On 2026/08/29 13:44, Kirill A. Korinsky wrote: > On Sun, 23 Aug 2026 19:38:47 +0200, > Фёдор <[email protected]> wrote: > > > > Current version in ports tree is 2.59, but lasted is 2.61 > > I doubt that any update of i2pd is possible till this one is resovled: > https://github.com/PurpleI2P/i2pd/issues/2435
it seems sane to just rip out the broken code. it wouldn't be the first time someone has had bad pledge code committed upstream without having it sanity-checked by people who actually know how pledge works, and then getting disabled in the port. I'm not going to run this code myself, but here's a build-tested-only update based on https://marc.info/?l=openbsd-ports&m=178491641115405&w=2 that does this, and also switches the certs from being installed to one dir and @sample'd, into being installed directly to the final location. (i got fed up with telling people they forgot to add the @sample, and "make plist" got a lot smarter around @cwd so it's sane to do it this way now) this is the last remaining port with files in /var/lib, so it would be nice to get that changed one way or another before 8.0, to clear the way for Antoine's cunning plan in the next release cycle. Index: Makefile =================================================================== RCS file: /cvs/ports/net/i2pd/Makefile,v diff -u -p -r1.33 Makefile --- Makefile 21 Feb 2026 14:20:20 -0000 1.33 +++ Makefile 24 Sep 2026 13:52:06 -0000 @@ -2,7 +2,7 @@ COMMENT = client for the I2P anonymous n GH_ACCOUNT = PurpleI2P GH_PROJECT = i2pd -GH_TAGNAME = 2.59.0 +GH_TAGNAME = 2.61.0 CATEGORIES = net HOMEPAGE = https://i2pd.website @@ -14,7 +14,7 @@ PERMIT_PACKAGE = Yes WANTLIB += ${COMPILER_LIBCXX} WANTLIB += boost_filesystem-mt boost_program_options-mt -WANTLIB += boost_atomic-mt c crypto m miniupnpc ssl z +WANTLIB += boost_atomic-mt boost_container-mt c crypto m miniupnpc ssl z COMPILER = base-clang ports-gcc MODULES = devel/cmake @@ -29,15 +29,16 @@ CONFIGURE_ARGS = -DWITH_UPNP=ON WRKSRC = ${WRKDIST}/build post-install: - ${INSTALL_DATA_DIR} ${PREFIX}/include/i2pd + ${INSTALL_DATA_DIR} ${PREFIX}/include/i2pd \ + ${PREFIX}/share/examples/i2pd ${INSTALL_DATA} ${WRKDIST}/libi2pd{,_client}/*.h \ ${PREFIX}/include/i2pd .for dir in family reseed - ${INSTALL_DATA_DIR} ${PREFIX}/share/examples/i2pd/certificates/${dir} + ${INSTALL_DATA_DIR} ${WRKINST}/var/i2pd/certificates/${dir} ${INSTALL_DATA} ${WRKDIST}/contrib/certificates/${dir}/* \ - ${PREFIX}/share/examples/i2pd/certificates/${dir} + ${WRKINST}/var/i2pd/certificates/${dir} .endfor - ${INSTALL_DATA} ${WRKDIST}/contrib/i2pd.conf \ + ${SUBST_DATA} ${WRKDIST}/contrib/i2pd.conf \ ${PREFIX}/share/examples/i2pd/i2pd.conf ${INSTALL_DATA} ${WRKDIST}/contrib/tunnels.conf \ ${PREFIX}/share/examples/i2pd/tunnels.conf Index: distinfo =================================================================== RCS file: /cvs/ports/net/i2pd/distinfo,v diff -u -p -r1.26 distinfo --- distinfo 21 Feb 2026 14:20:20 -0000 1.26 +++ distinfo 24 Sep 2026 13:52:06 -0000 @@ -1,2 +1,2 @@ -SHA256 (i2pd-2.59.0.tar.gz) = Dr6wXk82qzgJRJVhoJXcdnrYIaxqYclWI6tJvk/9OYs= -SIZE (i2pd-2.59.0.tar.gz) = 743516 +SHA256 (i2pd-2.61.0.tar.gz) = QJzTwCV0kShmEatqr2kJQMckj7iYN3wT+ttlqDbioKs= +SIZE (i2pd-2.61.0.tar.gz) = 779272 Index: patches/patch-contrib_i2pd_conf =================================================================== RCS file: patches/patch-contrib_i2pd_conf diff -N patches/patch-contrib_i2pd_conf --- /dev/null 1 Jan 1970 00:00:00 -0000 +++ patches/patch-contrib_i2pd_conf 24 Sep 2026 13:52:06 -0000 @@ -0,0 +1,41 @@ +Index: contrib/i2pd.conf +--- contrib/i2pd.conf.orig ++++ contrib/i2pd.conf +@@ -8,16 +8,16 @@ + + ## Tunnels config file + ## Default: ~/.i2pd/tunnels.conf or /var/lib/i2pd/tunnels.conf +-# tunconf = /var/lib/i2pd/tunnels.conf ++tunconf = ${SYSCONFDIR}/i2pd/tunnels.conf + + ## Tunnels config files path + ## Use that path to store separated tunnels in different config files. + ## Default: ~/.i2pd/tunnels.d or /var/lib/i2pd/tunnels.d +-# tunnelsdir = /var/lib/i2pd/tunnels.d ++tunnelsdir = ${SYSCONFDIR}/i2pd/tunnels.d + + ## Path to certificates used for verifying .su3, families + ## Default: ~/.i2pd/certificates or /var/lib/i2pd/certificates +-# certsdir = /var/lib/i2pd/certificates ++certsdir = ${SYSCONFDIR}/i2pd/certificates + + ## Where to write pidfile (default: /run/i2pd.pid, not used in Windows) + # pidfile = /run/i2pd.pid +@@ -30,7 +30,7 @@ + ## * stdout - print log entries to stdout + ## * file - log entries to a file + ## * syslog - use syslog, see man 3 syslog +-# log = file ++log = syslog + ## Path to logfile (default: autodetect) + # logfile = /var/log/i2pd/i2pd.log + ## Log messages above this level (debug, info, *warn, error, critical, none) +@@ -122,7 +122,7 @@ ipv6 = false + [http] + ## Web Console settings + ## Enable the Web Console (default: true) +-# enabled = true ++enabled = false + ## Address and port service will listen on (default: 127.0.0.1:7070) + # address = 127.0.0.1 + # port = 7070 Index: patches/patch-daemon_Daemon_cpp =================================================================== RCS file: patches/patch-daemon_Daemon_cpp diff -N patches/patch-daemon_Daemon_cpp --- /dev/null 1 Jan 1970 00:00:00 -0000 +++ patches/patch-daemon_Daemon_cpp 24 Sep 2026 13:52:06 -0000 @@ -0,0 +1,14 @@ +neuter broken pledge/unveil + +Index: daemon/Daemon.cpp +--- daemon/Daemon.cpp.orig ++++ daemon/Daemon.cpp +@@ -107,7 +107,7 @@ namespace util + i2p::config::ParseConfig(config); + i2p::config::Finalize(); + +-#ifdef __OpenBSD__ ++#if 0 + auto init_pledge = []() { + std::string pledge_file; i2p::config::GetOption("openbsd.pledge_file", pledge_file); + if (pledge_file == "") Index: patches/patch-libi2pd_Config_cpp =================================================================== RCS file: patches/patch-libi2pd_Config_cpp diff -N patches/patch-libi2pd_Config_cpp --- /dev/null 1 Jan 1970 00:00:00 -0000 +++ patches/patch-libi2pd_Config_cpp 24 Sep 2026 13:52:06 -0000 @@ -0,0 +1,23 @@ +neuter broken pledge/unveil + +Index: libi2pd/Config.cpp +--- libi2pd/Config.cpp.orig ++++ libi2pd/Config.cpp +@@ -396,7 +396,7 @@ namespace config { + ; + #endif + +-#ifdef __OpenBSD__ ++#if 0 + options_description openbsd_specific("OpenBSD specific options"); + openbsd_specific.add_options() + ("openbsd.pledge_file", value<std::string>()->default_value(""), "OpenbSD file with pledge rules") +@@ -433,7 +433,7 @@ namespace config { + #ifdef __linux__ + .add(unix_specific) + #endif +-#ifdef __OpenBSD__ ++#if 0 + .add(openbsd_specific) + #endif + ; Index: patches/patch-test_Makefile =================================================================== RCS file: patches/patch-test_Makefile diff -N patches/patch-test_Makefile --- /dev/null 1 Jan 1970 00:00:00 -0000 +++ patches/patch-test_Makefile 24 Sep 2026 13:52:06 -0000 @@ -0,0 +1,11 @@ +Index: tests/Makefile +--- tests/Makefile.orig ++++ tests/Makefile +@@ -18,7 +18,6 @@ ifneq (, $(findstring mingw, $(SYS))$(findstring windo + endif + + LDLIBS = \ +- -lboost_system$(BOOST_SUFFIX) \ + -lboost_program_options$(BOOST_SUFFIX) \ + -lssl \ + -lcrypto \ Index: pkg/PLIST =================================================================== RCS file: /cvs/ports/net/i2pd/pkg/PLIST,v diff -u -p -r1.18 PLIST --- pkg/PLIST 21 Feb 2026 14:20:20 -0000 1.18 +++ pkg/PLIST 24 Sep 2026 13:52:06 -0000 @@ -1,5 +1,5 @@ @newgroup _i2pd:838 -@newuser _i2pd:838:838::i2pd account:${LOCALSTATEDIR}/lib/i2pd:/sbin/nologin +@newuser _i2pd:838:838::i2pd account:/var/i2pd:/sbin/nologin @rcscript ${RCDIR}/i2pd @bin bin/i2pd include/i2pd/ @@ -29,6 +29,7 @@ include/i2pd/I2NPProtocol.h include/i2pd/I2PEndian.h include/i2pd/I2PService.h include/i2pd/I2PTunnel.h +include/i2pd/IdentMetrics.h include/i2pd/Identity.h include/i2pd/KadDHT.h include/i2pd/LeaseSet.h @@ -54,6 +55,7 @@ include/i2pd/Socks5.h include/i2pd/Streaming.h include/i2pd/Tag.h include/i2pd/Timestamp.h +include/i2pd/Torrents.h include/i2pd/TransitTunnel.h include/i2pd/TransportSession.h include/i2pd/Transports.h @@ -69,158 +71,56 @@ include/i2pd/util.h include/i2pd/version.h @static-lib lib/libi2pd.a @static-lib lib/libi2pdclient.a -@owner _i2pd -@group _i2pd -@sample ${SYSCONFDIR}/i2pd/ -@sample ${LOCALSTATEDIR}/lib/i2pd/ -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/ -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/ -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/ -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/router/ -@owner -@group @static-lib lib/libi2pdlang.a share/doc/pkg-readmes/${PKGSTEM} share/examples/i2pd/ -share/examples/i2pd/certificates/ -share/examples/i2pd/certificates/family/ -share/examples/i2pd/certificates/family/gostcoin.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/gostcoin.crt -@owner -@group -share/examples/i2pd/certificates/family/i2p-dev.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/i2p-dev.crt -@owner -@group -share/examples/i2pd/certificates/family/i2pd-dev.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/i2pd-dev.crt -@owner -@group -share/examples/i2pd/certificates/family/mca2-i2p.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/mca2-i2p.crt -@owner -@group -share/examples/i2pd/certificates/family/stormycloud.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/stormycloud.crt -@owner -@group -share/examples/i2pd/certificates/family/volatile.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/volatile.crt -@owner -@group -share/examples/i2pd/certificates/reseed/ -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/ -@owner -@group -share/examples/i2pd/certificates/reseed/acetone_at_mail.i2p.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/acetone_at_mail.i2p.crt -@owner -@group -share/examples/i2pd/certificates/reseed/admin_at_stormycloud.org.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/admin_at_stormycloud.org.crt -@owner -@group -share/examples/i2pd/certificates/reseed/creativecowpat_at_mail.i2p.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/creativecowpat_at_mail.i2p.crt -@owner -@group -share/examples/i2pd/certificates/reseed/diyarciftci_at_protonmail.com.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/diyarciftci_at_protonmail.com.crt -@owner -@group -share/examples/i2pd/certificates/reseed/echelon3_at_mail.i2p.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/echelon3_at_mail.i2p.crt -@owner -@group -share/examples/i2pd/certificates/reseed/hankhill19580_at_gmail.com.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/hankhill19580_at_gmail.com.crt -@owner -@group -share/examples/i2pd/certificates/reseed/i2p-reseed_at_mk16.de.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/i2p-reseed_at_mk16.de.crt -@owner -@group -share/examples/i2pd/certificates/reseed/igor_at_novg.net.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/igor_at_novg.net.crt -@owner -@group -share/examples/i2pd/certificates/reseed/lazygravy_at_mail.i2p.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/lazygravy_at_mail.i2p.crt -@owner -@group -share/examples/i2pd/certificates/reseed/orignal_at_mail.i2p.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/orignal_at_mail.i2p.crt -@owner -@group -share/examples/i2pd/certificates/reseed/r4sas-reseed_at_mail.i2p.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/r4sas-reseed_at_mail.i2p.crt -@owner -@group -share/examples/i2pd/certificates/reseed/rambler_at_mail.i2p.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/rambler_at_mail.i2p.crt -@owner -@group -share/examples/i2pd/certificates/reseed/reseed_at_diva.exchange.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/reseed_at_diva.exchange.crt -@owner -@group -share/examples/i2pd/certificates/reseed/sahil_at_mail.i2p.crt -@owner _i2pd -@group _i2pd -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/sahil_at_mail.i2p.crt -@owner -@group share/examples/i2pd/i2pd.conf +@mode 0750 @owner _i2pd @group _i2pd +@sample ${SYSCONFDIR}/i2pd/ +@mode 0640 +@owner root @sample ${SYSCONFDIR}/i2pd/i2pd.conf +@mode @owner @group share/examples/i2pd/tunnels.conf -@owner _i2pd +@mode 0640 +@owner root @group _i2pd @sample ${SYSCONFDIR}/i2pd/tunnels.conf +@mode @owner @group share/examples/login.conf.d/i2pd @sample ${SYSCONFDIR}/login.conf.d/i2pd +@cwd /var +@owner _i2pd +@group _i2pd +i2pd/ +i2pd/certificates/ +i2pd/certificates/family/ +i2pd/certificates/family/gostcoin.crt +i2pd/certificates/family/i2p-dev.crt +i2pd/certificates/family/i2pd-dev.crt +i2pd/certificates/family/mca2-i2p.crt +i2pd/certificates/family/stormycloud.crt +i2pd/certificates/family/volatile.crt +i2pd/certificates/reseed/ +i2pd/certificates/reseed/acetone_at_mail.i2p.crt +i2pd/certificates/reseed/admin_at_likogan.dev.crt +i2pd/certificates/reseed/admin_at_stormycloud.org.crt +i2pd/certificates/reseed/creativecowpat_at_mail.i2p.crt +i2pd/certificates/reseed/diyarciftci_at_protonmail.com.crt +i2pd/certificates/reseed/echelon3_at_mail.i2p.crt +i2pd/certificates/reseed/hankhill19580_at_gmail.com.crt +i2pd/certificates/reseed/i2p-reseed_at_mk16.de.crt +i2pd/certificates/reseed/igor_at_novg.net.crt +i2pd/certificates/reseed/lazygravy_at_mail.i2p.crt +i2pd/certificates/reseed/orignal_at_mail.i2p.crt +i2pd/certificates/reseed/r4sas-reseed_at_mail.i2p.crt +i2pd/certificates/reseed/rambler_at_mail.i2p.crt +i2pd/certificates/reseed/reseed_at_diva.exchange.crt +i2pd/certificates/reseed/sahil_at_mail.i2p.crt +i2pd/certificates/reseed/vserod1488_at_proton.me.crt Index: pkg/README =================================================================== RCS file: /cvs/ports/net/i2pd/pkg/README,v diff -u -p -r1.4 README --- pkg/README 16 Apr 2024 15:22:32 -0000 1.4 +++ pkg/README 24 Sep 2026 13:52:06 -0000 @@ -2,10 +2,52 @@ | Running ${PKGSTEM} on OpenBSD +----------------------------------------------------------------------- +Important: upgrading from i2pd < 2.61.0 +======================================= + +A major change in this package starting with version 2.61.0 requires +an intervention from all upgrading users: the running directory of i2pd, +which is also the $HOME directory of the _i2pd user, moves from +/var/lib/i2pd to /var/i2pd. + +If you installed a version of this package older than 2.61.0, you'll +change the _i2pd user's home directory and move all files under +/var/lib/i2pd to /var/i2pd. + +Unless you installed or configured i2pd in a non-standard way, here's +how most users should proceed: + +- terminate gracefully the i2pd process (see below) +- stop the service: + rcctl stop i2pd +- remove the old package: + pkg_delete i2pd +- delete the _i2pd user and group: + userdel _i2pd + groupdel _i2pd +- move /var/lib/i2pd to /var/i2pd: + mv /var/lib/i2pd /var/i2pd +- install the new package: + pkg_add i2pd +- edit /etc/i2pd/i2pd.conf (you can take inspiration from + /usr/local/share/examples/i2pd/i2pd.conf) +- restart the i2pd process: + rcctl restart i2pd + +At this point, the /var/lib directory should be empty and safe to +remove. + +If you edited /etc/newsyslog.conf to rotate i2pd log files +automatically, you should also adjust the path in it (see below). + +However, if you're installing this package for the first time with a +version equal or greather than 2.61.0, you have nothing special to do. + + Resource Limits: File Descriptors ================================= -${PKGSTEM} needs to open a lot of file descriptors. +i2pd needs to open a lot of file descriptors. For a regular node, you should raise the system-wide maxfiles limit to 8192: @@ -14,7 +56,7 @@ For a regular node, you should raise the # echo "kern.maxfiles=8192" >> /etc/sysctl.conf If you intend to run a floodfill, you should raise this limit even more: - + # sysctl kern.maxfiles=16000 # echo "kern.maxfiles=16000" >> /etc/sysctl.conf @@ -24,3 +66,56 @@ and also edit /etc/login.conf.d/i2pd: :openfiles-cur=8192:\ :openfiles-max=8192:\ :tc=daemon: + + +The HTTP interface +================== + +On OpenBSD, i2pd's HTTP interface is disabled by default, because it +allows any user on the system to perform actions on the daemon, such +as shutting it down, or access private data, such as the router +identity and the tunnels' B32 addresses. + +If you want to use this interface anyway, you can reenable it in +${SYSCONFDIR}/i2pd/i2pd.conf under the [http] section. + + +Graceful shutdown +================= + +It is good practice to shutdown the i2pd daemon gracefully, to avoid +immediately severing all connections, which would disconnect all +your peers and affect the overall operation of the I2P network. + +You can initiate a graceful shutdown without the HTTP interface by +sending a signal to the i2pd daemon like this: + + kill -INT $(cat /var/i2pd/i2pd.pid) + +When it shuts down gracefully, the i2pd daemon waits for all transit +tunnels to expire, which usually takes 10 minutes. + + +Logging +======= + +By default, this package sends its log messages to syslogd(8), which +writes them to the /var/log/daemon file. + +The default log level of i2pd ("warn") can be very verbose. You may +want to reduce this log verbosity by changing the "loglevel" +parameter in ${SYSCONFDIR}/i2pd/i2pd.conf. + +If you want log messages to be written to another file, e.g. +/var/i2pd/i2pd.log, you can change the "log" and "logfile" +parameters in ${SYSCONFDIR}/i2pd/i2pd.conf. To have this log file +rotated automatically, you can add an entry to /etc/newsyslog.conf +using the i2pd pid file so that newsyslog(8) can send SIGHUP to the +daemon after rotation. + +For example: + + /var/i2pd/i2pd.log _i2pd:_i2pd 644 6 * $D13 Z /var/i2pd/i2pd.pid + +Sending SIGHUP is enough for log rotation, and also makes i2pd reload +its tunnel configuration and rotate transient keys. Index: pkg/i2pd.rc =================================================================== RCS file: /cvs/ports/net/i2pd/pkg/i2pd.rc,v diff -u -p -r1.4 i2pd.rc --- pkg/i2pd.rc 11 Mar 2022 19:46:04 -0000 1.4 +++ pkg/i2pd.rc 24 Sep 2026 13:52:06 -0000 @@ -2,7 +2,12 @@ daemon="${TRUEPREFIX}/bin/i2pd --daemon" daemon_user="_i2pd" -daemon_flags="--service --datadir=${LOCALSTATEDIR}/lib/i2pd --conf=${SYSCONFDIR}/i2pd/i2pd.conf --tunconf=${SYSCONFDIR}/i2pd/tunnels.conf --tunnelsdir=${SYSCONFDIR}/i2pd/tunnels.d" +daemon_flags="--service \ + --datadir=/var/i2pd \ + --conf=${SYSCONFDIR}/i2pd/i2pd.conf \ + --tunconf=${SYSCONFDIR}/i2pd/tunnels.conf \ + --tunnelsdir=${SYSCONFDIR}/i2pd/tunnels.d \ + --certsdir=/var/i2pd/certificates" . /etc/rc.d/rc.subr
