OpenBSD 6.1 released
marc.info
marc.info
Massive update and normalization of manpages, conversion to mandoc format. Many pages were rewritten for clarity and accuracy.
Most of OpenSSL's documentation desperately needed attention and was full of extremely minor errors that rendered some parts unintelligible - for example, this confusing single character one that was already fixed in LibreSSL : https://github.com/openssl/openssl/commit/a41815f05e71009d2a...It's not just kernel bundled with a bunch of tools/programs which sort of seem to work together, but not in the same manor. Even FreeBSD have sometimes left me with the impression that the developers don't care about style and just import tools or subsystems at leave it at that, rather than making it feel like it belongs.
ZFS is large and complicated. http://www.tedunangst.com/flak/post/ZFS-on-OpenBSD
DTrace would be nice to have, but I believe there are CDDL license concerns.
Jails are a way of isolating services so that they cannot do (much) damage to the system in the event they are compromised. The closest alternative in OpenBSD is probably pledge(2), which allows a program to voluntarily renounce the ability to invoke a set of syscalls. There is also chroot if all you need is filesystem virtualization.
MAC can be complicated to implement. This comment explained things very well: https://news.ycombinator.com/item?id=8893749
> OpenBSD doesn't support a MAC framework because they believe the best approach to security is correctness, rather than trying to achieve security by adding features which results in more complexity, making it more difficult to ensure correctness. A common mistake people make is thinking that OpenBSD's primary goal is security; their primary goal is correctness. This just happens to result in better security more often than not.
Linux compat is a similar story. OpenBSD dropped it in the 6.0 release due to complexity and security concerns.
I don't know a whole lot about CloudABI.
pledge is more similar to Capsicum. It is simpler to implement in some programs, sure, but:
1) I don't like how pledge just kills the program. Rude. Capsicum refuses the offending operation.
2) Capsicum has an absolutely brilliant feature for directory access — you just open() a file descriptor to a directory, then you cap_enter()… and in the sandbox mode you can use openat() to open files below that directory! This is just so clever. Meanwhile pledge promised a simple directory whitelist option that is STILL NOT IMPLEMENTED :(
CloudABI is a portable ABI that can be described as POSIX plus Capsicum minus anything incompatible with Capsicum. So CloudABI programs start already in capability mode, expecting necessary file descriptors to be already open (there's a launcher tool for that). You can just run CloudABI binaries unmodified on several operating systems and they are always sandboxed, they have no way to access anything you didn't pass to them. CloudABI is out-of-the-box supported on FreeBSD, there are kernel patches for NetBSD and Linux, and a user-mode syscall translator for macOS. https://nuxi.nl/cloudabi/
Both are valid, and result in very different operating systems. These days most of my work can be fit into the OpenBSD envelope, which makes me feel especially good.
But then FreeBSD itself lacks ACLs on tmpfs, EAs on ZFS, and SO_PEERCRED; and moreover OpenBSD does have wscons.
Yeah, SO_PEERCRED, I remember that one. The sway Wayland compositor relies on it to authenticate privileged programs (desktop bars, screensavers, screenshot tools etc.) When I was porting sway, that really annoyed me.
What are EAs?
* https://www.freebsdnews.com/2016/01/27/zfs-boot-environment-...
I completely understand why these thing aren't being done, but not doing them mean that something will remain a little out of place.
[1] https://www.openbsd.org/orders.html [2] https://www.debian.org/CD/vendors/
Thanks for highlighting this. For me, OpenBSD releases needed so few fixes that keeping the system up to date wrapped around, and become more of a hassle to deal with! I'd get an email and have to manually rebuild something. Watching yet another flood of compiler output started feeling like a huge waste of time, despite only happening once every month or two.
For personal use, on debian I set a cron job and forget it. This utility hits the sweet spot to get me running OpenBSD again.
You can specify the types of updates to auto install (ie I use security updates only automatically).
[1] https://wiki.debian.org/UnattendedUpgrades#automatic_call_vi...
[2] http://unix.stackexchange.com/questions/293804/debian-a-star...
I'm not sure this has been reported before / correctly:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=837155 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=719597
Maybe give the maintainers a prod with a link to that thread?
https://www.openbsd.org/lyrics.html#61
That's usually my favourite part about new OpenBSD releases. :-)
Goodnight, sweet prince.
The Sharp Zaurus was where I first ran OpenBSD.
SPARC is one of the few unencumbered platforms without security bits (Intel ME or AMD PSP) and GPL cores: https://news.ycombinator.com/item?id=11423350
https://www.openbsd.org/sparc.html - Discontinued
https://www.openbsd.org/sparc64.html - Supported
So, you could run an HTTPS site, with a Perl fastCGI site, sending emails, all out of Base
Plus you get privsep'd X (xenocara)
https://wiki.ubuntu.com/X/Rootless
Also interesting is that support for rootless (at least in Arch) depends on, or perhaps was facilitated by systemd:
https://wiki.archlinux.org/index.php/Xorg#Rootless_Xorg_.28v...
I don't pay as close attention to Linux developments as I should these days!
--
- A lot of code has been removed or simplified to make the transition to multi-processor easier.
- printf(3) family of formatting functions now report to syslog when the %s format is used with a NULL pointer.
- When sending TCP streams they are locally stored in large mbuf clusters to improve memory management. The maximum TCP send and receive buffer size has been increased from 256KB to 2MB. Note that this results in a different pf(4) OS fingerprint for OpenBSD.
- ssh(1): Add a proxy multiplexing mode to ssh(1) inspired by the version in PuTTY by Simon Tatham. This allows a multiplexing client to communicate with the master process using a subset of the SSH packet and channels protocol over a Unix-domain socket, with the main process acting as a proxy that translates channel IDs, etc. This allows multiplexing mode to run on systems that lack file-descriptor passing used by current multiplexing code) and potentially, in conjunction with Unix-domain socket forwarding, with the client and multiplexing master process on different machines. Multiplexing proxy mode may be invoked using "ssh -O proxy ..."
- OpenSSH 7.4: Server support for the SSH v.1 protocol has been removed. {NB, note the "server" bit - "client" is not mentioned}
- Support for Linux guest VMs.
- The performance and concurrency of the malloc(3) family in multi-threaded processes has been improved.
- read(2) on directories now fails instead of returning 0.
- Support for permitting non-root users to mount(8) filesystems has been removed.
- Install sets are now fetched over an HTTPS connection by default when using a mirror that supports it.
- For incoming TLS connections syslogd(8) can validate client certificates with a given CA file.
- nc(1) now also supports OCSP stapling server side, and will show the stapling information client side.
- When log files are rotated, newsyslog(8) writes the creation time in UTC ISO format into the first line.
--
- sshd(8): Remove the UseLogin configuration directive and support for having /bin/login manage login sessions.
- sshd(8): Add a sshd_config DisableForwarding option that disables X11, agent, TCP, tunnel and Unix domain socket forwarding, as well as anything else we might implement in the future. Like the 'restrict' authorized_keys flag, this is intended to be a simple and future-proof way of restricting an account.
- sshd(8), ssh(1): Support the "curve25519-sha256" key exchange method. This is identical to the currently-supported method named "curve25519-sha256@libssh.org".
- Deprecate the sshd_config UsePrivilegeSeparation option, thereby making privilege separation mandatory. Privilege separation has been on by default for almost 15 years and sandboxing has been on by default for almost the last five.
- SHA512_256 family of functions added to libc.
- LibreSSL 2.5.3: Massive update and normalization of manpages, conversion to mandoc format. Many pages were rewritten for clarity and accuracy. Portable doc links are up-to-date with a new conversion tool.
--
- Use a hardware register for the thread pointer on arm for improved performance in multi-threaded processes.
- New vmm(4)/ vmd(8): Support was partially integrated in 6.0, but disabled.
- vmm(4) no longer requires VMX unrestricted guest capability (Nehalem and later CPUs are sufficient).
- Support VMs with > 2GB RAM.
- vmd(8) uses pledge(2) and the fork+exec model.
--
- All shared libraries, all dynamic and static-PIE executables, and ld.so(1) itself use the RELRO ("read-only after relocation") design such that more of the initial data is protected as read-only.
- The privileged parent process of syslogd(8) calls exec(2) to reshuffle its random memory layout.
- New function recallocarray(3) to reduce the risk of incorrect clearing of memory before and after reallocarray(3).
- arm added to the list of archs where the setjmp(3) family of functions apply XOR cookies to stack and return-address values in the jmpbuf.
- bioctl(8) now uses bcrypt PBKDF to derive keys for crypto volumes.
- Partial UTF-8 line editing support for ksh(1) Vi input mode.
- UTF-8 support in column(1).
--
Edit: Reordered things a little and grouped things together for legibility
- The iwm(4) driver now supports 802.11n MIMO (MCS 0-15).
- Enforcement of userland W^X on OCTEON Plus and later.
Is the EdgeRouter Lite an Octeon "Plus"?
- LLVM/Clang 4.0.0 (+ patches)
Looks like they shipped LLVM 4 into an actual stable release before FreeBSD! (because it's the first LLVM for them)
- New tpm(4) driver for Trusted Platform Module devices.
But that one was in FreeBSD since 2010 :P
Looks like:
ben@edge:~$ cat /proc/cpuinfo
system type : UBNT_E100
processor : 0
cpu model : Cavium Octeon+ V0.1Note it's only in base for the ARM platform.
This is a big help because now I can put in production the SuperMicro E200-8D I bought to replace our older gateway.
[edit] D'oh, for some reason I read "like pfsense" but missed "for openbsd."
And Postgres 9.6 in packages. Today is a good day
This is not a supported or convenient way to do your first OpenBSD install. Having a serial console is not necessary, but recommended (in particular, don't forget to configure <real-hw-interface>0, not the em0 that qemu is likely to offer you.) That said, I've done this before on some Hetzner serverauction (bare-metal) box, and the procedure worked fine (as one would expect.)
(Of course, you can run into hardware that OpenBSD doesn't support. Consult the man pages to find what is supported, or just try - server hardware is pretty likely to be supported.)