OpenBSD 6.7
marc.info
marc.info
OpenBSD is one of the last really good choices for an operating system, in my opinion. Redhat, the pretentious gnome developers, canonicals latest folly, proliferation of systemd cancer (homed being the latest abomination)... All these things take away from the user's freedom.
I hope OpenBSD continues for decades to come.
Highly recommended for everyone to try out.
I ask because I had a coworker/friend years ago from Ukraine and that's what he called it. My other friend and I who worked with him could not get him to say operating system no matter how much we poked at him. Anyway, just like the article itself you brought back a flood of memories so just curious like I said.
I've often heard that Thinkpads make great OpenBSD laptops. Are there any models in particular the HN crowd would recommend? In terms of my hardware needs, I don't really care about graphics like you'd get with an Nvidia card, but I do need wi-fi since it'd be really hard to set up a wired connection to my router in my current apartment.
Mind you I use this mainly for work so my needs are simple, an editor, a browser, a compiler and the like. The default window manager cwm makes for a simple "desktop" for me and the only thing I use at the moment for work that's not from base is mariadb, vim and firefox (plus dependencies of course). So I don't have a lot of splashy graphics to load or anything like that and don't do video or image editing very often. But even if you do need more, the package repository has a huge selection of programs and in my experience they all just work when installed.
On the other hand I put Battle for Wesnoth on it and although that's not really a very graphics intense game it runs great on the laptop.
Overall I really like using it day to day.
Just a slight correction, if you meant the "default" as in the window manager that starts on a freshly installed system: It's not cwm but fvwm. With that said, OpenBSD ships with cwm and it's trivial to switch between the two, but they are very different.
And yes, they are very different. I remember using fvwm fondly on Slackware Linux back in the mid 90's. I had hours of fun trying to configure it to look like Windows 95 and populating menus, all in a plain text file, no gui config available! I think I read somewhere recently that fvwm is still Theo's preferred WM and that's why it's the default...
Same, well late 90s here, and yep that was my go-to on Slackware, mostly because it was quite usable out of the box. I eventually went to Blackbox, then Fluxbox, then Gnome about six months before Pat decided to stop shipping it. I went to Xfce from there and never looked back (I never liked KDE before Plasma, and 4.x is still the default in Slackware).
@jcs tests popular laptop models on his blog: jcs.org
My reservations are more about sleep (even Linux still struggles with that) and power management (ditto). If my daily driver were a tower desktop, I’d probably use OpenBSD.
I have a desktop computer with Linux just because there is certain software I need for my work. But hardware support with OpenBSD and ThinkPads will for sure be a smoother experience compared to many Linux distros.
I made my first router with OpenBSD back in 2001, for a job, it was great! But I got fired for it, because the boss didn't understand how to use a command line...
I really love the OpenBSD documentation myself though. And how the whole system is made a way that they want you to understand what its doing. And a certain nostalgia over all the familiar components that still feel the same. Its like a time machine. I was transported to the year 2001 when I made that first router all over again, or earlier. It has that familiar smell to it. Like a grandma cooking with the same recipe for 25 years. Initial Version 1.1 = 18 October 1995
Now I'm going to investigate using OpenBSD as a GUI desktop, but I have concerns about Xenocara/X11/Xorg/Xfree86, (idk what to call it) being insecure: root perms, keyloggers, etc. Can anyone speak on that ? Has OpenBSD been fixed itself, or is it still using the same flawed codebase. Are there plans to move to Wayland?
No, of course not. At this point no implementation is secure enough to compete with Xenocara anyway. OpenBSD isn't shooting to be a Linux desktop OS, so if you want Wayland, Pulse, SystemD, and the like you'll simply just have to stick with the fast-moving experimental OS's where they test new, unproven things like those listed above.
Is there even any software for Wayland yet?
As far as I know, the difficulty on OpenBSD would be input. The Wayland world relies on evdev, so they either have to patch it to use their interfaces, or implement evdev.
On FreeBSD, we have a lot of devices supporting evdev :) Including the next generation HID stack: https://github.com/wulf7/iichid (currently external, but would be merged into the system eventually)
Also there's device discovery, for which we use https://github.com/FreeBSDDesktop/libudev-devd to pretend to be udev, but I suspect the OpenBSD people might not like solutions like that :D (Actually, does OpenBSD even have anything devd-like that provides hotplug notifications?)
OpenBSD has done a release every 6 months for ~23 years.
I really don't understand comments around here where they look at a repo and say "hmmm, no updates in a while, it must be bad". There is really crappy software that updates frequently. It isn't evidence of anything. Many people are capable of committing total garbage every week, and this would satisfy your check. OpenBSD with its 6 month release schedule does pretty well by comparison with a lot of other projects.
> but I have concerns about Xenocara/X11/Xorg/Xfree86, (idk what to call it) being insecure: root perms
Pretty sure that X doesn't run as root on OpenBSD.
Yes I am aware that it's relatively easy to write a keylogger for X.
My X server under OBSD is currently running as the _x11 user.
>keyloggers
I haven't heard about anything like that for X. Wouldn't any attempts to sandbox the ttys mess things that used them up in various ways? X is at heart a terminal oriented system. What are you trying to accomplish here? Normally it turns out that it is fairly futile to attempt to isolate tasks running as the same user from one another under the Unix security model.
The artwork for 6.7 was done by Jonni Phillips!
Besides mailing list postings, there isn't too much available for now. But btrace(8) & bt(5) together describe a utility and language that's supposed to be compatible with Linux bpftrace (but an entirely different implementation).
For example, I need traffic selectors that look like this (StrongSwan ipsec.conf):
leftsubnet=192.168.11.0/24,192.168.10.0/24
rightsubnet=10.0.2.0/24,10.0.1.0/24,10.0.3.0/24
It's not obvious how to set this up in iked.conf[0]. I recall something that said this isn't possible in iked.conf, but I can't find that source now.if just leaf, maybe try with full?
also haven't tried, but looks like the built in acme-client(1) can be configured to save the full chain if you're using that for the cert issuing stuff (acme-client.conf(5))
doas sysupgrade
It is uncanny how well this works. I've never had an ubuntu upgrade work as seamlessly.We were a bit surprised to see "Fixed softraid(4) CRYPTO volumes on 4K-sector disks" in the release notes. We don't have any 4k logical sector drives but for some reason I thought that was reasonably common in consumer drives these days.
From my perspective: it's easy to modify FreeBSD and contribute to upstream, the "monorepo" thing with keeping libc and the basic utilities developed together with the kernel is nice (no stupid "glibc devs don't want to make new syscall wrappers" situations lol), the kernel is less complex than Linux, and has made different (better) technical decisions in many cases (kqueue got pretty much everything right around 2000 while it took epoll and friends years to not suck; ALSA is.. baffling while FreeBSD's sound system is good; Capsicum is the right model for app self-sandboxing; "udev populates /dev by symlinking stuff from /sys" is nuts; jails are really hard to screw up, unlike the overly flexible linux namespaces; …)
Not that Linux (the kernel) is any worse, but userspace is developed separately and it's not as slick. We're also using openSuSE Leap, Debian and Ubuntu on the desktop. Probably going to ditch the last one in favour of Debian thanks to the snap ecosystem.
Why did Netflix choose BSD and not Linux?
Licensing is often a factor.
The reasons however will not be the same for everyone.
There are more similarities than differences between the two, however one difference IMO is that BSD has a level of "quality control", especially over the userland, that Linux does not. I find that my own sensibilities as a user align better with the relatively small number of people doing "quality control" and development for BSD projects than with the enormous number of people who work on Linux -- for me, the number of Linux contributors is too many to keep track of and I find it difficult to understand what all of their sensibilities are.
But Netflix chose it because of that: https://www.youtube.com/watch?v=KP_bKvXkoC4
I think part of the reason is non-technical.
Some companies won’t use Linux in their hardware because of its license.
Similarly, some developers prefer working on BSD-licensed over working on GPL-licensed software. Some may also like working on systems with fewer developers, so that they can have greater impact on the direction of development.
Also, there are still new things being invented for BSDs (and Illumos) that aren't available in Linux. E.g. FreeBSD has Jails and Illumos has Zones which provide a complete solution for "containers" which are put together from different components in Linux which overall may not be as secure as Illumos Zones. Another one is the PF firewall. In OpenBSD they introduced security features like pledge and unveil.
Another thing is ZFS:
- on Linux there are legal problems with shipping it out of the box;
- it's far more popular on FreeBSD and Illumos than on Linux, so it wouldn't surprise me if there are bugs that will show up on Linux, but not on the other two.
Regarding the Illumos/FreeBSD "trifecta" of zones/jails, ZFS, and DTrace - I prefer LXC, I treat laptops/workstations like cattle and only run FreeBSD+ZFS where its needed, and I don't need DTrace.
Brendan Gregg can elaborate on these topics much better than I can, and his words probably carry more weight, given his involvement with Illumos: http://www.brendangregg.com/blog/2017-09-05/solaris-to-linux...
For me, I use it for things that I want to be simple or unencumbered from licensing. Any sort of storage server in my house gets FreeBSD almost automatically. OpenBSD, I keep around mainly as a learning experience - it's really a simple, well-documented operating system, and it works flawlessly on a number of different Thinkpads. There are also plenty of opportunities to participate in the development of the OS itself or its packages.
> BSDs descend from the original Berkeley Unix from the 70s
But they continue to be worked on. To wit, this announcement.
> the newer, Linux, line
Linux did not pop into existence. It traces its heritage too all the way back to Unix, which traces its way to MULTICS, which traces...
"The success of UNIX lies not so much in new inventions but rather in the full exploitation of a carefully selected set of fertile ideas..." --- Dennis Ritchie and Ken Thompson
The objectivity of it is up to debate though, some argue that it is biased/unfair.
I think it's comparable in terms of features, and many of those features even originated or have canonical implementations that started under the umbrella of OpenBSD. Also some of the most sane defaults, and simple install process, of any OS I've ever used.
I think where OpenBSD really shines though is the documentation. Most issues I run into can be solved by reading the man pages included with the default install.
Also the video linked by q3k elsewhere in this thread is a great watch.
If I personally put my own opinion on it, I don't like unnecessary use of containers because the model gives you a lot of outdated dependencies, and I'm not sure whether containing a vulnerability once it happens is that noteworthy.
Old skool "use good, secure code. update dependencies" and not focusing on containing a vulnerability produces a much safer system IMO.
For a long time OpenBSD was focussed on security through correctness and code review, so that portion is not necessarily reflected in any of the grsecurity/pax type hardened linuxes.
But OpenBSD does have things like ASLR and kernel address randomization, advanced memory protection (W^X etc) and while it doesn't have ACLs or PAM it has pledge which is a great way of restricting system call access at the program level.
I tend to look at OpenBSD as a sort of "security incubator" program, where good security ideas and practices have the chance to grow. I think that the biggest impact of OpenBSD tends to be felt in OTHER operating systems and on the internet at large.
One of the big areas where OpenBSD has pushed things forward, in my opinion, is defense-in-depth for software. They put a lot of effort into maintaining high coding standards and an emphasis on correctness. They've been active in the area of exploit prevention and detection-- they were the first to really do W^X, they've been using ProPolice by default since forever, they randomize memory addresses, etc. But they're also very active in exploit mitigation-- that is, if we start by assuming that a program IS going to have a security bug, how do we limit the damage? OpenBSD has invented or popularized techniques like privilege separation, their "pledge" and "reveal" systems, and various other forms of sandboxing.
There's also the crypt side-- their work on cleaning up OpenSSL to create LibreSSL has been an incredible service. OpenSSH has been adopted EVERYWHERE. Their work has done a LOT to reduce the amount of unencrypted traffic going across the internet generally.
Depends on what you're doing with it -- but the base system ships with many things that you would want to use, and it's definitely concievable that you'd only run with OpenBSD software.
Web servers? OpenHTTPd. Mail wervers? OpenSMTPd. Proxies? Relayd Firewalls? pf Routing? Depends on what you need, but there's probably a daemon for that.
You can get a lot done without relying on ports. (Also, the ports are somewhat vetted, as far as I can tell.)
[0] https://undeadly.org/cgi?action=article&sid=20160107075227
Since they keep userspace stable, they generally have more stable programs running there as well.
For instance, systemd has has multiple remote exploits in a time window when the default OpenBSD base install has had zero.
Moving up the stack, OpenBSD often rewrites or simplifies important daemons (like httpd), and those tend to have closed or mitigated security holes before upstream exploits are discovered.
OpenBSD focuses on securing things at the source level. Hence all the compiler tricks to mitigate memory safety bugs, API for programmers to limit syscall exposure, privilege separation within individual programs, drive to avoid unnecessary complexity so the source is readable etc.
Why is their clang/llvm stale in a new release?
In the cases where OpenBSD (and FreeBSD) don't yet use clang, they use the most recent GCC version that was still GPLv2 licensed. GPLv3 is not acceptable to OpenBSD in the base system.
More recent versions of GCC are provided in the ports system, for users to install. Those are not used by the base system. The system compilers are (mostly) for building the system. They don't even search in regular paths users might expect, like /usr/local. If users need a general purpose compiler, they can install one from ports.
The situation with clang is similar. OpenBSD uses the last version of clang/LLVM that was still BSD-licensed. Now LLVM uses the Apache license, which is not acceptable to OpenBSD in the base system. (However, FreeBSD is okay with it.)
What happens in 2030 or 2040?
Users can install a newer gcc (v8.3) from packages/ports.
Newer LLVM releases are licensed with APL2.0, and that doesn't sit well with OpenBSD:
http://lists.llvm.org/pipermail/llvm-dev/2017-April/112300.h... https://marc.info/?l=openbsd-misc&m=147503691302850&w=2
So they're using the last LLVM release with an acceptable licence.