Feed openbsd-journal OpenBSD Journal

Favorite IconOpenBSD Journal

Link http://undeadly.org/
Feed http://undeadly.org/cgi?action=rss
Updated 2024-04-20 00:47
OpenBSD 7.4 Released
The OpenBSD project has announced the release ofOpenBSD 7.4,the 55 release of the OpenBSD operating system.The new release contains a number of innovations and improvements across a number of areas, including
OpenBGPD 8.3 released
The release of version 8.3 ofOpenBGPDhas beenannounced.This version contains a few fixes.
p2k23 - OpenBSD Ports Hackathon Dublin 2023
Rafael Sadowski (rsadowski@)bloggedabout his participation inp2k23.Perhaps most notable is his work in portingKDEPlasma.Read all about it athttps://rsadowski.de/posts/2023-10-09-p2k23-dublin-openbsd-hackathon/.There is some further discussion of the work in a thread titled NEW: KDE Plasma (x11/kde-plasma) on the ports@ mailing list.
rpki-client 8.6 released
Version 8.6ofrpki-client, the FREE, easy-to-use implementation of the ResourcePublic Key Infrastructure (RPKI)for Relying Parties (RP),has beenreleased.This version includes new compliance checks,random shuffling of processing of Manifest entries,and [non-random!] code shuffling.See the announcement for more details.This is another hint that a new OpenBSDreleaseis about to happen, and soon.
E-mail Filters In C
Jay Eptinxa has published a detailed write-up,entitledE-mail Filters In C,of his work creating aspamd(8)-likegreylistingsmtpd(8)filter.Thanks to Crystal Kolipe for letting us know!
OpenSSH 9.5 released
OpenSSH 9.5has beenreleased.This releases features the keystroke timing obfuscationon which we reportedearlier.
OpenBGPD 8.2 released
With a message from Claudio Jeker (claudio@), the OpenBSD project today announced the release of the OpenBSDBGP(Border Gateway Protocol) daemon OpenBGPD, version 8.2.The announcement reads,
Introduction to sysclean(8)
ManyOpenBSDsysadminsfind thesysclean(8)portuseful for removing obsolete files following upgrades.Sebastien Marie (semarie@),theauthorof sysclean(8),has written apiecegiving an under-the-hoodlook at the operation of this handy utility.It's well worth reading for those interested in understandinghow it works!
-current has moved to 7.4
With the followingcommit,Theo de Raadt (deraadt@) moved -current to version 7.4:
Viable ROP-free roadmap for i386/armv8/riscv64/alpha/sparc64
Theo de Raadt (deraadt@) posted totech@a detailedmessageexplaining the past and (potential) future ofanti-ROPmeasures in OpenBSD.It's well worth reading its entirety.Highlights include:
OpenBSD/arm64 on Hetzner Cloud
Frederic Cambus (fcambus@) wrote a blogpost about running OpenBSD on the arm64-based cloudservers provided by Hetzner. For now, only -current will work,because the new viogpu(4)driver[on which wereported earlier]is needed.Head on over to Frederic's blog for the full story!
EuroBSDCon 2023 presentations
EuroBSDCon 2023has now ended,and slides for many of the OpenBSD developer presentationsare now available in theusual place.Video of the presentations can be expected somewhat later.Slides from the tutorial"Network Management with the OpenBSD Packet Filter Toolset"arealso available.
Game of Trees 0.93 released
Version 0.93 of Game of Trees has been released (and the port updated).Read more...
-current has moved to 7.4-beta
With the followingcommit(s),Theo de Raadt (deraadt@) moved -currentto version 7.4-beta:
p2k23 Hackathon Report: Volker Schlecht (volker@) on rust and erlang progress
We are pleased to have anotherp2k23report, this time from Volker Schlecht (volker@)who writes:
3D printing on OpenBSD? Yes, that’s a thing!
Can you really do 3D printing from OpenBSD? Cue suspenseful musicwhilst I formulate my answer, which is: Yes.If you aren't familiar with the 3D printing process, it's dividedinto several steps, vaguely analogous to writing, compiling and runninga program in a compiled language.Read more...
p2k23 Hackathon Report: Landry Breuil (landry@) on chasing memory corruptions
Next up in the series of p2k23 hackathon reports is this from Landry Breuil (landry@), who writes,
p2k23 Hackathon Report: Jeremy Evans (jeremy@) on Ruby ports cleanup, database progress, and more
Next up in our reports from thep2k23 hackathonis one from Jeremy Evans (jeremy@).Jeremy writes:
p2k23 Hackathon Report: Marc Espie (espie@) on a flurry of packages activity
The p2k23 OpenBSD packages hackathon just concluded, and Marc Espie (espie@) wrote in with this report:
Game of Trees 0.92 released
Version 0.92of Game of Treeshas been released (and the portupdated):
Keystroke timing obfuscation added to ssh(1)
Damien Miller (djm@) hascommittedsupport for keystroke timing obfuscation tossh(1):
OpenSSH 9.4 released!
As alluded to with the recent"Call for testing"message on the openssh-unix-devmailing list, OpenSSH 9.4 has been released!The complete release notes may be read here:https://www.openssh.com/releasenotes.html#9.4p1
New routed IPsec VPN mode committed
The routed IPSec mode we reported on earlier has now been committed to -current by David Gwynne (dlg@), likely to be a prominent item for the upcoming OpenBSD 7.4 release.The main log message:
rpki-client 8.5 released
Version 8.5of rpki-client,OpenBSD'simplementation of the Resource Public Key Infrastructure (RPKI)for Relying Parties (RP),has been released.Features include:
Theo de Raadt on Zenbleed
The buzzword bug of the week is Zenbleed, which affects various AMD processors and is explained in more detail here. On OpenBSD, the latest -current snapshots already have the fixes, and errata patches will go out for the supported releases (7.2 and 7.3) shortly.In a post to the tech@ list, Theo de Raadt described the situation:
AMD processor microcode support added to -current
Thanks toaseriesofcommitsby Jonathan Gray (jsg@),-current now has support for microcode (updates)for AMD (amd64 and i386) processors:
Game of Trees 0.91 released
Version 0.91of Game of Treeshas been released (and the portupdated):
OpenSSH 9.3p2 released
As announced by Damien Miller: "We've just made an OpenSSH release to fix a remotely exploitable RCE vulnerability in ssh-agent's PKCS#11 support (CVE-2023-38408). Details at https://openssh.com/releasenotes.html#9.3p2Thanks to the Qualys Security Advisory Team for finding and reporting this bug."This appears to impact every version of OpenSSH's ssh-agent from 5.5 onwards.
Mandatory enforcement of indirect branch targets
Theo de Raadt (deraadt@)has updatedinnovations.htmlto include an item regarding the work which has been doneto enforce indirect branch target restriction(on theamd64[Intel]andarm64platforms).Thecommit messageprovides some detail:
OpenBGPD 8.1 released
Version 8.1 of OpenBGPD, the OpenBSD Border Gateway Protocol (BGP) routing daemon, has just been released.The announcement reads,
pkg_*: the road forward
An anonymous submitter reminded us that Marc Espie (espie@) posted a summary of the state of OpenBSD packages in a message to the tech mailing list with the subject pkg_*: the road forward.Marc writes,
Wayland on OpenBSD
Matthieu Herrb (matthieu@) has written some noteson his work at the (recently-concluded)g2k23 hackathonin Tallinn, Estonia.His article,Wayland on OpenBSD,starts:
Major pfsync(4) Rewrite Has Been Committed
The majorpfsync(4)rewrite on which werecently reportedhas beencommittedto -current by David Gwynne (dlg@).As it says in the commit message
Soft updates (softdep) disabled for future VFS work
A low key leak from the ongoing g2k23 hackathon comes the news thatsoft updates(akasoftdep) will, for now, be a no-opon OpenBSD-current.The commit message by Bob Beck (beck@) reads,
[CFT] sec(4) for Route Based IPSec VPNs
A new tool for creating flexible, route based site to site virtual private networks (site-to-site VPNs) is entering its call for testing phase on OpenBSD-current.In a message to the tech@ mailing list on July 4th, 2023, David Gwynne (dlg@) presented a diff that adds a new virtual network interface dubbed sec(4). The message reads,
Game of Trees 0.90 released
Version 0.90ofGame of Treeshas been released (and the portupdated):Read more...
[CFT] Major pfsync(4) Rewrite on the Horizon
A major rewrite of pfsync(4), the state table synchronization tool for redundant pf(4) setups is in the works.In a recent message to tech@, David Gwynne (dlg@) describes the multi-year process behind the diff contained in the message,
shutdown/reboot now require membership of group _shutdown
Theo de Raadt (deraadt@)committedchanges which result intheshutdown(8)andreboot(8)commands(in -current)requiring membership of the the (new) group"_shutdown".The commit message explains the rationale:Read more...
OpenSMTPD 7.3.0p0 released
TheOpenBSD projecthas releasedversion 7.3.0p0of OpenSMTPD, the project'sSMTPserver.Theannouncementreads in part:
Game of Trees 0.89 released
Version 0.89ofGame of Treeshas been released (and the portupdated):
New versions of LibreSSL released
TheLibreSSL projecthas announced the release of versions3.6.3 and3.7.3,and (development) version3.8.0of the software.Theannouncementfor versions 3.6.3 and 3.7.3 reads:
cron(8) now supports random ranges with steps
Thanks to the followingcommitby Todd Miller (millert@),cron(8)now supports random values in a rangewith a step value(i.e."<lo>~<hi>/<step>"incrontab(5) entries):
cron(8) now supports random ranges with steps
Thanks to the followingcommitby Todd Miller (millert@),cron(8)now supports random values in a rangewith a step value(i.e."<lo>~<hi>/<step>"incrontab(5) entries):
OpenBGPD 8.0 released
The OpenBSD project has released a new version ofOpenBGPD,the OpenBSD Border Gateway Protocol (BGP) routing daemon,version 8.0.Theannouncementreads,
OpenBGPD 8.0 released
The OpenBSD project has released a new version ofOpenBGPD,the OpenBSD Border Gateway Protocol (BGP) routing daemon,version 8.0.Theannouncementreads,
rpki-client 8.4 released
Version 8.4ofrpki-clienthas beenreleased, with a number of improvements and new features:
rpki-client 8.4 released
Version 8.4ofrpki-clienthas beenreleased, with a number of improvements and new features:
Game of Trees 0.88 released!
Version 0.88ofGame of Treeshas been released (and the portupdated):
Game of Trees 0.88 released!
Version 0.88ofGame of Treeshas been released (and the portupdated):
VM owners can now override the boot kernel
Dave Voutila (dv@)has addedanother feature to virtualisation on OpenBSD.Thanks to the followingcommit,it is now possible for the owners of virtual machinesto override the boot kernel:Read more...
12345678910...