Feed openbsd-journal OpenBSD Journal

Favorite IconOpenBSD Journal

Link http://undeadly.org/
Feed http://undeadly.org/cgi?action=rss
Updated 2024-05-16 00:32
Quantitative analysis of issues found by afl in mandoc
Ingo Schwarze (schwarze@) writes in with an analysis of the issues found by afl in mandoc:After realizing that I have nine topics for my BSDCan talk and that I can't cover them all in the depth they deserve, here are a few more details about afl and mandoc than I can't cover in the talk. Not a spoiler, there is still plenty of material for the talk!Read more...
BSDNow Episode 094: Builder's Insurance
On this week'sepisodeofBSDNow,Marc Espie (espie@) talks about dpb, OpenBSD's distributed package builder,which runs the binary package builds in Theo'sbasement.He talks about why it came about, the security measures built in, and the minimalistic and works-out-of-the-box configuration, among other things.The hosts also talk about their experiences at the recent BSDCan, and,ss usual, they have the roundup of the news, big and small, in the world of allthings BSD.[Video|HD Video|MP3 Audio|OGG Audio|Torrent]
Call for Testing: audio(4)
Alexandre Ratchov (ratchov@)posteda call for testing of a newaudio(4)driver:
LibreSSL 2.1.7 and 2.2.0 Released
Brent Cook (bcook@) hasannouncedthe latest LibreSSL releases, which contain fixes for several CVEs:
Microsoft Announces Support for SSH
Windows admins rejoice! Microsoft's PowerShell Teamannouncedfuture support for SSH, specificallyOpenSSH:
Heads Up: spamd(8) PF Rule Change
With a recentcommit,Reyk Flöter (reyk@) flipped the switch onspamd(8)'spf interfacement:
OpenBSD 5.7 CD 2 Incorrectly Pressed
OpenBSD project leader Theo de Raadt (deraadt@) outlined some issues with the CD plant, which led to an incorrectly-finished CD 2, some of which were, unfortunately, shipped prior to the issue being found.
BSDNow Episode 089: Exclusive Disjunction
On this week'sepisodeof BSDNow, the hosts interview Mike Larkin (mlarkin@) abouthow he got started in OpenBSD, hisrecentand upcoming work on W^X,and how that fits into the OpenBSD exploit mitigation ecosystem.As always, they also have all the news and reviews in the world of all things BSD.[Video | HD Video|MP3 Audio|OGG Audio|Torrent| YouTube]
OpenBSD 5.7 Shipping, First Pre-orders Arriving
After a delay due to unfortunate production problems (the first such delay in 20 years), the OpenBSD Store announced that all pre-orders had been shipped.And it seemed like only moments later that Raf Czlonka was the first to report on the misc@ mailing list that his pre-ordered OpenBSD 5.7 CD set had arrived.Even if you hadn't preordered, you still have a chance to order your CD set and other swag by visting the OpenBSD Store. If you want to support the project financially in other ways, the Donations page is, as always, a good place to start.
New disklabel(8) templates make for a more flexible autoinstall
In a this commit, a first in a series, Henning Brauer (henning@) made disk allocations during automatic installs much more flexible via the introduction of diskablel templates. The matching installer bits came along via this commit by Robert Peichaer (rpe@).Quoting the updated disklabel(8) man page,
OpenBSD 5.7 Released
May 1st, 2015, Calgary, AB, CA and elsewhere:OpenBSD 5.7 has been released. The brand new 5.7 subdirectory should now be available and filled up on all relevant mirrors for those of you who have yet to receive your CD orders.The release announcement, posted on project mailing lists earlier today, and the release home page both mention some highlights of the new release, while the complete changelog for the release is available on the OpenBSD website.While you are too late to be the first to preorder a shiny OpenBSD release CD set, you can order one of your own, as well as a very cool 5.7-release poster.
OpenBSD has accepted projects from Google Summer of Code 2015
The OpenBSD page for Google Summer of Code 2015 has been updated with the list of accepted projects for this year.
CfP extended for EuroBSDCon 2015
Due to overwhelming response, the deadline for submitting talks to EuroBSDCon has beenextended:
BSDNow Episode 085: PIE in the Sky
A bit late out of the gate, Undeadly readers are likely interested in thelatest episodeofBSDNow,featuring news of Solaris working to include OpenBSD's pf as an option on upcoming releases,the Bay Area BSD User Group keeping a stream of videos from their meetings going,some long-form blogging about the OpenBSD ports system,a discussion about keeping your home firewalls up to date,LLVM growing a fuzzing library, and most especially aninterview with Pascal Stumpf (pascal@), with an overview of the whys and hows of address space layout randomization (ASLR) and the work extending position-independent executable (PIE) to statically-linked binaries.[Video|HD Video|MP3 Audio|OGG Audio|Torrent]
p2k15 Hackathon Report: schwarze@ on USE_GROFF
Ingo Schwarze (schwarze@) writes in with our fourth report from the p2k15 ports hackathon:
Solaris Admins: For A Glimpse Of Your Networking Future, Install OpenBSD
Undeadly's very own Peter Hansteen haswritten upsome PF-on-Solaris-relatedemail chatter:
p2k15 Hackathon Report: stsp@ on wifi and games
Stefan Sperling (stsp@) writes in with our third report from the p2k15 ports hackathon:
p2k15 Hackathon Report: krw@ on GPT support
Ken Westerback (krw@) writes in with our second report from the p2k15 ports hackathon:
softraid(4) - RAID 5 Call for Testing
Joel Sing (jsing@) has put out acall for testingfor RAID 5 onsoftraid(4):
p2k15 Hackathon Report: landry@ on mozilla and more
Landry Breuil (landry@) writes in with our first report from the p2k15 ports hackathon:
OpenNTPD 5.7p4 released
The OpenNTPD team has announced the availability of OpenNTPD 5.7p4, which adds
SSH Protocol 1 Now Disabled at Compile Time
As Damien Miller (djm@)announcedon tech@, support for SSH version 1 is now no longer being included in OpenBSD SSH:
Donation request for network SMP development
Martin Pieuchot (mpi@) writes in about what's needed for further SMP improvements in the network stack:
OpenSSH 6.8 Released
This week has been full of other exciting news, so it may have been easy to miss that the OpenSSH team has released OpenSSH 6.8. The new release is billed as
OpenSSL 2015-03-19 Security Advisories - LibreSSL Largely Unaffected
The response to today's much-anticipated unveiling of newly discovered OpenSSL vulnerabilities has been varied and loud as expected. However, the impact on the OpenBSD-initated LibreSSL project's code -- which has undergone extensive cleanup since LibreSSL forked off OpenSSL's code base in 2014 -- appears to be limited. Out of a total of 13 CVEs in OpenSSL's announcement, only five - CVE-2015-0207, CVE-2015-0286, CVE-2015-0287, CVE-2015-0289 and CVE-2015-0209, still applied to LibreSSL's code.The main takeaway from the announcement appears to be that the cleanup has been effective, however these 'crash-inducing' issues have now been fixed in LibreSSL:
EuroBSDCon 2015 Call for Papers Is Out
The EuroBSDCon 2015 conference organizers have announced the Call for Papers for the upcoming conference in Stockholm, Sweden.Go to https://2015.eurobsdcon.org/call-for-papers/ for details; the full text of the announcement also follows after the fold.Read more...
libXfont Errata
LibreSSL 2.1.5 Released
The LibreSSL team has released LibreSSL 2.1.5, which the team characterizes as
OpenBSD @ AsiaBSDCon: httpd, PIE, and more
Slides from the AsiaBSDCon 2015 presentations are expected to appear on the OpenBSD web site (specifically the Presentations and Papers) page.The first presentation to appear there was Reyk Floeter's OpenBSD's new httpd (slides), also with a paper version.Other developers have been quite punctual too, publishing their presentations soon after their sessions at the conference:Peter Hessler: The results of using BGP for realtime import and export of spam whitelist/blacklist entries
OpenBSD 5.7 Preorders Started
Yes, you read that right!
FreeType Patches Available
Patches for bugs in the FreeType library areavailable:
s2k15 Hackathon Report: tedu@ on UVM SMP
Our fourth report from the s2k15 hackathon comes from Ted Unangst:
s2k15 Hackathon Report: Jonathan Gray on X Graphic Acceleration Improvements, afl fuzzer
Our third report from the s2k15 hackathon comes from Jonathan Gray (jsg@):
LibreSSL 2.1.4
Brent Cook (bcook@)posted:
Errata for X Server Infoleak
As reported by Ted Unangst (tedu@) ontech:
Summer of Code 2015 Project Ideas Announced
The OpenBSD foundation has published its Project Ideas List for this year's Google-sponsored Summer of Code. If you're a student with an appropriate background, this could be your chance to take a stab at contributing to the OpenBSD code base, with OpenBSD developers as your mentors.The Foundation and the OpenBSD project do not guarantee that SOC projects are accepted into the OpenBSD code base, but it's worth trying, isn't it?Check out the list and see if there's something there you want to spend most of the summer hacking on.
Episode 078: From the Foundation (Part 2)
In this week'sepisode,the fellas fromBSDNowinterview Ken Westerback (krw@), one of the directors of theOpenBSD Foundation. They also talk about the nascent BSDCan 2015schedule,Reyk Flöter's superfish-esquerelayd.conf,OpenBSD on the Minnowboard Max,and all the odds and ends in the week's BSD news.[Video|HD Video|MP3 Audio| OGG Audio|Torrent]
OpenBSD Foundation 2014/2015 News & Fundraising
Ken Westerback (krw@)wrote inon behalf of theOpenBSD Foundationto let us know what happened last year, and what's in store for us now:
s2k15 Hackathon Report: krw@ on improvements in dhclient(8), fdisk(8) and more
The second s2k15 hackathon reports comes from Ken Westerback (krw@), who writes:
s2k15 Hackathon Report: mpi@ on network stack SMP
Martin Pieuchot (mpi@) writes in with his report from the s2k15 hackathon:
BSDNow Episode 076: Time for a Change
On this week'sepisode,theBSDNowfolks interview Henning Brauer (henning@), featuring a cameo by the lovely and talented Ken Westerback (krw@) aboutOpenNTPD,especially in regards to theportable revivaland later drool over the newsecurity features.[Video|HD Video|MP3 Audio|OGG Audio|Torrent]
OpenBSD booth at SCALE 13x
Seth writes in to announce the OpenBSD booth at this year's SCALE 13x conference:
OpenBSD Just Works
After what appears to have been a very successful s2k15 hackathon, two significant thank you themed posts have appeared on OpenBSD mailing lists. Thefirst came on misc@ from longtime user and supporter Diana Eichert, with the subject a thankyou to OpenBSD. Diana writes,
Jazz concert with OpenBSD synths
Everybody's favourite audio hacker Alexandre Ratchov (ratchov@) is inviting you to a concert in Grenoble (France). Read on to find out how this relates to OpenBSD:
s2k15: Authenticated TLS 'constraints' in ntpd(8)
Reyk Flöter (reyk@)wrote into tech@, talking about some work he'd done ats2k15:
s2k15: the stack overflow that wasn't
From the trenches ofs2k15:
s2k15: warming up
Earlier this week, the s2k15 hackathon started down here in Brisbane Australia.
...1213141516