ccardenas@openbsd

79 Followers
40 Following
210 Posts
OpenBSD developer
OpenBSDccardenas
so I got my company collegues to agree to double the funding we had committed to help make bridge(4) mp safe in #OpenBSD
we have committed 6 days funding, and another person has committed to funding 1.5 days further dev work... #SMP #Bridge(4) anyone else want to help out in funding ... PM me .. and I can connect you to the dev directly ... Peace out and #RunBSD

 

"beck@ modified sys: Fix a collection of covering unveil bugs that prevent unveil's of upper level directories from working when you don't traverse into them starting from /. Most found by brynet@ and a few others. ok brynet@ deraadt@"

https://marc.info/?l=openbsd-cvs&m=154655236614423&w=2

With this change, unveil(2) can become an even more powerful tool that can be used to protect your applications, especially in cases where pledge(2) cannot be used.

#OpenBSD

'CVS: cvs.openbsd.org: src' - MARC

Alexandre Ratchov put out a call for testing for a new USB Audio class (UAC) v1.0/v2.0 driver for #OpenBSD, to replace the existing one: https://marc.info/?l=openbsd-tech&m=154627230907954&w=2
'new USB audio class v2.0 driver' - MARC

Retpolines now enabled by default in clang on #OpenBSD amd64.

https://marc.info/?l=openbsd-cvs&m=154621129329314&w=2

(It was previously enabled for the kernel, including handwritten assembly)

https://www.mail-archive.com/source-change[email protected]/msg97849.html
https://marc.info/?l=openbsd-cvs&m=152834458329715&w=2

'CVS: cvs.openbsd.org: src' - MARC

robert@ committed a change to further tighten the unveil paths for chromium on #OpenBSD, narrowing access to only the specific subdirectories in ~/.{config,local,cache} required, and also restoring ~/Downloads and /tmp as the path for uploads/downloads.  

https://marc.info/?l=openbsd-ports-cvs&m=154575916929236&w=2

For a brief period, ~/{Documents,Music,Pictures,Videos} were also allowed, but now only ~/Downloads (or /tmp) may be used as a staging area, moving files in and out of externally (shell or file manager).

'CVS: cvs.openbsd.org: ports' - MARC

OpenBSD 6.2 song: A 3 line diff

Fellow bsd Texans, chime in! I'll follow if you bellow.
Call for testing from Marc Espie (espie@), to forgo pkg_add(8) updates for packages that don't necessarily require updating: https://marc.info/?l=openbsd-tech&m=154462451202176&w=2 #OpenBSD
'pkg_add testing' - MARC

DNSSEC enabled in default unbound(8) configuration https://undeadly.org/cgi?action=article;sid=20181207141635
DNSSEC enabled in default unbound(8) configuration

OpenSMTPD proc filters & fc-rDNS