Skip to content
Xi Software Request an evaluation

Xi-Batch 1.9.1 and Xi-Text 1.25.4: nine hardening changes

A deliberate campaign across every command and service - privilege changes that fail closed, bounded copies, and checks on everything arriving over the wire.

Both products were released on 20 July carrying a hardening campaign of nine changes, run as a piece of work in its own right rather than as fixes to individual reports.

The two that change behaviour most are worth naming. Privilege handling now fails closed: if a command or service cannot switch to the identity it is meant to run as, it stops rather than continuing under the wrong one. And everything arriving over the network - job submissions, inter-server messages, the terminal-server and print protocols - is bounds-checked before it is unpacked.

Alongside those: bounded copies throughout, a corrected fault handler, and leap-year and buffer fixes found in the same pass.

Why run it as a campaign

Hardening done one report at a time fixes the places someone happened to look. Taken as a campaign, the same question gets asked of every command and service at once - what does this do with input it did not expect, and what happens if a privilege change fails - and the answer is made consistent across the products.

Correctly configured systems see no change in normal operation. The work is visible only where something was already wrong.

Release notes · Security