OpenBSD: Why and How (2016)
sivers.org
sivers.org
I don't consider myself a beginner to Unix or computers (I even have a PhD in the damn things), but I do consider myself a fairly inept and inexperienced systems administrator, with no great desire to spend the time to become better, and my needs are fairly basic - just the usual web/shell/IRC/mail server stuff, and other random infrastructure needs that come along for my work. Incidentally, this is exactly why I prefer OpenBSD. Everything is so minimalist, the defaults so sensible, and the documentation so good, that I trust the machines I set up. I have great confidence that I did not overlook something crucial. The OpenBSD http daemon is beautifully simple - too simple for many uses, but perfect for mine. The OpenBSD mail daemon is the only mail daemon I have ever been able to set up from scratch, just from reading the man pages.
I run Linux (NixOS and RHEL) on my desktop and some servers respectively, because of needs that OpenBSD simply does not support (mostly GPU computing). Linux is fine and certainly runs very fast, but OpenBSD is the only operating system I honestly like.
Maybe true, but it's not just for experts either. OpenBSD's unfriendly reputation ensured that I languished in Linux land way longer than I should have, convinced that I was too dumb for anything else.
If you can navigate directory structure, use a package manager, and uncomment lines in config files, you can use OpenBSD. Try it already. It's good.
Although I found that I barely have to touch my OpenBSD system...
I don't use BSD on the desktop though, still need Java.
One thing I do notice is OpenBSD's malloc implementation is much more serious about killing misbehaving apps so occasionally a process which does something it would get away with on linux/other will be taken out the back and lined up against the wall -- that's a feature and not a bug though (and configurable)
Could someone please point to an example, so that the difference in quality becomes apparent?
http://man.openbsd.org/ifconfig.8
https://linux.die.net/man/8/ip
The Linux one doesn't have an example anywhere of how to assign an IP address to an interface. Which is probably the most basic thing that you would be looking for.
https://linux.die.net/man/8/ifconfig
which says "This program is obsolete! For replacement check ip addr and ip link" and references ip(8) in the See Also section. Neither page refers to ip-address. In fact that entry doesn't exist on die.net which seems to be what Google considers to be the authoritative source for Linux man pages.
https://manpages.debian.org/testing/iproute2/ip-address.8.en...
https://linux.die.net/man/1/find
I usually read man pages on OpenBSD, even when I'm working on Linux. I also often link people on IRC OpenBSD man pages when they're struggling with their tools (or their manuals) on Linux. The reception is generally positive.
https://www.gnu.org/software/findutils/manual/html_mono/find...
To me, much like code and math, the art of writing good documentation is all about finding a way to make it short and simple (but still correct and complete).
It's possible that I just don't know how to use info. I always end up in the wrong place. That does not happen with man.
> and using the index you can jump to the canonical docs for any argument or command in one go
How?
> (ever spent time trying to find the hyphen-character section of a man page but struggled because it's referenced in 10 places?)
No, because the options are indented and inserting a few spaces before the hyphen in search string eliminates virtually all in-text references. Conventionally, the options are alpha-sorted too. In info pages, I end up wondering which section the option I want might be covered in.
I in Emacs info-mode. The prompt also has autocompletion.
As sibling commenters have mentioned, the Info tooling and format encourages people to split up their content into a bunch of nodes. In my experience, ~80% of Info manuals would be better if they were just concatenated into a single node, which the user could quickly Ctrl-F through with the tool of their choice.
[1] https://www.gnu.org/software/texinfo/manual/info-stnd/info-s...
[2] https://www.gnu.org/software/texinfo/manual/info-stnd/info-s...
But the good news is I read GNU is moving away from INFO for something else, forgot what it was.
Particularly when taking a certain vendor's certification tests, it was the work of seconds to write a man page example to disk and turn that into a script.
Semi-recent Centos7:
$ which find
/usr/bin/find
$ rpm -q --whatprovides '/usr/bin/find'
findutils-4.5.11-6.el7.x86_64
$ man find
No manual entry for find
$ more /etc/redhat-release
CentOS Linux release 7.7.1908 (Core)
So it claims to have the findutils rpm installed, which comes with manpages (especially since there is no find-man rpm) but I didn't get them for reasons. You just don't get that kind of experience on BSDs unless you very deliberately unmark manpages for installations. (which could be some kind of usecase, sure)
(Many of us out there have serious m4 trauma.)
Or you can buy a nice little library from OpenBSD where the PCM part is sufficiently described in one short man page: http://man.openbsd.org/sio_open.3
(With enough detail so that you can use it to write e.g. a latency-aware rhythm game that manages to keep audio and video in sync...)
Can you beat "uint32_t arc4random(void); void arc4random_buf(void *buf, size_t nbytes); uint32_t arc4random_uniform(uint32_t upper_bound);" as a RNG API? (No. Add it, glibc.)
I was pleasantly reminded how much Slackware still resembles BSD in how it configures things and it's emphasis on a minimal install that can be added to as needed. Other than new apps, a few improvements and, of course, updated hardware support Slackware has changed surprisingly little since I used it in 1995!
Patrick Volkerding is a great maintainer and I really appreciate his efforts over the past few decades!
Funny enough, OpenBSD's unfriendly behavior just had me go back to Linux land after running a FreeNAS server for two years. I got tired of every single help thread I was reading start with "Well you're stupid and you shouldn't do that" in one form or another.
Once Ubuntu got mature ZFS support in mainline, I was out.
What I've noticed about the OpenBSD mailing lists is that while people are generally decent and helpful if you show that you put at least some effort into your question, I also see negative responses to the less good questions that are just not needed, and without value.
I still like OpenBSD because it's just a good OS, but I think some people could stand to tune up their filters a bit.
So its a BSD, but not OpenBSD
This is why I jokingly call OpenBSD a full contact operating system; interacting with the community can feel like being at the bottom of a rubgy scrum. Still, the hardware requirements are so low and configuration and management easy enough I use it on old refurbished PCs as a firewall. Any refurbished $100 PC from microcenter and a couple of Intel gigabit ethernet cards is enough to make a decent firewall as long as you don't have gigabit ethernet to your ISP. OpenBSD really shines on legacy hardware.
I also enjoyed the fact it was the work of a few minutes to cut certificates for all my wifi devices and switch to certificate-based authentication instead of password-based. Unfortunately IOT vendors don't support that so you end up with a separate network just for semi-trusted devices.
In fairness to the people who called you stupid, you have some pretty glaring misunderstandings about whichever product you were using. (FreeNAS? OpenBSD?)
Whenever I couldn't figure something out I'd just read the manpage and go from there. Needless to say I also did a lot of trial and error, but that was mostly due to my own lack of knowledge at the time.
Fast forward to 2019, and at Mailhardener we run a couple OpenBSD instances, mostly because we really like OpenSMTPd. We also run Debian based servers for convenience reasons.
I still wouldn't recommend OpenBSD though, for almost all situations it would make more sense to run a Linux based OS. Whether it being on the desktop or on a server.
I've been using Linux as my primary system for 10 years now. Isn't it a bit exaggerated to group all Linux distributions together with ubuntu?
I think of myself as minimalist (arch linux / i3 / tmux / zsh / vim), thus fitting the description, but I'm not convinced by the argument to make the switch. On the contrary, the article feels like I better be ready to donate a lot of money if I want the system to run as I want it to.
> It’s uncompromising. It’s not a people-pleaser or vendor-pleaser. Linux is in everything from Android phones to massive supercomputers, so has to include features for all of them. The OpenBSD developers say no to most things.
I'm not sure if that's a good thing or not. Doesn't sound very community driven.
The security focus is probably the most interesting part here. I probably had the wrong assumption that most security-focused guys were on Kali linux.
I'll need a bit more nudging to make the jump over.
Typically, UNIX systems was for servers. And that is probably where security matters the most, too. Along with a conservative view on what hardware to support, it sounds an awful lot like a server operating system.
So does the article claim that it is good to run an operating system that targets servers on your desktop or laptop?
> I’ve donated $3850 to the developers to help improve the OpenBSD port of Node.js, Elixir, Erlang, Anki, Ledger, and Qutebrowser.
I'm pretty sure he's claiming it :) a port of Anki is not for servers ^^
Does ZSH still contain a ftp client? If you like minimal you should check out OpenBSD's ksh (oksh on arch maybe?), it behaves exactly the same way bash does (for me) and things like dd if=/dev/mm<tab> actually work, which iirc still doesn't on zsh.. :}
TBH, I didn't know about zshzftpsys, thanks for the knowledge transfer. Reading the manpage, I see
> type `which zftp' and if zftp is available you will get the message `zftp: shell built-in command'.
and I get
$ which zftp
zftp not found
As long as I don't zmodload zsh/zftp (and I certainly don't want to), I don't see any problem with this lib, now is there ?1) Commands have different switches. This is really annoying since you're probably using GNU/Linux at your day job.
2) It doesn't support all the new and fancy container/automation stuff that your colleauge is super stoked about.
3) Most companies haven't even heard about it, which causes certain problems. Example: I was working for a company that had a collaboration with Cisco, and we needed some binary blob in order to provision networking equipment. Getting this to work on OpenBSD was ten times as much work as making it run on Linux.
4) If you share your laptop with anyone, e.g. your wife or your parents when you're on holiday, they'll be a lot happier with Ubuntu.
In a perfect world, everyone would be running OpenBSD, but in the world as it is now, Linux is "better".
1) ??
2) Yes, this is fair -- but OpenBSD tends to fit more in the gateway/firewall/proxy/bastion space than running your microservices (although I've run plenty of node/etc apps on obsd hosts, IAAS and ansible is still a valid deployment path even after docker exists..)
3) Prop. vendor tools which require blobs should be run from whatever platforms they support. This is why you keep a windows laptop kicking around for flashing firmwares in the dc and so on
4) Family gets macs ;)
I don't think any of your points are enough to consider linux "better" than OpenBSD for any use case they're both capable of..
Loading a kernel module: Linux: modprobe, NetBSD: modload, FreeBSD: kldload
Seeing RX/TX information on an interface: Linux: ifconfig, NetBSD: netstat -b -I ale0
Change MAC address: Linux: ifconfig eth0 hw ether, NetBSD: ifconfig ale0 hw ether
2) Yes, I agree that OpenBSD exists in another space, which is fairly small. Is it worth introducing "unknown" tech to your team, though? I mean, is pf that much better than netfilter's nftables, to introduce something relatively unknown?
3) I agree. And "whatever platforms they support" means Linux nearly always, and very rarely OpenBSD. So you'll have to deal with Linux, but OpenBSD is optional and introduces additional complexity/stuff others on your team don't know about.
I think OpenBSD is better technology, but most of your colleagues will consider it unfamiliar territory, you'll miss out on new technology, etc.
I don't think that's the point. Nowadays, when somebody at works hits a bug and that ends up on my desk, I just tell them to setup a Docker container that reproduces the bug.
99% of the time the answer is, "oh, I had something misconfigured in my system, my fault". And I can close the bug without doing any actual work.
I can also develop on my laptop, desktop, etc. if all my environment is inside a docker container, without worrying that my workstation gets updated, some version of some library changes, and now I end up having multiple slightly different developer environments depending on the machine I use.
---
For me, the #1 reason not to use OpenBSD is lack of a good filesystem, and #2 lack of good drivers for modern hardware (e.g. I can't use a GPGPU from OpenBSD, or an Apple TV to stream my screen to do a presentation). Beyond that, lack of #3 docker prevents me from using it as a developing environment, and #4 lack of good cross-compilation toolchains from Linux to OpenBSD prevents me from trying to ship things from my development environment to OpenBSD systems.
What's wrong with OpenBSD's filesystem?
1) GNU extensions aren't always well thought out or standardized. Assuming everywhere is a current GNU userland will break frequently on multiple non-Linux OS's - look up trying to use `awk` on MacOS, which has BSD derived version.
2) Trendy developer conveniences with half-assed security like containers aren't really in line with OpenBSD's goals. If you want isolation, look into chroot, pledge, and unveil.
3) I'd blame Cisco in this case, not OpenBSD.
4) Says who? If a browser works, most people will be happy. The main use case for OpenBSD is network appliances like routers and infrastructure serving.
Even Linux isn't as consistent as some would have you believe. I regularly find that builds or application breaks because Red Hat is different from Ubuntu. And then, busybox is different from RHEL and Ubuntu. Also, busybox is different from older version of busybox.
I run into this often enough because customer runs stuff on RHEL while my company uses Ubuntu for development. And I happen to be working on an application that runs on different boards with different versions of busybox, as well as on mainstream x86-64 distros..
I agree with everything that you said. In an ideal world, we could all convince our colleagues that Docker and SELinux and Apparmor and such things are crap, and that everyone should be using OpenBSD alternatives. This is nothing but wishful thinking, however.
I wish the industry (and Cisco) would know about OpenBSD and wish to use it, but alas, this is not the case.
Yes, the main use is a fairly narrow part of possible uses, and introducing a whole new OS, package system and command set just because you prefer pf over nftables seems like something most of your colleagues would be a little disgruntled with.
Cannot get more enterprise that AIX :)
The main reason to avoid it is the limited hardware support, specially for laptops. I wish there were an equivalent of System76 for OpenBSD.
Second, the incredible flexibility of linux allows it to work in so many wildly different applications. It's a monolithic design, but it's so flexible you don't need to worry about it; it can be as narrow or as broad as you want it to be.
Just try it.
And I appreciate the low likelihood of privilege escalation (I keep seeing those bugs come up for the linux kernel, not for OpenBSD), and pledge/unveil limiting what apps can do to what they normally should do, so that damage by compromised apps can be greatly limited to a given user account or less. And yes, the clarity of documentation (like the excellent FAQs) and predictability of the system.
So basically, I read news all the time about this or that exploit, and I am not in the vulnerable group. But I do think that it took me more work to get set up the way I want, than when I used Debian more, but that work was very well worth it, and even more so when I include my config customizations to various apps that now work just as I want.
One addition to the base system I always make is to change the /etc/profile to set the default umask to 0077 (and other changes for my own convenience etc). I've long wondered why umask 0077 is not the system default. Although after changing it I had to wrap pkg_add in a script ("pa") which sets it back to the original default so that some apps don't get broken during installation for some reason.
Also, it seems worthwhile to choose compatible hardware, or some things might not work.
procfs isn't a program but a pseudo-filesystem. Are you just meaning to say that the info stored in /proc and displayed by strace is very useful to you? Or am I missing something else?
Does anybody here know if this issue has been fixed? Having a reliable, up to date, secure web browser (well, as secure as a web browser can be - up to date with the browser's own security updates) was the only thing that was holding me back from using it as a workstation. I had no problem back then using it as a server, but I couldn't justify running OpenBSD on my servers and Debian unstable on my desktop.
Running -current does give you up-to-date Firefox and Chromium packages.
But see my comments elsewhere in this discussion page for why I value obsd's pledge/unveil browser mods and lack of privilege escalation more important than having the latest browser fixes (which I also value, but relatively less).
Same goes for Chromium. I don't mind missing features. What I do mind is being behind on security patches.
What's the point of using OpenBSD (which is security focused) as a workstation when I can just be pwned by the latest browser bug?
For me, the point is as described elsewhere on this discussion (search for "lcall"): obsd is really good at isolation of users, and limiting potential damage by processes within a user's space, which I think of (at least on obsd) much more reliable than what a browser would do alone. So, I do my browsing in a user account that doesn't have access to the most important other things. If I do something like banking, I do that in a separate user account that does only that or only things at that level of security, separately from general browsing. And I mostly have images/javascript turned off when I do general browsing.
In my comment history there is another about why I use Iridium (or chromium sometimes) instead of firefox, with a question where you might know more than I.
(At my site lukecall.net , in the page footer is my email address if you have questions later that I might be able to answer.)
edit: ps: the way I separate users does involve extra work though, but now that the work is done I like it.
I guess I live in different universe than the author.
I think they're writing a git replacement under the BSD License, though I don't know how progress is going on that.
$ git worktree add ../foo-develop developtl;dr, it's the devil they know and they need no feature that Git or Mercurial provides.