TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Solaris adopting OpenBSD's pf

129 pointsby mfinchamabout 10 years ago

7 comments

SwellJoeabout 10 years ago
&quot;Perhaps due to Oracle&#x27;s practice of putting beta testers under non-disclosure agreements, or possibly because essentially no tech journalists ever read OpenBSD developer-focused mailing lists, Oracle&#x27;s PF plans have not generated much attention in the press.&quot;<p>Or, perhaps it&#x27;s because Solaris doesn&#x27;t matter to anyone anymore.<p>I just spent a week, or so, updating our installer for Solaris, which is the first time I&#x27;ve spent any time on Solaris in a long while. I was surprised by how far behind <i>everything</i> is, and how difficult it is to find people actually doing things with Solaris, anymore.<p>The CSW and spec-files-extra, repositories are all but unmaintained and have been for years, and thus includes packages that are insecure by default. Sun Freeware is now a commercial service, that is expensive enough for me to assume they only have a few hundred users (tops). Installing anything beyond a bare bones AMP stack is an exercise in frustration unlike anything I&#x27;ve ever seen (and I&#x27;ve been messing with UNIX and Linux systems for 20+ years).<p>Solaris 11 currently has outdated everything. The Open Source community that had sprung up around Solaris during the early OpenSolaris years has fled to Illumos-based distributions (or to Linux or the BSDs, I guess; they certainly aren&#x27;t working on Solaris, anymore), none of which have the resources to even compete with a modern Linux or even the BSDs in terms of number of people working on making it nice, modern, and easy to deploy.<p>In short, Solaris is a wasteland. Oracle seems to just be milking the remaining corporate users until the cash cow falls over dead.
评论 #9364901 未加载
评论 #9364824 未加载
评论 #9366914 未加载
评论 #9365618 未加载
评论 #9365646 未加载
评论 #9369136 未加载
评论 #9365767 未加载
评论 #9368441 未加载
评论 #9365053 未加载
walterbellabout 10 years ago
Oct 2014 thread on FreeBSD-based pfSense fork of OpenBSD pf, <a href="https:&#x2F;&#x2F;forum.pfsense.org&#x2F;index.php?topic=83075.0" rel="nofollow">https:&#x2F;&#x2F;forum.pfsense.org&#x2F;index.php?topic=83075.0</a><p><i>&quot;2.2 should prove to be significantly more scalable than OpenBSD, since we have SMP-capable pf now, which isn&#x27;t doable in OpenBSD (and will likely be a number of years until it is). Plus AES-NI, more coming soon. <a href="https:&#x2F;&#x2F;blog.pfsense.org&#x2F;?p=1473" rel="nofollow">https:&#x2F;&#x2F;blog.pfsense.org&#x2F;?p=1473</a><p>Bug fixes are brought over into FreeBSD from OpenBSD as needed (sometimes by us, sometimes by others), though FreeBSD pf is essentially a fork at this point since making it SMP-capable changed things significantly. It&#x27;s mostly separately-maintained at this point.&quot;</i>
评论 #9365422 未加载
评论 #9365719 未加载
PhantomGremlinabout 10 years ago
The blog says:<p><pre><code> possibly because essentially no tech journalists ever read OpenBSD developer-focused mailing lists, Oracle&#x27;s PF plans have not generated much attention in the press </code></pre> But that glosses over the obscurity of the mailing list post. I skim the OpenBSD tech list, and I also overlooked this post. Why? Here&#x27;s the title:<p><pre><code> pfi_kif leaks for PBR rules </code></pre> That doesn&#x27;t scream &quot;read me&quot; to casual observers, does it?<p>As for support for the &quot;reveal&quot; in the title, the mailing list post goes on to say:<p><pre><code> also for your info: IPF in Solaris is on its death row. PF in 11.3 release will be available as optional firewall. We hope to make PF default (and only firewall) in Solaris 12. You&#x27;ve made excellent job, your PF is crystal-clear design. </code></pre> The IPF packet filter currently in Solaris was originally also in OpenBSD. It was replaced by pf in 2001 after the IPF author started playing games with the copyright.
tomglindmeierabout 10 years ago
That just underlines the amazing work the OpenBSD guys are doing. In the end quality wins. I hope OpenBSD gets more and more adoption in the industry.
talideonabout 10 years ago
IIRC, there&#x27;s work going on in FreeBSD port its multithreading patches up to the latest version of pf. Hopefully the extra resources brought by Solaris using pf will help make that a reality.
评论 #9365427 未加载
cnstabout 10 years ago
Only took some one year for people to notice...<p><a href="http:&#x2F;&#x2F;marc.info&#x2F;?l=openbsd-tech&amp;m=140335809432589&amp;w=2" rel="nofollow">http:&#x2F;&#x2F;marc.info&#x2F;?l=openbsd-tech&amp;m=140335809432589&amp;w=2</a>
gonzoabout 10 years ago
OpenBSD dev spams us to buy his book, attend his tutorial on pf at BSDcan, and buy OpenBSD CD-ROM sets.<p>Why is this on HN? Why not a link to the original announcement?
评论 #9366234 未加载