Hasty Briefsbeta

Bilingual

HardenedBSD August / September 2026 Status Report

5 hours ago
  • HardenedBSD quarterly release engineering week is upcoming, with plans to cherry-pick security-related commits from FreeBSD's main branch into 15-stable.
  • Source changes include disabling pkgbase in bsdinstall, updating os-release files, enabling -ftrivial-var-auto-init=zero for video(4), fixing man page links, documenting rejection of AI-generated works, hardening ssh_config by disabling compression and TCP keepalives, and integrating experimental -fbounds-safety flag (disabled by default).
  • Ports change: fixed broken dependency for math/libformfactor.
  • -fbounds-safety is experimental and disabled by default; plumbing added to allow downstream users to integrate it into their own code, with future plans for kernel support once deemed production-ready.
  • Infrastructure updates: migrated rad.hardenedbsd.org and ngx-01 from VMs to jails, resolved initial issues but latent problems remain; next migration is rsync VM after quarterly builds, then Tor Onion Service modernization.
  • Enhanced auto-sync program to support multiple remotes, including GitHub mirroring every six hours; no plans to mirror auxiliary projects.
  • Long-term plan is to write a Rust orchestration daemon to interact with Radicle's control socket for CI/CD-lite functionality, which will also improve Rust skills.
  • Radicle vulnerability disclosed on 23 Sep 2026: malicious nodes can disclose private repositories, and traffic encryption only covers initial handshake. HardenedBSD avoids private repos and offers Tor Onion Service for encrypted transit, so not vulnerable to exposure but recommends Tor for traffic analysis.
  • Radicle's future migration to iroh will require coordinated efforts; formal testing and verification needed in protocol development; support and encouragement for Radicle team.
  • Personal reflection: mistakes happen, but formal verification should be standard; encourages proactive testing and Rust contributions.