Feed openbsd-journal OpenBSD Journal

Favorite IconOpenBSD Journal

Link http://undeadly.org/
Feed http://undeadly.org/cgi?action=rss
Updated 2024-12-03 17:15
Game of Trees 0.74 released
For those who have been paying attention to the Game of Trees development list, there has been a lot going on with got(1). Apologies here at undeadly for having missed some release announcements!
OpenBGPD 7.5 released
Our favorite BGP daemon, OpenBGPD, has a new version 7.5 out. The announcement reads,
rpki-client 7.9 released
A fairly critical component of routing security infrastructure, rpki-client, has a new release out, version 7.9.The announcement leads in,
In -current, dhclient(8) now just logs warnings and executes ifconfig(8)
Theo de Raadt (deraadt@)committedthe change:
r2k22 Hackathon Report: Job Snijders (job@) on rpki-client and more
The first r2k22 hackathon report is in, from Job Snijders (job@), who writes:
(Almost) 0 Dependency Websites with OpenBSD & AsciiDoc
Courtney Allen has published a blog post about how to run a website and blog almost exclusively on things that are in the OpenBSD base system already, only adding AsciiDoc to the mix.The lead in reads,
Analyzing locks in OpenBSD’s Kernel with Domain-Specific Knowledge
Christian Ludwig "wrote a tool to statically analyze spl(9) kernel locking in OpenBSD. It even found some bugs."His write up is here: https://medium.com/@chrissicool/analyze-openbsds-kernel-with-domain-specific-knowledge-ca665d92eebbHis code for the Lock Balancing Checker referenced in the write up is available under an ISC license and can be obtained here: https://github.com/chrissicool/lbc
Notable OpenBSD news you may have missed, 2022-06-28 edition
Here are a few recent OpenBSD news items that we almost missed ourselves:
Differences between base and ports LLVM in OpenBSD
Frederic Cambus (fcambus@)has written ablog entryregarding the significant differences between the versions ofLLVM inbase andports.
OpenBGPD 7.4 released
We wouldn't blame you if you it slipped under yourRADAR thatOpenBGPD 7.4 was released,since it doesn't appear to have been mentioned on the OpenBGPD website yet.However, the release notes may be found inthis mailing list postfrom June 14th, 2022:
Network Management with the OpenBSD Packet Filter Toolset from BSDCan 2022
Peter Hansteen, Massimiliano Stucchi and Tom Smyth gave a presentation on pf at BSDCan 2022. While a video recording from the event has yet to appear, the slides from their presentation may be viewed here:
OpenIKED 7.1 released
OpenIKED 7.1 was released on May 23rd, 2022.The complete release notes may be read here:
LibreSSL updated to 3.5.3
LibreSSL 3.5.3 was released on May 18th, 2022.The release notes may be found here:
Candlelit Console patch set to the framebuffer console
Crystal Kolipe writes in about her work on the framebuffer console, and provides an article on
Parallel IP forwarding activated
Following much development and testing,parallel IP forwarding has been enabled in -current.The most recent of the relevant commitsare:
pkg_add(1) speedup
In -current, the performance ofpkg_add(1)has been greatly enhanced by theenabling of caching by default:
syspatch71-001_wifi reissued
syspatch71-001_wifi was somewhatbroken(in terms of the housekeeping rather thanthe functionality of the patch).On those systems to which the faulty patch was applied,some manual intervention is required.Instructions for thisare now on theerrata page.
LibreSSL 3.5.2 released
Hot on the heels of OpenBSD 7.1's release,LibreSSLhas been updated to 3.5.2!The complete release notes may be read here:https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.5.2-relnotes.txt
April 21, 2022: OpenBSD 7.1 Released
The long spring (or fall) wait is over, the OpenBSD project today formally released OpenBSD 7.1, the 52nd release of our favorite open source operating system.As usual, the release page lists the main highlights of the new release, which include
OpenBGPD 7.3 released
Claudio Jeker (claudio@) has just announced the release of OpenBGPD 7.3. He writes:
OpenSSH 9.0 released
Version 9.0ofOpenSSHhas been released.Notable changes include:
OpenBSD/arm64 on Apple M1 systems
In amessage to tech@(and arm64@),Mark Kettenis (kettenis@) wrote:
Testing parallel forwarding
Hrvoje Popovski writes in with some result from his performance tests, like he did a few years ago:
LibreSSL 3.5.1 development branch as well as 3.4.3 (stable) and 3.3.6 released
For undeadly readers, our Errata column on the right side of the web site automatically updates and as of March 15th, 2022 some of you may have already noticed that there is a new security fix related to LibreSSL. Salient excerpt from the release notes as follows:
iwx(4) gains 11ac 80MHz channel support
Following a request-for-testingthreadon tech@,Stefan Sperling (stsp@)hascommittedsomeIEEE 802.11acsupport toiwx(4):
mtw(4), a driver for MediaTek MT7601U Wi-Fi devices
James Hastings (hastings@) hascommittedmtw(4),a driver forMediaTek MT7601UUSBWi-Fi devices:
LibreSSL 3.5.0 development branch released
As of February 24th, 2022, LibreSSL's development branch has been updated to version 3.5.0.
OpenSSH updated to 8.9
On February 23rd, 2022 OpenSSH was updated to version 8.9.
-current has moved to 7.1-beta
With the followingcommit,Theo de Raadt (deraadt@) moved -currentto version 7.1-beta:
Recent developments in OpenBSD, 2022-02-21 summary
Recent things of interest include:
New 'Reckless guide to OpenBSD' published
Crystal Kolipe writes in, saying
A proof of concept: running OpenBSD on the PinePhone
Crystal Kolipe has donea four partmulti-part write upabout getting OpenBSD running on aPinePhone here:
LibreSSL update
A long list of recent LibreSSLcommits by Theo Buehler (tb@)culminated inbumps to library versions:
DRM updated
Johathan Gray (jsg@) hasupdatedDRMto Linux 5.15.14 (with support for several additional chips):
SSH Agent Restriction
Damien Miller (djm@) justnoted on social media that he has committed(starting here)changes which allow control overssh-agent(1)key-forwarding based on destination host and forwarding path.A detailed description isavailableon theOpenSSH site.
Clang upgraded to version 13
After much preparatory work in base and ports,clang(1)has been upgraded to version 13.0.0 (on the relevant platforms).Patrick Wildt (patrick@) made thecommits.
Catchup 2021-11-03
Interesting developments (in -current) sinceOpenBSD 7.0 include:
OpenBSD 7.0 released
The OpenBSD projecthas releasedOpenBSD 7.0,the project's 51 release.As usual, the release pageoffers highlights, installation and upgrade instructions, as well as links toother resources such as thedetailed changelog.Notable improvements include, but are not limited to:
Catchup 2021-10-08
In the run-up to the OpenBSD 7.0 release, we note several recent interestingthings previously unreported:
Realtek wireless firmwares imported!
As a result of a licence change byRealtek,that company's wireless firmware images are now included in the tree.The followingcommitby Kevin Lo (kevlo@)explains the details:Read more…
September 30th, 2021 syspatches: some assembly might be required
Did you just runsyspatch(8)and see it fail?Here's the reason: one of the two root certificatesbehind the (excellent)Let's EncryptCA service has expired.A bug in (the "legacy" verifier of)LibreSSLalso contributed.The syspatches (for OpenBSD 6.8,032, for OpenBSD 6.9,018) mitigate the unfortunate situation.However, your syspatch may fail if your local mirror uses aLet's Encrypt certificate.Patch-22!In that case, the best advice may be to try a mirror that does notuse a Let's Encrypt certificate just to get past this speed bump.Read more…
EuroBSDCon 2021 videos are available
EuroBSDCon 2021was held [virtually] earlier this month.Videos of the presentation arenow available.Amongst the OpenBSD-related presentations is that byMarc Espie (espie@) -Debug Packages in OpenBSD(slides,video).
By default, scp(1) now uses SFTP protocol
Thanks to acommitby Damien Miller (djm@),scp(1) (in -current)now defaults to using theSFTP protocol:
Unlocking UVM faults yields significant performance boost
In a recentmessageto tech@ Martin Pieuchot (mpi@) wrote aboutanalysis of kernel lock contention.We reproduce the message(s) here, reformatted with his permission.
traceroute(8) gets speed boost
Florian Obser (florian@)has committeda significant speed boost fortraceroute(8):
xterm gets unveiled
With the followingcommit,Matthieu Herrb (matthieu@)gavexterm(1)someunveil(2)goodness:
iked(8) gains client-side support for DNS configuration
With the followingcommit,Tobias Heider (tobhe@)added client-side support for DNS configurationto iked(8):
timeout(1) utility imported
Job Snijders (job@)importedthetimeout(1)utility from NetBSD:
Fair Internet bandwidth management on a network using OpenBSD
OpenBSD Journal co-editor Solène Rapenne (solene@) writes,
Hibernate time reduced
Theo de Raadt (deraadt@)committeda change which significantly reduceshibernatetime on machines with larger amounts of RAM:
...234567891011...