Live data from Hacker News

In-kernel WireGuard is on its way to FreeBSD and the pfSense router

arstechnica.com

141–150 of 167 posts

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#141

Earlier quoted context omitted.

It makes sense to me. As I understand the FreeBSD mailing list posts, it was commissioned commercially, to add a feature to NetGate products. Must have: in-kernel WireGuard for NetGate products. Nice-to-have: a general-purpose FreeBSD kernel WireGuard. The scope crept, and a piece of code that might have been fit for some purpose (whatever limitations NetGate has for its network stack, like "no jumbo frames", etc) wa…

Thank you for the reply. Yes, I understand Jason is basically only involved as "I have looked at this thing you propose/ have in FreeBSD and I don't like what I see, let me improve/ discuss further plans". My question basically is: "How is it possible, the code of such quality was even seriously included in a branch of FreeBSD that would have been released if nobody would step in?" (That is if I understand the whole…

Short answer: With a very small number of exceptions, we trust FreeBSD developers to exercise good judgement in obtaining review and ensuring the quality of the code they commit. The FreeBSD project is selective in whom it gives commit bits to, and we have a mentoring process which further ensures that developers understand the norms.

This system isn't foolproof, but it generally works very well. There have been discussions about moving to a "mandatory review" model, but there is concern that this might overly slow down development in the context of a volunteer-run project.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#142
post #111

Earlier quoted context omitted.

So what does people typically use pfSense/OPNsense for which OpenWRT can’t do, or is a bad fit for? Asking as a curious OpenWRT devotee.

I'd say anything remotely security relevant.

Is that based in any way on the relative capabilities and security track records of OpenWRT and pfSense, or is a highly security-conscious userbase merely what's left for pfSense after eliminating anyone who wants good WiFi support and the ability to run on cheap commodity consumer appliances with tight memory and storage limits?

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#143
post #90
post #74

Earlier quoted context omitted.

> It's not an elaborate insult. My read on it wasn't that it was an elaborate insult, but more that it was far more denigrating than it needed to be, if he was trying to be professional. That doesn't mean it was purposeful, sometimes people just don't really associate the statements they make with how it may be perceived. I think it could have been communicated clearly and succinctly with something along the lines of…

I get your point about perceptions, but there's also another aspect of why I found it important and necessary to describe just how poor the code was: When you're talking about replacing and rewriting the implementation on the eve of release, you better have a good reason for doing so. Stuffing a rewrite of security critical code into the kernel at the last minute is a big red flag. The main question that immediately…

I can see how someone could be insulted by that one paragraph on a personal level, especially if it had been the person that wrote the code. I can't think of a nice way to say it though.

However, on a professional level, when a core maintainer of a protocol tells you your code is bad, it's time to sit down, eat some humble pie, and start taking notes. I think that's especially true if you're offering help or are willing to address online communities with positive messaging to help them save face.

I think you handled it really well. I almost feel sorry for Netgate that they lashed out at someone so good at managing the technical (code), social (community), and political (bullshit) sides of a software project. Almost.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#144
post #72

Earlier quoted context omitted.

There's not a good way for me to respond to that without going off-topic. The following is assuming that wasn't a rhetorical question, if it was rhetorical I guess we may just agree to disagree: Until he issues a public apology for his actions, I'll refer to him as Kip. Changing your name to run from the google searches is completely understandable, and I support second chances, but you need to show a bit of remorse…

I don't really think that the 'online mob' has the right to hold someone's past actions over their head, and expect some public appeasement before it relents.

His interactions with James have done nothing to convince me that he’s become a decent human being.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#146
post #72

Earlier quoted context omitted.

There's not a good way for me to respond to that without going off-topic. The following is assuming that wasn't a rhetorical question, if it was rhetorical I guess we may just agree to disagree: Until he issues a public apology for his actions, I'll refer to him as Kip. Changing your name to run from the google searches is completely understandable, and I support second chances, but you need to show a bit of remorse…

I don't really think that the 'online mob' has the right to hold someone's past actions over their head, and expect some public appeasement before it relents.

What you think has no bearing on reality. They will because they can.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#147

PSA: pfSense is closed-source [1]. It was discussed last month here on HN [2]. OPNsense is the equivalent FOSS alternative [3]. [1] https://github.com/rapi3/pfsense-is-closed-source [2] https://news.ycombinator.com/item?id=25894420 [3] https://en.wikipedia.org/wiki/OPNsense

I hope this will make a lot people contribute to OPNsense because I really prefer their GUI and over pfsense.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#148
post #57

Earlier quoted context omitted.

Keep in mind, back in February of 2020 when Kip Macy first announced that Netgate had hired him to port Wireguard, Jason offered to help. First Kip declines the offer, then seems to warm slightly to it, but ultimately appears to have not actually engaged Jason. If I'm Jason and I offer my help (for free), they don't take me up on my offer, then try to release code that would make my baby look quite ugly, I would prob…

"Kip Macy" don't you mean Matt Macy ?

[deleted]

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#149
post #72

Earlier quoted context omitted.

"Kip Macy" don't you mean Matt Macy ?

There's not a good way for me to respond to that without going off-topic. The following is assuming that wasn't a rhetorical question, if it was rhetorical I guess we may just agree to disagree: Until he issues a public apology for his actions, I'll refer to him as Kip. Changing your name to run from the google searches is completely understandable, and I support second chances, but you need to show a bit of remorse…

I wasn't aware this was the same person. Thanks.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#150
post #139

Note that there's additional follow-up available here: https://lists.freebsd.org/pipermail/freebsd-hackers/2021-Mar...

Absolutely the best outcome. BSDs has always been ( to me at least ) about getting things right, take time to get it baked before committing. The old, out of fashion style of getting things done properly and not shipping for the sake of it. Which is both a good thing and a bad thing in the modern world. But it is a trade off. I also hope FreeBSD sort of look into why it was committed in the first place. Hopefully thi…

[deleted]
Post reply on HN