occur, the following error
    message will be returned:

    UUUUnnnnaaaabbbblllleeee ttttoooo ccccrrrreeeeaaaatttteeee tttteeeemmmmppppoooorrrraaaarrrryyyy ffffiiiilllleeee




 _1._1._1_0._4  _s_h _n_o_c_l_o_b_b_e_r _O_p_t_i_o_n _a_n_d >| , >>| _C_o_n_s_t_r_u_c_t_s _A_d_d_e_d

 A nnnnoooocccclllloooobbbbbbbbeeeerrrr option similar to that already available with ccccsssshhhh and kkkksssshhhh has been
 added to the Bourne shell.

 When the nnnnoooocccclllloooobbbbbbbbeeeerrrr option is used (sssseeeetttt ----CCCC), the shell behavior for the
 redirection operators >>>> and >>>>>>>> changes as follows:


 +o  For >>>> with nnnnoooocccclllloooobbbbbbbbeeeerrrr set, sssshhhh will return an error rather than overwrite an



                                             Tru64 UNIX Patches 1-15








    existing file.  If the specified file name is actually a symbolic link, the
    presence of the symbolic link satisfies the criteria ffffiiiilllleeee eeeexxxxiiiissssttttssss whether or
    not the symbolic link target exists and sssshhhh returns an error.  The >>>>||||
    construct will suppress these checks and create the file.

 +o  For >>>>>>>> with nnnnoooocccclllloooobbbbbbbbeeeerrrr set, output is appended to the tail of an existing
    file.  If the file name is actually a symbolic link whose target does not
    exist, sssshhhh returns an error rather than create the file.  The >>>>>>>>|||| construct
    will suppress these checks and create the file.




 _1._1._1_0._5  _k_s_h _n_o_c_l_o_b_b_e_r _B_e_h_a_v_i_o_r _C_l_a_r_i_f_i_e_d

 For >>>> with nnnnoooocccclllloooobbbbbbbbeeeerrrr set, kkkksssshhhh will return an error rather than overwrite an
 existing file.  If the specified file name is actually a symbolic link, the
 presence of the symbolic link satisfies the criteria ffffiiiilllleeee eeeexxxxiiiissssttttssss whether or
 not the symbolic link target exists and kkkksssshhhh returns an error.  The >>>>||||
 construct will suppress these checks and create the file.

 For >>>>>>>> with nnnnoooocccclllloooobbbbbbbbeeeerrrr set, output is appended to the tail of an existing file.
 If the file name is actually a symbolic link to a nonexistent file, kkkksssshhhh
 returns an error.  This is a behavior change.  Because kkkksssshhhh does not have a >>>>>>>>||||
 redirection override, create the symbolic link target before accessing it
 through >>>>>>>> if you depend upon appending through a symbolic link.


 _1._1._1_0._6  _c_s_h _n_o_c_l_o_b_b_e_r _B_e_h_a_v_i_o_r _C_l_a_r_i_f_i_e_d

 For >>>> with nnnnoooocccclllloooobbbbbbbbeeeerrrr set, ccccsssshhhh will return an error rather than overwrite an
 existing file.  If the specified file name is actually a symbolic link, the
 presence of the symbolic link satisfies the criteria ffffiiiilllleeee eeeexxxxiiiissssttttssss whether or
 not the symbolic link target exists, and ccccsssshhhh returns an error.  The >>>>||||
 construct will suppress these checks and create the file.

 For >>>>>>>> with nnnnoooocccclllloooobbbbbbbbeeeerrrr set, output is appended to the tail of an existing file.
 If the file does not exist, or the file name is actually a symbolic link whose
 target does not exist, ccccsssshhhh returns an error rather than create the file.  The
 >>>>>>>>||||construct will suppress these checks and create the file.


 _1._1._1_0._7  _U_p_d_a_t_e_d _m_k_d_i_r _S_y_s_t_e_m _C_a_l_l _a_n_d _C_o_m_m_a_n_d

 This kit reverts the mmmmkkkkddddiiiirrrr system call, and thus the mmmmkkkkddddiiiirrrr command, to its
 Tru64 UNIX Version 4.n behavior with respect to symbolic links.  For the
 unusual case where a symbolic link is used as the very last element of a mmmmkkkkddddiiiirrrr
 path, the mmmmkkkkddddiiiirrrr system call now returns an error rather than create the
 target.

 If you want mmmmkkkkddddiiiirrrr to follow the symbolic link you can do so by making the last
 character of the mmmmkkkkddddiiiirrrr pathname a slash.  For example, if ////vvvvaaaarrrr////ttttmmmmpppp////ffffoooooooo is a
 symbolic link to ////uuuussssrrrr////xxxxxxxxxxxx, which does not exist, then
 mmmmkkkkddddiiiirrrr((((""""////vvvvaaaarrrr////ttttmmmmpppp////ffffoooooooo"""",,,,0000777755555555)))) will return an error but



 1-16 Tru64 UNIX Patches








 mmmmkkkkddddiiiirrrr((((""""////vvvvaaaarrrr////ttttmmmmpppp////ffffoooooooo////"""",,,,0000777755555555)))) will create ////uuuussssrrrr////xxxxxxxxxxxx.

 The behavior of mmmmkkkkddddiiiirrrr can also be controlled systemwide by an addition to the
 ssssyyyyssssccccoooonnnnffffiiiigggg options for the vvvvffffssss subsystem.  The new ssssyyyyssssccccoooonnnnffffiiiigggg option
 ffffoooolllllllloooowwww____mmmmkkkkddddiiiirrrr____ssssyyyymmmmlllliiiinnnnkkkkssss defaults to 0, specifying the secure symbolic link
 behavior.  Changing this option to 1, which we strongly discourage, will cause
 mmmmkkkkddddiiiirrrr to follow symbolic links.


 _1._1._1_0._8  _E_n_a_b_l_i_n_g _t_h_e /_d_e_v/_p_o_l_l _F_u_n_c_t_i_o_n

 In order to enable the ////ddddeeeevvvv////ppppoooollllllll function the special device ppppoooollllllll must be
 created manually.  The procedure is as follows:


 1. Change your directory to ////ddddeeeevvvv:

    # ccccdddd ////ddddeeeevvvv

 2. Execute the MAKEDEV script, found in that directory with either ppppoooollllllll or ssssttttdddd
    as an argument:

    # MMMMAAAAKKKKEEEEDDDDEEEEVVVV [poll or std]




 _1._1._1_0._9  _R_e_m_o_v_a_l _o_f _V_e_r_s_i_o_n-_S_w_i_t_c_h_e_d _P_a_t_c_h

 This patch provides a script, ////uuuussssrrrr////ssssbbbbiiiinnnn////eeeevvvvmmmm____vvvveeeerrrrsssswwww____uuuunnnnddddoooo, that allows you to
 remove the EVM patch after the version switch has been thrown by running
 cccclllluuuu____uuuuppppggggrrrraaaaddddeeee ----sssswwwwiiiittttcccchhhh.  This script will set back the version identifiers and
 request a cluster shutdown and reboot to finish the deletion of the patch.
 Another rolling upgrade will be required to delete the patch with dddduuuuppppaaaattttcccchhhh.

 _N_o_t_e

 Because the removal of a version-switched patch requires a cluster shutdown,
 only run this script when you are absolutely sure that this patch is the cause
 of your problem.

 This script must be run by root in multiuser mode after completing the rolling
 upgrade that installed the patch and before starting another rolling upgrade.
 The final removal of the patch can only be accomplished by rebooting the
 system or cluster after this script completes its processing.  This script
 will offer to shut down your system or cluster at the end of its processing.
 If you choose to wait, it is your responsibility to execute the shutdown of
 the system or cluster.

 Do not forget or wait for an extended period of time before shutting down the
 cluster.  Cluster members that attempt to reboot before the entire cluster is
 shut down can experience panics or hangs.





                                             Tru64 UNIX Patches 1-17








 _1._1._1_0._1_0  _N_e_w _e_e _A_t_t_r_i_b_u_t_e

 This patch adds a new eeeeeeee subsystem attribute, lllliiiinnnnkkkk____cccchhhheeeecccckkkk____iiiinnnntttteeeerrrrvvvvaaaallll, that allows
 the eeeeeeee driver link state polling interval to be tuned for faster failover
 times when using eeeeeeee devices for Link Aggregation.  Patch 1717.00 updates the
 ssssyyyyssss____aaaattttttttrrrrssss____eeeeeeee(5) reference page.


 _1._1._1_0._1_1  _S_u_p_p_o_r_t _f_o_r _N_e_t_w_o_r_k _L_i_n_k _A_g_g_r_e_g_a_t_i_o_n

 This patch enables support for network link aggregation, which can provide
 increased network bandwidth and availability.  Two or more physical Ethernet
 ports can be combined to create a link aggregation group, which is seen by
 upper-layer software as a single logical network interface.

 See the _N_e_t_w_o_r_k _A_d_m_i_n_i_s_t_r_a_t_i_o_n: _C_o_n_n_e_c_t_i_o_n_s manual for information on
 configuring link aggregation groups.  See llllaaaagggg(7) and llllaaaaggggccccoooonnnnffffiiiigggg(8) for more
 information about link aggregation.  Patch 1651.00 updates the llllaaaagggg(7)
 reference page and Patch 1755.00 updates the llllaaaaggggccccoooonnnnffffiiiigggg(8) reference page.


 _1._2  _S_u_m_m_a_r_y _o_f _B_a_s_e _O_p_e_r_a_t_i_n_g _S_y_s_t_e_m _P_a_t_c_h_e_s

 This section provides brief descriptions of the patches in Patch Kit 6 for the
 Tru64 UNIX operating system.  Because Tru64 UNIX patch kits are cumulative,
 each patch lists its state according to the following criteria:


 +o  New

    Indicates a patch that is new for this release.

 +o  New (Supersedes Patches ...  )

    Indicates a patch that is new to the kit but was combined (merged) with one
    or more patches during the creation of earlier versions of this kit, before
    it was publicly released.

 +o  Existing (Kit 5)

    Indicates a patch that was new in the indicated Version 5.1A patch kit.

 +o  Existing

    Indicates a patch that was introduced in Patch Kit 1 or Patch Kit 2.

 +o  Supersedes Patches ...

    Indicates a patch that was combined (merged) with other patches.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 65.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for Compaq C compiler and Compaq driver



 1-18 Tru64 UNIX Patches








 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes the following problems in the Compaq C compiler and Compiler driver:


    -  A compiler problem that caused a run-time failure in specific code that
       involved floating point arguments and varargs.

    -  A problem in the driver that failed to produce an object file for a
       command such as file.s -o file.o.

    -  A problem in the driver that would not allow a command line that
       contained only the -l library and no source or object files.

    -  A problem in the driver that failed to produce an object file when no
       output file was specified on the command line.



 NNNNuuuummmmbbbbeeeerrrr:::: Patch 86.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for Korn shell hang

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem where the Korn shell (ksh) could hang if you pasted a large
    number of commands to it when it was running in a terminal emulator window
    (such as an xterm).


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 117.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for evmget command

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a situation in which the evmget command and the event log nightly
    cleanup operation may fail with an "arg list too long" message.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 108.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a potential race deadlock

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a potential race deadlock between vclean/ufs_reclaim and
    quotaon/quotaoff when quota is enabled.





                                             Tru64 UNIX Patches 1-19








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 123.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects a memory leak in the XTI socket code

 SSSSttttaaaatttteeee:::: Existing


 +o  Corrects a memory leak in the XTI socket code.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 143.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Allows dxsetacl utility to delete access ACLs

 SSSSttttaaaatttteeee:::: Existing


 +o  Allows the dxsetacl utility to delete access ACLs.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 145.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0638U)

 SSSSttttaaaatttteeee:::: Existing


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of root directory compromise via lpr using X11.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 154.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0682U)

 SSSSttttaaaatttteeee:::: Existing


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 156.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes problems which prevented envmond from starting

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes problems which prevented envmond from starting.





 1-20 Tru64 UNIX Patches








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 169.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem in latsetup

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in latsetup when the directory /dev/lat is not found.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 171.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem in diskconfig

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in diskconfig where partitions with an offset and size of
    zero cannot be selected.  It also fixes a problem where overlapping
    partitions cannot be adjusted if the existing partitions are not in
    alphabetical order.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 173.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for ELSA Gloria Synergy, PS4D10, JIB graphic card

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem where, on the ELSA GLoria Synergy, PS4D10, and JIB graphic
    cards, the cursor position is not being updated properly.  The placement of
    the cursor is one request behind


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 185.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects a problem in the rdist utility

 SSSSttttaaaatttteeee:::: Existing


 +o  Corrects a problem in the rdist utility which was causing segmentation
    faults on files with more than one link.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 189.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for no rerouting problem on a CFS server

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem where pulling the network cable on one node acting as a CFS



                                             Tru64 UNIX Patches 1-21








    server in a cluster causes no rerouting to occur.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 210.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes problems with X server X Image Extension (XIE)

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes problems with the X server X Image Extension (XIE).


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 212.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem of the ATM setup script failing

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem of the ATM setup script failing when configuring an elan if
    the lane subsystem is not loaded.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 224.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: The joind server may fail to clean up its lock files

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem where joind may fail to clean up its lock files in
    /var/join.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 238.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for dxsetacl utility

 SSSSttttaaaatttteeee:::: Existing


 +o  Allows the dxsetacl utility to delete access ACLs.


 NNNNuuuummmmbbbbeeeerrrr:::: 245.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem in the strtod routine

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in which strtod() was returning different outputs for the
    same input.



 1-22 Tru64 UNIX Patches








 +o  Fixes a problem in which the tan() function was returning the wrong
    results.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 252.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Adds Essential Services Monitor daemon (esmd)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Provides enablers for the Compaq Database Utility.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 259.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Removes extraneous header comments

 SSSSttttaaaatttteeee:::: Existing


 +o  Removes extraneous history edit comments from exported DECthreads header
    files.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 281.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for NHD kit installations

 SSSSttttaaaatttteeee:::: Existing


 +o  Corrects a problem that occurs during the installation of a New Hardware
    Device (NHD) kit, in which the version.id file was not properly referenced
    thereby causing the installation to fail.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 311.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Quick Setup erroneously reports daemons do not start

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem that occurs on some systems, notably an AlphaStation DS10
    system, in which Quick Setup may erroneously report that some daemons did
    not start.  Subsequent attempts result in error messages that report on the
    existence of duplicate host names.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 327.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes C++ incompatibility




                                             Tru64 UNIX Patches 1-23








 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes C++ incompatibility in three files in /usr/include/alpha/hal/ and one
    file in /usr/include/io/common/.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 414.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem in stdio.h

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in where the interface renaming conditionals for fgetpos()
    and fsetpos() were mismatched.  It also fixes a problem in where the
    ftime() prototype was not available in the default compilation name space.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 416.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem in sys/timeb.h

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in where the interface renaming conditionals for fgetpos()
    and fsetpos() were mismatched.  It also fixes a problem in where the
    ftime() prototype was not available in the default compilation name space.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 428.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for evmwatch termination problem

 SSSSttttaaaatttteeee:::: Supersedes Patches 164.00 and 257.00


 +o  Resolves a memory leak and a filtering issue in the Event Manager, and
    allows the evmwatch utility to reconnect automatically if evmd fails and is
    restarted.

 +o  Fixes a problem in which binary error log (binlog) events posted by the EMX
    FibreChannel driver and the system console are reported incorrectly by the
    Event Manager, EVM.

 +o  Resolves an issue which can cause an Event Manager (EVM) client or the EVM
    daemon to core dump under rare circumstances.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 446.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)




 1-24 Tru64 UNIX Patches








 SSSSttttaaaatttteeee Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 453.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for dtgreet application

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in which after installing DCE, enabling SIA would cause a
    core dump and the greeter window does not come up.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 455.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for lsmsa product

 SSSSttttaaaatttteeee:::: Existing


 +o  Addresses a problem in the display of disk controller to disk hierarchy by
    the lsmsa product.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 457.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for broken symbolic links in /usr/lib/X11

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem where three symbolic links in /usr/lib/X11 pointed to
    nonexistent directories.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 459.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Symbolic links point to nonexistent directories

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in which three symbolic links in /usr/lib/X11 point to
    nonexistent directories.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 465.00




                                             Tru64 UNIX Patches 1-25








 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for Elsa Gloria Comet card

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in which the Elsa Gloria Comet card does not correctly draw
    nested shaded boxes or anything similar.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 467.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for accessx beeping functionality

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in which a beep does not occur when requested when the
    toggle keys option is enabled via accessx.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 481.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee:::: Existing


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 485.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for C++ compile problem

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a C++ compile problem in /usr/include/X11/Xlib.h.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 490.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for class scheduler failure

 SSSSttttaaaatttteeee:::: Supersedes Patch 183.00


 +o  Fixes a class scheduler semaphore race condition.

 +o  Causes the automatic detection of a nonexistent semaphore and allocates a
    new one, thus allowing the class scheduler to proceed without interruption.
    The class scheduler depends on semaphores to protect its database from



 1-26 Tru64 UNIX Patches








    simultaneous updates.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 500.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes libXm.so incompatability

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes an libXm.so incompatibility.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 519.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes the C++ incompatibility with pwrmgr.h

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes the C++ incompatibility of /usr/include/dec/pwrmgr/pwrmgr.h.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 525.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0779U)

 SSSSttttaaaatttteeee:::: Existing


 +o  Corrects a potential security vunerability where, under certain
    circumstances, SNMP services can stop functioning.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 527.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0779U)

 SSSSttttaaaatttteeee:::: Existing


 +o  Corrects a potential security vunerability where, under certain
    circumstances, SNMP services can stop functioning.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 531.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for KMF caused by malformed IPv4-in-IPv4 packets

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Corrects a condition in which a system configured with the IPTUNNEL kernel
    option will crash if it receives a corrupted IPv6-in-IPv4 packet, even if



                                             Tru64 UNIX Patches 1-27








    the system is not running IPv6.  The system will panic with the message
    "kernel memory fault in ip6ip4_input()."

 +o  Fixes a kernel memory fault caused by malformed IPv4-in-IPv4 packets.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 533.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for od command

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in which an invalid character sequence causes the od
    command to hang or display a partial character.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 535.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for balance utility

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes problem in which the balance utility terminated before balancing the
    whole domain when the domain was very large (greater than 4 GB).


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 537.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-48U)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.  These may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 545.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes EVMs periodic channel monitoring function

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in which the Event Manager's channel monitoring function is
    temporarily disabled if the evmreload command is run.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 551.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes an ATM signaling problem



 1-28 Tru64 UNIX Patches








 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes an ATM signaling problem.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 553.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: EVM daemon fails to find user-defined templates

 SSSSttttaaaatttteeee:::: Existing


 +o  Resolves a problem with the Event Manager (EVM) where user-defined events
    are not posted in a semirolled cluster.  The Event Manager daemon fails to
    find user-defined templates in /usr/share/evm/templates/local on
    nonupgraded nodes in a semirolled cluster.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 565.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Enabler for Compaq Database Utility

 SSSSttttaaaatttteeee:::: Supersedes Patches 179.00, 292.00


 +o  Provides enablers for the Compaq Database Utility.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 569.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: CD Mastering Software

 SSSSttttaaaatttteeee:::: Existing


 +o  Provides that CD Mastering Software for DS25 systems, which do not include
    a floppy drive, but have a CD-ROM burner instead.  In order to write to
    this device, CD Mastering Software is required.  It is made up of mkisofs
    and cdrecord software.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 571.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: The savecore command prematurely terminates crash dump recovery

 SSSSttttaaaatttteeee:::: Existing


 +o  Corrects a problem where the savecore command may prematurely terminate
    crash dump recovery on partitions larger than 4 GB.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 578.00



                                             Tru64 UNIX Patches 1-29








 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for zdump utility

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in the zdump utility when time zone file names are
    specified as arguments without leading colons (:).

 +o  Fixes a regression in the -v output to display the current time.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 580.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Extended Visual Information returns incorrect info

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes a problem in which the X server's Extended Visual Information (EVI)
    extension was returning incorrect information.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 588.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for NS record syntax in named.local file

 SSSSttttaaaatttteeee:::: Existing


 +o  Fixes the NS record syntax in a named.local file.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 691.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for atexit and pthread_prefork handler crashes

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Fixes a problem with atexit() or pthread_atfork() handlers in shared
    libraries.  An application will crash when handlers in shared libaries are
    called after the libraries are dlclosed and unmapped.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 693.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.



 1-30 Tru64 UNIX Patches








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 701.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Adds the mktemp(1) reference page for the mktemp command.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 705.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Updates the mktemp(3) reference page with changed information regarding the
    mktemp() and mkstemp() routines, and adds information about the mkdtemp()
    and mkstemps() libc routines.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 711.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for shfragbf

 SSSSttttaaaatttteeee:::: Existing


 +o  Clarifies the output of shfragbf, an AdvFS utility.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 713.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for rcinet script

 SSSSttttaaaatttteeee:::: Existing


 +o  Prevents the system from hanging when the rcinet script is used by
    correcting the order in which NetRAIN-related services are started and
    stopped.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 731.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Adds the safe_open(3) reference page for the safe_open() routine in libc.





                                             Tru64 UNIX Patches 1-31








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 733.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for Memory Channel driver problem

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Addresses a situation in which the Memory Channel device shuts down if too
    many state change interrupts are received.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 741.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Enhancement to savemeta script

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Enhances the capability of savemeta script as follows:


    -  Allows the script to be used in single user mode on a corrupt /usr
       domain.

    -  Causes all errors to return 1.



 NNNNuuuummmmbbbbeeeerrrr:::: Patch 744.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Shared library fix for libaio

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Fixes a rarely seen memory fault in libaio during aio_cancel().

 +o  Adds support for NEW_OPEN_MAX_SYSTEM (64K) file descriptors to libaio.

 +o  Prevents thread blocking forever when both libaio and libaio_raw are linked
    into the same image.

 +o  Closes an aio_read()/aio_cancel() race condition.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 747.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Static library fix for libaio

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Fixes a rarely seen memory fault in libaio during aio_cancel().




 1-32 Tru64 UNIX Patches








 +o  Adds support for NEW_OPEN_MAX_SYSTEM (64K) file descriptors to libaio.

 +o  Prevents thread blocking forever when both libaio and libaio_raw are linked
    into the same image.

 +o  Closes an aio_read()/aio_cancel() race condition.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 751.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0818U)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 753.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0818U)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 755.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0818U)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 757.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for script command

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Corrects a problem in which script would hang upon exit in a dfs
    configuration.




                                             Tru64 UNIX Patches 1-33








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 759.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: System Mgmt Station detects failing PCI adapters

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Provides the ability for the System Management Station to render PCI
    adapters with a warning or failed representation when they are in the
    indicted state.  This is in addition to the previous ability to render CPUs
    that are in the indicted state.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 761.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem in the mwm window manager

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Fixes a problem in the mwm window manager in which double-click actions are
    performed on the second button press instead of the second button release,
    thus causing the second button release event to be sent to any underlying
    window.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 763.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Adds the dirclean(8) reference page for the /usr/sbin/dirclean utility.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 765.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Provides the poll reference page

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Adds the poll(7) reference page for the /dev/poll driver.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 767.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Enhancement to fuser utility

 SSSSttttaaaatttteeee:::: Existing


 +o  Allows the fuser utility to display the reference option.  This option



 1-34 Tru64 UNIX Patches








    indicates the type of reference made; for example: open, closed, unlinked,
    or mmapped.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 769.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for su command

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Corrects the behavior of the su command so that the LOGNAME environment
    variable is changed to the target user when executed with the - option.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 771.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: lsmsa incorrectly processing passwords

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Fixes a problem where lsmsa incorrectly processes passwords that are longer
    than eight characters.  Anyone who tries to start the LSM GUI using a
    password of eight or more characters will be denied access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 773.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0795U)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form where inetd may block incoming connections when scanned by nmap or
    other port scanners.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 779.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes an xfs problem

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Fixes an xfs problem which causes a "QueryGlyphs failed" error in showfont.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 789.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for ppdof print filter core dump problem




                                             Tru64 UNIX Patches 1-35








 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Corrects a problem where the filter can core dump when the banner jobname
    contains 132 characters.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 791.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for salvage utility core dump problem

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Fixes a problem with the /sbin/advfs/salvage utility that could cause the
    utility to core dump.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 793.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for startslip program problem

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Fixes a problem where startslip was not able to extract all the information
    from the acucap file.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 795.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: A timing window can cause a hang in run_usr_cmd

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Fixes a problem in which a timing window can cause a hang in run_usr_cmd.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 801.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for convuser utility

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Fixes a problem where, if a user was working in enhanced security and then
    switched to base security, the group and other read privileges would get
    stripped from /etc/passwd.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 809.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Enables correctable error reporting from DTAGII



 1-36 Tru64 UNIX Patches








 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Enables correctable error reporting from DTAGII chips on GS320/160/80
    1.224Ghz CPU systems.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 817.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a simple_lock panic when using ATM

 SSSSttttaaaatttteeee:::: Supersedes Patchs 165.00, 167.00, 557.00


 +o  Fixes a kernel memory fault when using ATM.

 +o  Corrects a problem which could result in ATM/lane connection requests being
    dropped.

 +o  Fixes a kernel memory fault when using ATM.

 +o  Fixes a "simple_lock: time limit exceeded" panic when using ATM.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 824.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Provides the ckfsec reference page

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Delivers the ckfsec(1) reference page.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 826.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0794U)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 828.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (wc.symlink.002.spautils)

 SSSSttttaaaatttteeee:::: Existing (Kit 3)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the



                                             Tru64 UNIX Patches 1-37








    form of certain files in world-writable directories.

 +o  Provides the ckfsec utility which can help detect such files.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 830.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Incompatibility between Java 1.1.x and Java 2 1.2.x

 SSSSttttaaaatttteeee:::: Existing (Kit 3)

 This patch


 +o  Allows users of SysMan tools on the iPAQ and those who have Java 2 as their
    default Java version to communicate with Tru64 UNIX V5.1A systems.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 832.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Update to exportfs reference page

 SSSSttttaaaatttteeee::::  Existing (Kit 3)


 +o  Updates the exportfs(2) reference page with changed information regarding
    the exportfsdata structure as a result of increasing a number of file
    systems that can be NFS mounted from 256 to 1024.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 840.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Definition of XtPending was changed

 SSSSttttaaaatttteeee::::  Existing (Kit 3)


 +o  Fixes a problem where the definition of the X Toolkit function XtPending()
    was changed in Tru64 UNIX V5.1A which caused some applications built on
    earlier versions of Tru64 UNIX to fail.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 848.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.





 1-38 Tru64 UNIX Patches








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 850.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 852.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee::::  Supersedes Patch 92.00


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, users can clobber temporary files created by shell commands
    and utilities, for example under /sbin, /usr/sbin, /usr/bin, and /etc.

 +o  Fixes a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 992.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for library call used to calculate disk size

 SSSSttttaaaatttteeee::::  Supersedes Patch 844.00


 +o  Fixes a problem that prevented AdvFS from working correctly with LSM
    volumes between 1Tb and 2Tb.

 +o  Causes mkfdmn and addvol to issue a warning if an attempt is made to use an
    LSM volume greater than 2Tb.

 +o  Prevents addvol from adding invalid disks into a domain.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 994.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for problems in dsfmgr

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes many small problems in dsfmgr.





                                             Tru64 UNIX Patches 1-39








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 999.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-80U)

 SSSSttttaaaatttteeee::::  Supersedes Patches 71.00 and 997.00


 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the CDE online help.  Buffer overflows are sometimes exploited in
    an attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Fixes a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1002.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-80U)

 SSSSttttaaaatttteeee::::  Supersedes Patches 73.00 and 1000.00


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, users can clobber temporary files created by shell commands
    and utilities (that is, under /sbin, /usr/sbin, /usr/bin, and /etc).

 +o  Fixes a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1023.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes memory leak in PanoramiX/Xinerama Extension

 SSSSttttaaaatttteeee::::  Supersedes Patches 98.00, 99.00, 101.00, 439.00, 441.00, 1021.00


 +o  Provides New Hardware Delivery V4 (NHD4) enables for future hardware
    support of a graphics device.

 +o  Fixes an Xserver crash when using the GTK on systems using the Oxygen VX1
    graphics card.

 +o  Fixes an Xserver problem where, when PanoramiX is enabled and using CDE,
    icons from dtfile cannot be seen on other than the left screen while being
    moved.

 +o  Fixes a memory leak in the PanoramiX/Xinerama Extension that could cause a
    process core dump.



 1-40 Tru64 UNIX Patches








 +o  Fixes a problem with a Compaq Professional Workstation XP1000 667 MHz
    system with a PowerStorm 4D20 (PBXGB-CA) graphics card where fonts were
    sometimes drawn incorrectly.

 +o  Fixes a problem where the X Window System XGetImage() function returns
    erroneous data for displays with a depth greater than 8 when running the
    PanoramiX extension.

 +o  Corrects XCopyPlane on the Oxygen VX1 graphics card to copy only the
    requested bitplane rather than all bitplanes.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1027.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1044.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes failures under high DMA resource utilization

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a problem that can occur under high DMA resource utilization.  If
    a request for DMA resources (via dma_map_load()) fails, a stale pointer to
    freed memory is returned to the requestor, setting up the potential for a
    double free of malloc'd memory or dereferencing through that pointer,
    resulting in a panic.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1046.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1061.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2208)




                                             Tru64 UNIX Patches 1-41








 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability in routed which may allow
    nonprivileged users to gain unauthorized (root) access.  This may be in the
    form of local and remote security domain risks.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1063.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes hwmgr command to show path state correctly

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes the hwmgr command to show path state correctly.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1073.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2229)

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1075.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1087.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised compromised when a
    buffer overflow occurs in the dxterm utility.  Buffer overflows are
    sometimes exploited in an attempt to subvert the function of a privileged
    program and possibly execute commands at the elevated privileges if the



 1-42 Tru64 UNIX Patches








    program file has the setuid privilege.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1089.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised compromised when a
    buffer overflow occurs in the dxterm utility.  Buffer overflows are
    sometimes exploited in an attempt to subvert the function of a privileged
    program and possibly execute commands at the elevated privileges if the
    program file has the setuid privilege.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1091.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1093.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2339, SSRT2339)

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1095.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.





                                             Tru64 UNIX Patches 1-43








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1097.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix prevents "simple lock owned" panics

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Prevents "simple lock owned" panics.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1099.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1101.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1103.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for verify command

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes a problem whereby the verify utility would core dump if it
    encountered a specific type of metadata inconsistency.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1105.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee::::  Supersedes Patch 502.00


 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.  These may be in the



 1-44 Tru64 UNIX Patches








    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1109.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1115.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes interop problem between curses.h and esnmp.h

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes an interoperability problem between the curses.h and esnmp.h header
    files.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1117.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Correct improper file or privilege management

 SSSSttttaaaatttteeee::::  Existing


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1121.00

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Allows non-Compaq C compilers to avoid name space pollution when getting
    information about a file.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1123.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)





                                             Tru64 UNIX Patches 1-45








 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1125.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for hwmgr -show name command

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes the display for the hwmgr -show name command to align properly for
    the name field.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1127.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1129.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Update to hwmgr utility

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes a problem where, when using hwmgr to delete a component, the message
    "DELETE_COMMIT: Cannot fetch name" may be displayed on the console.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1140.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Modifies enablers for Enterprise Volume Manager

 SSSSttttaaaatttteeee::::  Supersedes Patches 199.00, 267.00, 315.00


 +o  Modifies enablers for the Enterprise Volume Manager.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1142.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0792U)

 SSSSttttaaaatttteeee::::  Existing (Kit 4)



 1-46 Tru64 UNIX Patches








 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1144.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1146.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Installs version V2.1-120 of libots3

 SSSSttttaaaatttteeee::::  Supersedes Patch 226.00


 +o  Installs version V2.1-120 of the /usr/lib/libots3.a and
    /usr/shlib/libots3.so libraries, which do the following:

    -  Fixes a problem in which the max threads clause for the SGI parallel
       interfaces is being ignored.

    -  Fixes a problem in which an OpenMP thread may hang when reaching a
       critical region and all other threads are awaiting CVs.

    -  Fixes a problem in which long-running OpenMP applications might overflow
       an internal libots3 counter, resulting in a breakdown of thread
       synchronization.



 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1148.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Installs version V2.1-120 of libots3

 SSSSttttaaaatttteeee::::  Supersedes Patch 228.00


 +o  Installs version V2.1-120 of the /usr/lib/libots3.a and
    /usr/shlib/libots3.so libraries, which do the following:


    -  Fixes a problem in which the max threads clause for the SGI parallel
       interfaces is being ignored.

    -  Fixes a problem in which an OpenMP thread may hang when reaching a



                                             Tru64 UNIX Patches 1-47








       critical region and all other threads are awaiting CVs.

    -  Fixes a problem in which long-running OpenMP applications might overflow
       an internal libots3 counter, resulting in a breakdown of thread
       synchronization.



 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1152.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Supersedes Patches 584.00, 775.00


 +o  Fixes a memory leak problem in the Window Manager.

 +o  Fixes a problem in the dtwm window manager where double-click actions are
    performed on the second button press instead of the second button release,
    which causes the second button release event to be sent to any underlying
    window.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1156.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1166.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes consvar -s bootdef_dev failure with KZPCC

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes a problem where I/O greater than 4 MB fails to KZPCC devices with the
    error ENODEV.

 +o  Fixes the problem of failed open calls to KZPCCs under heavy I/O.

 +o  Fixes consvar -s bootdef_dev failure with KZPCC.





 1-48 Tru64 UNIX Patches








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1168.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for libdix shared library

 SSSSttttaaaatttteeee:::: Supersedes Patches 76.00 and 78.00


 +o  Fixes a problem that will cause the X server to hang on rare occasions.
    Except for the mouse, everything on the desktop appears frozen.  Output
    from the ps command will show the X server using greater than 99% of the
    CPU time.

 +o  Fixes a problem that can cause CDE pop-up menus to appear on the wrong
    screen when running a multihead system with the PanoramiX extension
    enabled.

 +o  Fixes a problem that causes the reversal of black and white colors on
    screens other than screen 0 of a multihead system.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1172.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for sysconfig utility

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes a problem in which the lines in the output stream from sysconfig -Q
    can be truncated.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1175.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes core dump problem when using SysMan to configure NFS daemons in
    curses mode.

 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1183.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain



                                             Tru64 UNIX Patches 1-49








    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1185.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1187.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1192.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1197.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Provides updated keyboard map for Russian keyboard

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Provides an updated keyboard map for the Russian 3R-LKQ48-BT keyboard
    model.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1202.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security



 1-50 Tru64 UNIX Patches








 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1206.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes several potential security vulnerabilities which, under certain
    circumstances, could compromise system integrity.  These may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1208.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee::::  Supersedes Patch 573.00


 +o  Fixes several potential security vulnerabilities which, under certain
    circumstances, could compromise system integrity.  These may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1210.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a simple lock fault in the floppy driver

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes a simple lock panic in the floppy driver.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1220.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Added support for DECthreads V3.18-150

 SSSSttttaaaatttteeee::::  Supersedes Patches 82.00, 420.00, 783.00, 785.00, 1218.00


 +o  Installs DECthreads V3.18-150, which is the latest support version of the
    HP POSIX Threads library for Tru64 UNIX V5.1A.  It corrects several
    problems.





                                             Tru64 UNIX Patches 1-51








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1224.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1228.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Correct improper file or privilege management

 SSSSttttaaaatttteeee::::  Existing


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1232.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2368, SSRT2368)

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1242.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: libpset shared library fix

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes a problem that would prohibit processor set exclusive use on non-
    uniform memory access (NUMA) machines.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1244.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: libpset static library fix

 SSSSttttaaaatttteeee::::  Existing (Kit 4)





 1-52 Tru64 UNIX Patches








 +o  Fixes a problem that would prohibit processor set exclusive use on non-
    uniform memory access (NUMA) machines.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1246.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1253.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1255.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1257.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1260.00




                                             Tru64 UNIX Patches 1-53








 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem in procfs

 SSSSttttaaaatttteeee::::  Supersedes Patches 216.00, 805.00, 1258.00


 +o  Fixes a kernel memory fault in procfs.mod.

 +o  Fixes a system panic from procfs ioctl user code.

 +o  Fixes a VM locking problem in procfs.

 +o  Fixes a kernel memory fault related to ioctl PIOCMAP.

 +o  Fixes a problem in procfs that, in some situations, prevents exiting
    threads from exiting.  This creates a situation where these threads simply
    spin, consuming CPU time.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1262.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 5)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1270.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for the hwmgr utility

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Makes the following changes to the hwmgr utility:


    -  Corrects an error message that is displayed when hwmgr offlines a CPU
       that has only one bound process.

    -  Corrects the missing path to the SCP device the hwmgr -view devices
       command is issued.

    -  Lets hwmgr show CPU bindings with a tilde (~) character.  Using the
       tilde helps distinguish between CPU bindings and RAD bindings, and also
       keeps the two interfaces consistent.

    -  Corrects a problem that causes hwmgr to display successful exit status
       for failed delete and unconfigure commands.

    -  Lets the hwmgr -view transaction -cluster command work on a cluster.



 1-54 Tru64 UNIX Patches








    -  Corrects some command-parsing irregularities in hwmgr that may cause
       options like -category and -cluster to be confused.



 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1274.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1276.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee::::  Supersedes Patch 319.00


 +o  Fixes several potential security vulnerabilities which, under certain
    circumstances, could compromise system integrity.  These may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1281.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects a problem with SNMP

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects the problem where, when monitoring a system network, the output of
    IP Datagrams Received and IP Datagrams Sent looks strange when using Area
    graphs.

 +o  Corrects a problem with SNMP (Simple Network Management Protocol) retrieval
    of ARP (Adress Resolution Protocol) cache data when an ARP table has more
    than 288 entries.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1293.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow



                                             Tru64 UNIX Patches 1-55








    occurs in X11 applications.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1297.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1299.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1307.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem with the operation of osf_boot

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes a problem with the operation of osf_boot with the interactive flag on
    an AlphaServer ES45 system.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1309.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1311.00



 1-56 Tru64 UNIX Patches








 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1313.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1319.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1332.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Corrects a potential security vulnerability where under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the dxsysinfo utility.  Buffer overflows are sometimes exploited
    in an attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1334.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Supersedes Patches 193.00 and 1119.00



                                             Tru64 UNIX Patches 1-57








 +o  Fixes several potential security vulnerabilities which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.

 +o  Improves the cleanPR script to clear Persistent Reservations on HSV110
    device and to continue to go through all devices even if certain errors
    occur to one or some of devices.

 +o  Adds support in the cleanPR script to remove all Persistant Reservations
    for MSA controller.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1336.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes several potential security vulnerabilities where under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the dxterm utility.  Buffer overflows are sometimes exploited in
    an attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1350.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2193)

 SSSSttttaaaatttteeee::::  Existing (Kit 4)


 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1359.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects hang in the log command

 SSSSttttaaaatttteeee:::: Existing


 +o  Corrects a possible deadlock in the ./isl/log and ./usr/sbin/log commands.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1370.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Revises the ifconfig.8.gz reference page

 SSSSttttaaaatttteeee:::: Existing (Kit 5)



 1-58 Tru64 UNIX Patches








 +o  Revises the ifconfig(8) reference page.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1372.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Updates for the zoneinfo data file

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Updates the time zone data files in /etc/zoneinfo/ to include the most
    recent changes from the latest PD time zone source kit (tzdata2002d).


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1374.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file or privilege management

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1376.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Blocked mutex lock causes XTI problem

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a problem in XTI caused by a blocked mutex lock.  Any thread
    attempting to send an abortive disconnect would hang.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1378.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Threaded apps using XTI/TLI may terminate or hang

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a problem in XTI caused by a blocked mutex lock.  Any thread
    attempting to send an abortive disconnect would hang.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1539.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Scripts in /sbin/init.d are now world-readable

 SSSSttttaaaatttteeee:::: Existing (Kit 5)




                                             Tru64 UNIX Patches 1-59








 +o  Makes start up scripts in /sbin/init.d world readable.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1541.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2275)

 SSSSttttaaaatttteeee:::: Supersedes Patches 1018.00, 1020.00, 469.00


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the uucp utility.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Fixes a problem in uucp.  uucp between two Tru64 UNIX boxes hangs when a
    uucp failure occurs.

 +o  Provides protection against a class of potential security vulnerabilities
    called buffer overflows.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.  This patch allows a system administrator to enable
    memory management protections that limit potential buffer overflow
    vulnerabilities.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1543.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2275)

 SSSSttttaaaatttteeee:::: Supersedes Patch 1266.00


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.

 +o  Provides protection against a class of potential security vulnerabilities
    called buffer overflows.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.  This patch allows a system administrator to enable
    memory management protections that limit potential buffer overflow
    vulnerabilities.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1545.00



 1-60 Tru64 UNIX Patches








 AAAAbbbbssssttttrrrraaaacccctttt:::: Scripts in /sbin/init.d are now world-readable

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Makes start-up scripts in /sbin/init.d world readable.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1547.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2275)

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Provides protection against a class of potential security vulnerabilities
    called buffer overflows.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.  This patch allows a system administrator to enable
    memory management protections that limit potential buffer overflow
    vulnerabilities.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1551.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Scripts in /sbin/init.d are now world-readable

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Makes start-up scripts in /sbin/init.d world readable.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1553.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Scripts in /sbin/init.d are now world-readable

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Makes start-up scripts in /sbin/init.d world readable.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1555.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes various problems in the libc functions

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes various problems in the libc functions getdate(), strptime(),
    callrpc(), strncasecmp(), fork()/popen(), and nacreate().




                                             Tru64 UNIX Patches 1-61








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1565.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0753U, SSRT0752U, SSRT0788U)

 SSSSttttaaaatttteeee:::: Supersedes Patches 433.00, 434.00, 436.00, 697.00, 1009.00, 1011.00


 +o  Fixes the dtprintinfo memory fault problem with long LANG value.

 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of large values of command line arguments.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of large values of ENVIRONMENT variables and command line arguments.

 +o  Corrects a potential security vulnerability in CDE Subprocess Control
    Service (dtspcd), which has a potential buffer overflow condition that may
    lead to unauthorized access.

 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the DtSvc utility.  Buffer overflows are sometimes exploited in
    an attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1567.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: tcpdump does not filter UDP traffic properly

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a problem in tcpdump that caused it to not filter UDP traffic
    properly.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1570.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Provides enhanced KDBX debugging features

 SSSSttttaaaatttteeee:::: Supersedes Patches 699.00, 1353.00, 1568.00


 +o  Fixes a premature termination of the ofile kdbx extension, warning messages
    in various kdbx extensions, and token length warnings when kdbx is invoked.




 1-62 Tru64 UNIX Patches








 +o  Fixes a problem with audit data not being displayed by audit tool, problems
    with file object selection/deselection and directories, and NUMA
    performance issues associated with auditing.

 +o  Fixes problems in the kdbx u and vnode extensions.

 +o  Enhances KDBX debugging features to include a -A flag for route and to keep
    inpcb from truncating port numbers.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1572.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for termcap script

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a problem during a cluster rolling upgrade in which the merge for the
    termcap file failed.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1574.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Updates to Sysman Account Management application

 SSSSttttaaaatttteeee:::: Supersedes Patches 1057.00, 1059.00


 +o  Corrects a problem in which errors are generated when nonroot users who
    lack a valid home directory run the SysMan Account Management tool.

 +o  Corrects a problem in which errors are generated when +users or -users are
    present in the /etc/passwd file and the SysMan Account Management tool is
    used to display or modify +user or -user.  The symptom is: "several
    property fields, such as comments, LoginShell, HomeDirectory, for the +user
    or -user will have values of 1 or 0".

 +o  Fixes a problem in dealing with white spaces in a "Filter by Comment"
    search of the SysMan Account Management application.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1587.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Correct improper file or privilege management

 SSSSttttaaaatttteeee:::: Supersedes Patches 1113.00, 1584.00, 1585.00


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.

 +o  Allows accounting files to be referenced using CDSLs.




                                             Tru64 UNIX Patches 1-63








 +o  Corrects the display of the header from acctcom when accounting is first
    started.

 +o  Fixes an error in the lastlogin.sh script.

 +o  Resolves differences in CPU and connect times found in the conversion from
    ASCII format to binary and back to ASCII in accounting reports.

 +o  Resolves the differences in CPU time found in the output of the acctcom and
    acctmerg commands for the same input file.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1589.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: fwtmp will not display invalid (negative) pids

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects fwtmp so it does not display invalid (negative) PIDs when the
    number of decimal digits of pid value exceeds 5.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1591.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Removes the 250 variable limit for env command

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Removes the 250 variable limit for /usr/bin/env.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1593.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2408, SSRT2411, SSRT2410)

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects potential BIND (Berkeley Internet Name Domain) security
    vulnerabilities that may result in buffer overflows, unauthorized access,
    or denial of service.  These potential security vulnerabilities may be in
    the form of local and remote security domain risks.  The following
    potential security vulnerabilities have been corrected:

    SSRT2408 BIND - (Severity - High) SSRT2410 BIND - (Severity - High)
    SSRT2411 BIND - (Severity - High)



 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1596.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file or privilege management



 1-64 Tru64 UNIX Patches








 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.

 +o  Addresses compiler warnings caused by calling function with too few
    arguments.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1604.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: mcopy/mwrite can now overwrite existing files

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Eliminates several security vulverabilities.

 +o  Changes mcopy and mwrite to let them overwrite existing files.

 +o  Fixes mtools to let it return appropriate error messages for nonprivileged
    users.

 +o  Standardizes the mformat prompt.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1609.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Correct improper file access

 SSSSttttaaaatttteeee:::: Supersedes Patch 1111.00


 +o  Corrects several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1611.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Revises the kdbx(8) reference page

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Revises the kdbx(8) reference page to document the addition of the -A flag
    to route.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1613.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for cdvd command



                                             Tru64 UNIX Patches 1-65








 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects the output of the CDVD command, which had one extraneous line and
    a line that was incorrectly labeled.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1618.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes message catalog problem in rrestore

 SSSSttttaaaatttteeee:::: Supersedes Patches 506.00, 1616.00


 +o  Corrects the rdump command to dump data properly onto remote tape devices
    without receiving the SIGSEGV and dumping core.

 +o  Fixes dump to recognize LSM volumes correctly and not report random
    information when an error has occurred.

 +o  Introduces dumprmt.msg for remote dump and restore messages.  This new
    message catalog file is used in both rdump and rrestore programs.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1620.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Eliminates compiler warnings in mkdir

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Eliminates compiler warnings in mkdir.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1622.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Update to adduser command

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects the default UID displayed by adduser when UID_MAX exists in the
    /etc/passwd file.

 +o  Causes adduser to avoid duplicating UIDs.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1624.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Adds the chatr(1) reference page

 SSSSttttaaaatttteeee:::: Existing (Kit 5)





 1-66 Tru64 UNIX Patches








 +o  Adds the chatr(1) reference page.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1626.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Enhancement to chfile command

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Causes the chfile command to display a more informative error message if
    chfile fails while trying to enable data logging.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1628.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Enables tip to log into member specific log file

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Enables the tip command to log into the member-specific log file.

 +o  Corrects the path for the aculog file and gives appropriate permissions.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1630.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Path for the aculog file has been corrected

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Enables the tip command to log into the member specific log file.

 +o  Corrects the path for the aculog file and gives it appropriate permissions.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1632.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Provides correct labels for audit_tool and auditmask

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Provides the correct labels for mach events to the audit subsystem.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1634.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Audit subsystem utilities printing out wrong labels

 SSSSttttaaaatttteeee:::: Existing (Kit 5)




                                             Tru64 UNIX Patches 1-67








 +o  Provides the correct labels for mach events to the audit subsystem.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1636.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Correct improper file or privilege management

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1638.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file access

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1641.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes race condition in rm command

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Addresses the performance issue of rm -r with large directories.

 +o  Fixes the problem of a race condition in rm command, wherein two threads
    can successfully delete a file simultaneously.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1647.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: quotacheck may incorrectly report disk quote excess

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a problem where the quotacheck utility may incorrectly report that
    a disk quota has been exceeded.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1649.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Problem with with execution of bttape TCL scripts



 1-68 Tru64 UNIX Patches








 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a problem encountered when bttape TCL scripts are executed by
    nonprivileged users.

 +o  Adds $quote directive to the message catalog.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1651.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Revises the lag(7) reference page

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Revises the lag(7) reference page.

 +o  Updates information about ee drivers for DE60x Ethernet cards.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1653.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem in the KZPCA itpsa driver

 SSSSttttaaaatttteeee:::: Supersedes Patches 261.00,483.00, 797.00, 1233.00, 1235.00


 +o  Fixes a panic caused by SCSI bus resets with KZPCA HBAs.

 +o  Fixes a kernel memory fault panic after an "ITPSA: itpsa_action - error
    converting path ID to ITPSA softc structure" message.

 +o  Adds the capability for KZPCA devices to work with SCSI devices that only
    support asynchronous data transfers.

 +o  Fixes a kernel memory fault related to the KZPCA adapter.

 +o  Fixes a SDLT media error that causes bus resets with KZPCA adapters.

 +o  Fixes a problem in the KZPCA itpsa driver that can be seen when a SCSI
    target presents multiple LUNs.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1665.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects the behavior of ln -sf

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Eliminates compiler warnings in ln.

 +o  Corrects the behavior of ln -sf to address the issue caused when a symbolic



                                             Tru64 UNIX Patches 1-69








    link points to a nonexisting file.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1667.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Kernel memory corruption in subscription routine

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a possible kernel memory corruption problem in the kernel event
    subscription routine.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1669.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Revises the sys_attrs_dli(5) reference page

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Revises the sys_attrs_dli(5) reference page to document the two new globals
    dli_sendspace and dli_recvspace.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1675.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Correct improper file or privilege management

 SSSSttttaaaatttteeee:::: Supersedes Patch 1272.00


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.

 +o  Corrects the behavior of more, when given both a non-existing file and a
    non-empty file with long a file name or pathname.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1677.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: advfsstat prints negative values for statistics

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a problem with advfsstat printing negative values for statistics
    that are over 10 decimal digits long.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1679.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: cut command now handles incomplete lines correctly



 1-70 Tru64 UNIX Patches








 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes /usr/bin/cut to handle incomplete line correctly.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1682.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0743U, SSRT2256)

 SSSSttttaaaatttteeee:::: Supersedes Patches 69.00, 1177.00, 1680.00


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the ps utility.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Fixes a situation, in which the header fields displayed by the output of ps
    command are not aligned properly.

 +o  Allows white space in header field with ps -o.  Multiple headers with white
    space can be given with ps -o.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1684.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects label strings in sysman LSM application

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects some label strings in the SysMan LSM application.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1686.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: S19security script causes change in security config

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a problem in which running the /sbin/rc2.d/S19security script
    during system start up could cause an unintended change in the system
    security configuration.  This would happen only when /usr/bin/perl had been
    removed.





                                             Tru64 UNIX Patches 1-71








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1688.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Buffer overflow problem in the write command

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a buffer overflow problem in /usr/bin/write.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1693.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file or privilege management

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1695.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: grep now allow blank lines in the pattern file

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Changes the grep command to now allow blank lines in the pattern file and
    does not hang when executed with -w and -f options.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1697.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: defragment fails when unable to obtain enough memory

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a problem where defragment can fail if it is unable to obtain enough
    memory.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1699.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for volmake utility

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a problem in which, when creating a new plex, volmake reports that
    associating a subdisk with the plex would cause an overlap with another
    subdisk when they should not be overlapping.



 1-72 Tru64 UNIX Patches








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1701.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2275)

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Revises the sys_attrs_proc(5) reference page to add the new tunable
    executable_data.

 +o  Adds the new javaexecutedata(8) reference page.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1703.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: X server may hang every 49 days with Powerstorm card

 SSSSttttaaaatttteeee:::: Supersedes Patch 1042.00


 +o  Fixes a problem where the X server's command line option to turn off VESA
    Display Power Management Signalling (-dpms) does not work.

 +o  Corrects a problem in which the X server may hang every 49 days on systems
    with PowerStorm 4D40T, 4D50T, 4D51T, or 4D60T graphics options.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1707.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Modifies enablers for Enterprise Volume Manager

 SSSSttttaaaatttteeee:::: Supersedes Patches 197.00, 263.00, 313.00, 513.00, 1136.00


 +o  Modifies enablers for the Enterprise Volume Manager.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1709.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Modifies enablers for Enterprise Volume Manager

 SSSSttttaaaatttteeee:::: Supersedes Patches 201.00, 265.00, 317.00, 515.00, 1138.00


 +o  Modifies enablers for the Enterprise Volume Manager.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1711.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Removes compiler warnings addressing outside of array

 SSSSttttaaaatttteeee:::: Existing (Kit 5)





                                             Tru64 UNIX Patches 1-73








 +o  Removes compiler warnings addressing outside of array bounds.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1713.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem with os_mibs

 SSSSttttaaaatttteeee:::: Supersedes Patch 739.00


 +o  Fixes a problem with os_mibs that could cause the application to consume an
    excessive amount of CPU time.

 +o  Corrects a problem in os_mibs which resulted in the swap size and swap used
    values for the host mib being reported as negative values on some systems.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1715.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects exit status of sed when disk is full

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects the exit status of sed when the disk is full.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1717.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Revises the sys_attrs_ee(5) reference page

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Revises the sys_attrs_ee(5) reference page to document the new ee subsystem
    attribute link_check_interval.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1719.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file access

 SSSSttttaaaatttteeee:::: Supersedes Patches 529.00, 1158.00


 +o  Fixes a problem where no shell message is displayed when trying to su to a
    user other than root.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.

 +o  Addresses problems with the mksas utility where false warning messages are
    generated and where the user-specified temporary directory could be



 1-74 Tru64 UNIX Patches








    erroneously removed.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1721.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file or privilege management

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1729.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects which to take path info from environment

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes /usr/bin/which to take path information from environment rather than
    ~/.cshrc if it is invoked from other than C shell.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1731.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file or privilege management

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1735.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects problems with the NIFF daemon

 SSSSttttaaaatttteeee:::: Supersedes Patch 220.00


 +o  Corrects a problem where the NIFF daemon (niffd) would exit if its
    connection to the EVM daemon (evmd) failed, as in the case of an EVM daemon
    restart.

 +o  Corrects a problem in niffd that results in its memory usage growing over
    time.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1737.00



                                             Tru64 UNIX Patches 1-75








 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for btextract command

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a problem in which btextract was not preventing the advanced mode
    of restore for a system with LSM setup.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1739.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: make command not checking for time stamps

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Changes /usr/opt/ultrix/usr/bin/make so that it properly checks
    dependencies on archive libraries.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1741.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for login script

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a problem during a rolling upgrade in which the merge of the
    .login file would fail, with inadequate informational messages.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1743.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Order of records in CDF file not preserved

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a problem in which restoring cloned information from a generated
    configuration description file (CDF) using sysman -clone -apply fails to
    preserve the order of records in the CDF file.  CDF files are used to clone
    systems at the configuration and installation level.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1745.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes binlogd core dump problem

 SSSSttttaaaatttteeee:::: Supersedes Patches 586.00, 777.00, 1214.00


 +o  Fixes a problem in which the binlog daemon can core dump if it attempts to
    recover events from a panic dump file containing invalid event data.




 1-76 Tru64 UNIX Patches








 +o  Fixes a time formatting problem when Compaq Analyze is used to display
    events in time zones with a positive offset from GMT.

 +o  Causes the binary error log daemon, binlogd, to sync its logfiles before
    closing them on system shutdown.

 +o  Corrects a potential binlogd core dump problem when parsing its remote host
    authorization file (/etc/binlog.auth) with greater than 513 characters.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1747.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file or privilege management

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1749.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: SysMan Station may fail to generate hardware view

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a problem with some cluster configurations in which SysMan Station
    fails to generate the hardware view.  A Java stack trace is generated
    indicating that the routine HardwareLayout.fancyPlace was being executed at
    the time of the trace.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1751.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file or privilege management

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1753.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Enhancement for siacfg utility

 SSSSttttaaaatttteeee:::: Supersedes Patch 787.00





                                             Tru64 UNIX Patches 1-77








 +o  Allows non-local SIA mechanisms, LDAP for example, to place their mechanism
    last in the list of mechanisms.

 +o  Eliminates the "Using an array as a reference is deprecated" warning when
    running /usr/sbin/siacfg and during system boot on systems using Perl 5.8.0
    and higher.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1755.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Revises the lagconfig(8) reference page

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Revises the lagconfig(8) reference page to document fixes for Link
    Aggregation.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1757.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects an error return code for volinfo utility

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects an error return code for volinfo.  If a specified volume is not in
    the configuration database, the error code returned from volinfo will
    reflect this error.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1759.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: mkpasswd command dumps core

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a situation in which the mkpasswd command dumps core when executed by
    a nonprivileged user.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1761.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file or privilege management

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.





 1-78 Tru64 UNIX Patches








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1763.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for bcheckrc script

 SSSSttttaaaatttteeee:::: Supersedes Patch 1278.00


 +o  Clarifies a vague message that dn_setup would print if a system was brought
    to single-user mode because dsfmgr detected database errors during boot.

 +o  Fixes a problem with bcheckrc that occurs when it is run multiple times.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1765.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file or privilege management

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1767.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes IPv6 neighbor discovery daemon problem

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a problem where, under cerntain circumstances, the IPv6 neighbor
    discovery daemon can cause bad information to be written to a DNS database
    causing failures on subsequent database reloads.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1769.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes re_ioctl() cases DIODCMD and DIODCDB

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes re_ioctl() cases DIODCMD and DIODCDB to handle cases where cmd
    transfer size has been changed to avoid kernel memory fault.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1771.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0664U, SSRT0762U, SSRT0801)

 SSSSttttaaaatttteeee:::: Supersedes Patches 204.00, 206.00, 567.00, 1303.00, 1305.00




                                             Tru64 UNIX Patches 1-79








 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  These may be in the form
    of improper file or privilege management.

 +o  Corrects a problem with the ftpd daemon that could result in PC ftp clients
    hanging when transferring some files in ASCII mode.

 +o  Prevents an ftp daemon failure when using globbing string of several
    asterisks and provides corrections for the help command and character drop
    with the put command.

 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.

 +o  Corrects a problem in the ftp open command to allow the optional port
    argument to accept port numbers between 32768 and 65535.

 +o  Fixes an ftp client accounting error that occurs when transferring more
    than 4 GB files.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1773.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: scu utility displays misleading data expected pattern

 SSSSttttaaaatttteeee:::: Supersedes Patch 234.00


 +o  Updates /sbin/scu, the SCSI CAM utility program, to add support for
    Persistent Reserve for HSV110 and the display of 128-bit WWIDS.

 +o  Fixes a problem with scu where a mismatch between expected and found data
    displays incorrect data expected.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1775.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Eliminates use of /tmp file in SysMan CLI example

 SSSSttttaaaatttteeee:::: New


 +o  Eliminates the use of a /tmp file in a SysMan CLI example.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1783.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for rpc.lockd

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes issues with rpc.lockd dealing with replies to message passing RPCs,
    requests from hosts with multiple IP addresses, and grant messages issued



 1-80 Tru64 UNIX Patches








    to down clients.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1786.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1804.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for screend daemon

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a potential problem in screend.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1813.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2260, SSRT1-40U, SSRT1-41U, SSRT1-42U)

 SSSSttttaaaatttteeee:::: Supersedes Patches 288.00, 507.00, 509.00, 1076.00, 1077.00, 1078.00,
 1079.00, 1080.00, 1081.00, 1082.00, 1083.00, 1085.00, 1348.00, 1605.00,
 1607.00


 +o  Corrects lpd parent daemon problems when EVM is stopped and started.

 +o  Slows down event storm from remote host sending bad protocol information.

 +o  Fixes the following problems with the C shell command interpreter, csh:


    -  Corrects the error message displayed when a nonroot user performs issues
       the ls command with wildcard characters on a directory having permission
       700.

    -  Corrects the error message displayed when nonomatch is set and a user
       issues the ls command with the question mark (?) character.

    -  Fixes a problem so csh correctly recognizes the backslash (\) meta
       character.

    -  Corrects the problem in which a user may experience a core dump when
       using csh from the Japanese locale.




                                             Tru64 UNIX Patches 1-81








    -  Fixes a problem with csh redirection while redirecting standard input
       and standard output of a command to a file exist in a home directory
       using tilde (~) operation.


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the lpq, lpr and lprm commands.  Buffer overflows are sometimes
    exploited in an attempt to subvert the function of a privileged program and
    possibly execute commnads and the elevated privileges if the program file
    has the setuid privilege.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the dxterm utility.  Buffer overflows are sometimes exploited in
    an attempt to subvert the function of a privileged program and possibly
    execute commnads and the elevated privileges if the program file has the
    setuid privilege.

 +o  Corrects a problem where telnetd leaves an extra udp port open.

 +o  Corrects an lpc regression in the lpc buffer overflow fix.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the csh utility.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commnads and the elevated privileges if the program file has the
    setuid privilege.

 +o  Corrects several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the telnetd daemon.  Buffer overflows are sometimes exploited in
    an attempt to subvert the function of a privileged program and possibly
    execute commnads and the elevated privileges if the program file has the
    setuid privilege.

 +o  Fixes a number of problems in the lpd (line printer daemon) subsystem.

 +o  Fixes lpd case sensitivity, for example, "node.domain" being treated the
    same as "Node.Domain."

 +o  Fixes a problem that causes a segmentation fault.  when dbx is analyzing a
    Fortran program.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1817.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: mkcdsl now properly deals with sticky bits on files




 1-82 Tru64 UNIX Patches








 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a problem with mkcdsl not carrying the sticky bit through.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1821.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: EVM returns DECevent startup error in email msg

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects a problem in which protocol handshake error occurs when a high
    priority binlog event is being reported via a mail message.  This occurs
    because EVM uses DECevent to translate the binlog event, which requires the
    HOME environment variable to be set in order to startup.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1825.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee:::: Existing (Kit 5))


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1831.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)

 SSSSttttaaaatttteeee::::  Supersedes Patches 109.00, 110.00, 112.00, 282.00, 284.00, 442.00,
 444.00, 714.00, 716.00, 1047.00, 1048.00, 1049.00, 1050.00, 1051.00, 1052.00,
 1053.00, 1054.00, 1056.00, 1181.00


 +o  Fixes several potential security vulnerabilities which, under certain
    circumstances, could compromise system integrity.  These may be in the form
    of improper file access.

 +o  Fixes a problem with the SysMan Station that causes incorrect state
    information to be displayed after a CPU has been indicted.

 +o  Fixes possible deadlock conditions in the SysMan station daemon that might
    occur at daemon startup or during failover.

 +o  Provides enablers for Packaged Database Solution.

 +o  Corrects a problem in which objects in the Physical File System view do not
    have correct or updated properties.



                                             Tru64 UNIX Patches 1-83








 +o  Corrects a problem in which the SysMan Station cannot launch commands on
    objects where an object attribute is part of the command.

 +o  Fixes a problem where reconfiguration of network interface cards using
    SysMan makes the old IP address an IP alias.  The new IP address now
    replaces the old IP address.

 +o  Fixes the message catalogs in some legacy applications so that the proper
    pop-up error message is displayed at the appropriate time.

 +o  Fixes a problem which could cause communications over a cluster
    interconnect to break when gigabit Ethernet cards are used as cluster
    interconnects.  The problem could occur because the cards are shown in the
    netconfig suitlet as regular interface cards and a user may reconfigure
    this, potentially calling a break in the interconnect.

 +o  Corrects a problem in which Quick Setup does not check for failure when
    safely creating a temporary file.  Currently, it checks for failure and
    aborts the procedure if the action failed.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1918.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects Enhanced Security C1crypt password change

 SSSSttttaaaatttteeee:::: Supersedes Patches 1559.00, 1800.00, 1916.00


 +o  Fixes client (login, su, rshd, edauth, and sshd2) hangs and long delays
    under Enhanced Security, as well as some intermittent errors or failures
    seen with prpasswdd or rpc.yppasswdd.

 +o  Corrects a problem in which logins in TruCluster environments using
    Enhanced Security could hang on any member other than the one serving /var
    to CFS.

 +o  Corrects a problem on systems running Enhanced Security in which the edauth
    -R command will not write user-profile entries to the root partition.

 +o  Corrects a problem in which using C1crypt for password encryption on
    Enhanced Security systems prevents users from changing their passwords and
    causes the passwd command state to display the message "Password not
    changed:  failed to write protected password entry."


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1924.00

 AAAAbbbbssssttttrrrraaaacccctttt::::Enabler for Enterprise Volume Manager product

 SSSSttttaaaatttteeee:::: Supersedes Patches 67.00, 582.00, 574.00, 576.00, 703.00, 839.00,
 1012.00, 1013.00, 1014.00, 1015.00, 1017.00, 1344.00, 1471.00, 1451.00,
 1516.00, 1498.00, 187.00, 1346.00, 1823.00, 517.00, 1673.00, 1919.00, 1920.00,
 1921.00, 1922.00




 1-84 Tru64 UNIX Patches








 +o  Proves enablers for the Enterprise Volume Manager product.

 +o  Prevents a vold from core dumping when removing a disk from rootdg using
    voldiskadm or voldg.

 +o  Prevents a KMF (kernel memory fault) panic, in voldiskiostart(), when an
    I/O is attempted on an LSM device that is not accessible.

 +o  Fixes a situation in which when a cluster member fails, mirrored volumes
    are left in a state such that recovery is always necessary when members
    boot, even if no additional recovery should be necessary.

 +o  Prevents vold from core dumping on booting with the message:

    Commit: not holding dg lock


 +o  Fixes a collision problem with clsm sync and LSM startup.

 +o  Fixes a problem of a vold core dump when old config db exists.

 +o  Fixes a problem where cluster node panics on boot if klog does not exist.

 +o  Fixes a problem of LSM not recognizing third-party disks.

 +o  Fixes an inability to create a new diskgroup when vold is in noloadbalance
    mode.

 +o  Fixes error messages for non-rootdg disks when cluster root is under LSM
    control.

 +o  Fixes problems in LSM's autoconfiguration feature, as well as problems with
    the LSM commands volsave, volrestore and volclonedg.

 +o  Corrects performance issues on starting of Cluster Logical Storage Manager
    (CLSM) with large configurations.

 +o  Allows the proper synchronization of disk errors and failures in a cluster
    under CLSM control.

 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.

 +o  Prevents inconsistent LSM volumes when the name of a partition that is
    being encapsulated matches the name of a current LSM volume.

 +o  Ensures that a cluster member will be up to date with respect to the LSM
    configuration when calls are made to an internal LSM routine.  This patch
    prevents the smsd from triggering LSM configuration errors when querying
    LSM in a cluster.

 +o  Provides protection against a class of potential security vulnerabilities
    called buffer overflows.  Buffer overflows are sometimes exploited in an



                                             Tru64 UNIX Patches 1-85








    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.  This patch allows a system administrator to enable
    memory management protections that limit potential overflow
    vulnerabilities.



 +o  Corrects an I/O performance issue seen when CLSM is configured and one
    member of a cluster goes down unexpectedly.

 +o  Corrects an issue of a cluster node hanging on boot while the other member
    recovers the cluster root file systems.

 +o  Modifies volencap to prevent encapsulation of restricted partitions or
    placing swap into a non-rootdg diskgroup.

 +o  Allow volsave and volrestore to save nconfig/nlog policies for diskgroups
    and to restore them appropriately.

 +o  Corrects awk errors for invalid quit statements.

 +o  Corrects a problem with a mirrored LSM volume with dirty region logging
    (DRL) enabled still doing a full resynchronization during the first
    recovery after an unclean shutdown.

 +o  Fixes a problem in which volassist was unable to create a mirror of a
    striped volume with the mirror having a layout of concat.

 +o  Improves null partition checking code.

 +o  Fixes issues with I/O failures that are seen on non-rootdg diskgroups,
    including a conditions that causes the diskgroup to fail under certain
    conditions and to core dump when failing a non-rootdg disk.

 +o  Fixes a performance issue seen during plex detach operations.

 +o  Provides fixes that allow a full recovery in the event of an invalid magic
    number found in the recovery map.

 +o  Modifies the volassist command to correctly output a warning message for
    its grow and shrink operations.

 +o  Corrects an internationalization problem affecting the LSM voldiskadm
    command.  An instructional message that is output when choosing the
    voldiskadm list option was incorrect because it had not been entered
    properly in the message catalog.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1926.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2191)

 SSSSttttaaaatttteeee::::Supersedes 1317.00



 1-86 Tru64 UNIX Patches








 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the quot utility.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Improves null partition checking code.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1928.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2275)

 SSSSttttaaaatttteeee:::: Supersedes Patches 181.00, 486.00, 488.00, 191.00, 2.00, 121.00,
 241.00, 243.00, 400.00, 401.00, 402.00, 403.00, 404.00, 405.00, 406.00,
 407.00, 408.00, 409.00, 410.00, 412.00, 307.00, 302.00, 162.00, 253.00,
 255.00, 90.00, 218.00, 303.00, 305.00, 421.00, 422.00, 423.00, 424.00, 426.00,
 681.00, 682.00, 683.00, 684.00, 685.00, 686.00, 687.00, 689.00, 807.00,
 511.00, 729.00, 541.00, 146.00, 148.00, 126.00, 127.00, 128.00, 129.00,
 130.00, 131.00, 132.00, 134.00, 286.00, 6.00, 7.00, 8.00, 9.00, 10.00, 11.00,
 12.00, 13.00, 14.00, 15.00, 16.00, 17.00, 18.00, 19.00, 20.00, 21.00, 22.00,
 23.00, 24.00, 25.00, 26.00, 27.00, 28.00, 29.00, 30.00, 31.00, 32.00, 33.00,
 34.00, 35.00, 36.00, 37.00, 38.00, 39.00, 40.00, 41.00, 42.00, 43.00, 44.00,
 45.00, 46.00, 47.00, 48.00, 49.00, 50.00, 51.00, 52.00, 53.00, 54.00, 55.00,
 56.00, 57.00, 58.00, 59.00, 60.00, 61.00, 102.00, 63.00, 104.00, 214.00,
 236.00, 246.00, 247.00, 248.00, 250.00, 270.00, 271.00, 272.00, 273.00,
 274.00, 275.00, 276.00, 277.00, 279.00, 296.00, 298.00, 321.00, 323.00,
 325.00, 290.00, 152.00, 93.00, 95.00, 328.00, 329.00, 330.00, 331.00, 332.00,
 333.00, 334.00, 335.00, 336.00, 337.00, 338.00, 339.00, 340.00, 341.00,
 342.00, 343.00, 344.00, 345.00, 346.00, 347.00, 348.00, 349.00, 350.00,
 351.00, 352.00, 353.00, 354.00, 355.00, 356.00, 357.00, 358.00, 359.00,
 360.00, 361.00, 362.00, 363.00, 364.00, 365.00, 366.00, 367.00, 368.00,
 369.00, 370.00, 371.00, 372.00, 373.00, 374.00, 375.00, 376.00, 377.00,
 378.00, 379.00, 380.00, 381.00, 382.00, 383.00, 384.00, 385.00, 386.00,
 387.00, 388.00, 389.00, 390.00, 391.00, 392.00, 393.00, 394.00, 395.00,
 396.00, 397.00, 399.00, 543.00, 590.00, 592.00, 596.00, 203.00, 594.00,
 597.00, 598.00, 599.00, 600.00, 601.00, 602.00, 603.00, 604.00, 605.00,
 606.00, 607.00, 608.00, 609.00, 610.00, 611.00, 612.00, 613.00, 614.00,
 615.00, 616.00, 617.00, 618.00, 619.00, 620.00, 621.00, 622.00, 623.00,
 624.00, 625.00, 626.00, 627.00, 628.00, 629.00, 630.00, 631.00, 632.00,
 633.00, 634.00, 635.00, 636.00, 637.00, 638.00, 639.00, 640.00, 641.00,
 642.00, 643.00, 644.00, 645.00, 646.00, 647.00, 648.00, 649.00, 650.00,
 651.00, 652.00, 653.00, 654.00, 655.00, 656.00, 657.00, 658.00, 659.00,
 660.00, 661.00, 662.00, 663.00, 664.00, 665.00, 666.00, 667.00, 668.00,
 669.00, 671.00, 672.00, 673.00, 674.00, 675.00, 676.00, 677.00, 678.00,
 680.00, 834.00, 835.00, 837.00, 842.00, 846.00, 853.00, 854.00, 855.00,
 856.00, 857.00, 858.00, 859.00, 860.00, 861.00, 862.00, 863.00, 864.00,
 865.00, 866.00, 867.00, 868.00, 869.00, 870.00, 871.00, 872.00, 873.00,
 874.00, 875.00, 876.00, 877.00, 878.00, 879.00, 880.00, 881.00, 882.00,
 883.00, 884.00, 885.00, 886.00, 887.00, 888.00, 889.00, 890.00, 891.00,
 892.00, 893.00, 894.00, 895.00, 896.00, 897.00, 898.00, 899.00, 900.00,
 901.00, 902.00, 903.00, 904.00, 905.00, 906.00, 907.00, 908.00, 909.00,
 910.00, 911.00, 912.00, 913.00, 914.00, 915.00, 916.00, 917.00, 918.00,



                                             Tru64 UNIX Patches 1-87








 919.00, 920.00, 921.00, 922.00, 923.00, 924.00, 925.00, 926.00, 927.00,
 928.00, 929.00, 930.00, 931.00, 932.00, 933.00, 934.00, 935.00, 936.00,
 937.00, 938.00, 939.00, 940.00, 941.00, 942.00, 943.00, 944.00, 945.00,
 946.00, 947.00, 948.00, 949.00, 950.00, 951.00, 952.00, 953.00, 954.00,
 955.00, 956.00, 957.00, 958.00, 959.00, 960.00, 961.00, 962.00, 963.00,
 964.00, 965.00, 966.00, 967.00, 968.00, 969.00, 970.00, 971.00, 972.00,
 973.00, 974.00, 975.00, 976.00, 977.00, 978.00, 979.00, 980.00, 981.00,
 982.00, 983.00, 984.00, 985.00, 986.00, 987.00, 988.00, 80.00, 418.00, 780.00,
 782.00, 1215.00, 990.00, 1217.00, 1248.00, 1320.00, 1322.00, 1323.00, 1324.00,
 1326.00, 1338.00, 1339.00, 1340.00, 1341.00, 1343.00, 1355.00, 1360.00,
 1362.00, 1363.00, 1364.00, 1365.00, 1368.00, 1549.00, 1815.00


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.

 +o  Fixes a rmvol failure that would be seen as an E_PAGE_NOT_MAPPED error when
    no more space is available for user data migration to another volume in the
    domain.

 +o  Fixes a potential problem with vdf and showfdmn, where they could
    incorrectly display the message "showfdmn: No such file or directory."

 +o  Modifies rmvol so that error messages reflect why rmvol fails.

 +o  Modifies showfdmn so it will not print "Succeeded" on a failure.  For
    example:

    showfdmn: unable to get info for domain `domain_used` showfdmn: Succeeded


 +o  Corrects a problem in which advscan command incorrectly processes
    concatenated options (such as -ar vs.  -a -r).  For example, if -ar is
    specified, the -r option is not processed.



 +o  Fixes a problem that prevents AdvFS from working correctly with LSM volumes
    between 1 TB and 2 TB.

 +o  Adds more helpful informational messages, for example:


    -  Advscan will now indicate if a domain has all of its volumes, but they
       are stored in a different directories.  This scenario will cause mount
       to fail.

    -  The AdvFS I/O error message now includes the location of a file that
       will help you translate the error number into an error message.


 +o  Fixes various minor problems in dsfmgr.




 1-88 Tru64 UNIX Patches








 +o  Fixes an rmvol E_PAGE_NOT_MAPPED error.

 +o  Eliminate an ENO_MORE_BLKS error seen when performing a copy-on-write
    procedure to a clone file while an rmvol operation is in progress.

 +o  Provides protection against a class of potential security vulnerabilities
    called buffer overflows.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.  This patch allows a system administrator to enable
    memory management protections that limit potential buffer overflow
    vulnerabilities.

 +o  Prevents erroneous DMAPI messages that were being printed while using
    showfile.

 +o  Improves null partition checking code.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1930.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Correct edauth failure to write to root partition

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a problem on systems running Enhanced Security in which the edauth
    -R command will not write user-profile entries to the root partition.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1933.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects Enhanced Security C1crypt password change

 SSSSttttaaaatttteeee:::: Supersedes 1557.00, 1798.00, 1931.00


 +o  Fixes client (login, su, rshd, edauth, and sshd2) hangs and long delays
    under Enhanced Security, as well as some intermittent errors or failures
    seen with prpasswdd or rpc.yppasswdd.

 +o  Corrects a problem in which logins in TruCluster environments using
    Enhanced Security could hang on any member other than the one serving /var
    to CFS.

 +o  Corrects a problem on systems running Enhanced Security in which the edauth
    -R command will not write user-profile entries to the root partition.

 +o  Customers using C1crypt for password encryption on Enhanced Security
    systems have found that users are unable to change their passwords.
    Warnings from the passwd command state "Password not changed: failed to
    write protected password entry."





                                             Tru64 UNIX Patches 1-89








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1939.00

 AAAAbbbbssssttttrrrraaaacccctttt::::Feedback facility for dd

 SSSSttttaaaatttteeee:::: New


 +o  Provides the feedback facility for dd in long copies.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1950.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0785U)

 SSSSttttaaaatttteeee:::: Supersedes Patches 472.00, 473.00, 474.00, 475.00, 477.00, 721.00,
 723.00, 1066.00, 1067.00, 1068.00, 1069.00, 1071.00, 1357.00, 1597.00,
 1598.00, 1600.00, 1944.00, 1945.00, 1946.00, 1947.00, 1948.00


 +o  Corrects a problem with dxaccounts in which a core dump occurs when
    /etc/shells is a directory instead of a file.

 +o  Corrects a problem with dxaccounts in which the hour glass cursor remains
    after a failure to create a home directory in the process of adding or
    modifying an account.

 +o  Fixes a problem of dxaccounts in which names and security attributes of
    Tru64 UNIX users are not mapped correctly when they are viewed from PC
    Users' dialog.

 +o  Fixes the problem that user name entries are replicated in the /etc/group
    file when modifying users with either dxaccounts or SysMan accounts.

 +o  Fixes a problem in dxaccounts that can cause certain C2 security values to
    not be displayed, which could result in unexpected values being saved.

 +o  Fixes the problem of useradd, usermod, and dxaccounts ignoring password
    length restrictions when changing passwords.

 +o  Fixes a number of problems with dxaccounts on a system with ASU installed.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of passwords that have a length outside of the intended range.

 +o  Fixes several minor problems with the account management tools.

 +o  Corrects a problem with the userdel command core dumping when the shell
    field is empty in the passwd file.

 +o  Corrects a problem of the usermod command not working as expected with NIS
    +/- users.

 +o  Corrects the problem where the useradd command fails to create a user with



 1-90 Tru64 UNIX Patches








    the specified template field under Enhanced Security.

 +o  Updates the account management tools to use the latest versions of the ASU
    API calls when ASU is in use on the server.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.

 +o  Corrects a condition in which the useradd command was not managing default
    and template data properly.  This shows up most notably with useradd -p
    producing the message "Password must be between 32 and 80 characters."

 +o  Corrects a problem in which extra leading/trailing spaces from the FIND
    dialog box in dxaccounts were not trimmed before being used, which resulted
    in a search failure.

 +o  Changes dxaccounts to cause it to display account expiration date at first
    view.

 +o  Corrects a condition in which the useradd error message is confusing when
    ASU is installed and the user runs useradd on a non-PDC server.

 +o  Corrects an userdel -D failure to remove a user from /etc/passwd on systems
    running Enhanced Security systems.

 +o  Includes the fix for the situation where dxaccounts does not allow to
    change the local user password in enhanced security environment.

 +o  Fixes a problem that prevented the locking and unlocking of multiple
    selected users under C2 security.



 +o  Corrects a problem in which running the usermod command with certain
    options such as -x distributed, grace_limit, gives a "Cross-device link"
    error when the var and yp directories belong to two different filesets on a
    NIS master.

 +o  Prevents core dumps caused by the dxaccounts application in the following
    two cases:


    -  When UNIX login name is modified and its corresponding PC account is not
       remapped to the new login name.

    -  When a user tries to modify both UNIX account login name and PC account
       login name and tries to see information in 'PC user view'.


 +o  Corrects a problem in which dxaccounts core dumps when the root user is
    selected from the modification drop-down.





                                             Tru64 UNIX Patches 1-91








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1952.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: (SSRT0788U, SSRT0753U, SSRT0752U)

 SSSSttttaaaatttteeee:::: Supersedes Patches 493.00, 495.00, 725.00, 1328.00


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of large values of ENVIRONMENT variables.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the libXm utility.  Buffer overflows are sometimes exploited in
    an attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Fixes a libXm.so incompatibility.

 +o  Fixes a problem with the Motif ToggleButton Widget where, in some cases, it
    may not draw itself correctly.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.

 +o  Corrects a problem in which the XmCvtXmStringToCT() function, under certain
    circumstances, does not correctly convert a compound string to a string in
    compound text format.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1954.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0788U, SSRT0753U, SSRT0752U)

 SSSSttttaaaatttteeee:::: Supersedes Patches 496.00, 498.00, 727.00, 1330.00


 +o  Fixes a libXm.so incompatibility.

 +o  Fixes a problem with the Motif ToggleButton Widget where, in some cases, it
    may not draw itself correctly.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the libXm utility.  Buffer overflows are sometimes exploited in
    an attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.



 1-92 Tru64 UNIX Patches








 +o  Corrects a problem in which the XmCvtXmStringToCT() function, under certain
    circumstances, does not correctly convert a compound string to a string in
    compound text format.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1956.00

 AAAAbbbbssssttttrrrraaaacccctttt::::Resolution of a symlink problem

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a potential security vulnerability, where under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1958.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Correction to local and remote security domain risks

 SSSSttttaaaatttteeee:::: Supersedes Patches 1154.00, 1615.00


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the binmail (also called mail) utility.  Buffer overflows are
    sometimes exploited in an attempt to subvert the function of a privileged
    program and possibly execute commands at the elevated privileges if the
    program file has the setuid privilege.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file or privilege management.

 +o  Corrects a potential security vulnerability that may result in unauthorized
    Privileged Access or a Denial of Service (DoS).  This potential
    vulnerability may be in the form of local and remote security domain risks.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1960.00

 AAAAbbbbssssttttrrrraaaacccctttt::::awk not processing input files given in BEGIN section

 SSSSttttaaaatttteeee:::: Supersedes Patch 1671.00


 +o  Fixes a situation, in which awk was not processing the input files
    specified in the BEGIN section.  The awk/nawk command shows expected
    behavior with pipes.

 +o  This patch fixes three issues for awk:





                                             Tru64 UNIX Patches 1-93








    -  Corrects a problem of system integrity being compromised.  This may be
       in the form of improper file or privilege management.

    -  Returns the appropriate exit status when a disk is full.

    -  Accepts input records of lengths up to 5,119 bytes.



 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1962.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file access

 SSSSttttaaaatttteeee:::: Supersedes Patch 88.00


 +o  Fixes a problem with the disklabel command.  Disklabel was displaying large
    unsigned values as negative numbers.

 +o  Corrects a potential compromise to system integrity.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1964.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Correction to improper file access

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a potential compromise to system integrity.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1966.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0638U)

 SSSSttttaaaatttteeee:::: Supersedes Patches 139.00, 141.00


 +o  Allows the dxsetacl utility to delete access ACLs.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of root directory compromise via lpr using X11.

 +o  Corrects a potential compromise to system integrity.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1968.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a fatal error in the spike command



 1-94 Tru64 UNIX Patches








 SSSSttttaaaatttteeee::::Supersedes Patches 150.00, 555.00, 1188.00, 1190.00, 803.00, 1658.00


 +o  Fixes a problem that may cause the third command and other Atom-based
    instrumentation tools to fail.

 +o  Fixes a fatal assertion error reported by pixie, hiprof, third spike, cord,
    uprofile and odump object file tools for some executables linked at
    optimization level 2 (-O2) or greater.

 +o  This patch fixes the following problems in the linker (/usr/bin/ld):


    1. A problem with the datatype of the linker-defined _fpdata symbol.

    2. A problem that causes a linker crash when certain data alignment
       directives are used in the link.

    3. A problem in which the linker may corrupt the shared object registry
       file when -update_registry is specified with concurrent links.

    4. An error that occurs when the command ld -update_registry /dev/null is
       specified.

    5. A problem that may cause executables to fail with a segmentation
       violation when the address of an uninitialized data symbol in a shared
       library is used as the initial value of a global or static pointer
       variable.


 +o  Corrects a condition that causes a fatal error in /usr/bin/spike.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1970.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a fatal error in the spike command

 SSSSttttaaaatttteeee:::: Supersedes Patches 158.00, 1198.00, 1200.00, 1660.00


 +o  Fixes a problem where the spike command may fail to delete the low
    instruction of a pair of related instructions, causing it to abort with a
    runtime error.

 +o  Corrects a problem in which prof -pixie -testcoverage .Counts sometimes
    reports invalid source line number ranges.

 +o  Fixes performance tool failures on Sierra Clusters (PFS) Parallel File
    Systems.

 +o  Fixes a fatal assertion error reported by pixie, hiprof, third spike, cord,
    uprofile and odump object file tools for some executables linked at
    optimization level 2 (-O2) or greater.




                                             Tru64 UNIX Patches 1-95








 +o  Corrects a condition that causes a fatal error in /usr/bin/spike.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1972.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: vmstat incorrect kernel per-RAD memory usage

 SSSSttttaaaatttteeee:::: New


 +o  Corrects the output of the vmstat command for per-RAD kernel usage data.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1974.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Updates the mcutil .h files

 SSSSttttaaaatttteeee:::: Supersedes Patch 1212.00


 +o  Fixes and improves the mcutil program by correcting how bus resets are
    handled by the program, and by enhancing its error reporting capabilities.

 +o  Distributes the latest .h files for the mcutil program.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1976.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for nvbmtpg -v option

 SSSSttttaaaatttteeee:::: New


 +o  Enables the nvbmtpg utility to display only all the data in a specified
    mcell if the -v option has been selected.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1978.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: dxproctuner not displaying any data in fr_FR local

 SSSSttttaaaatttteeee:::: Supersedes Patches 438.00, 1802.00


 +o  Fixes a problem in dxproctuner where the process information is not
    displayed when there is a double quotation mark followed by any other
    character in the command column.

 +o  Corrects a problem with dxproctuner that caused it to give an error message
    or dump core when invoked.

 +o  Corrects a condition in which dxproctuner does not display data in the
    fr_FR locale




 1-96 Tru64 UNIX Patches








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1980.00

 AAAAbbbbssssttttrrrraaaacccctttt::::Local and remote security domain risks

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a potential security vulnerability problem that may result in
    unauthorized Privileged Access or a Denial of Service (DoS).  This
    potential vulnerability may be in the form of local and remote security
    domain risks.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1982.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Potential security vulnerability in gated

 SSSSttttaaaatttteeee:::: Supersedes Patches 1222.00, 1642.00, 1643.00, 1645.00, 1819.00


 +o  Corrects a problem using MD5 authentication with Version 2 RIP

 +o  Resolves a problem where the cluster interconnect route is inappropriately
    advertised.

 +o  Corrects a problem in which gated, upon route aging timeout, deletes a
    static or loopback host route that is added via routing socket.  In a
    cluster alias environment, this problem causes all TCP/UDP packets destined
    to the cluster alias address to mishandled.

 +o  Adds support to gated for the option aliases-nexthop.  This option provides
    a preference for the selection of next-hop address when multiple addresses
    exist on the interface.

 +o  Resolves a problem with gated where adding a route may not succeed under
    certain circumstances.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may occur when
    Gated daemon or Gated Control utility (gdc) incorrectly accesses temporary
    files.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1984.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Modification to secconfig suitlet

 SSSSttttaaaatttteeee:::: Supersedes Patch 749.00


 +o  Makes the customize database option available when using secconfig for
    shadow passwords.

 +o  Eliminates two warning messages from the SysMan Security Configuration tool



                                             Tru64 UNIX Patches 1-97








    that appear under the following conditions:


    -  When changing the root password on systems with ASU installed.

    -  When a user tries to trim auth logs before they are even created.



 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1986.00

 AAAAbbbbssssttttrrrraaaacccctttt::::Suppress an in_cksum() debug message sent to console

 SSSSttttaaaatttteeee:::: New


 +o  Causes an in_cksum() console debug message to be suppressed.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1988.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes for the collect utility

 SSSSttttaaaatttteeee:::: Supersedes Patches 175.00, 799.00, 1238.00, 1240.00, 1654.00, 1656.00


 +o  Fixes a problem when collect is run in historical mode.

 +o  Fixes collect to correctly report the network interface load percentage.

 +o  Allows the collect to recognize and gather KZPCC disk statistics.

 +o  Fixes the way collect handles Floating Point Exception.

 +o  Fixes a problem in which collect was unable to create a new data file from
    a data file that does not include a termination record.

 +o  Corrects a problem in which the collect utility exits with the message
    "chmod or chown failed.: No such file or directory" when it is run with the
    -H option and the directory linking to /var/adm/collect.dated does not
    exist.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1990.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for printer problems

 SSSSttttaaaatttteeee:::: New


 +o  Fixes a problem in which the user cannot connect to a printer on the
    parallel port after cancelling a print job.





 1-98 Tru64 UNIX Patches








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1992.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for fixdmn problems

 SSSSttttaaaatttteeee:::: Supersedes Patches 177.00, 559.00, 818.00, 819.00, 820.00, 822.00,
 1300.00, 1302.00, 1689.00, 1691.00


 +o  Makes the following changes to the fixfdmn utility:


    -  Fixes several problems where under extreme cases, it was possible for
       fixfdmn to core dump or to terminate without fixing the domain.

    -  Fixes a problem in which fixfdmn exits prematurely with the message
       "Can't allocate 0 bytes for group use array" and then instructs the user
       on how to make more memory available, even though more memory is not
       needed.

    -  Allows fixfdmn to modify only one page of the transaction log.

    -  Prevents fixfdmn from changing file sizes unnecessarily.

    -  Fixes a case were fixfdmn would abort when the same mcell was on the DDL
       more than once.

    -  Allows fixfdmn to be run on domains that have been mounted under Version
       5.1B and then moved back to an older version.

    -  Fixes a problem in which fixfdmn could core dump on a rare corruption in
       the tag file.

    -  Allows fixfdmn to remove full frag groups from the free frag list in the
       fileset frag file.

    -  Fixes three rare cases where fixfdmn could either fail to correct a
       domain or incorrectly make changes to a valid domain.

    -  Allows fixfdmn to fix a rare corruption case in the RBMT/BMT0.

    -  Improves the capability of fixfdmn to fix invalid extent data.



 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1994.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2280)

 SSSSttttaaaatttteeee:::: Supersedes Patches 561.00, 547.00, 813.00, 1284.00, 1285.00, 1287.00


 +o  Fixes a problem with cut-and-paste operations of JISX0212 Japanese
    characters on X Window System applications.




                                             Tru64 UNIX Patches 1-99








 +o  Fixes a problem in the X Toolkit library (Xt) that could cause the TeMIP
    Iconic_map Presentation Module application (mcc_iconic_map) to crash.

 +o  Fixes a problem in which the definition of the X Toolkit function
    XtPending() was changed, thereby causing some applications built on earlier
    versions of Tru64 UNIX to fail.

 +o  Fixes a problem with Worldwide Language Support where input method servers
    (such as VJE Delta) could not connect to their clients, thereby preventing
    users from entering non-English strings to their X Window System
    applications.

 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in X11 applications.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Fixes a problem where a Chinese character whose byte sequence contains 0x9b
    cannot be entered with dxhanziim or cut-and-pasted.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1996.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2280)

 SSSSttttaaaatttteeee:::: Supersedes Patches 549.00, 815.00, 563.00, 1288.00, 1289.00, 1291.00


 +o  Fixes a problem in the X Toolkit library (Xt) that could cause the TeMIP
    Iconic_map Presentation Module application (mcc_iconic_map) to crash.

 +o  Fixes a problem in which the definition of the X Toolkit function
    XtPending() was changed, which caused some applications built on earlier
    versions of Tru64 UNIX to fail.

 +o  Fixes a problem with cut-and-paste operations of JISX0212 Japanese
    characters on X Window System applications.

 +o  Fixes a problem with Worldwide Language Support where input method servers
    (such as VJE Delta) could not connect to their clients, thereby preventing
    users from entering non-English strings to their X Window System
    applications.

 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in X11 applications.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Fixes a problem where a Chinese character whose byte sequence contains 0x9b
    cannot be entered with dxhanziim or cut-and-pasted.



 1-100 Tru64 UNIX Patches








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 1998.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Modified volplex to detach mirrored swap plex

 SSSSttttaaaatttteeee:::: New


 +o  Changes volplex to allow a mirrored swap plex to be detached when it
    contains a phantom subdisk.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2000.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: munlockall() locks process memory

 SSSSttttaaaatttteeee:::: Supersedes Patch 136.00


 +o  Corrects the behavior of munlockall in the realtime library (librt).


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2002.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Static library fix for librt

 SSSSttttaaaatttteeee:::: Supersedes Patch 138.00


 +o  Corrects a problem in which the behavior of POSIX 4 message queues does not
    follow the standard and returns unique message descriptors.

 +o  Corrects the behavior of munlockall in the realtime library (librt).


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2004.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix incorrect diagnostic msg in traceroute

 SSSSttttaaaatttteeee:::: Supersedes Patch 718.00


 +o  Corrects a problem where traceroute sometimes failed to provide responses
    and finish a trace when the destination host name was given on the command
    line.

 +o  Fixes an incorrect diagnostic message in the traceroute command.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2007.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Assembler treats octal constants as decimal values

 SSSSttttaaaatttteeee:::: Supersedes Patches 471.00, 720.00, 2005.00




                                            Tru64 UNIX Patches 1-101








 +o  Installs Version 3.06.08 of the assembler and resolves assembler problems
    related to the following:


    -  The generation of an incorrect symbol table which can cause om to fail.

    -  The improper reordering of an instruction which restores the stack
       pointer when assembling with optimization active.

    -  The generation of a .ident string without a terminating NULL.

    -  The generation of an invalid optimization when a load instruction
       specifies a target register and a base register that are the same.


 +o  When a load instruction specifies a target register and a base register
    that are the same, the assembler may generate an invalid optimization.

 +o  Fixes a yacc stack overflow error in the Tru64 UNIX assembler.

 +o  Provides version 3.06.10 of the assembler.  This version fixes a problem
    encountered in version 3.06.09, wherein the assembler incorrectly treats
    octal constant data as if it were decimal.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2009.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Potential security vulnerability in mrouted

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of the mrouted daemon incorrectly creating and accessing temporary
    files.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2011.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: lsmbstartup fix to ignore comments in /etc/fstab

 SSSSttttaaaatttteeee:::: New


 +o  Fixes the situation in which lsmbstartup did not ignore comment lines in
    /etc/fstab.  It was therefore possible for it to attempt to process that
    line if it appeared to be an entry for the root file system.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2013.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file access




 1-102 Tru64 UNIX Patches








 SSSSttttaaaatttteeee:::: Existing


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2015.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Resolves a symlink problem

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a potential security vulnerability, where under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2017.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file access

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2019.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Prevents garbled characters with dxdw

 SSSSttttaaaatttteeee:::: New


 +o  Fixes a problem where, under certain circumstances, the Display Window
    application (dxdw) displays garbled characters in the transcript area of
    the application.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2021.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file access

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.



                                            Tru64 UNIX Patches 1-103








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2023.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file access

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a potential security vulnerability, where under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2025.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file access

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2027.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT1-45U)

 SSSSttttaaaatttteeee:::: Supersedes Patch 1226.00


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2029.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for Null Pointer Exception in LSMSA GUI

 SSSSttttaaaatttteeee:::: Supersedes Patch 455.00


 +o  Addresses a problem in the display of disk controller to disk hierarchy by
    the lsmsa product.

 +o  Fixes the problem in LSMSA GUI where the application throws a Null Pointer
    Exception while trying to display Volume/Fileset information on systems
    having ASU file-on-file mounts.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2031.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file access



 1-104 Tru64 UNIX Patches








 SSSSttttaaaatttteeee:::: New


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2033.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2193)

 SSSSttttaaaatttteeee:::: Supersedes Patch 1237.00


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity when a buffer overflow
    occurs in the mailcv utility.  Buffer overflows are sometimes exploited in
    an attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Corrects a potential security vulnerability that may result in unauthorized
    Privileged Access or a Denial of Service (DoS).  This potential
    vulnerability may be in the form of local and remote security domain risks.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2035.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2280)

 SSSSttttaaaatttteeee:::: Supersedes Patches 1249.00, 1251.00


 +o  Fixes several potential security vulnerabilities where under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the dtterm utility.  Buffer overflows are sometimes exploited in
    an attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2037.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: send disk group option to usage utils for volplex

 SSSSttttaaaatttteeee:::: New


 +o  Fixes a problem in which the volplex command was not sending the disk group
    option specified by the user to the usage type utility when both the usage



                                            Tru64 UNIX Patches 1-105








    type and disk group option are specified on the command line.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2039.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file access

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2057.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT0788U, SSRT0753U, SSRT0752U)

 SSSSttttaaaatttteeee:::: Supersedes Patches 539.00, 208.00, 429.00, 430.00, 432.00, 695.00,
 1003.00, 1004.00, 1005.00, 1006.00, 1283.00, 1008.00, 1560.00, 1561.00,
 1563.00, 1934.00, 1935.00, 1937.00


 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  The ttdbserverd
    contains a potential buffer overflow that may allow unauthorized access.

 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper file access.

 +o  Fixes the problem of palette files not being read from /etc/dt/palettes.

 +o  Fixes the dtprintinfo memory fault problem with long LANG value.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of large values of ENVIRONMENT variables and command line arguments.

 +o  Corrects a potential security vulnerability in CDE Subprocess Control
    Service (dtspcd), which has a potential buffer overflow condition that may
    lead to unauthorized access.

 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of large values of command line arguments.

 +o  Fixes a problem where a CDE session hangs at startup using localized .dt
    files located in the ~/.dt/types directory.

 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.  This may be in the
    form of improper privilege management.



 1-106 Tru64 UNIX Patches








 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the DtSvc utility.  Buffer overflows are sometimes exploited in
    an attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Corrects a potential security vulnerability in CDE that may result in
    unauthorized privileged access.  The potential vulnerability may be in the
    form of local and remote security domain risks.

    SSRT3589 - dtmailpr



 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2061.00

 AAAAbbbbssssttttrrrraaaacccctttt::::Correct handling of IPv6 literal addresses in rcp

 SSSSttttaaaatttteeee:::: New


 +o  Corrects a problem with handling of IPv6 literal addresses in rcp.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2064.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Modification to vdump and vrestore archive programs

 SSSSttttaaaatttteeee:::: Supersedes Patches 479.00, 119.00, 451.00, 3.00, 5.00, 447.00, 449.00,
 113.00, 115.00, 706.00, 707.00, 709.01, 1028.00, 1029.00, 1030.00, 1031.00,
 1032.00, 1033.00, 1034.00, 1035.00, 1036.00, 1037.00, 1038.00, 1040.00,
 1575.00, 1578.00, 1579.00, 1580.00, 1581.00, 2062.00


 +o  Corrects a problem in which access to a file may be denied when multiple
    processes attempt to access the same file at the same time, and access to
    the file should be allowed by an ACL on the file.

 +o  Corrects a problem in which if the ACL on a file is corrupted, the
    corrupted ACL is passed into the kernel causing a variety of problems.

 +o  Corrects a problem in which an AutoFS intercept point for a direct map
    entry may no longer induce automounts after an error has been detected
    during a previous automount attempt.

 +o  Fixes AutoFS problems as follows:


    -  Eliminates error messages concerning property lists seen via certain
       utilities such as vdump.

    -  Causes AutoFS automounts to occur when utilities name intercept points
       defined via indirect map entries.



                                            Tru64 UNIX Patches 1-107








    -  Fixes a deadlock that will occur in non-cluster systems when direct map
       entries are served locally.


 +o  Prevents a core dump from vdump when a message length is greater than
    MAX_MSG_SIZE.

 +o  Fixes vdump command problems as follows:


    -  Fixes a problem in which the command fails to flag compressed extended
       attributes records that are split across a vdump BLOCK boundary.

    -  Corrects a rewinding message to avoid a segfault with Internationalized
       messages.

    -  Fixes vrestore command problems as follows:


       +o  Fixes a problem in which the command fails to flag compressed
          extended attributes records that are split across a vdump BLOCK
          boundary.

       +o  Fixes a problem in which the command fails to set extended attributes
          due to confusion over selective restore of the file or directory
          associated.  Also results in display of the error message "error
          setting extended attributes."

       +o  Fixes a problem in which the selective restore of hard-linked files
          is incomplete when they exist in different directories (fails to
          create directory for second occurrence of file with same inode
          number).


 +o  Eliminates inefficient behavior by autofsd when the top-level directory of
    a direct hierarchical automount map entry cannot be successfully mounted.

 +o  Ensures that AutoFS correctly uses the mount options specified in automount
    map entries with replicated servers.

 +o  Fixes a problem where the tar -F (Fasttar) command ignores files named err
    but does not ignore files named errs and directories named SCCS and RCS.

 +o  Corrects pax/tar/cpio to properly extract explicitly specified files.

 +o  Corrects the behavior of several commands when used in conjunction with
    file systems that are locally served via AutoFS.

 +o  Provides support for wildcards in Linux /etc/exports entries.  Both AutoFS
    and Automount have been so enhanced.

 +o  Fixes a problem in which the aufofsd and autofsmount daemons do not
    properly parse the wildcard (*) character in map files.




 1-108 Tru64 UNIX Patches








 +o  Fixes a problem that prevents access to AutoFS file systems if ACLs are
    enabled.

 +o  Allows auto-unmounts to succeed for direct map entries in which the key
    contains a symbolic link.



 +o  Fixes a one byte gap in the maximum size in the tar command before an
    extended header record is used (8589934591 (octal 77777777777)).

 +o  Eliminates AutoFS automount failures due to the receipt of unexpected
    signals while sleeping in the kernel.

 +o  Corrects find -ls, which displays an incorrect number of blocks.

 +o  Supports a cluster patch that limits DLM lock contention by AutoFS in a
    cluster.

 +o  Fixes a defect that allows the possibility that certain AutoFS automounted
    file systems may be mounted more than once.

 +o  Ensures that autofsmount will process all NIS-provided map files included
    via the plus sign (+) syntax.  Currently, only the first one, at a given
    level of includes, will be correctly processed.

 +o  Eliminates extraneous communication between an AutoFS client and an NFS
    server's mount daemon in some situations when replicated servers are
    specified in an automount map entry.

 +o  Allows AutoFS to correctly handle NIS-based automount maps using the
    wildcard (*) key.

 +o  Corrects two debugging/diagnostic messages in the AutoFS utilities.

 +o  Fixes a cluster-specific problem with AutoFS in which a race condition
    leads to a slowdown, which may lead to automount failures.

 +o  Changes vrestore as follows:


    -  A file or directory name is displayed along with the error message when
       command fails to set a property list

    -  It will not dump core when a tape has a smaller blocksize than expected.

    -  It handles no-rewind tapes properly.

    -  It reads environment variable for user-defined device name.

    -  It allows attributes to be set to the top level directory.


 +o  Fixes tar to properly handle unusual directory specifications.



                                            Tru64 UNIX Patches 1-109








 +o  Corrects the tar program to properly handle unusual directory
    specifications.

 +o  Makes the following changes to vdump and vrestore:


    -  Fixes vdump to receive a Ctrl/c interrupt in the expected way.

    -  Fixes the vdump to pick up correct messages in all locales.

    -  Causes vdump to avoid some unnecessary function calls, thus allowing
       faster vdumps.

    -  Fixes vrestore to receive a Ctrl/c interrupt in the expected way.

    -  Fixes vrestore to pick up correct messages in all locales.

    -  Fixes vrestore to display bit file attributes upon -l option.

    -  Prevents vrestore from failing during a remote system call.

    -  Increases the maximum blocksize for vdump and vrestore.

    -  Fixes a problem that could cause vdump to crash due to compression code
       overflow.

    -  Disallow block sizes greater than 64 K.  This reverses a feature that
       was added in Patch Kit 5 that caused forward compatibility problems.

    -  Allows vdump to properly backup less than 512 byte files from CD-ROM.

    -  Causes the programs to avoid a cluster drd bandwidth problem that occurs
       when a restore is attempted via a private tape drive that is not on the
       current node.

    -  Causes the programs to avoid misinterpretation of archive version, which
       would happen in certain locales, causing vrestore to abort.


 +o  Reports errors emerging from the failure of the close() call for
    devices/files which are on an NFS mount point.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2066.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Revises the sys_attrs_inet.5 reference

 SSSSttttaaaatttteeee:::: New (Supersedes Patch 1705.00)


 +o  Revises the sys_attrs_inet.5 reference page to document the change of the
    increased default values for udp_ttl and tcp_ttl to 128 hops.  and revises
    the sys_attrs_net(5), netstat(1), and route(8) reference pages.




 1-110 Tru64 UNIX Patches








 +o  Revises the sys_attrs_net(5), netstat(1), and route(8) reference pages.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2068.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Resolves a problem that causes rsh process hangs

 SSSSttttaaaatttteeee:::: New


 +o  Resolves a problem that can cause the rsh processes to hang.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2070.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects improper file or privilege management

 SSSSttttaaaatttteeee:::: Supersedes Patches 1722.00, 1723.00, 1725.00


 +o  Corrects several potential security vulnerabilities where.  under certain
    circumstances, system integrity may be compromised.  These may be in the
    form of improper privilege management.

 +o  Fixes the message catalog for the CDE dtprintinfo application.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2072.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Revises volrestore(8) and volsave(8) reference pages

 SSSSttttaaaatttteeee:::: New


 +o  Revises the volrestore(8) and volsave(8) reference pages to document a
    change that allows volsave and volrestore to save nconfig and nlog policies
    for diskgroups and restore them appropriately.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2078.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security fix for sendmail utility

 SSSSttttaaaatttteeee:::: New (Supersedes Patches 1662.00, 1777.00


 +o  Corrects a potential security vulnerability in sendmail which may result in
    non-privileged users gaining unauthorized access to files or privileged
    access on the system.  This potential vulnerability may be in the form of a
    local or remote security domain risk.

 +o  Corrects several potential security vulnerabilities that may result in
    unauthorized Privileged Access or a Denial of Service (DoS).  These
    vulnerabilities may be in the form of local and remote security domain



                                            Tru64 UNIX Patches 1-111








    risks.

    SSRT3631 sendmail - (Severity - High)



 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2084.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2301, SSRT0845U, SSRT2266, SSRT2322)

 SSSSttttaaaatttteeee:::: Supersedes Patches 160.00, 1065.00, 1159.00, 1160.00, 1161.00, 1162.00,
 1164.00, 1352.00, 1264.00, 222.00, 67.00, 582.00, 574.00, 576.00, 703.00,
 839.00, 1012.00, 1013.00, 1014.00, 1015.00, 1017.00, 1344.00, 1346.00, 269.00,
 1025.00, 232.00, 504.00, 1107.00, 181.00, 486.00, 488.00, 191.00, 2.00,
 121.00, 241.00, 243.00, 400.00, 401.00, 402.00, 403.00, 404.00, 405.00,
 406.00, 407.00, 408.00, 409.00, 410.00, 412.00, 307.00, 302.00, 162.00,
 253.00, 255.00, 90.00, 218.00, 303.00, 305.00, 421.00, 422.00, 423.00, 424.00,
 426.00, 681.00, 682.00, 683.00, 684.00, 685.00, 686.00, 687.00, 689.00,
 807.00, 511.00, 729.00, 541.00, 146.00, 148.00, 126.00, 127.00, 128.00,
 129.00, 130.00, 131.00, 132.00, 134.00, 286.00, 6.00, 7.00, 8.00, 9.00, 10.00,
 11.00, 12.00, 13.00, 14.00, 15.00, 16.00, 17.00, 18.00, 19.00, 20.00, 21.00,
 22.00, 23.00, 24.00, 25.00, 26.00, 27.00, 28.00, 29.00, 30.00, 31.00, 32.00,
 33.00, 34.00, 35.00, 36.00, 37.00, 38.00, 39.00, 40.00, 41.00, 42.00, 43.00,
 44.00, 45.00, 46.00, 47.00, 48.00, 49.00, 50.00, 51.00, 52.00, 53.00, 54.00,
 55.00, 56.00, 57.00, 58.00, 59.00, 60.00, 61.00, 102.00, 63.00, 104.00,
 214.00, 236.00, 246.00, 247.00, 248.00, 250.00, 270.00, 271.00, 272.00,
 273.00, 274.00, 275.00, 276.00, 277.00, 279.00, 296.00, 298.00, 321.00,
 323.00, 325.00, 290.00, 152.00, 93.00, 95.00, 328.00, 329.00, 330.00, 331.00,
 332.00, 333.00, 334.00, 335.00, 336.00, 337.00, 338.00, 339.00, 340.00,
 341.00, 342.00, 343.00, 344.00, 345.00, 346.00, 347.00, 348.00, 349.00,
 350.00, 351.00, 352.00, 353.00, 354.00, 355.00, 356.00, 357.00, 358.00,
 359.00, 360.00, 361.00, 362.00, 363.00, 364.00, 365.00, 366.00, 367.00,
 368.00, 369.00, 370.00, 371.00, 372.00, 373.00, 374.00, 375.00, 376.00,
 377.00, 378.00, 379.00, 380.00, 381.00, 382.00, 383.00, 384.00, 385.00,
 386.00, 387.00, 388.00, 389.00, 390.00, 391.00, 392.00, 393.00, 394.00,
 395.00, 396.00, 397.00, 399.00, 543.00, 590.00, 592.00, 596.00, 203.00,
 594.00, 597.00, 598.00, 599.00, 600.00, 601.00, 602.00, 603.00, 604.00,
 605.00, 606.00, 607.00, 608.00, 609.00, 610.00, 611.00, 612.00, 613.00,
 614.00, 615.00, 616.00, 617.00, 618.00, 619.00, 620.00, 621.00, 622.00,
 623.00, 624.00, 625.00, 626.00, 627.00, 628.00, 629.00, 630.00, 631.00,
 632.00, 633.00, 634.00, 635.00, 636.00, 637.00, 638.00, 639.00, 640.00,
 641.00, 642.00, 643.00, 644.00, 645.00, 646.00, 647.00, 648.00, 649.00,
 650.00, 651.00, 652.00, 653.00, 654.00, 655.00, 656.00, 657.00, 658.00,
 659.00, 660.00, 661.00, 662.00, 663.00, 664.00, 665.00, 666.00, 667.00,
 668.00, 669.00, 671.00, 672.00, 673.00, 674.00, 675.00, 676.00, 677.00,
 678.00, 680.00, 834.00, 835.00, 837.00, 842.00, 846.00, 853.00, 854.00,
 855.00, 856.00, 857.00, 858.00, 859.00, 860.00, 861.00, 862.00, 863.00,
 864.00, 865.00, 866.00, 867.00, 868.00, 869.00, 870.00, 871.00, 872.00,
 873.00, 874.00, 875.00, 876.00, 877.00, 878.00, 879.00, 880.00, 881.00,
 882.00, 883.00, 884.00, 885.00, 886.00, 887.00, 888.00, 889.00, 890.00,
 891.00, 892.00, 893.00, 894.00, 895.00, 896.00, 897.00, 898.00, 899.00,
 900.00, 901.00, 902.00, 903.00, 904.00, 905.00, 906.00, 907.00, 908.00,
 909.00, 910.00, 911.00, 912.00, 913.00, 914.00, 915.00, 916.00, 917.00,
 918.00, 919.00, 920.00, 921.00, 922.00, 923.00, 924.00, 925.00, 926.00,



 1-112 Tru64 UNIX Patches








 927.00, 928.00, 929.00, 930.00, 931.00, 932.00, 933.00, 934.00, 935.00,
 936.00, 937.00, 938.00, 939.00, 940.00, 941.00, 942.00, 943.00, 944.00,
 945.00, 946.00, 947.00, 948.00, 949.00, 950.00, 951.00, 952.00, 953.00,
 954.00, 955.00, 956.00, 957.00, 958.00, 959.00, 960.00, 961.00, 962.00,
 963.00, 964.00, 965.00, 966.00, 967.00, 968.00, 969.00, 970.00, 971.00,
 972.00, 973.00, 974.00, 975.00, 976.00, 977.00, 978.00, 979.00, 980.00,
 981.00, 982.00, 983.00, 984.00, 985.00, 986.00, 987.00, 988.00, 80.00, 418.00,
 780.00, 782.00, 1215.00, 990.00, 1217.00, 1248.00, 1320.00, 1322.00, 1323.00,
 1324.00, 1326.00, 1338.00, 1339.00, 1340.00, 1341.00, 1343.00, 1355.00,
 1360.00, 1362.00, 1363.00, 1364.00, 1365.00, 1367.00, 125.00, 309.00, 460.00,
 461.00, 463.00, 734.00, 735.00, 737.00, 1130.00, 1131.00, 1132.00, 1134.00,
 97.00, 84.00, 1170.00, 1379.00, 1380.00, 1381.00, 1382.00, 1383.00, 1384.00,
 1385.00, 1386.00, 1387.00, 1388.00, 1389.00, 1390.00, 1391.00, 1392.00,
 1393.00, 1394.00, 1395.00, 1396.00, 1397.00, 1398.00, 1399.00, 1400.00,
 1401.00, 1402.00, 1403.00, 1404.00, 1405.00, 1406.00, 1407.00, 1408.00,
 1409.00, 1410.00, 1411.00, 1412.00, 1413.00, 1414.00, 1415.00, 1416.00,
 1417.00, 1418.00, 1419.00, 1420.00, 1421.00, 1422.00, 1423.00, 1424.00,
 1425.00, 1426.00, 1427.00, 1428.00, 1429.00, 1430.00, 1431.00, 1432.00,
 1433.00, 1434.00, 1435.00, 1436.00, 1437.00, 1438.00, 1439.00, 1440.00,
 1441.00, 1442.00, 1443.00, 1444.00, 1445.00, 1446.00, 1447.00, 1448.00,
 1449.00, 1450.00, 1451.00, 1452.00, 1453.00, 1454.00, 1455.00, 1456.00,
 1457.00, 1458.00, 1459.00, 1460.00, 1461.00, 1462.00, 1463.00, 1464.00,
 1465.00, 1466.00, 1467.00, 1468.00, 1469.00, 1470.00, 1471.00, 1472.00,
 1473.00, 1474.00, 1475.00, 1476.00, 1477.00, 1478.00, 1479.00, 1480.00,
 1481.00, 1482.00, 1483.00, 1484.00, 1485.00, 1486.00, 1487.00, 1488.00,
 1489.00, 1490.00, 1491.00, 1492.00, 1493.00, 1494.00, 1495.00, 1496.00,
 1497.00, 1498.00, 1499.00, 1500.00, 1501.00, 1502.00, 1503.00, 1504.00,
 1505.00, 1506.00, 1507.00, 1508.00, 1509.00, 1510.00, 1511.00, 1512.00,

 1513.00, 1514.00, 1515.00, 1516.00, 1517.00, 1518.00, 1519.00, 1520.00,
 1521.00, 1522.00, 1523.00, 1524.00, 1525.00, 1526.00, 1527.00, 1528.00,
 1529.00, 1530.00, 1531.00, 1532.00, 1533.00, 1534.00, 1535.00, 1537.00,
 1602.00, 1781.00, 1787.00, 1788.00, 1789.00, 1790.00, 1791.00, 1792.00,
 1793.00, 1794.00, 1796.00, 1805.00, 1806.00, 1807.00, 1808.00, 1809.00,
 106.00, 1179.00, 1727.00, 1811.00, 1826.00, 1827.00, 1828.00, 1830.00, 195.00,
 1315.00, 1832.00, 1833.00, 1834.00, 1835.00, 1837.00, 1838.00, 1839.00,
 1840.00, 1841.00, 1842.00, 1843.00, 1844.00, 1845.00, 1846.00, 1847.00,
 1848.00, 1849.00, 1850.00, 1851.00, 1852.00, 1853.00, 1854.00, 1855.00,
 1856.00, 1857.00, 1858.00, 1859.00, 1860.00, 1861.00, 1862.00, 1863.00,
 1864.00, 1865.00, 1866.00, 1867.00, 1868.00, 1869.00, 1870.00, 1871.00,
 1872.00, 1873.00, 1874.00, 1875.00, 1876.00, 1877.00, 1878.00, 1879.00,
 1880.00, 1881.00, 1882.00, 1883.00, 1884.00, 1885.00, 1886.00, 1887.00,
 1888.00, 1889.00, 1890.00, 1891.00, 1892.00, 1893.00, 1894.00, 1895.00,
 1896.00, 1897.00, 1898.00, 1899.00, 1900.00, 1901.00, 1902.00, 1903.00,
 1904.00, 1905.00, 1906.00, 1907.00, 1908.00, 1909.00, 1910.00, 1911.00,
 1912.00, 1913.00, 1915.00, 2040.00, 2041.00, 2042.00, 2043.00, 2044.00,
 2045.00, 2046.00, 2047.00, 2048.00, 2049.00, 2050.00, 2051.00, 2052.00,
 2053.00, 2055.00, 2074.00, 2076.00, 2079.00, 2080.00, 2081.00, 2082.00


 +o  Fixes a problem in which the cp and cat commands produce different file
    sizes when reading from a tape device.  It also corrects the cp command
    performance related to the problem.




                                            Tru64 UNIX Patches 1-113








 +o  Adds support for new devices branded by HP.

 +o  Adds latent device recognition support for MSA1000 storage array
    controllers.

 +o  Enhances SuperDLT maximum transfer size edit to be more tolerant of
    previous changes.

 +o  Provides device support for the SDLT160/320 tape drive.

 +o  Adds support for Ultrium 2 SCSI tape drive.

 +o  Adds latent support for logical devices.

 +o  Provides support for the Ultrium tape drive.

 +o  Corrects a potential security vulnerability which, under certain
    circumstances, could compromise system integrity.  This may be in the form
    of improper file access.

 +o  Fixes a problem where the mv command will not perform a move if the inode
    of the file is the same as the inode of the destination directory, even
    though the file and directory are on different file systems.

 +o  Prevents a vold from core dumping when removing a disk from rootdg using
    voldiskadm or voldg.

 +o  Prevents a KMF (kernel memory fault) panic, in voldiskiostart(), when an
    I/O is attempted on an LSM device that is not accessible.

 +o  Prevents vold from core dumping on booting with the message:

    Commit: not holding dg lock

 +o  Proves enabler for Enterprise Volume Manager product.

 +o  Fixes a situation in which when a cluster member fails, mirrored volumes
    are left in a state such that recovery is always necessary when members
    boot, even if no additional recovery should be necessary.

 +o  Fixes a collision problem with clsm sync and LSM startup.

 +o  Fixes a problem of a vold core dump when old config db exists.

 +o  Fixes a problem where cluster node panics on boot if klog does not exist.

 +o  Fixes a problem of LSM not recognizing third-party disks.

 +o  Fixes an inability to create a new diskgroup when vold is in noloadbalance
    mode.

 +o  Fixes error messages for non-rootdg disks when cluster root is under LSM
    control.




 1-114 Tru64 UNIX Patches








 +o  Fixes problems in LSM's autoconfiguration feature, as well as some problems
    in the LSM commands volsave, volrestore, and volclonedg.

 +o  Fixes several potential security vulnerabilities where, under certain
    circumstances, system integrity may be compromised.

 +o  Allows the proper synchronization of disk errors and failures in a cluster
    under CLSM control.

 +o  Fixes a volrecover error of "Cannot refetch volume" when volumes exist only
    in a non-rootdg diskgroup.

 +o  Moves the control of the start and stop of the clu_mibs agent from
    /sbin/init.d/clu_max script to /sbin/init.d/snmpd script.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised through improper file
    access (overwriting of files).  This potential vulnerability is in the form
    of a local security domain risk.  The following potential security
    vulnerability has been corrected:

    SSRT2301 uudecode (Severity - Medium)


 +o  Fixes a problem in NetRAIN by causing NetRAIN interface creation to fail if
    any of the requested standby interfaces do not exist.

 +o  Adds support to ifconfig application for the IPv6 command line argument
    ip6reachabletime.

 +o  Fixes a class scheduler semaphore race condition.  The class scheduler
    depends on semaphores to protect its database from simultaneous updates.
    This patch automatically detects if the semaphore no longer exists and
    allocates a new one, allowing the class scheduler to proceed without
    interruption.

 +o  Fixes a problem where logins appear to be hung on standalone systems with
    Enhanced Security enabled.

 +o  Fixes a regular expression matching problem in multibyte locales.

 +o  Fixes the -ignore_all_versions and -ignore_version flags for the run-time
    loader (/sbin/loader).

 +o  Fixes a problem where strtod() was returning different outputs for the same
    input.

 +o  Fixes a problem where the tan() function was returning the wrong results.

 +o  Eliminates a libc memory leak that occurred when calling dlclose() in
    applications linked with the threads run-time environment.

 +o  Changes the optional dynamic loader arguments -allocator_range and
    -allocator to -preallocated_range.



                                            Tru64 UNIX Patches 1-115








 +o  Fixes a problem in mktime() when adjusting for a tm struct containing an
    invalid tm_isdst (daylight savings time) setting.

 +o  Fixes a segmentation fault problem with long LOCPATH and LANG values.

 +o  Fixes a problem in which the RPC TCP server incorrectly tries to write to a
    socket that has already been closed by a client.

 +o  Fixes an application core dump problem when the LANG environment variable
    is too long.

 +o  Fixes a problem with the fopen() function in which fopen() returned a "file
    not found" message when insufficient memory was available to allocate the
    FILE structure.  With this patch, the fopen() function now returns the
    message "not enough space" for this case.

 +o  Fixes a problem in fread() in which excessive I/O was taking place for
    large amounts of data, causing performance problems.  It also addresses a
    failure in fread() to properly handle data sizes that have representations
    greater than 32 bits (2^32 of data).



 +o  Fixes a loader core dump that occurs when invoking certain call_shared
    executables that have been processed by post-link instrumentation tools.

 +o  Fixes a problem with the strerror() function in which buffers could not be
    allocated.

 +o  Fixes a problem with the fwrite() function in which it failied when the
    total number of bytes to be written is larger than 2 GB.

 +o  Fixes a regular expression problem with the REG_NEWLINE flag of the
    regexec() routine.

 +o  Resolves a memory leak and a filtering issue in the Event Manager (EVM),
    and allows the evmwatch utility to reconnect automatically if evmd fails
    and is restarted.

 +o  Provides enablers for the Compaq Database Utility.

 +o  Fixes a problem in which binary error log (binlog) events posted by the EMX
    FibreChannel driver and the system console are reported incorrectly by the
    Event Manager.

 +o  Provides the /usr/lbin/mkstemp program which allows the mechanism to create
    a secure temporary file.

 +o  Fixes a problem in which the EVM daemon acting as a subscribing client
    within a cluster will unexpectedly drop the connection to the other EVM
    daemons in the cluster.  This may happen when an EVM client subscribes to
    events specifying the cluster alias.

 +o  Resolves an issue which can cause an Event Manager client or the EVM daemon



 1-116 Tru64 UNIX Patches








    to core dump under rare circumstances.

 +o  Fixes a sys_check problem in which verification of invoking a processes'
    name in CLISCRIPT failed due to the PARSING of ps command output.

 +o  Fixes a multi-thread timing window in malloc and free where the list of
    free chunks could become corrupted, resulting in a segfault.

 +o  Fixes a regular expression performance problem in sed.

 +o  Fixes a problem with printing long double values.

 +o  Fixes a performance degradation in malloc, in applications which perform
    many mallocs and few frees.  With this patch, the performance of malloc is
    constant regardless of the number of allocated chunks outstanding.

 +o  Fixes a problem with atexit() or pthread_atfork() handlers in shared
    libraries.  An application will crash when handlers in shared libraries are
    called after the libraries are dlclosed and unmapped.

 +o  Fixes a problem in which compiled format doprnt code does not handle
    precision correctly.

 +o  Corrects the following problems with the alt driver for DEGPA Gigabit
    Ethernet adapters.  These problems affect all Tru64 systems using alt with
    vMAC or NetRAIN:


    -  Fixes vMAC to let it work with DEGPA.

    -  Prevents two DEGPA adapters from getting the same MAC address in a
       NetRAIN configuration.

    -  Fixes a problem with RLIMIT_DATA process limits when running fsck on a
       large file system.

    -  Fixes "ata_probe: reset failed, sts=0x7f, err=0x7f" errors for IDE disks
       not connected to the system.


 +o  Fixes a rare emx driver boot issue and a rare heavy load I/O hang.

 +o  Updates the emx driver to v2.03 to fix a problem that could cause the
    driver panic during adapter resets.



 +o  A previous release of this patch updated the emx driver to v2.02 to correct
    the following problems:


    -  A panic of cannot grow probe list

    -  A problem of a mcs_lock panic when an adapter experiences a h/w hang



                                            Tru64 UNIX Patches 1-117








       condition


 +o  A previous release of this patch updated the emx driver to v2.01 to correct
    the following problems:


    -  A problem of unexpected tape I/O aborts

    -  Panic of "can't grow probe list"

    -  Several kernel memory faults within the driver

    -  Redundant adapter failures no longer panic the system

    -  A problem of panicking with low memory resources

    -  Stalling I/O during reprobing when a cluster member goes down


 +o  Fixes problems seen with the loading and unloading of dynamic drivers.

 +o  Fixes a problem when using the VX1 graphics module in which the mouse
    cursor disappears when moved along left- and top-most edge.

 +o  Fixes a kernel crash dump generation problem that resulted in the wrong
    pages being compressed and written.  Without this fix, postmortem debugging
    may be difficult or impossible.

 +o  Fixes a "simple_lock timeout" system panic due to a bug between mcs_unlock
    and mcs_lock_try on the same CPU.

 +o  Provides New Hardware Delivery V4 (NHD4) enablers for future hardware
    support including:


    -  Graphic devices

    -  A new platform

    -  An array controller


 +o  Fixes a domain panic pointing to quotaUndo, when a domain has a fileset
    with a clone, the clone is deleting, and a file in the fileset finds no
    space available in the domain.

 +o  Provides a new /usr/sbin/wol command that utilizes the Wake feature for a
    future platform.

 +o  Fixes a time loss problem seen on DS systems only when using console
    callbacks.  The patch resynchronizes the clock when time loss is detected.

 +o  Fixes a rare panic in the driver for the DE600/DE602 10/100 Ethernet



 1-118 Tru64 UNIX Patches








    adapter.

 +o  Corrects a problem where the network subsystem sometimes sends a null TCP
    packet when a connection is reset.

 +o  Provides enabler support for Enterprise Volume Manager product.

 +o  Fixes a system panic with "malloc_check_checksum: memory pool corruption."

 +o  Fixes a problem in which issuing a quot -h command causes a memory fault
    when the /etc/fstab file contains a mount point that is not mounted.

 +o  Fixes a problem with IPv6 raw socket creations.

 +o  Corrects a CFS problem that could cause a panic with the panic string of
    "CFS_INFS full."

 +o  Fixes a problem with erroneous data being returned from the DEVIOCGET ioctl
    if an error occurs while processing the ioctl.

 +o  Fixes a problem in which a TCP socket can continue to receive data with no
    application running.



 +o  Fixes a performance problem and the results are large performance increases
    in configurations where more than eight tapes are supported on a
    FibreChannel (usually behind an MDR or FCTCII).

 +o  Fixes problems found with RAID Services that include:


    -  RAID services not acknowledging presence of CAM RAID device

    -  A hang, the inability to prohibit a user from deleting a logical volume
       while it is in use

    -  A "malloc_check_checksum: memory pool corruption" system panic


 +o  Fixes a problem in which threads can hang in x_load_inmem_xtnt_map().

 +o  Fixes the following Virtual Memory problems.  The first three are seen on
    NUMA systems only, and the fourth problem can be seen on any system type:


    -  A "vm_pg_alloc: page not free" system panic that occurs during process
       migration.

    -  A "vm_pageout_activate: page already active" system panic that occurs if
       one thread is unlocking some pages in memory while another thread is
       migrating them.

    -  Memory inconsistencies caused by a fault path for large shared memory



                                            Tru64 UNIX Patches 1-119








       regions prematurely releasing a hold on a page it just locked.  This can
       cause variety of problems including user program errors and system
       panics.

    -  A "simple_lock: time limit exceeded" system panic that occurs if very
       large (8 MB or larger) System V Shared memory regions are in use.


 +o  Allows a single ddr.dbase entry to support a particular SCSI device on both
    parallel SCSI and FC busses.  Previously, SCSI devices connected behind an
    FCTCII or MDR would not be properly associated with their ddr.dbase entry.

 +o  Fixes a problem in which a panic occurs while task swapping.

 +o  Fixes a problem in virtual memory that can cause a kernel memory fault.

 +o  Fixes a problem in which the I/O transfer rate can suddenly drop when
    writing to a hole in an AdvFS domain, when a volume in that domain becomes
    full.

 +o  Fixes a problem with the memory troller attempting to post an EVM event
    indicating that a particular PFN has been mapped out.

 +o  Fixes lock time issues and UBC performance problems, and provides AdvFS and
    UFS performance improvements in systems (other than the AlphaServer GS80,
    GS160, and GS320) with low memory.

 +o  Fixes several problems related to shared memory (memory that can be
    accessed by more than one CPU) that could lead to panics, hangs, and
    performance problems.

 +o  Fixes a bug that can cause performance problems for certain applications
    when the sysconfigtab parameter ipc:sem_broadcast_wakeup is set to 0.

 +o  Fixes a problem in which a check for managed address may return an invalid
    value when called with the address of a gh region not on rad 0.

 +o  Fixes a kernel memory fault in msg_rpc_trap.

 +o  Fixes a potential problem with lost data after a direct I/O write with a
    file extension followed quickly by a system crash.

 +o  Fixes a crash that occurs when disk controllers are restarted repeatedly.

 +o  Fixes a "u_shm_oop_deallocate: reference count mismatch" error due to a
    problem in the locking mechanism when gh_chunks are in use.

 +o  Provides I/O barrier code that prevents HSG80 controller crashes (firmware
    issue).



 +o  Corrects the problem of a thread deadlocking against itself under the
    following conditions:



 1-120 Tru64 UNIX Patches








    -  Running in a cluster.

    -  Opening (and then closing) a directory that has an index file.

    -  Trying to open the index file through .tags (for example, defragment)
       and by coincidence getting the vnode that pointed to the directory that
       the index file is attached to.


 +o  Fixes the kernel panic "bs_invalidate_rsvd_access_struct:  bad access
    struct."

 +o  Ensures that DMAPI region information maintains consistency across CFS
    server and client nodes in the case that an unexpected node failure occurs.

 +o  Fixes a problem where additional HSZ70 control ports, /dev/cport/scpN, were
    created during HSZ70 controller failover operations.

 +o  Prevents a crash seen while deleting SCSI devices using hwmgr.

 +o  Fixes a problem where new devices could be created when following the HSZ70
    controller failover procedure.

 +o  Fixes a problem in which reading a clone file that is still in the cache
    after using the rmvol utility may panic the system.

 +o  Fixes a problem where a variable was used without being initialized, which
    could lead to a possible kernel memory fault.

 +o  Fixes a performance problem and the results are large performance increases
    in configurations where more than eight tapes are supported on a Fibre
    Channel (usually behind an MDR or FCTCII).

 +o  Fixes problems found with RAID Services that include:


    -  RAID services not acknowledging presence of CAM RAID device

    -  A hang, the inability to prohibit a user from deleting a logical volume
       while it is in use

    -  A "malloc_check_checksum: memory pool corruption" system panic


 +o  Fixes a problem in which threads can hang in x_load_inmem_xtnt_map().

 +o  Provides several changes to CAM:


    -  Fixes a problem where passthrough IOCTL fails with EIO (CAM_BUSY).

    -  Fixes a RESERVATION CONFLICT driver BUSY problem.

    -  Enforces superuser-only access for SCSI passthrough.



                                            Tru64 UNIX Patches 1-121








 +o  Provides AdvFS and VFS support for the freezefs and thawfs commands.

 +o  Provides EVM V2 enablers.

 +o  Enables access to SCSI control ports (/dev/cport/scp??), allowing
    management of some types of RAID controllers.

 +o  Eliminates unintended AutoFS automount storms.

 +o  Fixes a problem where extraneous "This node removed from cluster" events
    cause panics of cluster nodes.

 +o  Fixes a panic that occurs if DMAPI operations are erroneously executed on
    an NFS file system.

 +o  Processes triggering stack growth with anon_rss_enforce set to 2, and
    exceeding the set resident memory limit hang or panic.

 +o  Fixes a kernel panic with "xfer_hole_stg: unaligned kernel access" or
    "xfer_hole_stg: kernel memory fault."

 +o  Fixes a timing window where flushing data to disk can be incomplete when a
    system is going down, if more than one thread calls reboot() without first
    going through shutdown, /sbin/reboot, or /sbin/halt.



 +o  Ensures that if an AdvFS file is opened for both O_DIRECTIO and O_APPEND,
    threads racing to append data to the file will be correctly synchronized,
    and all data will be appended to the file.

 +o  Fixes several direct I/O problems seen when using the aio interface.  The
    symptoms include a kernel memory fault, and an aio condition that causes a
    live_dump to be generated.

 +o  Fixes a condition where the smoothsync thread, in attempting to flush dirty
    buffers for memory-mapped files, would also flush buffers for non-memory-
    mapped files.  This did not cause any errors, but could cause more I/O than
    necessary to be done.

 +o  Allows POSIX semaphores/msg queues to operate properly on a CFS client.

 +o  Fixes a problem where running verify may panic the system.

 +o  Corrects a condition in which a kernel memory fault may occur while
    attempting to read a log record.

 +o  Prevents a race in msfs_umount.

 +o  Provides a fix to a deadlock situation that can occur when invoking the
    hwmgr-showcomp command while the devices on an HSZ70 are changing their
    names.

 +o  Fixes a problem where network interfaces can appear unresponsive to network



 1-122 Tru64 UNIX Patches








    traffic.

 +o  Fixes a problem where "path reduced" messages are printed at boot time for
    devices that still have at least one valid path.

 +o  Enables the quick reclaim and deallocation of a vnode.

 +o  Fixes a problem where a panic may occur when the DMAPI functionality is in
    use.

 +o  Fixes a problem where the setgid bit of a directory was not being set when
    created, if its parent directory had the setgid bit set.

 +o  Makes several changes to kernel routing:


    -  Fixes a problem that caused a panic when deleting an IP address.

    -  Fixes a problem of a panic when performing IP reconfiguration.

    -  Adds an interface route on address configuration.


 +o  Fixes a problem that caused an "ics_unable_to_make_progress:  input thread
    stalled" panic.

 +o  Addresses three UBC issues:


    -  Reinstates ubc_maxpercent hardlimit behavior.

    -  Allows the UBC to purge and steal pages under very low free memory
       conditions during page allocation.

    -  Removes memory mapping for NFS pages being invalidated and freed.  Pages
       were being freed but still mapped to the process.


 +o  Fixes NFS support for the Enterprise Volume Manager product.

 +o  Corrects a performance problem in which NFS V3 I/O used larger than
    necessary buffers when writing to locked files, resulting in lower
    throughput.

 +o  Provides a script, /usr/sbin/evm_versw_undo, that will allow a user to
    remove the EVM patch after the version switch has been thrown by running
    clu_upgrade -switch.  This script will set back the version identifiers and
    request a cluster shutdown and reboot to finish the deletion of the patch.
    Another rolling upgrade will be required to delete the patch with dupatch.



 +o  Enables a version-switched patch.




                                            Tru64 UNIX Patches 1-123








 +o  Causes a SCSI check condition with NO SENSE status to be treated by the
    disk driver as a condition to retry the I/O.

 +o  Fixes a condition in which a panic that could occur if an illegal argument
    is passed to UFS mount by a root user.

 +o  Fixes a kernel build failure when AdvFS is excluded from the build.

 +o  Fixes a problem where the system may be hung or there are poor response
    times on systems with limited numbers of CPUs.

 +o  Fixes a condition that causes an "RDG unwire panic" when running with RDG
    and GH chunks.

 +o  Resolves a problem where duplicate attributes are registered for all CAM
    devices present in a system.  This affects iostat output and any other
    application that relies on the attribute data.

 +o  Adds workarounds for additional firmware problems found in the HSx
    controller.

 +o  Fixes for scheduler at high load averages and initial NUMA process
    placement.

 +o  Fixes an rmvol failure that would be seen as an E_PAGE_NOT_MAPPED error
    when no more space is available for user data migration to another volume
    in the domain.

 +o  Fixes the following tape drive problems:


    -  Tape devices in multipath configurations unexpectedly rewind or go off
       line.  (Multipath means that I/O can reach the device by an alternate
       data path, such as a redundant controller or bus.) Note that this patch
       reverts the tape drive configuration to single path mode.

    -  The vdump utility fails to close because the drive goes offline before
       the dump operation is complete.  An error message similar to the
       following is displayed:

       vdump: unable to properly close device ; [5] I/O error


 +o  Fixes a problem in which opening a disk partition sometimes fails when the
    disk is on shared bus.

 +o  Fixes a kernel memory fault panic on NUMA systems because of corrupt UBC
    LRU.

 +o  Fixes a problem of poor interactive response, including hanging commands
    and logins and random drops in I/O rates when writing many large files.

 +o  Fixes a potential problem in which stale data may be returned to an
    application running on a CFS client when it reads data from a file on a CFS



 1-124 Tru64 UNIX Patches








    server.  Another possible symptom is incomplete flushing of user data when
    an fsync() is issued or an O_[D]SYNC write is performed.

 +o  Fixes a problem where new barrier code will not reserve after a
    registration if a new device or cluster is installed.

 +o  Fixes a problem where HSV110 Persistent Reserve with a Reservation conflict
    SCSI status gets passed off to cam_notify when it should not, resulting in
    incorrect reservation status.

 +o  Fixes a problem with data inconsistency that can occur when a CFS client
    reads a file that was recently written to.

 +o  Fixes SEL logging problem where panic events were logged as misc events.
    It also adds new event types that can be logged.

 +o  Fixes a problem in which the system could panic while performing CPU
    hotswap.



 +o  Fixes a problem in which Link Aggregation groups can be successfully
    created and configured but are unable to successfully transmit and receive
    packets over the resulting lag interface.

 +o  Prevents a potential panic with non-StorageWorks RAID controllers that used
    the same name for a controller and a disk drive.  Although this conflict
    was resolved in a prior release, it was possible that an attempt by the
    kernel to access the disk drive could result in a system panic.

 +o  Provides support for a related cluster patch.

 +o  Removes a panic seen at boot time of the form:

    Panic (cpu 6): u_anon_oop_deallocate: anon_rss_pagelist has pages queued


 +o  Fixes a kernel memory fault in wait_to_readyq(), advfs_page_busy(), or
    potentially other routines that may reference a vm_page, bsBuf or ioDesc
    that has been freed prematurely.

 +o  Fixes the C++ incompatibility of the following:

    /usr/include/io/dec/bi/bdareg.h /usr/include/io/dec/bi/buareg.h
    /usr/include/io/dec/eisa/aceregs.h /usr/include/io/dec/eisa/eisa.h
    /usr/include/io/dec/fbus/fbusreg.h /usr/include/io/dec/pci/pci.h
    /usr/include/io/dec/pcmcia/pcmcia.h /usr/include/io/dec/pcmcia/ti1130_reg.h
    /usr/include/io/dec/tc/sccreg.h /usr/include/io/dec/tc/tc.h
    /usr/include/io/dec/ws/comet_driver.h /usr/include/io/dec/ws/comet_regs.h
    /usr/include/io/dec/ws/inputdriver.h /usr/include/io/dec/ws/ws_driver.h


 +o  Restores the cam_logger() interface to its published specifications, and
    introduces the cam_logger3() interface to accept a hardware ID in its



                                            Tru64 UNIX Patches 1-125








    parameter list.

 +o  Addresses a potential UBC panic that could occur when accessing CFS file
    systems.

 +o  Fixes a problem with vm_faults against anon objects mapped by multiple map
    entries.

 +o  Provides ECC Enhancements for DTAG error logging for AlphaServer GS80,
    GS160, and GS320 systems.

 +o  Fixes a problem where decreasing the smoothsync_age does not always have an
    effect.

 +o  Fixes system panic and data corruption caused by changing the fifo
    parameter pipe-databuf-size while fifo operations are in flight.

 +o  Fixes AdvFS synchronization problems with lingering I/O messages during
    domain deactivation or rmvol actions.

 +o  Fixes problems caused by certain kmem_debug settings (kmem_debug=0x40,
    kmem_protected_size=4096) and AdvFS's handling of freed memory.

 +o  Fixes and provides enhancements to Tru64 UNIX to support Encore realtime
    software.

 +o  Modifies the rmvol command error messages to reflect why rmvol fails.

 +o  Modifies the showfdmn command so it does not print success message on a
    failure.  For example:

    showfdmn: unable to get info for domain 'domain_used' showfdmn: Successful




 +o  Fixes a potential CFS deadlock.

 +o  Fixes a problem when running ssh v2.4.0 and v2.4.1 when executing ls in
    sftp and when uploading public key using ssh-pubkeymgr.

 +o  Fixes SEL logging problem where panic events were logged as misc events.
    It also adds new event types that can be logged.

 +o  Corrects a problem that is encountered when trying to create an Oracle
    database on an AlphaServer GS80, GS160, or GS320 system that has a
    memoryless QBB.  Without this patch, direct I/O to an AdvFS file using
    asynchronous I/O will hang if it is completed on a memoryless QBB.

 +o  Corrects problems when running the dd utility on a disk with a label.  It
    would not return errors when expected.

 +o  Fixes a problem with I/O suspended (hung) in a cluster configuration where
    one or more rad does not have a valid, initialized path.



 1-126 Tru64 UNIX Patches








 +o  Fixes a problem that causes bugchecks from applications running DecThreads.

 +o  Fixes a problem for locking on retry case for multi-threaded select/poll.
    For example: PANIC: "thread_block: simple lock owned."

 +o  Fixes a potential problem where system responsiveness may be impacted.

 +o  Fixes a kernel memory fault in DMAPI code under cluster stress conditions.

 +o  Fixes a calculation leading to poor hash table distribution for NFS client
    mount points in the cluster.

 +o  Eliminates unintended AutoFS automounts, in particular those that may
    result via the execution of the df command on systems running Tru64 UNIX
    versions earlier than Version 5.0.

 +o  Corrects a problem in which multi-volume AdvFS V3 domains exhibit I/O
    errors that are not attributable to hardware.  The same problem also causes
    a failed mkfset due to ENO_XTNTS.

 +o  Corrects a problem with storage allocation by reducing the number of extent
    maps generated, subsequently giving better I/O performance on the resulting
    file.  Prior to this modification, storage allocation for a file opened for
    direct I/O could, depending on the write sizes requested, have large extent
    maps even though the disk is not fragmented.  Although the file functions
    correctly, performance is reduced by the numerous extent maps.

 +o  Corrects a problem in which file permissions inherited from a default ACL
    may be different than expected in rare cases.

 +o  Corrects a problem where the DLI queue stalls when there is no traffic in
    the TCP/IP or HDLC stacks.

 +o  Corrects a problem whereby clocks on systems could move backwards after
    subsequent relocations of the root file system using the cfsmgr command.

 +o  Corrects a problem where a "kernel stack not valid" halt on a CPU will
    trigger a "PANIC TB_SHOOT ACK TIMEOUT" or lock timeout on a non-NUMA
    system.

 +o  Corrects a problem with a simple lock timeout, or a panic due to holding a
    simple lock during a context switch on a non-NUMA system.

 +o  Corrects an issue seen on NFS clients.  The aggressive behavior of client
    negative lookup cache for concurrent create/lookup was corrected.

 +o  Corrects an issue with mmaped() files on a NFS-mounted file system in which
    changes to an mmaped() file were not immediately seen.



 +o  Fixes a problem where the tape changer is only accessible from member that
    is the drd server for the changer.




                                            Tru64 UNIX Patches 1-127








 +o  Fixes a problem where socket-based applications can hang in soclose().

 +o  Fixes a problem during file system relocation in which the system may panic
    due to a kernel memory fault when a directory larger than 8192 bytes has
    been deleted, while simultaneously being accessed by another thread.

 +o  Corrects a kernel memory fault on multiple CPU systems when two or more
    CPUs find an AdvFS problem at the same time.

 +o  Fixes a problem where, after a system crash, there is a domain panic on
    reboot.

 +o  Corrects the problem where attempts to delete psets can hang the system.

 +o  Prevents an AdvFS metadata inconsistency in the event of a system crash.

 +o  Prevents a possible extent map corruption when multiple volumes are full.

 +o  Fixes a problem with multi-threaded applications that can cause the
    application to consume 100 percent of the CPU usage time.

 +o  Fixes a domain panic in a cluster when a file system is mounted on a disk
    accessed remotely over the cluster interconnect.

 +o  Fixes a locking problems in vclean().

 +o  Fixes the CEH bus/target and LUN number when the LUN is greater than 127.

 +o  Fixes a kernel memory fault when freeing devices.

 +o  Corrects problems with USB causing panics on heavily stressed systems.

 +o  Corrects a problem with the counters maintained for the NetRAIN virtual
    interface.

 +o  Fixes a problem in which the psrinfo -v command may print an incorrect CPU
    cache size in a mixed CPU size/speed environment.

 +o  Prevents a panic in assert_wait_mesg caused by the posting of an event_wait
    without clearing a previous request.

 +o  Fixes a problem where tape and changer devices on FibreChannel could
    occasionally return an incorrect offline status.

 +o  Enables improvements in the kernel crash dump subsystem that make it
    possible to generate a dump after disk driver shutdown has taken place.

 +o  Fixes a potential kernel memory fault panic in the Virtual Memory subsystem
    on SMP systems.

 +o  Adds hardware support for the AlphaServer DS25.

 +o  Fixes a minor problem in the AlphaServer ES45 environmental error handling
    code.



 1-128 Tru64 UNIX Patches








 +o  Corrects problems where NFS can deadlock.

 +o  Corrects an AdvFS problem in which EIOs are returned by AdvFS to NFS.

 +o  Corrects a kernel memory fault panic in malloc_thread().

 +o  Fixes the predictable TCP Sequence Number.

 +o  Corrects a data inconsistency that can occur when a CFS client reads a file
    that was recently written to.



 +o  Provides support for a related cluster patch to support multiple filesets
    being mounted from the cluster_root domain.

 +o  Fixes a potential deadlock situation when using freezefs on multiple
    domains while also running addvol (or rmvol).

 +o  Fixes numerous problems of accessing de-allocated and freed vnodes.

 +o  Fixes the following problems in Link Aggregation (LAG):


    -  An inability to modify the ipmtu of a LAG interface

    -  An inability to work with gigabit Ethernet jumbo frames

    -  Attempts to use a link that is down

    -  Poor performance in server-to-server configurations


 +o  Fixes a situation which a failed open to a device causes an error that the
    device cannot be deleted using the hwmgr command.

 +o  Fixes an incorrect return type in a logging routine that prevented proper
    operation of the memory troller on an AlphaServer DS20L.

 +o  Corrects a problem when offlining a processor in which a seldom-taken code
    path may attempt to take a complex (sleep or blocking) lock while in
    interrupt context, thereby causing the kernel to panic.

 +o  Fixes a potential problem with vdf and showfdmn, where they could
    incorrectly display the message "showfdmn: No such file or directory."

 +o  Prevents a cluster file system server panic that can occur if a cluster
    client clears the server cache entries for a file being operated on by
    defragment, balance, migrate, rmvol, or mssh.

 +o  Fixes several problems found in the KZPEA driver that could result in hung
    I/O, pending I/O not being cleared on a reset, panics seen when aborting
    I/O, and hard errors returned to applications on opens during reset
    conditions.



                                            Tru64 UNIX Patches 1-129








 +o  Changes the evm_versw_undo script to fix no-roll installation and deletion
    of the EVM version-switched patch.

 +o  Fixes a problem with the logging of MUNSA reject status messages to the
    console during boot which could cause a system to boot extremely slowly.

 +o  Fixes a kernel memory fault from sth_close_fifo() caused by a NULL pointer.

 +o  Corrects a problem to allow cluster unlinked files to be handled properly
    during a relocation.

 +o  Fixes a deadlock problem when deleting devices while the system disk is in
    error recovery.

 +o  Fixes POSIX semantics for accessing a "." entry.

 +o  Closes a race condition between VFS and UFS layer code that causes panic
    while periodic sync mechanism flushes dirty buffers out to disks.

 +o  Fixes performance shortcomings in NXM thread replacement.

 +o  Reduces the number of inputs/outputs to the disk, which reduces the number
    of audible disk ticks.

 +o  Corrects a problem where, when NFS mounts using the -o proplist option,
    disk space is not being freed when files are deleted.

 +o  Fixes a kernel memory fault in u_seg_global_destroy.

 +o  Fixes a crash when an AdvFS file system reports I/O errors and enters into
    a domain panic state.  AdvFS error cleanup would panic on an invalid
    pointer and report an "invalid memory read access from kernel mode" panic
    message.



 +o  Fixes an ISO9660 file system size limitation of 2.1 GB and provides full
    capacity access to DVD-ROM media.

 +o  Fixes a problem that can prevent certain tape applications from recovering
    paths to devices that have failed.

 +o  Prevents a panic from occurring while trying to mount an AdvFS domain.  The
    panic would only appear when the mount command was about to fail.

 +o  Corrects a problem with reservation conflicts in the TUR recovery loops.

 +o  Fixes two NFS kernel memory fault panics due to bad NFS server data.

 +o  Corrects "u_anon_free: page busy" panics.

 +o  Corrects a problem where an I/O can fail back to the application when a
    HSV110 V2 path failover is performed.




 1-130 Tru64 UNIX Patches








 +o  Corrects a situation where a tape open with no tape present in the drive
    can take as long as six minutes to fail.

 +o  Fixes a VFS namecache race condition where both positive and negative
    namecache entries can exist.

 +o  Corrects a problem where low UBC memory conditions cause a hang in AdvFS.

 +o  Corrects a problem in cluster backups of global root directories or backup
    of different system disks in a cluster.

 +o  Fixes an AdvFS alignment fault panic caused by inconsistent AdvFS metadata
    in a directory.  In particular, the directory's entry size is an unaligned
    value.

 +o  Creates a condition where, if an I/O fails and it can be helped by an
    AdvFS-initiated retry, a message is written to the console providing
    information on how to retry.

 +o  Fixes an internal value related to the maximum I/O size for a device was
    being calculated incorrectly.

 +o  Provides support for the DEGXA Gigabit Ethernet device, including the
    AlphaServer ES25 onboard 10/100/1000 Ethernet port.

 +o  Adds the Reserve/Release/Path_Lock feature to tape and changer drivers.

 +o  Corrects a problem of writing erroneous data to the binary error log file
    and provides missing header definitions for error interpretation.

 +o  Provides a variety of domain panic fixes that better capture, explain, and
    handle domain panics.

 +o  Fixes a cluster-as-NFS-server chown() problem.

 +o  Fixes a problem in which the system panics while running applications
    performing an open of a RAID device and the faulting routine was
    control_port_open.

 +o  Fixes a problem where cluster file system I/O and AdvFS domain access
    causes processes to hang.

 +o  Fixes a situation in which a system running CD record software experiences
    I/O timeout errors when writing CDs.

 +o  Helps avoid a silent infinite loop in vdump by correcting the AdvFS system
    call OP_GET_BKUP_XTNT_MAP.  The call will now return the valid xtntCnt when
    it fails due to E_NOT_ENOUGH_XTNTS.

 +o  Fixes a problem where, in certain cases, large files (greater than 30 GB)
    suffered extreme fragmentation.

 +o  Fixes a kernel panic with "bfs_alloc: kernel memory fault."




                                            Tru64 UNIX Patches 1-131








 +o  Corrects a problem that results in broadcast or multicast packets being
    processed multiple times on behalf of a NetRAIN device, once for each
    backup interface.

 +o  Fixes a problem that causes the 4.3BSD socket interface to return incorrect
    values for IOCTL calls accessing IP alias address information.



 +o  Provides support for a cluster patch that corrects a performance issue seen
    when multiple threads/processes simultaneously access the same file on an
    SMP system with more than one CPU.

 +o  Corrects a problem where, when entering the hwmgr -view devices command on
    a member in a cluster, the device name would not be updated and would be
    listed as unknown.

 +o  Corrects a situation where only the a and c device special files are
    created when adding a CD-ROM or floppy after boot.  Users no longer have to
    enter dsfmgr -K or reboot in order to make all the device special files.

 +o  Fixes heap and stack limitations in the older operating system versions
    required for SAP.

 +o  Prevents several possible system panics and an AdvFS deadlock.

 +o  Fixes a problem that allowed an application with superuser privileges to
    cause a system panic when attempting to delete a non-existent connection;
    for example.  when the trcpkill program runs while stopping ASU.

 +o  Fixes an AdvFS AIO read timing issue when reading a fragged file via
    directIO.

 +o  Prevents a panic when more metadata file space is needed and the disk write
    to allocate it fails.

 +o  Removes a restriction where dynamic VMEbus device drivers could only probe
    one controller per driver.  Multiple controllers per driver now configure
    successfully.

 +o  Fixes kernel memory faults caused by ufs_sync_int accessing an inactivated
    or de-allocated vnode.  This change also corrects a problem with negative
    block number detection in ufs_strategy.

 +o  Provides support for the pseudo device /dev/poll to the kernel, which
    allows for efficient polling of a large number of file descriptors.

 +o  Corrects a problem that caused the RFC 2001 Fast Retransmit Algorithm
    within the kernel to work incorrectly.

 +o  Makes several changes to the ee driver for DE60x Ethernet cards, including
    the following (these problems affect all Tru64 UNIX systems containing
    DE60x network interfaces):




 1-132 Tru64 UNIX Patches








    -  Fixes a race condition that can cause a panic when a transmit timeout
       occurs.

    -  Improves error checking when allocating buffers.

    -  Fixes DMA resource allocation to prevent a panic when a machine runs low
       on DMA resources.

    -  Adds a new ee subsystem attribute link_check_interval that allows the
       link state polling interval to be tuned for faster failover times when
       using DE60x interfaces for Link Aggregation.


 +o  Fixes a DMAPI problem where showfile can show that DMAPI regions exist when
    they do not.

 +o  Provides support for a cluster-specific patch that fixes a race between
    cluster mounts and file system lookups, and fixes a situation in which file
    system failover deadlocks.

 +o  Fixes an NFS readahead performance problem where performance is degraded
    when reading past 2 GB in a file.

 +o  Fixes a problem in which advscan incorrectly processes concatenated options
    (for example, ar rather than -a -r).  For instance, if -ar is specified,
    the -r option will not be processed.

 +o  Prevents a lock hierarchy violation from occurring when AdvFS tries to
    extent a file on a system that is out of memory.

 +o  Addresses the problem of applications hanging with outstanding I/O during
    high volume I/O in a cluster environment.

 +o  Prevents some AdvFS domain panics due to inadequate error handling between
    the HSG80 and the Tru64 UNIX disk driver.



 +o  Re-enables mountd to support exports file with multiline entry using
    leading spaces as a continued line indicator.  The problem was introduced
    with a patch that increases support of NFS file mounting from 254 to 1024
    entries.

 +o  Corrects a problem with arp messages not being sent on interface static
    routes.

 +o  Provides the PCI indictment for storage component location to diagnose a
    PCI adapter failure.

 +o  Resolves a deadlock problem as well as a potential problem with incorrect
    or inconsistent cluster devts that could occur in a cluster when removing
    or replacing a device.

 +o  Corrects a problem in which moving the power supply from one slot to



                                            Tru64 UNIX Patches 1-133








    another can cause a panic.

 +o  Corrects a possible panic when auditing execve with exec_argp/exec_envp
    enabled.

 +o  Allows the device special file instance numbers to be reduced to the their
    lowest possible value and avoid runaway device names.

 +o  Corrects a problem where, under certain conditions, invalidating a portion
    of a very large file can make the file system appear to be hung.  Any
    program trying to access the file system (for example, issuing the ls
    command) hangs until the file is invalidated.  This will only happen when
    rt_preempt_opt=1.

 +o  Allows multiple applications utilizing RAID services to send maintenance
    commands without interfering with each other.

 +o  Prevents different threads on multiple RADs from creating multiple
    references to the same level 3 page table.

 +o  Corrects a problem involving New_wire_method (light weight wiring),
    sometimes referred to as the Oracle connect problem or Oracle performance
    problem.

 +o  Prevents the ARMTech kernel malloc invalid size panic.

 +o  Prevents crash dumps on certain systems that use granularity hinted
    regions.

 +o  Increases the number of file systems that can be mounted from 256 to 1024.

 +o  Fixes audit to generate exportfs_create audit records correctly.

 +o  Prevents a situation in which the disk drives on a DS25 overheat if the
    system door is removed for too long.

 +o  Prevents a Kernel Memory Fault panic in irefresh while walking the mounted
    vnode list.

 +o  Fixes a problem resulting in a system panic for applications that directly
    call nxm_get_bindings.

 +o  Allows users other than root to mount CD-ROM media on directories that they
    own.

 +o  Prevents the loss of data in files opened for direct I/O when writing in
    increments smaller than 8 K.

 +o  Fixes a problem in network Link Aggregation (LAG) where the MAC address of
    a LAG interface would change if the link from which it had derived its MAC
    address went down.

 +o  Fixes a kernel panic with get_xm_page_range_info:kernel memory fault.




 1-134 Tru64 UNIX Patches








 +o  Corrects several issues with page faults and stack object growth.

 +o  Corrects a problem where df was showing negative values for large NFS file
    systems.

 +o  Corrects a problem in which multi-threaded processes may hang in timed
    condition waits (pthread_cond_timedwait()) when running realtime system
    contention scope threads.

 +o  Enables a larger maximum (1,073,741,824) for the inode_hash_size attribute
    in the UFS subsystem.

 +o  Fixes a problem that was causing the tcp_rad_fasttimo timer to consume
    excessive amounts of CPU time.



 +o  Corrects a problem in which a domain ID was not always updated when
    mounting an AdvFS file system with the -o dual option in a cluster.  If the
    mount -o dual happened on a node other than the node that was serving the
    original domain, AdvFS did not detect that the domain ID was already active
    and failed to update the ID for the new domain.  The fix is to always
    create a new domain ID when the -o dual option is used.

 +o  Corrects a problem introduced in a prior patch that can result in a system
    panic when outputting through the packet filter.

 +o  Corrects a problem in which cluster members panics occurred when previously
    failed paths to a device (for example, hsz80) are restored.

 +o  Fixes a bug that prevented AdvFS from working correctly with LSM volumes
    between 1Tb and 2Tb.

 +o  Causes mkfdmn and addvol to issue a warning if an attempt is made to use an
    LSM volume greater than 2Tb in size.

 +o  Fixes a problem in which AdvFS domains from systems running pre-5.0
    versions of Tru64 UNIX and mounted on systems running Patch Kit 3 for
    Version 5.0A would give "corrupted directory entry size" error messages
    when some files were accessed.

 +o  Corrects a problem in which systems configured with VX1 graphics card will
    not return to the console when the halt button is pressed, thereby making
    the console unusable.

 +o  Fixes the problem on an I/O slow start after a host or HSV reboot.

 +o  Fixes an HSV110 snapshot failure problem due to reservation conflict error
    when multiple paths are present.

 +o  Fixes a problem that occurs with an AdvFS file system when ACLs are enabled
    and there is a Default Access ACL on a directory.  The permissions of
    symbolic links created in that directory appear to be incorrect, even
    though access is unaffected.



                                            Tru64 UNIX Patches 1-135








 +o  Fixes a race during AdvFS volume removal that can cause a panic in the
    bs_osf_complete() routine.

 +o  Fixes a problem seen with TAHI IPv6 conformance Test #4 for the IPv6
    Specification.

 +o  Removes preemption latencies for ICS threads.

 +o  Fixes a problem with audit data not being displayed by the audit tool.

 +o  Fixes problems with file object selection/deselection and directories.

 +o  Fixes NUMA performance issues associated with auditing.

 +o  Keeps USB from initializing on systems where USB is not supported.

 +o  Fixes mmap denying a request at address 0 with MAP_FIXED.

 +o  Fixes (n)madvise with MADV_DONTNEED's handling of shared memory, which
    currently leads to mismapped memory.

 +o  Provides the PCI indictment for storage component location to diagnose a
    PCI adapter failure.

 +o  Improves msync performance on files that are mapped with the MAP_PRIVATE
    flag.

 +o  Improves the process exit procedure for processes that have had the nice
    command used on them.

 +o  Fixes the problem of mount/umount failures and panics in MFS, UFS, and
    FDFS.

 +o  Eliminates a condition that causes a hang that occurs while unmounting an
    AdvFS fileset.

 +o  Corrects a problem of TS202c system installation failures.

 +o  Corrects a kernel memory fault that can happen when running applications
    that use the Cray Intra-Node Shared Memory library.

 +o  Prevents the loss of single system image for an NFS file system mounted
    from a cluster when there are certain problems communicating with the
    external NFS server.



 +o  Fixes a panic that can occur when appending to a file when using UFS.

 +o  Resolves a kernel memory faults in the TCP/IP subsystem.

 +o  Fixes kernel memory fault in shadowvnode() caused by NULL vnode pointer.

 +o  Fixes insmntque() to conform to proper locking when removing and adding



 1-136 Tru64 UNIX Patches








    vnode to the mount vlist.

 +o  Fixes a problem when the kernel incorrectly closes a socket that causes
    Sybase 1613 errors to be produced.

 +o  Enables SmartArray 5300 controller hardware events to be logged to the
    binary.errlog file during boot.  This is useful in diagnosing logical
    volume state change and physical drive hotswaps that can occur while the
    system is not booted.

 +o  Fixes a problem in which fuser is unable to report on all referenced
    resources.  This is a problem when attempting to identify reasons for
    unmount failures.

 +o  Fixes a problem with hung NFS threads due to orphaned mbufs.

 +o  Corrects a problem with the handling of lock acquisition and release
    ordering when erasing device mapping contained within SCSI_DIDs.

 +o  Fixes a problem with printing long double values.

 +o  Fixes a potential memory discrepancy (and subsequent kernel memory fault)
    by preventing an "mcs_unlock: lock not found" panic when using process-
    shared with mcs locks.

 +o  Fixes several problems in the CAM and I/O space.

 +o  Adds code to print greater than 61 UNIX domain sockets and change file read
    errors from /dev/kmem to ignore and continue in a running system.

 +o  Alleviates a temporary hang/pause condition seen when forking or running
    down an application with several child processes, from a parent process
    having an extremely large number of unique or discontiguous memory
    allocations.

 +o  Corrects a problem in which multithreaded applications may see corruption
    of the quadword immediately following a buffer that is written by
    strncpy(), where an update to the quadword by a second thread is lost.

 +o  Resolves kernel memory faults in the TCP/IP subsystem.

 +o  Fixes a correctable error reporting problem that turns off the reporting of
    correctable errors forever on any CPU, except CPU 0, once throttling of
    correctable errors has begun.

 +o  Corrects a problem found wherein the rmtmpfiles script would produce errors
    at startup of the form:

    dirclean: lstat failure for starting directory: /.osonly_tmp/: No such file
    or directory


 +o  Fixes a problem with the Smart Array driver that could cause a system hang
    to occur during error recovery when I/O is active.



                                            Tru64 UNIX Patches 1-137








 +o  Modifies AdvFS usage of thread_block to ensure that calls to thread_block
    will not hang the system.

 +o  Fixes several IPMI-related problems, including the following:


    -  Broadcast "Get Device ID" IPMI command.

    -  OS power down support (shutdown -p).

    -  Erroneous fields in 686 OS-detected environmental machine check logout
       frame.

    -  Unusually large number of 686 sensor timeouts with heavy system load.

    -  IPMI always reports -48v sensors as broken, seen as "redundant power
       supply failed" messages.

    -  IPMI memory leak.




 +o  Fixes an AdvFS asynchronous direct I/O problem that could cause a thread to
    hang.

 +o  Fixes a rmvol E_PAGE_NOT_MAPPED error.

 +o  Eliminates an ENO_MORE_BLKS error seen when performing a copy-on-write
    operation to a clone file while an rmvol is in progress.

 +o  Corrects a problem in AdvFS where it avoids a potential stranded log record
    in memory that does not get out to disk by fixing a race condition.

 +o  Prevents a device (for example a disk) from getting two sets of device
    special files.  This problem can occur in a cluster if hundreds of new
    devices are being found on multiple systems while these systems are booting
    at the same time.

 +o  Corrects a problem with a hwmgr delete while a SCSI scan is in progress.

 +o  Corrects a problem in which compression is not turned off when a device is
    accessed through the noncompression device special file (/dev/tape/tapex)
    after having accessed the same device through the compression device
    special file (/dev/tape/tapexc).

 +o  Fixes segmentation errors that can occur when running SAS.

 +o  Fixes a panic caused by a problem within the swapping subsystem.

 +o  Allows the auditing of login and su events based in part on what is in user
    profiles (for Enhanced Security), the prevailing auditing characteristics
    of the originating process, and the system-wide audit mask.  Previously,
    only the system audit mask was referenced.



 1-138 Tru64 UNIX Patches








 +o  Fixes a problem in which camreport may report negative device IDs.

 +o  Fixes a multithread timing window in malloc and free where the list of free
    chunks could become corrupted, resulting in a segfault.

 +o  Prevents the hardware management cluster database from being reset.

 +o  Fixes a problem encountered where a truncated AdvFS file erroneously zeroed
    data for the remaining leading segment of the file.

 +o  Corrects a kernel memory fault panic that occurs when running an
    application that uses the Cray Intra-Node Shared Memory library (Sierra
    systems only).

 +o  Corrects a problem that could result in the panic of a cluster member or
    inconsistent data when the sbcompress_threshold configurable is set.

 +o  Corrects a problem where, under indeterminate circumstances, when drivers
    are unloaded or unconfigured, the system may crash if certain kmem_debug
    flags are set (particularly 0x40 or 0x01).  The crash stack backtrace will
    show remove_dynamic_struct as the problem routine.

 +o  Fixes a problem with SIA that caused the Internet Express LDAP
    Authentication module to be unable to look up default group information for
    a user at login time.

 +o  Prevents a panic in fifo_write with the panic message "NULL fifo_bufhdr
    append pointer."

 +o  Corrects the erroneous reporting of success, when attempting to write
    beyond the file size limit using synchronized I/O.

 +o  Corrects the calculation of _PC_FILESIZEBITS, which is used by the
    operating system for pathconf file characteristics.

 +o  Fixes a system panic in AdvFS when an I/O error occurs in the property list
    component.  The panic string seen is "msfs_pl_cur_to_pnt(1) - failed to ref
    page."

 +o  Fixes a problem in the CAM subsystem where it would print out "bad block
    number" to the error log on a recovered read error.  The string has been
    changed to "block number."

 +o  Fixes problems with NUMA disk statistics.



 +o  Fixes various small problems in dsfmgr.

 +o  Prevents a potential process (not system) hang seen when a system comes
    under heavy memory load with monolithic memory use (gigabyte-scale single
    objects).

 +o  Removes latencies for ICS threads.



                                            Tru64 UNIX Patches 1-139








 +o  Introduces type checking of attributes when registering components with the
    hardware manager.

 +o  Corrects a problem where, under high DMA resource utilization,
    dma_map_load() may generate an invalid bus address in a scatter/gather
    entry if the device is using 64-bit addressing, which could result in a
    system crash or data loss.

 +o  Changes CHIM to fix Ignore Wide Residue fix and Kernel Memory Fault panic.

 +o  Fixes a potential problem with modifying files via directIO when there is a
    clone fileset.

 +o  Fixes three problems and adds support for one new feature in the alt driver
    for DEGPA Gigabit Ethernet adapters.  These problems affect all Tru64 UNIX
    systems containing DEGPA network interfaces.

 +o  Fixes a situation where mounting a valid CD-ROM the first time fails with
    the message "no valid file system exists on this partition."

 +o  Adds an event which indicates that the soft or hard error count has changed
    on the device identified in the event.

 +o  Prevents a cluster AdvFS panic after a disk array controller restart.

 +o  Fixes a problem where a user wire request (mlock) fails on NUMA machines.

 +o  Prevents a "u_anon_free: page busy" system panic.

 +o  Prevents the system panic "PWS_CCB_QUE_REMOVE: ccb not on any list" caused
    by a device or bus reset occurring during the execution of a command to a
    media changer device, such as a tape library.

 +o  Corrects a failure in the safe_open() routine which caused symbolic links
    given by a relative path from the current working directory sometimes to
    give ENOENT errors incorrectly.

 +o  Fixes a rare case of a thread blocking when waiting for memory.

 +o  Corrects performance issues when accessing a file with direct I/O enabled.

 +o  Allows the Event Manager daemon, evmd, to stop listening on its default TCP
    port 619.  This capability is not available for clustered systems.

 +o  Corrects invalid hwmgr show component inconsistency.

 +o  Fixes a KMF problem that can happen if some nodes in cluster are rebooted
    and a device is shared by all the nodes.

 +o  Fixes the counting of files in AdvFS, which was reporting no available
    inodes when there were plenty.

 +o  Resolves a problem of not being able to view files on some CD-ROM media
    that is created by third party software.



 1-140 Tru64 UNIX Patches








 +o  Replaces the system panics caused by "Can't clear bit twice" with a domain
    panic.

 +o  Fixes a problem when using the getrusage function where the memory usage
    could be incorrectly reported.

 +o  Fixes a problem of an occasional deadlock during process exit for
    multithreaded processes.



 +o  Fixes a memory leak in the NFS server encountered when it receives
    malformed packets.

 +o  Fixes a problem in which, when using the hardware manager to show
    attributes, the LONG_MAX and LONG_MIN values are displayed incorrectly.

 +o  Fixes a problem in the kernel network subsystem that caused a kernel memory
    fault panic in the routine m_adj().

 +o  Prevents the memory troller from starting on platforms with aluminum EV68
    CPUs.

 +o  Fixes potential quota errors during recovery.

 +o  Provides a configurable setting that will cause an error return for any
    read of tape from a tape that requests less the full amount of data in the
    tape block.

 +o  Fixes the problem of a kernel memory fault panic in the IP multicast
    loopback code.

 +o  Eliminates false directory lookup warning messages generated by an
    incorrect comparison caused by mismatched file ID variable types and
    slightly improves client caching performance.

 +o  Fixes a problem in which rebooting immediately after entering a hwmgr
    -redirect scsi command results in a boot to single user mode with the
    following error being displayed:

    bcheckrc: Device Naming failed boot configure or verify Please correct the
    problem and continue or reboot INIT: SINGLE-USER MODE

 +o  Corrects the behavior of the NFS client negative lookup result cache.

 +o  Corrects problems of audit_tool supplying incorrect or insufficient data
    about an audit event.

 +o  Prevents panics caused by bad arguments to system calls.

 +o  Fixes two potential problems in the NFS V3 client where unstable writes
    could potentially remain uncommitted when they should have been committed
    to stable storage.




                                            Tru64 UNIX Patches 1-141








 +o  Fixes a problem in the VM subsystem that could cause a crash with the panic
    string "vm_page_ssm_unwire."

 +o  Allows for the proper initialization of the member cache in the set
    descriptor.

 +o  Helps avoid a potential lock timeout in AdvFS that could cause a panic with
    the panic string "mcs_lock: time limit exceeded."

 +o  Corrects mount(), df(), and memory mapping problems that may prevent users
    from accessing data on some DVD media, or information about the mounted
    media.

 +o  Provides more helpful AdvFS informational messages:


    -  Advscan now reports if a domain has all of its volumes, but they are
       stored in a different directories.  This scenario will cause mount to
       fail.

    -  The AdvFS I/O error message now includes the location of a file that
       will help you translate the error number into an error message.

    -  Prevents false invalid Inquiry data error reports during boot.

    -  Fixes mmap accepting negative lengths, which may lead to a "malloc:
       invalid size" panic.

    -  Fixes a problem in which a taso-compiled binary is unable to allocate
       more memory after performing a series of mmap calls.

    -  Corrects the problem where /sbin/ddr_config does not accept values for
       ReadyTimeSeconds larger than 255.  The new limit is 86400 seconds (24
       hours).

    -  Fixes excessive FIDS_LOCK contention observed when large numbers of
       files are using system based file locking.

    -  Fixes the reporting of device monitoring events and hardware errors
       during disk recovery from the disk driver to the binary errlog.




 +o  Forces a domain panic instead of a system panic if AdvFS metadata is
    discovered to be incorrect in frag_group_dealloc.

 +o  Fixes a problem in which offlining a CPU with one or more bound processes
    can lead to a "malloc_check_checksum: memory pool corruption" panic.

 +o  Fixes a problem in which mmap memory locked with mlockall() using the
    MCL_FUTURE flag does not actually become wired automatically.

 +o  Prevents addvol from adding invalid disks into a domain.



 1-142 Tru64 UNIX Patches








 +o  Fixes an extended regular expression problem where the interval expression
    "{m,n}" is handled incorrectly.

 +o  Fixes a problem in the cluster where the non-default alias mounting feature
    was disabled.

 +o  Fixes a kernel memory fault panic in AdvFS that could cause a panic from
    the imm_page_to_xtnt() routine.

 +o  Fixes a problem in which an NFS server exports files on a third-party file
    system can result in a system crash.

 +o  Fixes a problem that occurs when a mounting cluster root if the cluster
    root domain devices are private to different cluster members, causing the
    cluster to hang when attempting to boot.  With this fix, the cluster will
    boot with a warning to the console.  Although this configuration is not
    recommended, the cluster should be bootable.  The problem occurs with non-
    LSM cluster root domains.

 +o  Corrects a memory leak in the VM subsystem.

 +o  Corrects a potential deadlock in hardware configuration subsystem.

 +o  Fixed the audit_tool search algorithm to differentiate between prived and
    non-prived UIDs, and to allow regular expressions in string searches.

 +o  Fixes a problem when monitoring I/O via advfsstat.

 +o  Installs DECthreads V3.18-150, which is the latest support version of the
    HP POSIX Threads library for Tru64 UNIX V5.1A.  Previous releases of this
    patch installed the following versions:


    -  DECthreads V3.18-148

    -  DECthreads V3.18-144

    -  DECthreads V3.18-141, which specifically addressed problems with the
       pre-emption of the symbolic name table() by application code, and the
       alignment of the Stack Pointer in user-created threads.

    -  DECthreads V3.18-138, which specifically addressed a problem that could
       arise when using recursive mutexes with condition variables.

    -  DECthreads V3.18-133


 +o  Adds SCSI reserve/release support to mt to assist open SAN tape management.

 +o  Corrects problems in the aha_chim driver that could result in bus hangs,
    panics, and inappropriate access of freed memory during a high rate of bus
    resets.

 +o  Adds enablers for Smart Array controller.



                                            Tru64 UNIX Patches 1-143








 +o  Fixes a problem of a controller reset being issued on an idle system due to
    a thread wake-up signal being missed.  This problem may occur when using
    the Smart Array 5300 series controllers.

 +o  Fixes a potential floating point error in threaded applications.

 +o  Provides support for DEGXA Gigabit Ethernet, including ES25 onboard
    10/100/1000 port and upgrades the driver for systems with existing support.

 +o  Fixes a race condition introduced by a previous patch.



 +o  Adds support for binlog text messages when an environmental system event
    occurs with an AlphaServer DS20L system.  In addition, because of the
    DS20L's thermal sensitivity, the environmental thermal thresholds have been
    lowered.

 +o  Updates ddr.mod to support New Hardware Devices Version 6 (NHD-6) devices.

 +o  Fixes a flaw in the NFS server that could cause it to crash upon reception
    of malformed input.

 +o  Addresses problems with the NFS server in which a crash can occur with a
    concurrent read and truncate on an AdvFS file or with malformed or
    malicious READDIR[PLUS] version 3 RPCs.

 +o  Address a condition in which AdvFS domain panics would occur during HSZ and
    HSG failovers.

 +o  Corrects a problem in which some networking applications, especially X.25
    and X.29, stopped working after the installation of Patch Kit 3 because of
    interactions with security-related fixes and their relationship with fstat.

 +o  Prevents CS Cluster issues with the DCE/DFS file system when pages are
    being flushed as part of a vnode.

 +o  Fixes various problems with the bcm driver for DEGXA Gigabit Ethernet that
    can cause crashes.

 +o  Fixes a problem in which /usr/bin/ksh hangs for certain scripts that
    contain the wait command.

 +o  Makes shell inline input files more secure.

 +o  Adds sh noclobber and new constructs.

 +o  Updates the mkdir system call.

 +o  Corrects a problem in which ksh fails to substitute the tilde (~) character
    for a user's home directory after making an assignment using the # or %
    characters.

 +o  Fixes a problem with ksh that occurs when a ksh menu is started from within



 1-144 Tru64 UNIX Patches








    user's .profile file and ksh does not stop when the Telnet session is
    stopped.

 +o  Fixes an Asian language processing problem under the Korn shell.

 +o  Corrects a problem in which sh was using a high amount of CPU time.

 +o  Corrects a problem in which sh will not receive a SIGSEGV signal when the
    user runs the type utility with a file path greater than 69 characters.

 +o  Fixes a problem where the vi editor core dumps when it finds invalid syntax
    during a substitute operation.

 +o  Fixes a problem in which shutting down the network would also shut down the
    cluster interconnect interface in a LAN cluster.

 +o  Corrects several potential security vulnerabilities which, under certain
    circumstances, could compromise system integrity.  These may be in the form
    of improper file or privilege management.

 +o  Prevents vold from core dumping when attempting to delete a disk that was
    not initialized properly.

 +o  Fixes a deadlocking problem in the kernel where a file open on a clone
    could hang when ACLs are enabled.

 +o  Fixes a problem where gh_min_seg_size could not be set below 8 M.

 +o  Corrects a KMF caused by uninitialized or incorrect parameters passed to
    the setsockopt system calls.



 +o  Fixes a problem where Smart Array 5300 Logical Volumes were counted as RAID
    controllers.

 +o  Installs Version 1.12 of the ciss driver.

    Previous releases of the Version 5.1A patch kit installed versions 1,02,
    1.07, 1.08, 1.09, and 1.11 of the ciss driver.

 +o  Fixes a problem that can cause a GS80 to hang after a SA5300 reset.

 +o  Fixes a potential system crash when shutting down after using a DAPBA or
    DAPCA ATM adapter.

 +o  Corrects a potential problem on a system generating a heavy volume of audit
    events in which the auditd -d command that flushes the kernel audit buffers
    could cause audit data corruption on a multi-CPU machine.

 +o  Fixes a problem that can cause a hang to occur during the renaming of an
    AdvFS file.

 +o  Prevents a kernel memory fault panic in _OtsMove when going through the



                                            Tru64 UNIX Patches 1-145








    fs_read() routine.

 +o  Fixes a casting error in AdvFS that produces a warning message.

 +o  Fixes potential crashes from within the pshared subsystem.

 +o  Fixes the changer driver to report the manufacturer ID.

 +o  Fixes nissetup to leave /etc/group with an incorrect mode of 600 after
    removing NIS.

 +o  Corrects a newfs and extendfs problem in which a statically sized cylinder
    summary area of a UFS file system limited the overall size of the file
    system.  In some situations in which a large (greater than 800 GB) file
    system is created, newfs would not exit with an error even if the cylinder
    summary area could not be written to the disk.

 +o  Corrects a problem with mfs in which requests to create a memory file
    system with a large size can result in a core dump and silent error.

 +o  Adds system configuration tunables for AlphaServer ES45 environmental
    monitoring.

 +o  Fixes a problem in file property lists where the maximum length of a
    property list name was limited to 245 characters.  The new limit is 255.

 +o  Reschedules certain default cleanup cron jobs so that they are not skipped
    during a time change to DST.

 +o  Prevents a possible panic in bs_derefpg.

 +o  Change an rws write lock in the VMAC lookup routine to an rws read lock for
    better SMP scaling.

 +o  Fixes a regression from pre-Version 5.0 releases in the libc mktime()
    function's handling of potentially ambiguous tm struct times; that is,
    those that fall within a backward clock shift and have an initially
    negative tm_isdst value).

 +o  Fixes a cluster panic with the following error message:

    panic (cpu 3): ics_unable_to_make_progress: heartbeat checking blocked


 +o  Fixes a system panic that produces one of the following panic strings:

    mcs_lock: lock already owned by cpu thread_block: simple lock owned


 +o  Fixes a problem encountered with the Bourne shell when a file name with
    trailing slash (/) is used as an argument to the command.

 +o  Corrects problems in tape open and tape ioctl when the FNDELAY flag is set,
    which could result in tape devices not responding or in a kernel memory



 1-146 Tru64 UNIX Patches








    fault.

 +o  Fixes a condition that results in system hangs or panics resulting from bad
    locking in the AdvFS msfs_getpage routine.

 +o  Fixes a problem where the home directory and login shell attributes for a
    user account were not suppled to the audit daemon for authentication
    failures.



 +o  Adds recognition for possible future devices.

 +o  Eliminates compiler warnings in ksh.

 +o  Increases the TCP window from 96 KB to 500 KB to improve performance.

 +o  Changes the netisr thread to dynamically estimate the reply size and
    reserve the space in the socket buffer.

 +o  Adds a new timeout check to notice when the data has not been acknowledged
    in 30-50 seconds and copy those buffers.  This allows the UBC to free up
    those mbufs.

 +o  Corrects a problem when running Enhanced Security in which an emergency log
    in for the root account on the console would fail in TruCluster
    configurations with the following string:

    Impossible to execute /sbin/sh


 +o  Provides a workaround for a domain panic when corruption in the deferred-
    delete list of an AdvFS file system is detected.

 +o  Changes the /usr/sbin/dirclean utility so it no longer attempts to remove
    the AdvFS .tags directory or the quota.group and quota.user files.

 +o  Prevents kmfs when AdvFS encounters proplist metadata inconsistencies.

 +o  Fixes a system panic in the ubc_page_stealer routine.

 +o  Corrects a kernel memory fault in the table syscall.

 +o  Improves kernel module functions

 +o  Fixes various problems in the libc functions getdate(), strptime(),
    callrpc(), strncasecmp(), fork(), and popen(), and the libnuma function
    nacreate().

 +o  Fixes a cross-node cluster deadlock that can occur when AdvFS threads on
    two cluster nodes simultaneously call code that requires the taking of
    already held AdvFS locks on the other node.

 +o  Fixes a problem in which volmigrate returns a shell error when attempting



                                            Tru64 UNIX Patches 1-147








    to migrate an AdvFS domain with multiple filesets.  These domains can now
    be migrated as long as all the filesets are mounted.

 +o  Fixes sh to print the correct msg when enhanced core file naming is on.

 +o  Enhances cron to do extensive logging.

 +o  Addresses an issue in which I/O may not be completed under certain
    circumstances.

 +o  Fixes client (login, su, rshd, edauth, and sshd2) hangs and long delays
    under Enhanced Security, as well as some intermittent errors or failures
    seen with prpasswdd or rpc.yppasswdd.

 +o  Enables mountd to correctly handle entries with multiple lines input in
    exports file.



 +o  Fixes a problem in the alt driver that prevents DEGPA from being used with
    DE50x or DE60x adapters in a LAG set.

 +o  Makes start up scripts in /sbin/init.d world readable.

 +o  Provides protection against a class of potential security vulnerabilities
    by allowing a system administrator to enable memory management protections
    that limit potential buffer overflow vulnerabilities.  Buffer overflows are
    sometimes exploited in an attempt to subvert the function of a privileged
    program and possibly execute commands at elevated privileges if the program
    file has the setuid privilege.

 +o  Improves AdvFS scalability.  These improvements help reduce lock contention
    and improve performance.

 +o  Corrects lockmode 4 problem in cdisk_event_notify.

 +o  Prevents a hang in LSM/CLSM commands in sosleep().

 +o  Fixes a problem where the system can panic with a "kernel memory fault" in
    simple_lock(), being called from fuser().

 +o  Fixes a possible (though rare) hang in the hardware configuration
    subsystem.

 +o  Prevents a situation where an AdvFS Migrate syscall launched from the CFS
    client could result in a hung client thread and a hung server thread.

 +o  Fixes a panic resulting from race condition in the memory file system (MFS)
    over the cluster file system (CFS).

 +o  Fixes a problem in which rmvol causes file and directory information to
    become lost, which can cause domain panics or strange behavior on file
    statistics.




 1-148 Tru64 UNIX Patches








 +o  Fixes a case where rmvol causes files to lose their ACLs, which opens up a
    security hole on those files.

 +o  Fixes a case where rmvol enters into an infinite loop while trying to move
    a file from one volume to another.

 +o  Fixes a ksh problem related to cleaning the process when terminal is
    abruptly stopped.

 +o  Fixes a problem that could cause the following message to be incorrectly
    generated:

    ccfg_MakeDeviceIdentWWID: Invalid device ID


 +o  Fixes a condition that can cause the following erroneous console warning
    message to be provided when cluster root is under LSM control:

    WARNING: cluster root devices are on private buses!


 +o  Fixes a problem which causes a hang in fcntl()/setflck().

 +o  Prevents a kernel memory fault when an original fileset is unmounted during
    the deletion of its clone fileset.

 +o  Fixes an occasional panic that can be seen when reading from a process
    using Granularity Hints via procfs.

 +o  Increases the default values for udp_ttl and tcp_ttl to 128 hops.

 +o  Changes the fwupgrade command to allow the specified firmware update image
    to be located on a BOOTP server in a connected network.



 +o  Fixes the following problems in sh:


    -  A service denial problem when a quoted script is executed.

    -  A problem with handling ELF files.

    -  A problem with the shell variable $- not holding -C set option when it
       is turned on.

    -  A problem printing broken characters when the type builtin utility of sh
       is invoked in a Japanese locale.


 +o  Fixes the bcmdriver for DEGXA to correct problems that cause it to
    incorrectly report data overruns and prevent DEGX2-SA modules from being
    recognized.




                                            Tru64 UNIX Patches 1-149








 +o  Fixes the IDE/ATAPI driver's reset logic to prevent a kernel memory fault
    when booting and to properly detect and log all master and slave reset
    failures when the system is operational.

 +o  Fixes the error "invalid IPL 4."

 +o  Fixes a problem in which the return value of an unlink() call is not
    checked when two threads try to move a file to two different destination,
    and although one of the threads could unlink() the source file, no relevant
    error message is displayed.

 +o  Improves performance for removing or truncating large files on UFS file
    systems.

 +o  Corrects an issue of a cluster node hanging on boot while the other member
    recovers the cluster root file systems.

 +o  Corrects a problem in which multi-CPU systems will sometimes live lock
    while processing incoming network traffic.  In some cases the live lock
    could result in a cluster event timeout panic.

 +o  Addresses an issue where NULL inquiry data causes a "Device has no name"
    error as well as possible I/O stalls.

 +o  Prevents unnecessary retries of the following: On HSG80, fail unit
    attention with ascq = Oxf002 and returns proper error to a higher layer.

 +o  Corrects the improper scheduling of cron jobs related to months not having
    31 days.

 +o  Fixes a problem where a device file, such as /dev/console, can become
    inaccessible, returning the error "Bad File Number."

 +o  Fixes a problem where attempts by the runtime loader (/sbin/loader) to free
    a null pointer are in error.

 +o  Allows volsave and volrestore to save nconfig/nlog policies for diskgroups
    and restore them appropriately.

 +o  Corrects awk errors for invalid quit statements.

 +o  Changes ICMP redirect processing code so it does not create an invalid
    route for an invalid redirect.

 +o  Prevents crontab from removing its entries and vi from truncating the
    existing file when a file system is full.

 +o  Fixes a problem where defragment (or migrate, balance, or rmvol) threads
    can hang in ms_malloc() and overlay_xtnt_map().

 +o  Fixes a problem in which NIS clients may fail to connect to non-Tru64 UNIX
    NIS servers that only support the V2 NIS protocol.

 +o  Fixes a problem where the CAM I/O subsystem does not always zero the Cam



 1-150 Tru64 UNIX Patches








    Control Blocks which are used by the peripheral drivers, which can cause a
    kernel memory fault or a system hang when the subsystem is low on memory.

 +o  Allows AdvFS to record if a domain panic has occurred, even if a system
    panic results.

 +o  Corrects a problem in which volsave would indicate that the configuration
    had changed during saving when nothing else was going on.  This change
    allows for synchronization for a couple of vold requests and will make sure
    volsave and other commands are more cluster safe and synchronized.



 +o  Fixes a situation where, on a panic, the operating system will erroneously
    reboot instead of halt and fail to take a crash dump.

 +o  Corrects small memory leaks within the kernel that occur infrequently.

 +o  Eliminates the compiler warnings in ksh.

 +o  Adds a -M command option to newfs to let users specify permissions of an
    mfs root directory when it is first created.

 +o  Fixes a problem caused when the TCP layer prematurely closes a slow, but
    good connection with TCP reset.

 +o  Corrects an I/O performance issue seen when CLSM is configured and one
    member of a cluster goes down unexpectedly.

 +o  Fixes a potential kernel memory fault in the IPv6 subsystem.  The problem
    is caused by ICMP error reporting in the IPv6 subsystems for packets
    containing IPv6 extension headers and options.

 +o  Fixes an sh problem while executing command substitution.

 +o  Corrects a locking problem with NFS running over UFS.

 +o  Verifies path structures in ctape_ioctl and ctape_generic_passthru to
    prevent a kernel memory fault if the tape was opened with FNDELAY flag set.

 +o  Prevents a panic that may occur in a cluster when a fileset mounted -o dual
    is failed over or unmounted during shutdown.

 +o  Corrects the creation of console boot device strings for devices on
    subordinate buses.

 +o  Fixes a problem in which an invalid character sometimes appears when
    requesting the name of a boot device via consvar.

 +o  Resolves internet protocol conformance issues and fixes a problem with
    sending multicast datagrams.

 +o  Resolves a problem where some de50x network interface cards, under specific
    circumstances, may not send gratuitous arp packets.



                                            Tru64 UNIX Patches 1-151








 +o  Clarifies the "LIDs do not match" error message.  It now displays the
    values that do not match.  The intent is to assist system managers or
    service personnel with troubleshooting when this error occurs.

 +o  Fixes library dependencies to allow ifconfig to be run in single user mode.

 +o  Fixes a slow boot when booting several cluster nodes at the same time and
    CLSM is configured.

 +o  Corrects a problem in which incorrect I/O status may be returned by the
    KZPEA driver when attempting to abort an I/O during a reset.

 +o  Corrects problems with the time of year (TOY) clock.

 +o  Adds support for IPV6_UNICAST_HOPS socket option on raw sockets.

 +o  Improve the fragment gathering mechanism to boost performance.

 +o  Fixes an AdvFS path which can cause a panic in the advfs_page_busy()
    routine.

 +o  Fixes a problem where memory could retain execute permission on EV6
    machines.



 +o  Fixes a condition that causes a delete_pv_entry panic when kernel virtual
    address space has high usage.

 +o  Fixes the /sbin/init.d/route script to correct a problem that causes routes
    to not get flushed properly.

 +o  Corrects a potential security vulnerability that could result in a denial
    of service on RPC-based servers with Enhanced Security (C2) enabled.  This
    vulnerability may be in the form of local and remote security domain risks.

    SSRT2412 portmapper with Enhanced Security enabled (Severity - High)


 +o  Corrects problems in UFS extendfs that could cause file system metadata
    inconsistency.

 +o  Corrects a potential security vulnerability that could result in
    nonprivileged users gaining unauthorized access to files or privileged
    access on the system.  This potential vulnerability may be in the form of a
    local and remote security domain risk.

 +o  Fixes a problem where a process waiting on a semaphore does not get woken
    up.

 +o  Fixes a problem in which the quot -v command sometimes returns wrong quota
    information on UFS partition.

 +o  Fixes memory leaks caused by certain type of scripts.



 1-152 Tru64 UNIX Patches








 +o  Prevent a_lock related panics.

 +o  Fixes a problem where an I/O error (EIO) can occasionally be returned after
    a page fault.

 +o  Corrects netstat and ifconfig so that MAC addresses are printed using 2-
    digit hex octets with leading zeros.

 +o  Addresses system problems that can occur when the system is under heavy I/O
    load and/or low memory conditions.

 +o  Corrects a problem in which the class scheduler fails to restart if a
    system administrator starts then stops it and then removes system owned
    semaphores (via ipcrm -s).  The error returned is "class_open: allocate or
    access semaphore Invalid argument."

 +o  Fixes a problem where a cluster member can panic with a kernel memory fault
    in kdm_isenabled().

 +o  Prevents a kernel memory fault panic that would occur when the audit daemon
    is set to periodically dump the kernel audit buffers to the audit log file
    (auditd -d freq).

 +o  Updates the camreport program to generate additional status and adds
    support for new devices.



 +o  Fixes an IDE/ATA bus hang caused by attempting to complete raw odd byte DMA
    transfers to/from IDE/ATAPI devices.

 +o  Fixes a performance problem where threads could spend a long time in the
    check_busy() AdvFS routine.

 +o  Increases the default limit of DLI packets to 16 K and makes the limit
    tunable.

 +o  Modifies volencap to prevent encapsulation of restricted partitions or
    placing swap into non-rootdg diskgroup.

 +o  Fixes a problem that could cause corruption in a forked process that may be
    evident when using the C shell.

 +o  Provides protection against a class of potential security vulnerabilities
    called buffer overflows.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.  This patch allows a system administrator to enable
    memory management protections that limit potential buffer overflow
    vulnerabilities.

 +o  ARP request for a permanent ARP entry is ignored, user cannot connect from
    remote system.




                                            Tru64 UNIX Patches 1-153








 +o  Corrects a potential security vulnerability that could result in
    unauthorized privileged access or a denial of service.  This potential
    vulnerability may be in the form of local and remote security domain risks.

 +o  Corrects the following potential security vulnerability:

    SSRT2384 rpc (Severity - High)


 +o  Improves the scalabilty and performance of AdvFS.

 +o  Corrects a problem that causes an NFS client panic when it receives a null
    entry as a response to a readdirplus request from an NFS server.

 +o  Corrects a problem that causes an NFS client panic caused by receiving
    illegal file access mode from an NFS client.

 +o  Corrects a "blkfree: freeing free block" panic and a "blkfree:  freeing
    free frag" panic.

 +o  Corrects a race condition that may result in hung disks under certain
    circumstances, for example, after a SCSI reset is done.

 +o  Prevents an IDE bus hang caused when issuing a play audio track command
    from scu to an ATAPI CD-ROM containing an enhanced CD.

 +o  Fixes an internal problem in the kernel's AdvFS, UFS, and NFS file systems
    where extended attributes with names greater than 247 characters could not
    be set on files.  The new limit is 254 plus a null string terminator.



 +o  Corrects interoperability problems with the libsshrcmd.so library or any
    threaded library that uses the rcmd function.

 +o  Fixes a standard violation on AdvFS.

 +o  Replaces two potential panics in AdvFS with domain panics.

 +o  Corrects mv to correctly parse the pathname when source directory ends in
    trailing slash (/).

 +o  Prevents a potential hang during umount if a domain_panic has been
    encountered.

 +o  Fixes a problem in audit_tool which appends nonsense characters to the
    audit information to the output of an execve event in brief mode.

 +o  Prevents segmentation faults when sia_ses_init is passed a malformed
    argument vector.

 +o  Fixes the Bourne shell so that the expansion $@ generates zero fields when
    no positional parameters are specified for the shell function.




 1-154 Tru64 UNIX Patches








 +o  Corrects a situation in which files created under directories such as
    /usr/lib/sabt/ during the btcreate of file systems with LSM gets copied on
    to the tape.  The files will be removed before they are dumped to the tape.

 +o  Fixes a problem that causes the following panic:

    ppppaaaannnniiiicccc:::: rrrrddddgggg:::: uuuunnnnwwwwiiiirrrriiiinnnngggg

 +o  Corrects a problem where, in some circumstances, a system may panic with a
    kernel memory fault when a device that is being opened by one program is
    being deleted via the hwmgr utility.

 +o  Fixes a potential panic in the auditing of the swapctl syscall.

 +o  Fixes a write/pwrite problem when O_SYNC is set.

 +o  Corrects a possible security hole reported by SSRT2323.

 +o  Allows the size of the NFS server's duplicate request cache to be adjusted
    as needed.

 +o  Corrects a problem in which logins in TruCluster environments using
    Enhanced Security could hang on any member other than the one serving /var
    to CFS.

 +o  Corrects a problem that could cause a cluster crash when VMAC is enabled.

 +o  Corrects memory file system size to accommodate the required space while
    creating bttape in AdvFS or UFS with LSM support.

 +o  Corrects a problem in which KZPEA firmware fails to correctly handle file
    marks with odd byte transfers.

 +o  Fixes a problem in the Network startup script that could result in a
    failure to configure an interface with an IP address.

 +o  Fixes an error in some sections of code that get an E_PAGE_NOT_MAPPED error
    when the code expected the page to exist.

 +o  Fixes two problems in the dynamic runtime loader that might cause an
    application to crash.

 +o  Closes a small race condition when accessing an internal data structure in
    AdvFS.

 +o  Causes restore to export file (-root=hostlist) behavior.

 +o  Fixes an error that can cause a multivolume domain to report ENO_MORE_BLKS
    when some volumes still have free storage.

 +o  Fixes an underlying problem in the NFS client that could lead to a panic on
    a single system or an assertion failure panic on a cluster.





                                            Tru64 UNIX Patches 1-155








 +o  Corrects the behavior of the sort command which now checks for duplicates
    with the -c, -u, and -k flags.

 +o  Changes sort to give exit value > 1 for all the error messages, in
    compliance with existing specifications.

 +o  Corrects the sort command so it does not dump core when more than 50 sort
    keys are used.

 +o  Fixes various problems in the ee driver for DE60x Ethernet adapters.

 +o  Fixes various problems in the bcm driver for DEGXA Gigabit Ethernet
    adapters.

 +o  Adds preliminary ddr support for the DAT-72 device.

 +o  Prevents kernel memory fault Panic from defragment or rmvol

 +o  Corrects a problem that could result in a system panic on close() if the
    BPF default packet filter is in use.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised when a buffer overflow
    occurs in the quot utility.  Buffer overflows are sometimes exploited in an
    attempt to subvert the function of a privileged program and possibly
    execute commands at the elevated privileges if the program file has the
    setuid privilege.

 +o  Corrects problems with name resolution when an error is encountered during
    processing of the local host files.

 +o  Allows tasks with just one SCS thread to be migrated in the same manner as
    single threaded processes in NUMA environments.

 +o  Improves null partition checking.

 +o  Corrects problems in AdvFS write logic, including:


    -  a mismatch between the value reported by the write syscall and the
       number of bytes.

    -  a problem that appears as unavailable, unused storage.


 +o  Provides the logging of an informational event to the errorlog when the
    peripheral driver is unable to get an user specified IDENTIFIER for a
    storage array device.

 +o  Modifies the ifconfig command to include an RCS ID for patch tracking
    purposes.

 +o  Fixes CAM errors that arise when opening CD-ROM devices containing blank
    media.



 1-156 Tru64 UNIX Patches








 +o  Fixes a problem where a cluster node hangs or panics during boot with a
    SLTO on the vdIoLock.  POSIX named semaphores will be in use on the
    cluster.

 +o  Corrects a problem in which Tru64 UNIX sees an HP-XP RAID array controller
    as a disk after an HP-XP storage device is added to the system.

 +o  Fixes the number of cylinders defined in the last cylinder group of a UFS
    file system that has been extended.

 +o  Corrects idle-wait time accounting within the AdvFS file system, as
    reported by the vmstat -w command.

 +o  Resolves a problem affecting IPv6 sockets where a packet transmission might
    fail when the destination address is not specified.

 +o  Changes the at command to prevent jobs that fail to execute when LANG and
    LD_LIBRARY_PATH are set.

 +o  Increases the auditability of memory wire and unwire operations.



 +o  Corrects a potential security vulnerability has been discovered where,
    under certain circumstances, system integrity may be compromised.  This may
    be in the form of improper file access.

 +o  Corrects a condition in which command response deteriorates to about 30
    seconds when doing an rmvol on a domain with a volume containing large
    files (8 GB).  The condition could last for the duration of the transfer,
    which could be 45 minutes.

 +o  Corrects a potential security vulnerability that may result in a local
    Denial of Service (DoS).

 +o  Fixes a problem in which data from an AdvFS file with a frag could be
    written to an incorrect location if an NFS client grew the file.

 +o  Provides comment handling capability in the route initialization script for
    parsing /etc/routes file.

 +o  Modifies the mountd daemon to address a core dump problem.

 +o  Updates the DDR entry for the MSA array and adds other future new device
    support.

 +o  Replaces several system panics with domain panics.

 +o  Enhances HP-XP array controller support and possible future new tape device
    support.

 +o  Fixes a problem in which clua.mod does not handle TCP RST messages
    appropriately.




                                            Tru64 UNIX Patches 1-157








 +o  Fixes a problem that can cause a kernel memory fault during boot if a
    FibreChannel LSM boot disk is not discovered during the device probe.

 +o  Allows acceleration of boot on large memory GS systems.

 +o  Provides modifications for possible future emx hardware.

 +o  Updates ICMP code to add redirect timeout support and nonmodifiable route
    table entries.

 +o  Provides hardware support for the DS15/TS15 platform.

 +o  Corrects a problem in which users are unable to change their passwords on
    systems running Enhanced Security that use C1crypt for password encryption.
    In such cases, the passwd command returns the warning "Password not
    changed: failed to write protected password entry."

 +o  Corrects a problem on systems running Enhanced Security in which the edauth
    -R command will not write user-profile entries to the root partition.

 +o  Fixes a "simple lock: time limit exceeded" panic.

 +o  Corrects the problem of the statfs() function returning EINVAL when
    operating on an fattach() function clone streams device.

 +o  Sets a software limit to prevent serious performance problems that can
    occur when TCP connections that have an rate-limit enforced by a downstream
    network device overrun the device.

 +o  Fixes a condition that could cause the panic "trap:  invalid memory read
    access from kernel mode in procfs_psinfo()."

 +o  Fixes issues with I/O failures seen on non-rootdg disk groups, including
    the following:


    -  The reimport of the disk group may fail under certain conditions

    -  vold may core dump when failing a non-rootdg disk


 +o  Fixes a performance issue seen during plex detach operations.



 +o  Corrects a problem in which table() calls would not correctly get process
    arguments.

 +o  Corrects a panic resulting from a race condition between vnode deallocation
    logic and the use of CACHE_LOOKUP_REF/CACHE_LOOKUP_RELE in grab_bsacc and
    bs_dealloc_access (which attempt to block vnode deallocation).

 +o  Adds support for recognizing ELF and HP-UX file format to the file command.




 1-158 Tru64 UNIX Patches








 +o  Corrects a "simple_lock: time limit exceeded" issue that can occur in the
    CAM I/O subsystem when MCS locking is disabled.

 +o  Corrects the NFS server's handling of files open for direct I/O.

 +o  Fixes two problems in the dynamic runtime loader that might cause an
    application to crash.

 +o  Corrects a rare illegal instruction system crash.

 +o  Fixes several race conditions in seg code.

 +o  Fixes IP multicast packets to work with loopback traffic.

 +o  Corrects a race condition during disk error recovery failure processing
    that can result in hung processes

 +o  Fixes a panic in AIO.

 +o  Corrects a problem to allow CLSM ioctls to return EINVAL when not in a
    cluster.

 +o  Fixes a potential failure during the start up of a multithreaded process.

 +o  Addresses performance issues seen in select() under certain circumstances.

 +o  Prevents a potential panic when AdvFS looks up a file name.

 +o  Fixes a memory fault condition in the user agent driver that occurs when
    multiple threads issue I/Os on different CPUs.

 +o  Fixes a number of regular expression problems in multibyte locales and
    fixes a potential hang problem with complex regular expressions

 +o  Corrects a problem in which a read or write operation to a changer device
    creates an unkillable process.

 +o  Addresses a problem in the IPv6 subsystem where under certain conditions a
    system may panic.

 +o  Addresses a scaling issue seen on large multiprocessor systems in dealing
    with the class scheduling subsystem.

 +o  Prevents a potential unaligned memory crash when ACLs are on.

 +o  Corrects a problem of excessive swapping resulting from MFS files system
    creation.

 +o  Checks for valid m->m_next in dli_input() to avoid kernel memory fault
    panic.

 +o  Corrects a condition in which an error causes a domain panic in
    bs_frag_dealloc or frag_group_dealloc which results in a panic from a
    kernel memory fault in access_invalidate and the frag file is not closed



                                            Tru64 UNIX Patches 1-159








    properly during the exit from bs_frag_dealloc.



 +o  Fixes a leak of kernel address space.

 +o  Fixes jitter problems in 24-bit depth on VX1 graphics cards with certain
    date codes.

 +o  Fixes a condition in which paging activities on a heavily loaded system can
    cause the system to crash with a "simple_lock: uninitialized lock" panic.

 +o  Increases the number of pages that can be pinned at deletion time from 4 to
    6.  It also improves the informational messages returned by a few domain
    panic strings.

 +o  Fixes a problem in the ee driver for DE60x Ethernet adapters

 +o  Fixes a problem in the PCI bus code that can prevent some functions on a
    multi-function PCI card from being configured.

 +o  Fixes a condition in which a system crash can occur if hwmgr deletes a disk
    while it is in recovery.

 +o  Fixes a race condition in the kernel AIO code that could panic the system
    with either a jkernel memory fault or a duplicate malloc free.

 +o  Fixes a ksh memory fault problem that occurs when logging in.

 +o  Corrects a problem in which calling aio_write with a negative size may
    cause a system panic.

 +o  Corrects problems that can result in changer devices not responding or in a
    kernel memory fault when the FNDELAY flag is set in changer open and
    changer ioctl.

 +o  Adds support for DEGXA-SB and DEGXA-TB Gigabit Ethernet

 +o  Fixes a memory fault condition in the emx driver that occurs when
    responding to an inquiry command from a remote port in the fabric.

 +o  Fixes an I/O hang condition on FibreChannel.

 +o  Corrects a problem that can cause a core dump when the fwupgrade command is
    executed with qualifiers.

 +o  Corrects a Kernel Memory Fault caused by configuring an IPv6 address on a
    legacy network interface card.

 +o  Fixes a hole in disk I/O handling that could cause a panic.

 +o  Eliminates the panic, "lock_terminate: lock owned."

 +o  Corrects a problem that occurs in some low free memory situations, in which



 1-160 Tru64 UNIX Patches








    a kernel thread that completes AIO requests may stall on one request,
    causing other requests (that can complete) to back up behind it.

 +o  Increases BOOTP error timeout values for Remote Installation Service (RIS)
    kernel installations.

 +o  Fixes a potential process hang when exiting that can occur on a system that
    has dynamically powered off a processor.

 +o  Fixes an improper handling of domain, area, and fabric RSCN (Registered
    State Change Notifications) by the emx driver that results in the
    nondetection of path failures to storage devices in the fabric.

 +o  Fixes hung I/O in systems with multiple RADs.

 +o  Corrects a condition that can cause applications using the pshared
    subsystem to hang.  The hang would be seen as the result of a thread
    failing to wake up after its condition variable timer had expired.



 +o  Updates DDR for the SDLT600 tape drive.

 +o  Fixes panic: simple_unlock: no locks owned by cpu.

 +o  Updates DDR for the DLT VS series of tape devices.

 +o  Addresses issues seen in the taking of non-interactive core dumps using the
    coredump command.

 +o  Corrects a problem in which the rewind() function would fail to reposition
    to the beginning of a file.

 +o  Corrects inefficiencies and apparent login hangs involving Enhanced
    Security in a TruCluster environment.

 +o  Fixes a problem in which a thread can hang during a malloc call.

 +o  Corrects a condition that can cause a system panic caused by stack growth.

 +o  Causes the sysconfigtab settings for the titan_sys_ps_hotswap and
    titan_sys_fan_hotswap attributes to be maintained after a system reboot.

 +o  Fixes a system hang seen when rename is called with "." as the target and
    causes other rename argument restrictions to be enforced.

 +o  Corrects a problem in which certain older tape drives (for example, TZK50
    and TSV07) would produce errors when they were accessed.

 +o  Fixes possible invalidation of mmap dirty pages before they can be flushed
    to disk.

 +o  Prevents a potential panic seen with memory_test=partial or
    memory_test=none.



                                            Tru64 UNIX Patches 1-161








 +o  Prevents AdvFS metadata inconsistencies and panics on full domain.

 +o  Fixes a problem where an I/O operation may be treated as complete before it
    has actually finished, thereby possibly causing a panic in XPT or a storage
    driver.

 +o  Corrects a condition in which active paths may be improperly treated as
    standby, which could reduce performance or cause a device to switch
    controllers unnecessarily.

 +o  Fixes a condition in which fork() would return EAGAIN incorrectly on a
    process using gh_chunks.

 +o  Adds pfilt_loopback and pfilt_physaddr kernel flags for controlling
    packetfilter written packets.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 2088.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Removes the race security vulnerability in find

 SSSSttttaaaatttteeee:::: Supersedes Patches 479.00, 119.00, 451.00, 3.00, 5.00, 447.00, 449.00,
 113.00, 115.00, 706.00, 707.00, 709.01, 1028.00, 1029.00, 1030.00, 1031.00,
 1032.00, 1033.00, 1034.00, 1035.00, 1036.00, 1037.00, 1038.00, 1040.00,
 1576.00, 1577.00, 1583.00, 1940.00, 1941.00, 1943.00, 2059.00


 +o  Corrects a problem in which access to a file may be denied when multiple
    processes attempt to access the same file at the same time and access to
    the file should be allowed by an ACL on the file.

 +o  Corrects a problem in which if the ACL on a file is corrupted, the
    corrupted ACL is passed into the kernel causing a variety of problems.

 +o  Corrects a problem in which an AutoFS intercept point for a direct map
    entry may no longer induce automounts after an error has been detected
    during a previous automount attempt.

 +o  Fixes AutoFS problems as follows:


    -  Eliminates error messages concerning property lists seen via certain
       utilities such as vdump.

    -  Causes AutoFS automounts to occur when utilities name intercept points
       defined via indirect map entries.

    -  Fixes a deadlock that will occur in non-cluster systems when direct map
       entries are served locally.




 +o  Prevents a core dump from vdump when a message length is greater than



 1-162 Tru64 UNIX Patches








    MAX_MSG_SIZE.

 +o  Fixes vdump command problems as follows:


    -  Fixes a problem in which the command fails to flag compressed extended
       attributes records that are split across a vdump BLOCK boundary

    -  Corrects a rewinding message to avoid a segfault with Internationalized
       messages.


 +o  Fixes vrestore command problems as follows:


    -  Fixes a problem in which the command fails to properly handle extended
       attributes records in compressed archives.  This results in malloc
       failures, proplist corruption, program abort, program crashes due to
       segfault or invalid memory access, and the display of the error message
       "error setting extended attributes"

    -  Fixes a problem in which the command fails to set extended attributes
       due to confusion over selective restore of the file or directory
       associated.  Also results in display of error message "error setting
       extended attributes."

    -  Fixes a problem in which the selective restore of hard-linked files is
       incomplete when they exist in different directories (fails to create
       directory for second occurrence of file with same inode number) .


 +o  Eliminates inefficient behavior by autofsd when the top level directory of
    a direct hierarchical auto-mount map entry cannot be successfully mounted.

 +o  Ensures that AutoFS correctly uses the mount options specified in auto-
    mount map entries with replicated servers.

 +o  Fixes a problem where the tar -F (Fasttar) option ignores files named "err"
    but does not ignore files named "errs" and directories named "SCCS" and
    "RCS".

 +o  Corrects the pax, tar, and cpio commands to properly extract explicitly
    specified files.  When an archive contained a file with extended attributes
    and a different file (occurring later in the archive) was specified to be
    extracted, improper buffer pointer management resulted in the following
    display (example uses tar):

    tar: /dev/nrmt0h : This doesn't look like a tar archive tar: /dev/nrmt0h :
    Skipping to next file...  tar: Memory allocation failed for extended data
    while reading :  Not enough space

    The directory option was similarly affected.  In this case the information
    for the specified file was not reported.




                                            Tru64 UNIX Patches 1-163








 +o  Corrects the behavior of several commands when used in conjunction with
    file systems that are locally served via AutoFS.

 +o  Provides support for wildcards in Linux /etc/exports entries.  Both AutoFS
    and Automount have been so enhanced.

 +o  Fixes a problem in which the autofsd and autofsmount daemons do not
    properly parse the asterisk character (*) in map files.

 +o  Fixes a problem that prevents access to AutoFS file systems if ACLs are
    enabled.



 +o  Permits auto-unmounts to succeed for direct map entries in which the key
    contains a symbolic link.

 +o  Fixes a one byte gap/hole in the maximum size in the tar command before an
    extended header record is used (8589934591 (octal 77777777777)).

 +o  Eliminates AutoFS auto-mount failures due to the receipt of unexpected
    signals while sleeping in the kernel.

 +o  Corrects the find -ls command so it displays the correct number of blocks.

 +o  Supports a cluster patch which limits DLM lock contention by AutoFS in a
    cluster.

 +o  Fixes a defect that allows the possibility that certain AutoFS auto-mounted
    file systems may be mounted more than once.

 +o  Ensures that autofsmount will process all NIS-provided map files included
    via the "+" syntax.  Currently, only the first one, at a given level of
    includes, will be correctly processed.

 +o  Eliminates extraneous communication between an AutoFS client and an NFS
    server's mount daemon in some situations when replicated servers are
    specified in an auto-mount map entry.

 +o  Allows AutoFS to correctly handle NIS-based auto-mount maps using the
    wildcard (*) key.

 +o  Corrects two debugging/diagnostic messages in the AutoFS utilities.

 +o  Fixes a cluster-specific problem with AutoFS in which a race condition
    leads to a slowdown which may lead to auto-mount failures.

 +o  Fixes the following problems with the tar, pax, and cpio commands:


    -  Enables tar to check for and report write errors.

    -  Gives tar, pax, and cpio the capability to unalter the ctime of input
       files upon the creation of an archive and enables the display of warning



 1-164 Tru64 UNIX Patches








       message if pax or cpio is unable to preserve the time of input files.

    -  Corrects the behavior of the tar o option.

    -  Fixes the cpio -m option in cases where the destination and source files
       have same mtime.

    -  Corrects the pax -l option to create hard links properly.

    -  Corrects the cpio -o option so that extended UID file ownership is not
       corrupted.

    -  Fixes the long file names handling in tar.

    -  Corrects tar to properly handle unusual directory specifications.

    -  Fixes pax to handle ACL on directories properly.


 +o  Corrects the find -links, -size, -i, -inum behavior with respect to the +
    operations.  Find + operations will match "Greater Than", rather "Greater
    Than or Equal To."

 +o  Ensures that tar utility correctly restores directory permissions when
    extracted using -p option.

 +o  Fixes an AutoFS panic during an unmount operation when AutoFS tries to
    remove a directory.

 +o  Removes the race security vulnerability in find utility.

 +o  Ensures that tar/pax utilities correctly restore the file mode when
    extracted using appropriate options.

 +o  Fixes a problem with the find command that occurs when a large number of
    directories are searched.





















                                            Tru64 UNIX Patches 1-165










                                             TruCluster Server Patches        2






 This chapter provides information about the patches included in Patch Kit 6
 for the TruCluster Server software.

 This chapter is organized as follows:


 +o  Section 2.1 provides release notes that are specific to the TruCluster
    Server software patches in this kit.

 +o  Section 2.2 provides brief descriptions of the purpose of the TruCluster
    Server patches included in this kit.


 Tru64 UNIX patch kits are cumulative.  For this kit, this means that the
 patches and related documentation from patch kits 1 through 4 are included,
 along with patches that are new to this kit.  To aid you in using this
 document, release notes that are new with this release are listed as (New) in
 the section head.  The beginning of Section 2.2 provides a key for
 understanding the history of individual patches.


 _2._1  _R_e_l_e_a_s_e _N_o_t_e_s

 This section provides release notes that are specific to the TruCluster Server
 software patches in this kit.  References to patch numbers are for TruCluster
 Server patches unless otherwise indicated.


 _2._1._1  _R_e_q_u_i_r_e_d _S_t_o_r_a_g_e _S_p_a_c_e

 The following storage space is required to successfully install this patch
 kit:


 +o  Approximately 250 MB of temporary storage space is required to untar this
    patch kit (base and TruCluster).  We recommend that this kit not be placed
    in the ////, ////uuuussssrrrr, or ////vvvvaaaarrrr file systems because doing so may unduly constrain
    the available storage space for the patching activity.

 +o  Approximately 102 MB of storage space in ////vvvvaaaarrrr////aaaaddddmmmm////ppppaaaattttcccchhhh////bbbbaaaacccckkkkuuuupppp may be
    required for archived original files if you choose to install and revert
    all patches.  See the _P_a_t_c_h _K_i_t _I_n_s_t_a_l_l_a_t_i_o_n _I_n_s_t_r_u_c_t_i_o_n_s for more
    information.

 +o  Approximately 104.9 MB of storage space in ////vvvvaaaarrrr////aaaaddddmmmm////ppppaaaattttcccchhhh may be required
    for original files if you choose to install and revert all patches.  See











    the _P_a_t_c_h _K_i_t _I_n_s_t_a_l_l_a_t_i_o_n _I_n_s_t_r_u_c_t_i_o_n_s for more information.

 +o  Approximately 2.6 MB of storage space is required in ////vvvvaaaarrrr////aaaaddddmmmm////ppppaaaattttcccchhhh////ddddoooocccc for
    patch abstract and README documentation.

 +o  Approximately 176 KB of storage space is needed in ////uuuussssrrrr////ssssbbbbiiiinnnn////dddduuuuppppaaaattttcccchhhh for
    the patch management utility.


 See Section 1.1.1 for information on space needed for the operating system
 patches.


 _2._1._2  _R_e_m_o_v_i_n_g _S_o_m_e _P_a_t_c_h_e_s _C_a_n _C_a_u_s_e _P_r_o_b_l_e_m_s

 Removing the following patches from your cluster may cause problems:


 +o  Patches that were installed before a cluster was created.

 +o  Patches that were installed before one or more new members were added to
    the cluster.  This includes running cccclllluuuu____aaaadddddddd____mmmmeeeemmmmbbbbeeeerrrr during a rolling upgrade
    after the install stage has been completed.


 Because some patches cannot be safely removed in a cluster without causing
 member-specific problems, we recommend that you do not remove patches under
 these conditions.  Section 2.1.3 describes a problem of this type.


 _2._1._3  _P_a_t_c_h _R_e_m_o_v_a_l _C_a_u_s_e_s _L_o_g_i_n _E_r_r_o_r

 If you removed Version 5.1A patches that were installed before a cluster was
 created or before new members were added, you may see an error similar to the
 following when you attempt to log into a member:

 Login Error: Compaq Tru64 UNIX V5.1A (Rev. 1885) (system.xyzcorp.net) console
 login:
 INIT: Command is respawning too rapidly. Check for possible errors.
 id:  esmd "/usr/sbin/esmd /dev/null 2>&#38;1

 If you see this error, remove the following lines from that cluster member's
 ////eeeettttcccc////iiiinnnniiiittttttttaaaabbbb file:

   esm_init:23:wait:/sbin/init.d/esm init ////ddddeeeevvvv////nnnnuuuullllllll 2222>>>>&&&&####33338888;;;;1111
   esmd:23:respawn:/usr/sbin/esmd ////ddddeeeevvvv////nnnnuuuullllllll 2222>>>>&&&&####33338888;;;;1111





 _2._1._4  _U_p_d_a_t_e_s _f_o_r _R_o_l_l_i_n_g _U_p_g_r_a_d_e _P_r_o_c_e_d_u_r_e_s

 The following sections provide information on rolling upgrade procedures.



 2-2 TruCluster Server Patches








 _2._1._4._1  _P_r_o_b_l_e_m _W_h_e_n _U_n_d_o_i_n_g _R_o_l_l _w_i_t_h _W_o_r_l_d_w_i_d_e _L_a_n_g_u_a_g_e_s _I_n_s_t_a_l_l_e_d

 If, on a system with Worldwide Languages installed, you complete a rolling
 upgrade of Patch Kit 6 and then run the cccclllluuuu____uuuuppppggggrrrraaaaddddeeee ----uuuunnnnddddoooo iiiinnnnssssttttaaaallllllll command, the
 ttttaaaarrrr program may report that it cannot find files it expects to find.  This
 condition is caused by a file left in the ////cccclllluuuusssstttteeeerrrr////aaaaddddmmmmiiiinnnn////ttttmmmmpppp directory from
 the previous setup stage.

 To correct this problem, take the following steps:


 1. Undo the setup stage again.

 2. Issue the following command:

    # rrrrmmmm ----ffff ////cccclllluuuusssstttteeeerrrr////aaaaddddmmmmiiiinnnn////ttttmmmmpppp////****


 3. Redo the setup stage.




 _2._1._4._2  _O_r_d_e_r _f_o_r _R_o_l_l_i_n_g _N_H_D_6 _a_n_d _P_a_t_c_h _K_i_t _6

 Because Patch Kit 6 contains all of the information contained in the NHD6 kit,
 you do not need to roll the NHD6 kit in addition to Patch Kit 6.  If, however,
 you plan to roll both kits, you must install the NHD kit first, followed by
 the patch kit.  If you reverse the installation order, you will get a kernel
 build failure after installing the NHD6 kit.


 _2._1._4._3  _U_n_r_e_c_o_v_e_r_a_b_l_e _F_a_i_l_u_r_e _P_r_o_c_e_d_u_r_e

 The procedure to follow if you encounter unrecoverable failures while running
 dddduuuuppppaaaattttcccchhhh during a rolling upgrade has changed.  The new procedure calls for you
 to run the cccclllluuuu____uuuuppppggggrrrraaaaddddeeee ----uuuunnnnddddoooo iiiinnnnssssttttaaaallllllll command and then set the system baseline.
 The procedure is explained in the _P_a_t_c_h _K_i_t _I_n_s_t_a_l_l_a_t_i_o_n _I_n_s_t_r_u_c_t_i_o_n_s as notes
 in Section 5.3 and Section 5.6.


 _2._1._4._4  _D_u_r_i_n_g _R_o_l_l_i_n_g _P_a_t_c_h, _D_o _N_o_t _A_d_d _o_r _D_e_l_e_t_e _O_S_F, _T_C_R, _I_O_S, _o_r _O_S_H
          _S_u_b_s_e_t_s

 During a rolling upgrade, do not use the ////uuuussssrrrr////ssssbbbbiiiinnnn////sssseeeettttlllldddd command to add or
 delete any of the following subsets:


 +o  Base Operating System subsets (those with the prefix OOOOSSSSFFFF).

 +o  TruCluster Server subsets (those with the prefix TTTTCCCCRRRR).

 +o  Worldwide Language Support (WLS) subsets (those with the prefix IIIIOOOOSSSS).




                                       TruCluster Server Patches 2-3








 +o  New Hardware Delivery (NHD) subsets (those with the prefix OOOOSSSSHHHH).


 Adding or deleting these subsets during a roll creates inconsistencies in the
 tagged files.


 _2._1._4._5  _U_n_d_o_i_n_g _a _R_o_l_l_i_n_g _P_a_t_c_h

 When you undo the stages of a rolling upgrade, the stages must be undone in
 the correct order.  However, the cccclllluuuu____uuuuppppggggrrrraaaaddddeeee command incorrectly allows a user
 undoing the stages of a rolling patch to run the cccclllluuuu____uuuuppppggggrrrraaaaddddeeee uuuunnnnddddoooo pppprrrreeeeiiiinnnnssssttttaaaallllllll
 command before running the cccclllluuuu____uuuuppppggggrrrraaaaddddeeee uuuunnnnddddoooo iiiinnnnssssttttaaaallllllll command.

 The problem is that in the install stage, cccclllluuuu____uuuuppppggggrrrraaaaddddeeee cannot tell from the
 dddduuuuppppaaaattttcccchhhh flag files whether the roll is going forward or backward.  This
 ambiguity allows a user who is undoing a rolling patch to run the cccclllluuuu____uuuuppppggggrrrraaaaddddeeee
 uuuunnnnddddoooo pppprrrreeeeiiiinnnnssssttttaaaallllllll command without first having run the cccclllluuuu____uuuuppppggggrrrraaaaddddeeee uuuunnnnddddoooo iiiinnnnssssttttaaaallllllll
 command.

 To avoid this problem when undoing the stages of a rolling patch, make sure to
 follow the documented procedure and undo the stages in order.


 _2._1._4._5._1  _I_g_n_o_r_e _M_e_s_s_a_g_e _A_b_o_u_t _M_i_s_s_i_n_g _l_a_d_e_b_u_g._c_a_t _F_i_l_e _D_u_r_i_n_g _R_o_l_l_i_n_g
 _U_p_g_r_a_d_e - When installing the patch kit during a rolling upgrade, you may see
 the following error and warning messages.  You can ignore these messages and
 continue with the rolling upgrade.

 Creating tagged files.

 \&...............................................................................
 \&.....

 *** Error ***
 The tar commands used to create tagged files in the '/usr' file system have
 reported the following errors and warnings:
      tar: lib/nls/msg/en_US.88591/ladebug.cat : No such file or directory
 \&.........................................................

 *** Warning ***
 The above errors were detected during the cluster upgrade. If you believe that
 the errors are not critical to system operation, you can choose to continue.
 If you are unsure, you should check the cluster upgrade log and refer
 to clu_upgrade(8) before continuing with the upgrade.



 _2._1._4._6  _c_l_u__u_p_g_r_a_d_e _u_n_d_o _o_f _I_n_s_t_a_l_l _S_t_a_g_e _C_a_n _R_e_s_u_l_t _i_n _I_n_c_o_r_r_e_c_t _F_i_l_e
          _P_e_r_m_i_s_s_i_o_n_s

 This note applies only when both of the following are true:





 2-4 TruCluster Server Patches








 +o  You are using iiiinnnnssssttttaaaalllllllluuuuppppddddaaaatttteeee, dddduuuuppppaaaattttcccchhhh, or nnnnhhhhdddd____iiiinnnnssssttttaaaallllllll to perform a rolling
    upgrade.

 +o  You need to undo the iiiinnnnssssttttaaaallllllll stage; that is, to use the cccclllluuuu____uuuuppppggggrrrraaaaddddeeee uuuunnnnddddoooo
    iiiinnnnssssttttaaaallllllll command.


 In this situation, incorrect file permissions can be set for files on the lead
 member.  This can result in the failure of rrrrsssshhhh, rrrrllllooooggggiiiinnnn, and other commands
 that assume user IDs or identities by means of sssseeeettttuuuuiiiidddd.

 The cccclllluuuu____uuuuppppggggrrrraaaaddddeeee uuuunnnnddddoooo iiiinnnnssssttttaaaallllllll command must be run from a nonlead member that
 has access to the lead member's boot disk.  After the command completes,
 follow these steps:


 1. Boot the lead member to single-user mode.

 2. Run the following script:

    #!/usr/bin/ksh -p
    #
    #    Script for restoring installed permissions
    #
    cd /
    for i in /usr/.smdb./$(OSF|TCR|IOS|OSH)*.sts
    do
      grep -q "_INSTALLED" $i 2>/dev/null &#38;&#38; /usr/lbin/fverify -y <"${i%.sts}.inv"
    done


 3. Rerun iiiinnnnssssttttaaaalllllllluuuuppppddddaaaatttteeee, dddduuuuppppaaaattttcccchhhh, or nnnnhhhhdddd____iiiinnnnssssttttaaaallllllll, whichever is appropriate, and
    complete the rolling upgrade.


 For information about rolling upgrades, see Chapter 7 of the _C_l_u_s_t_e_r
 _I_n_s_t_a_l_l_a_t_i_o_n manual, iiiinnnnssssttttaaaalllllllluuuuppppddddaaaatttteeee(8), and cccclllluuuu____uuuuppppggggrrrraaaaddddeeee(8).


 _2._1._4._7  _M_i_s_s_i_n_g _E_n_t_r_y _M_e_s_s_a_g_e_s _C_a_n _B_e _I_g_n_o_r_e_d _D_u_r_i_n_g _R_o_l_l_i_n_g _P_a_t_c_h

 During the sssseeeettttuuuupppp stage of a rolling patch, you might see a message like the
 following:

 Creating tagged files.
 \&............................................................................

 clubase: Entry not found in /cluster/admin/tmp/stanza.stdin.597530

 clubase: Entry not found in /cluster/admin/tmp/stanza.stdin.597568

 An EEEEnnnnttttrrrryyyy nnnnooootttt ffffoooouuuunnnndddd message will appear once for each member in the cluster.
 The number in the message corresponds to a PID.




                                       TruCluster Server Patches 2-5








 You can safely ignore this EEEEnnnnttttrrrryyyy nnnnooootttt ffffoooouuuunnnndddd message.


 _2._1._4._8  _R_e_l_o_c_a_t_i_n_g _A_u_t_o_F_S _D_u_r_i_n_g _a _R_o_l_l_i_n_g _U_p_g_r_a_d_e _o_n _a _C_l_u_s_t_e_r

 This note applies only to performing rolling upgrades on cluster systems that
 use AutoFS.

 During a cluster rolling upgrade, each cluster member is singly halted and
 rebooted several times.  The _P_a_t_c_h _K_i_t _I_n_s_t_a_l_l_a_t_i_o_n _I_n_s_t_r_u_c_t_i_o_n_s direct you to
 manually relocate applications under the control of Cluster Application
 Availability (CAA) prior to halting a member on which CAA applications run.

 Depending on the amount of NFS traffic, the manual relocation of AutoFS may
 sometimes fail.  Failure is most likely to occur when NFS traffic is heavy.
 The following procedure avoids that problem.

 At the start of the rolling upgrade procedure, use the ccccaaaaaaaa____ssssttttaaaatttt command to
 learn which member is running AutoFS.  For example:

 # ccccaaaaaaaa____ssssttttaaaatttt ----tttt
 Name           Type           Target    State     Host
 ------------------------------------------------------------
 autofs         application    ONLINE    ONLINE    rye
 cluster_lockd  application    ONLINE    ONLINE    rye
 clustercron    application    ONLINE    ONLINE    swiss
 dhcp           application    ONLINE    ONLINE    swiss
 named          application    ONLINE    ONLINE    rye

 To minimize your effort in the procedure described as follows, it is desirable
 to perform the roll stage last on the member where AutoFS runs.

 When it comes time to perform a manual relocation on a member where AutoFS is
 running, follow these steps:


 1. Stop AutoFS by entering the following command on the member where AutoFS
    runs:

    # ////uuuussssrrrr////ssssbbbbiiiinnnn////ccccaaaaaaaa____ssssttttoooopppp ----ffff aaaauuuuttttooooffffssss


 2. Perform the manual relocation of other applications running on that member:

    # ////uuuussssrrrr////ssssbbbbiiiinnnn////ccccaaaaaaaa____rrrreeeellllooooccccaaaatttteeee ----ssss _c_u_r_r_e_n_t__m_e_m_b_e_r -c _t_a_r_g_e_t__m_e_m_b_e_r



 After the member that had been running AutoFS has been halted as part of the
 rolling upgrade procedure, restart AutoFS on a member that is still up.  (If
 this is the roll stage and the halted member is not the last member to be
 rolled, you can minimize your effort by restarting AutoFS on the member you
 plan to roll last.)




 2-6 TruCluster Server Patches








 1. On a member that is up, enter the following command to restart AutoFS.
    (The member where AutoFS is to run, _t_a_r_g_e_t__m_e_m_b_e_r, must be up and running
    in multi-user mode.)

    # ////uuuussssrrrr////ssssbbbbiiiinnnn////ccccaaaaaaaa____ssssttttaaaarrrrttttaaaauuuuttttooooffffssss ----cccc _t_a_r_g_e_t__m_e_m_b_e_r


 2. Continue with the rolling upgrade procedure.




 _2._1._5  _W_h_e_n _T_a_k_i_n_g _a _C_l_u_s_t_e_r _M_e_m_b_e_r _t_o _S_i_n_g_l_e-_U_s_e_r _M_o_d_e, _F_i_r_s_t _H_a_l_t _t_h_e _M_e_m_b_e_r

 To take a cluster member from multiuser mode to single-user mode, first halt
 the member and then boot it to single-user mode.  For example:

 # sssshhhhuuuuttttddddoooowwwwnnnn ----hhhh nnnnoooowwww
 >>> bbbbooooooootttt ----ffffllll ssss

 Halting and booting the system ensures that it provides the minimal set of
 services to the cluster and that the running cluster has a minimal reliance on
 the member running in single-user mode.

 When the system reaches single-user mode, run the following commands:

 # iiiinnnniiiitttt ssss
 # bbbbcccchhhheeeecccckkkkrrrrcccc
 # llllmmmmffff rrrreeeesssseeeetttt



 _2._1._6  _A_d_d_i_t_i_o_n_a_l _S_t_e_p_s _R_e_q_u_i_r_e_d _W_h_e_n _I_n_s_t_a_l_l_i_n_g _P_a_t_c_h_e_s _B_e_f_o_r_e _C_l_u_s_t_e_r
        _C_r_e_a_t_i_o_n

 This note applies only if you install a patch kit before creating a cluster;
 that is, if you do the following:


 1. Install the Tru64 UNIX base kit.

 2. Install the TruCluster Server kit.

 3. Install the Version 5.1A Patch Kit-0005 before running the cccclllluuuu____ccccrrrreeeeaaaatttteeee
    command.


 In this situation, you must then perform three additional steps:


 1. Run vvvveeeerrrrsssswwww, the version switch command, to set the new version identifier:

    # ////uuuussssrrrr////ssssbbbbiiiinnnn////vvvveeeerrrrsssswwww ----sssseeeettttnnnneeeewwww




                                       TruCluster Server Patches 2-7








 2. Run vvvveeeerrrrsssswwww to switch to the new version:

    # ////uuuussssrrrr////ssssbbbbiiiinnnn////vvvveeeerrrrsssswwww ----sssswwwwiiiittttcccchhhh


 3. Run the cccclllluuuu____ccccrrrreeeeaaaatttteeee command to create your cluster:

    # ////uuuussssrrrr////ssssbbbbiiiinnnn////cccclllluuuu____ccccrrrreeeeaaaatttteeee





 _2._1._7  _P_r_o_b_l_e_m_s _w_i_t_h _c_l_u__u_p_g_r_a_d_e _s_w_i_t_c_h _S_t_a_g_e

 If the cccclllluuuu____uuuuppppggggrrrraaaaddddeeee sssswwwwiiiittttcccchhhh stage does not complete successfully, you may see a
 message like the following:

 versw: No switch due to inconsistent versions

 The problem can be due to one or more members running ggggeeeennnnvvvvmmmmuuuunnnniiiixxxx, a generic
 kernel.

 Use the command cccclllluuuu____ggggeeeetttt____iiiinnnnffffoooo ----ffffuuuullllllll and note each member's version number, as
 reported in the line beginning

 Member base O/S version

 If a member has a version number different from that of the other members,
 shut down the member and reboot it from vvvvmmmmuuuunnnniiiixxxx, the custom kernel.  If
 multiple members have the different version numbers, reboot them one at a time
 from vvvvmmmmuuuunnnniiiixxxx.


 _2._1._7._1  _C_l_u_s_t_e_r _I_n_f_o_r_m_a_t_i_o_n _f_o_r _T_r_u_6_4 _U_N_I_X _P_a_t_c_h _2_0_8_4._0_0

 See Section 1.1.20.7 for version switch information related to Tru64 UNIX
 Patch 2084.00.


 _2._1._7._2  _C_h_a_n_g_e _t_o _g_a_t_e_d _R_e_s_t_r_i_c_t_i_o_n &#_1_5_1; _P_a_t_c_h _3_3_6._0_0

 The following information explains the relaxed CCCClllluuuusssstttteeeerrrr AAAAlllliiiiaaaassss::::  ggggaaaatttteeeedddd
 restriction, delivered in TruCluster Patch 336.00.

 Prior to this patch, we required that you use ggggaaaatttteeeedddd as a routing daemon for
 the correct operation of cluster alias routing because the cluster alias
 subsystem did not coexist gracefully with either the rrrroooouuuutttteeeedddd or static routes.
 This patch provides an aaaalllliiiiaaaassssdddd daemon that does not depend on having ggggaaaatttteeeedddd
 running in order to function correctly.

 The following is a list of features supported by this patch:





 2-8 TruCluster Server Patches








 +o  The ggggaaaatttteeeedddd and rrrroooouuuutttteeeedddd routing daemons are supported in a cluster.  In
    addition, static routing is supported (no routing daemons are required).

    Because aaaalllliiiiaaaassssdddd is optimized for ggggaaaatttteeeedddd, using ggggaaaatttteeeedddd remains the default and
    preferred routing daemon.  However, it is no longer mandatory, nor is it
    the only way to configure routing for a cluster member.  For example, you
    could configure a cluster where all members use static routing, or some
    members run rrrroooouuuutttteeeedddd, or use a combination of routing daemons and static
    routes.

    However, the existing restriction against using ooooggggaaaatttteeeedddd still applies; do
    not use ooooggggaaaatttteeeedddd as a routing daemon in a cluster.

    _N_o_t_e

    Cluster members do not have to have identical routing configurations.  In
    general, it is simpler to configure all cluster members identically, but in
    some instances, an experienced cluster administrator might choose to
    configure one or more members to perform different routing tasks.  For
    example, one member might have CCCCLLLLUUUUAAAAMMMMGGGGRRRR____RRRROOOOUUUUTTTTEEEE____AAAARRRRGGGGSSSS====""""nnnnooooggggaaaatttteeeedddd"""" in its
    ////eeeettttcccc////rrrrcccc....ccccoooonnnnffffiiiigggg file and have a fully populated ////eeeettttcccc////rrrroooouuuutttteeeessss file.  Or a
    member might run with nnnnooooggggaaaatttteeeedddd and rrrroooouuuutttteeeedddd ----qqqq.


 +o  The alias daemon

    The alias daemon will handle the failover of cluster alias IP addresses via
    the cluster interconnect for either dynamic routing or static routing.  If
    an interface fails, aaaalllliiiiaaaassssdddd reroutes alias traffic to another member of the
    cluster.  As long as the cluster interconnect is working, there is always a
    way for cluster alias traffic to get in or out of the cluster.

 +o  Multiple interfaces per subnet (for network load balancing)

    Although ggggaaaatttteeeedddd does not support this configuration, because static routing
    is supported, an administrator can use static (nnnnooooggggaaaatttteeeedddd) routing for network
    load balancing.


 By default, the cluster alias subsystem uses ggggaaaatttteeeedddd, customized configuration
 files (////eeeettttcccc////ggggaaaatttteeeedddd....ccccoooonnnnffff....mmmmeeeemmmmbbbbeeeerrrr), and RIP to advertise host routes for alias
 addresses.  You can disable this behavior by specifying the nnnnooooggggaaaatttteeeedddd option to
 cccclllluuuuaaaammmmggggrrrr, either by running the cccclllluuuuaaaammmmggggrrrr ----rrrr nnnnooooggggaaaatttteeeedddd command on a member or by
 setting CCCCLLLLUUUUAAAAMMMMGGGGRRRR____RRRROOOOUUUUTTTTEEEE____AAAARRRRGGGGSSSS====""""nnnnooooggggaaaatttteeeedddd"""" in that members ////eeeettttcccc////rrrrcccc....ccccoooonnnnffffiiiigggg file.  For
 example, the network configuration for a member could use rrrroooouuuutttteeeedddd, or ggggaaaatttteeeedddd
 with a site-customized ////eeeettttcccc////ggggaaaatttteeeedddd....ccccoooonnnnffff file, or static routing.

 For a cluster, there are three general routing configuration scenarios:


 +o  The default configuration:  aaaalllliiiiaaaassssdddd controls ggggaaaatttteeeedddd.


    -  Each member has the following in its ////eeeettttcccc////rrrrcccc....ccccoooonnnnffffiiiigggg file:



                                       TruCluster Server Patches 2-9








       GATED="yes"
       CLUAMGR_ROUTE_ARGS=""  # if variable present, set to a null string


    -  If needed, static routes are defined in each member's ////eeeettttcccc////rrrroooouuuutttteeeessss file.

       _N_o_t_e

       Static routes in ////eeeettttcccc////rrrroooouuuutttteeeessss files are installed before routing daemons
       are started, and honored by routing daemons.


 +o  Members run ggggaaaatttteeeedddd, but the cluster alias and aaaalllliiiiaaaassssdddd are independent of it.
    The administrator has total control over ggggaaaatttteeeedddd and its configuration file,
    ////eeeettttcccc////ggggaaaatttteeeedddd....ccccoooonnnnffff.  This approach is useful for an administrator who wants to
    enable IP forwarding and configure a member as a full-fledged router.


    -  Each member that will follow this policy has the following in its
       ////eeeettttcccc////rrrrcccc....ccccoooonnnnffffiiiigggg file:

       GATED="yes"
       CLUAMGR_ROUTE_ARGS="nogated"
       ROUTER="yes"  # if this member will be a full-fledged router


    -  If needed, configure static routes in ////eeeettttcccc////rrrroooouuuutttteeeessss.


 +o  Static routing: one or more cluster members do not run a routing daemon.


    -  Each member that will use static routing has the following in its
       ////eeeettttcccc////rrrrcccc....ccccoooonnnnffffiiiigggg file:

       GATED="no"
       CLUAMGR_ROUTE_ARGS="nogated"
       ROUTED="no"
       ROUTED_FLAGS=""


    -  Define static routes in that member's ////eeeettttcccc////rrrroooouuuutttteeeessss file.





 _2._1._7._3  _V_e_r_s_i_o_n _S_w_i_t_c_h _W_a_r_n_i_n_g _A_d_d_e_d &#_1_5_1; _P_a_t_c_h _3_5_1._0_0

 TruCluster Server Patch 351.00 provides a warning that informs you that
 installed patches include a version switch, so those patches cannot be removed
 using the normal patch removal procedure.  The waring allows you to continue
 with the switch stage or exit clu_upgrade.




 2-10 TruCluster Server Patches








 In addition to the warning prior to the switch stage, this patch also provides
 additional user information after the user has decided to perform a patch
 rolling upgrade and has entered the pathname to a patch kit which contains one
 or more patches requiring a version switch.

 The additional user information identifies the patches containing the version
 switch and provides references to the appropriate user documentation.


 _2._1._7._4  _I_n_f_o_r_m_a_t_i_o_n _f_o_r _P_a_t_c_h _3_7_1._0_0

 This section provides information for TruCluster Server Patch 371.00.


 _2._1._7._5  _E_n_a_b_l_e_r_s _f_o_r _E_V_M

 This patch provides enablers for the Compaq SANworks(tm) Enterprise Volume
 Manager (EVM) Version 2.0.


 _2._1._7._6  _R_o_l_l_i_n_g _U_p_g_r_a_d_e _V_e_r_s_i_o_n _S_w_i_t_c_h

 This patch uses the rolling upgrade version switch to ensure that all members
 of the cluster have installed the patch before it is enabled.

 Prior to throwing the version switch, you can remove this patch by returning
 to the rolling upgrade install stage, rerunning dddduuuuppppaaaattttcccchhhh, and selecting the
 Patch Deletion item in the Main Menu.

 You can remove this patch after the version switch is thrown, but this
 requires a shutdown of the entire cluster.

 To remove this patch after the version switch is thrown, use the following
 procedure:

 _N_o_t_e

 Use this procedure only under the following conditions:


 +o  The rolling upgrade that installed this patch, including the clean stage,
    has completed.

 +o  The version switch has been thrown (cccclllluuuu____uuuuppppggggrrrraaaaddddeeee ----sssswwwwiiiittttcccchhhh).

 +o  A new rolling upgrade is not in progress.

 +o  All cluster members are up and in multiuser mode.



 1. Run the ////uuuussssrrrr////ssssbbbbiiiinnnn////eeeevvvvmmmm____vvvveeeerrrrsssswwww____uuuunnnnddddoooo command.

    When this command completes, it asks whether it should shut down the entire



                                      TruCluster Server Patches 2-11








    cluster now.  The patch removal process is not complete until after the
    cluster has been shut down and restarted.

    If you do not shut down the cluster at this time, you will not be able to
    shut down and reboot an individual member until the entire cluster has been
    shut down.

 2. After cluster shutdown, boot the cluster to multiuser mode.

 3. Rerun the rolling upgrade procedure from the beginning (starting with the
    setup stage).  When you rerun dddduuuuppppaaaattttcccchhhh, select the Patch Deletion item in
    the Main Menu.


 For more information about rolling upgrades and removing patches, see the
 _P_a_t_c_h _K_i_t _I_n_s_t_a_l_l_a_t_i_o_n _I_n_s_t_r_u_c_t_i_o_n_s.


 _2._1._7._7  _R_e_s_t_r_i_c_t_i_o_n_s _R_e_m_o_v_e_d

 The restriction of not supporting multiple filesets from the cccclllluuuusssstttteeeerrrr____rrrrooooooootttt
 domain has been removed.  It is now fully supported to have multiple filesets
 from the cccclllluuuusssstttteeeerrrr____rrrrooooooootttt domain to be mounted in a cluster; however, this could
 slow down the failover of this domain in certain cases and should only be used
 when necessary.

 The restriction of not supporting multiple filesets from a boot partition
 domain has been removed.  It is now fully supported to have multiple filesets
 from a node's boot partition to be mounted in a cluster; however, when the CFS
 server node leaves the cluster all filesets mounted from that node's boot
 partition domain will be force unmounted.


 _2._1._7._8  _C_A_A _a_n_d _D_a_t_a_s_t_o_r_e &#_1_5_1; _P_a_t_c_h _3_3_8._0_0

 This section provides information about TruCluster Server Patch 338.00.

 During a rolling upgrade, when the last member is rolled and immediately after
 the version switch is thrown, a script is run to put CAA on hold and copy the
 old datastore to the new datastore.  CAA will connect to the new datastore
 when it is available.

 The time required to do this depends on the amount of information in the
 datastore and the speed of each member machine.  For 50 resources we have
 found the datastore conversion itself to only take a few seconds.

 To undo this patch, the following command must be run:

 ////uuuussssrrrr////ssssbbbbiiiinnnn////cccclllluuuusssstttteeeerrrr////ccccaaaaaaaa____rrrroooollllllllDDDDaaaattttaaaassssttttoooorrrreeee bbbbaaaacccckkkkwwwwaaaarrrrdddd

 You are prompted to guide the backward conversion process.

 One step of this command will prompt you to kill the ccccaaaaaaaadddd daemons on all
 members.  A ccccaaaaaaaadddd daemon may still appear to be running as an uninterruptible



 2-12 TruCluster Server Patches








 sleeping process (state UUUU in the ppppssss command) after issuing a kkkkiiiillllllll ----9999 command.
 You can safely ignore this and continue with the conversion process as
 prompted, because ccccaaaaaaaadddd will be killed when the process wakes up.


 _2._2  _S_u_m_m_a_r_y _o_f _T_r_u_C_l_u_s_t_e_r _S_o_f_t_w_a_r_e _P_a_t_c_h_e_s

 This section provides brief descriptions of the patches in Patch Kit 6 for the
 TruCluster Server software products.  Because Tru64 UNIX patch kits are
 cumulative, each patch lists its state according to the following criteria:


 +o  New

    Indicates a patch that is new for this release

 +o  New (Supersedes Patches ...  )

    Indicates a patch that is new to the kit but was combined (merged) with one
    or more patches during the creation of earlier versions of this kit, before
    it was publicly released.

 +o  Existing (Kit 4)

    Indicates a patch that was new in the specified Version 5.1A patch kit.

 +o  Existing

    Indicates a patch that was introduced in Patch Kit 1 or Patch Kit 2.

 +o  Supersedes Patches ...

    Indicates a patch that was combined (merged) with other patches.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 27.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for clusterwide wall messages not being received

 SSSSttttaaaatttteeee:::: Existing


 +o  Allows the cluster wall daemon to restart following an EVM daemon failure.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 88.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for cluster hang during boot

 SSSSttttaaaatttteeee:::: Supersedes Patch 29.00


 +o  Addresses a situation where the second node in a cluster hangs upon boot
    while setting the current time and date with ntpdate.



                                      TruCluster Server Patches 2-13








 NNNNuuuummmmbbbbeeeerrrr:::: Patch 121.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Using a cluster as a RIS server causes panic

 SSSSttttaaaatttteeee:::: New


 +o  Fixes a problem that causes a panic when using a cluster as a RIS server.

 +o  Provides a fix to RIS/DMS serving in a cluster.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 136.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Enhancement for clu_autofs shutdown script

 SSSSttttaaaatttteeee:::: Existing


 +o  Makes the /sbin/init.d/clu_autofs script more robust.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 188.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes cluster kernel problem that causes a hang

 SSSSttttaaaatttteeee:::: Supersedes patches 70.00, 186.00


 +o  Fixes a panic in the kernel group services when another node is booted into
    the cluster.

 +o  Fixes a problem in the cluster kernel that causes the cluster to hang when
    a member is rebooted into the cluster.

 +o  Fixes a problem in the cluster kernel that causes one or more members to
    panic during a cluster shutdown.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 195.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Memory Channel API problem causes system hang

 SSSSttttaaaatttteeee:::: Existing (Patch Kit 3)


 +o  Fixes a problem in the Memory Channel API that can cause a system to hang.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 212.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects performance issues on starting cluster LSM

 SSSSttttaaaatttteeee:::: Supersedes Patch 150.00



 2-14 TruCluster Server Patches








 +o  Eliminates spurious duplicate error messages when cluster root is under LSM
    control.

 +o  Corrects performance issues on starting of Cluster Logical Storage Manager
    with large configurations.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 254.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security

 SSSSttttaaaatttteeee:::: Supersedes Patch 52.00


 +o  Provides enablers for the Compaq Database Utility.

 +o  Corrects a potential security vulnerability where, under certain
    circumstances, system integrity may be compromised.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 256.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for cluster hang

 SSSSttttaaaatttteeee:::: Existing (Kit 4)


 +o  Enables a cluster to boot even if the cluster root domain devices are
    private to different cluster members.  This is not a recommended
    configuration; however, it should not result in an unbootable cluster.
    Currently, this is with respect to cluster root domains not under LSM
    control.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 265.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for cluster alias manager SUITlet

 SSSSttttaaaatttteeee:::: Existing (Kit 4)


 +o  Fixes the problem in which the cluster alias manager SUITlet falsely
    interprets any cluster alias with virtual={t|f} configured as a virtual
    alias regardless of its actual setting.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 308.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects various problems with CAA commands

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes a problem in which some CAA commands, especially caa_profile, in rare



                                      TruCluster Server Patches 2-15








    scenarios might not function correctly.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 310.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes kernel EVM threads not properly preempting

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes the potential of multiple assert_wait and timeout panics due to
    kernel EVM threads not properly preempting.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 314.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Corrects LSM partition types in CNX partition

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Corrects the LSM partition types in the CNX partition of boot disk for the
    clu_partmgr utility.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 320.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: File names with dollar sign cause upgrade undo probs

 SSSSttttaaaatttteeee:::: Existing (Kit 5)


 +o  Fixes rolling upgrade undo problems with file names that contain a dollar
    sign ($).


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 336.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: aliasd now interprets NIFF parameters correctly

 SSSSttttaaaatttteeee:::: Supersedes Patches 6.00, 7.00, 9.00, 207.00, 208.00, 210.00, 332.00,
 333.00, 334.00


 +o  Fixes a problem in which a cluster member loses connectivity with clients
    on remote subnets.

 +o  Fixes a problem with aliasd not handling multiple virtual aliases in a
    subnet and IP aliases.

 +o  Allows cluster members to route for an alias without joining.

 +o  Fixes a problem with aliasd writing illegal configurations into
    gated.conf.memberX.



 2-16 TruCluster Server Patches








 +o  Fixes a problem with a default route not being restored after network
    connectivity issues.

 +o  Fixes a race condition between aliasd and gated.

 +o  Fixes a problem with a hang caused by an incorrect /etc/hosts entry.

 +o  Fixes aliasd_niff to allow EVM restart.

 +o  Provides enablers for Compaq Database Utility.

 +o  Allows aliasd daemon to include interface aliases when determining whether
    or not an interface is appropriate for use as the ARP address for a cluster
    alias when selecting the proxy ARP master.

 +o  Fixes a problem in which with multiple members booting simultaneously
    aliasd would become deadlocked when trying to select the proxy ARP master
    for cluster aliases.  As a result, some aliases could become unreachable
    because there would be no proxy ARP master.

 +o  Fixes a problem in which the aliasd daemon message "NIFF parameters for
    interface are too lax" was erroneously output due to the conversion of
    internal NIFF parameters from seconds to milliseconds.  The aliasd daemon
    now interprets NIFF parameters correctly.

 +o  Fixes a problem in which a core dump occurs in aliasd when all interfaces
    are removed on a cluster member that is set up with at least one cluster
    alias that is added with virtual=t and without subnet.

 +o  Fixes a problem of disabling and reenabling a cluster alias source route on
    a given interface.

 +o  Fixes a problem of restoring static routes when interface revives.

 +o  Corrects a problem in which liasd terminates the incorrect gated process.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 338.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Enables CAA to startup and failover system services

 SSSSttttaaaatttteeee:::: Supersedes Patches 1.00, 2.00, 3.00, 5.00, 53.00, 54.00, 55.00, 56.00,
 57.00, 58.00, 60.00, 66.00, 71.00, 72.00, 74.00, 84.00, 93.00, 95.00, 242.00,
 301.00, 302.00, 304.00


 +o  Increases parallelism in CAA event handling.

 +o  Fixes a problem with CAA in which after the first resource is started CAA
    cannot start or stop resources, the resource moves to the unknown state,
    and a core file is left behind by the action of starting and stopping
    resources.

 +o  Provides enablers for Compaq Database Utility.



                                      TruCluster Server Patches 2-17








 +o  Corrects a problem in which datastore may get corrupted due to improper
    datastore locking.  This may occur when multiple CAA CLI commands are run
    in the background.

 +o  Corrects a problem in which the caa_profile command may complain of failure
    to create and log EVM events.

 +o  Corrects a problem in which the caa_profile -create command inserts extra
    attributes, such as REBALANCE, into the profile when used to create an
    application profile.  This will cause CAA GUI to fail to validate the
    profile.

 +o  Corrects a problem where the caa_stat command can crash, leaving a core
    file when it receives a SIGPIPE signal.  The problem has been known to
    occur when caa_stat output is piped to a command such as head.

 +o  Fixes a problem that occurs when long resource or attribute names are used
    and the space is not reclaimed correctly when the resource is unregistered.

 +o  Fixes a caad memory leak caused by caa_stat -f.

 +o  Corrects a problem in which CAA fails to close a TDF after processing a
    corresponding resource profile.  Over time this will lead to reaching the
    process limit for open file descriptors and will prevent CAA from
    functioning properly.

 +o  Changes the clu_mibs agent to cause it to retry the connection with the
    Event Manager daemon (evmd) indefinitely until it succeeds.  The clu_mibs
    agent's start and stop control has been moved from /sbin/init.d/clu_max
    script to /sbin/init.d/snmpd script.

 +o  Resolves erroneous behavior of resources with dependencies upon other
    resources (required resources).  This solves several problems with
    starting, stopping, and relocating a resource with dependencies when the
    resource's start or stop scripts fail, or when relocating during a
    shutdown.

 +o  Causes the old datastore to correctly migrate to the new datastore during
    the rolling upgrade and corrects the problem where no resource information
    was preserved.

 +o  Resolves the issue with the default CAA system services (dhcp named
    cluster_lockd autofs) not running after the installation of the patch kit.
    In addition to the default CAA system services, any previously registered
    resource would be lost.

 +o  Prevents member hangs during boot in unusual circumstances that cause the
    CAA daemon to crash or exit during initialization.

 +o  Fixes three CAA problems triggered by heavy CAA activity conditions.

 +o  Fixes a problem in one of the shipped rc scripts whereby Oracle fails
    during start-up on a clustered system.




 2-18 TruCluster Server Patches








 +o  Fixes the problem that causes the App resource to not go off line when last
    dependent network resource goes off line.

 +o  Fixes a problem where CAAD might core dump due to a race condition when
    multiple events to which it subscribes arrive simultaneously.

 +o  Fixes the problem that could cause the target member crashes during service
    start up.

 +o  Enables CAA to start up and fail over system services before any user
    services.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 351.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2265)

 SSSSttttaaaatttteeee:::: Supersedes Patch 48.00, 138.00, 244.00, 306.00


 +o  Provides a warning to users who have installed a patch kit that includes a
    patch that requires a version switch.  See Section 2.1.10

 +o  Addresses a problem seen during the setup stage of a rolling upgrade,
    during tag file creation.  This patch changes a variable to only look at
    500 files at a time, while making tag files instead of the current 700.

 +o  Corrects a potential security vulnerability in the cluster interconnect
    security configuration that may result in a denial of service.

 +o  Provides clu_upgrade enhancements.

 +o  Corrects a problem with adding a cluster member to a one node cluster
    during a rolling upgrade.  The cluster will no longer not let you advance
    in the rolling upgrade process.


 PPPPaaaattttcccchhhh:::: Patch 353.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Allow use of 255 in the Lan Interconnect IP address

 SSSSttttaaaatttteeee:::: Supersedes Patches 41.00, 80.00, 173.00, 175.00, 246.00


 +o  Fixes a cluster installation problem of having an LSM disk and a disk media
    with the same name.  Normally, the installation script would not let you
    install because it was looking at the disk name, not the disk media name.

 +o  Allows disks over 10 GB to be used as member or quorum disks.

 +o  Automates the running of run versw to resolve issues with version switched
    patches and cluster installation.

 +o  Automatically enables IP filtering for the cluster interconnect on cluster



                                      TruCluster Server Patches 2-19








    installation and member addition.

 +o  Allows installation on unlabeled disks.

 +o  Allows the cluster installation to detect layered product kits in /var as
    well as /usr/var.

 +o  Corrects problems with LSM disks and the cluster quorum tools, specifically
    when a member having LSM disks local to it is down, the quorum tools fail
    to update quorum, thereby causing other cluster commands to fail.

 +o  Corrects a problem to allow the use of "255" in the Lan Interconnect IP
    address.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 355.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix rdg: unwiring problem in RDG with local transfers

 SSSSttttaaaatttteeee:::: Supersedes Patches 37.00, 82.00, 132.00, 134.00, 182.00, 183.00,
 185.00, 249.00, 250.00, 252.00


 +o  Closes a timing window that can cause Oracle 9i to hang when a remote node
    in the cluster goes down.

 +o  Fixes a problem in which panics could occur on process termination and in
    situations involving multiple memory channel adapters.

 +o  Makes the rdginit daemon program safe to execute multiple times on all
    cluster interconnect types.

 +o  Resolves a problem resulting in an incorrect error status being returned
    from RdgInit.

 +o  Makes the following changes to Reliable DataGram (RDG):


    -  Changes RDG wiring behavior to match VM's fix to wiring GH chunks.

    -  Fixes an RDG problem that can result in user processes hanging in an
       uninterruptible state.

    -  Resolves an RDG panic in the RdgShutdown routine.

    -  Fixes a problem in which an RDG kernel thread can starve other timeshare
       threads on a uniprocessor cluster member.  In particular, system
       services such as networking threads can be affected.


 +o  Resolves a potential kernel memory fault when another node is powered off.

 +o  Resolves a potential user process hang under extreme stress conditions.




 2-20 TruCluster Server Patches








 +o  Fixes a kernel thread pre-emption problem that can result in panics due to
    the starvation of other kernel threads.

 +o  Fixes some misleading send/receive byte count statistics.

 +o  Fixes multiple problems seen with the TruCluster RDG component.  The
    problems were panics of the following types "rdg: unwiring," "vl_unwire:
    page is not wired," and "KMF: from _otsmove."


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 357.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Security (SSRT2394)

 SSSSttttaaaatttteeee:::: Supersedes Patches 50.00, 200.00, 267.00, 269.00, 316.00


 +o  Fixes a situation where a cluster shutdown under load on a cluster using a
    LAN interconnect takes a very long time.

 +o  Prevents a panic with duplicate incoming connections on boot.

 +o  Provides a complete and better error message in event of a misconfigured
    ICS/TCP adapter.

 +o  Fixes a condition where a node is not allowed to join the cluster after a
    panic.

 +o  Addresses a condition where a node may panic while under load.

 +o  Corrects a potential security vulnerability that may result in denial of
    service.  This potential security vulnerability may be in the form of local
    and remote security domain risks.

 +o  Corrects a problem in which setting the sysconfig inet subsystem values for
    the tcp_keepcnt attribute to a value < 2 cause the member to panic on boot
    with the following panic string:

    NetRAIN configured.
    panic (cpu 0): trap: illegal instruction
    DUMP: Warning: no disk available for dump.


 +o  Provides knowledgeable users with the ability to lower the
    cluster_rebuild_delay.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 359.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Correct lock acquires after mpsleep

 SSSSttttaaaatttteeee:::: Supersedes Patches 68.00, 257.00, 259.00





                                      TruCluster Server Patches 2-21








 +o  Fixes a problem where node reboots during a clusterwide shutdown would
    result in difficult-to-diagnose system panics.

 +o  Fixes Connection Manager problems that could result in panics.

 +o  Fixes a timing problem in the Connection Manager that could cause the
    panics "CNX MGR: COMMIT_TX: INVALID NODE STATE" or "CNX unaligned access."

 +o  Forces a reboot to resolve communications problems in a two node cluster
    rather than hang.

 +o  Corrects lock acquires after mpsleep.

 +o  Corrects the rebuild delay remainder to be minimally second.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 363.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fix for ics_mct: RX CONN 3 panic

 SSSSttttaaaatttteeee:::: Supersedes Patches 44.00, 46.00, 189.00, 190.00, 191.00, 193.00,
 260.00, 261.00, 263.00, 312.00, 360.00, 361.00


 +o  Fixes a situation where ICS is unable to make progress because heartbeat
    checking is blocked or the input thread is stalled.  The symptom is a panic
    of a cluster member with the panic string ICS_UNABLE_TO_MAKE_PROGRESS:
    HEARTBEAT CHECKING BLOCKED/INPUT THREAD STALLED.

 +o  Fixes the problem of a cluster member failing to rejoin the cluster after
    Memory Channel failover.

 +o  Addresses a panic that occurs when higher priority threads running on a
    cluster member block the internode communication service Memory Channel
    transport (ics_ll_mct) subsystem's input thread from execution.

 +o  Fixes numerous panics and hangs with the way a cluster communicates with
    its nodes.

 +o  Fixes a problem with hang and panics during boot.

 +o  Fixes a problem that causes a panic with the string "rcnx_status:
    different node.'"

 +o  Fixes a boot hang of the following string:

    ics_mct: Node arrival waiting for out of line node down cleanup to complete


 +o  Fixes a clusterwide hang during extensive of Memory Channel traffic.

 +o  Addresses an assertion caused by a bad user pointer passed to the kernel
    via sys_call.




 2-22 TruCluster Server Patches








 +o  Addresses a panic that occurs while another member was going down.

 +o  Corrects an ICS (cluster interconnect) handle memory leak.

 +o  Addresses a memory leak in the Memory Channel transport layer.

 +o  Addresses a node hang where a node can become unresponsive as a result of a
    disconnected Memory Channel cable or a Memory Channel hub being powered
    down.

 +o  Addresses an ics_mct: RX CONN 3 panic when a node is joining the cluster.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 366.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes a problem in Memory Channel driver

 SSSSttttaaaatttteeee:::: Supersedes Patches 11.00, 62.00, 97.00, 145.00, 146.00, 148.00, 203.00,
 204.00, 206.00, 273.00, 274.00, 275.00, 277.00, 329.00, 331.00, 364.00


 +o  Fixes a situation in which one or several cluster members would panic if a
    Memory Channel cable was removed or faulty.

 +o  Fixes a problem that causes a clusterwide panic with the Memory Channel
    power off in a LAN interconnect cluster.

 +o  Allows a user to kill a LAN interconnect cluster via Memory Channel.

 +o  Supports Memory Channel usage in a LAN cluster.

 +o  Fixes a problem where the master failover node goes offline during a
    failover and failing over due to parity errors increasing beyond the limit.

 +o  Fixes a problem in which a bad Memory Channel cable causes a cluster member
    to panic with a panic string of "rm_eh_init" or "rm_eh_init_prail."

 +o  Provides changes that should make Memory Channel failovers work better and
    to handle bad optical cables.

 +o  Fixes a problem in which a node booting into a cluster hangs during Memory
    Channel initialization.

 +o  Fixes a kernel memory fault in rm_get_lock_master.

 +o  Fixes a regression for single physical rail Memory Channel configurations.

 +o  Provides a fix to clean up stale data left on an offline physical rail by
    the Memory Channel driver.

 +o  Facilitates kernel debugging.

 +o  Corrects a condition that can cause superfluous "rm_event, index too big"
    messages may appear on a system console.



                                      TruCluster Server Patches 2-23








 +o  Corrects a problem in a memory channel cluster in which rebooting a node
    without performing a hardware reset can crash other members with a
    RM_AUDIT_ACK_BLOCK panic.

 +o  Fixes issues associated with the initialization of the RM driver.

 +o  In a memory channel cluster, rebooting a node without performing a hardware
    reset can crash other members with a RM_AUDIT_ACK_BLOCK panic.

 +o  Fixes several problems in the Memory Channel driver.

 +o  Corrects a problem that occurs in a Memory Channel cluster in which
    rebooting a node without performing a hardware reset can crash other
    members with an RM_AUDIT_ACK_BLOCK panic.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 371.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: NFS server with direct I/O assertion panic

 SSSSttttaaaatttteeee:::: Supersedes Patches 12.00, 13.00, 14.00, 15.00, 16.00, 17.00, 18.00,
 19.00, 20.00, 21.00, 22.00, 23.00, 25.00, 76.00, 92.00, 98.00, 99.00, 100.00,
 101.00, 102.00, 103.00, 104.00, 105.00, 106.00, 107.00, 108.00, 109.00,
 110.00, 111.00, 112.00, 113.00, 114.00, 116.00, 140.00, 142.00, 64.00, 86.00,
 117.00, 119.00, 43.00, 151.00, 152.00, 153.00, 154.00, 155.00, 156.00, 157.00,
 158.00, 159.00, 160.00, 161.00, 162.00, 163.00, 164.00, 165.00, 166.00,
 167.00, 168.00, 169.00, 170.00, 172.00, 30.00, 31.00, 32.00, 33.00, 35.00,
 78.00, 90.00, 122.00, 123.00, 124.00, 125.00, 126.00, 127.00, 129.00, 144.00,
 196.00, 198.00, 202.00, 213.00, 214.00, 215.00, 216.00, 217.00, 218.00,
 219.00, 220.00, 221.00, 222.00, 223.00, 224.00, 225.00, 226.00, 227.00,
 228.00, 229.00, 230.00, 231.00, 232.00, 233.00, 234.00, 235.00, 236.00,
 237.00, 238.00, 240.00, 270.00, 272.00, 278.00, 279.00, 280.00, 281.00,
 282.00, 283.00, 284.00, 285.00, 286.00, 287.00, 288.00, 289.00, 290.00,
 291.00, 292.00, 293.00, 294.00, 295.00, 296.00, 297.00, 298.00, 300.00,
 318.00, 321.00, 322.00, 324.00, 325.00, 326.00, 371.00, 339.00, 340.00,
 341.00, 342.00, 343.00, 344.00, 345.00, 346.00, 347.00, 349.00, 367.00,
 368.00, 369.00


 +o  Makes AdvFS fileset quota enforcement work properly on a cluster.

 +o  Corrects a "cfsdb_assert" panic condition which can occur following the
    failure of a cluster node.

 +o  Corrects a problem that can cause cluster members to hang while waiting for
    the update daemon to flush /var/adm/pacct.

 +o  Prevents a potential hang that can occur on a CFS failover.

 +o  Allows POSIX semaphores/msg queues to operate properly on a CFS client.

 +o  Addresses a potential file corruption problem, which could cause erroneous
    data to the returned when reading a file at a CFS client node.  There is
    also a small possibility that this problem could result in the CFS panic



 2-24 TruCluster Server Patches








    "AssertFailed: bp->b_dev."

 +o  Addressees two potential CFS panic conditions that might occur for a
    DMAPI/HSM managed file system.  The panic strings are:


    -  Assert Failed: ( t)->cntk_mode <= 2

    -  Assert Failed: get_recursion_count(
       current_threa&#38;CMI_TO_REC_LOCK(mi)) == 1


 +o  Corrects a problem in which a possible panic that could occur if multiple
    CFS client nodes leave the cluster while a CFS relocate or unmount is
    occurring.

 +o  Fixes a problem where a possible KMF panic occurs when executing the
    command cfsmgr -a DEVICES on a file system with LSM volumes.

 +o  Corrects a CFS problem that could cause a panic with the panic string of
    "CFS_INFS full".

 +o  Fixes a problem where a possible CFS panic might occur when a file is
    opened in Direct I/O mode at the same time it is being truncated by a
    separate process.

 +o  Provides enablers for the Enterprise Volume Manager product.

 +o  Fixes a memory leak in cfscall_ioctl().

 +o  Provides support for the freezefs utility.

 +o  Fixes a data inconsistency that can occur when a CFS client reads a file
    that was recently written to and whose underlying AdvFS extent map contains
    more than 100 extents.

 +o  Fixes a panic that can occur during the mount of a clusterized file system
    on top of a non-clusterized file system.

 +o  Prevents a kernel memory fault panic during unmount in a cluster or during
    a planned relocation.

 +o  Fixes support for mounting other filesets from the cluster_root domain in a
    cluster.

 +o  Fixes the assertion failure ERROR != ECFS_TRYAGAIN.



 +o  Fixes a race condition during a cluster mount that results in a transient
    ENODEV seen by a name space lookup.

 +o  Fixes a problem in which a panic on boot could occur if a mount request is
    received from another node too early in the boot process.



                                      TruCluster Server Patches 2-25








 +o  Fixes support for mounting other filesets from the cluster_root domain in a
    cluster.

 +o  Fixes the assertion failure ERROR != ECFS_TRYAGAIN.

 +o  Fixes a race condition during a cluster mount that results in a transient
    ENODEV seen by a name space lookup.

 +o  Fixes a problem in which a panic on boot could occur if a mount request is
    received from another node too early in the boot process.

 +o  Fixes a problem in which a PANIC: CFS_ADD_MOUNT() - DATABASE ENTRY PRESENT
    panic could occur when a node rejoins the cluster.

 +o  Fixes a race condition in cluster mount support that results in a transient
    mount failure and a second race that might result in a kernel memory fault
    panic during mount.

 +o  Fixes a cluster problem with hung unmounts (possibly seen as hung node
    shutdowns).

 +o  Fixes a problem in which a UBC panic could occur when accessing CFS file
    systems.

 +o  Prevents a possible Kernel Memory Fault panic on racing mount
    update/unmount/remount operations for the same mount point.

 +o  Fixes a possible race between node shutdown and unmount.

 +o  Prevents a possible Kernel Memory Fault panic on the mount update on a
    Memory File System (MFS) and other possible panics when bad arguments are
    passed to the mount library interface.

 +o  Prevents the panic "Assert failed: vp->v_numoutput > 0" or a system hang
    when a file system becomes full and direct asynchronous I/O via CFS is
    used.  A vnode will exist that has v_numoutput with a greater than 0 value
    and the thread is hung in vflushbuf_aged().

 +o  Prevents a possible Kernel Memory Fault in function ckidtokgs.

 +o  Fixes a potential CFS deadlock condition.

 +o  Corrects the problem of the cfsmgr error "Not enough space" when attempting
    to relocate a file system with a large amount of disks.

 +o  Fixes a problem in which possible CFS client node file read failures could
    occur if the domain storage devices were closed during a previous failure
    to perform a failover mount on the client node,

 +o  Fixes support for mounting other filesets from a cluster node's boot
    partition domain.

 +o  Addresses a cluster problem that can arise in the case where a cluster is
    serving as an NFS server.  The problem can result in stale data being



 2-26 TruCluster Server Patches








    cached at the nodes which are servicing NFS requests.

 +o  Fixes a CFS panic that might occur for a DMAPI/HSM managed file system:

    (panic): cfstok_hold_tok(): held token table overflow


 +o  Fixes a panic "cmn_err: CE_PANIC: ics_unable_to_make_progress:  netisrs
    stalled" in clua.mod due to wait for malloc when memory is exhausted.

 +o  Fixes a panic in clua_cnx_unregister where a TP structure could not be
    allocated for a new TCP connection.

 +o  Fixes problems with cluster alias selection priority when adding a member
    to an alias.

 +o  Fixes a problem when the cluster alias subsystem does not send a reply to a
    client that pings a cluster alias address with a packet size of less than
    28 bytes.



 +o  Addresses a potential clusterwide hang which can occur in the Cluster File
    System.

 +o  Fixes a problem in which file permissions inherited from the default ACL
    may be different than expected under the following conditions:


    -  ACLs are enabled on the system.

    -  There is a default ACL on a directory.

    -  A request is issued from a CFS client to create a file within that
       directory.


 +o  Fixes a problem where cluster file system I/O and AdvFS domain access
    causes processes to hang.

 +o  Prevents an infinite loop during node shutdown when using server_only file
    systems.

 +o  Allows the cfsstat -i command to execute properly.

 +o  Fixes a potential Cluster File System deadlock that can occur during CFS
    failover processing following the failure of a CFS server node.

 +o  Prevents process hangs on clusters mounting NFS file systems and accessing
    files locked by the plock() function on the NFS server.

 +o  Fixes a possible timing window whereby a booting node may panic due to
    memory corruption if another node dies.




                                      TruCluster Server Patches 2-27








 +o  Fixes a small window that can cause a clusterwide panic on node reboot in a
    quorum loss situation.

 +o  Fixes a problem in which a cluster member may panic with the panic string
    "kernel memory fault".

 +o  Fixes a possible boot hang that could occur if the cluster_root domain
    consists of LSM volumes whereby the underlying physical storage is
    nonshared.

 +o  Prevents a memory leak from occurring when using small, unaligned Direct
    I/O access (that is, not aligned on a 512 boundary and does not cross a 512
    byte boundary).

 +o  Prevents the cfsmgr command from displaying an erroneous server name when a
    request is made for statistics for an unmounted file system.

 +o  Fixes support for Synchronized I/O in clusters.

 +o  Eliminates erroneous EIO errors that could occur if a client node becomes a
    server during a rename/unlink/rmdir system call.

 +o  Corrects a CFS problem that could result in degraded performance when
    reading at file offsets past 2 GB.

 +o  Corrects a cluster file locking problem that can arise when file systems
    are exported from the cluster to NFS client nodes.

 +o  Fixes a CFS problem where file access rights may not appear consistent
    clusterwide.

 +o  Fixes a race between cluster mounts and file system lookups.

 +o  Fixes a problem in which file system failover deadlocks.

 +o  Corrects a Cluster File System (CFS) performance issue seen when multiple
    threads/processes simultaneously access the same file on an SMP (more than
    one CPU) system.



 +o  Fixes a memory fault panic from clua_cnx_thread.

 +o  Fixes a problem in which an application that uses file locking may
    experience degraded performance.

 +o  Provides the I/O barrier code that prevents HSG80 controller crashes
    (firmware issue).

 +o  Fixes a situation in which a rebooting cluster member would panic shortly
    after rejoining the cluster if another cluster member was doing remote disk
    I/O to the rebooting member when it was rebooted.

 +o  Allows high density tape drives to use the high density compression setting



 2-28 TruCluster Server Patches








    in a cluster environment.

 +o  Fixes a kernel memory fault panic that can occur within a cluster member
    during failover while using shared served devices.

 +o  Fixes the problem of clusterwide hang because a DRD node failover is stuck
    and unable to bid a new server for served device.

 +o  Adds DRD Barrier reties to work around HSx firmware problems.

 +o  Fixes a problem in which CAA applications using tape/changers as required
    resources will not come ONLINE (as seen by caa_stat).

 +o  Fixes a problem in which the tape changer is only accessible from member
    that is the DRD server for the changer.

 +o  Fixes a problem where an open request to a disk in a cluster fails with an
    illegal errno (>=1024).

 +o  Fixes a problem where an open to a tape drive in a cluster would take six
    minutes (instead of two) to fail if there were no tape in the drive.

 +o  Corrects a problem in which a cluster would hang the next time a node was
    rebooted after a tape device was deleted from the cluster.

 +o  Fixes a domain panic in a cluster when a file system is mounted on a disk
    accessed remotely over the cluster interconnect.

 +o  Fixes the race condition problem when multiple unbarrierable disks fail at
    the same time.

 +o  Fixes a kernel memory fault in drd_open.

 +o  Prevents an infinite loop in drd_open().

 +o  Fixes several Device Request Dispatcher problems.

 +o  Provides the required mechanism to remove a rolling upgrade issue with CD-
    ROM and floppy disk device handling.

 +o  Fixes a problem in which a cluster or a device can get I/O stuck or that a
    cluster node may panic after a device has been deleted.

 +o  Fixes a problem of excessive FIDS_LOCK contention that occurs when large
    number of files are using system-based file locking.

 +o  Causes the immediate updating of the attributes on a directory when files
    are removed by a cluster node that is not the file system server.

 +o  Fixes a hang condition in Device Request Dispatcher (DRD) when accessing a
    failed disk.

 +o  Prevents a "simple_lock: time limit exceeded" panic or an "Assert Failed:
    brp->br_fs_svr_out" panic that can be seen while executing chfsets on a



                                      TruCluster Server Patches 2-29








    cluster.

 +o  Fixes problems in the cluster kernel where a cluster member hangs during
    cluster shutdown or while booting.



 +o  Fixes a problem in the cluster kernel where a cluster member panics when a
    tape device is accessed.

 +o  Fixes a token problem that could cause an unmount to hang.

 +o  Fixes a condition that causes the panic "CNX MGR: Invalid configuration for
    cluster seq disk" during simultaneous booting of cluster nodes.

 +o  Fixes a problem in which two nodes leaving the cluster within a short time
    period would cause I/O on some devices to get stuck.

 +o  Fixes a problem in which a new device would not be properly configured in a
    cluster if the device was discovered during a boot.

 +o  Causes the Device Request Dispatcher (DRD) to retry to get disk attributes
    when EINPROGRESS is returned from the disk driver.

 +o  Fixes an issue with ICS (Internode Communication Services) on a NUMA-based
    system in a cluster.

 +o  Fixes a possible race condition between a SCSI reservation conflict and an
    I/O drain that could result in a hang.

 +o  Adds support for multiple opens to tape libraries/media changers.

 +o  Alleviates a condition in which a cluster member takes an extremely long
    time to boot when using LSM.

 +o  Corrects reference-counting errors that may lead to a panic during cluster
    mount.

 +o  Relieves pressure on the CMS global DLM lock by allowing AutoFS automounts
    to back off.

 +o  Addresses a potential panic in the Cluster File System that can occur when
    using raw Asynchronous I/O.

 +o  Addresses a potential panic in the Cluster File System that can occur when
    using file system quotas.

 +o  Fixes kernel memory faults associated with passing in invalid parameters to
    the mount system call.

 +o  Fixes the problem of a potential hang when multiple nodes are shutting down
    simultaneously and server-only file systems are mounted.

 +o  Fixes the problem of a potential system crash when adding a cluster alias.



 2-30 TruCluster Server Patches








 +o  Improves the responsiveness of EINPROGRESS handling during the issuing of
    I/O barriers.  The fix removes a possible infinite loop scenario which
    could occur due to the deletion of a storage device.

 +o  Allows AutoFS auto-UNmounts to back off, thereby relieving pressure on the
    CMS global DLM lock.

 +o  Adds data validation checking pertaining to cluster messages involving
    tokens, to assist in problem isolation and diagnosis.

 +o  Corrects diagnostic code that might result in a panic during kernel boot.

 +o  Corrects a problem in which a bus reset causes the loss of quorum,
    resulting in a cluster hang.

 +o  Fixes a problem in the cluster kernel where a cluster member panics while
    doing remote I/O over the interconnect.

 +o  Fixes a performance problem where threads could spend a long time in the
    check_busy() AdvFS routine.

 +o  Fixes a panic that may occur during an unmount.

 +o  Fixes a cross-node cluster deadlock that can occur when AdvFS threads on
    two cluster nodes simultaneously call code that requires the taking of
    already held AdvFS locks on the other node.



 +o  Corrects a problem in which mounting on a directory in a clone fileset
    fails with "Device Busy".

 +o  Enhances cluster file system performance when using file locks to
    coordinate file access.

 +o  Prevents a kernel memory fault panic in some cases where AdvFS
    administration commands are performed on a mounted fileset of an
    inaccessible AdvFS domain.

 +o  Fixes a problem in the Device Request Dispatcher.

 +o  Fixes a race condition in the Device Request Dispatcher.

 +o  Fixes a problem that occurs when multiple rsh sessions target the cluster
    alias address, and clua.mod gives out a single port to be used for multiple
    sessions and cause chaos.

 +o  Fixes an internal problem in the kernel's AdvFS, UFS, and NFS file systems
    where extended attributes with names greater than 247 characters could not
    be set on files.  The new limit is 254 plus a null string terminator.

 +o  Fixes a condition that could cause a panic when a node is halting.

 +o  Fixes a race condition in CFS readahead logic and a race condition in CFS



                                      TruCluster Server Patches 2-31








    token logic.

 +o  Improves the fragment gathering mechanism to boost performance.

 +o  Fixes a condition that can cause a panic problem when clua.mod is unloaded.

 +o  Fixes a condition that can cause a boot up panic when ippport_userreserved
    is 1000 or less.

 +o  Fixes a problem where access to the quorum disk can be lost if the quorum
    disk is on a parallel SCSI bus and multiple bus resets are encountered.

 +o  Fixes a regression associated with non-SCSI storage.

 +o  Fixes a timing window during asynchronous reads on a CFS client.

 +o  Fixes a cfsmgr core dump when passing the incorrect number of arguments
    upon force unmounting a served file system.

 +o  Fixes a problem in which a CFS client for a file with a hole preceding a
    frag might drop the frag.

 +o  Eliminates a performance problem when a node acting as CFS server of an NFS
    client file system is write-appending to an external NFS server.

 +o  Fixes a panic that may occur due to a race condition during the mounting of
    a booting node's boot partition.

 +o  Fixes a race between nodes performing failover processing which might lead
    to an incorrect change in the state of file locks.

 +o  Corrects a problem where, under some circumstances, a system may panic with
    a kernel memory fault when a device that is being opened by one program is
    being deleted via the hwmgr utility.

 +o  Fixes a KMF from mc_bcopy or _OtsMove.

 +o  Addresses a potential hang in the NFS server when file systems are being
    relocated in a cluster.

 +o  Helps to close a race where synchronous writes may obtain disk allocations
    that were promised to cached client writes.

 +o  Preserves the error code from an asynchronous write error on a CFS client
    and returns the error from the close system call.

 +o  Fixes a potential data inconsistency caused by a problem in the CFS block
    reservation code which incorrectly calculates the amount of space requested
    and used by direct I/O writes.

 +o  Fixes a potential data inconsistency that may occur when a domain is nearly
    full.  The problem causes client write requests shipped synchronously to
    the server to no longer have subsets of pages written asynchronously due to
    a race with VM.



 2-32 TruCluster Server Patches








 +o  Fixes a reconnect problem that occurs when an interface comes down and up
    again.

 +o  Fixes a panic in clua.mod that is caused by it receiving a delete-cnx
    request from a member and finding that cnx is in an UNREGISTER state.

 +o  Resolves a kernel memory fault in m_copym.

 +o  Fixes a forced unmount of non-failoverable file system (for example, NFS
    and AutoFS) panic in the case that the initiator is down.

 +o  Fixes a problem of a panic that occurs in clua.mod when max_aliasid is
    increased and aliases are added.

 +o  Fixes a rare cluster hang caused by dead locks between the CFS client and
    server during multiple write operations.

 +o  Fixes an unaligned kernel access in the cluster I/O stack.

 +o  Fixes a problem in which clua.mod does not handle TCP RST messages
    appropriately.

 +o  Fixes a condition that causes a long delay of an NFS-connection failover
    when servicing a cluster member that dies.

 +o  Addresses the panic "Assert Failed: (cp->c_flags &#38; CDIRECTIO) == 0" in
    the cluster file system.

 +o  Causes the correct processing in the close() system call.

 +o  Fixes a condition that causes a boot panic.

 +o  Fixes a condition that causes a CFS client panic during a file system read
    operation when the server goes down, resulting in the client becoming the
    server and attempting to release the direction token that had already been
    released.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 373.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: Fixes problems in the DLM subsystem

 SSSSttttaaaatttteeee:::: Supersedes patches 39.00, 131.00, 178.00, 179.00, 181.00


 +o  Fixes a panic in DLM when another node in the cluster is halted.

 +o  Fixes a panic in the DLM deadlock detection code.

 +o  Fixes a problem where a process using the Distributed Lock Manager can take
    up to ten minutes to exit.

 +o  Fixes several DLM related crashes and performance issues.




                                      TruCluster Server Patches 2-33








 +o  Corrects a problem causing a cluster member panic.

 +o  Corrects a problem in which DLM would not always return the resource block
    information for the sublock even if the sublock was held.

 +o  Fixes a Distributed Lock Manager panic when calling the dlm_get_lkinfo()
    routine passing an lkid of a lock block that has already been declared dead
    by the deadlock detection thread.


 NNNNuuuummmmbbbbeeeerrrr:::: Patch 375.00

 AAAAbbbbssssttttrrrraaaacccctttt:::: caa_relocate does not kill the autofsd

 SSSSttttaaaatttteeee:::: New


 +o  Fixes a problem in which caa_relocate AutoFS does not kill the autofsd
    daemon.






































 2-34 TruCluster Server Patches










                                               Revised Reference Pages        A






 This appendix provides changes to reference pages due to patches included in
 this kit.


 _A._1  _e_n_v_c_o_n_f_i_g(_8) _U_p_d_a_t_e

 This section updates the eeeennnnvvvvccccoooonnnnffffiiiigggg(8) reference page.

 envconfig(8)


 NAME

   envconfig - Configures the Environmental Monitoring daemon

 SYNOPSIS

   /usr/sbin/envconfig -c var=value

   /usr/sbin/envconfig start | stop

   /usr/sbin/envconfig -q

 OPTIONS

 Environmental Monitoring provides a means of detecting system threshold
 conditions, that if exceeded, could result in a loss of data or damage to
 the system itself.  To detect and notify users of critical conditions, the
 envmond daemon is used. This utility, envconfig, is used to customize the
 envmond daemon.  This section describes the envconfig options you can use
 to configure the daemon.

  -c var=value
       Sets the variables that specify how the system environment is
       monitored.  These variables are stored in the /etc/rc.config file and are
       read by the envmond daemon at system startup. If a variable is not
       set, the default value of that variable is assumed.

  ENVMON_CONFIGURED
       Specifies the state of Environmental Monitoring.  If this variable
       is set to zero (0), the Environmental Monitoring package is not
       started during the system boot.  If this variable is set to 1, and
       Environmental Monitoring is supported by that platform, it is
       started during the system boot.  The default value is zero (0).

 ENVMON_GRACE_PERIOD











        Specifies the time (in minutes) that can elapse between the detec-
        tion of a high temperature condition and the shutdown of the sys-
        tem.  The default value is 15 minutes.

  ENVMON_HIGH_THRESH
       Specifies the threshold level that can be encountered before the
       envmond daemon broadcasts a warning and suggested action.

  ENVMON_MONITOR_PERIOD
       Specifies the frequency (in seconds) between queries of the system
       by the envmond daemon.  The default value is 60 seconds.

  ENVMON_USER_SCRIPT
       Specifies the path of a user-defined script that you want the
       envmond daemon to execute when a high threshold level is encoun-
       tered.  The envmond daemon continues to check the environment after
       the script has executed and proceeds as needed should the high
       threshold levels persist.

      If you set this variable, the envmond daemon directs output from
      the script to /dev/console.  Output is not displayed on standard
      output or written to a file as this is not the behavior of the dae-
      mon.  To display on standard output, explicitly specify the logger
      command within the user defined script

  ENVMON_SHUTDOWN_SCRIPT
      Specifies the path of a user-defined shutdown script that you want
       the envmond daemon to execute when a shutdown condition is encoun-
       tered.  The envmond daemon will execute this script in place of
       /sbin/shutdown. If you want the system to be shut down and you
       configure a script for ENVMON_SHUTDOWN_SCRIPT you must execute
       /sbin/shutdown from within your script. If you do not specify
       anything for ENVMON_SHUTDOWN_SCRIPT envmond will, by default,
       run /sbin/shutdown when a shutdown condition is encountered.

       If you set this variable, the envmond daemon directs output from
       the script to /dev/console.  Output is not displayed on standard
       output or written to a file as this is not the behavior of the dae-
       mon.  To display on standard output, explicitly specify the logger
       command within the user-defined script.

 start | stop
       Turns the envmond daemon on or off after system startup.

  -q  Displays the values of ENVMON_CONFIGURED, ENVMON_GRACE_PERIOD,
       ENVMON_HIGH_THRESH, ENVMON_MONITOR_PERIOD, ENVMON_USER_SCRIPT,
       and ENVMON_SHUTDOWN_SCRIPT as specified in the /etc/rc.config
       file.  If a specified entry is not found, the environmental
       variable is not displayed.

 DESCRIPTION

   The envconfig utility is used to customize the envmond daemon.  You must
   have root privileges to use this utility. Using this utility, you can:



 A-2 Revised Reference Pages









     +  Specify whether or not Environmental Monitoring is turned on or off at
        system startup.

     +  Specify how much time can elapse between the envmond daemon encounter-
        ing a critical condition and the daemon initiating an orderly shutdown
        of the system.

     +  Specify how frequently the envmond daemon queries the system for
        information.

     +  Start and stop the envmond after Environmental Monitoring has been
        turned on at system startup.

     +  Display the settings of the environment variables as specified in the
        /etc/rc.config file.

 Note that the feature that you want to monitor must be supported on a given
  platform. For example, the AlphaServer 8400/GS140 supports reporting of
  power supply and fan status, the current system temperature, and the max-
  imum allowed system temperature.

 EXAMPLES

   The following procedure describes how you test for and start the environ-
   mental monitoring subsystem

    1.  In multiuser mode, check the status of the environmental monitoring
        subsystem as follows:
             #  /sbin/sysconfig -q envmon
             envmon:
             env_current_temp = 35
             env_high_temp_thresh = 40
             env_fan_status = 0
             env_ps_status = 0
             env_supported = 1

    2.  If the value of env_supported is 0, configure the envmond daemon and
        reboot the system using either of the following methods:

          +  At the command prompt, enter the following command:
                  #  /usr/sbin/envconfig -c ENVMON_CONFIGURED=1

          +  Use the rcmgr command as follows:
                  #  rcmgr set ENVMON_CONFIGURED 1

 This command will enable the envmond daemon and export the variable, creating
 the following two lines in the /etc/rc.config file:

        ENVMON_CONFIGURED="1"
        export ENVMON_CONFIGURED

   You can use the /sbin/sysconfig command to view the system environment at
   any time. The envmond daemon will the print warning messages in the event



                                         Revised Reference Pages A-3








   of a power supply failure, abnormality, or high temperatures. Error logs
   are logged in the /var/adm/binary.errlog.

   In the following example, the system shuts down in 10 minutes if the tem-
   perature does not fall below the critical threshold.

        /usr/sbin/envconfig -c ENVMON_GRACE_PERIOD=10

 FILES

   /etc/rc.config*
       Databases that contains the values of the environment monitoring vari-
       ables. Note that you must use the rcmgr comand to update the rc.config*
       files, particularly on clustered systems.

 SEE ALSO

   Commands: envmond(8)



 _A._2  _s_y_s__c_h_e_c_k(_8) _U_p_d_a_t_e

 This section updates the ssssyyyyssss____cccchhhheeeecccckkkk(8) reference page.

 syscheck (8)

 NAME

   sys_check, runsyscheck - Generates system configuration information and
   analysis

 SYNOPSIS

   /usr/sbin/sys_check [options...]

 OPTIONS

   -all
       Lists all subsystems, including security information and setld inven-
       tory verification.  This option may take a long time to complete.

   -debug
       Outputs debugging information to stderr (standard error output).

   -escalate [ xx ]
       Creates escalation files for reporting problems to your technical sup-
       port representative. This option produces one file,
       TMPDIR/escalate.tar unless there are crash dump files; if so,
       it also creates two other files: TMPDIR/escalate_vmunix.xx.gz
       and TMPDIR/escalate_vmcore.xx.gz. If you use the -escalate
       option, sys_check runs with the -noquick option and collects the output
       in the escalate.tar file. Optionally, you can specify a number (xx)
       with the -escalate option to define a crash number.



 A-4 Revised Reference Pages









       See also the ENVIRONMENT VARIABLES section for information on how you
       can set the value of TMPDIR.

   -evm
       Generates Event Manager (EVM) warnings. When EVM is configured, warn-
       ings are posted as EVM events identified by the string
       sys.unix.sys_check.warning. Six levels of priority ranging from 0-500
       are used, as follows:

         +  0 - Information only.

         +  100 - Note

         +  200 - Tuning Note

         +  300 - Tuning Suggestion

         +  400 - Operational

         +  500 - Warning

   -frame
       Produces frame HTML output, which consists of three files:
       sys_checkfr.html, sys_checktoc.html, and sys_check.html (unless you
       specify a different file name with the -name option).  This option
       cannot be used with the -nohtml option. The following options are
       available for use with the -frame option:

       -name name
           Specifies the name to use for the frame files output.  The default
           name is sys_check.

       -dir name
           Sets the directory for the frames output.  Used only with the
           -frame option.  The default is the current directory (.).

   -help or (-h)
       Outputs help information.

   -nohtml
       Produces text output, consisting of one text file, instead of the
       default HTML output. This option cannot be used with the -frame option.

   -noquick
       Outputs configuration data and the setld scan.  Excludes security
       information.

   -perf
       Outputs only performance data and excludes configuration data. This
       option takes less time to run than others.

   -v  Displays the sys_check version number.




                                         Revised Reference Pages A-5








   -warn
       Executes only the warning pass. This option takes less time to run than
       other options.

   -nowarn
       Executes only the data gathering pass.

 DESCRIPTION

   The sys_check utility is a system census and configuration verification
   tool that is also used to aid in diagnosing system errors and problems. Use
   sys_check to create an HTML report of your system's configuration (software
   and hardware). The size of the HTML output that is produced by the
   sys_check utility is usually between .5 MB and 3 MB.

   The sys_check utility also performs an analysis of operating system parame-
   ters and attributes such as those that tune the performance of the system.
   The report generated by sys_check provides warnings if it detects problems
   with any current settings. Note that while sys_check can generate hundreds
   of useful warnings, it is not a complete and definitive check of the health
   of your system. The sys_check utility should be used in conjunction with
   event management and system monitoring tools to provide a complete overview
   and control of system status. Refer to  EVM(5)  for infor-
   mation on event management. Refer to the System Administration guide for
   information on monitoring your system.

   When used as a component of fault diagnosis, sys_check can reduce system
   down time by as much as 50% by providing fast access to critical system
   data. It is recommended that you run a full check at least once a week to
   maintain the currency of system data. However, note that some options will
   take a long time to run and can have an impact on system performance.  You
   should therefore choose your options carefully and run them during off-peak
   hours. At a minimum, perform at least one full run (all data and warnings)
   as a post-configuration task in order to identify configuration problems
   and establish a configuration baseline. The following table provides guide-
   lines for balancing data needs with performance impact.
   ___________________________________________________________________________
   Option                          Run time                    Performance                 Recommended At
                                                                             impact
   ___________________________________________________________________________
  -warn, -
 perf                   Short.                           Minimal.                      Regular
                                                                                                                   updates, at
                                                                                                                   least weekly
   null -
  no options          Medium, perhaps        Some likely at              Run at least
   selected.                       15 to 45 minutes          peak system use.        once post-
                                         depending on pro-
                                             installation
                                         cessor.                                                              and update
                                                                                                                  after major
                                                                                                                  configuration
                                                                                                                  changes. Update
                                                                                                                  your initial



 A-6 Revised Reference Pages








                                                                                                                  baseline and
                                                                                                                  check warnings
                                                                                                                  regularly.
   -noquick, -
 all,           Long, perhaps 45        Very likely at                Use only when
   -
 escalate.                  minutes on fast,           peak use.                      troubleshooting
                                     large systems to                                                a system prob-
                                     hours on low-
 end                                              lem or escalat-
                                     systems.                                                             ing a problem
                                                                                                                to your techni-
                                                                                                                cal support
                                                                                                                representative.
   ___________________________________________________________________________

   You can run some sys_check options from the SysMan Menu or the
   /usr/sbin/sysman -cli command-line interface. Choose one of the following
   options from the menu:

        >- Support and Services
            | Create escalation report [escalation]
            | Create configuration report [config_report]

   Alternatively, use the config_report and escalation accelerators from the
   command line. Note that the escalation option should only be used in con-
   junction with a technical support request.

   The runsyscheck script will run sys_check as a cron task automatically if
   you do not disable the crontab entry in /var/spool/cron/crontabs/root.
   Check for the presence of an automatically generated log file before you
   create a new log as it may save time.

   When you run the sys_check utility without command options, it gathers con-
   figuration data excluding the setld scan and the security information and
   displays the configuration and performance data by default. It is recom-
   mended that you do this at least once soon after initial system configura-
   tion to create a baseline of system configuration, and to consider perform-
   ing any tuning recommendations.

   On the first run, the sys_check utility creates a directory named
   /var/recovery/sys_check. On subsequent runs, sys_check creates additional
   directories with a sequential numbering scheme:

     +  The previous sys_check directory is renamed to
        /var/recovery/sys_check.0 while the most recent data (that is, from
        the current run) is always maintained  in  /var/recovery/sys_check.

     +  Previous sys_check directories are renamed with an incrementing exten-
        sion; /var/recovery/sys_check.0 becomes /var/recovery/sys_check.1, and
        so on, up to /var/recovery/sys_check.5.

   There is a maximum of seven directories. This feature ensures that you
   always have up to seven sets of data automatically. Note that if you only



                                         Revised Reference Pages A-7








   perform a full run once, you may want to save the contents of that direc-
   tory to a different location.

   Depending on what options you choose, the /var/recovery/sys_check.*
   directories will contain the following data:

     +  Catastrophic recovery data, such as an etc files directory, containing
        copies of important system files. In this directory, you will find
        copies of files such as /etc/group, /etc/passwd, and /etc/fstab.

     +  Formatted stanza files and shell scripts and that you can optionally
        use to implement any configuration and tuning recommendations gen-
        erated by asys_check run. You use the sysconfigdb command or run the
        shell scripts to implement the stanza files. See the sysconfigdb(8)
        reference page for more information.

 NOTES

   You must be root to invoke the sys_check utility from the command line;
   you must be root or have the appropriate privileges through Division of
   Privileges (DoP) to run Create Configuration Report and Create Escalation
   Report from the SysMan Menu. The sys_check utility does not change any sys-
   tem files.

   The sys_check utility is updated regularly. You can obtain the latest ver-
   sion of the sys_check utility from either of two sources:

     +  The most up-to-date version of the sys_check kit is located on the
        sys_check tool web site,
        http://www.tru64unix.compaq.com/sys_check/sys_check.html.

     +  You can also obtain sys_check from the patch kit, see
        http://www.support.compaq.com/patches/.

   You should run only one instance of sys_check at a time. The sys_check
   utility prevents the running of multiple instances of itself, provided that
   the value of the TMPDIR environment variable is /var/tmp, /usr/tmp, /tmp,
   or a common user-defined directory.  This avoids possible collisions when
   an administrator attempts to run sys_check while another administrator is
   already running it. However, no guarantees can be made for the case when
   two administrators set their TMPDIR environment variables to two different
   user-defined directories (this presumes that one administrator does not
   choose /var/tmp, /usr/tmp, or /tmp).

   The sys_check utility does not perform a total system analysis, but it does
   check for the most common system configuration and operational problems on
   production systems.

   Although the sys_check utility gathers firmware and hardware device revi-
   sion information, it does not validate this data.  This must be done by
   qualified support personnel.

   The sys_check utility uses other system tools to gather an analyze data. At
   present, sys_check prefers to use DECevent, and you should install and con-



 A-8 Revised Reference Pages








   figure DECevent for best results.

   If DECevent is not present, the sys_check utility issues a warning message
   as a priority 500 EVM event and attempts to use uerf instead. In future
   releases, Compaq Analyze will also be supported on certain processors.

   Note that there are restrictions on using uerf, DECevent and Compaq Analyze
   that apply to:

     +  The version of UNIX that you are currently using.

     +  The installed version of sys_check.

     +  The type of processor.

 EXIT STATUS

   The following exit values are returned:

   0   Successful completion.

   >0  An error occurred.

 LIMITATIONS

   DECevent or Compaq Analyze may not be able to read the binary error log
   file if old versions of DECevent are being used  or if the binary.errlog
   file is corrupted.  If this problem occurs, install a recent version of
   DECevent and, if corrupted, recreate the binary.errlog file.

   HSZ controller-specific limitations include the following:

   HSZ40 and HSZ50 controllers:
       The sys_check utility uses a free LUN on each target in order to com-
       municate with HSZ40 and HSZ50 controllers. To avoid data gathering
       irregularities, always leave LUN 7 free on each HSZ SCSI target for
       HSZ40 and HSZ50 controllers.

   HSZ70, HSZ80 and G80 controllers:
       The sys_check utility uses a CCL port in order to communicate with
       HSZ70 controllers. If a CCL port is not available, sys_check will use
       an active LUN.  To avoid data gathering irregularities, enable the CCL
       port for each HSZ70 controller.

   The sys_check utility attempts to check the NetWorker backup schedule
   against the /etc/fstab file.  For some older versions of NetWorker, the
   nsradmin command contains a bug that prevents sys_check from correctly
   checking the schedule.  In addition, the sys_check utility will not
   correctly validate the NetWorker backup schedule for TruCluster Server.

 EXAMPLES

    1.  The following command creates escalation files that are used to report
        problems to your technical support organization:



                                         Revised Reference Pages A-9








             # sys_check -escalate

    2.  The following command outputs configuration and performance informa-
        tion, excluding security information and the setld inventory, and pro-
        vides an analysis of common system configuration and operational prob-
        lems:
             # sys_check > file.html

    3.  The following command outputs all information, including configura-
        tion, performance, and security information and a setld inventory of
        the system:
             # sys_check -all > file.html

    4.  The following command outputs only performance information:
             # sys_check -perf > file.html

    5.  The following command provides HTML output with frames, including con-
        figuration and performance information and the setld inventory of the
        system:
             # sys_check -frame -noquick

    6.  The following command starts the SysMan Menu config_report task from
        the command line:
             # /usr/sbin/sysman config_report

        Entering this command invokes the SysMan Menu, which prompts you to
        supply the following optional information:

          +  Save to (HTML) - A location to which the HTML report should be
             saved, which is /var/adm/hostname_date.html by default.

          +  Export to Web (Default) - Export the HTML report to Insight
             Manager. Refer to  the System Administration manual for information on
             Insight Manager.

          +  Advanced options - This option displays another screen in which
             you can choose a limited number of run time options. The options
             are equivalent to certain command-line options listed in the
             OPTIONS section.

             In this screen, you can also specify an alternate temporary
             directory other than the default of /var/tmp.

          +  Log file - The location of the log file, which is
             /var/adm/hostname_date.log by default.

    7.  The following is an example of a stanza file advfs.stanza in
        /var/recovery/sys_check.*:
             advfs:
             AdvfsCacheMaxPercent=8

    8.  The following is an example of a shell script apply.kshin
        /var/recovery/sys_check.*:
             cd /var/cluster/members/member/recovery/sys_check/



 A-10 Revised Reference Pages








             llist="advfs.stanza
             vfs.stanza "
             for stf in $llist; do
             print " $stf "
                     stanza=`print $stf | awk -F . '{print $1 }'`
             print "/sbin/sysconfigdb -m -f $stf $stanza"
                     /sbin/sysconfigdb -m -f $stf $stanza
             done
             print "The system may need to be rebooted for these
             changes to take effect"

 ENVIRONMENT VARIABLES

   The following environment variables affect the execution of the sys_check
   utility. Normally, you only change these variables under the direction of
   your technical support representative, as part of a fault diagnosis pro-
   cedure.

   TMPDIR
       Specifies a default parent directory for the sys_check working sub-
       directory, whose name is randomly created; this working subdirectory is
       removed when sys_check exits. The default value for TMPDIR is /var/tmp.

   LOGLINES
       Specifies the number of lines of log file text that sys_check includes
       in the HTML output.  The default is 500 lines.

   BIGNUMFILE
       Specifies the number of files in a directory, above which a directory
       is considered excessively large.  The default is 15 files.

   BIGFILE
       Specifies the file size, above which a file is considered excessively
       large. The default is 3072 KB.

   VARSIZE
       Specifies the minimum amount of free space that sys_check requires in
       the TMPDIR directory.  The default is 15 MB and should not be reduced.
       The sys_check utility will not run if there is insufficient disk space.

   RECOVERY_DIR
       Specifies the location for the sys_check recovery data.  The default is
       /var/recovery.  The sys_check utility automatically cleans up data from
       previous command runs.  The typical size of the output generated by
       each sys_check utility run is 400 KB.  This data may be useful in
       recovering from a catastrophic system failure.

   ADHOC_DIR
       Specifies the location at which sys_check expects to find the text
       files to include in the HTML output.  The default is the /var/adhoc
       directory.

   TOOLS_DIR
       Specifies the location at which sys_check expects to find the binaries



                                        Revised Reference Pages A-11








       for the tools that it calls.  The default is /usr/lbin.

 FILES

   /usr/sbin/sys_check
       Specifies the command path.

            Note

          This file may be a symbolic link.

   /usr/lbin/*
       Various utilities in this directory are used by sys_check.

            Note

          These files may be symbolic links.

   The sys_check utility reads many system files.

 SEE ALSO

   Commands: dop(8), sysconfigdb(8), sysman_cli(8), sysman_menu(8)

   Miscellaneous: EVM(5), insight_manager(5)

   Books: System Administration, System Tuning



 _A._3  _s_y_s__a_t_t_r_s__n_e_t_r_a_i_n(_5), _n_i_f_f_t_m_t(_7), _a_n_d _n_i_f_f_c_o_n_f_i_g(_8) _U_p_d_a_t_e_s

 The installation of Patch 2084.00 results in changes to the
 ssssyyyyssss____aaaattttttttrrrrssss____nnnneeeettttrrrraaaaiiiinnnn(5), nnnniiiiffffffffttttmmmmtttt(7), nnnniiiiffffffffccccoooonnnnffffiiiigggg(8), and iiiiffffccccoooonnnnffffiiiigggg(8)reference
 pages.  Patch 1370.00 updates iiiiffffccccoooonnnnffffiiiigggg(8); the following sections describe
 changes to the other reference pages.


 _A._3._1  _s_y_s__a_t_t_r_s__n_e_t_r_a_i_n(_5)

 nr_timeout_dead_interface

         The time interval or frequency between successive polls of a dead
         interface by the NetRAIN interface recovery thread.

         Minimum value: 0.5 (seconds)

   nr_timeout_o

         Minimum value: 1.1

   nr_timeout_t

         Minimum value: 0.5



 A-12 Revised Reference Pages









   You can specify decimal values (for example, 2.5 or 0.8) for
   nr_timeout_dead_interface, nr_timeout_o, and nr_timeout_t.  When you recon-
   figure any of these values by using the sysconfig -r command, they are all
   validated together.  If any value fails validation, all previous (valid)
   values are restored and EINVAL is returned. Each value must be greater than
   or equal to its minimum value.

   The nr_timeout_o and nr_timeout_t values are validated in conjunction with
   a third timer value (dt), calculated as (nr_timeout_t - nr_timeout_o) / 3.
   These 3 timer values are validated as described in nifftmt(7).

 SEE ALSO

   sys_attrs(5), nifftmt(7)

   Network Administration: Connections



 _A._3._2  _n_i_f_f_t_m_t(_7)

 The time_to_dead field (shown in the EXAMPLES section and in
             niffconfig -v) is the  amount of time that expires between the
             red alert being raised and the interface being declared dead. It
             is calculated by the traffic monitor thread as t2 - t1 - (2 *
             dt).

   You can specify the values for t1, dt, and t2 in seconds (if the
   MIF_MILLISECONDS bit is clear in the flags field), or in milliseconds (if
   the MIF_MILLISECONDS bit is set). See the EXAMPLES section to see how this
   is used.

   The traffic monitor thread enforces the following restriction between the
   timing parameters:

        t2 >= t1 + 2dt

        t1 >= 0.5
        t2 >= 1.1
        dt >= 0.2

   In the preceding restrictions, the values for t1, dt, and t2 are in
   seconds.

        #include
        #include
        #include
        #include
        #include
        #include
        #include
        #include




                                        Revised Reference Pages A-13








        /* these strings map to the "state" enum */
        char *state[] = {"INIT", "GREEN", "YELLOW", "ORANGE", "RED", "DEAD"};

        /* usage: niff_example tu0 tu1 tu2...
         * must supply the name of at least one
         * network interface
         */
        main(int ac, char **av)
        {
          int t1 = 20, t2 = 60, dt = 5;
          char **oldav;
          mif_t mif;
          int s;

          oldav = ++av;
          s = socket(AF_INET, SOCK_DGRAM, 0);

          /* tell the traffic monitor to start watching these interfaces */
          while (*av) {
            printf("Adding interface %s to the traffic monitor\n", *av);
            bzero(&#38;mif, sizeof (mif));
            bcopy(*av, &#38;mif.name[0], MIN(strlen(*av)+1, sizeof(mif.name)-
 1));
            mif.t1 = t1;
            mif.t2 = t2;
            mif.dt = dt;
            mif.flags = 0;
            if (ioctl(s, SIOCTMTADD, &#38;mif) < 0) {
                perror("couldn't add interface");
                break;
            }
            ++av;
          }
          av = oldav;

          /* get the status of the interfaces - NB will probably always
           * be in the "init" state
           */
          while (*av) {
            printf("checking the status of interface %s\n", *av);
            bzero(&#38;mif, sizeof (mif));
            bcopy(*av, &#38;mif.name[0], MIN(strlen(*av)+1, sizeof(mif.name)-
 1));
            if (ioctl(s, SIOCTMTSTATUS, &#38;mif) < 0) {
                perror("couldn't get status for interface");
                break;
            } else {
                printf("Interface: %05s, state: %s ", mif.name,
                                state[miff.current_state]);
                if (mif.flags &#38; MIF_MILLISECONDS)
                   printf("Timer values in milliseconds...\n");
                else
                   printf("Timer values in seconds...\n");
                printf("t1: %d, dt: %d, t2: %d, time to dead: %d,



 A-14 Revised Reference Pages








                  current_interval:%d, next time: %d\n",
                  mif.t1, mif.dt, mif.t2, mif.time_to_dead, mif.current_interval,
                  mif.next_time);
            }
            ++av;
          }
          av = oldav;

          /* tell the traffic monitor to stop watching */
          while (*av) {
            printf("deleting interface %s from the traffic monitor0, *av);
            bzero(&#38;mif, sizeof (mif));
            bcopy(*av, &#38;mif.name[0], MIN(strlen(*av)+1, sizeof(mif.name)-
 1));
            if (ioctl(s, SIOCTMTREMOVE, &#38;mif) < 0) {
                perror("couldn't remove interface");
            }
            ++av;
          }
          exit(0);
        }



 _A._3._3  _n_i_f_f_c_o_n_f_i_g(_8)

 SYNOPSIS

   /usr/sbin/niffconfig [-a] [-m] [-r] [-s] [-u] [-v] [-d dt] [-o t2] [-t t1]
   [interface1 interface2...]

   -d dt
       Specifies the time period, in seconds, that the traffic monitor thread
       uses between reads of the interface counters when it suspects there is
       a connectivity problem. This number must be smaller than the number
       given for t1 (see the -t option). The default time period is 5 seconds.
       If dt is not specified, niffconfig uses the default.

   -o t2
       Specifies the total number of traffic-free seconds that must elapse
       before the traffic monitor thread determines that a network interface
       has failed.  This number must be at least the sum of the t1 and two
       times dt.  That is, given the default time period for dt (5 seconds)
       and t1 (20 seconds), the t2 value must be at least 30 seconds.  The
       default time period for t2 is 60 seconds. If t2 is not specified,
       niffconfig uses the default.

   -m  Modifies the timing parameters of an interface that is already being
       monitored. Typically, this option is specified along with one or more
       of -t t1, -d dt, or -o t2 options.  If none of these parameters are
       specified, the default value is used. You cannot specify the -m option
       with the -a, -s, -r, -u, or -v options.

   -t t1



                                        Revised Reference Pages A-15








       Specifies the time period, in seconds, that the traffic monitor thread
       delays between reads of the interface counters when the network is run-
       ning normally.  The default time period is 20 seconds. If t1 is not
       specified, niffconfig uses the default.

   -v  Displays the status, timer values, and description (verbose mode) of
       all interfaces currently being monitored to standard out (stdout). See
       nifftmt(7) for a definition of each of the parameters.

   Except for the -u and -v options, all niffconfig options require one or
   more network interfaces to be specified.

   You can specify the t1, dt, and t2 timer values as decimal values (for
   example, 2.6 or 0.8).  When setting timer values with the -a or -m options,
   all three  timer values (t1, dt, and t2) are validated as described in
   nifftmt(7). If the validation fails, the operation is cancelled and a mes-
   sage is printed t o stdout.

   NetRAIN initiates its own internal interface monitoring (using NIFF) when a
   NetRAIN set is created. NetRAIN monitored interfaces are visible only with
   the -v option. You cannot use niffconfig to perform any other management
   operations on the NetRAIN interfaces. To modify the timer values for
   NetRAIN monitored interfaces, use the ifconfig command.

   You can start additional monitoring of an interface that is already being
   monitored internally for NetRAIN. In that case, the niffconfig -v command
   will display the two different monitoring structures for the interface.
   All other niffconfig options will operate only on the non-NetRAIN monitor-
   ing structure.

 EXAMPLES
    5.  To display all parameters for all interfaces that are being monitored,
        including NetRAIN interface monitoring, enter:
             # niffconfig -v




 _A._4  _w_o_l(_8) _U_p_d_a_t_e

 The installation of Patch 2084.00 changes the information in the wwwwoooollll(8)
 reference page.

    wol(8)


 NAME

   wol - Send network packet to power on target system (wake-on-LAN)

 SYNOPSIS

   /usr/sbin/wol [nw_interface] hw_address




 A-16 Revised Reference Pages








 OPTIONS

   nw_interface
       Specifies the network interface to use in making the connection to the
       target system, for example: tu1. This argument is optional.

 OPERANDS

   hw_address
       Specifies the hardware network address of the target system, for exam-
       ple: 00-02-56-00-03-29. This argument is mandatory.

 DESCRIPTION

   The wol utility generates and transmits a network packet to power on a
   remote system. Before you can use the wol utility, you must enable the
   remote system management wake-on-LAN feature on the target system.

   You must specify the target system's hardware address. You may optionally
   specify the network interface to use in making the connection to the target
   system. If no network interface is specified, the wol utility locates the
   first configured network interface and prompts you for confirmation.

   To enable the wake-on-LAN feature, set the target system's wol_enable con-
   sole variable to on and reset the system so that the network controller can
   read the new state. Use one of the following methods to enable this feature
   on the target system:

     +  From the target system's console prompt. enter the following commands:
      >>> set wol_enable on
      >>> init

     +  From the target system's UNIX root prompt, enter the following com-
        mands:
      % consvar -s wol_enable on
      set wol_enable = on
      % consvar -a
      Console environment variables saved
      % reboot

   Use one of the following methods to disable the wake-on-LAN feature:

     +  From the target system's console prompt. enter the following commands:
      >>> set wol_enable off
      >>> init

     +  From the target system's UNIX root prompt, enter the following commands:
             % consvar -s wol_enable off
      set wol_enable = on
      % consvar -a
      Console environment variables saved
      % reboot

  Note



                                        Revised Reference Pages A-17








        You must reset the target system for the new setting to take effect.

 RESTRICTIONS

   You must be logged in as root or have superuser privileges to use the wol
   utility.

   The wake-on-LAN feature is only available on specific platforms. On plat-
   forms that support this feature, additional restrictions may apply. For
   example, the wake-on-LAN feature may be supported on specific network
   interface ports only. See your hardware documentation for additional infor-
   mation.

 EXIT STATUS

   0 (Zero)
       Success.

   >0  An error occurred.

 ERRORS

     +  Error detecting default interface

        Explanation:

        The wol utility cannot automatically detect a default network inter-
        face.

        User Action:

   -- Verify that a configured network interface exists on your system.

   -- Manually specify a configured network interface on the wol com-
      mand line.

     +  Patterns must be specified as hex digits The Magic Packet address must
        be specified as 00-11-22-33-44-55

        Explanation:

        The hardware network address entered was in the wrong format. This
        argument must be in the following format: xx-xx-xx-xx-xx-xx, where x
        is a hexadecimal character (0 through 9 and A through F, inclusive).

        User Action:

        Specify the hardware network address correctly.


 EXAMPLES

    1.  The following example shows a simple use of the wol utility, where the
        host system detects the first configured network interface and prompts



 A-18 Revised Reference Pages








        for confirmation:
      # /usr/sbin/wol 00-02-56-00-03-29
      No sending device specified, using tu0, continue? (y/n) y

    2.  The following example shows the same use of the wol utility, where the
        user declines confirmation of the selected network interface:
      # /usr/sbin/wol 00-02-56-00-03-29
      No sending device specified, using tu0, continue? (y/n) n
      Aborting...

    3.  The following example explicitly specifies a network interface:

      # /usr/sbin/wol tu1 00-02-56-00-03-29

 ENVIRONMENT VARIABLES

   wol_enable
       Enables or disables the wake-on-LAN feature on the target system. Valid
       values are on and off.

        Note

   This is a system console variable, not a UNIX environment variable.
   The DESCRIPTION section tells you how to enable the wake-on-LAN
   feature on the target system. You must enable this feature before
   you use the wol utility.

 FILES

   /usr/sbin/wol
       Wake-on-LAN utility.

 SEE ALSO

   Commands: consvar(8), halt(8), reboot(8), shutdown(8)

   New Hardware Delivery Release Notes and Installation Instructions

   System Administration


















                                        Revised Reference Pages A-19



