This is Shawn Webb from The HardenedBSD Project. I use the bsd.network Mastodon
instance. This message is cryptographically signed with GPG by me.
My GPG public key can be found here: https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/raw/master/Shawn_Webb/03A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc
-----BEGIN PGP MESSAGE-----
owGbwMvMwMH4Xy99UfmPh78Y1zL6JYnlJhaX5Kfk5+mWpRZlplXqGhjqlVSUJGeY
LgrJyCxWAKLgjMTyPIXw1KQkhbSi/FyFkIxUBY/EopTUvNQUp2AXhYCi/KzU5BI9
BU+F0uJUhRKgdFJxil5eakl5flG2gi/UAq7MvOKSxLzkVD0FsMm5qcXFiempIBuS
iyoLSvLTixILMjKTE3NyKhWKM9OBpiuUZ5ZkKLgHuCskVQLV63Fx+VaCuQWlSTmZ
yQrZqZUKyYl5CkmpCmn5pXkpChmpRalWChklJQXFVvr66ZklehlQh4JclF+Uro/E
1weaAjShWF9XvyixXB8UEKlF+mDfxoN8q29g7Gji7OTq5GRh5Opo6mhm7mLpZmxh
auzmZuRqZu5oZG7uZuFq6OaoBzRIL7E4mauTyZiFgZGDQVZMkYV5yenXO/SWLqud
bxEMC3FWJlC4MnBxCsBEvBj5f7N6cu+IKbu0W9lzaq5JetLVD0ey12mlHj/msqfr
uMmbBZ2rOf6eiDQ12V/pp1l/w0Ju+qff7rKnLq8qjH8Y2HftWnv1m9DK8/uSXk9J
/NQl9a9e51utUPdGNZGFvBUXbGX5P+7f+XL6ogtGJjf0Jk24c1P5e2bWNwfOA29l
Kz236GmtXXjaJunG0S12P8z6+CXiTdeJnFeW4Fp0yr3sor7ZBc1LCnZ+ukIzsoUW
r1885eyr9fsvcagHKLIuMn17yULsYECJdOBR6d3FW56kuav+e9UYqsFffvXUAY0Q
k2sdUbu+v2mpuaid7R0mu+QTg2WXb1haZjzP+qU35nxPOciRX6ctoXTrTXPwlAs3
d22bFTjllBPfffYbUx5Oc9lcuP6Sj+QWzxfv/i+N++nAc/Ndk8zHfdrfd6pqb345
b/F5lo+eBf8bb+rN/Ow6YdaFp9ElyUcVOnR0Xe28jxdM32v/trTjM+P27fqmZtJG
mROK/z3I/JuwZMHy0ysTr9rUB29d+PFK7ELzvPSKG+uZJxzNnblu08lT4S6mLK3H
/5wSvKvUz6Sd0XEt4JEA55qrbEon1SfuO6xVI3Uju8trfkRYLtPZ4x+kth++quT8
NG7qhe87tu2pNee4Pj30vGXotRtnjlbcn270NSj0A2u4y87LgqyTlOxuam+M/Xwx
753l+S9yCjoi1TevTP81R+xzQrpdcsO0Zz4qH5Qr3adfAwA=
=E4qi
-----END PGP MESSAGE-----
#HardenedBSD 15-STABLE and 16-CURRENT OS installer images and updates are building now.
I needed to tell #nginx to bypass the caching and throttling for git clones.
Now we should see much more stable access to the HardenedBSD repos over HTTPS.
I ended up reverting the entire jail back to a ZFS autosnapshot from last night. nginx is happy again, but I still have no idea why.
So this morning, I went to debug some issues with the #HardenedBSD #nginx server.
Now, when I try to start nginx, I get the following:
nginx: [emerg] limit_req_zone "radicle_api" is already bound to key "$server_name" in /usr/local/etc/nginx/zones/active/rad.hardenedbsd.org:1
The config file in question: https://hardenedbsd.org/~shawn/2026-10-01_rad.hardenedbsd.org.conf-r01.txt
I haven't changed a single line. Does anyone know what's going on? Why this started failing?
Creating the #HardenedBSD 2026q4 branches now.
Today is brought to you by #Maybeshewill : https://www.youtube.com/watch?v=KJ5ZcZ5SzBo
LLDB/FreeBSD project is almost over and I just finished the hardest part (trapframe unwinding). I wrote a blog post on how I approached this issue. It’s not technical deep dive, but it’ll help people to understand how kernel debugging changes in future versions of FreeBSD.
Buffer overflow in PCRE2's JIT implementation. Ouch.
In related news, PCRE2 will no longer be built with JIT on #HardenedBSD : https://radicle.network/nodes/rad.hardenedbsd.org/ports/commits/af6e19efae37c154b463ee3d8e8362874494acb6
I started the #HardenedBSD 2026q4 release engineering process this evening. Initial basic testing of 16-CURRENT succeeded on a #Protectli FW4B.
Building 15-STABLE now.
Today, I forgot that we disable TCP forwarding in sshd in #HardenedBSD by default.
It took an embarrassingly long time to remember that crucial little detail today.
HardenedBSD cofounder, Emerald Onion Advisory Board member, employed in offensive cybersecurity, all around infosec wonk.