Live data from Hacker News

OpenBSD 6.4 released

openbsd.org

111–120 of 179 posts

Re: OpenBSD 6.4 released

#111
post #24
post #13

Linux is a depressing mess after you've used OpenBSD. Such a high quality system, with stellar documentation. It's unfortunate that Linux has become so popular even though the BSD's are so much better. A bad historical accident. Damn you Linus...

Is OpenBSD suitable for use on a laptop? I have a Dell Latitute 7370 running KDE Neon, and it runs really well. All hardware is supported, battery life is on-par with Windows, etc. Would OpenBSD work well on this laptop?

As that model has an intel chipset it will probably work fine. The main problem will be wireless because of Intel have the micro-code blob. IIRC you will need want to look at this:

https://man.openbsd.org/fw_update.1

It basically requires you to copy the firmware to a USB stick and run the tool and then Wireless just works.

Re: OpenBSD 6.4 released

#112
post #72
post #58

Earlier quoted context omitted.

Also, I think FreeBSD eliminated the giant lock ~10 years ago and maintains similarly good documentation. It’s just a matter of priorities, and SMP scalability/high performance has never been on the top of the OpenBSD list.

> It’s just a matter of priorities Yes, and goals. OpenBSD is much more conservative with regard to features, and focuses on security, and that results in a more secure system overall. If you need to eek out every last percent of performance, use something else. If you want to worry less about security on a system that is fairly exposed (e.g. a firewall), then it can be an extremely good fit. For example, here's a co…

On the other hand some of this can be explained by linux being a higher value target with more security research around it. If I find a remote exploit in the linux kernel I have a few billion targets, but if I find one in a *BSD I probably have a few million, tops.

Re: OpenBSD 6.4 released

#113
post #102

Earlier quoted context omitted.

> With OpenBSD specifically, you can get 90% of the way there with chroots, standard process isolation, and a bit of shell scripting This is a classic case of "THAT HackerNews response to Dropbox" [1]. If it's that easy, why isn't there a prepackaged wrapper with simple switches, rather than leaving developers to fight for themselves among piles of custom hacks? The problem is not just deployment, the Docker differen…

OpenBSD should seriously look at their story in that area, because it's one of the few where they could still potentially compete (because Docker is still fundamentally a pile of hacks, and pretty insecure too). I’m pretty sure the Open BSD developers are completely comfortable with their story. They develop this software for themselves first. If you like it and it’s useful to you you are welcome to it. If not, look…

> I’m pretty sure the Open BSD developers are completely comfortable with their story.

They were pretty comfortable with their patching story -- until enough people complained and lo, syspatch(8) appeared.

Beyond the posturing, nobody likes to run a project that nobody else uses; and sometimes even lusers are right.

> Every piece of the system is carefully thought out and organized

I am not saying they should rush out a crap docker clone, but rather a "carefully thought out and organized" docker alternative.

> you can do it yourself in 10 steps or less.

It's still 5x the steps you need with docker. As I said, it's about simple reproducibility rather than just isolation. Even if it were easy to write my own docker-compose (and indeed many people argued the same, when docker first emerged, because it actually was little more than shell scripts), having one well-defined set of tools helps tremendously with kickstarting adoption and to avoid reinventing the wheel every few weeks.

Re: OpenBSD 6.4 released

#114
post #113

Earlier quoted context omitted.

OpenBSD should seriously look at their story in that area, because it's one of the few where they could still potentially compete (because Docker is still fundamentally a pile of hacks, and pretty insecure too). I’m pretty sure the Open BSD developers are completely comfortable with their story. They develop this software for themselves first. If you like it and it’s useful to you you are welcome to it. If not, look…

> I’m pretty sure the Open BSD developers are completely comfortable with their story. They were pretty comfortable with their patching story -- until enough people complained and lo, syspatch(8) appeared. Beyond the posturing, nobody likes to run a project that nobody else uses; and sometimes even lusers are right. > Every piece of the system is carefully thought out and organized I am not saying they should rush ou…

I would be surprised if user complaints were the motivation for syspatch. More likely, the author built something he found useful, and contributed it to the project.

Most of the time on the openbsd email list, when a "user" suggests a feature or asks for a change to something, the reply is something along the lines of "sounds great, where is your patch?"

Re: OpenBSD 6.4 released

#115
post #113

Earlier quoted context omitted.

> I’m pretty sure the Open BSD developers are completely comfortable with their story. They were pretty comfortable with their patching story -- until enough people complained and lo, syspatch(8) appeared. Beyond the posturing, nobody likes to run a project that nobody else uses; and sometimes even lusers are right. > Every piece of the system is carefully thought out and organized I am not saying they should rush ou…

I would be surprised if user complaints were the motivation for syspatch. More likely, the author built something he found useful, and contributed it to the project. Most of the time on the openbsd email list, when a "user" suggests a feature or asks for a change to something, the reply is something along the lines of "sounds great, where is your patch?"

> More likely, the author built something he found useful, and contributed it to the project.

It required a service set up by the project itself. And this after years (decades?) of explicitly rejecting the concept of automated patching (because it supposedly engendered "a false sense of security"). Come on.

Re: OpenBSD 6.4 released

#116
post #113

Earlier quoted context omitted.

> I’m pretty sure the Open BSD developers are completely comfortable with their story. They were pretty comfortable with their patching story -- until enough people complained and lo, syspatch(8) appeared. Beyond the posturing, nobody likes to run a project that nobody else uses; and sometimes even lusers are right. > Every piece of the system is carefully thought out and organized I am not saying they should rush ou…

I would be surprised if user complaints were the motivation for syspatch. More likely, the author built something he found useful, and contributed it to the project. Most of the time on the openbsd email list, when a "user" suggests a feature or asks for a change to something, the reply is something along the lines of "sounds great, where is your patch?"

Exactly this. Unless of course you became an Iridium level donor with the caveat that someone promised to build a Docker clone for you.

Edit: And in response to toyg's comment, here is a link to a video of a talk by the developer in question, who mentions in passing that he builds things for OpenBSD that help him put it into production. This is less than a minute into his talk. Please educate yourself about the project before making ridiculous demands on the devs' time and falsely assigning wrong motives to them. It's unfriendly.

https://archive.fosdem.org/2018/schedule/event/openbsd_base_...

Re: OpenBSD 6.4 released

#117
post #35

Earlier quoted context omitted.

You can try it right now inside virtualbox, and 20 minutes later you realize that it is has all you need. After a few days, you'll notice that you spend most of your time inside the virtual machine, and then it makes sense to turn your setting upside down and work directly on the saner system.

OpenBSD just isn't performant enough for me. I can't honestly say that it has what I need when I get multi-second system freezes when opening or closing tabs in chromium (though this was under 6.0) Battery life under OpenBSD is atrocious compared even to Linux. It's a great server OS but it's not ready for laptop daily driver use unless your laptop just sits plugged in all day.

I use it as a daily driver for my laptop. It's quite performant. I also boot a linux distro sometimes on that machine, and don't notice much difference in battery life between the two.

They've been adding drivers like crazy for a while now, too, so there are many more hardware choices than there were a couple years ago.

Re: OpenBSD 6.4 released

#118
post #90
post #13

Linux is a depressing mess after you've used OpenBSD. Such a high quality system, with stellar documentation. It's unfortunate that Linux has become so popular even though the BSD's are so much better. A bad historical accident. Damn you Linus...

I've never understood why the end users of these free and libre kernels feel the need to fight so much.

I'm not sure, but I bet it's the same reason why (some of) the end users of, say, Boeing and Airbus aircraft feel the need to fight so much as well.

Re: OpenBSD 6.4 released

#120

Earlier quoted context omitted.

I would be surprised if user complaints were the motivation for syspatch. More likely, the author built something he found useful, and contributed it to the project. Most of the time on the openbsd email list, when a "user" suggests a feature or asks for a change to something, the reply is something along the lines of "sounds great, where is your patch?"

Exactly this. Unless of course you became an Iridium level donor with the caveat that someone promised to build a Docker clone for you. Edit: And in response to toyg's comment, here is a link to a video of a talk by the developer in question, who mentions in passing that he builds things for OpenBSD that help him put it into production. This is less than a minute into his talk. Please educate yourself about the proje…

> Please educate yourself about the project

Oh, I am educated enough, don't worry. Which is why I was so surprised to see it finally adopt a solution for a problem that had been pointed out for 20 years, after spending those 20 years replying to everyone that it was just the wrong thing to do in principle.

> It's unfriendly

It's also unfriendly to gaslight away blatant problems, for whatever reason, until they get fixed -- at which point they are admitted as actual problems. Then again, OpenBSD is hardly a friendly project, culturally speaking.

Post reply on HN