3.6

Ponderosa Released November 1, 2004
Copyright 1997-2004, Theo de Raadt.
ISBN 0-9731791-4-7
3.6 Song: "Pond-erosa Puff (live)"

All applicable copyrights and credits are in the src.tar.gz, sys.tar.gz, xenocara.tar.gz, ports.tar.gz files, or in the files fetched via ports.tar.gz.


What's New

This is a partial list of new features and systems included in OpenBSD 3.6. For a comprehensive list, see the changelog leading to 3.6.

  • New platform:
    • OpenBSD/luna88k
      Expanding the mvme88k porting effort by supporting Omron's line of 88100-based workstations.

  • SMP support on OpenBSD/i386 and OpenBSD/amd64 platforms.

  • New functionality:
    • A cleaned up DHCP server and client implementation, now featuring privilege separation and safe defaults.
    • A new NTP daemon written from scratch, which ought to fit the needs of most NTP users.
    • pfctl(8) now provides a rules optimizer to help improve filtering speed.
    • The packet filter, pf(4), now supports nested anchors.
    • tcpdrop(8), a command to drop TCP connections.
    • The NMBCLUSTERS option has been eliminated, replaced by a sysctl with higher default values on many platforms.
    • Added support for cksum (three flavours), md4, sha256, sha384 and sha512 to the md5(1) command.
    • Memory file systems created by the mount_mfs(8) command now can be populated immediately after creation.
    • New hotplugd(8) daemon and hotplug(4) device that watch for newly attached devices.
    • isakmpd(8) now supports NAT-traversal and Dead Peer Detection (RFC 3706).
    • strtonum(3), a simple, robust and therefore safe function to convert strings to numbers, has been added.
    • On the OpenBSD/sparc platform, StackGhost buffer overflow exploit protection has been added.
    • A generic IEEE 802.11 framework has been added.

  • Improved hardware support, including:
    • Sangoma T1 and E1 cards (san(4)).
    • Jumbo frames are now working reliably on em(4), sk(4), and ti(4) adapters.
    • USB 2.0 (ehci(4)) controllers.
    • AIC79xx-based Ultra320 SCSI adapters, such as the Adaptec 29320 and 39320 (ahd(4)).
    • The i386 and amd64 CD bootloader code no longer emulates a floppy which improves the chances of booting on newer machines.
    • New atw(4) driver for ADMtek ADM8211 802.11b wireless adapters.
    • New axe(4) driver for ASIX Electronics AX88172 USB Ethernet adapters.
    • New cdce(4) driver for Ethernet over USB bridges.
    • New ichpcib(4) driver for Intel ICHx/ICHx-M LPC PCI-ISA bridges.
    • New gscpcib(4) driver for National Semiconductor Geode SC1100 PCI-ISA bridges.
    • New iic(4) driver for Inter IC (I2C) master/slave buses.
    • New lmtemp(4) driver for National Semiconductor LM75/LM77 temperature sensors.
    • New gscsio(4) driver for National Semiconductor Geode SC1100 Super I/O chips.
    • New gpio(4) driver and accompanying gpioctl(8) utility for supporting General Purpose Input/Output.
    • New mediabay(4) macppc driver for the ATA33 HD controller over removable CD.
    • New re(4) driver for Realtek 8169/8169S/8110S PCI Ethernet adapters.
    • hw.setperf sysctl hooks for PowerNow in AMD K6 and K7 processors.

  • New functionality for bgpd(8), the Border Gateway Protocol Daemon:
    • Kernel memory management improvements now allow the full global routing table to be kept in memory without customizing or tuning.
    • Support for adding received prefixes to a pf(4) table.
    • Support for IPsec, both manually keyed and using IKE.
    • Support for setting BGP communities (RFC1997) on incoming and outbound UPDATES.
    • Support for NOPEER community (RFC3765).
    • Partial support for RFC2858 Multiprotocol Capabilities, currently only IPv4-unicast is announced.
    • Support for Route Reflection (RFC2796).
    • Support for dynamic network announcements.
    • Support for Route Refresh Capability (RFC2918).

  • Improved NFS performance and reliability.

  • Shared libraries and gcc 3.3.2 on the OpenBSD/hppa port.

  • Privilege separation or revocation for the following programs:

  • Over 2700 ports, 2500 pre-built packages.

  • Many improvements for security and reliability (look for the red print in the complete changelog).

  • As usual, many improvements in manual pages and other documentation.

  • OpenSSH 3.9:
    • sshd(8) now re-executes itself on accepting a new connection. This security measure ensures that all execute-time randomizations are reapplied for each connection rather than once, for the master process' lifetime. This includes mmap and malloc mappings, shared library addressing, shared library mapping order, ProPolice and StackGhost cookies on architectures that support such things.
    • Selected environment variables can now be passed between the client and the server.
    • Session multiplexing: a single ssh connection can now carry multiple login/command/file transfer sessions.

  • The system includes the following major components from outside suppliers:
    • XFree86 4.4.0 unencumbered (+ patches, and i386 contains 3.3.6 servers (+ patches) for legacy chipsets not supported by 4.4)
    • Gcc 2.95.3 (+ patches) and 3.3.2 (+ patches)
    • Perl 5.8.5 (+ patches)
    • Apache 1.3.29, mod_ssl 2.8.16, DSO support (+ patches)
    • OpenSSL 0.9.7d (+ patches)
    • Groff 1.15
    • Sendmail 8.13.0, with libmilter
    • Bind 9.2.3 (+ patches)
    • Lynx 2.8.5rel.2 with HTTPS and IPv6 support (+ patches)
    • Sudo 1.6.7p5
    • Ncurses 5.2
    • Latest KAME IPv6
    • Heimdal 0.6rc1 (+ patches)
    • Arla 0.35.7
    • Binutils 2.14
    • Gdb 6.1


How to install

Following this are the instructions which you would have on a piece of paper if you had purchased a CDROM set instead of doing an alternate form of install. The instructions for doing an ftp (or other style of) install are very similar; the CDROM instructions are left intact so that you can see how much easier it would have been if you had purchased a CDROM instead.


Please refer to the following files on the three CDROMs or ftp mirror for extensive details on how to install OpenBSD 3.6 on your machine:


Quick installer information for people familiar with OpenBSD, and the use of the "disklabel -E" command. If you are at all confused when installing OpenBSD, read the relevant INSTALL.* file as listed above!

OpenBSD/i386:

Play with your BIOS options to enable booting from a CD. The OpenBSD/i386 release is on CD1. If your BIOS does not support booting from CD, you will need to create a boot floppy to install from. To create a boot floppy write CD1:3.6/i386/floppy36.fs to a floppy and boot via the floppy drive.

Use CD1:3.6/i386/floppyB36.fs instead for greater scsi controller support, or CD1:3.6/i386/floppyC36.fs for better laptop support.

If you can't boot from a CD or a floppy disk, you can install across the network using PXE as described in the included INSTALL.i386 document.

If you are planning on dual booting OpenBSD with another OS, you will need to read INSTALL.i386.

To make a boot floppy under MS-DOS, use the "rawrite" utility located at CD1:3.6/tools/rawrite.exe. To make the boot floppy under a Unix OS, use the dd(1) utility. The following is an example usage of dd(1) , where the device could be "floppy", "rfd0c", or "rfd0a".

# dd if=<file> of=/dev/<device> bs=32k

Make sure you use properly formatted perfect floppies with NO BAD BLOCKS or your install will most likely fail. For more information on creating a boot floppy and installing OpenBSD/i386 please refer to this page.

OpenBSD/vax:

Boot over the network via mopbooting as described in INSTALL.vax.

OpenBSD/amd64:

The 3.6 release of OpenBSD/amd64 is located on CD2. Boot from the CD to begin the install - you may need to adjust your BIOS options first. If you can't boot from the CD, you can create a boot floppy to install from. To do this, write CD2:3.6/amd64/floppy36.fs to a floppy, then boot from the floppy drive.

If you can't boot from a CD or a floppy disk, you can install across the network using PXE as described in the included INSTALL.amd64 document.

If you are planning to dual boot OpenBSD with another OS, you will need to read INSTALL.amd64.

OpenBSD/macppc:

Put the CD2 in your CDROM drive and poweron your machine while holding down the C key until the display turns on and shows OpenBSD/macppc boot.

Alternatively, at the Open Firmware prompt, enter boot cd:,ofwboot /3.6/macppc/bsd.rd

OpenBSD/sparc:

The 3.6 release of OpenBSD/sparc is located on CD3. To boot off of this CD you can use one of the two commands listed below, depending on the version of your ROM.

ok boot cdrom 3.6/sparc/bsd.rd
or
> b sd(0,6,0)3.6/sparc/bsd.rd

If your SPARC system does not have a CD drive, you can alternatively boot from floppy. To do so you need to write CD3:3.6/sparc/floppy36.fs to a floppy. For more information see this page. To boot from the floppy use one of the two commands listed below, depending on the version of your ROM.

ok boot floppy
or
> boot fd()

Make sure you use a properly formatted floppy with NO BAD BLOCKS or your install will most likely fail.

If your SPARC system doesn't have a floppy drive nor a CD drive, you can either setup a bootable tape, or install via network, as told in the INSTALL.sparc file.

OpenBSD/sparc64:

Put the CD3 in your CDROM drive and type boot cdrom.

If this doesn't work, or if you don't have a CDROM drive, you can write CD3:3.6/sparc64/floppy36.fs to a floppy and boot it with boot floppy.
Make sure you use a properly formatted floppy with NO BAD BLOCKS or your install will most likely fail.

You can also write CD3:3.6/sparc64/miniroot36.fs to the swap partition on the disk and boot with boot disk:b.

If nothing works, you can boot over the network as described in INSTALL.sparc64

OpenBSD/alpha:

Write 3.6/alpha/floppy36.fs or 3.6/alpha/floppyB36.fs (depending on your machine) to a diskette and enter boot dva0. Refer to INSTALL.alpha for more details.

Make sure you use a properly formatted floppy with NO BAD BLOCKS or your install will most likely fail.

OpenBSD/cats:

After updating the firmware to at least ABLE 1.95 if necessary, boot 3.6/cats/bsd.rd from an ABLE-supported device (such as a CD-ROM or an existing FFS or EXT2FS partition).

OpenBSD/hp300:

Boot over the network by following the instructions in INSTALL.hp300.

OpenBSD/hppa:

Boot over the network by following the instructions in INSTALL.hppa or the hppa platform page.

OpenBSD/luna88k:

Copy bsd.rd to a Mach or UniOS partition, and boot it from the PROM. Alternatively, you can create a bootable tape and boot from it. Refer to the instructions in INSTALL.luna88k for more details.

OpenBSD/mac68k:

Boot MacOS as normal and partition your disk with the appropriate A/UX configurations. Then, extract the Macside utilities from 3.6/mac68k/utils onto your hard disk. Run Mkfs to create your filesystems on the A/UX partitions you just made. Then, use the "BSD/Mac68k Installer" to copy all the sets in 3.6/mac68k/ onto your partitions. Finally, you will be ready to configure the "BSD/Mac68k Booter" with the location of your kernel and boot the system.

OpenBSD/mvme68k:

You can create a bootable installation tape or boot over the network.
The network boot requires a MVME68K BUG version that supports the NIOT and NBO debugger commands. Follow the instructions in INSTALL.mvme68k for more details.

OpenBSD/mvme88k:

You can create a bootable installation tape or boot over the network.
The network boot requires a MVME88K BUG version that supports the NIOT and NBO debugger commands. Follow the instructions in INSTALL.mvme88k for more details.


Notes about the source code

src.tar.gz contains a source archive starting at /usr/src. This file contains everything you need except for the kernel sources, which are in a separate archive. To extract:

# mkdir -p /usr/src
# cd /usr/src
# tar xvfz /tmp/src.tar.gz

sys.tar.gz contains a source archive starting at /usr/src/sys. This file contains all the kernel sources you need to rebuild kernels. To extract:

# mkdir -p /usr/src/sys
# cd /usr/src
# tar xvfz /tmp/sys.tar.gz

Both of these trees are a regular CVS checkout. Using these trees it is possible to get a head-start on using the anoncvs servers as described here. Using these files results in a much faster initial CVS update than you could expect from a fresh checkout of the full OpenBSD source tree.


How to upgrade

If you already have an OpenBSD 3.5 system, and do not want to reinstall, upgrade instructions and advice can be found in the Upgrade Guide.


Ports Tree

A ports tree archive is also provided. To extract:

# cd /usr
# tar xvfz /tmp/ports.tar.gz

The ports/ subdirectory is a checkout of the OpenBSD ports tree. Go read the ports page if you know nothing about ports at this point. This text is not a manual of how to use ports. Rather, it is a set of notes meant to kickstart the user on the OpenBSD ports system.

The ports/ directory represents a CVS (see the manpage for cvs(1) if you aren't familiar with CVS) checkout of our ports. As with our complete source tree, our ports tree is available via anoncvs. So, in order to keep current with it, you must make the ports/ tree available on a read-write medium and update the tree with a command like:

# cd [portsdir]/; cvs -d anoncvs@server.openbsd.org:/cvs update -Pd -rOPENBSD_3_6

[Of course, you must replace the local directory and server name here with the location of your ports collection and a nearby anoncvs server.]

Note that most ports are available as packages on our mirrors. Updated packages for the 3.6 release will be made available if problems arise.

If you're interested in seeing a port added, would like to help out, or just would like to know more, the mailing list ports@openbsd.org is a good place to know.