Consider two OpenBSD PF configurations:
pf1.conf, where SSH blocked by default, but internal LAN traffic is allowed:
block in on em0 proto tcp to port 22
pass in quick on em0 proto tcp from 192.168.0.0/16 to any
and updated pf2.conf, where someone added quick to the blocking rule "for safety's sake":
block in quick on em0 proto tcp to port 22
pass in quick on em0 proto tcp from 192.168.0.0/16 to any
quick was added to a broad block rule, silently shadowing the subsequent quick pass rule. Both are quick rules, both are present, and the change consists of just one word. A reviewer might reason: "The pass rule still has quick, so LAN traffic should still go through." However, among quick rules, the "first-match-wins" principle applies, not "last-match-wins": the block in quick rule now matches LAN traffic before the quick pass rule and shadows it. "Last-match-wins" only applies to non-quick rules. Visually, nothing appears broken, yet the behavior has changed.
And proofwall detect this:
$ ./proofwall diff -n 2 pf1.conf pf2.conf
DIFFERENT: rulesets are NOT semantically equivalent. Regressions (2): pass in A, block in B:
- 192.168.0.0:0 -> 0.0.0.0:22 proto=tcp flags=0x00 iface="em0" dir=in
- 192.168.0.0:0 -> 0.0.0.0:22 proto=tcp flags=0xff iface="em0" dir=in
Rule issues (1):
[B] line 2: redundant rule (removing it changes nothing): pass in quick on em0 proto tcp from 192.168.0.0/16 to any
This is interpreted as follows: a regression specifically for 192.168.0.0/16 -> tcp/22 (traffic that previously passed is now blocked), while the pass ... quick rule in the second config has become redundant - its effect is completely overridden by an earlier block quick rule.
OpenBSD 7.9 released
Release notes: https://www.openbsd.org/79.html
Announce: https://marc.info/?l=openbsd-announce&m=177919671915512&w=2
OpenBSD Errata: October 7, 2026 (isakmpd xserver expat wsdisplay)
Errata patches for isakmpd, X11 server, libexpat and kernel wscons have been released for OpenBSD 7.8 and 7.9.
Binary updates for the amd64, arm64 and i386 platform are available via the syspatch utility. Source code patches can be found on the
respective errata page:
Notable changes in this release include:
LibreSSL 4.2.2 and 4.3.3 released
Recently the OpenSSH team have received a large number of security bug reports, many of which are findings from AI models or made with AI assistance. While many AI reports are determined not to have security impact when considered in the context of a realistic threat model, we very much welcome these reports, especially when combined with human triage, analysis, test-cases and particularly when accompanied by proposed fixes.
We have seen a number of cases where a security bug identified by AI tools is subsequently independently discovered by a different researcher. This suggests that adversaries who do not report bugs to OSS projects are likely to be able to discover these bugs too. Given this, the OpenSSH team will, for now, be making more frequent releases to get bugfixes into users' hands more quickly rather than batching them until the next planned release.
Un-hanging the HP Envy 17-DA0013dx for OpenBSD
Native Mac man page editor with syntax coloring, mandoc syntax checking & live preview.
https://github.com/sveinbjornt/ManDrake
(this can be easily replaced by vim, tmux and mandoc)
"On Random Numbers" - an RFC draft written by Damien Miller and Rich Salz.
Input devices on OpenBSD for console, X11 and Wayland - Matthieu Herrb
Slides: https://www.openbsd.org/papers/eurobsdcon2026-matthieu-input.pdf
Video: https://exquisite.tube/w/iMjFGHMDpVGg4gk41ZVWvQ
This talk will present the current state of the input device "stack" on OpenBSD, and discuss some ideas for upcoming changes in order to get the console, X.Org and Wayland applications the best possible support.
There are challenges with the different event encoding models, hot-plugging devices and handling their suspend and resume life cycles.
Rafael Sadowski (@sizeofvoid) told about his recent work on httpd(8) and relayd(8).
Headers Up! What's New in httpd and relayd
Unix Manpages, Then and Now - Kristaps Dzonsons
OpenNTPD - 20 years and a few milliseconds later - Henning Brauer
From Report to Patch, the OpenBSD Errata Process -
Alexander Bluhm
Video: https://exquisite.tube/w/sDafcZjdEQpR83aogPSx9j
Slides: https://www.openbsd.org/papers/eurobsdcon2026-bluhm-errata.pdf
New blog post: #EuroBSDCon in Brussels, then the w2k26 #OpenBSD hackathon in Edmonton.
🐡 httpd: header block/drop rules
🐡 relayd: regress tests + failover ideas
🐡 SDDM on OpenBSD, KWin on Wayland
🐡 What Plasma 6.8 means for KDE on OpenBSD
https://rsadowski.de/posts/2026/w2k26-edmonton-openbsd-hackathon/
Theo de Raadt has sent a follow-up to a proposal he sent early last year to #OpenBSD tech@, "Locking down openat(2) and friends with O_BELOW and F_BELOW"
I started this journey to lock down the file traversal abilities of openrsync, because unveil and pledge didn't work there. I decided to look at putting a restriction on the dirfd.
My proposal is that we lock the dirfd with a F_BELOW flag saying that only downwards traversals are permitted. This flag can be set with fcntl(), or in open() with O_BELOW.
When the openat(2)-family sees a dirfd is locked, that call will not process an absolute path and won't allow traversals upwards using "..". The call returns ENOENT.
I'd like to thank @mlarkin for helping keep my old Opteron 4162s going with the latest VMM changes. I had a real rollercoaster with the 8.0-snapshot changes. First, it sounded like family 10h Opterons (like the 4162) would no longer be supported because of missing the NRIPS instruction. It turns out that they actually do support it, however. My first test of 8.0 worked, but when I updated things were broken, but it boiled down to a one line fix which is now in place.
https://cvsweb.openbsd.org/diff/src/usr.sbin/vmd/x86_vm.c?rev=1.28&prev=1.27
Now I can keep stability testing on 8.0 to make sure everything else is working well!
OpenBSD formal driver verification with SeL4
Paper: https://arxiv.org/pdf/2311.03585v1
Source: gitlab.com/system.verification/openbsd-formal-driver-verification-with-sel4
Unofficial OpenBSD news, updates and thoughts. #OpenBSD #WhyOpenBSD #RunBSD #PlayOnBSD #CallForTesting #OpenSSH #EuroBSDCon #AsiaBSDCon #BSDCan #errata #release
Chief editor: @sergeyb