Software-update: OPNsense 26.7.3
Het pakket OPNsense is een firewall met uitgebreide mogelijkheden. Het is gebaseerd op het besturingssysteem FreeBSD en is oorspronkelijk een fork van m0n0wall en pfSense. Het pakket kan volledig via een webinterface worden ingesteld en heeft onder andere ondersteuning voor mfa, OpenVPN, IPsec, CARP en captive portal. Daarnaast kan het packetfiltering toepassen en beschikt het over een traffic shaper. De ontwikkelaars achter OPNsense hebben de derde update voor versie 26.7 uitgebrachten de releasenotes voor die uitgave kunnen hieronder worden gevonden.
OPNsense 26.7.3 releasedHere is your biweekly dose of bugfixes and quality of life improvements! This update offers several new features: VLANs on bridges, "received-on" firewall rule support, persistent rule label tracking, repeatable WireGuard QR codes, menu favourites and full screen grid support. On top of that it bundles the recent FreeBSD 15.1-RELEASE-p3, fixes and cleanups as well as third party updates such as OpenSSL 3.5.8 and OpenSSH 10.5p1. Enjoy. :)
Meanwhile, development is busy with adding interface settings to the new MVC assignments page, which includes building wireless MVC/API support. That is all for now. Need to get back to work.
Here are the full patch notes:system: offer post-quantum mldsa44-ed25519 OpenSSH server host keysystem: do not regenerate all OpenSSH key files when adding new key typessystem: truncate long names in services dashboard widgetsystem: use created user name for change eventsystem: handle missing objects during deletion in APIsystem: multiple PHP warning fixessystem: avoid filter_configure() calls to make existing backend call less obscuresystem: add favorites section to menusystem: approximate user being expired for the grid view iconsystem: replace cron restart in static PHP pagessystem: fix server certificate purpose detection for ECinterfaces: permit a VLAN device as bridge memberinterfaces: resolve VLAN devices indirectly via interfaces_configure()interfaces: handle missing GRE and GIF during deletion in APIinterfaces: multiple PHP warning fixesinterfaces: emit discovered hosts sorted by last_seen via hostwatchcaptive portal: exclude IPv4 from roaming logicdhcrelay: add options for circuit_id and remote_iddnsmasq: remove count badge from GroupBy with static configuration elementsdnsmasq: add "expand-hosts" optionfirewall: remove 2a10::/12 from bogonsv6.samplefirewall: deprecate old rule register function names due to functional overlapsfirewall: add missing TLS ports to well-known portsfirewall: use new "rlabel" from pfctl for persistent rule identification across reloadsfirewall: emit gateway debug message in block rules only when gateway is not emptyfirewall: aliases: use same dynamic label as in KEA DHCPv6 for a unified lookfirewall: aliases: fix spinner on alias dialog save buttonfirewall: destination NAT: make local-port numeric before applying range in registered firewall rulefirewall: rules: add "received-on" interface keyword as interface origin optionfirewall: rules: promote "statetype" from advanced to common option for "received-on" usagefirmware: revoke 26.1 fingerprintkea: remove count badge from GroupBy with static configuration elementskea: use DOM construction for the "dynamic" labelnetwork time: strict security GUI supportunbound: update Hagezi blocklists to use new mirror URLwireguard: FreeBSD 15 no longer allows addresses without netmaskswireguard: cleaner QR codeswireguard: preserve peer generator state for existing peersmvc: BaseField: add getInitialValue()mvc: OptionField: fix simplified option group definitionmvc: fix typo in base_form.volt advanced/help toggle IDsmvc: fix assorted stale imports in the code baseui: tabulator: add _showMaximized() modal that can show a grid close to full screenui: add keyboard shortcut "f" to maximize a currently visible gridui: scope "all help" and "advanced mode" toggle to closest relevant formui: trigger "h" and "a" keyboard shortcuts on all relevant matchesplugins: os-caddy 2.2.1plugins: os-frr 1.55plugins: os-theme-rebellion 1.9.7src: posixshm: fix a TOCTOU race in the FIOSSHMLPGCNF handlersrc: tty: revalidate after dropping the tty lock in ioctl handlerssrc: ppp: fix multiple vulnerabilitiessrc: openssl: fix multiple vulnerabilitiessrc: cred: fix group_is_primary()src: dsp: fix a potential use-after-free in dsp_oss_syncstart()src: unix: fix some bugs in the SOCK_STREAM receive pathsrc: hwpmc: fix the execve handlersrc: ucode: fix validation on Intel platformssrc: netmap: fix driver name handlingsrc: netmap: fix a race in kqueue registrationsrc: e1000: assorted upstream patches from stable/15src: iflib: support recoverable initialization failuresrc: route: add an eventhandler for rt_numfibs changessrc: rawip: fix handling of checksums in rip6_input()src: pf: attempt to handle overlapping group and interface namessrc: pf: check if a group has a kif before dereferencing itsrc: pf: fix fallout from the STATE_LOOKUP macro removalsrc: pf: re-optimize state key handlingsrc: pf: rule label patch was merged from a wrong versionsrc: pfsync: handle large MTU pfsync interfacessrc: ktls: propagate EPG_FLAG_ANON to mapped mbufssrc: netipsec: fix sockaddr type set in ipcomp6_nonexp_encapcheck()src: src: PF_KEY socket: limit the length of copied socket addresssrc: ure: add USB device IDs for additional RTL8152/RTL8153 adapterssrc: ure: fix spurious link flaps from MIIports: ca_root_nss / nss 3.127ports: expat 2.8.3ports: kea 3.0.4ports: monit 6.0.0ports: openssh 10.5p1ports: openssl 3.5.8ports: perl 5.42.3ports: phalcon 5.20.3ports: php 8.5.9ports: rrdtool 1.11.0ports: sqlite 3.53.4
system: offer post-quantum mldsa44-ed25519 OpenSSH server host keysystem: do not regenerate all OpenSSH key files when adding new key typessystem: truncate long names in services dashboard widgetsystem: use created user name for change eventsystem: handle missing objects during deletion in APIsystem: multiple PHP warning fixessystem: avoid filter_configure() calls to make existing backend call less obscuresystem: add favorites section to menusystem: approximate user being expired for the grid view iconsystem: replace cron restart in static PHP pagessystem: fix server certificate purpose detection for ECinterfaces: permit a VLAN device as bridge memberinterfaces: resolve VLAN devices indirectly via interfaces_configure()interfaces: handle missing GRE and GIF during deletion in APIinterfaces: multiple PHP warning fixesinterfaces: emit discovered hosts sorted by last_seen via hostwatchcaptive portal: exclude IPv4 from roaming logicdhcrelay: add options for circuit_id and remote_iddnsmasq: remove count badge from GroupBy with static configuration elementsdnsmasq: add "expand-hosts" optionfirewall: remove 2a10::/12 from bogonsv6.samplefirewall: deprecate old rule register function names due to functional overlapsfirewall: add missing TLS ports to well-known portsfirewall: use new "rlabel" from pfctl for persistent rule identification across reloadsfirewall: emit gateway debug message in block rules only when gateway is not emptyfirewall: aliases: use same dynamic label as in KEA DHCPv6 for a unified lookfirewall: aliases: fix spinner on alias dialog save buttonfirewall: destination NAT: make local-port numeric before applying range in registered firewall rulefirewall: rules: add "received-on" interface keyword as interface origin optionfirewall: rules: promote "statetype" from advanced to common option for "received-on" usagefirmware: revoke 26.1 fingerprintkea: remove count badge from GroupBy with static configuration elementskea: use DOM construction for the "dynamic" labelnetwork time: strict security GUI supportunbound: update Hagezi blocklists to use new mirror URLwireguard: FreeBSD 15 no longer allows addresses without netmaskswireguard: cleaner QR codeswireguard: preserve peer generator state for existing peersmvc: BaseField: add getInitialValue()mvc: OptionField: fix simplified option group definitionmvc: fix typo in base_form.volt advanced/help toggle IDsmvc: fix assorted stale imports in the code baseui: tabulator: add _showMaximized() modal that can show a grid close to full screenui: add keyboard shortcut "f" to maximize a currently visible gridui: scope "all help" and "advanced mode" toggle to closest relevant formui: trigger "h" and "a" keyboard shortcuts on all relevant matchesplugins: os-caddy 2.2.1plugins: os-frr 1.55plugins: os-theme-rebellion 1.9.7src: posixshm: fix a TOCTOU race in the FIOSSHMLPGCNF handlersrc: tty: revalidate after dropping the tty lock in ioctl handlerssrc: ppp: fix multiple vulnerabilitiessrc: openssl: fix multiple vulnerabilitiessrc: cred: fix group_is_primary()src: dsp: fix a potential use-after-free in dsp_oss_syncstart()src: unix: fix some bugs in the SOCK_STREAM receive pathsrc: hwpmc: fix the execve handlersrc: ucode: fix validation on Intel platformssrc: netmap: fix driver name handlingsrc: netmap: fix a race in kqueue registrationsrc: e1000: assorted upstream patches from stable/15src: iflib: support recoverable initialization failuresrc: route: add an eventhandler for rt_numfibs changessrc: rawip: fix handling of checksums in rip6_input()src: pf: attempt to handle overlapping group and interface namessrc: pf: check if a group has a kif before dereferencing itsrc: pf: fix fallout from the STATE_LOOKUP macro removalsrc: pf: re-optimize state key handlingsrc: pf: rule label patch was merged from a wrong versionsrc: pfsync: handle large MTU pfsync interfacessrc: ktls: propagate EPG_FLAG_ANON to mapped mbufssrc: netipsec: fix sockaddr type set in ipcomp6_nonexp_encapcheck()src: src: PF_KEY socket: limit the length of copied socket addresssrc: ure: add USB device IDs for additional RTL8152/RTL8153 adapterssrc: ure: fix spurious link flaps from MIIports: ca_root_nss / nss 3.127ports: expat 2.8.3ports: kea 3.0.4ports: monit 6.0.0ports: openssh 10.5p1ports: openssl 3.5.8ports: perl 5.42.3ports: phalcon 5.20.3ports: php 8.5.9ports: rrdtool 1.11.0ports: sqlite 3.53.4
Source:
Tweakers.net