▲ 59 r/opnsense
OPNsense 26.4.2 business edition released
- system: improve the log_archive script to also work on log subdirectories
- system: routing: changed "disable" option to "enable"
- system: add "local_uri" type in SanitizeFilter() and use it to avoid hardcoding
- system: several compatible adjustments for upcoming PHP 8.5
- system: enhance live log widget (contributed by Greelan)
- system: support 7680 bit RSA type for certificates and authorities
- reporting: improve parsing in NetFlow for overlapping flow timestamps and use UTC for cleanups
- reporting: stop NetFlow service before reloading configuration
- interfaces: properly format API times to ISO format and convert timezone for display in automatic discovery
- interfaces: fix typos in GIF reconfiguration script
- interfaces: improve VIP page save when no subnet was posted
- firewall: use htmlSafe() on action search value in live log (reported by call-AX)
- firewall: always show automatic and legacy rules in new rules GUI
- firewall: add the same new rules GUI design to the MVC NAT pages
- firewall: add CSV download/upload to MVC NAT pages
- firewall: add migration for outbound NAT into source NAT page
- firewall: destination NAT: display effective port when local-port is omitted
- firewall: source NAT: allow empty target which means the interface address
- firewall: source NAT: skip rendering rules when mode is not advanced/manual or hybrid
- firewall: improve performance on MVC pages using virtualDOM
- firewall: allow WAN as "associated interface" for NPTv6 when prefix ID is set
- firewall: fix TypeError on alias getItem() with unknown UUID (contributed by haxorton)
- firewall: show rule counts that can be exported and hide tab if no rules exist
- firewall: improve interface filter logic to include floating rules with multiple interfaces when they overlap with at least one interface in the interface filter request
- firewall: add validations for "No RDR" option to prevent target and local-port being set
- firewall: fix some small issues in menu registration for legacy pages
- firewall: constraint source NAT getAction() to only general page and align setAction() accordingly
- firewall: scope get action to general settings in source NAT
- kea: prevent converting the decimal prefix_id using hexdec() for dynamic PD
- kea: add widget to show DHCP leases
- kea: simplify model option values
- kea: improve prefix watcher accuracy via both interface and MAC address key
- kea: store subnet IDs inside the model so they cannot shift during config regeneration
- kea: change dynamic pool range from prefix to range 1000-2000
- kea: switch custom DHCP option config generation to libdhcp_flex_option library
- openvpn: add some input validation for control characters in connection status (reported by lujiefsi)
- openvpn: simplify model option values
- unbound: switch AAAA-only mode from respip to block_a_wdata (contributed by Maurice Walker)
- unbound: update Hagezi blocklists to use new mirror URL
- mvc: add some missing htmlSafe() calls for generated HTML (reported by lujiefsi)
- mvc: guard BaseField::setNodes() against a list given for a scalar leaf (contributed by haxorton)
- mvc: DescriptionField: disable special and newline characters
- mvc: FileObject: fix exception bug (contributed by Greelan)
- mvc: give throwReadOnly() a sibling named throwNotFullAdmin()
- mvc: use camelCase for carp_status action
- mvc: translate backend system status messages
- mvc: translate grid view labels
- ui: add some more legacy_html_escape_form_data() safeguards (reported by Arpit Jain)
- ui: bootgrid: minor optimizations
- plugins: os-OPNDNS 1.0 is an authoritative nameserver with RFC2136 support using PowerDNS
- plugins: os-OPNWAF 2.3
- plugins: os-cloudflared 1.1
- plugins: os-freeradius 1.10.2
- plugins: os-vnstat 1.4
- src: igc: disable PCIe ASPM to improve stability
- src: ena: update driver version to v2.8.3
- src: coredump: do not assume that the number of ELF segments is consistent
- src: sysvsem: fix a TOCTOU race in semctl()
- src: wg: check for crypto operation errors
- src: tzdata: import 2026c
- ports: curl 8.21.0
- ports: lighttpd 1.4.84
- ports: openssh 10.4p1
- ports: openvpn 2.7.6
- ports: phalcon 5.16.0
- ports: py-duckdb 1.5.4
- ports: python 3.13.15
- ports: syslog-ng 4.12.0
- ports: unbound 1.26.0
u/fitch-it-is — 6 days ago