19 ms·
OpenBSD 6.0 released
- justin66 10y agoThis seems like a big deal: One thing to note: this will be the last version of OpenBSD to be pressed on CD. The project will now focus on internet-only distribution, giving much more flexibility in the release schedule.
- jasonkostempski 10y agoIt does? I was under the impression the only reason anyone still did that was to give something physical to donators.
- ue_ 10y agoPerhaps I'm the only person using computers in 2016 who only installs OpenBSD via CD :-)
- jasonkostempski 10y agoI still install all my OSes via CD/DVD but I burn them myself from an ISO.
- Touche 10y agoI haven't even owned a computer with a CD/DVD drive in over 10 years. One thing that drives me mad is that computer manufacturers still distribute recovery images as DVDs, even though the computers the discs are for don't have drives.
- SixSigma 10y agoUSB CD/DVD drives exist
- Touche 10y agoYeah I know, it's just annoying to own something you'll need once every 2 years or so.
- dnzm 10y agoIn fact, I prefer to own something that I use once or twice a year (and between different computers at that), and then store in a box somewhere, rather than having a piece of computer suck in dust and whatnot all the time. Not exactly a counterpoint to what you were saying, but somehow related.
- SixSigma 10y agoSuch as re-installation DVDs
- agumonkey 10y agoI only do to enjoy the pleasure of old ways. Interacting with CDs and CD drives reminds me of when it was cutting edge. Tray mechanics, the speed intake of spinning motors. Even the latency and seek sounds. And somehow, the (almost since it's on DVD RW) immutability. In some ways, the sheer speed of SSD is ... boring when you're not in a hurry. ps: a bit like vynil lovers who take their player out for similar reasons.
- jasonkostempski 10y agoI do that too. I also like to imagine a post-apocalyptic, no-internet time where I have a generator, PC, BSD disk and the knowledge to use them to rule the new world while everyone else is stuck on the "Activation Required" screen.
- PhantomGremlin 10y agoFortunately OS X isn't as bad as Windows. I haven't tried the most recent version, but for previous versions I have successfully installed OS X from a USB stick, without needing any internet access at all. However, the OS X binaries are signed. So, when the key expires, people are SOL. I had this problem, and easily re-downloaded my various older OS X versions. But in the general case it's quite disturbing: http://www.macrumors.com/2016/03/03/older-os-x-installers-broken-by-certificate/ http://www.macrumors.com/2016/03/03/older-os-x-installers-br...
- aruggirello 10y agoReminds me of my old faithful Amiga, and its 3,5" floppy drive...it made a distinct, almost musical sound. You just turned the machine on and that famous splash screen would appear, then the empty drive would start ticking regularly, waiting for an 880Kb disk. As soon as a disk was inserted, you could hear its typical seek noise while the system booted, track after track...
- pjmlp 10y agoAnd the famous click of death.
- anthk 10y agoI install it from the ramdisk, much better.
- GTP 10y agoHow? How can you make a ramdisk resistant to a reboot?
- clarry 10y agoYou don't need to. It's created a-fresh for you when you boot bsd.rd. After you're done installing, you don't need the ramdisk as you'll boot your newly installed bsd kernel.
- GTP 10y agoAre you referring to the upgrade method described here [1]? [1] https://www.openbsd.org/faq/faq4.html#bsd.rd https://www.openbsd.org/faq/faq4.html#bsd.rd
- jimktrains2 10y agoThe last couple installs of any OS I've done have been a few off of USB and the rest off PXE.
- dmm 10y agoDon't forget the awesome stickers!
- groovy2shoes 10y agoYeah, and even the packaging. The latest release (5.9) was the first "official" OpenBSD CD set I ever bought, and I was astounded by the quality of the set, from the packaging and inserts to the discs themselves. I don't know why, but I didn't expect it to be so... professional. I pre-ordered this release, too. I like being able to help out the OpenBSD project financially and get something nice out of it. Oh, well. RIP, OpenBSD CDs.
- throwaway7767 10y agoCDs are read-only, whereas a USB stick has (generally insecure) firmware that can be modified. So in a setting where the user is concerned about persistent USB malware, it can make sense to use them. It's a niche concern of course, but I suspect it's a little bit more common in the OpenBSD community than in many others. Of course it shouldn't be too hard for those users to build their own install boot CDs with the tarballs for installation, just skip the big package sets and install them later if the whole won't fit on the disc.
- soccerdave 10y agoWhat happens if your cd that comes in the mail is swapped out for a different cd by a malicious actor?
- kabdib 10y agoYou check hashes (from the web site) after you copy the files to media you trust, and then any tampering is really interesting . . .
- aruggirello 10y agoYou can find well-known hashes to check your install media with online (assuming you can trust the media because it comes wrapped up in a nice package is a bit naive...). What you cannot check however, is a USB key firmware (ring-0?) malware, that lives completely outside of disk space, and thus is beyond reach, but might have limited (or even complete) access to the system it is plugged to. CDs and DVDs (don't know, but perhaps SD/compact flash/etc. cards too?) are thus the last mainstream media that come with 'no firmware attached'.
- joyfulgerard 10y ago> What happens when a malicious actor leaves physical evidence all over? They get caught.
- justin66 10y agoThe flexibility in the release schedule strikes me as very useful. The CD sales business is admittedly less interesting.
- Gracana 10y agoOne nice thing about the physical CDs is that they're trustworthy source for the release's signify pubkeys (which you can compare with the ones on the website.)
- angry-hacker 10y agoWhat if someone tampers the CD before it is delivered to you?
- ghshephard 10y agoIt is - I did not know this. I purchased a USB-DVD player for the sole purpose of getting a physical delivery of OpenBSD. Sad to see it go by the wayside.
- cupantae 10y agoI can't tell if this is a joke.
- nayden 10y agoit is not a joke. http://www.openbsd.org/lyrics.html#60f http://www.openbsd.org/lyrics.html#60f
- orbitingpluto 10y agoHow did I not know about these songs? How?
- ghshephard 10y agoWhich part - buying a USB/DVD player just for OpenBSD? In three+ years that's literally the only thing I've used it for. Nothing else. The part about OpenBSD 6.0 not being on CD? I have no idea - this is the first I heard about it. Couldn't really find anything on the site either other than the song lyrics referenced above...
- mytec 10y agoI enjoyed receiving the CD package and the associated artwork.
- bch 10y agoI thought the (forced) schedule was considered a feature, to allow users to know when to expect updates and to have developers know when work had to be finalised for inclusion in the release.
- yegortimoshenko 10y agoNow, that OpenBSD runs on Xen (and, by extension, on Amazon EC2), is there an official AMI?
- microcolonel 10y agoIf I understand correctly, this also means that the main excuse for it not being supported on DigitalOcean is now alleviated. :- )
- misframer 10y agoDoesn't DigitalOcean use KVM?
- microcolonel 10y agoI stand corrected, seems it's KVM. Seems some other people were confused. I've been told in other places that it's Xen. OpenBSD has had working virtio-blk and virtio-net drivers since about 5.3/5.4/5.5 IIRC. hmm...
- pyritschard 10y agoDO relies on KVM which OpenBSD has supported for a good while. If you are interested in something similar - including price-wise - to digital ocean with support for OpenBSD, I encourage you to try https://exoscale.ch https://exoscale.ch
- riffraff 10y agoI am not an OpenBSD user, but as in every release I am happy to check the lyrics for the release song, this time we got 6 so it's awesome :) http://www.openbsd.org/lyrics.html#60a http://www.openbsd.org/lyrics.html#60a
- corv 10y agoThat song[0] brings a smile to my face. Keep up the great work OpenBSD! [0]: http://ftp.openbsd.org/pub/OpenBSD/songs/song60a.mp3 http://ftp.openbsd.org/pub/OpenBSD/songs/song60a.mp3
- jrcii 10y agoYay! I get to spend 5 hours figuring out how to update the syntax for my pf.conf rules.
- SSLy 10y agoWhat? Where do you see notes about it being changed?
- SixSigma 10y agoGets PF for free, complains.
- jrcii 10y agoGmail is free, would you be happy if they updated it and your email didn't work anymore? I love OpenBSD but they constantly change the rule syntax for pf, which invalidates huge swaths of forum posts and other online documentation, even published books. The man page doesn't contain every conceivable explanation and example for every scenario either, nor could it, so that is also not a solution. Whether or not the price is free, the use is not, as it requires hours of valuable time to implement.
- pfortuny 10y agoYou have to ACT proactively to upgrade OpenBSD, unlike gmail.
- SixSigma 10y ago> Gmail is free, would you be happy if they updated it and your email didn't work anymore? I would shrug, meh and do something else. I've had my lifestyle made illegal a couple of times. Perspective.
- chriscappuccio 10y agoThe last and only major PF syntax change was, what, 5 years ago now ? 4 years ago ? Any other changes are relatively minor and reflect other changes, such as features being removed or added.
- octotoad 10y agoFarewell sparc32. You will be missed by the retrocomputing geeks.
- rjsw 10y agoStill supported by NetBSD.
- chriscappuccio 10y agoThrough emulation. How useful...
- rjsw 10y agoNetBSD/sparc runs on real hardware as well as emulators.
- MustardTiger 10y agoNot supported, "supported". Big difference.
- dmm 10y agoVAX too. Looking forward all of the platforms not supported by LLVM are doomed.
- willvarfar 10y agoOne big step in this release is the mandating of W^X by default. > "Unfortunately there is important third-party code, such as just-in-time compilers, that still uses mmap(2) to make memory both writable and executable, so for the time being, we have to arrange ourselves with it." If a program wants to JIT on OpenBSD, how should it do it in a secure, OpenBSD-approved way?
- avsm 10y agoUse mprotect(2) on the region of memory that the program wants to make executable. http://man.openbsd.org/OpenBSD-current/man2/mprotect.2 http://man.openbsd.org/OpenBSD-current/man2/mprotect.2 This is good portable programming practise anyway...
- willvarfar 10y agoSo they should create a writeable mmapping, write the code into it, then change it to W^X using mprotect? How does this stop an attacker doing the same via ROP? ADDED: The approach that comes to my mind is that they could have two processes. One process has the sourcecode, and pages where it can write code. The other process can execute the code. The code updates performance counters which the JITing process can read, so the JITter has feedback to know what to optimise. However, this sounds a large architectural change, prevents programs JITting programs they generate on the fly, and causes the JIT to lack behind somewhat. On the Mill CPU (disclaimer: I'm on the Mill team) the CPU can change processes ("turfs" in Mill terms) using a "portal" function call. This alleviates somewhat the performance concerns, as the JITted program can call into the JITer process synchronously and cheaply.
- DasIch 10y agoIt might not make such attacks impossible but it will make them more complicated and that by itself should cause some attackers to fail. Isn't that by itself worth doing?
- dmm 10y ago> How does this stop an attacker doing the same via ROP? Wait, isn't that backwards? Doesn't the use of W^X necessitate the use of ROP? Right now a JIT has lots of memory that is W&X so you just need a memory exploit to inject some code and then find a way to jump to it, no need for ROP. But if you implement W^X this won't work because now you can't inject code with just a memory exploit, you also have to set it to executable with mprotect(2). So instead you use ROP, and inject only data which includes jumps to carefully selected sections of code in libc, etc, that implements an exploit. I mean you could probably use ROP to run mprotect, but by that point it's pointless because you're already running code on the system right?
- mrb 10y ago"To deter code reuse exploits, rc(8) re-links libc.so on startup, placing the objects in a random order." I love this defense in depth, buried in the release notes... https://www.openbsd.org/60.html https://www.openbsd.org/60.html
- armitron 10y agoThis is pretty much useless. Attackers have moved on to using information leaks in order to determine memory layout and placement of objects. So in practice, this doesn't really deter anything. Information leaks are everywhere.
- CraigJPerry 10y agoI don't know why you're being down voted. We've had ASLR in Linux for years and various attacks have been successful. The string format attack is the one I remember most clearly which basically renders ASLR useless.
- gkya 10y agoObviously it's not useless. Not all attackers have agreed collectively to use differents methods. Also, if it leaks in multiple points, it's better to start from a hole instead of letting it all go before finding a patch big enough for all.
- aomix 10y agoPretty much any security measure in isolation can be bypassed. So you need to stack as many as are reasonable on top of each other to limit the attacker's toolkit. This change is basically free and makes certain things more difficult for attackers, so why not?
- aweinstock 10y agoAttacker-controlled format strings are very convenient bugs, but they can't do everything. Consider the program: int main() { char buf[20]; fgets(buf, sizeof buf, stdin); printf(buf); return 0; } An attacker writing to the program's stdin can read at offsets to the stack (e.g. "%42$x"), read the contents of arbitrary non-null memory (e.g. "ABCD%5$s", where ABCD is a 32-bit memory address, and 5 is the positional parameter corresponding to the start of buf), and write an arbitrary value to an arbitrary address (e.g. "ABCD%38x%5$n", to write the value 42 to address 0x44434241). A significant limitation of the vulnerability in the above program is the attacker can't, in a single execution of the program, read a value, then do computations on it locally, then write a value based on those computations. This flexibility is needed in order to bypass ASLR.
- zzzcpan 10y agoTalking about security, I'm hoping for a bound-checking memory-safe C compiler to eventually made it into something like OpenBSD or FreeBSD and be used by default for all ports and packages. Almost no software there would suffer from the overhead, and OpenBSD doesn't even promise or try to be very fast, it's a perfect place for it.
- pedrocr 10y agoIs a "bound-checking memory-safe C compiler" even possible in the general case without implementing a new Rust-like language?
- ape4 10y agoThere's the convention where you put char stuff[0]; at the end of a struct and malloc has necessary.
- david-given 10y agoIt certainly used to be in the old C89 days. I can't comment about C99 and above (because I don't know the spec well enough). I know there used to be a gcc patch which did exactly this. The way it works is that the C89 spec defines memory in terms of objects, and it's illegal to even think about a pointer that doesn't point into an object (or to the byte after). That is, it's not just illegal to dereference it, you're not even allowed to create one. So, because you know that every pointer must point at an object (or NULL), you encode the object and length of the object into the pointer. So pointers end up being a tuple of three words: object, object length, and offset. Now you have enough information to bounds check all accesses while still allowing pointer arithmetic within an object. Of course, in real life, people do all kinds of wrong things which de-facto C allows but which de-jure C doesn't, such as pointer arithmetic between objects. But the spec does allow bounds checking. (I abused this to implement a C to Perl compiler.) Incidentally, fun fact: the 286 memory segmentation system supports mostly-bounds-checked pointer accesses in hardware.
- nanolith 10y agoYes. But, you typically have to use a theorem prover to build up static checking for functions, and then enforce proof obligations on callers to said functions. If done in a system like Coq or Isabelle, the proof obligations become a parallel markup to C that is used in conjunction with the source code to enforce policies. Bounds checking is one policy -- and a relatively easy one to implement at that -- and other policies can be stacked. Take a look at VST for an example already in the wild. I'm currently working on a somewhat different approach that does not have the severe license restrictions that CompCert has. http://vst.cs.princeton.edu/download/ http://vst.cs.princeton.edu/download/
- deleted 10y ago[deleted]
- Johnny_Brahms 10y agoFor those of you who are looking at a reason to play around with openBSD, there might be some progress at getting it to run at the Raspberry pi 2 and 3: http://marc.info/?l=openbsd-cvs&m=147059203101111&w=2 http://marc.info/?l=openbsd-cvs&m=147059203101111&w=2 Probably not going to happen, but it runs on some other ARM7 SBCs. Mine is running FreeBSD currently, but where is the geek cred in that?
- nayden 10y agothis is currently being worked on as I type this reply :)
- deleted 10y ago[deleted]
- Johnny_Brahms 10y ago_nice_. For my pi I want something that I don't have to think about. A colleague pwned my rpi because I hadn't updated it in ages. OpenBSD seems like a better choice...
- peatmoss 10y agoI've wondered about OpenBSD on the NTC CHIP computer. I have one that I haven't quite gotten around to doing anything with that I'd love to OpenBSD-ify.
- chriscappuccio 10y agoIt is supported.
- peatmoss 10y agoOh, well, that makes things easy then. Do you know off hand which image one uses?
- chriscappuccio 10y ago
- nn3 10y agoIt's good that they have their priorities straight. No more Linux binaries support (who need compatibility anyways?), but instead you get 5 songs sung by the project leader.
- IntelMiner 10y agoIf you're running OpenBSD, likely you're running it for the features it provides (security and code correctness) If you want to run Linux apps, run them on your Linux box and use your OpenBSD machine to firewall it off
- olp2 10y agoOnly the "Goodbye" song is sung by Theo de Raadt.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- chriscappuccio 10y agoIf your priority is to run Linux binaries under OpenBSD, you could improve the support, perhaps even implement 64-bit emulation. But since you didn't do that, and nobody else wanted to, the unused crap was removed instead. Imagine that???
- MustardTiger 10y agoHow dare they remove the code for a "feature" that hasn't worked in several years! The horror!
- 20yrs_no_equity 10y agoI love BSD and would like to use it, but we're kinda in a Linux world. Question: If I am building a custom hardware device (and we will be in the future, I believe) can we run OpenBSD on it using the ARM port, but also invoke binaries created for linux? It appears that support was removed. In the near term I need to build for Linux, But eventually we'll be able to target our own hardware, and one of our toolchain items doesn't support BSD right now (and is closed source, though we are considering an open source alternative.) Any thoughts?
- chriscappuccio 10y agoLinux emulation was only complete for one port - i386. Not amd64, not armv7, nothing else. And, it was emulating a very old Linux kernel interface. What could it have possibly done that you can't do by simply compiling the program using the native toolchain?
- rjsw 10y agoLinux ARM binaries require the OS to map a page at the top of the address space that is shared between the kernel and userspace, you would need to check whether OpenBSD ever included this in their Linux emulation. The support for this isn't in NetBSD either but there has been a request to add it in order to run a Citrix app.
- bigato 10y agoThey removed Linux emulation support in 6.0.
- protomyth 10y agoI've never really had a separate /usr/local partition, but it looks like that might not be such a bad idea given the upgrade guide: https://www.openbsd.org/faq/upgrade60.html https://www.openbsd.org/faq/upgrade60.html
- Esau 10y agoI like having separate partitions (or slices) for everything. The guy who introduced me to UNIX did it so he could mount certain filesystems "ro" or "noexec". He also told me that partitioning can help avoid inode exhaustion but I really doubt that is an issue with modern filesystems. I still partition with NetBSD. It just feels right; even if not necessary.
- protomyth 10y agoOh, I partition too, but I do /, /usr, /var, /var/log, /home, /tmp, /opt (yeah, yeah, I know), and then anything server specific (mail, maybe www). I just don't do the /usr/local.
- Esau 10y agoWhen I set up NetBSD, I create /, /usr, /var. /tmp, and /home. I have never create a /usr/local partition but I can see value in it is you want /usr itself to be read-only.
- protomyth 10y agoI do /var/log because of some bad experiences with runaway programs - samba went psycho on me in the 3.x days.
- Tharkun 10y agoI never run out of disk space, but I frequently run out of inodes. It's definitely still an issue. And if you don't stop to think about when you're creating your file system, it tends to bite you in the arse at a later date.
- Theizestooke 10y agoI'm trying to use the austrian mirror, ftp5.eu.openbsd.org, but I'm getting empty directories or "Permission denied" when trying to access the packages folders http://ftp5.eu.openbsd.org/ftp/pub/OpenBSD/6.0/packages/ http://ftp5.eu.openbsd.org/ftp/pub/OpenBSD/6.0/packages/
- fredmorcos 10y agoHave you tried ftp2? I had problems today with one of them (can't remember which worked and which didn't). EDIT: http://ftp2.eu.openbsd.org/pub/OpenBSD/ http://ftp2.eu.openbsd.org/pub/OpenBSD/
- hackuser 10y agoThis is a good opportunity to ask: Can anyone recommend a laptop I could put OpenBSD on and be fully functional for busy workdays (i.e., when I need to spend 100% of the day being a knowledge worker with a reliable tool I don't have to think about, and 0% being a sysadmin trying to get their tool to work)? On one hand I've seen threads on HN and Reddit saying how OpenBSD works flawlessly, esp. on various Thinkpads. OTOH I read in-depth reports like these, by OpenBSD insiders who know far more than I ever will, and even their results seem insufficient: * https://gist.github.com/reyk/80dca43c8bcfa76d2a7ff147ea64d442 https://gist.github.com/reyk/80dca43c8bcfa76d2a7ff147ea64d44... e.g., "The [wlan] connection is sometimes not stable or the firmware shows errors when switching the AP configuration. But stsp@ is actively working on improving it!" * http://www.tedunangst.com/flak/post/Thinkpad-Carbon-X1-2015 http://www.tedunangst.com/flak/post/Thinkpad-Carbon-X1-2015 * https://marc.info/?l=openbsd-misc&m=145275871714024&w=2 https://marc.info/?l=openbsd-misc&m=145275871714024&w=2 EDIT: For those interested in this topic, I would start with tedunangst's excellent summary from earlier this year. Thank you Ted!: http://www.tedunangst.com/flak/post/openbsd-laptops http://www.tedunangst.com/flak/post/openbsd-laptops
- carapace 10y agoSame question, for desktop server/workstation?
- clarry 10y agoIf you don't need ridiculous performance, I can recommend the shuttle fanless mini PCs. I have a DS437 and a DS57U7. Both used to be desktops, now the former serves as a server. I think there's a new one out now (DS67*), I haven't tried it yet. But I might buy one. Or wait for the next gen of intel CPUs. http://dmesgd.nycbug.org/index.cgi?action=dmesgd&do=view&id=2810 http://dmesgd.nycbug.org/index.cgi?action=dmesgd&do=view&id=... http://dmesgd.nycbug.org/index.cgi?action=dmesgd&do=view&id=2809 http://dmesgd.nycbug.org/index.cgi?action=dmesgd&do=view&id=... Note that I swapped the wlan card on one of these, for an Intel one. I don't know if the original card would've worked; I never tried it.
- 10y ago
- keithpeter 10y ago"...the kern.usermount sysctl is also no more. Administrators who want to let users mount devices will need to configure doas(1) for that task." For convenient laptop use I prefer allowing my user account to mount USB drives and have that done by mouseclicks in some way. Antoine Jacoutot's toad package is not in the 6.0 packages collection, but xfce4-mount is, so I assume I can set up the appropriate doas rule for a user and then configure xfce4-mount to ignore the local drive. I shall have a play on Sunday.