OpenBSD/arm64 on Apple M1 systems
marc.info
marc.info
I guess I’ll keep an eye out for a second hand M1 mini, or wait for a refurbished mini to show up on the Apple online store (in Ireland). Would love to add another RISC system to my home fleet of machines running OpenBSD (and a couple of FreeBSD).
Edit: this could of course also be used for running a server on a M1 mini!
If you have supported hardware (and that’s a bit if and caveat; smaller than it used to be, but still quite large), then everything just works. Even little things like the built-in screen brightness buttons, just work regardless of if you’re in x11 or a terminal (same with volume buttons), because it’s designed as a complete system rather than a distribution of otherwise unrelated open source projects.
These days I’m on macOS, mainly because of the hardware but also a few pieces of software that I have hard time replacing (Scrivener and Mathematica).
- "Linux® Binary Compatibility"
- "Describes the Linux® compatibility features of FreeBSD. Also provides detailed installation instructions for many popular Linux® applications such as Oracle® and Mathematica®."
https://docs.freebsd.org/en/books/handbook/book/#preface-ove...
I wasn't able to find that exact reference in the docs of the current release (using a mobile device at the moment). However, there is a very useful forum thread for anyone interested. It's not a straightforward install, but it's definitely possible to install/use Mathematica on FreeBSD.
https://forums.freebsd.org/threads/freebsd-13-0-runs-mathema...
Compare:
https://help.ubuntu.com/lts/ubuntu-help/index.html
https://docs.freebsd.org/doc/13.0-RELEASE/usr/local/share/do...
It of course helps that nothing ever changes in BSD-land. After 50 years of development, they are largely feature-complete and are not going to be doing massive changes just for the sake of massive changes. As such they get much lower levels of "documentation rot", things rust a lot slower when nothing ever changes and as such it's a lot easier (and more productive) to build comprehensive documentation.
But the amount of churn in linux is insane, Ubuntu has used three completely different init systems in the 15 years since I started using Linux seriously. For java development, I routinely see and use StackOverflow answers from like 2009 that are completely valid still, and yet answers from that era are completely useless for Linux, which has invalidated that acquired-knowledge twice since then. You can pretty much sysadmin FreeBSD out of the handbook, and if you need to search then an answer from 2009 is usually still valid.
It's absolutely a cathedral-vs-bazaar situation. Cathedral is presented as a negative in that metaphor, but the cathedral ensures enough stability that you can start Having Nice Things instead of just constantly scrambling to rewrite everything every time a vendor thinks they've built a better mousetrap.
A lot of useful material with near-official status is kept under the Linux Documentation Project, https://tldp.org/ They have a git repository at https://github.com/tLDP/LDP
There are some cases of real churn in Linux but they're rare. The new init systems and such come with plenty of useful features that simplify many administration tasks: the reason for people being so unsatisfied with them is that they bring lots of what's effectively cowboy-coded hacks and prototype-quality code in order to enable these features. But rewriting all of this stuff from the ground up with a clean, Unix-like design (or rather, Plan9-, Limbo- or Amoeba-like, given that Linux now supports the needed foundational features for these) while preserving its feature set would involve more rather than less churn.
I‘d be curious to hear more about what you're referring to, if you were willing to expand. What foundational features are new to Linux that would be really useful for cleaner init system (etc.) designs?
ZFS would like a word. FreeBSD, for all intents and purposes, pioneered the adoption of ZFS for the everyday enthusiast.
I'm yet to dive in, I've only dabbled.
It's definitely a bit heavier than other filesystems but it's one of those things where I can't imagine setting up a Linux/Unix system without it anymore.
I wouldn't exactly classify ZFS as a "new" feature though. ZFS dates to 2004, OpenZFS dates to 2006, and OpenSolaris dates to 2010. 20 years is pretty well into "mature technology" by most standards, even 16 years is very mature by software standards.
Or video accelerated YouTube.. Or Microsoft office..
Really, I love OpenBSD, but I only really use it for (internet) networking these days, FreeBSD looks after my storage, and it's all proxmox with ubuntu 20.04 vms running k8s for apps.
Someday I'll switch back, but working as a freelancer with a lot of different customers bsds are just too painful to run bare metal (def works with ssh/mosh/tmux though!)
You can get GPU accelerated YouTube videos in OpenBSD, provided you have a supported GPU in the first place. You have to use Firefox and enable gfx.webrender.all and layers.acceleration.force-enabled in about:config. I've been able to get up to 2Kp60 smooth as butter on Intel HD 530 graphics in OpenBSD 7.0. 4Kp60 plays and drops a few frames, but my monitor is 2K so I have no need for 4K playback anyway.
https://www.openbsd.org/faq/faq13.html#enablerec
https://www.openbsd.org/faq/faq13.html#webcam
https://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/www/chromium...
If you are an OS & BSD aficionado, you like to spent time working with OpenBSD because <reasons> ok, but otherwise I would advise against it.
A bunch of us have a trail of old macs that are weird to use because of the whole system is stuck on the last supported OS, which happens to be the most bloated for that hardware, and doesn’t receive updates anymore. Moving to another simpler system altogether makes it a better proposition. As a matter of choice, BSD is more familiar than linux in many ways.
M1 laptops are not in that position yet, but in 2 years I’d totally imagine getting rid of macos on sub machines.
I've got the same questions about macOS to be honest
Not to mention consistency. On all other competing platforms consistency across applications tends to be rather bad.
- It’s UNIX, and has been since Snow Leopard, that makes some development tasks easier. YMMV
- I like the UI (personal preference)
- MS Office stuff is native
- I’ve heard the fan on my M1 box twice in a year
- Can run x86 Docker images via emulation, usually seamlessly
Docker is running in a Linux VM of course on a Mac, so there’s a slight performance hit.
Even all the SIP stuff doesn’t get in the way, in my experience.
Mark Kettenis' from the OpenBSD project is responsible for upstreaming Apple M1 support for u-boot, and has been collaborating with the Asahi Linux team.
As a practical / project management matter, how do they manage to support a diversity of hardware? What proportion of their resources is spent just keeping up with hardware?
Are they short of money or developers, or is the famed portability of it just not as true as it used to be?
I love raspberry pi but they are definitely not as "open" and drop-in compatible as most people think.
That seems to be a problem with most ARM devices, so may not be specific or the fault of the Pi people.
So, yes, 'non-Debian' which (Debian) includes Raspbian, not 'non-Raspbian' which (Raspbian) precludes Debian.
Raspbian is probably closer to Debian than Ubuntu is, but it's still quite clear that you're not on Debian.
https://www.debian.org/derivatives/ https://wiki.debian.org/Derivatives
But it doesn’t surprise me that it just works since Ubuntu is a commercial distro. They even sell products for the Raspberry Pi version.
I used to use Ubuntu MATE on pi, but when the Pi4 came out it took a long time before it was supported.
If so, I don't know what it's like on the MacBook or MacBook Pro, but on my Mac Mini, I can reliably say that the battery life is dismal ;-)
Possible typo? The Mac Mini does not have a battery.
That being said, they use coreboot and hardware with open/well known drivers. I actually bought a Librem 14 and installed Windows on it for my spouse, and surprisingly, everything on it worked out of the box.
This guy does a lot of testing https://jcs.org/
I'd be really interested to hear if any arm64 or other RISC architecture laptops are useable! M1 is a step in that direction, it would be really surprising to me if it worked well beyond basic support yet however. Asahi linux took like over a year to get to that point but it sounds from reading that link that they're pretty gung ho on getting it working for 7.1 which is amazing to hear. It sounds like other hardware support in those laptops is the big thing.
Fun miscellaneous stuff: SMP on intel architecture is disabled on openbsd for security reasons, so looking at alternatives to make things go fast with guarantees for that is big right now.
doas sysctl hw.smt=1
I do this occasionally when running larger compilations (LLVM or similar). If you want it enabled permanently you can add hw.smt=1
to /etc/sysctl.confApple-sanctioned alternative operating systems such as VMware ESXi have also caused problems in the past and should not be used at all anymore because Apple does not seem to play well with others on that level (by releasing uncoordinated firmware updates).
You may have a point, unless this insinuated physical damage from altOS on Apple Silicon never appears.
> Apple-sanctioned alternative operating systems such as VMware ESXi have also caused problems in the past and should not be used at all anymore
VMWare currently supports running their bare metal hypervisor on (at least) Intel Mac hardware (except for Mac Pro due to COVID straining VMWare development, and not because ESXi causes Mac Pros to detonate), but does not consider any Mac with VMWare an enterprise-grade setup.
> because Apple does not seem to play well with others on that level (by releasing uncoordinated firmware updates).
Please accept some humble advice: since there are three and only three reasons to update anything: bugfixes, pressing security issues and the last a need for new features, generally, one should never update firmware, and this is especially true the moment the update appears. In the first case, unless the bug prevents booting, it couldn't be less important, secondly, worrying about firmware security issues is silly, because if you can't physically prevent access to the computer, it's pwned anyway no matter how secure the firmware is. And in the last case, if you have a functioning system in production, then it doesn't need new features, get out of here with needing new features on production. The notion is absurd on it's face.
Not true. Apple hired some of the best security experts in the world to build a system that was resistant to pwnage even if the attacker has physical access to the machine:
https://mobile.twitter.com/XenoKovah/status/1425800637166596...
Secure Boot can indeed be disabled, but that will change the TPM PCR values, so assuming a standard BitLocker configuration, the TPM will fail to unlock the BitLocker key. So if you try to disable Secure Boot on such a machine, you will be unable to boot unless you have the BitLocker recovery key.
This is just completely wrong. You're peddling bad 20-year-old advice that hasn't ever been completely true, and especially not anymore.
First, firmware updates often patch vulnerabilities that would allow attacks without physical access. Most obviously, vulnerabilities in the networking hardware can allow attackers to take control a machine by sending crafted packets. But other hardware issues can also, e.g., make it possible for untrusted code to perform a privilege escalation of some kind. You want firmware updates to protect yourself.
Second, Macs/iOS devices and PCs—through the Secure Enclave and TPM, respectively—offer really good protection against physical access attacks. They verify the integrity of boot components and are only able to decrypt the system volume if they detect an untampered boot chain. Further, they can lock down direct memory access to protect powered-on systems from bypasses to user authentication. This is why nowadays, if a thief steals your laptop and you had the hard drive encryption with hardware security features on (on Windows, if you set up with a Microsoft Account, this is enabled without any further action by the user), you can feel fairly secure that even a technically savvy thief cannot access your data. Firmware updates can fix vulnerabilities in these security systems.
Above, you said, "worrying about firmware security issues is silly, because if you can't physically prevent access to the computer". That's not someone else's claim, it's yours. If you didn't intend it to be your claim, you erred in expressing it, since that's what it conveys. That's the claim the other poster refuted. I simply don't understand you when you say they "disagreed with someone else's argument"? I control F'd the parent posts and found no such claim made by anyone, except you.
Your (apparent) claim is obviously wrong for the reasons already pointed out by the other poster, including that there are firmware-level attacks that do not require physical access. Some of these vulnerabilities can be fixed by firmware updates. So, if possible, it makes sense to promptly apply each patch that will fix such a vulnerability.
I see this fantastical claim thrown around on all kinds of forums, of course never with sources cited.
There shouldn't be any potential for thermal damage from software. There should be very simple low level circuitry on the board that cuts power after a critical temperature is exceeded, regardless of how the OS or firmware are set up. Many consumer devices have something like this so that they don't melt down and hurt people. Are you trying to say that Apple isn't including basic safety features anymore?
In fact, my hottest running Macs in my collection, the G4 PowerBooks, run cooler under Linux than OS X 10.5
I still think you're grossly overstating the risks of modes of failure that just don't happen that often.
Unfortunately, the most exotic alternative OS that Macs support is BootCamp and that’s not yet for ARM so hack away while booted into Darwin (macOS) using a VM. I recommend Zephyr for big time hacking fun! :)