Feed openbsd-journal OpenBSD Journal

Favorite IconOpenBSD Journal

Link http://undeadly.org/
Feed http://undeadly.org/cgi?action=rss
Updated 2026-02-02 16:17
New VPN FAQ
Landry Breuil (landry@) hascommittedawork-in-progressFAQ section"Virtual Private Networks (VPN)":
Improvements to X86FixupGadgets pass of clang(1)
Todd Mortimer (mortimer@) hascommittedimprovements to (the anti-ROP)"X86FixupGadgets" passofclang(1)for amd64 and i386:
Faster vlan(4) forwarding? - blog post by mpi@
Hrvoje Popovski wrote in to alert us that Martin Pieuchot (mpi@) has written a new blog post entitled Faster vlan(4) forwarding?, which leads in with
openrsync imported into the tree
openrsync,a clean-room implementation ofrsync,is being developed byKristaps Dzonsonsas part ofthe rpki-client(1) project[featured in anearlier article].openrsync(1) has beenimported into the tree(as "rsync") by Sebastian Benoit (benno@):
Florian Obser on unwind(8)
Florian Obser (florian@) kindly wrote in with news on some recent work:
Security Vulnerability Mitigations
Fresh from thea2k19 hackathon,Joel Sing (jsing@) delivereda presentationat the2019 linux.conf.au.Video is now available.
Support for 2TB of memory added
Mike Larkin (mlarkin@) just committed support for 2TB of physical memory on the amd64 platform:
join-ing any open wifi network is now possible
Peter Hessler (phessler@) hascommittedchangesto make it possible to join any open wifi network:Read more…
vmm(4) for i386 deleted from -current
Withtwocommitsby Pratik Vyas (pd@),vmm(4) support for i386 host systems has been deleted (one can still run i386 guests under vmm on an amd64 host).The commit messages explain the reasoning behind this move:Read more…
OpenBSD on the Acer Aspire One, At Ten
Ian Darwin (ian@) wrote in to let us know that he's writtenan articlewhich is a follow-up to an Undeadlystory from a decade ago!The article provides a fine illustration of benefits of a bloat-freeOS.Thanks very much for the pointer, Ian.
New console font Spleen made default
Frederic Cambus (fcambus@) has just changed the default console font to Spleen, a font of his own creation:
Real paragraphs for mandoc HTML output
Another major step forward just happened inmandoc(1)HTML output: paragraphs are now represented with real HTML<p> elements, and a number of cases were fixedin which mandoc used to generate output violating HTML syntax,mostly related to macros and requests that controlline fillingin paragraphs of text.Read more…
Ingo Schwarze -mandoc Better documentation – on the web and for LibreSSL video is now published
Tom Smyth has another article (and video) for us:
Video of Todd Mortimer Removing ROP gadgets from OpenBSD
This contribution comes directly from Tom Smyth:
OpenBSD 6.2 song: A 3 line diff
With the followingcommit,Theo de Raadt (deraadt@) released thesong for OpenBSD 6.2!
DNSSEC enabled in default unbound(8) configuration
With thiscommit,Florian Obser (florian@) enabled DNSSEC validation in the defaultunbound.conf(5)in -current:
OpenSMTPD proc filters & fc-rDNS
Gilles Chehade (gilles@) has written anotherpieceon progress inOpenSMTPDdevelopment.-current now has proc filters!
Otto Moerbeek on the Virtues of OpenBSD malloc(3)
Otto Moerbeek (otto@) has issued aseries of Mastodon messagesexplaining some of the the virtues of OpenBSD'smalloc(3)implementation.They provide excellent reading in easily-digestible pieces.
A proposal for a new RPKI validator: OpenBSD rpki-client(1)
Job Snijders (job@) has written anarticle at Mediumproposing rpki-client(1),a new, BSD-licensedRPKIvalidator.
OpenBGPD - Adding Diversity to the Route Server Landscape
Claudio Jeker (claudio@) wrote in to let us know that he and Job Snijders (job@) have writtenan article about OpenBGPDforRIPE Labs.
OpenBSD Community reaches Iridium in 2018!
Right on the heels of the previous announcement, Kenneth R. Westerback (krw@) of the OpenBSD Foundation writes to inform us:
Blog post by jcs@ on reverse engineering audio drivers
On his blog, joshua stein (jcs@) has a description of the hoops he jumped through to get stereo sound out of his Huawei Matebook X under OpenBSD (something that only worked under Windows with special drivers).His approach involves logging all PCI device accesses by running Windows in QEMU under Linux with VFIO, parsing that, and making the OpenBSD azalia(4) driver do the same.Thanks to joshua for the interesting write-up!
Microsoft goes Gold for 2018!
Kenneth R. Westerback (krw@) writes to inform us:
malloc.conf replaced with a sysctl
In this commit, Otto Moerbeek (otto@) moved malloc handling from a softlink in /etc to a sysctl instead.
OpenSMTPD released and upcoming filters preview
Gilles Chehade (gilles@) has writtenan articleon recent progress inOpenSMTPD.It begins:
Introducing the OpenBSD Virtualization FAQ
Returning readers are likely aware that OpenBSD in its OpenBSD/amd64 and OpenBSD/i386 varieties comes with virtualization built in, brought to you by the vmm(4) subsystem.
The OpenBSD Foundation receives the first Silver contribution from a single individual
Earlier this week the OpenBSD foundation received its first Silver donation from an individual contributor. Thank you John Carmack for the very generous contribution! The support will ensure that many important projects are moving forward and continue making impact.
OpenBSD Foundation gets a second Iridium donation from Handshake!
Ken Westerback (krw@ when wearing his dev hat) wrote in with some great news:
OpenBSD 6.4 Released
The release of OpenBSD 6.4 has beenannounced:
New mandoc feature: -T html -O toc
Ingo Schwarze (schwarze@) writes in about fresh developments in mandoc(1):
EuroBSDcon 2018 slides available
EuroBSDcon 2018is now over, and slides for OpenBSD-related presentations are now availablefrom theusual place.As always, there's some great reading there (especially for those of uswho were unable to attend the conference).Unfortunately, there will not be any video this year.
n2k18 Hackathon report: Ken Westerback (krw@) on disklabel(8) work, dhclient(8) progress
Fresh from the just concluded n2k18 hackathon comes this report from Ken Westerback(krw@),who writes:
vmm(4) gets support for qcow2
In ashortseriesofcommits,Carlos Cardenas (ccardenas@) added support forqcow2image support to vmd(8).[This builds on anearlier commitadding support for pluggable disk backends.]The code was written by Ori Bernstein, who posted his diffs (thread 1, thread 2) to the tech@openbsd.org mailing list in August.Read more…
Fuzzing the OpenBSD Kernel
Anton Lindqvist (anton@) gave a talk atBSD Users Stockholm Meetup #3 on the kernel coverage tracing kit he committed recently.Slidesare now available via theOpenBSD Events and Papers page.The slides contain a list of bugs found and fixed as a result of this work.See also:kcov(4)
OpenBSD Foundation gets first 2018 Iridium donation!
Ken Westerback (krw@ when wearing his dev hat) wrote in withsome great news:
Disable SMT/Hyperthreading in all Intel BIOSes
In amessage to tech@,Theo de Raadt (deraadt@)gives an update on the state-of-play regarding processor vulnerabilities:
Fix for L1TF issue in Intel CPUs committed
Theo de Raadt (deraadt@) hascommitteda diff to mitigate the"Intel L1TF screwup" for the amd64 platform we reported on earlier:
Theo on the latest Intel issues
Theo de Raadt (deraadt@)posted to the tech@ mailing list with some background on how the latest discovered Intel CPUissues relate to OpenBSD.
Video of Interactive OpenBSD Porting Workshop
[Dr.] Brian Callahan (bcallah@) recently live-streamed(at twitch.tv/NewAstroCity)an interactive OpenBSD Porting Workshop.A recording of the workshop isnow available.
arm64 gains RETGUARD
In aseriesofcommits,Todd Mortimer (mortimer@) has added RETGUARDfor the arm64 platform.We previously reported theaddition of RETGUARD for amd64.Read more…
Happy Bob's Libtls tutorial
Bob Beck (beck@ when wearing OpenBSD-only hat)has writtena tutorialon using libtls:
mandoc-1.14.4 released
Ingo Schwarze (schwarze@ when wearing OpenBSD-only hat)wrote in to let us know about the new release:
X11 on really small devices
Patrick Wildt (patrick@) has been experimenting with small I2C and SPI-connected displays, and withthis commit, it was enabled for armv7 and arm64 platforms as ssdfb(4) in -current.Read more…
g2k18 hackathon report: Ingo Schwarze on sed(1) bugfixing with Martijn van Duren, and about other small userland stuff
For the g2k18 Ljubljana hackathon, i decided to try and get ridof as many small userland tasks as possible.Lots of them have been piling up over time.Read more…
Theo de Raadt on "unveil(2) usage in base"
In amessageto tech@, Theo de Raadt (deraadt@) discusses the state of development ofunveil(2)support in userland (and for a certain port):Read more…
g2k18 hackathon report: Kenneth Westerback on dhcpd(8) fixes, disklabel(8) refactoring and more
A new g2k18 hackathon report has arrived, this time from Kenneth Westerback (krw@), who writes:
More mitigations against speculative execution vulnerabilities
Philip Guenther (guenther@)and Bryan Steele (brynet@)have added more mitigations against speculative executionCPU vulnerabilitieson the amd64 platform.Read more…
rtadvd(8) has been replaced by rad(8)
rad(8) [as described in the g2k18 hackathonreport byFlorian Obser (florian@)]is now the only IPv6router advertisement daemon in -current, following the removal ofrtadvd(8).Advice on making the transition has beenadded to current.html
g2k18 hackathon report: Claudio Jeker on OpenBGPD developments
Claudio Jeker (claudio@) is next up with his report from Ljubljana:
g2k18 hackathon report: Carlos Cardenas on vmm/vmd progress, LACP
Another g2k18 hackathon report has arrived, this one fromCarlos Cardenas (ccardenas@), who writes:
...891011121314151617...