A shiny new update is available, addressing the recent security advisories from FreeBSD, OpenSSL, Sudo and a number of minor bugs.
To all our 18.1-BETA testers we say this: thank you! The results have been thoroughly positive. If you would like to participate as well, please take a closer look:
https://forum.opnsense.org/index.php?topic=6257.0
pfSense software version 2.4.2 is a maintenance release bringing security patches and stability fixes for issues present in previous pfSense 2.4.x branch releases.
I just wasted an hour trying to figure out why xorg had strange output but no errors on this laptop, and it’s because I had i915_load=”YES” in /boot/loader.conf instead of i915_load=”YES” in /etc/rc.conf. I’m almost nearly sure I’ve mentioned that before, but if not: here you go.
(though if you never plan to run X, you can put it in loader.conf and everything will just work.)
If you happen to be running an old version of DragonFly, you may need to do an intermediate upgrade to move to releases after 5.0. This is in part because of commits to support C++14. This only applies to version of DragonFly before 4.4.
We are happy to announce the release of pfSense® software version 2.3.2!
This is a maintenance release in the 2.3.x series, bringing a number of bug fixes. The full list of changes is on the 2.3.2 New Features and Changes page.
This release includes fixes for 60 bugs, 8 features and 2 todo items completed.
If you haven’t yet caught up on the changes in 2.3.x, check out the Features and Highlights video. Past blog posts have covered some of the changes, such as the performance improvements from tryforward, and the webGUI update.
As always, you can upgrade from any prior version directly to 2.3.2. The Upgrade Guide
covers everything you’ll need to know for upgrading in general. There
are a few areas where additional caution should be exercised with this
upgrade if upgrading from 2.2.x or an earlier release, all noted in the 2.3 Upgrade Guide.
For those upgrading from a 2.3 beta or RC version who have not yet upgraded to 2.3-RELEASE, please see this post.
While, nearly all of the common regressions between 2.2.6 and
2.3-RELEASE have been fixed in subsequent releases, the following still
exist:
IPsec IPComp does not work. This is disabled by default. However in
2.3.1, it is automatically not enabled to avoid encountering this
problem. Bug 6167
IGMP Proxy does not work with VLAN interfaces, and possibly other edge cases. Bug 6099. This is a little-used component. If you’re not sure what it is, you’re not using it.
Those using IPsec and OpenBGPD may have non-functional IPsec unless OpenBGPD is removed. Bug 6223
Compared to pfSense 2.2.x, the list of available packages in pfSense
2.3.x has been significantly trimmed. We have removed packages that
have been deprecated upstream, no longer have an active maintainer, or
were never stable. A few have yet to be converted for Bootstrap and may
return if converted. See the 2.3 Removed Packages list for details. pfSense 2.3.2 does bring back ntopng, and the vnstat (traffic totals) package is new.
Downloads are available on the mirrors as usual. Downloads for New Installs and Upgrades to Existing Systems –
note it’s usually easier to just use the auto-update functionality, in
which case you don’t need to download anything from here. Check the Firmware Updates page for details.
The development of the upcoming major version of FreeBSD, whose final release is scheduled for early September, continues at a fast pace. Although delayed by a week, the 11.0-BETA2 build was finally announced yesterday: "The
second BETA build of the 11.0-RELEASE release cycle is now available. A
summary of changes since 11.0-BETA1 includes: several build- and
toolchain-related fixes; WITNESS and INVARIANTS have been disabled on
powerpc, powerpc64, arm and armv6 architectures; freebsd-update(8) has
been updated to allow '*-dbg' distribution sets; ctld(8) no longer exits
when reloading the configuration with invalid initiator-portal clauses;
GENERIC-NODEBUG kernel configurations have been removed; the callout
code has been updated to avoid a system panic with TCP timers; several
other changes." See also the (incomplete) release notes which are still work-in-progress. Quick links to download the amd64 and i386 installation DVD images: FreeBSD-11.0-BETA2-amd64-dvd1.iso (2,479MB, SHA512), FreeBSD-11.0-BETA2-i386-dvd1.iso (2,203MB, SHA512).
A new iso is available for testing for 64bit. Currently there
are two install media, one for DVD/CD and one for USB devices. Be sure
to select the right media. Dot img for usb and dot iso for CD/DVD. Download is available here
Currently the main packages available for testing are: LXDE,
chromium, Xorg, wine, transmission and a few Window Managers. New
Packages are added daily and more DE should be available in a few days.
xfce4, firefox and vlc will be next uploaded. Though there are multiple PKGBUILD for these already available at Github
Also you can view daily reports of the repository, which includes
broken packages, packages which fail to pull in dependencies, outdated
packages (Checked against freebsd ports) and other information: Repository Report
Installation help can be found at: ZFS Install Guide
If You need additional help, feel free to join irc.freenode.net
#pacbsd-dev as this is quite active. All new uploaded packages, git
commits, repository reports are posted here daily.
One more note, any issues can be reported to us directly on #pacbsd-dev on IRC, or on our bug tracker. Bug Tracker
DragonFly 4.6 release candidate 2 has been tagged. You can pull it directly from the master site in img or iso form (check your local mirror instead if possible), or shift to the new tag.
“Where is RC1?” you may ask? I tagged the first release candidate some days ago, and this bug was immediately found right after. It was easier to go right to RC2 once a fix was found.
This candidate will probably lead directly to a release version, so
if you want to run the release version exactly, wait a few days.
News
New Security Advisory: NetBSD-SA2016-006 (mail.local)
This week on BSDNow, we have all sorts of interesting news,
including a Kernel Fuzzing audit done for OpenBSD, a much improved ‘C’
client for LetsEncrypt, an interview with Dru Lavigne and more! Stick
around for your place to B...SD!
The source tree for the Lumina desktop
has just been soft-frozen in preparation for the upcoming release of
version 1.0.0 in mid-August (tentatively targeting August 8th for final
reviews/checks).
This means that all interface elements (GUI’s, widgets, etc) as well
as any text which requires translation may no longer be changed without
approval from both Ken Moore and the documentation team (basically only
things like bug fixes or spelling errors).
This is now the time to go through and perform any translations of
the Lumina desktop in preparation for the release. You can see the
current translation progress and help perform translations on the PC-BSD translations website.
We have also created a new tarball of the Lumina source tree on github (v1.0.0-Beta2)
so that package distributors have time to audit their current build
systems and ensure that the Lumina files/binaries are being packaged
properly (please report any packaging issues ASAP so that we can adjust
things as necessary). This is very important as a few binary names and
install locations for files have changed, and some optional dependencies
have changed as well (“compton” may be used instead of “xcompmgr” for
example).
This week on the show, Allan & I are going to be showing you
a very interesting interview we did talking about using FreeBSD to
drive a Robot! You won’t want to miss this one. That plus all the latest
news, heading your way right now!
Today on the show, we are going to be chatting with Michael
Dexter about a variety of topics, but of course including bhyve! That
plus the latest news is heading your way right now on BSDNow, the place
to B….SD!
In my two previous posts I talked about creating a new port and
copying a port from head to a branch. The goal of this post is the
creation of a new function: CreatePortOnBranch($category_name,
$port_name, $CommitBranch) The failed start I started out with this
stored procedure: Running it gave this message: # select
CreatePort('sysutils', 'bacula-server', [...]
We are pleased to announce the availability of the LibreSSL package
repo for 11-CURRENT/amd64. This repo is based off of the
LibreSSL-in-base branch (hardened/current/master-libressl) that Bernard
Spil has been working on. Going forward, along with providing binary
updates for that branch via hbsd-update(8), we will also
provide binary packages. We will also provide binary packages soon for
the LibreSSL 10-STABLE branch (hardened/10-stable/master-libressl).
Having both the feature branches along with package repos will allow us
to investigate making LibreSSL the standard in HardenedBSD.
We would like to thank Bernard Spil for his continuous hard work.
We're glad to have him on the team. Thanks to him, HardenedBSD is the
first downstream FreeBSD project to have both LibreSSL in base along
with a package repo that matches.
CheriBSD is a fork of FreeBSD to support the CHERI research CPU. We have
extended the kernel to provide support for CHERI memory capabilities as
well as modifying applications and libraries including tcpdump,
libmagic, and libz to take advantage of these capabilities for improved
memory safety and compartmentalization. We have also developed custom
demo applications and deployment infrastructure for our table demo
platform. In this talk I will discuss the challenges facing a long
running, public fork of FreeBSD.
This week on BSDNow, we interview Nick Wolff about how FreeBSD
is used across the State of Ohio & some of the specific technology
used. That, plus the latest news is coming your way right now on BSDNow,
the place to B...SD.
There was a newer release of OpenSSL (1.0.1p) last week, so there’s a new revision of the DragonFly release – 4.2.3. There’s little major change other than the security fix for OpenSSL. Those readers who can count past 2 may notice that there wasn’t a
4.2.2. We went straight from 4.2.1 to 4.2.3. That’s my fault. I
screwed up tagging and Git doesn’t like repeated, deleted tags.
The second BETA build of the 10.2-RELEASE cycle is now available. Installation images are available for the amd64, i386, ia64, powerpc, powerpc64, and sparc64 architectures. FreeBSD/arm
SD card images are available for the BEAGLEBONE, CUBOX-HUMMINGBOARD,
GUMSTIX, RPI-B, PANDABOARD, and WANDBOARD kernels. FreeBSD 10.2-BETA2 is also available on several third-party hosting providers. See the PGP-signed announcement email for installation image checksums and more information.
Coming up this time on the show, we’ll be talking with the CTO of
Xinuos, David Meyer, about their adoption of FreeBSD. We also discuss
the BSD license model for businesses & the benefits of contributing
changes back. Watch it here.
opnsense-update: exclude /etc/tty from the upgrade
bsdinstaller: reworked the internals to align to modern port standards
captive portal: switched rules generation to new template engine
firmware: reimplement the GUI firmware update using MVC code
menu: remove collapse/expand inconsistencies
dashboard: fix disabled widgets dialog
nat: fixed delete of multiple item
nat: fix display of disabled rules
queues: the legacy ALTQ traffic shaper is now found under “Firewall:
Queues” to make room for the upcoming traffic shaper reimplementation
based on IPFW/dummynet
The 10th pkgsrcCon is happening on the weekend of July 4th and 5th 2015 in Berlin.
Developers, contributors, and users are all welcome to attend.
More details can be found on the pkgsrcCon 2015 website.
Everyone is welcome to make a presentation. So please do!
If you already have title or topic please send an email to wiedi@frubar.net.
The linuxulator (the Linux
emulation/translation layer in FreeBSD) has recently undergone a major
overhaul. Many of FreeBSD's userbase relies on the linuxulator to
provide things like the Adobe Flash Player browser plugin, linux
browsers, and certain linux-centric tasks. The linuxulator provides a
set of security challenges. It is yet another attack vector. The core
HardenedBSD team would like to completely remove the linuxulator from
HardenedBSD's codebase.
What would be removed:
linuxulator and its dependents
linprocfs (pending investigation, this might not be removed)
If you were running a version of DragonFly 4.1 (i.e. the master
version, not release) built between the 20th and 25th, rebuild. There’s
a UFS bug introduced in that short timeframe.
If you are running 4.0.x release or built your version of DragonFly-master outside of that date range – you are unaffected.
This week on the show, we've got something
pretty different. We went to a Linux convention and asked various people
if they've ever tried BSD and what they know about it. Stay tuned for
that, all this week's news and, of course, answers to your emails, on
BSD Now - the place to B.. SD.
May 1st, 2015, Calgary, AB, CA and elsewhere:
OpenBSD 5.7
has been released. The brand new 5.7 subdirectory should now be
available and filled up on all relevant mirrors for those of you who
have yet to receive your CD orders.
The release announcement,
posted on project mailing lists earlier today, and the release home
page both mention some highlights of the new release, while the complete changelog for the release is available on the OpenBSD website.
While you are too late to be the first to preorder a shiny OpenBSD release CD set, you can order one of your own, as well as a very cool 5.7-release poster.
The PC-BSD team is pleased to announce the
availability of RC1 images for the upcoming quarterly 10.1.2 release.
Please test these images out and report any issues found on our bug tracker.
What else is new in PC-BSD 10.1.2? How about a new version of the
Lumina Desktop Environment! PC-BSD users who stick to the “Production”
branch of packages will find that the Lumina desktop has
evolved/improved an incredible amount since the last quarterly update
for PC-BSD (10.1.1), so I highly recommend that you try it out! The
release notes for this new version are also listed at the bottom of this
announcement for those of you who have been tracking along with its
development, so please try it out and let us know what you think!
Coming up this time on the show, we'll be
speaking with Christos Zoulas, a NetBSD security officer. He's got a new
project called blacklistd, with some interesting possibilities for
stopping bruteforce attacks. We've also got answers to your emails and
all this week's news, on BSD Now - the place to B.. SD.
Last week in BSD
OPNsense, pfSense, m0n0wall, HardenedBSD, Lumina Desktop, BSDnow, NetBSD, s2k15, DragonFly BSD
Releases
there seems to be none, let me know if I am wrong
Other news
Request For Testing: OPNsense on FreeBSD 10.1
As most of you know FreeBSD 10.0 is
approaching End Of Life at the end of this month. OPNsense is still
based on FreeBSD 10.0, but the necessary custom patches have been
forward-ported to FreeBSD 10.1 in the past week. We would love to push
out our next stable release 15.1.6 on top of FreeBSD 10.1 including a
new feature for base system upgrades which is one of our current weak
points for delivering quick and easy security updates for your running
installations.
In order to ship FreeBSD 10.1 we ask you to participate in this request for testing by trying the following snapshot for amd64: https://pkg.opnsense.org/snapshots
i386 snapshots can be produced based on demand.
Please let us know how the snapshot works for you (bad *and* good)
right here in this thread, or use one of the following alternatives. https://twitter.com/opnsense
#opnsense on Freenode IRC
project@opnsense.org
The next version of the Lumina desktop
environment has just been released! Version 0.8.2 is mainly a
“spit-and-polish” release: focusing on bugfixes, overall appearances,
and interface layout/design. The FreeBSD port has already been updated
to the new version, and the PC-BSD “Edge” repository will be making the
new version available within the next day or two (packages building
now). If you are creating/distributing your own packages, you can find
the source code for this release in the “qt5/0.8.2″ branch in the Lumina repository on GitHub.
The major difference that people will notice is that the
themes/colors distributed with the desktop have been greatly improved,
and I have included a few examples below. The full details about the
changes in this release are listed at the bottom of the announcement.
Reminder: The Lumina desktop environment is still considered to be
“beta-quality”, so if you find things that either don’t work or don’t
work well, please report them on the PC-BSD bug tracker so that they can get fixed as soon as possible.
This week on the show, we'll be chatting with
Alex Reece and Matt Ahrens about what's new in the world of OpenZFS.
After that, we're starting a new tutorial series on submitting your
first patch. All the latest BSD news and answers to your emails, coming
up on BSD Now - the place to B.. SD.
The NetBSD Project is pleased to announce NetBSD 5.1.5, the fifth
security/bugfix update of the NetBSD 5.1 release branch, and NetBSD
5.2.3, the third security/bugfix update of the NetBSD 5.2 release
branch. They represent a selected subset of fixes deemed important for
security or stability reasons, and if you are running a prior release of
either branch, we strongly suggest that you update to one of these
releases.
For more details, please see the release notes at:
http://www.NetBSD.org/releases/formal-5/NetBSD-5.1.5.html
http://www.NetBSD.org/releases/formal-5/NetBSD-5.2.3.html
Complete source and binaries for NetBSD are available for download
at many sites around the world. A list of download sites providing FTP,
AnonCVS, SUP, and other services may be found at:
http://www.NetBSD.org/mirrors/
As a reminder and warning, the upcoming release of NetBSD 7.0 will bring
about the end of support for the following branches:
- netbsd-5
- netbsd-5-1
- netbsd-5-2
As in the past, we will provide a grace period of a month, but now is a
good time to start thinking about your upgrade paths.
PC-BSD 10.1 Highlights
* KDE 4.14.2
* GNOME 3.12.2
* Cinnamon 2.2.16
* Chromium 38.0.2125.104_1
* Firefox 33.1
* NVIDIA Driver 340.24
* Lumina desktop 0.7.1-beta
* Pkg 1.3.8_3
* New AppCafe HTML5 web/remote interface, for both desktop / server usage
* New CD-sized text-installer ISO files for TrueOS / server deployments
* New Centos 6.6 Linux emulation base
* New HostAP mode for Wifi GUI utilities
* UEFI support for boot and installation
* Automatic tuning of ZFS memory usage at install time
* Support for full-disk (GELI) encryption without an unencrypted /boot partition (Also on mirror/raidz setups!)
* New VirtualBox / VMware / RAW disk images of desktop / server installations
For a more complete list of changes, please check our wiki page.
TrueOS
Along with our traditional PC-BSD DVD ISO image, we have also created a CD-sized ISO image of TrueOS, our server edition.
This is a text-based installer which includes FreeBSD 10.1-Release under the hood. It includes the following features:
* ZFS on Root installation
* Boot-Environment support
* Command-Line versions of PC-BSD utilities, such as Warden, Life-Preserver and more.
* Support for enabling the AppCafe web-interface for remote usage out of box
* Support for full-disk (GELI) encryption without an unencrypted /boot partition (Also on mirror/raidz setups!)
Please get it from the usual place: http://www.freenas.org/download/
This should, knock on wood, be the very last release on the
9.2.1-BRANCH and also the last 32 bit version of FreeNAS, so if you’ve
got some older hardware you just have to keep using, this is the release
to run!
Please see https://bugs.freenas.org/projects/freenas/issues?query_id=104 for all bugs addressed in this release, though the list is very short:
Fix a bug preventing Directory Server mode from working.
Fix a memory leak in ZFS that is triggered by having a compressed dataset and an L2ARC device.
Preserve the Samba SID across reboots and upgrades.
Fix two problems in the config file generator for CTL:
Unbreak device extents when using physical devices or multi path devices.
Unbreak the case when target auth or discover auth is set to Auto.
Fix a priviledge escalation issue.
Save debug now includes the output of zpool history.
The FreeBSD Foundation is pleased
to announce it has received a $1,000,000 donation from Jan Koum, CEO and
Co-Founder of WhatsApp. This marks the largest single donation to the
Foundation since its inception almost 15 years ago, and serves as
another example of someone using FreeBSD to great success and then
giving back to the community.
The following contains the full text from Jan's Facebook post on 11/17/2014:
Last
week, I donated one million dollars to the FreeBSD Foundation, which
supports the open source operating system that has helped millions of
programmers pursue their passions and bring their ideas to life.
I’m
actually one of those people. I started using FreeBSD in the late 90s,
when I didn’t have much money and was living in government housing. In a
way, FreeBSD helped lift me out of poverty – one of the main reasons I
got a job at Yahoo! is because they were using FreeBSD, and it was
my operating system of choice. Years later, when Brian and I set out to
build WhatsApp, we used FreeBSD to keep our servers running. We still
do.
I’m announcing this donation to shine a light
on the good work being done by the FreeBSD Foundation, with the hope
that others will also help move this project forward. We’ll all benefit
if FreeBSD can continue to give people the same opportunity it gave me –
if it can lift more immigrant kids out of poverty, and help more
startups build something successful, and even transformative.
This time on the show, we'll be talking with
Justin Cormack about NetBSD rump kernels. We'll learn how to run them on
other operating systems, what's planned for the future and a lot more.
As always, answers to viewer-submitted questions and all the news for
the week, on BSD Now - the place to B.. SD.
PC-BSD Notable Changes
* Cinnamon 2.2.14
* Chromium 37.0.2062.94
* NVIDIA Driver 340.24
* Lumina desktop 0.6.2-beta
* Pkg 1.3.7
* Various fixes to the Appcafe Qt UI
* Bugfixes to Warden / jail creation
* Fixed a bug with USB media not always being bootable
* Fixed several issues with Xorg setup
* Improved Boot-Environments to allow “beadm activate” to set default
* Support for jail “bulk” creation via Warden
* Fixes for relative ZFS dataset mount-point creation via Warden
* Support for full-disk (GELI) encryption without an unencrypted /boot partition
TrueOS
Along with our traditional PC-BSD DVD ISO image, we have also created a CD-sized ISO image of TrueOS, our server edition.
This is a text-based installer which includes FreeBSD 10.0-Release under the hood. It includes the following features:
* ZFS on Root installation
* Boot-Environment support
* Command-Line versions of PC-BSD utilities, such as Warden, Life-Preserver and more.
* Support for full-disk (GELI) encryption without an unencrypted /boot partition
We have some additional features also in the works for 10.1 and later, stay tuned this fall for more information.
The first BETA build of the 10.1-RELEASE
release cycle is now available on the FTP servers for the amd64, armv6,
i386, ia64, powerpc, powerpc64 and sparc64 architectures. The image checksums follow are included in the original announcement email. Installer images and memory stick images are available here.If you notice problems you can report them through the Bugzilla PR system or on the -stable mailing list.If you would like to use SVN to do a source based update of an existing system, use the "stable/10" branch.A list of changes since 10.0-RELEASE are available on the stable/10 release notes page.
The Design and Implementation of the FreeBSD Operating System (2nd Ed.) The most complete, authoritative technical
guide to the FreeBSD kernel’s internal structure has now been
extensively updated to cover all major improvements between Versions 5
and 11. Approximately one-third of this edition’s content is completely
new, and another one-third has been extensively rewritten. This book is
due to release on September 15, 2014. You can […]
The i386 package repo based on the
hardened/current/master branch is now live! The packages are signed by
us. The RSA certificate used for package signing can be found attached
to this post and can additionally be found here. The repository can be found here. We will be updating the i386 repo on a weekly basis.
This week on the show, it's all about Lumina. We'll be giving you a
visual walkthrough of the new BSD-exclusive desktop environment, as well
as chatting with the main developer. There's also answers to your
emails and all the latest news, on BSD Now - the place to B.. SD.
In a bit of perfect timing, PC-BSD’s desktop environment, Lumina, has been ported to DragonFly, thanks to mneumann! It’s not in dports yet, but it should be buildable from source…