OpenBSD needs your help - call for donations
undeadly.org
undeadly.org
http://www.openbsd.org/cgi-bin/man.cgi?query=strncpy
http://www.openbsd.org/cgi-bin/man.cgi?query=malloc
They don't just explain what strncpy & malloc do. They also explain how to use these functions correctly and securely. With examples.
Compare that to glibc's manuals (pretty typical of what you can find under Linux):
http://linux.die.net/man/3/malloc
http://linux.die.net/man/3/strncpy
Clearly OpenBSD folks care.
A post in-thread linked to the online man pages, here's the FAQ (http://openbsd.org/faq/index.html). Another good documentation example is the man page for the filesystem layout (http://www.openbsd.org/cgi-bin/man.cgi?query=hier).
For this release, tmux (http://tmux.sourceforge.net/) is in the base system, and there's a new security-audited SMTP daemon (http://www.openbsd.org/cgi-bin/man.cgi?query=smtpd&sekti...). :)
Assuming it is a short file, it would require only one block read (the block pointed to by the directory entry). The broken symlink method may be faster (one less disk read, a lot less parsing overhead) but is much less human-friendly. And the added speed would only be meaningful if the file got checked more often than at program start.
The code is in /usr/src/lib/libc/stdlib/malloc.c . I didn't know OpenBSD's malloc was under the "beer-ware license". :)
Reading a symlink is one system call. Reading a file is three or more system calls. There is an overhead cost for each system call -- and if you're going to be doing something for almost every process, you might as well be as efficient as possible.
Sorry, but I just can't see why it would be a better option.
As cperciva already noted below, readlink() is one syscall, whereas reading and parsing a configuration file is many syscalls and much more code. This is malloc we're talking about here, not general purpose user-configurable software.
This is not to say anything bad about OpenBSD which I have no doubt is a great system, just that the comparison is somewhat unfair.
It's also nice to use a finely crafted piece of software that doesn't feel like it has been bolted together haphazardly (like your typical Linux distro).
That said, OpenBSD is probably the most organized project out of all open source projects close to the same size and scope. They release like clockwork, they do not (or try not to) rush new features out just so they can make the next release, and there really is an uncompromising drive for perfection.
I would love to contribute code to the project, but I have to be honest: though I'm by no means a slouch programmer, those guys seriously outclass me, and I'd be completely out-of-my-league.
Having perused bits of Linux source from time to time, I don't feel that's so much the case outside of OpenBSD.
I think the OpenBSD project encompasses a lot of the values that a majority of the users on this site would agree with.
On the other hand it lacks many fancy features. For example it filesystem is somewhat dated compared to ZFS or BFS. But that's the price to pay to get a stable, secure, and well polished operating-system.
PS: OpenBSD's manuals are awesome.
"To ensure that novice users of OpenBSD do not need to become security experts overnight (a viewpoint which other vendors seem to have), we ship the operating system in a Secure by Default mode. All non-essential services are disabled. As the user/administrator becomes more familiar with the system, he will discover that he has to enable daemons and other parts of the system. During the process of learning how to enable a new service, the novice is more likely to learn of security considerations.
This is in stark contrast to the increasing number of systems that ship with NFS, mountd, web servers, and various other services enabled by default, creating instantaneous security problems for their users within minutes after their first install."
But Ubuntu is locked down by default now. And their security responsiveness seems pretty good.
One of the ironies is that the "only two remote holes in the default install" bit, while impressive compared to, say, Microsoft, is still two more than Red Hat and Ubuntu have shipped over the same period. (Disclosure: that's from memory. I'd have to look up dates on remote exploits to be sure.)
it's 2 remote holes in 11 years. ubuntu wasn't even around 5 years ago.
But even so: Ubuntu has had zero remote holes in the default install in 5 years. I'm getting hung up on a divide by zero bug somewhere, but I think that works out better if you want to be pedantic about this stuff, no? :)
Seriously: it's a dumb marketing slogan, and it means next to nothing. In point of fact over the last 6-7 years OpenBSD doesn't have a particularly distinguished security record according to their own metric. It's better than Microsoft.
If, say, vendor A, gave US$ 1 million to the OpenBSD project, vendor B could pick the improvements and incorporate in their own proprietary products for no cost, creating a competitive advantage unless the improvements are so narrow they only apply to A's products. If, however, vendor A donated the same amount to a GPL-licensed project, vendor B could not take unilateral benefit from the money invested and would have to either use the improvements from within another GPL-like product or not at all, effectively negating any competitive advantage it could acquire from A's investment.
I think the AT&T legal imbroglio had little to do to the comparative success of the GNU/Linux system.
That's often a good thing. For headless installs, a Python and GTK-based install doesn't cut it.
"pkg_add pkgname" fetches a package and its dependencies once you choose a mirror, anyway, and using text files rather than menus to configure the system means you can keep your configuration in VC, configure a typical system by just applying patches, etc.
> using text files rather than menus to configure the system means you can keep your configuration in VC, configure a typical system What configuration? We were talking about installers and anaconda can use kickstart files to automate the installation. And of course they can be kept in a VCS.
The other day we were talking about the need for social skills in large projects mostly because of CK's message exchange on LKML about BFS. Theo is a very clever guy and does some truly outstanding work, but I would not like to work with him on anything important. I love what I do and I have no need to get burned.
The thing I remember the most was he had long spider-like fingers and could touch type.
I was at a company called Rainbow Software in Calgary.
it seems they really are having fun !!!