[ANNOUNCE] WireGuard Snapshot `0.0.20181218` Available

Jason A. Donenfeld Jason at zx2c4.com
Tue Dec 18 16:50:27 CET 2018

Hash: SHA256


A new snapshot, `0.0.20181218`, has been tagged in the git repository.

Please note that this snapshot is, like the rest of the project at this point
in time, experimental, and does not consitute a real release that would be
considered secure and bug-free. WireGuard is generally thought to be fairly
stable, and most likely will not crash your computer (though it may).
However, as this is a pre-release snapshot, it comes with no guarantees, and
its security is not yet to be depended on; it is not applicable for CVEs.

With all that said, if you'd like to test this snapshot out, there are a
few relevant changes.

== Changes ==

  * jerry-rig: replace S_shipped with pl
  This fixes our jerry rig script, so that people can patch WireGuard into
  arbitrary kernel trees, instead of building as a standalone module.
  * chacha20,poly1305: simplify perlasm fanciness
  Numerous cleanups and correctness fixes in the assembly generators.
  * compat: don't undef BUILD_BUG_ON for Clang >=8
  The clang bug was finally fixed upstream, so we remove the workaround, while
  retaining the hack in our compat layer.
  * embeddable-wg-library: do not warn on unrecognized netlink attributes
  This brings behavior into parity with wg(8), and also allows more graceful
  addition of netlink attributes.
  * chacha20: do not define unused asm function
  This not only decreases code size, but also makes PaX's RAP happier.
  * compat: account for Clang CFI
  It turns out that RAP is no longer the only game in town, when it comes to CFI
  on kernels before Kees' epic timer_list refactoring. The Pixel 3/3XL kernels
  are based on 4.9 and come with Clang CFI on by default, so we account for this
  in our compat layer, so that we don't get CFI violation's and thus crashes.
  * wg-quick: bring interface up while setting MTU
  A small optimization to save a fork/exec.
  * makefile: use immediate expansion and use correct template patterns
  Coming up with the right combination of makefile template params that work on
  many kernels hasn't been easy, but hopefully this should solve building in a
  number of strange circumstances. If you're still having issues and you're
  using ccache, be sure to flush your cache first, as the cache might be serving
  stale copies of gcc's dependency info.

This snapshot contains commits from: Jason A. Donenfeld, Nathan Chancellor, 
and Aaron Jones.

As always, the source is available at https://git.zx2c4.com/WireGuard/ and
information about the project is available at https://www.wireguard.com/ .

This snapshot is available in compressed tarball form here:
  SHA2-256: 2e9f86acefa49dbfb7fa6f5e10d543f1885a2d5460cd5e102696901107675735
  BLAKE2b-256: e83755faa9ccb87048bc53b5d533c4b8e4a6fa859d2f95400c5a1716ff31a457

A PGP signature of that file decompressed is available here:
  Signing key: AB9942E6D4A4CFC3412620A749FC7012A5DE03AE

If you're a snapshot package maintainer, please bump your package version. If
you're a user, the WireGuard team welcomes any and all feedback on this latest

Finally, WireGuard development thrives on donations. By popular demand, we
have a webpage for this: https://www.wireguard.com/donations/

Thank you,
Jason Donenfeld



More information about the WireGuard mailing list