Live data from Hacker News

In-kernel WireGuard is on its way to FreeBSD and the pfSense router

arstechnica.com

51–60 of 167 posts

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#51

Earlier quoted context omitted.

Netgate funds a lot of FreeBSD work, and employs FreeBSD committers. I certainly wouldn't describe them as hostile to open source.

They can be a touch snotty towards developers who aren't freebsd committees.

I think every project has people like that. I can think of some open source projects which are led by people with attitude problems.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#52

Earlier quoted context omitted.

They can be a touch snotty towards developers who aren't freebsd committees.

I think every project has people like that. I can think of some open source projects which are led by people with attitude problems.

Real subtle, Colin.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#53

Im confused, pfsense 2.5 is out and has wireguard support. Is that version full holes I should be aware off?

It's a userland implementation. This is for the in-kernel implementation. It should be faster. Also, there are some comments that the userland version is rather hacky and probably should be transitioned away from once you can.

The userland version is also from the original author of WireGuard and not that bad actually.

I'm currently running it in an OPNsense box to serve our internet needs. I have a connection that without VPN can push through about 400-800 Mbps, and when I put the VPN on for all traffic, I can still push 400-800 Mbps through my connection.

The in-kernel version can do the same with less CPU usage, and can probably drive multi-gigabit connections without any trouble.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#54
post #52

Earlier quoted context omitted.

I think every project has people like that. I can think of some open source projects which are led by people with attitude problems.

Real subtle, Colin.

I mean, Linus has openly acknowledged that he has behaved unprofessionally in the emails he sends to people who are trying to contribute. There isn't anything secret here.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#55
post #29

Earlier quoted context omitted.

The opnsense fork has supported wireguard for a while, and has far less restrictive licensing. I highly recommend having a look.

OPNsense is criminally underrated. My main routers for my office are virtualized OPNsense VM's in high availability with CARP, DHCP, DNS, VPN endpoints, inter-vlan routing, gateway policies, outbound nat... I could go on. It all works extremely well I can't fathom why people still choose pfSense with all of the community shenanigans and closed source versions. My only gripe with it over 3 years has been the documenta…

I did LOTS of research on what firewall/router distro to install to my new router a few months ago. See my comment history for considering different options.

I have to say choosing OPNsense has been a great choice. All the things you said I can agree on, but I have to add one more thing:

That quick search bar on the top-right corner where you can quickly type where you want to go. That thing is just super nice when jumping through places in the router.

Now if I'd need to build a new router, I'd like to try my luck with NixOS. Would be great if I could just build a new router from a reproducible configuration.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#56
post #31

Earlier quoted context omitted.

Netgate funds a lot of FreeBSD work, and employs FreeBSD committers. I certainly wouldn't describe them as hostile to open source.

Perhaps entitled is the right word then.

Maybe. It's not necessarily without reason -- if you make a lot of contributions and they are generally very well received, it's quite sensible to anticipate that further contributions will be equally well received and to be surprised if they're not.

This was made worse by the unfortunate timing -- the final release candidate is just 3 days away. Any other time, we would have gone slower, had more discussion, et cetera; unfortunately this turned into an emergency.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#57
post #28
post #11

Earlier quoted context omitted.

Wow. Netgate come off as incredibly unprofessional. According to the article linked and the info here in that email you linked this is my conclusion: * Netgate tried to ship flawed code that has multiple security issues. * Jason Donenfeld, one of the lead Wireguard developers, went out of his way to work on rewriting it to be better in time for the 13.0 release of FreeBSD * This Netgate employee is angry that they we…

That was my impression too, then I went back a couple prior messages, and looked at the earlier announcement. Wihle Netgate looks to have overreacted (at least from the info we have), I can understand why they would be upset. This was in the original announcement: The first step was assessing the current state of the code the previous developer had dumped into the tree. It was not pretty. I imagined strange Internet…

Keep in mind, back in February of 2020 when Kip Macy first announced that Netgate had hired him to port Wireguard, Jason offered to help. First Kip declines the offer, then seems to warm slightly to it, but ultimately appears to have not actually engaged Jason.

If I'm Jason and I offer my help (for free), they don't take me up on my offer, then try to release code that would make my baby look quite ugly, I would probably also have a pretty severe reaction.

Could Jason have been slightly more professional? Absolutely. But we're all human and I can't entirely blame him, I'm sure he was frustrated that he offered to help multiple times and they both didn't take him up on the offer, and tried to release a hatchet job with his name (indirectly) attached to it.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#58
post #42
post #28

Earlier quoted context omitted.

That was my impression too, then I went back a couple prior messages, and looked at the earlier announcement. Wihle Netgate looks to have overreacted (at least from the info we have), I can understand why they would be upset. This was in the original announcement: The first step was assessing the current state of the code the previous developer had dumped into the tree. It was not pretty. I imagined strange Internet…

Similar reaction here. My first impression was Netgate being an arse. But then when you read the announcement I kind of understand why Scott is angry. Because while the post may have been in "good faith" in an Open Development and Open Source world, it surely isn't in a professional and business world especially when the work is sponsored ( being paid ). Jason should have informed Netgate the quality of the code is s…

> it surely isn't in a professional and business world especially when the work is sponsored ( being paid ).

To play devil's advocate: Netgate isn't paying Jason, and they're taking his open source code to create a proprietary commercial project. I'd say Jason owes them exactly nothing in the way of courtesy or consideration. Could he have been more polite for the sake of being polite and community goodwill? Probably.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#60

Link to relevant announcement email: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649... There's also Jason's reply to apparently not-nice feedback of someone from NetGate: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649...

Jason's reply is an impressive display of de-escalation. The NetGate person's message has a lot of hostility and Jason really doesn't return any of it. Hope NetGate comes around to working with the WireGuard maintainers more in the future.
Post reply on HN