OpenBSD Journal

OpenBSD Journal

New laptops and OpenBSD: HP Envy 17-DA0013dx

Contributed by Peter N. M. Hansteen on from the Slim laptop envy dept.

We have to admit that even users of a well rounded operation system like OpenBSD sometimes encounter hardware that is not quite supported yet.

Fortunately, sometimes the user facing the problematic hardware is an experienced developer like Ian Darwin, and he took the time to write up his experience in a blog post titled Un-hanging the HP Envy 17-DA0013dx for OpenBSD.

The article leads in with,

I recently acquired a lightly-used HP Envy 17" laptop, model DA0013dx, and of course wanted to run OpenBSD on it. It came with Windows 11 on an internal NVME drive. Booting OpenBSD from a USB device failed fast: it hung. To get there, first of course I had to disable "secure boot" in the BIOS.

and chronicles the steps until he reaches the conclusion,

Last words

If you want a modern laptop with a 16:9 touchscreen display to run OpenBSD, the HP Envy is not a bad choice.

If this sounds good to you, go on read the whole thing!

openssh-10.6 released

Contributed by Peter N. M. Hansteen on from the ssh! we release dept.

In their usual, unassuming fashion, the OpenSSH project have released a new version, release 10.6.

The full text of the 10.6 release nodes reads:

OpenSSH 10.6 was released on 2026-10-06. It is available from the
mirrors listed at https://www.openssh.com/.

OpenSSH is a 100% complete SSH protocol 2.0 implementation and
includes sftp client and server support.

Recently the OpenSSH team have received a large number of security
bug reports, many of which are findings from AI models or made with
AI assistance. While many AI reports are determined not to have
security impact when considered in the context of a realistic
threat model, we very much welcome these reports, especially when
combined with human triage, analysis, test-cases and particularly
when accompanied by proposed fixes.

Read more…

LibreSSL 4.2.2 and 4.3.3 released

Contributed by Peter N. M. Hansteen on from the TLS! TLS! Stable! dept.

In a move that hints strongly that the new OpenBSD release is about to drop soon, the LibreSSL project have announced the new stable releases.

The announcement reads,

List:       openbsd-announce
Subject:    LibreSSL 4.2.2 and 4.3.3 released
From:       Brent Cook <busterb () gmail ! com>
Date:       2026-10-06 0:38:40

We have released LibreSSL 4.3.3 and 4.2.2, which are available in the
LibreSSL directory of your local OpenBSD mirror.

Read more…

Headers Up! What's New in httpd and relayd

Contributed by rueda on from the reinforced relaying revealed dept.

As previously noted, Rafael Sadowski (radowski@) has been behind a recent pickup in development of httpd(8) and relayd(8).

Now Rafael has written a new piece, entitled Headers Up! What's New in httpd and relayd, on some of his recent work on httpd(8) and relayd(8).

Among the notable additions are expanded and improved filtering and pattern matching features which make it harder to make a case for putting something like nginx in front of your httpd(8) and relayd(8) setups.

So while we at Undeadly were making notes with a view to reporting on all these features, Rafael himself beat us to it.

His latest article is well worth reading, here.

OpenBGPD 9.3 released

Contributed by rueda on from the et tu, routed dept.

In another hint that a new OpenBSD release is close, the OpenBGPD project has announced a new release of its software, version 9.3:

We have released OpenBGPD 9.3, which will be arriving in the
OpenBGPD directory of your local OpenBSD mirror soon.

This release includes the following changes to the previous release:

    * Add shorthand for well-known "DOWNGRADE" BGP community.

    * Remove support old aspa-set table format that included per-provider AFI.
      Rpki-client stopped issuing those with the 8.5 release in July 2023.

    * Use getexecpath in the fork-and-execute privilege separation setup
      and implement portable shims for various other operating systems.

    * Various minor fixes:
       - Improve graceful restart timer handling for multi-AFI/SAFI sessions.
       - Clear the connected nexthop flag when nexthops and nexthops are
	 no longer connected.
       - Fix edge case where an ASPA table update was not applied because the
	 system erroneously thought the table did not change.

OpenBGPD-portable is known to compile and run on FreeBSD and the
Linux distributions Alpine, Debian, Fedora, RHEL/CentOS and Ubuntu.
It is our hope that packagers take interest and help adapt OpenBGPD-portable
to more distributions.

We welcome feedback and improvements from the broader community.
Thanks to all of the contributors who helped make this release
possible.

OpenBSD -current is now "8.0-current"

Contributed by rueda on from the no^Wsomething-to-see-here dept.

Theo de Raadt (deraadt@) updated the version of OpenBSD -current from "8.0" to "8.0-current".

List:       openbsd-cvs
Subject:    CVS: cvs.openbsd.org: src
From:       Theo de Raadt <deraadt () cvs ! openbsd ! org>
Date:       2026-09-30 20:44:06
Message-ID: 93920a1f5b4035b8 () cvs ! openbsd ! org

CVSROOT:	/cvs
Module name:	src
Changes by:	deraadt@cvs.openbsd.org	2026/09/30 14:44:06

Modified files:
	sys/conf       : newvers.sh 

Log message:
8.0 -current development

Thes means that those running the latest-and-greatest [via a sufficiently new snapshot or built from source] no longer need to use "-D snap" with pkg_add(1) (and pkg_info(1)).

OpenBSD -current has moved to version 8.0

Contributed by rueda on from the here-we-go-again dept.

The OpenBSD 8.0 release cycle is entering its final phases…

With the following commit, Theo de Raadt (deraadt@) moved -current to version 8.0 (dropping the "-beta"):

CVSROOT:	/cvs
Module name:	src
Changes by:	deraadt@cvs.openbsd.org	2026/09/26 10:41:23

Modified files:
	sys/conf       : newvers.sh 

Log message:
leave -beta

For those unfamiliar with the process:
this is not the 8.0 release, but is part of the standard build-up to the release.

Remember: It's time to start using "-D snap" with pkg_add(1) (and pkg_info(1)).

(Regular readers will know what comes next…)
This serves as an excellent reminder to upgrade snapshots frequently, test both base and ports, and report problems [plus, of course, donate!].

OpenBSD gains new networking daemon - rtrd(8)

Contributed by rueda on from the late-reports dept.

Job Snijders (job@) imported rtrd(8), and its associated control program, rtrctl(8):

CVSROOT:	/cvs
Module name:	src
Changes by:	job@cvs.openbsd.org	2026/09/16 10:11:46

Added files:
	usr.sbin/rtrctl: Makefile ometric.c ometric.h rtrctl.8 rtrctl.c 
	usr.sbin/rtrd  : Makefile RTRX.PROTOCOL cache.c cache.h 
	                 commands.c commands.h hash.c hash.h ip_utils.c 
	                 ip_utils.h logs.c logs.h packets.c packets.h 
	                 rtr_config.h rtrd.8 rtrd.c sched.c sched.h 
	                 send.c send.h signals.c signals.h sockets.c 
	                 sockets.h stats.c stats.h structs.h tables.c 
	                 tables.h version.h 

Log message:
Import rtrd(8), an easy-to-use RPKI-To-Router protocol implementation

The rtrd(8) program is intended as a scalable distribution layer to
deliver data produced by rpki-client(8) to clients such as bgpd(8)
in multi-node/multi-vendor IXP and ISP deployments. A single rtrd(8)
instance can concurrently serve many BGP routers and route servers.

Many thanks to Ralph Covelli from Hurricane Electric for creating rtrd!

OK deraadt@ claudio@

The software was later linked to the build

The original author, Ralph Covelli, is now rcovelli@.

vmm(4)/vmd(8) gain support for multi-processor VMs

Contributed by rueda on from the late-reports dept.

Mike Larkin (mlarkin@) committed support for multi-processor virtual machines (i.e. guests):

CVSROOT:	/cvs
Module name:	src
Changes by:	mlarkin@cvs.openbsd.org	2026/09/17 20:35:55

Modified files:
	sys/arch/amd64/amd64: vmm_machdep.c 
	sys/arch/amd64/include: vmmvar.h 
	sys/dev/vmm    : vmm.c 
	usr.sbin/vmctl : main.c vmctl.8 vmctl.c vmctl.h 
	usr.sbin/vmd   : arm64_vm.c fw_cfg.c lapic.c lapic.h parse.y 
	                 vm.c vm.conf.5 vmd.c vmd.h x86_vm.c 

Log message:
vmm(4)/vmd(8): mp plumbing

Implements the sipi/init lapic state machine, mp IPI support and various
other changes required for mp. vmctl and man page changes for new start
and vm.conf options.

tested by dv and me on various guests

ok dv

This represents a huge jump forward in vmm(4)/vmd(8) flexibility and usability.

Donate!

Donate to OpenBSD

Features

We are constantly on the lookout for stories of how you put OpenBSD to work. Please submit any informative articles on how OpenBSD is helping your company.

OpenBSD Errata

Unofficial RSS feed of OpenBSD errata

OpenBSD 7.9

0302026-09-30 SECURITY Incorrect upper bound for uid and gid can result in -1 being used.
0292026-09-30 SECURITY Semaphore operation semop(2) could trigger a use-after-free in the kernel.
0282026-09-30 SECURITY After wg(4) interface destruction a use-after-free could be triggered by incoming packets.
0272026-09-30 SECURITY A malicious IKEv2 peer could crash iked(8), or cause a certificate validation verdict to be applied to the wrong peer identity.
0262026-09-30 SECURITY A reference counting bug could lead to use-after-free in the kernel.
0252026-09-30 SECURITY An errant process could cause ps(1) to crash due to a buffer overflow in sysctl(2).

OpenBSD 7.8

0662026-09-30 SECURITY Incorrect upper bound for uid and gid can result in -1 being used.
0652026-09-30 SECURITY Semaphore operation semop(2) could trigger a use-after-free in the kernel.
0642026-09-30 SECURITY After wg(4) interface destruction a use-after-free could be triggered by incoming packets.
0632026-09-30 SECURITY A malicious IKEv2 peer could crash iked(8), or cause a certificate validation verdict to be applied to the wrong peer identity.
0622026-09-30 SECURITY A reference counting bug could lead to use-after-free in the kernel. The ipcs(1) command stopped working after ABI change.
0612026-09-30 SECURITY An errant process could cause ps(1) to crash due to a buffer overflow in sysctl(2).

XML/RSS/RDF

Users wishing RSS/RDF summary files of OpenBSD Journal can retrieve: RSS feed

Options are available.

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]