Game of Trees 0.129 released
Contributed by græy on from the again and again and again dept.
OpenBSD Journal
Contributed by græy on from the again and again and again dept.
Contributed by Peter N. M. Hansteen on from the files§ good! dept.
"a new, crash-safe, snapshotting, copy on write FS that I wrote for 9front, and which I am in the process of moving to OpenBSD.
Ori gave a presentation about the work at EuroBSDCon 2026, and posted a summary message titled GEFS on OpenBSD: A very early preview to tech@, inviting hacking and testing:
List: openbsd-tech Subject: GEFS on OpenBSD: A very early preview From: ori () eigenstate ! org Date: 2026-09-15 15:45:05 Message-ID: EBB049B251DCF60A8C9A0575F6FC7DC9 () eigenstate ! org Before anyone asks: I am *not* proposing to put this in tree for a while yet. What is it ---------- So, as people may have seen at EuroBSD, I've got a rough, buggy, issue-filled preview of GEFS running on OpenBSD. The port is NOT ready for production, and data loss is currently expected, especially on error.
Contributed by Peter N. M. Hansteen on from the smoother delivery dept.
The announcement says,
List: openbsd-announce Subject: OpenSMTPD 7.9.0p0 From: "Omar Polo" <op () openbsd ! org> Date: 2026-09-13 21:11:58 OpenSMTPD is a FREE implementation of the SMTP protocol with some common extensions. It allows ordinary machines to exchange e-mails with systems speaking the SMTP protocol. It implements a fairly large part of RFC5321 and can already cover a large range of use-cases.
Contributed by Paul 'WEiRD' de Weerd on from the fishy-videos dept.
Last weekend was the EuroBSDCon conference, this time in Brussels, Belgium. Several talks were held, with quite a few on OpenBSD.
You can watch all the talks on peer tube, check the dedicated OpenBSD playlist, or pick your favorite talk from the list:
Contributed by rueda on from the again-and-again-and dept.
Version 0.128 of Game of Trees has been released (and the port updated). Complete release notes are as follows:
Contributed by Peter N. M. Hansteen on from the rpki me up dept.
rpki-client(8), with various improvements, enhancements and fixes.
The announcement reads
List: openbsd-announce Subject: rpki-client 9.9 released From: Sebastian Benoit <benno () openbsd ! org> Date: 2026-08-23 19:25:37 Message-ID: aotJMUL7356PdqRC () jackline ! openbsd ! adns ! de rpki-client 9.9 has just been released and will be available in the rpki-client directory of any OpenBSD mirror soon. It is recommended that all users upgrade to this version for improved reliability.
Contributed by Peter N. M. Hansteen on from the SSH! SSLithering out to the world dept.
The release notes read,
OpenSSH 10.5/10.5p1 (2026-08-11) OpenSSH 10.5 was released on 2026-08-11. It is available from the mirrors listed at https://www.openssh.com/. OpenSSH is a 100% complete SSH protocol 2.0 implementation and includes sftp client and server support. Recently the OpenSSH team have received a large number of security bug reports, many of which are findings from AI models or made with AI assistance. While many AI reports are determined not to have security impact when considered in the context of a realistic threat model, we very much welcome these reports, especially when combined with human triage, analysis, test-cases and particularly when accompanied by proposed fixes.
Contributed by Peter N. M. Hansteen on from the not the roto-router dept.
The announcement reads,
List: openbsd-announce Subject: OpenBGPD 9.2 released From: Claudio Jeker <claudio () openbsd ! org> Date: 2026-08-06 13:22:26 Message-ID: anSKksatjxeom0lQ () diehard ! n-r-g ! com We have released OpenBGPD 9.2, which will be arriving in the OpenBGPD directory of your local OpenBSD mirror soon. This release includes the following changes to the previous release:
relayd(8) and httpd(8)Contributed by Peter N. M. Hansteen on from the https, really relayed dept.
rsadowski@) has a new blog post out titled Dead Software Walking: The ongoing evolution of relayd(8) and httpd(8) where he tells the story.
The article starts with
Start with WHYAs I mentioned in my OpenBSD 7.8 highlights post, development of relayd(8) and httpd(8) had stalled. Many diffs appeared on the
tech@mailing list from different contributors, but few were committed into the repository. The main reason was simple: Established OpenBSD developers weren’t interested in these daemons anymore. Call it momentum, or timing.
And he goes on to describe his motivation, and the numerous improvements that he and Kirill Korinsky (kirill@) added to those daemons once they got started.
Read the whole thing here: Dead Software Walking: The ongoing evolution of relayd(8) and httpd(8).
Donate to OpenBSD
We are constantly on the lookout for stories of how you put OpenBSD to work. Please submit any informative articles on how OpenBSD is helping your company.
OpenBSD 7.9
| 021 | 2026-09-14 SECURITY In ldapd(8), an authentication result from one transaction could be applied to another. |
| 020 | 2026-09-14 SECURITY Multiple vulnerabilities in the X server and server side font library. CVE-2026-55999 CVE-2026-56000 CVE-2026-56001 CVE-2026-56002 CVE-2026-56003 |
| 019 | 2026-09-14 SECURITY Backport all changes from libexpat 2.8.4. CVE-2026-66046 CVE-2026-76641 CVE-2026-76957 |
| 018 | 2026-09-14 RELIABILITY Prevent integer overflow in shmat(4). |
| 017 | 2026-09-14 RELIABILITY Prevent integer overflow in wscons(4). |
| 016 | 2026-09-14 SECURITY A malicous NFS server could aid a local user in avoiding access controls. |
OpenBSD 7.8
| 057 | 2026-09-14 SECURITY In ldapd(8), an authentication result from one transaction could be applied to another. |
| 056 | 2026-09-14 SECURITY Multiple vulnerabilities in the X server and server side font library. CVE-2026-55999 CVE-2026-56000 CVE-2026-56001 CVE-2026-56002 CVE-2026-56003 |
| 055 | 2026-09-14 SECURITY Backport all changes from libexpat 2.8.4. CVE-2026-66046 CVE-2026-76641 CVE-2026-76957 |
| 054 | 2026-09-14 RELIABILITY Prevent integer overflow in shmat(4). |
| 053 | 2026-09-14 RELIABILITY Prevent integer overflow in wscons(4). |
| 052 | 2026-09-14 SECURITY A malicous NFS server could aid a local user in avoiding access controls. |
Users wishing RSS/RDF summary files of OpenBSD Journal
can retrieve: 
Options are available.
Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]