OpenBSD: Maintaining the quality mindset

David Braue, ZDNet Australia

03 September 2004 06:29 PM

Tags: theo, de raadt, openbsd, david, braue

Come October, Theo de Raadt will be joined by five fellow developers for an intense period of takeout food, hikes through the hills in his native Calgary, Canada, beers and long conversations about the future of OpenBSD, the open source operating system for which de Raadt is project head.

At the same time, they’ll co-ordinate the final touches of the next release of OpenBSD, which will emerge on November 1 as the latest iteration of a carefully structured design process that’s resulted in a new release every six months for the past 10 years.

The last two months of that six-month cycle reflect the care with which de Raadt and his dozen-strong team of core developers has looked after the OpenBSD source. After four months of intense and frenzied development, OpenBSD’s APIs were locked down this week; the rest of the code will be intensively tested and progressively locked down until developers can do no more than make simple edits to MAN pages.

In late October, the entire code base will be frozen and the master CD release for pressing. On November 1, once the disc is out the door, the code will be unlocked and a new frenzy of development will commence as members of the environment’s extended global development network gear up again for the May 1, 2005 release.

Such is life at the helm of OpenBSD, a lower-profile open source cousin to Linux that has matured considerably from its roots at the University of California, Berkeley. Yet while grassroots support of Linux has enjoyed strong brand recognition and the endorsement of governments, companies and major IT vendors alike, OpenBSD continues evolving in relative obscurity – so much so that a recent book on the environment named just 220 known users, even though one reseller de Raadt has spoken with has installed 11,000 OpenBSD servers in the last four years.

de Raadt’s explanation for this curious mismatch: many customers are simply using OpenBSD in quiet mode, choosing it over alternative operating systems in a recognition of the meticulous coding and exacting standards that de Raadt and his team demand.

"We are non-stop trying to find ways across our entire source tree that small little programmer errors result in problems," says de Raadt, who fronted the AUUG 2004 conference in Melbourne this week to share his experiences. "The problem with security is that people learn what they’re supposed to by example, learn they’re supposed to use APIs in a certain way, and they’re just wrong. At some point, we have to start asking ourselves whether features are the thing, or whether quality is the issue. I really think we have to focus on the quality before the features".

The key difference between OpenBSD’s design and that of Linux, says de Raadt, is that Linux is effectively an assemblage of individual development efforts centred around a single Linux kernel controlled by Linus Torvalds. OpenBSD, on the other hand, is a complete operating system that is built from a single, carefully managed code base and tested end to end before each release.

With a concerted focus on security, the OpenBSD effort has spawned open tools such as the OpenSSH toolkit, which has become the de facto standard for secure online communications in many Unix and Linux distributions. Other byproducts of the effort include a robust BGP implementation, IPSec stack and packet filter.

Far from resenting the widespread borrowing of the group’s security, de Raadt encourages it: "We are software security craftsmen," he smiles. "I’d rather have people there using our software than writing their own and doing a bad job of it. If their machines get broken into, everybody else’s insecurity on the global Internet becomes my insecurity".

In the OpenBSD world, after all, there is no pressure from marketing organisations to push new features to meet arbitrary deadlines. Once submitted by developers, new features are carefully tested, revised and reworked until it’s bug-free; if a feature isn’t ready, it simply won’t ship until the next release. Or the next one.

Advertisement

Talkback 5 comments

  1. That should say BGP, not PGP. Anonymous -- 04/09/04

    That should say BGP, not PGP.

  2. Theo gave a very interesting and thought provoking presentation at AUUG'2004. The slides from his presentation (containing a lot of useful info) can be found at: http://www.auug.org.au/events/2004/auug2004/theo/ Anonymous -- 04/09/04

    Theo gave a very interesting and thought provoking presentation at AUUG'2004. The slides from his presentation (containing a lot of useful info) can be found at:

    http://www.auug.org.au/events/2004/auug2004/theo/

  3. Those 220 numbers are way off. I alone have 5 or 6 clients of different companies using OpenBSD. Not even counting the 6 more I have mananging residential routing for those same clients homes. Anonymous -- 05/09/04

    Those 220 numbers are way off. I alone have 5 or 6 clients of different companies using OpenBSD. Not even counting the 6 more I have mananging residential routing for those same clients homes.

  4. Thanks for your replies. Yes, it was BGP not PGP, so our apologies. With regard to the 220 figure, here is a reply from the writer of the article. "Theo says the book he was referring to (the 220 users figure) was: Building Firew Anonymous -- 06/09/04

    Thanks for your replies. Yes, it was BGP not PGP, so our apologies. With regard to the 220 figure, here is a reply from the writer of the article.

    "Theo says the book he was referring to (the 220 users figure) was:

    Building Firewalls with OpenBSD and PF [2nd edition]
    by Jacek Artymiak
    ISBN 83-916651-1-9
    October 2003, 320 pp.
    Author Jacek Artymiak, known for his series of excellent online articles about pf and OpenBSD security in general, wrote this book covering OpenBSD and pf on 320 pages.
    Table of contents (pdf)
    Index (pdf)
    [Order direct from the OpenBSD website International][Europe]

    "It's available from the OpenBSD orders page at http://www.openbsd.org/books.html

    "As I pointed out in the story, the actual number is clearly much higher -- Theo was trying to make the point that many users are operating under the radar and using BSD for its security capabilities, but not trumpeting their use of it anywhere".

  5. Hi all, OpenBSD is getting noticed in differrent part of the world! Fisrt of all it is free and then it is Secure and Reliable! I personally feel that there will be a steady growth in the amount of people using OpenBSD if people who ha Anonymous -- 18/09/04

    Hi all,

    OpenBSD is getting noticed in differrent part of the world! Fisrt of all it is free and then it is Secure and Reliable!

    I personally feel that there will be a steady growth in the amount of people using OpenBSD if people who have used it and benifitted from it share their testimonies openly and get the Idea out of people's mind that it is for nerds! That was what was told to me when I wanted to try out OpenBSD first!

Add your opinion


ZDNet's CIO Vision Series

Customs | Murray Harrison, CIO

Australian Customs CIO Murray Harrison dislikes SLAs and runs away if a vendor talks to him about innovation. In this interview, he also explains why getting excited about gadgets can be dangerous and talks about how Customs' outsourcing strategy has evolved.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Munir Kotadia iPhone suckers test our patience
    So how many of you have bought a 3G iPhone? Do you feel like a sucker? If you don't, maybe you will once your first bill arrives.
  • Array Westpac bank: AVG's toughest competitor
    The next time you're buying antivirus software, don't go direct to Symantec or McAfee. Don't download free antivirus. And definitely don't see Harvey Norman. Ask your bank — they're quite literally giving the stuff away.
  • Array Will you manage in the exabyte era?
    Mammoth growth in storage volumes is a fact of life, but even so it's helpful to pause occasionally and try and work out whether our information strategies have fallen hopelessly out of step with the pace of technological growth and changes in costs.
  • More blogs »

Tags

Back to top

Featured