Mint minden november 1-én, ma is van OpenBSD release. Theo de Raadt pár órával ezelőtt jelentette be az OpenBSD 3.8-as verzióját:
``2005. november 1.
Örömmel jelentjük be az OpenBSD 3.8 hivatalos kiadását. Ez a 18. CD-ROM-on megjelenő kiadásunk (és a 19. FTP-n keresztüli). Továbbra is büszkék vagyunk az OpenBSD azon rekordjára, hogy nyolc év alatt csak egyetlen távoli rést tartalmazott az alapértelmezett telepítés. Mint a korábbi kiadásaink, a 3.8 is jelentős fejlesztéseket tartalmaz, beleértve új funkciókat is a rendszer majdnem teljes területén:''- Improved hardware support, including:
o New aps driver for the built-in accelerometer found in some IBM ThinkPad laptops.
o New art driver for Accom Networks Artery T1 and E1 cards.
o New auixp driver for the ATI IXP series integrated AC'97 audio controller.
o Basic RAID management using bioctl(8) in the ami(4) MegaRAID driver.
o New ciss driver for Compaq Smart ARRAY 5 and 6 RAID controllers.
o New epic driver for SMC 83C170 ethernet adapters.
o New ichwdt driver for Intel 6300ESB ICH watchdog timer.
o New pcn driver for the AMD Am79c97x (PCnet) ethernet adapters.
o New safte driver for SCSI Accessed Fault-Tolerant Enclosures, and a rewritten
ses driver for SCSI Enclosure Services, both allowing monitoring through
sysctl and sensorsd.
o New ueagle driver for Analog Devices Eagle ADSL modems.
o New uipaq driver for iPAQ USB serial.
o New viasio driver for VIA VT1211 LPC Super I/O hardware sensors.
o New zaudio driver for the built-in Zaurus audio CODEC.
o Improved com driver for serial port PCMCIA cards, such as cellular modems
on Zaurus.
o Improved support for many umass devices.
o Updated driver from X.Org for the Intel i810 family graphics chipset,
including support for the external VGA output on laptops.
- New tools:
o bioctl(8), a RAID management interface.
o ipsecctl(8), a simple IPsec management tool.
o stat(1), displaying file status obtained from stat(2) or lstat(2).
o hostapd(8), a wireless Host Access Point daemon.
o ifstated(8), a daemon monitoring ethernet interfaces status.
o watchdogd(8), companion to the hardware watchdog devices.
o ztsscale(8), a tool to calibrate the Zaurus touch screen.
o xidle(1), a tool to run a program on X inactivity.
o gzsig(1), create and verify cryptographic signatures built into gzip file headers.
o sasyncd(8), a daemon to synchronize IPSec SA's for failover gateways.
- New functionality:
o mount_udf(8), providing UDF (DVD) filesystem support.
o Network interface aggregation, using the virtual trunk(4) interface.
o Partial wide character and locale support in the C and C++ libraries.
o wd(4) disks have the security feature frozen before being attached
to prevent malicious users setting a password that would prevent the
contents of the drive from being accessed.
o On the OpenBSD/sparc64 platform, StackGhost buffer overflow exploit
protection has been added.
o zaudio(4) changes the mute values if the headphones are plugged in or out.
- New functionality for ospfd(8), the Open Shortest Path First Daemon:
o ospfd is now able to redistribute static, connected and default routes.
o ospfctl is now able to display all relevant information.
o Interoperability with cisco and Extreme has been improved.
o Support for parsing and displaying parsed configuration file, similar to bgpd.
o Support for cryptographic authentication has been added.
o Interface finite state machine has been reworked, primarily to improve
interoperability.
o The performance of the shortest path first calculation has been improved.
o Numerous bugs have been discovered and fixed during the last 6 months.
- New functionality for bgpd(8), the Border Gateway Protocol Daemon:
o bgpd is now able to redistribute static and connected routes dynamically.
o Full route label support; pf(4) can filter based on information bgpd
attaches to the routes.
o An additional per prefix weight has been added used to evaluate prefixes
with equal AS path length.
o New route decision tunable rde med compare always to force bgpd to compare
the MED independent of the peer AS.
o IPv6 support.
- Assorted improvements and code cleanup:
o malloc(3) has been rewritten to use the mmap(2) system call,
introducing unpredictable allocation addresses and guard pages, which
helps in detecting heap based buffer overflows and prevents various
types of attacks.
o libc(3) source code has been converted to ANSI C.
o realpath(3) is now thread safe.
o Several pathname races and potential buffer handling problems have been
fixed in pax(1).
o Problems with signal delivery on OpenBSD/sparc and OpenBSD/sparc64 have
been fixed.
o Reliability of signal handlers using floating point on
OpenBSD/i386 and OpenBSD/macppc has been improved.
o NFS write performance has been improved greatly.
o Countermeasures against various blind ICMP attacks have been implemented.
- Over 3200 ports, 3000 pre-built packages, improved package tools.
- As usual, many improvements in manual pages and other documentation.
- OpenSSH 4.2:
o Adds a new compression method that delays the start of zlib
compression until the user has been authenticated successfully. The
new method ("Compression delayed") is on by default in the server and
eliminates the risk of any zlib vulnerability leading to a compromise
of the server from unauthenticated users.
o Added support for the improved arcfour cipher modes from
draft-harris-ssh-arcfour-fixes-02. The improves the cipher's
resistance to a number of attacks by discarding early keystream
output.
o Many improvements to connection multiplexing, including a new
opportunistic multiplexing mode, automatic fallback to plain
connections when multiplexing fails and support for multiplexed X11
and agent forwarding.
o Many additional bug fixes and improvements, as described in the
release announcement.
- This release of OpenBSD includes the following major components from
outside suppliers:
o X.Org 6.8.2 (+ patches, and i386 contains XFree86 3.3.6 servers (+ patches)
for legacy chipsets not supported by X.Org)
o Gcc 2.95.3 (+ patches) and 3.3.5 (+ patches)
o Perl 5.8.6 (+ patches)
o Apache 1.3.29, mod_ssl 2.8.16, DSO support (+ patches)
o OpenSSL 0.9.7g (+ patches)
o Groff 1.15
o Sendmail 8.13.4, with libmilter
o Bind 9.3.1 (+ patches)
o Lynx 2.8.5rel.2 with HTTPS and IPv6 support (+ patches)
o Sudo 1.6.8p9
o Ncurses 5.2
o Latest KAME IPv6
o Heimdal 0.6.3 (+ patches)
o Arla 0.35.7
o Binutils 2.15 (+ patches)
o Gdb 6.3
A teljes bejelentés itt.