OpenBSD Innovations
openbsd.org
openbsd.org
By creating OpenSSH and the fact all fortune 500 companies use it, I would say every year, the foundation should be bringing in around 1 or 2 million. It is time these companies really give back.
And while I am here, hardware vendors should open up their source, looking directly an Nvidia.
b) part of what makes it great is that they don't
Not that there is anything wrong with raising money, but the ideology behind openBSD don't really fit if they go for profit
Industry wide adoption?
A moral people could operate communism successfully. Unfortunately, most people are not even remotely moral. Pragmatically moral (in plain view, but not behind closed doors), for sure, but innately good -- definitely not.
Contributions and reciprocity are praiseworthy of course, and we should all aspire to this. But that doesn't mean someone is ethically wrong for choosing to accept a gift freely given without giving one in return.
Because of the endless amount of expectations.
All cultures I'm familiar with recognize that someone who is well off taking advantage of a tragedy of the commons is unethical. The particulars vary by locale but my impression is that it is universal that the degree of condemnation increases the wealthier the person exploiting the system is.
When I accept a friend's hospitality and don't reciprocate, I am taking their time and resources. When I take five free samples at the store, I ruin it for others who come later.
When I download an open source GitHub repo, I am burning 1¢ of Microsoft's money.
Perhaps my definition is off? If so I would appreciate a pointer about the correct terminology.
I suppose it might be different in the case of a one-time fork. It still seems like there's an ethical obligation to contribute back if you are well off and you benefit from something. I think there's a meta, societal level tragedy of the commons to be found there. But if you aren't actively benefiting from maintenance efforts then perhaps it doesn't qualify as a direct tragedy of the commons.
If nobody pays for that cost, then the work will never get done in the first place, and we won't have these resources.
While the other examples seem good for illustrating the point, this one has it backwards I think. Microsoft worked very hard to be in this position. They did this on purpose and this aspect is essential to their success:
- GitHub did everything they could to capture the market by being free to use and by leveraging the network effect
- Microsoft bought GitHub at a point where it was already widely successful in this aspect, so they fully knew what they were buying
Capturing the whole open source market is part of their business model. I don't like they've done this and I don't get to choose where authors host their code. Even the authors themselves might not have felt free to choose something else because of the network effect. It's only fair Microsoft pays for the privilege. GitHub being free is a feature for Microsoft.
> When I accept a friend's hospitality and don't reciprocate
I came to realize that you don't need to return the favor specifically to the person who helped you. Things work as long as you help anybody. The loop will be closed by someone who will eventually help the person who helped you (or has in the past). Actually, it doesn't events need to be a loop. This is very powerful and quite relaxing because you can be chill both for helping and for receiving help, and it has the potential of working very well and be very enjoyable.
In short: take (from anybody) as long as yougive (to anybody)
(Of course, in a friendship, some reciprocity is necessary, if things only go one way, it doesn't work)
Another pithy way people express this is with "pay it forward" https://en.wikipedia.org/wiki/Pay_it_forward
Many cultures do in fact work that way. And while modern American culture views the idea of taking everything you can and only giving back what you are contractually forced to in a more positive light, the term freeloader still has negative connotations.
Your point about the gap between the words of a license and an ethical expectation is well taken. But why put that gap there at all? It's going out of your way to make sure that people have the choice to screw you.
That’s not a thing in American culture. Maybe you are referring the low trust culture of international commerce, which just happens to be centered in the US.
Not users, companies that make bilions. We call that shameless.
Or you can charge money for your product.
> Use GPLv3 or AGPL then. If you want companies to "give back" when they use your code, put it in the licence.
Seems like a poor choice given that projects like MongoDB try out AGPL for this reason and then later switch to nonfree licenses like SSPL. OpenBSD is not interested in that—whether its attempts to raise funds through goodwill work out or not, OpenBSD will always be free software.
A company doesn't have ethics. It's sole purpose is to make a profit.
One of the primary outcomes that people want from corporate structures is profit, but that is not the structure's "sole purpose", either in law or practise.
Corporate structures can't have ethics because they are not people (legal constructions of "person" vs "natural person" notwithstanding).
https://www.nytimes.com/roomfordebate/2015/04/16/what-are-co...
https://www.forbes.com/sites/jerrybowyer/2017/04/25/what-mak...
https://money.usnews.com/investing/articles/public-benefit-c...
You need to make it about utility. Open sourcing some package or contributions to an existing package is giving you returns far beyond your investment. A community will help maintaining, improving, growing your code. Perhaps even competitors will chip in. (If they don't, well, their loss..) It's going to be a net positive.
Yet people still need to work somehow, and UBI is more of an ideal that will never happen in capitalism society driven by profits of few shareholders at the expense of everyone else.
Now the current trend is replacing people with self service machines, they aren't getting UBI, they are being shown the street.
You mention nvidia support, others are hopeful for a better filesystem and wifi as well.
Citation needed, they've raised nowhere near that amount.
https://github.com/bob-beck/foundation-web/commit/483266cece...
That's certainly what they meant ;)
OpenBSD has supported 11ac for several years, and has the iwx(4) driver for modern Intel WiFi cards. There's also support for Broadcom FullMAC, bwfm(4), which is on e.g: Apple Silicon machines.
HaikuOS also has a port of OpenBSD's iwm/iwx drivers.
FreeBSD just recently announced they've started porting the OpenBSD iwx driver.. from Haiku.
https://freebsdfoundation.org/blog/laptop-support-and-usabil...
Lets assume goals like OpenBSD's. If one also wants money, they can make the software paid, free for many categories of users, source-available, and derivatives (mods) allowed. The paid part can be regular payments or one-time per release. Probably an exception to mods allowed saying they can't backport paid features from new versions to old versions but independent creation is allowed. From there, companies will pay to support it or they'll determine it has no market value.
There are proprietary, source-available RTOS's on the market for real-time and secure use. One source said, but I haven't verified, that INTEGRITY RTOS royalty-free was around $17,000 minimum per product or company. Another said LynxOS with communications middleware was around $50,000. A number of small vendors exist showing one can generate sales if their product is marketable. Tons of companies selling firewalls, load balancers, etc like OpenBSD is often used in.
https://en.wikipedia.org/wiki/Comparison_of_real-time_operat...
So, if money is important, they can change their terms to demand money some or all of the time. If the license says "free giveaway!," expect most people to treat it that way. I imagine quite a few of the developers have exactly that expectation. They are motivated by the joy of writing great code, not money.
I would also add that it indirectly kills the vast majority of programming jobs - nobody is ever going to get paid to create a JPEG decoder as everyone can just use libjpeg. Nobody is ever get paid to write a new kernel as everyone can just use Linux. Very few people are going to get paid to work on a new database as you can just use Postgres...
Once there's a good enough open source solution in a field, in the long run it will out-compete commercial offerings, even it's overall a worse package, as it's some guy's free time project and is created on a $0 budget.
Programmers work for free, end users get a worse product, companies make trillions.
Not that it negates your point in any way, but lots of people are paid lots of money to write Zircon (Google Fuschia's kernel) which is intended to replace Linux in many scenarios.
Yes I am aware it is shipping on Nest Hub.
What matters after almost 15 years, with a couple of major rewrites, is when it will ship on anything else besides Nest Hub.
What could you mean by that? It's an extremely successful model organizationally and technically.
> it indirectly kills the vast majority of programming jobs
All software kills the vast majority of jobs - think of all the jobs there would be if we had no software. Anyway, are we short of programming jobs?
Efficiencies create new, higher-value possibilities than, for example, JPEG decoders.
> It's an extremely successful model organizationally and technically.
There are technically impressive open source projects - e.g. Linux, and most of them have people paid to work on them full time. Those are the exception, not the rule. Most open source projects are some guy's hobby, done for free in their free time. Hobbyists solve problems they find interesting, and often ignore a lot of the "gruntwork" required to make a technically sound package. > Anyway, are we short of programming jobs?
Yes. Especially good ones. > Efficiencies create new, higher-value possibilities than, for example, JPEG decoders.
I don't see it - a large portion of programming jobs have devolved to gluing together a bunch of open-source libraries, doing the boring gruntwork to actually make them work, and dealing with the inevitable hell, caused by using 500 components that were never designed to work together.OTOH some commercial software only solve problems that make money, and ignore the technically sound part unless it makes money. E.g. the enshittification of Google, Windows or Facebook, and friends, from a product that worked to a product that nobody asked for. All the technicality spent in tracking users, more ads, etc.
These are a lot of commercial software that are not much more than a repackaging of open source software and a UI layer (ffmpeg, for example).
And most proprietary software becomes completely unavailable when the company making it goes out of business. At least with the open source software, if there is interest in it, someone else can pick it up, if the original creator stops maintaining it.
> a large portion of programming jobs have devolved to gluing together a bunch of open-source libraries, doing the boring gruntwork to actually make them work, and dealing with the inevitable hell, caused by using 500 components that were never designed to work together.
And you think that would be any different without open source? A large portion of programming would still be gluing together a bunch of components, but instead of open source libraries you would have proprietary libraries, where if the documentation is inadequate or wrong, you have no option of looking at the source code to see what it actually does. Or in-house libraries that were designed for some specific purpose that doesn't match yours at all, and are very low quality, because they were made under a tight deadline, and no one ever went back to pay the tech debt after the MVP was released. Or maybe instead of a library you make API calls to some SaaS with no SLA and barely any documentation.
It also applies to proprietary software.
E.g. exactly how Linux was created? ;)
90% of everything is crud:
Yes
> required to make a technically sound package.
No. What they don’t do is take the time to turn it into a product used by a general audience. Technical soundness is usually something corporations don’t have time for.
Maybe I misunderstand, but computers make us much more efficient: writing, graphics, computation, communication, storage and retrieval of information, searching information, machine control, ... for a time, 'computers' were rooms full of people doing computations.
Think of the software stack that runs HN. What would we do? Write letters to a journal for publication? Gather in a room someplace?
If this is the way computer science evolves, it is safe to say that it evolves at the same pace as life.
The concepts of compilers, operating systems, databases, file systems, computer graphics all evolved from the 60s to the early 90s.
After that, it was mostly scaling.
And the open core licenses of nowadays are nothing more than a rebranding of those kind of license models.
I bet you didn't use any Microsoft product. /s
> some guy's free time project and is created on a $0 budget.
> Programmers work for free
You seem to be completely out of touch with what FOSS is.
The amount of relevant FOSS hacked by some teenager for free in moms basement is negligible. The largest contributors to the Linux kernel are IBM, Intel and Oracle. Nobody there works for free.
How much upstream do you think BSD gets from Sony and Apple, besides a few crumbs?
clang was sponsored exactly to allow Google and Apple to take a compiler and not be legally obliged to upstream their sauce.
Nowadays clang has mostly replaced most proprietary compilers on surviving UNIXes, and embedded OSes, how much of those downstream changes land on upstream clang? It is mostly volunteer work improving ISO C and ISO C++ compliance, despite all the money being made by those folks.
Sponsored is an understatement. It was pretty much entirely funded by those two, so if the goal was to leech on volunteers, that would be a pretty bad move by those companies.
Which is exactly what happened after clang got mature enough, GCC was expunged from their platforms.
Apple first, followed by Google about a year later.
Note that nowadays, Apple clang has its own column on cppreference, Google is focused on Carbon/Rust/Go, and both cases most of the contributions are on LLVM side, not clang and ISO compliance.
P.S. you focus on ISO compliance. Could it be that the actual user base does not really care about it as much as the rest of the aspects of the compiler (features, correctness, performance) and thus deprioritized by everyone. I don't consider clang abandoned by Google or Apple.
Also clang was only one example of who profits and who puts into the work, like the endless number of PhD students contributing to LLMV or MLIR.
If you think it's the long tail of endless contributions is what makes a production quality open source project like clang tick, well, we disagree...
(In fact such PhD students are often the prime beneficiaries of the work by commercial companies, because they get to build their research stuff on top of LLVM.)
This thread keeps having its goal posts moved around, first is was an example, then got the spotlight of being only about clang, then I pointed out about Apple/Google original purposes, then it was something else, and yet another one.
Just head off to /r/cpp that is where hunches are coming from.
Have you at very least filtered by C++ clang only related contributions instead of LLVM ones?
Most likely not, only clicked here https://github.com/llvm/llvm-project/graphs/contributors and came right away to reply.
To contextualize, I have been one of those PhD student in the exact same space who used clang/libtooling in a past life, as well as a maintainer of a sufficiently popular corporate open source projects, and I do have my own hunches on how much exactly random "volunteer contribution" is often worth (hint: it is mostly extra pain for the maintainers to review).
The irony is if Apple closed it up for themselves as proprietary software in the first place, they would not have received that criticism. If you start open sourcing, you will be treated with a much different, IMHO unfair, benchmark.
Before LLVM, much of the PL research prototype would be done on Java with some research JVM crap because it was hard to do it in the real world with native code, so I could the academics beneficiaries not among the abused.
Looked at another way, open source means that instead of a bunch of programmers getting paid to write multiple implementations of the same thing over and over, so the programmers that otherwise would be doing that can instead work on new innovative things.
In an ideal world, all software would be open source, and programmers would spend all their time improving said software for everyone. The problem is I don't know how those programmers would be compensated for their work. In many ways, open source software is a public good, since anyone can benefit from it[1], so an argument could be made that OSS should be publicly funded (i.e. paid for by government grants). However, I am doubtful that the government could do a good job of allocating resources to open source projects. Then again, I don't think the private sector is doing a great job of that either. Just look at how many resources are put into showing people ads.
[1]: And it has the interesting property, that unlike most public goods, the cost does not scale with the number of people who use it, or have a limit on the number of people who use it.
And if a project does want to be open source eventually, they can already license their code that way.
Same idea as for patents vs trade secrets.
This is bad in the long term because alternative ways of doing things open other avenues of investigation and development.
But all we get are improved versions of hammer when everything is made out as a nail.
Even well-established software can have meaningful alternatives. Look at ripgrep. While it hasn't replaced grep as a distro default, it's still being used by folks that find it a better solution for them.
Companies make billions? Good. It's time to tax them and use the money for the benefit of everyone.
if there's no technical reason why libjpeg isn't suitable, I'd consider it a huge waste of human life to create another. if there is a good technical reason to build a new one, then somebody will do it for free or somebody will pay for it to be made.
I think the system is working.
The reason this doesn't really matter in a truly noticeable way, and why I'm also not really concerned about AI taking programming jobs, is that demand for software is so much higher than supply. You can go to any random local small business, and within five minutes, you will identify software demand that is not being met adequately, or at all. They use Excel for their inventory and constantly have problems with it that need to be manually resolved. Their website doesn't work right and nobody knows how to fix the broken links. They have somebody who does paychecks by hand. One person is in charge of scheduling holidays in a shared calendar. And so on.
These companies would pay developers to fix their issues if they could afford them. As programmers become more productive, whether that is by using open-source software instead of writing things manually, by using LLMs, or by other means, there is a downward pressure on salaries. But that doesn't mean that jobs disappear; it just means that more companies now have access to developers they could previously not afford.
We make less money doing some in-house processes for a small, local business than writing a database for a multinational corporation. But on the upside, we improve the lives of people who actually matter, rather than making some billionaire even richer.
What I do find massively problematic is that the developers of the open source ones often aren't paid. That should be impossible, companies are profiting off of free labour and that's wrong. If anything open source developers should get paid more per accepted PR, they provide more value and probably better quality code.
There's still many paid offerings for databases, operating systems (esp RTOS's), and image processing. That includes libraries. The companies are usually profitable with some making a fortune on the products. Quite opposite of what you said.
The question you should ask is: why?
Next question: how do I use those lessons to sell and give away something like OpenBSD?
Open Source achieves the exact opposite of what you say. It allows people to direct their talent and effort to solving high-value problems instead of low-value ones. Instead of writing a JPEG decoder, you can create a professional photography workflow or a pre-press pipeline. Instead of writing the low-level bits of a database, you can create an enterprise SaaS.
Yes, Open Source infrastructure is hard to compete with. However, it is super easy to out-compete companies that are wasting their engineering resources re-inventing the wheel.
Of course, there is always the option of doing the basic stuff better of course and being rewarded for it. Some will.
And, while this reply is already too long to get into it, the majority of Open Source is written by people being paid to do it. So, wrong there too.
this doesn't make sense, how can you expect hardware companies to do this, where the moat???
Hardware companies need their devices supported by as many operating systems as possible, especially if those devices can be used in servers, desktops less so. Apple is pretty much the exception.
You can still support linux while still having closed source
Open source is a pragmatic arrangement where developers embedded in the industry can collaborate and share code; often explicitly supported by the companies they work for. It has worked very well for decades and there's no urgent reason to change anything.
For example, Damien Miller, who puts in a lot of time on OpenSSH, is employed by Google. Employing key contributors is how the industry supports OSS.
Yeah that's just confirmation bias. How often do we read about key open source libraries that are being maintained by one random dude in his free time, said dude's free time dries up, and suddenly everyone is in panic mode on how to get funding to him.
It'd be much nicer if every tech company above X amount of yearly revenue would be required to kick in 1.0% (0.1%? 2.5%?) of their profit into a foundation. That foundation then would put out bounties or contracts for open source project maintainers. The priority (= monetary value) of these would be decided on by a mix of community voting, open source expert panel, and commercial interest, split ⅓/⅓/⅓.
If you were paying someone to full-time maintain XZ or Heartbleed, or whatever, it would have their singular attention.
[0]https://www.mail-archive.com/xz-devel@tukaani.org/msg00567.h...
> I haven't lost interest but my ability to care has been fairly limited mostly due to longterm mental health issues but also due to some other things. Recently I've worked off-list a bit with Jia Tan on XZ Utils and perhaps he will have a bigger role in the future, we'll see.
As Microsoft has been demonstrating for decades, there is no direct correlation between budget and quality.
It was a fork of Tatu Ylönen's SSH, so I think it would be more accurate to call it forking, not creating.
Of course, they've created a lot of new code as well since 1999.
I'm not going to sit here shilling for the corporates, but at the same time I think you need to put yourself in their shoes.
The stance you are taking is essentially the same as if a chugger stops me in the street and asks me to sign up to regular donations to $charity because "its only $1 a month". To which the inevitable answer is "sure, and there are a gazillion other charities, so I'm supposed to give $1 to all of them because its 'only' $1 a month" ? I will choose which charities and how much to donate to on my terms, thank you very much.
And its the same with corporates and open-source. Your favourite pet-project might be OpenBSD and you might think $evilCorp should give more to them ? But what about all the gazillion other pieces a typical $evilCorp will use ? OpenSSL ? curl ? ping ? traceroute ? In your idealistic world a corporate would give $1m to each of them I guess ?
The fact is the corporate lawyers know you've released your software on open terms. I'm sure they would be happy to buy an OpenBSD license ... but OpenBSD made their bed, as it says on their website "OpenBSD policy is simple — OpenBSD strives to provide code that can be freely used, copied, modified, and distributed by anyone and for any purpose. "
And before you say "well, they could donate instead of buying licenses" ... let's just say you would be naïve. Buying licenses is a "simple" standardised procurement exercise in most corporates. Meanwhile giving donations typically is a far more bespoke process involving far more administrative burden. And the smaller the recipient of the donation, the more admin burden required.
As others have pointed out $evilCorp does contribute indirectly to open-source. Many of the core maintainers and contributors to open-source are employed by $evilCorp and file their PRs to the open-source projects on their employer's dime, often whilst sitting in their employer's offices, using their employer's computers and infrastructure.
Indeed. The observation is that generally for most corporations the charities are "nobody" and the amounts are "$0". If you, an individual, behave this way then you're a bad person. The argument is merely that the corporate "people" are also being bad people.
> In your idealistic world a corporate would give $1m to each of them I guess?
Why make this ridiculous strawman? If we said "some reasonable amount, distributed among their dependencies" why is that unreasonable? Do we have to draw out the whole picture before these people even attempt to consider what a reasonable contribution could be?
> The fact is the corporate lawyers know you've released your software on open terms.
Yes, and corporate parasites will therefore extract the maximum value while providing the minimum in return. History repeats itself.
> Buying licenses is a "simple" standardised procurement exercise in most corporates.
If you think about this for a few seconds you will realise it is not a good excuse. If ping/openssl/whatever had a "recommended contribution" listed on their "corporate licensing" page, then there is no administrative burden required whatsoever. You just pay whatever they ask, same as a license. You think the price is too high? Make up one.
So why is there a high administrative burden? Simply, because corporates themselves place a high value on "paying the bare legal minimum". In other words, they over-value the virtue of being cheap and unsociable. If your reaction to this is "that's just how business is", then good for you: according to your understanding, business is antisocial, and should be discouraged.
Our system rewards those who take as much as they can and give as little as they can. The tradeoff here is that each entity having a certain amount of freedom makes us happier since we can be different and choose to allocate our resources in different ways. But asking corporations to give back when they don't have to is like asking your neighbours to pay more tax because the roads need repairing.
You can't appeal to individuals, so the solution is simply to raise the bar on what that minimum is. The way to do that with software is to use copyleft licences. Support copyleft projects in any way you can and reject permissively licensed projects where possible. If we had stuck with copyleft we'd be so much better off.
There's no reason for them to do so while maintainers continue to be willing to work for free and governments take a lax stand on security breaches.
I attended a memorial on Zoom and people said he also created the building blocks that permitted Mobile IP (IP on your cell phone) to work.
If you knew John, then my condolences. We're all using the things he built, every day.
There's also execute-only memory and BTI/IBT on modern Intel/AMD, and ARM machines, enabled by default. Including a significant amount of ports development work to make the larger software ecosystem ready for this.
EPAN is already supported, hardware is now arriving, it's used if available, but the idea that execute-only was less important than PAN was probably misguided.
I used to do some OpenBSD ports work, and even got a tiny patch into the base system. I love OpenBSD! I don't have an axe to grind here! But it is not above reproach, and I think this site is overall harsh but fair.
https://freshbsd.org/openbsd/ports?q=firefox
Tor browser bundle is also being updated consistently.
Their 'unusual' approach to security might be a distraction they don't need. But maybe it's the only way to hope to pull it off? Maybe they can't do it the GLAM (Google, Linux, Apple, Microsoft) way with OBSD's resources.
What's the use case for this?
EDIT: further down is one example:
> RETGUARD is a replacement for the stack-protector which uses a per-function random cookie (located in the read-only ELF .openbsd.randomdata section) to consistency-check the return address on the stack. Implemented for amd64 and arm64 by Todd Mortimer in OpenBSD 6.4, for mips64 in OpenBSD 6.7, and powerpc/powerpc64 in OpenBSD 6.9. amd64 system call stubs also protected in OpenBSD 7.3.
Many things, retguard uses this for per-function random cookies, for instance.
The bootloader uses this mechanism to pass data to the kernel.
https://www.openbsd.org/papers/hackfest2014-arc4random/mgp00...
While not the same, this is a SECCOMP-based Linux alternative (and it can even be used to restrict pre-compiled binaries).
https://nanovms.com/dev/tutorials/applying-sandbox-security-...
Why should I expect a program to set allowed syscalls/filesystem paths? Why would I trust that it will set itself the right permissions? What is allowed should be set externally from the program, similarly how I can map filesystem volumes and add capabilities to a Docker container [1].
I'm not familiar with BSD and I only used it a couple times out of curiosity. What am I missing?
[1] https://docs.docker.com/engine/security/#linux-kernel-capabi...
so the observation is that programs tend to have a startup state where they need access to files and a run state where they don't. so pledge/unveil is a mechanism for a program to inform the os that it no longer needs access to files/syscalls and any future access should be considered a hostile takeover. please kill me.
Because the admin or owner will know FAR less about what a complex program needs at all times, and when it will be safe to drop privs. A database might be tested for a week and then it has a special snapshot thing done for the monthly backup and you did not foresee this, whereas the coders would know what perms are needed in order to do these dumps. Hence, you can't set perms just once before starting, and as a user of said software, you can't expect to just make a quick test and then design a fully working harness for it either.
¹ e.g. https://github.com/FRRouting/frr/blob/3f290c97e8325bd9db9363...
Emulated TLS isn't particularly great though in any case :/
Alternatively, debug in a VM where the security features are disabled.
> especially the memory randomization ones
I have never once relied on memory addresses being reproducible between program runs. In an era of ASLR that seems like a really bad plan. Plus multithreading breaks that for malloc'd stuff anyway.
Does anyone have such experience? Is it ok?
I left it ultimately because it had way worse battery life than Linux on my T480s and I also wanted to play some games with steam.
I never used OpenBSD. Why is it incredibly slow?
[0] https://www.mail-archive.com/source-changes@openbsd.org/msg9...
Your experience will be a lot more variable on any other laptop.
Worth remembering that OpenBSD has no support for bluetooth, which many users often require on a laptop.
If you have a 'must have' device for your desktop environment that's bluetooth, then yes, it makes OpenBSD unviable for you; but OpenBSD isn't viable for every use case.
Yes, and desktop, especially laptop, is an example.
Yeah, it was annoying when I tried to pair my mouse- but you know… a wired mouse isn’t that big of a deal.
One thing that brings me the most displeasure about internet discourse about operating systems is this idea that they all have to do all the same things.
Thats homogeny by another name; the point of different operating systems is different trade-offs.
You've clearly had a different experience with Bluetooth, and that's good for you, and neither of our experiences is universal, but I think there are plenty of people willing to use a desktop OS without Bluetooth.
Heck, my new car only uses bluetooth to do phone pairing, then it switches to wifi to talk to phones, because that's clearly better than Bluetooth.
[1] for which there is an easy workaround in the form of class compliant usb audio cards that output to bluetooth.
I run openbsd on my laptop, a thinkpad x260 with an ssd, and it works great.
The problem is that all the user facing stuff in macOS isn’t BSD. It’s Apples proprietary APIs. So while macOS was originally and technically based on BSD, almost none of that is exposed to their users.
So they’re technically correct that macOS / Next was based on BSD. But also completely wrong to recommend macOS as a comparison to OpenBSD.
BSD stuff has a complicated history due to the lawsuits in the 1990s.
NetBSD and FreeBSD were based on 386BSD. OpenBSD was a fork of NetBSD by one of the NetBSD founders (Theo deRaadt)...
Also OpenStep is an API rather than an OS. So macOS contains both NextStep and OpenStep code.
After NeXTSTEP 3.3 there was OPENSTEP 4.0.
OPENSTEP 4.2 is the last operating system release prior to Rhapsody.
Yes it’s confusing.
Considering how obsessed with UX that Jobs was, I don’t get how he thought the naming conventions were a good idea.
NeXT looks good in the logo, and they spent $100,000 on it.
FWIW, I like it but it is confusing and made harder by the fact they also didn’t stick to their own conventions much of the time.
AFAIK there isn’t any BSD code in Windows however the original TCP/IP stack in Windows was a port from BSD. But we are talking about the early 90s here and it’s long since been rewritten by Microsoft (or so they say, but I have no reason to disbelieve Microsoft)
Microsoft did leverage BSD code for common network utilities (ping, tracert, ftp, etc.), which still exist in Windows today, although Microsoft's preference is to leverage the "better" equivalent PowerShell cmdlets where available.
[0] https://en.wikipedia.org/wiki/Spider_Systems
[1] https://web.archive.org/web/20151229084950/http://www.kuro5h...
EDIT: If you want to hunt for BSD code, try taking a look at NT4[2].
[2] https://github.com/lianthony/NT4.0/tree/master/private/ntos/...
https://en.wikipedia.org/wiki/Windows_Vista_networking_techn...
I recently checked out KDE 6 for the first time last year, it really is as easy running as 'pkg_add kde kde-plasma kde-plasma-extras' and then reading through the local pkg-readme file, that said if you're not familiar with OpenBSD it won't be like other systems where it comes preinstalled and preconfigured.
https://brynet.ca/article-l13gen2.html
There's many popular window mangers and applications you can install using the package tools, as you'd expect, including Chromium and Firefox, but you can quickly search here: https://openbsd.app/
A lot to like about openBSD; doas is my daily driver on linux, openbsd man changes are incredible, but I'm not going to mess about recovering disks just because I forgot to plug my laptop in.
1. Power management may not be as good as with Linux
2. No HDMI sound support
3. No bluetooth
4. You need to be comfortable with config files and man pages.
5. Probably fewer applications in the ports tree (I have all I need).
If you are fine with the above, OpenBSD is the finest OS I've used so far. I've never run into random issues like wifi connectivity, audio issues like with Linux."Hello, I'd like to by a CARP license please."[0]
It didn't need the executable to end up in a single block either, every individual section could end up in a different location. Compilers produced large numbers of sections to facilitate this process.
Amigas could, of course, have position-independent code. Use BSR and BRA rather than JSR and JMP; use LEA label(pc),A0 / MOVE.L (A0),D0 instead of MOVE.L label,D0 .. but the limits for PC-relative addressing are +/- 32k so you need to get creative to reach code or data further than that.
More commonly, Amiga executables had relocs, a list of fixups to apply. The code on disk in each hunk was written as if all hunks were loaded at address 0. There was then a list of relocations at the end of each hunk, saying what offsets in that hunk need the base address of another hunk (including themselves) added there, to fixup the absolute address reference.
This is relocatable code, but not position independent code. If I used an MMU to make that relocated code appear at another address, all its absolute addressing would be wrong at that new address.
Position-independent code can be shared by multiple proceeses, and appear anywhere in their address space, while only existing once in memory
The difference is that, with position-independent code, it can be loaded once, no relocations needed, and the same pages of code can be mapped into hundreds of processes' address spaces, each at a random location. Doing it like resident Amiga programs would mean loading to a specific address (even if random), and then it'd have to remain at that address across all processes, which makes it difficult to have different combinations of shared objects in the address space.
> that's why they're claiming them as their innovations?
I think they are just listing their specific implementations as innovations, their particular approach. Too many of what they list was definitely not an original idea, so they can't possible be suggesting otherwise. At least, I would hope not.
Landlock was released in Linux 5.13, in 2021. Pledge was released in OpenBSD 5.9, in 2016. As far as I'm aware, Pledge is the first of its kind.
I found the announcement email for Landlock posted to the lkml[1] where the author compares the project to Pledge. There's also his talk[2] from 2016 if you're interested. I was certain landlock predated pledge, as I thought the website or earliest talk was from late 2015, but I am less certain now, indeed I seem to have been wrong in my claim.
As for either being the first, at the very least Seatbelt from Apple has a paper dated 2011[3] and was released with macOS 10.5.
[1] https://lwn.net/Articles/700607/
[2] https://archives.kernel-recipes.org/document/landlock-lsm-un...
[3] https://www.ise.io/wp-content/uploads/2017/07/apple-sandbox....
https://www.openbsd.org/papers/tame-fsec2015/
I'll concede that's less likely and I'm probably just wrong and misremembering though.
This is so plainly, and verifiably untrue, that it's almost funny. The patch series and kernel commit adding Landlock to the Linux kernel even references OpenBSD pledge(2)/unveil(2) as a source of inspiration.
https://github.com/torvalds/linux/commit/17ae69aba89dbfa2139...
https://lore.kernel.org/linux-security-module/20210422154123...
I just found that email and the talk for the project myself and noted the author referenced pledge in another comment, but thought that could be due to the earlier OpenBSD release having gotten press, making it useful as a point of comparison.
I had honestly thought the landlock website or an earlier talk had pre-dated the release of OpenBSD 5.9, but I appear to have been wrong about that.
The implementation of OpenBSD predates many safer systems languages but I think OpenBSD should now start moving to a checked variant of C or a safer language like Rust/OCaml/Odin/Zig/Something else.
The conversion can start with some OpenBSD user space programs. I notice a steady stream of C related security fixes in the OpenBSD changelog. Many of these could have been probably avoided if the implementation language was more “safe” by default.
I doubt that this is going to happen but I think it is fair to point out that using C does give you some additional security headaches by default.
Everyone is busy jumping up and down and bitching about reinventing the wheel in Rust but no one has even taken the time to rewrite the simplest of Unix tools in Rust.
Not to mention OpenBSD has a rule that "base builds base" and the Rust compiler is a bloated monster that would fail that most basic task.
So where is the benefit?
Parent wasn't about rust specifically. Just something safer than C
Under development for longer than a decade and still unstable
Maybe catching up to 40+ years of development takes a little bit of time?
Sure. But that's not OpenBSD's problem, is it?
Someone is “putting up”, just need someone to merge uutils and the OpenBSD kernel to see what it starts to look like.
Maybe this is the next part of the “put up or shut up” mantra- but we’re getting closer.
The parents irony is not lost though. C and perl are both quite dangerous in their own ways, lots of implicit assumptions; its ironic that a safety focused operating system would lean in on those languages.
"The uutils project reimplements ubiquitous command line utilities in Rust. Our goal is to modernize the utils, while retaining full compatibility with the existing utilities."
It would be nice if they commit to replacing more than just Linux tools. There are numerous quirks/additions to the GNU utils that the BSDs don't want or need.
https://github.com/sharkdp/bat (Haven't used this one, but it's pretty popular)
Where is 'grep'?
https://github.com/BurntSushi/ripgrep Use this one often. It's fast af to search a directory of source code.
Where is Korn Shell?
https://fishshell.com/blog/fish-4b/ Fish is now entirely in Rust, very popular, and to be frank basically a step above bash or ksh.
All I know is that I'm increasingly replacing classic unix cli tools with rust ones that are just better and faster.
Then mentioned elsewhere, but this isn't as big of a problem on OpenBSD, but would be fore NetBSD. The Rust tools don't support all the supported architectures. This is where BSD philosophy diverges. With NetBSD, if you got a PDP-11 or a toaster with a chip, they are more than happy to make NetBSD run on it, and the NetBSD team also don't necessarily have a requirement for physical hardware, if there is an esoteric chip with QEMU support, they will happily try to support it. OpenBSD will maintain support for an architecture so long as someone is willing to maintain it and owns the physical hardware (which is why it supports less than NetBSD).
This is also why NetBSD is sort of "stuck on " gcc. I believe they would like to move to clang, but can't due to architecture support.
Some more addition to the first paragraph: OpenBSD to a degree takes this to a whole other level than the other BSDs. OpenBSD maintains their own fork of X11 called xenocara and window manager, cwm. In theory, you can have a pretty basic and functional system from boot code to window manager with all of that code being code maintained by the same team, the OpenBSD developers. They even have their own version control system called got.
Hardware that isn’t supported by many of these “newer & safer” languages.
Zig isn't even 1.0. Odin,DasBetterC have not much uptake.
OCaml has a GC which is a non-starter for kernel, it could be used in user space sure.
Then I guessed they looked around, and saw oh we can do it on x86 too, the pax way.
Genuinely curious, and it’s been years since I’ve looked at it.
I guess addressing the network stack is work that still remains?
Can't say if they still do, but FreeBSD for the longest time used to list the floppy driver being one of the modules using GiantLock and that was a problem for what I guess was about zero people.
But if one asks fbsd devs if they still have it, they would have to answer yes, even if the rest of the OS runs super great without locks anywhere else, so the binary question of "is there somewhere something that for some time could possibly call the giant lock" isn't very interesting, but rather "will it do it for the tasks I imagine I will run on my machine?" and that would have to be a more fine-grained question with some research, just like the locks in the kernels are getting more and more fine-grained.
OpenBSD still uses CVS, and I suspect its development will benefit greatly (actually accelerate) from the switch, once it eventually happens.
(FWIW, there several other *BSD's.)
Unless you're spinning up a MUD.
I would say FreeBSD is somewhat like Ubuntu is to Linux - easy to get setup, works for more people.
There isn’t anything like OpenBSD in the Linux world - where the primary focus is system correctness, even at the cost of user convenience at times.
(Emphasis mine.)
Typography matters for readability. For the minimum get a decent line height and limit the line length to 60-ish characters.
Are OpenBSD not taking (potential) users seriously? User experience matters, and the readability of the docs is part of the UX.
(sorry for the rant)
And for readability I already have my browser set up with my favorite fonts and font sizes and background/foreground colors. How can I expect every website to guess my preferences perfectly, as opposed to all the other people with different preferences. So I just set it up one time in the browser UI and it just works everywhere.
If a user is not able to navigate a font/color selection UI but wants to give technical advice to the OpenBSD team, I think it's that user not taking OpenBSD developers seriously.
As a result, you can disable all syscalls for your program with one simple request: 'exit()'
There are alternative to syscall. For example, writing to shared memory. Shared memory as IPC is hard. And you need some syscall to set the memory up.. .
Or if you're trying to solve a problem, what are you doing that pledge() doesn't cover? For that matter WASM.... would do that, so why not use it?