HardenedBSD

Security-oriented derivative of FreeBSD. Primary goal is a clean-room reimplementation of the grsecurity patchset for the BSD community.

2025-07-01

#HardenedBSD is now a part of the #GitHub Sponsors program: github.com/sponsors/HardenedBS

2025-06-28

As #HardenedBSD switches to quarterly releases for the base OS, we have now formalized the names of the branches and tags.

@lattera is currently working this weekend on updating our build scripts to handle quarterly releases.

Eleven years after we started this project, we are gaining our first formalized release process. Perhaps #FreeBSD might finally add us to the BSD family tree file. :-)

For more detailed information: groups.google.com/a/hardenedbs

2025-06-04

We are performing emergency network maintenance on our development/build infrastructure. Service will be periodically interrupted.

Official announcement: groups.google.com/a/hardenedbs

2025-05-20

In April 2025, @lattera, @asomers, and a few other #FreeBSD developers held a small weekend hackathon for optional #Rustlang support in FreeBSD.

We have now published a status report on that effort: hardenedbsd.org/article/shawn-

#Rust #Programming

HardenedBSD boosted:
2025-04-21

The latest version of the #FreeBSD package manager (pkg) does a lot of extra work in determining dependencies, so much so that it's really prolonging our package builds.

We ( #HardenedBSD ) may need to scale back our monthly installation/updater builds to quarterly because of just how much the new package manager prolongs building packages.

The problem then becomes, what do we do when there's a #FreeBSD Security Advisory? We may have to adopt a more formal approach to handling security advisories for the base OS. That would be a good thing to have overall, but hasn't really been needed until now-ish.

Our exploit mitigations and security hardening techniques generally mitigate a large portion of security advisories, so waiting for the next monthly build has been an acceptable compromise. That changes if we go to quarterly builds.

HardenedBSD boosted:
2025-04-02

If I were to host a regular #HardenedBSD hacking sessions via #Signal, using screen sharing, would you attend?

#SignalApp #Programming #FreeBSD

HardenedBSD boosted:
2025-03-28

We've now exposed the #HardenedBSD arm64 package builder web interface. You can now follow along on the progress of our arm64 package builds.

tx-01.hardenedbsd.org/index.ht

HardenedBSD boosted:
2025-03-18

The electrician completed his work. Both of the new 20A circuits are working. The #HardenedBSD infrastructure has now been moved to the new circuits. Zero downtime. :-)

2025-03-13

The infrastructure is back online. Please let us know if you have any troubles.

2025-03-13

In powering the servers back on, it was determined that one of the two new 20A circuits is faulty. We will call the electrician back tomorrow to fix the faulty circuit.

Regardless, we're still going forward with powering on our infrastructure.

2025-03-13

The electrician successfully completed all work items. We're applying updates to the infrastructure now and will have the infrastructure back online tonight.

Stay tuned. :-)

2025-03-12

The infrastructure is now powered down.

2025-03-11

The #HardenedBSD dev/build infrastructure will be powered down in around an hour from now (currently 23:07 UTC). This is in preparation for the planned electrical work tomorrow (12 Mar 2025).

The infrastructure will be back online within 48 hours.

Thank you for your patience and understanding.

HardenedBSD boosted:
2025-03-06

The local DNS server for the #HardenedBSD dev/build infrastructure experienced a kernel panic a couple days ago. I fixed that this morning. Our every-six-hour auto-sync setup was impacted. That, too, was fixed today.

The infrastructure should be completely functional again. Please let me know if you experience any issues.

2025-02-10

On 12 March 2025, we plan to increase the power capabilities in our
server room. The #HardenedBSD development infrastructure will be
offline during the maintenance.

Users are encouraged to make use of our [mirrors](hardenedbsd.org/content/mirror) during that time
for downloading installation media.

Our package repos and binary updates are hosted on a server hosted
elsewhere, so access to those resources will NOT be impacted.

We will keep everyone informed.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst