Annotation of www/plus20.html, Revision 1.16
1.1 deraadt 1: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML Strict//EN">
2: <html>
3: <head>
4: <title>OpenBSD 2.0 changes</title>
5: <link rev=made href=mailto:www@openbsd.org>
6: <meta name="resource-type" content="document">
7: <meta name="description" content="the main OpenBSD page">
8: <meta name="keywords" content="openbsd,main">
9: <meta name="distribution" content="global">
10: <meta name="copyright" content="This document copyright 1996 by OpenBSD.">
11: </head>
12:
13: <BODY BGCOLOR="#FFFFFF" TEXT="#000000" LINK="#23238E">
14:
1.15 jsyn 15: <a href="index.html"><img alt="[OpenBSD]" height="30" width="141" src="images/smalltitle.gif" border="0"></a>
1.1 deraadt 16: <p>
1.7 deraadt 17: <h2><font color=#e00000>Changes made between birth and OpenBSD 2.0.</font><hr></h2>
1.1 deraadt 18:
19: <p>
20: This is a partial list of the major machine independent changes
21: (ie. these are the changes people ask about most often). Port
22: specific changes have also been made, and are sometimes mentioned
23: in the pages for the specific <a href=plat.html>ports</a> if you
24: are interested in further port-specific details. Many ports
25: have had architecture-specific enhancements relative to NetBSD,
26: but when they do not they certainly have plenty of platform-independent
27: changes, starting with those listed below..
28:
29: <p>
30: Note: <font color=#e00000>Problems for which patches exist are marked in red</font>.
31:
32: <p>
33: <h3>
1.16 ! deraadt 34: <a href="plus21.html">For changes leading up to OpenBSD 2.1, click here</a>.<br>
! 35: <a href="plus22.html">For changes leading up to OpenBSD 2.2, click here</a>.<br>
! 36: <a href="plus23.html">For changes leading up to OpenBSD 2.3, click here</a>.<br>
! 37: <a href="plus24.html">For changes leading up to OpenBSD 2.4, click here</a>.<br>
! 38: <a href="plus25.html">For changes leading up to OpenBSD 2.5, click here</a>.<br>
! 39: <a href="plus26.html">For changes leading up to OpenBSD 2.6, click here</a>.<br>
! 40: <a href="plus27.html">For changes leading up to OpenBSD 2.7, click here</a>.<br>
! 41: <a href="plus28.html">For changes leading up to OpenBSD 2.8, click here</a>.<br>
! 42: <a href="plus29.html">For changes leading up to OpenBSD 2.9, click here</a>.<br>
! 43: <a href="plus30.html">For changes leading up to OpenBSD 3.0, click here</a>.<br>
1.14 deraadt 44: <a href="plus31.html">For changes leading up to OpenBSD 3.1, click here</a>.<br>
1.16 ! deraadt 45: <a href="plus.html">For changes in OpenBSD-current, click here</a>.
1.1 deraadt 46: <br>
47: </h3>
48:
49: <h3><font color=#0000e0>OpenBSD 2.0 released.</font></h3><p>
50: <ul>
51: <li>CTM is now a supported way of obtaining OpenBSD source code.
52: <li>Added sudo (which is maintained by one of our developers)
53: <li>Working Linux ext2fs.
54: <li>We have completed security reviews of almost all userland programs and libraries except for the gnu stuff (where, based on preliminary inspection there is poor handling of temp files).
55: <li>FreeBSD's adduser(8) command. Also an rmuser(8) command.
56: <li>A 7% reduction in size of static binaries.
57: <li>Compile time option to compile the source tree almost completely dynamic.
58: <li>Almost a hundred more security fixes, including /tmp races because of strncpy.
59: <li>Another kerberos security fix.
60: <li>deal with the SYN bomb problem (denial of service attack) as well known.
61: <li>less version 2.90
62: <li>mopd for networking booting Digital machines
63: <li>latest GNU groff, incorporated in a clean wrapperized form.
64: <li>secure multicast tools against possible security problems.
65: <li>sendmail gecos hole fixed (in a number of ways; other programs in the source tree were also vulnerable.)
66: <li>Nice sample files in /etc
67: <li>16 partitions working on sparc and i386 (yipee!)
68: <li>vim is replacing nvi, since nvi does not have a pure BSD license, and vim also works better.
69: <li>And of course... more security related bugfixes... (ie. dump, restore, mt).
1.4 rohee 70: <li>ftp command modified for easily scripted ftp & http downloads.
1.1 deraadt 71: <li>Complete in-tree development for MIPS/Alpha systems (ie. binutils).
72: <li>New routed from SGI.
73: <li>*Hobbit*'s netcat utility. The crackers use it, so should you.
74: <li>Say goodbye to dump, restore, and mt security holes: They are no longer setuid.
75: <li>DDB can now access symbol tables from LKM modules
76: <li>Some serial driver support for /dev/cuaXX devices to support transparent out+dial
77: <li>FreeBSD pipe() system call; quite a bit faster.
78: <li>libgnumalloc is gone; our malloc() is better.
79: <li>Kernel warns if /dev/console does not exist; nice warning for booting with an unpopulated /dev directory.
80: <li>cdio command for using CD audio.
81: <li>Even more security fixes.
82: <li>latest version of perl, and a lndir command.
83: <li>gcc 2.7.2.1 (to get closer to native alpha support ar gcc bugs).
84: <li>vim version 4.5
85: <li>a good start at NETIPX support
86: <li>improved locate command
87: <li>Fixed timeout support in RPC library, and also fixed it to support more than FD_SETSIZE file descriptors.
88: <li>rudimentary support for ISA Plug-and-Play cards
89: <li>`lsof'-style features in fstat.
90: <li>Numerous ftpd improvements and fixes, including multihomed and skey support.
91: <li>ncr53cXXX scsi scripts assembler
92: <li>arc4-based random support in kernel
93: <li>Kerberos is much more silent if not configured
94: <li>scsi subsystem security fix
95: <li>much newer join command (4.4lite2 with other fixes)
96: <li>RCS version 5.7
1.4 rohee 97: <li>added /etc/fbtab support to login & init.
1.1 deraadt 98: <li>partial protection against tcp SYN attacks.
1.4 rohee 99: <li>POSIX & C2 requirement; lose setuid/setgid bits if owner/group changed by chown(). This can be turned off with sysctl.
1.1 deraadt 100: <li>a real adduser program, which can even be used uninteractively.
101: <li>install now supports -C, -p, and -S flags.
102: <li>20 or so more security fixes
103: <li>at -f security fix.
104: <li>generic protection against the bind() takeover problem.
105: <li>new rdisc Router Discovery daemon
106: <li>Numerous FreeBSD userland fixes and improvements incorporated.
107: <li>FreeBSD malloc() that uses mmap() and is able to free unused memory.
108: <li>Fixed long-standing vm swap-leak.
109: <li>_POSIX_SAVED_IDS behaviour with permitted BSD extensions.
110: <li>Newest version of pppd.
111: <li>zlib (non-GPL'd gzip-compatible library)
112: <li>Numerous more security policy and implementation improvements (OpenBSD defaults to installing in a very secure mode)
113: <li>Significantly improved ftp daemon.
114: <li>Protection from the udp spamming and ftp bounce attacks.
115: <li>randomized port allocation in bind(), bindresvport(), and rresvport() -- security via unpredictability.
116: <li>The most secure rdist support anywhere.
117: <li>Fortran in the tree.
118: <li>terminfo database support.
119: <li>Working ATAPI audio support for multiple architectures.
120: <li>Linux ext2fs and BSD4.4 LFS support being worked on.
121: <li>Accepts FreeBSD MD5 passwords in password maps, soon will be able to generate them too
122: <li>Even more security fixes.
1.5 rohee 123: <li>using AT&T awk, gawk is toast
1.1 deraadt 124: <li>pax as tar, gnutar is toast
125: <li>Boot kernels with "-c" to edit/enable/disable device configuration tables
1.4 rohee 126: <li>ATM support (support for one company's sparc & i386 cards available)
1.1 deraadt 127: <li>kernfs extensions
128: <li>select() that can handle any amount of file descriptors.
129: <li>new system calls: rfork(), minherit(), poll().
130: <li>/sbin/init now deals with non-existant ttys, no longer spins gettys madly.
131: <li>ncheck utility for ffs
132: <li>Numerous scsi fixes
133: <li>Some ddb improvements and extensions
134: <li>In-kernel update(8) with an adaptive algorithm
135: <li>/dev/*random -- a device driver providing some kinds of random data
136: <li>Solid YP master, server, and client capabilities.
137: <li>Kerberos and other crypto in the source tree that is exportable
138: <li>Numerous security related fixes
139: <li>new scsi, md5, pkg_* commands
1.12 jsyn 140: <li>ATAPI support (should work on all ISA buses)
1.1 deraadt 141: <li>Some LKM support in the tree.
142: <li>All the pieces needed for cross compilation are in the source tree.
143: <li>Verbatim integration of the GNU tools (using a wrapper Makefile)
1.11 pvalchev 144: <li>nlist() that understands ELF, ECOFF, and a.out, allowing non-a.out ports to use kvm utilities
1.1 deraadt 145: <li>better ELF support
146: <li>ipfilter for filtering dangerous packets and Network Address Translation for IP masquerading.
147: <li>The FreeBSD ports subsystem was integrated and is usable by you!
148: <li>a termlib library which understands termcap.db, needed for new curses.
149: <li>New curses library, including libform, libpanel and libmenu.
1.12 jsyn 150: <li>Many many NetBSD PRs fixed (which NetBSD has not yet fixed)
1.1 deraadt 151: </ul>
152: <p>
153:
154: This list mentions mostly platform-independent changes. For a list of changes
155: made in a particular platform, please check the page for that platform. If you
156: find them not listed there, the changes are either (1) not being documented or
157: (2) are documented here.<br><br>
158:
159: <hr>
160: <p>
161: <h3>
1.16 ! deraadt 162: <a href="plus21.html">For changes leading up to OpenBSD 2.1, click here</a>.<br>
! 163: <a href="plus22.html">For changes leading up to OpenBSD 2.2, click here</a>.<br>
! 164: <a href="plus23.html">For changes leading up to OpenBSD 2.3, click here</a>.<br>
! 165: <a href="plus24.html">For changes leading up to OpenBSD 2.4, click here</a>.<br>
! 166: <a href="plus25.html">For changes leading up to OpenBSD 2.5, click here</a>.<br>
! 167: <a href="plus26.html">For changes leading up to OpenBSD 2.6, click here</a>.<br>
! 168: <a href="plus27.html">For changes leading up to OpenBSD 2.7, click here</a>.<br>
! 169: <a href="plus28.html">For changes leading up to OpenBSD 2.8, click here</a>.<br>
! 170: <a href="plus29.html">For changes leading up to OpenBSD 2.9, click here</a>.<br>
! 171: <a href="plus30.html">For changes leading up to OpenBSD 3.0, click here</a>.<br>
1.14 deraadt 172: <a href="plus31.html">For changes leading up to OpenBSD 3.1, click here</a>.<br>
1.16 ! deraadt 173: <a href="plus32.html">For changes leading up to OpenBSD 3.2, click here</a>.<br>
! 174: <a href="plus.html">For changes in OpenBSD-current, click here</a>.
1.1 deraadt 175: <br>
176: </h3>
177:
178: <hr>
179: <a href="index.html"><img height=24 width=24 src=back.gif border=0 alt=OpenBSD></a>
180: <a href=mailto:www@openbsd.org>www@openbsd.org</a>
1.16 ! deraadt 181: <br><small>$OpenBSD: plus20.html,v 1.15 2002/06/18 01:44:05 jsyn Exp $</small>
1.1 deraadt 182:
183: </body>
184: </html>