Oh, hi!
This update finally brings interface settings to MVC/API! It also brings
a number of fixes and improvements from FreeBSD stable/15 including a fix
for previous Hyper-V boot issues and hopefully also fixes ice driver DDP
issues with newer firmware versions.
For the interface settings MVC/API there a few things to keep in mind:
o You can find them on the assignments page integrated into the existing grid.
o Commonly required DHCP advanced options not in basic mode have been made available.
o Advanced/file based modes for DHCP are gone and will reset on save.
o Saving settings queues them for reconfiguration and storage.
o A reboot without apply will discard the previously saved changes.
o Apply works similar to the old interfaces.php page but uses a rewritten backend sequence.
o The old interfaces.php page is still available retaining the old style settings.
o The old interfaces.php page will likely move to a plugin for 27.1.
We are looking for your feedback on this historic milestone!
Here are the full patch notes:
o system: use correct type for IP when killing active states in "lockout_handler" (reported by Omar Habra of Apex Security Research)
o system: reject a null gateway in getGatewayAction()
o system: add "latency_avg" as sanity check for running dpinger
o system: missing chown in backup call for proper non-root web GUI access
o system: do not allow system scope users to be renamed
o reporting: unbound: add DNSSEC status column in details grid
o interfaces: add interface configuration settings in new assignments page
o interfaces: prevent interface_configure() from reloading non-interface hooks when in batch mode
o interfaces: improve queue build sequence in interfaces_dependencies()
o interfaces: remove stale VIP address after update (contributed by ExpRam)
o interfaces: be more conservative with -no_dad
o interfaces: add a new 'updateip' hook
o firewall: aliases: reject reversed port ranges
o firewall: destination NAT: fix destination for no-rdr rules (reported by fa1k3)
o firewall: destination NAT: add safety guards for calculated port ranges
o ipsec: add "replay_window" option to children
o monit: log from the first line and reconfigure through the base class (contributed by IvanTheGeek)
o openvpn: default keepalive to "10 60" in server mode and improve validation
o bootgrid: upgrade Tabulator to version 6.5.3
o mvc: disable Nginx reverse proxy buffering on configd streams
o mvc: dispatch failed message during reconfiguredAction()
o mvc: PortField: keep the first well-known service in the option list (contributed by fa1k3)
o mvc: PortField: always return a string for normalizedPort()
o mvc: UidField: allow an arbitrarily specified UID for system scope users upon creation
o ui: do not add the spinner again when it fails
o plugins: add error returns to plugins_configure()
o plugins: os-ndp-proxy-go 1.5[1]
o src: sysvsem: heap out-of-bounds access in semop(2)[2]
o src: ktls: remote DoS via receive-side kernel TLS[3]
o src: udp: IPv6 UDP sendto(2) bypasses jail loopback restriction[4]
o src: vfs: multiple jail filesystem root escapes[5]
o src: openssl: out-of-bounds read in OpenSSL DTLS retransmission[6]
o src: kqueue: memory safety bugs in kqueue copy-on-fork implementation[7]
o src: syslogd: fix leaking child processes when logging to a pipe[8]
o src: iflib: do not hold the ifnet lock across registration
o src: ixgbe: correct Wake-on-LAN configuration
o src: dummynet: do not overflow the points[ED_MAX_SAMPLES_NO] array
o src: pf: mark non-port packets to require IP checksumming
o src: pf: set the correct type for rule timeouts
o src: loopback: improve checksum offloading
o src: vlan: use the exclusive lock everywhere
o src: routing: initialize V_rt_numfibs earlier during boot
o src: raw ip: clear sin_port on bind(2)
o src: nd6: fix regeneration of temp addresses in detached state
o src: hyperv: fix single page invalidation path
o src: route/fib_algo: fix nexthop index collision across families
o src: ice: do not leave device non-functional if Tx scheduler config fails
o src: netipsec: fix V_spd_size updates
o src: bnxt: assorted updates from stable/15
o src: ixl: assorted updates from stable/15
o src: linxkpi: assorted updates from stable/15
o src: net80211: assorted updates from stable/15
o src: pci: assorted updates from stable/15
o ports: ca_root_nss / nss 3.130[9]
o ports: expat 2.8.5[10]
o ports: pcre2 10.49[11]
o ports: phalcon 5.22.1[12]
o ports: php 8.5.11[13]
o ports: py-duckdb 1.5.6[14]
Stay safe and open source,
Your OPNsense team
--
[1] https://github.com/opnsense/plugins/blob/stable/26.7/net/ndp-proxy-go/pkg-descr
[2] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:64.sysvsem.asc
[3] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:67.ktls.asc
[4] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:69.udp.asc
[5] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:66.jail.asc
[6] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:68.openssl.asc
[7] https://www.freebsd.org/security/advisories/FreeBSD-SA-26:65.kqueue.asc
[8] https://www.freebsd.org/security/advisories/FreeBSD-EN-26:23.syslogd.asc
[9] https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_130.html
[10] https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/Changes
[11] https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.49
[12] https://github.com/phalcon/cphalcon/releases/tag/v5.22/1
[13] https://www.php.net/ChangeLog-8.php#8.5.11
[14] https://github.com/duckdb/duckdb/releases/tag/v1.5.6