<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Tue, 14 Apr 2026 03:02:47 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Lenovo”</title>
    <link>https://www.bsdnow.tv/tags/lenovo</link>
    <pubDate>Thu, 18 Feb 2021 03:00:00 -0500</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros.
The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day. 
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros.
The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day. 
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>390: Commercial Unix Killer</title>
  <link>https://www.bsdnow.tv/390</link>
  <guid isPermaLink="false">a77e0ca4-6c57-4cd9-ad09-1fbf8292e5d8</guid>
  <pubDate>Thu, 18 Feb 2021 03:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/a77e0ca4-6c57-4cd9-ad09-1fbf8292e5d8.mp3" length="55003992" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Did Linux kill Commercial Unix, three node GlusterFS setup on FreeBSD, OpenBSD on the Lenovo ThinkPad X1 Nano (1st Gen), NetBSD on EdgeRouter Lite, TLS Mastery first draft done</itunes:subtitle>
  <itunes:duration>55:36</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>Did Linux kill Commercial Unix, three node GlusterFS setup on FreeBSD, OpenBSD on the Lenovo ThinkPad X1 Nano (1st Gen), NetBSD on EdgeRouter Lite, TLS Mastery first draft done
NOTES
This episode of BSDNow is brought to you by Tarsnap (https://www.tarsnap.com/bsdnow)
Headlines
Did Linux Kill Commercial Unix? (https://www.howtogeek.com/440147/did-linux-kill-commercial-unix/)
Sales of commercial Unix have fallen off a cliff. There has to be something behind this dramatic decline. Has Linux killed its ancestor by becoming a perfectly viable replacement, like an operating system version of Invasion of the Body Snatchers?
Wireguard: Simple and Secure VPN in FreeBSD (https://klarasystems.com/articles/simple-and-secure-vpn-in-freebsd/)
A great article by Tom Jones about setting up Wireguard on FreeBSD
***
Setup a Three Node Replicated GlusterFS Cluster on FreeBSD (http://www.unibia.com/unibianet/freebsd/setup-three-node-replicated-glusterfs-cluster-freebsd)
GlusterFS (GFS) is the open source equivalent to Microsoft's Distributed Filesystem (DFS). It's a service that replicates the contents of a filesystem in real time from one server to another. Clients connect to any server and changes made to a file will replicate automatically. It's similar to something like rsync or syncthing, but much more automatic and transparent. A FreeBSD port has been available since v3.4, and (as of this post) is currently at version 8.0 with 9.0 being released soon.
News Roundup
OpenBSD on the Lenovo ThinkPad X1 Nano (1st Gen) (https://jcs.org/2021/01/27/x1nano)
Lenovo has finally made a smaller version of its X1 Carbon, something I’ve been looking forward to for years.
NetBSD on the EdgeRouter Lite (https://www.cambus.net/netbsd-on-the-edgerouter-lite/)
NetBSD-current now has pre-built octeon bootable images (which will appear in NetBSD 10.0) for the evbmips port, so I decided to finally give it a try. I've been happily running OpenBSD/octeon on my EdgeRouter Lite for a few years now, and have previously published some notes including more detail about the CPU.
“TLS Mastery” first draft done! (https://mwl.io/archives/9938)
Beastie Bits
A Thread on a FreeBSD Desktop for PineBook Pro (https://forums.freebsd.org/threads/freebsd-desktop-for-pinebook-pro.78269/)
FOSSASIA Conference - March 2021(Virtual) (https://eventyay.com/e/fa96ae2c)
WireGuard for pfSense Software (https://www.netgate.com/blog/wireguard-for-pfsense-software.html)
NetBSD logo to going Moon (https://mail-index.netbsd.org/netbsd-advocacy/2021/02/07/msg000849.html)
***
###Tarsnap
This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.
### Producer's Note
&amp;gt; Hey everybody, it’s JT here.  After our AMA episode where I mentioned I was looking for older BSD Retail Copies, I was contacted by Andrew who hooked me up with a bunch of OpenBSD disks from the 4.x era.  So shout out to him, and since that worked so well, I figured I'd give it another shot and ask that if anyone has any old Unixes that will run on an 8088, 8086, or 286 and you're willing to send me copies of the disks. I've recently dug out an old 286 system and I’d love to get a Unix OS on it.  I know of Minix, Xenix and Microport, but I haven’t been able to find many versions of them.  I've found Microport 1.3.3, and SCO Xenix... but that's about it.  Let me know if you happen to have any other versions, or know where I can get them.  
Feedback/Questions
Christian - ZFS replication and verification (https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/390/feedback/Christian%20-%20ZFS%20replication%20and%20verification)
Iain - progress (https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/390/feedback/Iain%20-%20progress)
Paul - APU2 device (https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/390/feedback/Paul%20-%20APU2%20device)
***
Send questions, comments, show ideas/topics, or stories you want mentioned on the show to feedback@bsdnow.tv (mailto:feedback@bsdnow.tv)
***
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, shell, unix, os, berkeley, software, distribution, release, zfs, zpool, dataset, interview, Linux, commercial unix, glusterfs, cluster, setup, Lenovo, Thinkpad, x1 nano, edgerouter, lite, tls, book</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Did Linux kill Commercial Unix, three node GlusterFS setup on FreeBSD, OpenBSD on the Lenovo ThinkPad X1 Nano (1st Gen), NetBSD on EdgeRouter Lite, TLS Mastery first draft done</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" rel="nofollow">Tarsnap</a></p>

<h2>Headlines</h2>

<h3><a href="https://www.howtogeek.com/440147/did-linux-kill-commercial-unix/" rel="nofollow">Did Linux Kill Commercial Unix?</a></h3>

<blockquote>
<p>Sales of commercial Unix have fallen off a cliff. There has to be something behind this dramatic decline. Has Linux killed its ancestor by becoming a perfectly viable replacement, like an operating system version of Invasion of the Body Snatchers?</p>

<hr>

<h3><a href="https://klarasystems.com/articles/simple-and-secure-vpn-in-freebsd/" rel="nofollow">Wireguard: Simple and Secure VPN in FreeBSD</a></h3>

<ul>
<li>A great article by Tom Jones about setting up Wireguard on FreeBSD
***</li>
</ul>
</blockquote>

<h3><a href="http://www.unibia.com/unibianet/freebsd/setup-three-node-replicated-glusterfs-cluster-freebsd" rel="nofollow">Setup a Three Node Replicated GlusterFS Cluster on FreeBSD</a></h3>

<blockquote>
<p>GlusterFS (GFS) is the open source equivalent to Microsoft&#39;s Distributed Filesystem (DFS). It&#39;s a service that replicates the contents of a filesystem in real time from one server to another. Clients connect to any server and changes made to a file will replicate automatically. It&#39;s similar to something like rsync or syncthing, but much more automatic and transparent. A FreeBSD port has been available since v3.4, and (as of this post) is currently at version 8.0 with 9.0 being released soon.</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://jcs.org/2021/01/27/x1nano" rel="nofollow">OpenBSD on the Lenovo ThinkPad X1 Nano (1st Gen)</a></h3>

<p>Lenovo has finally made a smaller version of its X1 Carbon, something I’ve been looking forward to for years.</p>

<hr>

<h3><a href="https://www.cambus.net/netbsd-on-the-edgerouter-lite/" rel="nofollow">NetBSD on the EdgeRouter Lite</a></h3>

<p>NetBSD-current now has pre-built octeon bootable images (which will appear in NetBSD 10.0) for the evbmips port, so I decided to finally give it a try. I&#39;ve been happily running OpenBSD/octeon on my EdgeRouter Lite for a few years now, and have previously published some notes including more detail about the CPU.</p>

<hr>

<h3><a href="https://mwl.io/archives/9938" rel="nofollow">“TLS Mastery” first draft done!</a></h3>

<hr>
</blockquote>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://forums.freebsd.org/threads/freebsd-desktop-for-pinebook-pro.78269/" rel="nofollow">A Thread on a FreeBSD Desktop for PineBook Pro</a></li>
<li><a href="https://eventyay.com/e/fa96ae2c" rel="nofollow">FOSSASIA Conference - March 2021(Virtual)</a></li>
<li><a href="https://www.netgate.com/blog/wireguard-for-pfsense-software.html" rel="nofollow">WireGuard for pfSense Software</a></li>
<li><a href="https://mail-index.netbsd.org/netbsd-advocacy/2021/02/07/msg000849.html" rel="nofollow">NetBSD logo to going Moon</a>
***
###Tarsnap</li>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.
### Producer&#39;s Note
&gt; Hey everybody, it’s JT here.  After our AMA episode where I mentioned I was looking for older BSD Retail Copies, I was contacted by Andrew who hooked me up with a bunch of OpenBSD disks from the 4.x era.  So shout out to him, and since that worked so well, I figured I&#39;d give it another shot and ask that if anyone has any old Unixes that will run on an 8088, 8086, or 286 and you&#39;re willing to send me copies of the disks. I&#39;ve recently dug out an old 286 system and I’d love to get a Unix OS on it.  I know of Minix, Xenix and Microport, but I haven’t been able to find many versions of them.  I&#39;ve found Microport 1.3.3, and SCO Xenix... but that&#39;s about it.  Let me know if you happen to have any other versions, or know where I can get them.<br></li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/390/feedback/Christian%20-%20ZFS%20replication%20and%20verification" rel="nofollow">Christian - ZFS replication and verification</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/390/feedback/Iain%20-%20progress" rel="nofollow">Iain - progress</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/390/feedback/Paul%20-%20APU2%20device" rel="nofollow">Paul - APU2 device</a>
***</li>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" rel="nofollow">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Did Linux kill Commercial Unix, three node GlusterFS setup on FreeBSD, OpenBSD on the Lenovo ThinkPad X1 Nano (1st Gen), NetBSD on EdgeRouter Lite, TLS Mastery first draft done</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" rel="nofollow">Tarsnap</a></p>

<h2>Headlines</h2>

<h3><a href="https://www.howtogeek.com/440147/did-linux-kill-commercial-unix/" rel="nofollow">Did Linux Kill Commercial Unix?</a></h3>

<blockquote>
<p>Sales of commercial Unix have fallen off a cliff. There has to be something behind this dramatic decline. Has Linux killed its ancestor by becoming a perfectly viable replacement, like an operating system version of Invasion of the Body Snatchers?</p>

<hr>

<h3><a href="https://klarasystems.com/articles/simple-and-secure-vpn-in-freebsd/" rel="nofollow">Wireguard: Simple and Secure VPN in FreeBSD</a></h3>

<ul>
<li>A great article by Tom Jones about setting up Wireguard on FreeBSD
***</li>
</ul>
</blockquote>

<h3><a href="http://www.unibia.com/unibianet/freebsd/setup-three-node-replicated-glusterfs-cluster-freebsd" rel="nofollow">Setup a Three Node Replicated GlusterFS Cluster on FreeBSD</a></h3>

<blockquote>
<p>GlusterFS (GFS) is the open source equivalent to Microsoft&#39;s Distributed Filesystem (DFS). It&#39;s a service that replicates the contents of a filesystem in real time from one server to another. Clients connect to any server and changes made to a file will replicate automatically. It&#39;s similar to something like rsync or syncthing, but much more automatic and transparent. A FreeBSD port has been available since v3.4, and (as of this post) is currently at version 8.0 with 9.0 being released soon.</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://jcs.org/2021/01/27/x1nano" rel="nofollow">OpenBSD on the Lenovo ThinkPad X1 Nano (1st Gen)</a></h3>

<p>Lenovo has finally made a smaller version of its X1 Carbon, something I’ve been looking forward to for years.</p>

<hr>

<h3><a href="https://www.cambus.net/netbsd-on-the-edgerouter-lite/" rel="nofollow">NetBSD on the EdgeRouter Lite</a></h3>

<p>NetBSD-current now has pre-built octeon bootable images (which will appear in NetBSD 10.0) for the evbmips port, so I decided to finally give it a try. I&#39;ve been happily running OpenBSD/octeon on my EdgeRouter Lite for a few years now, and have previously published some notes including more detail about the CPU.</p>

<hr>

<h3><a href="https://mwl.io/archives/9938" rel="nofollow">“TLS Mastery” first draft done!</a></h3>

<hr>
</blockquote>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://forums.freebsd.org/threads/freebsd-desktop-for-pinebook-pro.78269/" rel="nofollow">A Thread on a FreeBSD Desktop for PineBook Pro</a></li>
<li><a href="https://eventyay.com/e/fa96ae2c" rel="nofollow">FOSSASIA Conference - March 2021(Virtual)</a></li>
<li><a href="https://www.netgate.com/blog/wireguard-for-pfsense-software.html" rel="nofollow">WireGuard for pfSense Software</a></li>
<li><a href="https://mail-index.netbsd.org/netbsd-advocacy/2021/02/07/msg000849.html" rel="nofollow">NetBSD logo to going Moon</a>
***
###Tarsnap</li>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.
### Producer&#39;s Note
&gt; Hey everybody, it’s JT here.  After our AMA episode where I mentioned I was looking for older BSD Retail Copies, I was contacted by Andrew who hooked me up with a bunch of OpenBSD disks from the 4.x era.  So shout out to him, and since that worked so well, I figured I&#39;d give it another shot and ask that if anyone has any old Unixes that will run on an 8088, 8086, or 286 and you&#39;re willing to send me copies of the disks. I&#39;ve recently dug out an old 286 system and I’d love to get a Unix OS on it.  I know of Minix, Xenix and Microport, but I haven’t been able to find many versions of them.  I&#39;ve found Microport 1.3.3, and SCO Xenix... but that&#39;s about it.  Let me know if you happen to have any other versions, or know where I can get them.<br></li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/390/feedback/Christian%20-%20ZFS%20replication%20and%20verification" rel="nofollow">Christian - ZFS replication and verification</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/390/feedback/Iain%20-%20progress" rel="nofollow">Iain - progress</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/390/feedback/Paul%20-%20APU2%20device" rel="nofollow">Paul - APU2 device</a>
***</li>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" rel="nofollow">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>346: Core File Tales</title>
  <link>https://www.bsdnow.tv/346</link>
  <guid isPermaLink="false">8f8d0474-abb5-4b90-955c-8d8cfd6dc489</guid>
  <pubDate>Thu, 16 Apr 2020 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/8f8d0474-abb5-4b90-955c-8d8cfd6dc489.mp3" length="40304872" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Tales from a core file, Lenovo X260 BIOS Update with OpenBSD, the problem of Unix iowait and multi-CPU machines, Hugo workflow using FreeBSD Jails, Caddy, Restic; extending NetBSD-7 branch support, a tale of two hypervisor bugs, and more.</itunes:subtitle>
  <itunes:duration>55:58</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>Tales from a core file, Lenovo X260 BIOS Update with OpenBSD, the problem of Unix iowait and multi-CPU machines, Hugo workflow using FreeBSD Jails, Caddy, Restic; extending NetBSD-7 branch support, a tale of two hypervisor bugs, and more.
Headlines
Tales From a Core File - Lessons from the Unix stdio ABI: 40 Years Later (https://fingolfin.org/blog/20200327/stdio-abi.html)
On the side, I’ve been wrapping up some improvements to the classic Unix stdio libraries in illumos. stdio contains the classic functions like fopen(), printf(), and the security nightmare gets(). While working on support for fmemopen() and friends I got to reacquaint myself with some of the joys of the stdio ABI and its history from 7th Edition Unix. With that in mind, let’s dive into this, history, and some mistakes not to repeat. While this is written from the perspective of the C programming language, aspects of it apply to many other languages.
Update Lenovo X260 BIOS with OpenBSD (https://www.tumfatig.net/20200331/update-lenovo-x260-bios-with-openbsd/)
My X260 only runs OpenBSD and has no CD driver. But I still need to upgrade its BIOS from time to time. And this is possible using the ISO BIOS image.
First off all, you need to download the “BIOS Update (Bootable CD)” from the Lenovo Support Website.
News Roundup
The problem of Unix iowait and multi-CPU machines (https://utcc.utoronto.ca/~cks/space/blog/unix/IowaitAndMultipleCPUs)
Various Unixes have had a 'iowait' statistic for a long time now (although I can't find a source for where it originated; it's not in 4.x BSD, so it may have come through System V and sar). The traditional and standard definition of iowait is that it's the amount of time the system was idle but had at least one process waiting on disk IO. Rather than count this time as 'idle' (as you would if you had a three-way division of CPU time between user, system, and idle), some Unixes evolved to count this as a new category, 'iowait'.
My Latest Self Hosted Hugo Workflow using FreeBSD Jails, Caddy, Restic and More (https://www.jaredwolff.com/my-latest-self-hosted-hugo-workflow/)
After hosting with Netlify for a few years, I decided to head back to self hosting. Theres a few reasons for that but the main reasoning was that I had more control over how things worked.
In this post, i’ll show you my workflow for deploying my Hugo generated site (www.jaredwolff.com). Instead of using what most people would go for, i’ll be doing all of this using a FreeBSD Jails based server. Plus i’ll show you some tricks i’ve learned over the years on bulk image resizing and more.
Let’s get to it.
Extending support for the NetBSD-7 branch (http://blog.netbsd.org/tnf/entry/extending_support_for_the_netbsd)
Typically, some time after releasing a new NetBSD major version (such as NetBSD 9.0), we will announce the end-of-life of the N-2 branch, in this case NetBSD-7.
We've decided to hold off on doing that to ensure our users don't feel rushed to perform a major version update on any remote machines, possibly needing to reach the machine if anything goes wrong.
Security fixes will still be made to the NetBSD-7 branch.
We hope you're all safe. Stay home.
Tale of two hypervisor bugs - Escaping from FreeBSD bhyve (http://phrack.org/papers/escaping_from_freebsd_bhyve.html)
VM escape has become a popular topic of discussion over the last few years. A good amount of research on this topic has been published for various hypervisors like VMware, QEMU, VirtualBox, Xen and Hyper-V. Bhyve is a hypervisor for FreeBSD supporting hardware-assisted virtualization. This paper details the exploitation of two bugs in bhyve - FreeBSD-SA-16:32.bhyve (VGA emulation heap overflow) and CVE-2018-17160 (Firmware Configuration device bss buffer overflow) and some generic techniques which could be used for exploiting other bhyve bugs. Further, the paper also discusses sandbox escapes using PCI device passthrough, and Control-Flow Integrity bypasses in HardenedBSD 12-CURRENT
Beastie Bits
GhostBSD 20.02 Overview (https://www.youtube.com/watch?v=kFG-772WGwg)
FuryBSD 12.1 Overview (https://www.youtube.com/watch?v=5V8680uoXxw)
&amp;gt; Joe Maloney got in touch to say that the issues in the video and other ones found have since been fixed.  Now that's community feedback in action, and an example of a developer who does his best to help the community. A great guy indeed.
OS108-9.0 amd64 MATE released (https://forums.os108.org/d/27-os108-9-0-amd64-mate-released)
FreeBSD hacking: carp panics &amp;amp; test (https://www.twitch.tv/videos/584064729)
Inaugural FreeBSD Office Hours (https://www.youtube.com/watch?v=6qBm5NM3zTQ)
Feedback/Questions
Shody - systemd question (http://dpaste.com/2SAQDJJ#wrap)
Ben - GELI and GPT (http://dpaste.com/1S0DGT3#wrap)
Stig - DIY NAS (http://dpaste.com/2NGNZG5#wrap)
Send questions, comments, show ideas/topics, or stories you want mentioned on the show to feedback@bsdnow.tv (mailto:feedback@bsdnow.tv)

    
    Your browser does not support the HTML5 video tag.
 
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, interview, core, core file, core dump, bios, bios update, lenovo, x260, thinkpad, Unix, iowait, self-hosted, hugo, jails, caddy, restic, branch, branch support, hypervisor, bugs</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Tales from a core file, Lenovo X260 BIOS Update with OpenBSD, the problem of Unix iowait and multi-CPU machines, Hugo workflow using FreeBSD Jails, Caddy, Restic; extending NetBSD-7 branch support, a tale of two hypervisor bugs, and more.</p>

<h2>Headlines</h2>

<h3><a href="https://fingolfin.org/blog/20200327/stdio-abi.html" rel="nofollow">Tales From a Core File - Lessons from the Unix stdio ABI: 40 Years Later</a></h3>

<blockquote>
<p>On the side, I’ve been wrapping up some improvements to the classic Unix stdio libraries in illumos. stdio contains the classic functions like fopen(), printf(), and the security nightmare gets(). While working on support for fmemopen() and friends I got to reacquaint myself with some of the joys of the stdio ABI and its history from 7th Edition Unix. With that in mind, let’s dive into this, history, and some mistakes not to repeat. While this is written from the perspective of the C programming language, aspects of it apply to many other languages.</p>
</blockquote>

<hr>

<h3><a href="https://www.tumfatig.net/20200331/update-lenovo-x260-bios-with-openbsd/" rel="nofollow">Update Lenovo X260 BIOS with OpenBSD</a></h3>

<blockquote>
<p>My X260 only runs OpenBSD and has no CD driver. But I still need to upgrade its BIOS from time to time. And this is possible using the ISO BIOS image.</p>

<p>First off all, you need to download the “BIOS Update (Bootable CD)” from the Lenovo Support Website.</p>
</blockquote>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://utcc.utoronto.ca/%7Ecks/space/blog/unix/IowaitAndMultipleCPUs" rel="nofollow">The problem of Unix iowait and multi-CPU machines</a></h3>

<blockquote>
<p>Various Unixes have had a &#39;iowait&#39; statistic for a long time now (although I can&#39;t find a source for where it originated; it&#39;s not in 4.x BSD, so it may have come through System V and sar). The traditional and standard definition of iowait is that it&#39;s the amount of time the system was idle but had at least one process waiting on disk IO. Rather than count this time as &#39;idle&#39; (as you would if you had a three-way division of CPU time between user, system, and idle), some Unixes evolved to count this as a new category, &#39;iowait&#39;.</p>
</blockquote>

<hr>

<h3><a href="https://www.jaredwolff.com/my-latest-self-hosted-hugo-workflow/" rel="nofollow">My Latest Self Hosted Hugo Workflow using FreeBSD Jails, Caddy, Restic and More</a></h3>

<blockquote>
<p>After hosting with Netlify for a few years, I decided to head back to self hosting. Theres a few reasons for that but the main reasoning was that I had more control over how things worked.</p>

<p>In this post, i’ll show you my workflow for deploying my Hugo generated site (<a href="http://www.jaredwolff.com" rel="nofollow">www.jaredwolff.com</a>). Instead of using what most people would go for, i’ll be doing all of this using a FreeBSD Jails based server. Plus i’ll show you some tricks i’ve learned over the years on bulk image resizing and more.</p>

<p>Let’s get to it.</p>
</blockquote>

<hr>

<h3><a href="http://blog.netbsd.org/tnf/entry/extending_support_for_the_netbsd" rel="nofollow">Extending support for the NetBSD-7 branch</a></h3>

<blockquote>
<p>Typically, some time after releasing a new NetBSD major version (such as NetBSD 9.0), we will announce the end-of-life of the N-2 branch, in this case NetBSD-7.</p>

<p>We&#39;ve decided to hold off on doing that to ensure our users don&#39;t feel rushed to perform a major version update on any remote machines, possibly needing to reach the machine if anything goes wrong.</p>

<p>Security fixes will still be made to the NetBSD-7 branch.</p>

<p>We hope you&#39;re all safe. Stay home.</p>
</blockquote>

<hr>

<h3><a href="http://phrack.org/papers/escaping_from_freebsd_bhyve.html" rel="nofollow">Tale of two hypervisor bugs - Escaping from FreeBSD bhyve</a></h3>

<blockquote>
<p>VM escape has become a popular topic of discussion over the last few years. A good amount of research on this topic has been published for various hypervisors like VMware, QEMU, VirtualBox, Xen and Hyper-V. Bhyve is a hypervisor for FreeBSD supporting hardware-assisted virtualization. This paper details the exploitation of two bugs in bhyve - FreeBSD-SA-16:32.bhyve (VGA emulation heap overflow) and CVE-2018-17160 (Firmware Configuration device bss buffer overflow) and some generic techniques which could be used for exploiting other bhyve bugs. Further, the paper also discusses sandbox escapes using PCI device passthrough, and Control-Flow Integrity bypasses in HardenedBSD 12-CURRENT</p>
</blockquote>

<hr>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://www.youtube.com/watch?v=kFG-772WGwg" rel="nofollow">GhostBSD 20.02 Overview</a></li>
<li><a href="https://www.youtube.com/watch?v=5V8680uoXxw" rel="nofollow">FuryBSD 12.1 Overview</a>
&gt; Joe Maloney got in touch to say that the issues in the video and other ones found have since been fixed.  Now that&#39;s community feedback in action, and an example of a developer who does his best to help the community. A great guy indeed.</li>
<li><a href="https://forums.os108.org/d/27-os108-9-0-amd64-mate-released" rel="nofollow">OS108-9.0 amd64 MATE released</a></li>
<li><a href="https://www.twitch.tv/videos/584064729" rel="nofollow">FreeBSD hacking: carp panics &amp; test</a></li>
<li><a href="https://www.youtube.com/watch?v=6qBm5NM3zTQ" rel="nofollow">Inaugural FreeBSD Office Hours</a></li>
</ul>

<hr>

<h2>Feedback/Questions</h2>

<ul>
<li>Shody - <a href="http://dpaste.com/2SAQDJJ#wrap" rel="nofollow">systemd question</a></li>
<li>Ben - <a href="http://dpaste.com/1S0DGT3#wrap" rel="nofollow">GELI and GPT</a></li>
<li>Stig - <a href="http://dpaste.com/2NGNZG5#wrap" rel="nofollow">DIY NAS</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" rel="nofollow">feedback@bsdnow.tv</a></li>
</ul>

<hr>

<video controls preload="metadata" style=" width:426px;  height:240px;">
    <source src="http://201406.jb-dl.cdn.scaleengine.net/bsdnow/2019/bsd-0345.mp4" type="video/mp4">
    Your browser does not support the HTML5 video tag.
</video>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Tales from a core file, Lenovo X260 BIOS Update with OpenBSD, the problem of Unix iowait and multi-CPU machines, Hugo workflow using FreeBSD Jails, Caddy, Restic; extending NetBSD-7 branch support, a tale of two hypervisor bugs, and more.</p>

<h2>Headlines</h2>

<h3><a href="https://fingolfin.org/blog/20200327/stdio-abi.html" rel="nofollow">Tales From a Core File - Lessons from the Unix stdio ABI: 40 Years Later</a></h3>

<blockquote>
<p>On the side, I’ve been wrapping up some improvements to the classic Unix stdio libraries in illumos. stdio contains the classic functions like fopen(), printf(), and the security nightmare gets(). While working on support for fmemopen() and friends I got to reacquaint myself with some of the joys of the stdio ABI and its history from 7th Edition Unix. With that in mind, let’s dive into this, history, and some mistakes not to repeat. While this is written from the perspective of the C programming language, aspects of it apply to many other languages.</p>
</blockquote>

<hr>

<h3><a href="https://www.tumfatig.net/20200331/update-lenovo-x260-bios-with-openbsd/" rel="nofollow">Update Lenovo X260 BIOS with OpenBSD</a></h3>

<blockquote>
<p>My X260 only runs OpenBSD and has no CD driver. But I still need to upgrade its BIOS from time to time. And this is possible using the ISO BIOS image.</p>

<p>First off all, you need to download the “BIOS Update (Bootable CD)” from the Lenovo Support Website.</p>
</blockquote>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://utcc.utoronto.ca/%7Ecks/space/blog/unix/IowaitAndMultipleCPUs" rel="nofollow">The problem of Unix iowait and multi-CPU machines</a></h3>

<blockquote>
<p>Various Unixes have had a &#39;iowait&#39; statistic for a long time now (although I can&#39;t find a source for where it originated; it&#39;s not in 4.x BSD, so it may have come through System V and sar). The traditional and standard definition of iowait is that it&#39;s the amount of time the system was idle but had at least one process waiting on disk IO. Rather than count this time as &#39;idle&#39; (as you would if you had a three-way division of CPU time between user, system, and idle), some Unixes evolved to count this as a new category, &#39;iowait&#39;.</p>
</blockquote>

<hr>

<h3><a href="https://www.jaredwolff.com/my-latest-self-hosted-hugo-workflow/" rel="nofollow">My Latest Self Hosted Hugo Workflow using FreeBSD Jails, Caddy, Restic and More</a></h3>

<blockquote>
<p>After hosting with Netlify for a few years, I decided to head back to self hosting. Theres a few reasons for that but the main reasoning was that I had more control over how things worked.</p>

<p>In this post, i’ll show you my workflow for deploying my Hugo generated site (<a href="http://www.jaredwolff.com" rel="nofollow">www.jaredwolff.com</a>). Instead of using what most people would go for, i’ll be doing all of this using a FreeBSD Jails based server. Plus i’ll show you some tricks i’ve learned over the years on bulk image resizing and more.</p>

<p>Let’s get to it.</p>
</blockquote>

<hr>

<h3><a href="http://blog.netbsd.org/tnf/entry/extending_support_for_the_netbsd" rel="nofollow">Extending support for the NetBSD-7 branch</a></h3>

<blockquote>
<p>Typically, some time after releasing a new NetBSD major version (such as NetBSD 9.0), we will announce the end-of-life of the N-2 branch, in this case NetBSD-7.</p>

<p>We&#39;ve decided to hold off on doing that to ensure our users don&#39;t feel rushed to perform a major version update on any remote machines, possibly needing to reach the machine if anything goes wrong.</p>

<p>Security fixes will still be made to the NetBSD-7 branch.</p>

<p>We hope you&#39;re all safe. Stay home.</p>
</blockquote>

<hr>

<h3><a href="http://phrack.org/papers/escaping_from_freebsd_bhyve.html" rel="nofollow">Tale of two hypervisor bugs - Escaping from FreeBSD bhyve</a></h3>

<blockquote>
<p>VM escape has become a popular topic of discussion over the last few years. A good amount of research on this topic has been published for various hypervisors like VMware, QEMU, VirtualBox, Xen and Hyper-V. Bhyve is a hypervisor for FreeBSD supporting hardware-assisted virtualization. This paper details the exploitation of two bugs in bhyve - FreeBSD-SA-16:32.bhyve (VGA emulation heap overflow) and CVE-2018-17160 (Firmware Configuration device bss buffer overflow) and some generic techniques which could be used for exploiting other bhyve bugs. Further, the paper also discusses sandbox escapes using PCI device passthrough, and Control-Flow Integrity bypasses in HardenedBSD 12-CURRENT</p>
</blockquote>

<hr>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://www.youtube.com/watch?v=kFG-772WGwg" rel="nofollow">GhostBSD 20.02 Overview</a></li>
<li><a href="https://www.youtube.com/watch?v=5V8680uoXxw" rel="nofollow">FuryBSD 12.1 Overview</a>
&gt; Joe Maloney got in touch to say that the issues in the video and other ones found have since been fixed.  Now that&#39;s community feedback in action, and an example of a developer who does his best to help the community. A great guy indeed.</li>
<li><a href="https://forums.os108.org/d/27-os108-9-0-amd64-mate-released" rel="nofollow">OS108-9.0 amd64 MATE released</a></li>
<li><a href="https://www.twitch.tv/videos/584064729" rel="nofollow">FreeBSD hacking: carp panics &amp; test</a></li>
<li><a href="https://www.youtube.com/watch?v=6qBm5NM3zTQ" rel="nofollow">Inaugural FreeBSD Office Hours</a></li>
</ul>

<hr>

<h2>Feedback/Questions</h2>

<ul>
<li>Shody - <a href="http://dpaste.com/2SAQDJJ#wrap" rel="nofollow">systemd question</a></li>
<li>Ben - <a href="http://dpaste.com/1S0DGT3#wrap" rel="nofollow">GELI and GPT</a></li>
<li>Stig - <a href="http://dpaste.com/2NGNZG5#wrap" rel="nofollow">DIY NAS</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" rel="nofollow">feedback@bsdnow.tv</a></li>
</ul>

<hr>

<video controls preload="metadata" style=" width:426px;  height:240px;">
    <source src="http://201406.jb-dl.cdn.scaleengine.net/bsdnow/2019/bsd-0345.mp4" type="video/mp4">
    Your browser does not support the HTML5 video tag.
</video>]]>
  </itunes:summary>
</item>
<item>
  <title>78: From the Foundation (Part 2)</title>
  <link>https://www.bsdnow.tv/78</link>
  <guid isPermaLink="false">6999608e-fe27-4efa-96b0-eb1e928acf0a</guid>
  <pubDate>Wed, 25 Feb 2015 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/6999608e-fe27-4efa-96b0-eb1e928acf0a.mp3" length="50146996" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week we continue our two-part series on the activities of various BSD foundations. Ken Westerback joins us today to talk all about the OpenBSD foundation and what it is they do. We've also got answers to your emails and all the latest news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:09:38</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>This week we continue our two-part series on the activities of various BSD foundations. Ken Westerback joins us today to talk all about the OpenBSD foundation and what it is they do. We've also got answers to your emails and all the latest news, on BSD Now - the place to B.. SD.
This episode was brought to you by
&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;
Headlines
BSDCan 2015 schedule (https://www.bsdcan.org/2015/schedule/)
The list of presentations for the upcoming BSDCan conference has been posted, and the time schedule should be up shortly as well
Just a reminder: it's going to be held on June 12th and 13th at the University of Ottawa in Canada
This year's conference will have a massive fifty talks, split up between four tracks instead of three (but unfortunately a person can only be in one place at a time)
Both Allan and Kris had at least one presentation accepted, and Allan will also be leading a few  "birds of a feather" gatherings
In total, there will be three NetBSD talks, five OpenBSD talks, eight BSD-neutral talks, thirty-five FreeBSD talks and no DragonFly talks
That's not the ideal balance (https://twitter.com/bsdcan/status/570394627158773760) we'd hope for, but BSDCan says (https://twitter.com/bsdcan/status/570398181864972288) they'll try to improve that next year
Those numbers are based on the speaker's background, or any past presentations, for the few whose actual topic wasn't made obvious from the title (so there may be a small margin of error)
Michael Lucas (who's on the BSDCan board) wrote up a blog post (http://blather.michaelwlucas.com/archives/2325) about the proposals and rejections this year
If you can't make it this year, don't worry, we'll be sure to announce the recordings when they're made available
We also interviewed Dan Langille (http://www.bsdnow.tv/episodes/2014_12_31-daemons_in_the_north) about the conference and what to expect this year, so check that out too
***
SSL interception with relayd (http://www.reykfloeter.com/post/41814177050/relayd-ssl-interception)
There was a lot of commotion recently about superfish (http://www.forbes.com/sites/thomasbrewster/2015/02/19/superfish-need-to-know/), a way that Lenovo was intercepting HTTPS traffic and injecting advertisements
If you're running relayd (http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/relayd.8), you can mimic this evil setup on your own networks (just for testing of course…)
Reyk Floeter (http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time), the guy who wrote relayd, came up a blog post about how to do just that (https://gist.github.com/reyk/4b42858d1eab3825f9bc#file-relayd-superfish-conf)
It starts off with some backstory and some of the things relayd is capable of
relayd can run as an SSL server to terminate SSL connections and forward them as plain TCP and, conversely, run as an SSL client to terminal plain TCP connections and tunnel them through SSL
When you combine these two, you end up with possibilities to filter between SSL connections, effectively creating a MITM scenario
The post is very long, with lots of details (https://www.marc.info/?l=openbsd-tech&amp;amp;m=135887624714548&amp;amp;w=2) and some sample config files - the whole nine yards
***
OPNsense 15.1.6.1 released (https://forum.opnsense.org/index.php?topic=77.0)
The OPNsense team has released yet another version in rapid succession, but this one has some big changes
It's now based on FreeBSD 10.1, with all the latest security patches and driver updates (as well as some in-house patches)
This version also features a new tool for easily upgrading between versions, simply called "opnsense-update" (similar to freebsd-update)
It also includes security fixes for BIND (https://kb.isc.org/article/AA-01235) and PHP (http://php.net/ChangeLog-5.php#5.6.6), as well as some other assorted bug fixes
The installation images have been laid out in a clean way: standard CD and USB images that default to VGA, as well as USB images that default to a console output (for things like Soekris and PCEngines APU boards that only have serial ports)
With the news of m0n0wall shutting down last week, they've also released bare minimum hardware specifications required to run OPNsense on embedded devices
Encouraged by last week's mention of PCBSD trying to cut ties with OpenSSL, OPNsense is also now providing experimental images built against LibreSSL (https://forum.opnsense.org/index.php?topic=78.0) for testing (and have instructions on how to switch over without reinstalling)
***
OpenBSD on a Minnowboard Max (http://www.countersiege.com/2015/02/22/minnowboard_max_openbsd.html)
What would our show be without at least one story about someone installing BSD on a weird device
For once, it's actually not NetBSD…
This article is about the minnowboard max (http://www.minnowboard.org/meet-minnowboard-max/), a very small X86-based motherboard that looks vaguely similar to a Raspberry Pi
It's using an Atom CPU instead of ARM, so overall application compatibility should be a bit better (and it even has AES-NI, so crypto performance will be much better than a normal Atom)
The author describes his entirely solid-state setup, noting that there's virtually no noise, no concern about hard drives dying and very reasonable power usage
You'll find instructions on how to get OpenBSD installed and going throughout the rest of the article
Have a look at the spec sheet if you're interested, they make for cool little BSD boxes
***
Netmap for 40gbit NICs in FreeBSD (https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054717.html)
Luigi Rizzo posted an announcement to the -current mailing list, detailing some of the work he's just committed
The ixl(4) driver, that's one for the X1710 40-gigabit card, now has netmap support
It's currently in 11-CURRENT, but he says it works in 10-STABLE and will be committed there too
This should make for some serious packet-pushing power
If you have any network hardware like this, he would appreciate testing for the new code
***
Interview - Ken Westerback - directors@openbsdfoundation.org (mailto:directors@openbsdfoundation.org)
The OpenBSD foundation (http://www.openbsdfoundation.org/donations.html)'s activities
News Roundup
s2k15 hackathon report: dhclient/dhcpd/fdisk (http://undeadly.org/cgi?action=article&amp;amp;sid=20150221222235)
The second trip report from the recent OpenBSD hackathon has been published, from the very same guy we just talked to
Ken was also busy, getting a few networking-related things fixed and improved in the base system
He wrote a few new small additions for dhclient and beefed up the privsep security, as well as some fixes for tcpdump and dhcpd
The fdisk tool also got worked on a bit, enabling OpenBSD to properly wipe GPT tables on a previously-formatted disk so you can do a normal install on it
There's apparently plans for "dhclientng" - presumably a big improvement (rewrite?) of dhclient
***
FreeBSD beginner video series (https://www.youtube.com/user/bsdtutorial/videos)
A new series of videos has started on YouTube, aimed at helping total beginners learn about FreeBSD
We usually assume that people who watch the show are already familiar with basic concepts, but they'd be a great introduction to any of your friends that are looking to get started with BSD and need a helping hand
So far, he's covered how to get FreeBSD (https://www.youtube.com/watch?v=D26rOHkI-iE), an introduction to installing in VirtualBox (https://www.youtube.com/watch?v=PCyYW19bPDU), a simple installation (https://www.youtube.com/watch?v=HCE89kObutA) or a more in-depth manual installation (https://www.youtube.com/watch?v=OwqCjz9Fgao), navigating the filesystem (https://www.youtube.com/watch?v=6YJhdOGjN50), basic ssh use (https://www.youtube.com/watch?v=Yl5Bg2qz21I), managing users and groups (https://www.youtube.com/watch?v=ioB73i7QUjI) and finally some basic editing (https://www.youtube.com/watch?v=VxxbO-gt9FA) with vi (https://www.youtube.com/watch?v=16FNtCj-uS4) and a few other topics
Everyone's gotta start somewhere and, with a little bit of initial direction, today's newbies could be tomorrow's developers
It should be an ongoing series with more topics to come
***
NetBSD tests: zero unexpected failures (https://blog.netbsd.org/tnf/entry/regular_test_runs_down_to)
The NetBSD guys have a new blog post up about their testing suite (http://wiki.netbsd.org/tutorials/atf/) for all the CPU architectures
They've finally gotten the number of "expected" failures down to zero on a few select architectures
Results are published (http://releng.netbsd.org/test-results.html) on a special release engineering page, so you can have a look if you're interested
The rest of the post links to the "top performers" (ones with less than ten failure) in the -current branch
***
PCBSD switches to IPFW (https://github.com/pcbsd/pcbsd/commit/b80f78d8a5d002396c28ac0e5fd6f69699beaace)
The PCBSD crew continues their recent series of switching between major competing features
This time, they've switched the default firewall away from PF to FreeBSD's native IPFW firewall
Look forward to Kris wearing a "keep calm and use IPFW" shir- wait
***
Feedback/Questions
Sean writes in (http://slexy.org/view/s21U6Ln6wC)
Dan writes in (http://slexy.org/view/s2Kp0xdfIb)
Florian writes in (http://slexy.org/view/s216DcA8DP)
Sean writes in (http://slexy.org/view/s271iJjqtQ)
Chris writes in (http://slexy.org/view/s21zerHI9P)
***
Mailing List Gold
VCS flamebait (https://www.marc.info/?l=openbsd-misc&amp;amp;m=142454205416445&amp;amp;w=2)
Hidden agenda (https://lists.freebsd.org/pipermail/freebsd-gnome/2015-February/031561.html)
*** 
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, openbsd foundation, donations, openssh, funding, hackathon, gsoc, core infrastructure initiative, linux foundation, charity, lenovo, superfish, relayd, opnsense, soekris</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week we continue our two-part series on the activities of various BSD foundations. Ken Westerback joins us today to talk all about the OpenBSD foundation and what it is they do. We&#39;ve also got answers to your emails and all the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source" /></a><a href="http://www.digitalocean.com/" title="DigitalOcean"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers" /></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid" /></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2015/schedule/" rel="nofollow">BSDCan 2015 schedule</a></h3>

<ul>
<li>The list of presentations for the upcoming BSDCan conference has been posted, and the time schedule should be up shortly as well</li>
<li>Just a reminder: it&#39;s going to be held on June 12th and 13th at the University of Ottawa in Canada</li>
<li>This year&#39;s conference will have a massive <strong>fifty</strong> talks, split up between four tracks instead of three (but unfortunately a person can only be in one place at a time)</li>
<li>Both Allan and Kris had at least one presentation accepted, and Allan will also be leading a few  &quot;birds of a feather&quot; gatherings</li>
<li>In total, there will be three NetBSD talks, five OpenBSD talks, eight BSD-neutral talks, thirty-five FreeBSD talks and no DragonFly talks</li>
<li>That&#39;s not the <a href="https://twitter.com/bsdcan/status/570394627158773760" rel="nofollow">ideal balance</a> we&#39;d hope for, but <a href="https://twitter.com/bsdcan/status/570398181864972288" rel="nofollow">BSDCan says</a> they&#39;ll try to improve that next year</li>
<li>Those numbers are based on the speaker&#39;s background, or any past presentations, for the few whose actual topic wasn&#39;t made obvious from the title (so there may be a small margin of error)</li>
<li>Michael Lucas (who&#39;s on the BSDCan board) wrote up <a href="http://blather.michaelwlucas.com/archives/2325" rel="nofollow">a blog post</a> about the proposals and rejections this year</li>
<li>If you can&#39;t make it this year, don&#39;t worry, we&#39;ll be sure to announce the recordings when they&#39;re made available</li>
<li>We also <a href="http://www.bsdnow.tv/episodes/2014_12_31-daemons_in_the_north" rel="nofollow">interviewed Dan Langille</a> about the conference and what to expect this year, so check that out too
***</li>
</ul>

<h3><a href="http://www.reykfloeter.com/post/41814177050/relayd-ssl-interception" rel="nofollow">SSL interception with relayd</a></h3>

<ul>
<li>There was a lot of commotion recently about <a href="http://www.forbes.com/sites/thomasbrewster/2015/02/19/superfish-need-to-know/" rel="nofollow">superfish</a>, a way that Lenovo was intercepting HTTPS traffic and injecting advertisements</li>
<li>If you&#39;re running <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/relayd.8" rel="nofollow">relayd</a>, you can mimic this <em>evil</em> setup on your own networks (just for testing of course…)</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow">Reyk Floeter</a>, the guy who wrote relayd, came up a blog post about how to do <a href="https://gist.github.com/reyk/4b42858d1eab3825f9bc#file-relayd-superfish-conf" rel="nofollow">just that</a></li>
<li>It starts off with some backstory and some of the things relayd is capable of</li>
<li>relayd can run as an SSL server to terminate SSL connections and forward them as plain TCP and, conversely, run as an SSL client to terminal plain TCP connections and tunnel them through SSL</li>
<li>When you combine these two, you end up with possibilities to filter between SSL connections, effectively creating a MITM scenario</li>
<li>The post is very long, with lots of <a href="https://www.marc.info/?l=openbsd-tech&m=135887624714548&w=2" rel="nofollow">details</a> and some sample config files - the whole nine yards
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=77.0" rel="nofollow">OPNsense 15.1.6.1 released</a></h3>

<ul>
<li>The OPNsense team has released yet another version in rapid succession, but this one has some big changes</li>
<li>It&#39;s now based on FreeBSD 10.1, with all the latest security patches and driver updates (as well as some in-house patches)</li>
<li>This version also features a new tool for easily upgrading between versions, simply called &quot;opnsense-update&quot; (similar to freebsd-update)</li>
<li>It also includes <strong>security</strong> fixes <a href="https://kb.isc.org/article/AA-01235" rel="nofollow">for BIND</a> <a href="http://php.net/ChangeLog-5.php#5.6.6" rel="nofollow">and PHP</a>, as well as some other assorted bug fixes</li>
<li>The installation images have been laid out in a clean way: standard CD and USB images that default to VGA, as well as USB images that default to a console output (for things like Soekris and PCEngines APU boards that only have serial ports)</li>
<li>With the news of m0n0wall shutting down last week, they&#39;ve also released bare minimum hardware specifications required to run OPNsense on embedded devices</li>
<li>Encouraged by last week&#39;s mention of PCBSD trying to cut ties with OpenSSL, OPNsense is also now providing experimental <a href="https://forum.opnsense.org/index.php?topic=78.0" rel="nofollow">images built against LibreSSL</a> for testing (and have instructions on how to switch over without reinstalling)
***</li>
</ul>

<h3><a href="http://www.countersiege.com/2015/02/22/minnowboard_max_openbsd.html" rel="nofollow">OpenBSD on a Minnowboard Max</a></h3>

<ul>
<li>What would our show be without at least one story about someone installing BSD on a weird device</li>
<li>For once, it&#39;s actually not NetBSD…</li>
<li>This article is about the <a href="http://www.minnowboard.org/meet-minnowboard-max/" rel="nofollow">minnowboard max</a>, a very small X86-based motherboard that looks vaguely similar to a Raspberry Pi</li>
<li>It&#39;s using an Atom CPU instead of ARM, so overall application compatibility should be a bit better (and it even has AES-NI, so crypto performance will be much better than a normal Atom)</li>
<li>The author describes his entirely solid-state setup, noting that there&#39;s virtually no noise, no concern about hard drives dying and very reasonable power usage</li>
<li>You&#39;ll find instructions on how to get OpenBSD installed and going throughout the rest of the article</li>
<li>Have a look at the spec sheet if you&#39;re interested, they make for cool little BSD boxes
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054717.html" rel="nofollow">Netmap for 40gbit NICs in FreeBSD</a></h3>

<ul>
<li>Luigi Rizzo posted an announcement to the -current mailing list, detailing some of the work he&#39;s just committed</li>
<li>The ixl(4) driver, that&#39;s one for the X1710 40-gigabit card, now has netmap support</li>
<li>It&#39;s currently in 11-CURRENT, but he says it works in 10-STABLE and will be committed there too</li>
<li>This should make for some serious packet-pushing power</li>
<li>If you have any network hardware like this, he would appreciate testing for the new code
***</li>
</ul>

<h2>Interview - Ken Westerback - <a href="mailto:directors@openbsdfoundation.org" rel="nofollow">directors@openbsdfoundation.org</a></h2>

<p><a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow">The OpenBSD foundation</a>&#39;s activities</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://undeadly.org/cgi?action=article&sid=20150221222235" rel="nofollow">s2k15 hackathon report: dhclient/dhcpd/fdisk</a></h3>

<ul>
<li>The second trip report from the recent OpenBSD hackathon has been published, from the very same guy we just talked to</li>
<li>Ken was also busy, getting a few networking-related things fixed and improved in the base system</li>
<li>He wrote a few new small additions for dhclient and beefed up the privsep security, as well as some fixes for tcpdump and dhcpd</li>
<li>The fdisk tool also got worked on a bit, enabling OpenBSD to properly wipe GPT tables on a previously-formatted disk so you can do a normal install on it</li>
<li>There&#39;s apparently plans for &quot;dhclientng&quot; - presumably a big improvement (rewrite?) of dhclient
***</li>
</ul>

<h3><a href="https://www.youtube.com/user/bsdtutorial/videos" rel="nofollow">FreeBSD beginner video series</a></h3>

<ul>
<li>A new series of videos has started on YouTube, aimed at helping total beginners learn about FreeBSD</li>
<li>We usually assume that people who watch the show are already familiar with basic concepts, but they&#39;d be a great introduction to any of your friends that are looking to get started with BSD and need a helping hand</li>
<li>So far, he&#39;s covered <a href="https://www.youtube.com/watch?v=D26rOHkI-iE" rel="nofollow">how to get FreeBSD</a>, <a href="https://www.youtube.com/watch?v=PCyYW19bPDU" rel="nofollow">an introduction to installing in VirtualBox</a>, <a href="https://www.youtube.com/watch?v=HCE89kObutA" rel="nofollow">a simple installation</a> or a more in-depth <a href="https://www.youtube.com/watch?v=OwqCjz9Fgao" rel="nofollow">manual installation</a>, <a href="https://www.youtube.com/watch?v=6YJhdOGjN50" rel="nofollow">navigating the filesystem</a>, <a href="https://www.youtube.com/watch?v=Yl5Bg2qz21I" rel="nofollow">basic ssh use</a>, <a href="https://www.youtube.com/watch?v=ioB73i7QUjI" rel="nofollow">managing users and groups</a> and finally some <a href="https://www.youtube.com/watch?v=VxxbO-gt9FA" rel="nofollow">basic editing</a> <a href="https://www.youtube.com/watch?v=16FNtCj-uS4" rel="nofollow">with vi</a> and a few other topics</li>
<li>Everyone&#39;s gotta start somewhere and, with a little bit of initial direction, today&#39;s newbies could be tomorrow&#39;s developers</li>
<li>It should be an ongoing series with more topics to come
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/regular_test_runs_down_to" rel="nofollow">NetBSD tests: zero unexpected failures</a></h3>

<ul>
<li>The NetBSD guys have a new blog post up about their <a href="http://wiki.netbsd.org/tutorials/atf/" rel="nofollow">testing suite</a> for all the CPU architectures</li>
<li>They&#39;ve finally gotten the number of &quot;expected&quot; failures down to zero on a few select architectures</li>
<li>Results are <a href="http://releng.netbsd.org/test-results.html" rel="nofollow">published</a> on a special release engineering page, so you can have a look if you&#39;re interested</li>
<li>The rest of the post links to the &quot;top performers&quot; (ones with less than ten failure) in the -current branch
***</li>
</ul>

<h3><a href="https://github.com/pcbsd/pcbsd/commit/b80f78d8a5d002396c28ac0e5fd6f69699beaace" rel="nofollow">PCBSD switches to IPFW</a></h3>

<ul>
<li>The PCBSD crew continues their recent series of switching between major competing features</li>
<li>This time, they&#39;ve switched the default firewall away from PF to FreeBSD&#39;s native IPFW firewall</li>
<li>Look forward to Kris wearing a &quot;keep calm and use IPFW&quot; shir- wait
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21U6Ln6wC" rel="nofollow">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2Kp0xdfIb" rel="nofollow">Dan writes in</a></li>
<li><a href="http://slexy.org/view/s216DcA8DP" rel="nofollow">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s271iJjqtQ" rel="nofollow">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s21zerHI9P" rel="nofollow">Chris writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-misc&m=142454205416445&w=2" rel="nofollow">VCS flamebait</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-gnome/2015-February/031561.html" rel="nofollow">Hidden agenda</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week we continue our two-part series on the activities of various BSD foundations. Ken Westerback joins us today to talk all about the OpenBSD foundation and what it is they do. We&#39;ve also got answers to your emails and all the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source" /></a><a href="http://www.digitalocean.com/" title="DigitalOcean"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers" /></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid" /></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2015/schedule/" rel="nofollow">BSDCan 2015 schedule</a></h3>

<ul>
<li>The list of presentations for the upcoming BSDCan conference has been posted, and the time schedule should be up shortly as well</li>
<li>Just a reminder: it&#39;s going to be held on June 12th and 13th at the University of Ottawa in Canada</li>
<li>This year&#39;s conference will have a massive <strong>fifty</strong> talks, split up between four tracks instead of three (but unfortunately a person can only be in one place at a time)</li>
<li>Both Allan and Kris had at least one presentation accepted, and Allan will also be leading a few  &quot;birds of a feather&quot; gatherings</li>
<li>In total, there will be three NetBSD talks, five OpenBSD talks, eight BSD-neutral talks, thirty-five FreeBSD talks and no DragonFly talks</li>
<li>That&#39;s not the <a href="https://twitter.com/bsdcan/status/570394627158773760" rel="nofollow">ideal balance</a> we&#39;d hope for, but <a href="https://twitter.com/bsdcan/status/570398181864972288" rel="nofollow">BSDCan says</a> they&#39;ll try to improve that next year</li>
<li>Those numbers are based on the speaker&#39;s background, or any past presentations, for the few whose actual topic wasn&#39;t made obvious from the title (so there may be a small margin of error)</li>
<li>Michael Lucas (who&#39;s on the BSDCan board) wrote up <a href="http://blather.michaelwlucas.com/archives/2325" rel="nofollow">a blog post</a> about the proposals and rejections this year</li>
<li>If you can&#39;t make it this year, don&#39;t worry, we&#39;ll be sure to announce the recordings when they&#39;re made available</li>
<li>We also <a href="http://www.bsdnow.tv/episodes/2014_12_31-daemons_in_the_north" rel="nofollow">interviewed Dan Langille</a> about the conference and what to expect this year, so check that out too
***</li>
</ul>

<h3><a href="http://www.reykfloeter.com/post/41814177050/relayd-ssl-interception" rel="nofollow">SSL interception with relayd</a></h3>

<ul>
<li>There was a lot of commotion recently about <a href="http://www.forbes.com/sites/thomasbrewster/2015/02/19/superfish-need-to-know/" rel="nofollow">superfish</a>, a way that Lenovo was intercepting HTTPS traffic and injecting advertisements</li>
<li>If you&#39;re running <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/relayd.8" rel="nofollow">relayd</a>, you can mimic this <em>evil</em> setup on your own networks (just for testing of course…)</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow">Reyk Floeter</a>, the guy who wrote relayd, came up a blog post about how to do <a href="https://gist.github.com/reyk/4b42858d1eab3825f9bc#file-relayd-superfish-conf" rel="nofollow">just that</a></li>
<li>It starts off with some backstory and some of the things relayd is capable of</li>
<li>relayd can run as an SSL server to terminate SSL connections and forward them as plain TCP and, conversely, run as an SSL client to terminal plain TCP connections and tunnel them through SSL</li>
<li>When you combine these two, you end up with possibilities to filter between SSL connections, effectively creating a MITM scenario</li>
<li>The post is very long, with lots of <a href="https://www.marc.info/?l=openbsd-tech&m=135887624714548&w=2" rel="nofollow">details</a> and some sample config files - the whole nine yards
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=77.0" rel="nofollow">OPNsense 15.1.6.1 released</a></h3>

<ul>
<li>The OPNsense team has released yet another version in rapid succession, but this one has some big changes</li>
<li>It&#39;s now based on FreeBSD 10.1, with all the latest security patches and driver updates (as well as some in-house patches)</li>
<li>This version also features a new tool for easily upgrading between versions, simply called &quot;opnsense-update&quot; (similar to freebsd-update)</li>
<li>It also includes <strong>security</strong> fixes <a href="https://kb.isc.org/article/AA-01235" rel="nofollow">for BIND</a> <a href="http://php.net/ChangeLog-5.php#5.6.6" rel="nofollow">and PHP</a>, as well as some other assorted bug fixes</li>
<li>The installation images have been laid out in a clean way: standard CD and USB images that default to VGA, as well as USB images that default to a console output (for things like Soekris and PCEngines APU boards that only have serial ports)</li>
<li>With the news of m0n0wall shutting down last week, they&#39;ve also released bare minimum hardware specifications required to run OPNsense on embedded devices</li>
<li>Encouraged by last week&#39;s mention of PCBSD trying to cut ties with OpenSSL, OPNsense is also now providing experimental <a href="https://forum.opnsense.org/index.php?topic=78.0" rel="nofollow">images built against LibreSSL</a> for testing (and have instructions on how to switch over without reinstalling)
***</li>
</ul>

<h3><a href="http://www.countersiege.com/2015/02/22/minnowboard_max_openbsd.html" rel="nofollow">OpenBSD on a Minnowboard Max</a></h3>

<ul>
<li>What would our show be without at least one story about someone installing BSD on a weird device</li>
<li>For once, it&#39;s actually not NetBSD…</li>
<li>This article is about the <a href="http://www.minnowboard.org/meet-minnowboard-max/" rel="nofollow">minnowboard max</a>, a very small X86-based motherboard that looks vaguely similar to a Raspberry Pi</li>
<li>It&#39;s using an Atom CPU instead of ARM, so overall application compatibility should be a bit better (and it even has AES-NI, so crypto performance will be much better than a normal Atom)</li>
<li>The author describes his entirely solid-state setup, noting that there&#39;s virtually no noise, no concern about hard drives dying and very reasonable power usage</li>
<li>You&#39;ll find instructions on how to get OpenBSD installed and going throughout the rest of the article</li>
<li>Have a look at the spec sheet if you&#39;re interested, they make for cool little BSD boxes
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054717.html" rel="nofollow">Netmap for 40gbit NICs in FreeBSD</a></h3>

<ul>
<li>Luigi Rizzo posted an announcement to the -current mailing list, detailing some of the work he&#39;s just committed</li>
<li>The ixl(4) driver, that&#39;s one for the X1710 40-gigabit card, now has netmap support</li>
<li>It&#39;s currently in 11-CURRENT, but he says it works in 10-STABLE and will be committed there too</li>
<li>This should make for some serious packet-pushing power</li>
<li>If you have any network hardware like this, he would appreciate testing for the new code
***</li>
</ul>

<h2>Interview - Ken Westerback - <a href="mailto:directors@openbsdfoundation.org" rel="nofollow">directors@openbsdfoundation.org</a></h2>

<p><a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow">The OpenBSD foundation</a>&#39;s activities</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://undeadly.org/cgi?action=article&sid=20150221222235" rel="nofollow">s2k15 hackathon report: dhclient/dhcpd/fdisk</a></h3>

<ul>
<li>The second trip report from the recent OpenBSD hackathon has been published, from the very same guy we just talked to</li>
<li>Ken was also busy, getting a few networking-related things fixed and improved in the base system</li>
<li>He wrote a few new small additions for dhclient and beefed up the privsep security, as well as some fixes for tcpdump and dhcpd</li>
<li>The fdisk tool also got worked on a bit, enabling OpenBSD to properly wipe GPT tables on a previously-formatted disk so you can do a normal install on it</li>
<li>There&#39;s apparently plans for &quot;dhclientng&quot; - presumably a big improvement (rewrite?) of dhclient
***</li>
</ul>

<h3><a href="https://www.youtube.com/user/bsdtutorial/videos" rel="nofollow">FreeBSD beginner video series</a></h3>

<ul>
<li>A new series of videos has started on YouTube, aimed at helping total beginners learn about FreeBSD</li>
<li>We usually assume that people who watch the show are already familiar with basic concepts, but they&#39;d be a great introduction to any of your friends that are looking to get started with BSD and need a helping hand</li>
<li>So far, he&#39;s covered <a href="https://www.youtube.com/watch?v=D26rOHkI-iE" rel="nofollow">how to get FreeBSD</a>, <a href="https://www.youtube.com/watch?v=PCyYW19bPDU" rel="nofollow">an introduction to installing in VirtualBox</a>, <a href="https://www.youtube.com/watch?v=HCE89kObutA" rel="nofollow">a simple installation</a> or a more in-depth <a href="https://www.youtube.com/watch?v=OwqCjz9Fgao" rel="nofollow">manual installation</a>, <a href="https://www.youtube.com/watch?v=6YJhdOGjN50" rel="nofollow">navigating the filesystem</a>, <a href="https://www.youtube.com/watch?v=Yl5Bg2qz21I" rel="nofollow">basic ssh use</a>, <a href="https://www.youtube.com/watch?v=ioB73i7QUjI" rel="nofollow">managing users and groups</a> and finally some <a href="https://www.youtube.com/watch?v=VxxbO-gt9FA" rel="nofollow">basic editing</a> <a href="https://www.youtube.com/watch?v=16FNtCj-uS4" rel="nofollow">with vi</a> and a few other topics</li>
<li>Everyone&#39;s gotta start somewhere and, with a little bit of initial direction, today&#39;s newbies could be tomorrow&#39;s developers</li>
<li>It should be an ongoing series with more topics to come
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/regular_test_runs_down_to" rel="nofollow">NetBSD tests: zero unexpected failures</a></h3>

<ul>
<li>The NetBSD guys have a new blog post up about their <a href="http://wiki.netbsd.org/tutorials/atf/" rel="nofollow">testing suite</a> for all the CPU architectures</li>
<li>They&#39;ve finally gotten the number of &quot;expected&quot; failures down to zero on a few select architectures</li>
<li>Results are <a href="http://releng.netbsd.org/test-results.html" rel="nofollow">published</a> on a special release engineering page, so you can have a look if you&#39;re interested</li>
<li>The rest of the post links to the &quot;top performers&quot; (ones with less than ten failure) in the -current branch
***</li>
</ul>

<h3><a href="https://github.com/pcbsd/pcbsd/commit/b80f78d8a5d002396c28ac0e5fd6f69699beaace" rel="nofollow">PCBSD switches to IPFW</a></h3>

<ul>
<li>The PCBSD crew continues their recent series of switching between major competing features</li>
<li>This time, they&#39;ve switched the default firewall away from PF to FreeBSD&#39;s native IPFW firewall</li>
<li>Look forward to Kris wearing a &quot;keep calm and use IPFW&quot; shir- wait
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21U6Ln6wC" rel="nofollow">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2Kp0xdfIb" rel="nofollow">Dan writes in</a></li>
<li><a href="http://slexy.org/view/s216DcA8DP" rel="nofollow">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s271iJjqtQ" rel="nofollow">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s21zerHI9P" rel="nofollow">Chris writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-misc&m=142454205416445&w=2" rel="nofollow">VCS flamebait</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-gnome/2015-February/031561.html" rel="nofollow">Hidden agenda</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
