netgate freebsd performance patch

Started by Lucid1010, October 09, 2026, 12:00:52 PM

Previous topic - Next topic
https://www.netgate.com/blog/ding-dong-ditch-the-doorbell-prank-in-freebsds-iflib
Is it possible to backport this patch to OPNsense, or should we wait until FreeBSD applies it?



Same as always: wait for stable branch merge.

Also, are we going to hear Netgate praise itself every two weeks now on their blog for open source work while forgetting to push any CE code commits for 6 months?

Feels like a new marketing strategy.  I wish them the best.  :)


Cheers,
Franco

FreeBSD already applied the fix to HEAD (write only once instead of thrice) and it will be MFC'd (backported to STABLE) in 2 weeks. The batched write enhancement is still under revision.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Quote from: franco on October 09, 2026, 12:25:30 PMforgetting to push any CE code commits for 6 months?

But, but...: https://forum.netgate.com/topic/201215/releasing-more-often-doesn-t-mean-more-secure

Why do they still have a chip on their shoulder? The obsession is unhealthy.

Quote from: Greelan on October 09, 2026, 10:08:06 PMWhy do they still have a chip on their shoulder? The obsession is unhealthy.
Maybe because many users moved over to OPNsense for some reasons?
So did I. The reasons were discussed on both forums in several threads.

That discussion even carried over to the TrueNAS forum.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Networking is love. You may hate it, but in the end, you always come back to it.

OPNSense HW
N355 - i226-V | AQC113C | 16G | 500G - PROD

PRXMX
N5105 - i226-V | 2x8G | 512G - NODE #1
N100 - i226-V | 16G | 1T - NODE #2

Going back a ways, and pretty far out in left field... Back when I heard about [opnsense.com] I thought it was a pretty funny troll. (It was .com, wasn't it?) From a distance it seemed to show which side had a sense of humor. Turns out it really didn't break down that way.

Back at my first Internet job - tech support for a mainly dial-up ISP - we had a joke that we'd support anything. Simply put, helping people out was good PR. "Catch more flies". There's plenty of give and take between the two 'senses (e.g. the rather gentle poke above), but the core attitudes are a bit different. Netgate folks seem to subscribe to the zero-sum model of life; OPNsense folks do not seem to.

October 10, 2026, 08:49:47 PM #8 Last Edit: October 10, 2026, 09:08:07 PM by franco
Quote from: Greelan on October 09, 2026, 10:08:06 PMBut, but...: https://forum.netgate.com/topic/201215/releasing-more-often-doesn-t-mean-more-secure

That's cute.  I think this makes the same mistakes that the infamous Tom Lawrence video made.  I let my friend ChatGPT answer and leave the actual reasons for those CVEs and scores for someone who is genuinely interested in why things are going more and more into this direction and which CVEs likely still in pfSense today but we can't check because the source code is no longer available even for researchers... how inconvenient...

The post makes a valid technical point: frequent releases do not automatically mean better security. OPNsense has experienced several serious vulnerabilities, including recurring command-injection issues, and it's reasonable to question whether its development and review processes adequately prevent these problems. However, frequent updates are not inherently a weakness either. They can reduce the time users remain exposed to known vulnerabilities. The important measures are vulnerability prevention, patch quality, and time to remediation, not simply how often new versions are released.

The comparison with pfSense is statistically questionable and potentially misleading. The author compares just eight CVSS-scored pfSense vulnerabilities against 33 OPNsense CVEs, despite acknowledging that Netgate published 49 security advisories. These are not equivalent datasets, so comparing their average severity or claiming pfSense has a lower severity ceiling doesn't establish that pfSense is more secure. The post also applies different standards: OPNsense is criticized for existing vulnerabilities, while pfSense receives credit for its planned Go rewrite and System Patches mechanism. Meanwhile, OPNsense's own architectural hardening efforts receive little attention.

Overall, the post reads more like competitive advocacy than an impartial security analysis. It starts with an entirely reasonable premise, presents legitimate vulnerabilities, but then uses selectively framed statistics to suggest that pfSense has superior security engineering without actually demonstrating it. That doesn't necessarily mean the author is deliberately misleading, but the presentation creates an impression the evidence cannot support. Ironically, the author correctly argues that release frequency doesn't prove security, yet appears to suggest that lower reported CVSS scores do. Neither is a reliable measure on its own.



Cheers,
Franco on behalf of ChatGPT

All of that said, there is no doubt a lesson in repeated CVEs happening due to similar reasons (input sanitization). I assume the tests have been hardened on that front.

As a matter of interest, does the development team use AI for vulnerability spotting?