OpenBSD and the modern laptop
bsdly.blogspot.com
bsdly.blogspot.com
Even with 802.11ad (that I don't have) there's a huge difference between having to plug in when you reach a "fast area" and not having to.
Going wired->wifi is like going desktop->laptop. I'll admit to being slow to go to both laptop and wifi years ago, but at least to me they're clearly superior.
Still I think it is awful.
I hear it is because the spectrum is jammed but I almost cannot believe it: I have a big garden and so have my neighbours.
What do you guys do to get fast, stable wireless?
The ubquiti has a spectrum survey mode that will tell you what sort of interference it sees on each channel. It takes 10's of minutes to run, and seems pretty thorough.
The real winning feature is that it is designed to be ceiling mounted, so I could place it in the center of my house, a few feet away from the nearest wall. There is also a mesh mode, where you buy more than one. If your house is big, and interference isn't the problem, that might help. I haven't tried it. They have newer / different models that do a better job of this than the UAP-Pro.
Later, I replaced my router with a pc engines apu2 running openbsd. Ubiquiti has a highly recommended cheap router (edgerouter lite) that works out of the box, if you aren't looking for a hobby project. People have gotten openbsd to run on it too.
service restart netif lagg0
And sometimes also service restart dhclient lagg0
But it might also be that I was to impatient and that it would have reconnected to wifi by itself if I gave it more time. How long does yours take to get back on wifi?I feel people have only used badly configured crappy consumer APs on crappy laptops (without MIMO) and don't understand that wifi doesn't have to be slow and unreliable.
"A deep dive into why Wi-Fi kind of sucks": https://arstechnica.com/information-technology/2017/03/802-e...
Good routers can go over 100Mbps, easily, and I would never think that 'less' speed is 'okay' in a world where increased speeds are just a requirement of technology over time, and usage, of said technology.
Note that I said 800-1100Mbps.
> but the problem has always been variable latency
Symptom of crappy consumer equipment.
> Any kind of interfere from the dozens of other Wi-Fi networks in the area seems to have an effect
Well yeah, that is why I use 5GHz which doesn't penetrate walls very well so I don't get any interference.
The power used is very low. More power just means more interference. The bottleneck is the transmit power on the client, which is very low. More power on the AP just make everything louder. I've set up power level based on this document: https://support.apple.com/en-us/HT203068. Unfortunately only Apple documents this stuff, but works pretty well for everything AFAICT.
I don't have any special antennas. If you need to cover a large space with a single AP you might need one, but the best philosophy on 5GHz is to have many smaller APs.
All my APs are connected through ethernet (actually everything is PoE powered). I don't use any mesh stuff (although Mikrotik can be used in that configuration, I don't recommend it). All my APs are simple bridges, I don't use the Mikrotik tunnel stuff.
I don't use 802.11r because Mikrotik can't do it yet. I am not sure if anyone except Cisco can do it. I wish I had 802.11r, this is my Achilles' heel.
Everything works very well, but you get what you pay for. Mikrotik is really cheap compared to the real stuff out there, which means much less polish, more bugs, and no real documentation. If I were to do it again I might chose Unifi[2] instead. Don't get me wrong, this all works very well, but the level of polish is what you'd expect out of a GitHub project compared to some real commercial product. For example while you can set antenna gain in standalone AP mode, you can't do it in managed AP mode. Minor stuff like that.
I also run a RADIUS server and I create user accounts for all my wireless users (WPA2 Enterprise). At different locations users have the same credentials.
I use all kinds of clients (Linux/BSD/macOS), but the ones where I'm most interested in speed are the Macbooks.
https://www.openbsd.org/60.html
https://www.openbsd.org/61.html
Not every project has engineers from Intel with internal datasheets, this came up before with USB 3.0 xHCI, which had Linux drivers long before the specs were public. There weren't even devices on the market!
OpenBSD is developed by volunteers.
I ended up putting FreeBSD on it and it worked great for a while. Then came the reboots, the lockups ... turns out I really should have run memtest86 first. The memory was bad; probably several other things too. I purchased it from a dodgy used shop and didn't realize all of this until past the 30 days. The memory on those models are soldered in too. I ended up eBaying it as a parts laptop.
Supposedly a fully functional X1 1st gen runs OpenBSD great. :-P
Would definitely recommend this setup for folks not needing anything fancy (not for gaming/3d apps), but for your average web developer, it'll do the trick.
The caveat is that a T500 isn't exactly "modern" (c. 2006), but it's got a Core 2 Duo @ 2Ghz and 8G of ram, which is plenty for my admittedly modest needs.
Linux has the mess of NetworkManager
FreeBSD idled hard and also has wifi-supplicant and crap.
Solaris is a dead end and you can forget wifi.
OpenBSD was perfect, it felt so cleanly engineered with wifi/wpa handled by ifconfig.
the only concern was the bluetooth- they do not support, in any form, bluetooth. Because: "We have never seen a clean implementation of bluetooth". And yes, they trail with wifi support, but on a 7 year old laptop, that's fine.
Did wonders for my battery life too.
What's wrong with wpa_supplicant? It works really well, you just write one config file with all the networks and you can set the networks' priorities…
ifconfig wlan0 scan
ifconfig wlan0 ssid "thingIfound" wpakey "password" up
dhclient wlan0I guess there are advantages to the wpa_supplicant way of doing things too. But you have the option on openbsd too at least.
Somehow, OpenBSD on a 2012 x220 has all the energy saving features, suspend abilities, media buttons actions, etc you could hope for in the base system, without a full desktop environment.
I find this simplicity quite relaxing compared to linux, where you would have to install either a full DE or a bunch of not-so-well-integrated softwares (acpid, tlp, powertop, ...) to have your machine just-working with a simple terms+browser+tilingwm setup.
On the other hand, browser performance is not as great, virtualization, docker, USB automount and wifi roaming aren't really there. It doesn't make a difference for me though.
If I knew anything about filesystems at all I think I'd volunteer to get it done, it seems like a pressing issue that nobody seems to care about much. I'd rather be able to mount as many things as GNU/Linux can before even thinking about USB automount...
Mounting msdos filesystems works for me on NetBSD, maybe the OpenBSD folks could copy some code.
There are many things missing in obsd, but overall, I find the experience on a thinkpad relaxing enough to be worth it.
But then from the Gist the author linked wrt getting X working with HiDPI:
> I'm using X in full resolution of 2560x1440 with wsfb (backed by efifb(4)). I configured my X session for HiDPI (retina), so I had to calculate and set DisplaySize in xorg.conf to get the correct DPI. With my configuration below, most but not all fonts display correctly. A few widgets still have tiny fonts.
And later in that same Gist:
> I'm using Window Maker (since about 1997). It doesn't fully support HiDPI but it is possible to make it useable by tweaking the fonts. Some widgets are still tiny but window titles, menus etc. work fine.
So to fill in what comes after the ellipses for the typical respondent of news of a laptop running OpenBSD: "Really? But... wouldn't that require special trips to the internet to copy/paste configuration settings that still only partially solve the problem of a laptop running an OS that wasn't designed to run on a laptop?" And the answer seems to be: yes.
One more bullet point from that Gist:
> In /etc/sysctl.conf I have to disable suspend when the lid is closed: machdep.lidsuspend=0
But the blog author says suspend/resume does indeed work. Is the blog author manually suspending/resuming, or did he get it to trigger correctly when the lid is open/closed?
These problems seem related to the choice of WindowMaker, not OpenBSD. Choosing a different window manager or desktop environment won't have the same issues.
And ACPI events vary wildly, unless the two people are using the exact same model I wouldn't be surprised if their suspend/resume success is different.
Independent scaling per monitor is supposedly supported in Wayland and just around the corner in KDE so I live in hope. I hear it's mostly working in the very latest versions of Gnome now at least, although I couldn't get it to work.
(I appreciate that this is a thread about BSD - I'm just pointing out that the situation in Linux isn't much better)
From what I could gather one could use cpucontrol to change the stored voltages and then let powerd, powerd++ or however OpenBSD handles this do its work. Thanks for that. But it looks like no one ever tried and reported on this. Hm.
[Background: mounting/unmounting by non-root users was removed in 6.0(?) for security reasons and the toad daemon/hotplug solution became apparently unavailable)
PS: OpenBSD 6.1 on an older thinkpad (X200) just works fine with xfce4
Unlike some other operating systems, OpenBSD encourages users to split their disk into a number of partitions, rather than just one or two large ones. Some of the reasons for doing so are:
Security:
Some of OpenBSD's default security features rely on filesystem mount(8) options such as nosuid, nodev, noexec or wxallowed.
Stability:
A user or a misbehaved program can fill a filesystem with garbage if they have write permissions for it. Your critical programs, which hopefully run on a different filesystem, do not get interrupted.
Integrity:
If one filesystem is corrupted for some reason, then your other filesystems are most likely still OK.
fsck(8):
You can mount partitions that you never or rarely need to write to as readonly most of the time, which will eliminate the need for a filesystem check after a crash or power interruption.
Edit: verbatim formatI admit I do cargo-cult partitioning. I don't really know whether the recommendations out there are current, outdated, mistaken or what.
I find a lot of recommendations about partitioning, swap, memory etc, at least for Linux, are cargo cult anyway, or at least outdated and/or poorly explained, which amounts to the same.
But really, just having rigid partitions makes me feel uneasy. ZFS datasets all share the same space, and you can set quotas if you want that can be changed anytime.
Flexible/resizable partitions are definitely easier, but I think you could have gotten the fixed scheme right if you had tried.
> create a 10gb EC2 instance
Unlike some other operating systems, OpenBSD encourages users to split their disk into a number of partitions, rather than just one or two large ones. Some of the reasons for doing so are:
Security:
Some of OpenBSD's default security features rely on filesystem mount(8) options such as nosuid, nodev, noexec or wxallowed.
Stability:
A user or a misbehaved program can fill a filesystem with garbage if they have write permissions for it. Your critical programs, which hopefully run on a different filesystem, do not get interrupted.
Integrity:
If one filesystem is corrupted for some reason, then your other filesystems are most likely still OK.
fsck(8):
You can mount partitions that you never or rarely need to write to as readonly most of the time, which will eliminate the need for a filesystem check after a crash or power interruption.
https://www.openbsd.org/faq/upgrade60.html
The wxallowed mount option. W^X is now strictly enforced by default; a program can only violate it if it is located on a filesystem mounted with the wxallowed mount(8) option. This allows the base system to be more secure as long as /usr/local is a separate filesystem.
The base system has no W^X-violating programs, but the ports tree contains quite a few: chromium, mono, node, gnome, libreoffice, jdk, zeal, etc. If you want to run any of these ports on a regular basis, you need to add wxallowed to the mount options for /usr/local in fstab(5), e.g.:
01020304050607.h /usr/local ffs rw,nodev,wxallowed 1 2
Small disks may not have a separate partition for /usr/local. In that case, add wxallowed to the smallest partition containing it: /usr or /.Starting a W^X-violating program from a partition without the wxallowed mount option will produce a core dump and the dmesg(8) will contain an entry such as soffice.bin(15529): mprotect W^X violation. You can temporarily allow W^X-violating ports by issuing mount -uo wxallowed /usr/local.
https://en.m.wikipedia.org/wiki/W%5EX
W^X ("Write XOR Execute"; spoken as W xor X) is a security feature in operating systems and virtual machines. It is a memory protection policy whereby every page in a process's or kernel's address space may be either writable or executable, but not both. Without such protection, a program can write (as data) CPU instructions in an area of memory intended for data and then arrange to run (as executable) those instructions. This can be dangerous if the writer of the memory is malicious.
Generally I use the auto layout as a strong hint on how many partitions to make and the general size suggestions - then alter based on my needs (ie. bumping var instead of home for servers).
Is this uncommon enough to need specifying? I've heard something along the lines of Ubuntu having no actual root user for security reasons, but I got no impression that this was a common approach. If root isn't a real user, what are your options when your main user is compromised?
You can usually login by editing the grub kernel command line, and setting init=/bin/sh
Disk encryption may or may not make account recovery more complicated.
Yeah right... Some strange demographics in there...