Skip to content
CAI
Software that uses CAICheck a score

opnsense/core

33.1

Weak · 19 September 2026

111.4k

lines of production code

PHP

with JavaScript, Python

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is the OPNsense firewall distribution, providing a comprehensive suite of network security and management capabilities including firewall rules, NAT, VPNs, DHCP, DNS, and traffic shaping. It features a modern Model-View-Controller architecture for its web interface and API, supporting high-availability clustering, captive portals, and intrusion detection. The codebase also includes extensive tooling for build validation, code quality, and software composition analysis.

How it got here

2014–2016 — MVC framework migration and backend modernization

106 changes.

This period focused on migrating the OPNsense web interface and core system components to a new Model-View-Controller (MVC) architecture, replacing legacy PHP implementations with modern Python 3 backends. The work involved rewriting critical services like configd, IDS, and Captive Portal, while simultaneously cleaning up deprecated configuration files and standardizing system logging and authentication infrastructure.

2017–2022 — MVC architecture migration and subsystem modernization

83 changes.

This period focused on migrating core subsystems—including Firewall, Interfaces, IPsec, OpenVPN, Unbound, and Syslog—from legacy PHP implementations to a unified Model-View-Controller (MVC) architecture. The work involved rewriting configuration models, API controllers, and user interface views to ensure consistent data handling and validation, while also refactoring backend scripts to Python 3 and restructuring boot-time initialization for improved reliability.

2023–2025 — MVC framework migration and service modernization

94 changes.

This period focused on replacing the legacy Phalcon MVC framework with a custom implementation and migrating core subsystems like OpenVPN, WireGuard, Kea DHCP, and Trust to the new architecture. It also involved modernizing backend scripts for DNS, firewall aliases, and health monitoring, while introducing new features such as SSO support and host discovery.

2026 — MVC migration and SBOM tooling

11 changes.

This period focused on migrating legacy configuration systems, particularly for Radvd and interfaces, to the modern MVC/API architecture while introducing new validation and migration scripts. The work also included adding unit tests for firewall rules, DHCP options, and IPv6 logic, alongside a new SPDX 3 SBOM generator tool and UI theme improvements.

Features

Add IANA reference data for DHCP and time zones

The contrib/iana directory now includes CSV and tab-separated files containing IANA-registered DHCPv4 and DHCPv6 option definitions, along with ISO 3166 country codes and timezone mappings. These static data files provide the reference tables needed to parse and validate DHCP parameters and geographic time zone identifiers.

contrib/iana · high confidence

Add IPsec SPD listing utility with automatic rule detection

A new library module for IPsec management has been introduced, providing a function to list Security Policy Database (SPD) entries by parsing the output of the setkey command. This utility distinguishes between automatic and manual rules, allowing callers to filter results by specific request IDs or rule type, which supports event handling for manual SPD entries when a request ID is set.

src/opnsense/scripts/ipsec/lib · high confidence

Add PHP Parallel Lint 1.3.2

The \contrib/parallel-lint\ directory now includes the PHP Parallel Lint tool (version 1.3.2). This adds a standalone PHP syntax checker that runs linting jobs in parallel, supporting output formats such as plain text, JSON, Checkstyle, and GitLab Code Quality. The tool allows users to specify PHP versions, exclude files, and view git blame information for syntax errors, and it is available as a standalone executable or via Composer.

contrib/parallel-lint · high confidence

Add Routes Index Controller

A new IndexController has been added for the Routes module, providing the entry point for the static routes management interface. This controller initializes the necessary form dialogs and grid views required to display and edit route configurations within the web UI.

src/opnsense/mvc/app/controllers/OPNsense/Routes · high confidence

Add UI library stylesheets for datepicker, select, charts, and dashboard widgets

The CSS directory now includes stylesheets for several UI components: bootstrap-datepicker v1.7.1, bootstrap-select v1.13.18, Chart.js v4 (via chart.css), nvd3 v1.8.6 (via nv.d3.css), jqTree, GridStack (gridstack.min.css and gridstack-extra.min.css), and dashboard-specific layouts (dashboard.css, dns-overview.css). These files provide the visual styling for date pickers, enhanced select dropdowns, data charts, tree views, draggable dashboard widgets, and DNS overview statistics.

src/opnsense/www/css · high confidence

Added Base32 encoder and decoder utility

The repository now includes a Base32 encoding and decoding class (Base32.php) in the contrib/base32 directory. This utility implements RFC 4648 compliant encoding and decoding, allowing users to convert strings to and from Base32 format using the standard alphabet. The class provides static methods for encoding and decoding, handling padding and character validation internally.

contrib/base32 · high confidence

Added SVG flag icons for Andorra, UAE, Afghanistan, Antigua and Barbuda, and Anguilla

The web interface now includes scalable vector graphics (SVG) flag icons for Andorra, the United Arab Emirates, Afghanistan, Antigua and Barbuda, and Anguilla. These assets are added to the \src/opnsense/www/css/flags/1x1/\ directory, enabling their use in the UI for country selection or identification.

src/opnsense/www/css/flags · high confidence

Added default beep melody database files

The system now includes a set of default melody definitions for the beep utility, located in the \src/etc/opnsense-beep.d\ directory. These new files (\high\, \low\, \start\, and \stop\) define specific audio patterns using frequency and duration values, allowing the system to play distinct sounds for high/low priority events and start/stop actions.

src/etc/opnsense-beep.d · high confidence

Auto theme switching with flash prevention

The new 'opnsense-auto' theme automatically switches between 'opnsense' and 'opnsense-dark' based on the browser's color scheme preference. To prevent visual flickering during this switch, the theme hides page content until the correct styles and images are applied, ensuring a seamless user experience.

src/opnsense/www/themes/opnsense-auto · high confidence

Captive portal zone-based configuration and lighttpd integration

The Captive Portal service now supports zone-based configuration, allowing multiple independent portal zones to be defined with specific interfaces, authentication servers, timeouts, and allowed addresses/MACs. This change introduces new configuration templates (captiveportal.conf, lighttpd-zone.conf, lighttpd-api-dispatcher.conf) that generate per-zone lighttpd server instances listening on dynamic ports (zoneid + 8000/9000), handle SSL/TLS settings per zone, and proxy API access to a central dispatcher. Users can now deploy distinct captive portal experiences on different interfaces or with different access policies, with the system automatically managing the underlying web server configuration for each zone.

src/opnsense/service/templates/OPNsense/Captiveportal · high confidence

Compiled assets for the official OPNsense dark theme

The build directory for the opnsense-dark theme now includes the compiled CSS and font assets required for the new dark user interface. This update provides the necessary stylesheets for core UI components, including the dashboard, DNS overview, and data tables (Tabulator), as well as supporting libraries like Bootstrap Dialog and Select. Additionally, the Source Sans Pro font files and their license are now bundled to ensure consistent typography across the dark-themed interface.

src/opnsense/www/themes/opnsense-dark/build · high confidence

IDS policy editor now displays rule origin metadata

The Intrusion Detection System policy editor now shows the message and source origin for each rule in the adjustments grid. This is achieved by new model field types that fetch rule metadata via the backend, allowing users to see where rules originate directly within the policy configuration interface.

src/opnsense/mvc/app/models/OPNsense/IDS/FieldTypes · high confidence

Initial DHCP Relay configuration interface

The DHCP Relay management page is now available in the GUI, allowing users to configure relay agents and their destinations. This change introduces the RelayController which loads the necessary forms and grid views for managing relay settings and destination servers.

src/opnsense/mvc/app/controllers/OPNsense/DHCRelay · high confidence

Initial Dnsmasq service configuration and startup scripts

This change introduces the core configuration template and startup script for the Dnsmasq DNS and DHCP service. The new \dnsmasq.conf\ template generates settings for interface binding, DHCP ranges, lease times, and various DNS behaviors (such as rebind protection, DNSSEC, and logging). It also includes support for DHCPv6, router advertisements, and specific options like \no-ping\, \add-mac\, and \add-subnet\. The \rc.conf.d\ file ensures the service is enabled or disabled based on the user's configuration, while \+TARGETS\ maps the generated configuration to the correct system paths.

src/opnsense/service/templates/OPNsense/Dnsmasq · high confidence

Initial IDS controller stubs for Intrusion Detection System UI

This change introduces the initial PHP controller stubs for the Intrusion Detection System (IDS) module within the OPNsense MVC framework. The IndexController sets up the main IDS dashboard view, wiring together forms for general settings, rule dialogs, ruleset management, and SSL fingerprinting. The PolicyController provides the foundation for the policy editor, linking the policy grid and rule dialog forms to the policy view. These controllers serve as the backend entry points for the new IDS frontend components.

src/opnsense/mvc/app/controllers/OPNsense/IDS · high confidence

Initial Monit service integration and configuration template

This change introduces the core Monit service monitoring infrastructure to OPNsense by adding the initial template files for the Monit configuration (monitrc) and system startup (rc.conf.d). Users can now configure global Monit settings such as the monitoring interval, HTTPD access controls, logging, and email alerting. The template supports defining various service checks (process, host, network, system, and custom programs) with specific options like PIDs, interfaces, timeouts, and polling frequencies. It also enables configuring service dependencies, start/stop actions, and custom test conditions, while including support for SSL options in mail server connections and a mechanism to include custom Monit configuration files.

src/opnsense/service/templates/OPNsense/Monit · high confidence

Initial NetFlow collection and aggregation service configuration

This change introduces the foundational configuration templates for the NetFlow feature, enabling the generation of system startup scripts and daemon settings for both the netflow collector and the flowd aggregator. Users will now have the underlying infrastructure in place to capture network flow data, with specific configuration files managing the enabling of the netflow daemon based on interface and target settings, as well as configuring the flowd service to listen on localhost port 2056 and store all flow records.

src/opnsense/service/templates/OPNsense/Netflow · high confidence

Initial support for Kea DHCPv4 and DHCPv6 services

This change introduces the initial configuration templates for the Kea DHCP server, offering a new alternative to the existing DHCPv4 implementation. It adds support for DHCPv4 and DHCPv6 servers, along with a DHCP DDNS server and a control agent. The templates define the startup behavior via \keactrl.conf\ and system integration via \rc.conf.d\, allowing users to enable or disable these specific Kea components independently.

src/opnsense/service/templates/OPNsense/Kea · high confidence

Introduce Cron model with newDailyJob helper and strict validation

The Cron module now includes a dedicated model (Cron.php and Cron.xml) that defines the schema for cron jobs and provides a newDailyJob helper method. This helper creates new cron entries with a default origin of 'cron' and the job disabled by default (enabled=0), requiring manual regeneration to activate. The model enforces strict validation on all cron parameters (minutes, hours, days, months, weekdays) using regular expression masks, ensures the origin field is limited to 30 characters, and standardizes the use of DescriptionField for job descriptions.

src/opnsense/mvc/app/models/OPNsense/Cron · high confidence

Introduce Favorites section in the navigation menu

The navigation menu now includes a new Favorites section that appears at the top of the menu for logged-in users. This section dynamically lists menu items that a user has marked as favorites in their profile settings, providing quick access to frequently used pages. The implementation adds a new PHP model to handle the collection of these favorites and updates the menu XML structure to include the new section.

src/opnsense/mvc/app/models/OPNsense/Core/Menu · high confidence

Introduce Kea DHCP controller for IPv4 and IPv6 management

The new DhcpController in the Kea module provides the backend routing for managing Kea DHCP services, supporting both IPv4 and IPv6 configurations. It exposes endpoints for general settings, subnets, reservations, options, and peers for both protocol versions, as well as dedicated views for lease monitoring (leases4 and leases6). Additionally, it includes specific actions for controlling the DHCP agent and configuring Dynamic DNS (DDNS) settings, effectively replacing the previous DHCPv4 implementation with a unified interface for the Kea server.

src/opnsense/mvc/app/controllers/OPNsense/Kea · high confidence

Introduce Kea DHCPv4/v6 service models and configuration generation

The Kea DHCP service models (KeaDhcpv4, KeaDhcpv6, KeaDdns, KeaCtrlAgent) and their corresponding XML definitions are added to the codebase. These models define the configuration schema for the Kea DHCP server, including support for DHCPv4 and DHCPv6 subnets, reservations, dynamic DNS (DDNS) settings, and control agent parameters. The PHP model classes implement logic to generate JSON configuration files for Kea, handling subnet definitions, option data collection, and validation rules for IP addresses, prefixes, and MAC addresses. This change establishes the backend foundation for managing the Kea DHCP service within OPNsense.

src/opnsense/mvc/app/models/OPNsense/Kea · high confidence

Introduce OPNsense Base MVC framework classes

This change adds the foundational classes for the OPNsense Model-View-Controller (MVC) framework within the \OPNsense\\Base\ namespace. It introduces \BaseModel\ to handle binding configuration data to objects, \BaseModelMigration\ to manage default migration logic, and \BaseValidator\ alongside a new \Validation\ class to decouple validation from Phalcon's native implementation. Additionally, it adds \ModelException\ and \ValidationException\ to standardize error handling within the new model layer.

src/opnsense/mvc/app/models/OPNsense/Base · high confidence

Introduces SSO provider abstraction and typed Kea DHCP option validation

This change adds a new \Provider\ class in the \OPNsense\\Auth\\SSOProviders\ namespace to serve as a minimalistic interface for Single Sign-On (SSO) support, allowing users to configure external authentication providers. Simultaneously, it introduces a strict type system for Kea DHCP options via the new \KeaOptionDataField\ model and \KeaEncoding\ enum, which enforces specific data types (such as IPv4, IPv6, HEX, and UINT) for DHCP option codes to prevent invalid configurations and ensure proper encoding.

php · high confidence

Introduction of SSO provider container interface

A new ISSOContainer interface has been added to the authentication library, defining a standard contract for components that manage multiple Single Sign-On (SSO) providers. This interface requires implementing classes to provide a generator of provider objects, establishing the foundational structure for how SSO providers are listed and accessed within the system.

src/opnsense/mvc/app/library/OPNsense/Auth/SSOProviders · high confidence

Intrusion Detection System (IDS) model initialization

The Intrusion Detection System configuration model has been initialized with a new data structure defining rule management, policy enforcement, and general settings. Users can now configure rule actions (alert, drop, pass), define custom policies with priorities and rule-set associations, and manage user-defined rules including SSL fingerprinting and bypass options. General settings include interface selection, capture modes (PCAP, Netmap, Divert), home network definitions, and packet size limits.

src/opnsense/mvc/app/models/OPNsense/IDS · high confidence

Migrate User, Group, and Privilege management to MVC/API controllers

The System Access management interface now uses new MVC/API controllers (GroupController, PrivController, UserController) to handle user, group, and privilege operations. This migration introduces specific safety fences that prevent users from locking themselves out by restricting access modifications that would remove all administrative privileges. It also adds support for exporting and importing user configurations via CSV, allows long usernames for non-local users without shell accounts, and ensures that changes to groups and users trigger the necessary authentication synchronization via configdpRun.

src/opnsense/mvc/app/controllers/OPNsense/Auth/Api · high confidence

Monit service management and status monitoring API

This change introduces the API controllers for the Monit service integration, enabling users to configure and monitor system services via the web interface. The ServiceController provides endpoints to check and reconfigure the Monit service, while the SettingsController exposes CRUD operations for managing alerts, services, and tests. The StatusController fetches the live Monit status page, converting raw text output into styled HTML for display and returning XML data for programmatic access.

src/opnsense/mvc/app/controllers/OPNsense/Monit/Api · high confidence

Monit service monitoring model initialization

The Monit service monitoring module has been initialized with its core configuration model. This introduces the data structure for managing general Monit settings (such as polling intervals, mail server connections with SSL options, and HTTP daemon access), as well as the definitions for alert recipients and monitored services. The model enforces validation rules for service names, event types, and test conditions, laying the groundwork for the Monit UI and service management features.

src/opnsense/mvc/app/models/OPNsense/Monit · high confidence

New API controllers for Kea DHCPv4/6 management and lease operations

This change introduces a set of new API controllers in the Kea module to manage DHCPv4 and DHCPv6 services, including subnets, reservations, options, and high-availability peers. It adds specific controllers for the control agent and DDNS settings, as well as dedicated lease management controllers (Leases4, Leases6) that fetch live lease data from the backend and support deleting individual leases. The ServiceController now checks the enabled status of both DHCPv4 and DHCPv6 services, and the new architecture supports CSV import/export for reservations and exposes lease expiration and HA settings to the GUI.

src/opnsense/mvc/app/controllers/OPNsense/Kea/Api · high confidence

New API controllers for core system management

This change introduces a suite of new API controllers in the Core module to manage system configuration and state. The BackupController provides endpoints to list, diff, delete, revert, and download configuration backups. The DashboardController manages user-specific dashboard layouts, including retrieving, saving, and restoring default widget configurations. The DefaultsController allows retrieving factory default settings and performing partial or full configuration resets. The FirmwareController handles firmware update checks, status retrieval, and package management. The HasyncController and HasyncStatusController manage high-availability synchronization and remote service control. The InitialSetupController handles the initial system setup wizard. The MenuController provides user-context-sensitive menu trees and search functionality. The ServiceController allows searching and controlling system services. The SnapshotsController manages ZFS boot environment snapshots, including creation, listing, and note management.

src/opnsense/mvc/app/controllers/OPNsense/Core/Api · high confidence

New API endpoints for DHC Relay configuration and management

This change introduces the backend API controllers for the DHC Relay feature, enabling the GUI to manage relay settings and service status. The SettingsController exposes endpoints to search, add, edit, delete, and toggle individual relay entries and destinations, while also providing a search function that includes the new circuit\_id and remote\_id fields and reflects the current running status of each relay. The ServiceController adds a reconfigure action that triggers the dhcrelay service to apply configuration changes via the backend.

src/opnsense/mvc/app/controllers/OPNsense/DHCRelay/Api · high confidence

New API endpoints for Traffic Shaper service management and statistics

This change introduces new API controllers for the Traffic Shaper module, specifically adding endpoints to manage the shaper service state and retrieve detailed traffic statistics. The new \ServiceController\ allows administrators to reconfigure the shaper (triggering template reloads for both Shaper and IPFW) and flush all IPFW rules via dedicated API actions. Additionally, a \statisticsAction\ endpoint is added to fetch current pipe, queue, and rule statistics, enriching the raw data with descriptive metadata from the configuration model to provide a comprehensive traffic breakdown overview in the UI.

src/opnsense/mvc/app/controllers/OPNsense/TrafficShaper/Api · high confidence

New API endpoints for gateway status and route management

The system now exposes new API controllers for the Routes module. A new GatewayController provides a status endpoint that returns current gateway health information via the backend, enabling dashboard widgets to display real-time gateway status. The RoutesController has been rewritten to use the ApiMutableModelControllerBase, introducing specific actions for searching, adding, retrieving, deleting, and toggling routes. Notably, the route update and deletion logic now defers actual removal to the apply phase by writing to temporary files, ensuring that static routes are correctly cleaned up when configuration changes are applied.

src/opnsense/mvc/app/controllers/OPNsense/Routes/Api · high confidence

New CLI scripts for model migrations and validation

Added three new executable scripts in the MVC script directory to improve developer tooling and operational control: \run\_migrations.php\ allows administrators to execute database schema migrations for models (optionally targeting specific plugins via a class prefix) with verbose logging support; \run\_validations.php\ provides a command-line interface to validate model definitions and report errors; and \load\_phalcon.php\ centralizes the Phalcon framework initialization and custom autoloader setup required by these scripts.

src/opnsense/mvc/script · high confidence

New Captive Portal API endpoints for access control, sessions, and vouchers

The Captive Portal now exposes a comprehensive set of API controllers to manage access and sessions programmatically. The AccessController provides status checks compliant with RFC 8908, including support for anonymous login when no authentication servers are configured and the ability to retrieve client MAC addresses via the hostwatch service. The SessionController allows administrators to list connected clients, search across zones, and manually connect or disconnect users. Voucher management is now handled by the VoucherController, which supports listing groups, generating and expiring vouchers, and dropping expired entries. Additionally, the TemplateController enables the creation, modification, and download of captive portal web templates, while the ServiceController ensures the IPFW firewall rules are reloaded when the service is reconfigured.

src/opnsense/mvc/app/controllers/OPNsense/CaptivePortal/Api · high confidence

New Captive Portal client, zone, and voucher management interfaces

The Captive Portal settings UI has been rebuilt with new Volt templates that introduce three main capabilities: a client session grid allowing administrators to filter by zone and disconnect individual clients; a zone management grid for configuring captive portal zones; and a voucher management interface that supports listing, creating, and deleting vouchers with configurable validity, expiry, and quantity, including CSV download. These views wire up to the existing Captive Portal API endpoints to provide a modern, tab-based interface for managing active sessions, network zones, and access credentials.

src/opnsense/mvc/app/views/OPNsense/CaptivePortal · high confidence

New Cron API controllers for job management and service restart

Added ServiceController and SettingsController to the Cron API. The SettingsController exposes actions to retrieve, add, update, delete, and toggle cron jobs, including validation that prevents modification of commands/parameters for jobs created by other services and restricts deletion of automatically registered jobs. The ServiceController provides an action to restart the cron daemon via configd.

src/opnsense/mvc/app/controllers/OPNsense/Cron/Api · high confidence

New Cron job management interface

The Cron settings page now provides a dedicated interface for managing scheduled tasks. This change introduces new MVC controllers (IndexController and ItemController) that power the job listing grid and the form for opening/editing individual cron items, replacing the previous implementation.

src/opnsense/mvc/app/controllers/OPNsense/Cron · high confidence

New DHCPD lease file watcher

A new Python module has been added to monitor the DHCP server lease file (/var/dhcpd/var/db/dhcpd.leases). This watcher parses lease entries, handling file rotation by detecting inode changes, and extracts key details such as IP address, MAC address, hostname, and lease timestamps. It specifically handles hostname overrides and cleans up formatting artifacts like trailing semicolons from the lease data.

src/opnsense/site-python/watchers · high confidence

New Dnsmasq Leases view with interface/protocol filtering and reservation management

The Dnsmasq configuration interface now includes a dedicated Leases tab (leases.volt) that displays current DHCP and DNS leases in a grid. Users can filter the lease list by specific network interfaces and IPv4/IPv6 protocol. The view provides direct actions for each lease: a 'Find Reservation' button to locate existing static reservations and an 'Add Reservation' button to create new ones, pre-populating the settings form with the lease's IP, MAC, client ID, or hostname. The settings view (settings.volt) has been updated to support these grids with interface-based grouping and tag filtering.

src/opnsense/mvc/app/views/OPNsense/Dnsmasq · high confidence

New Host Discovery API endpoints for interface neighbor scanning

This change introduces the API controllers for the new Host Discovery feature, enabling automatic discovery of network neighbors. The ServiceController exposes a search endpoint that queries the underlying hostwatch service and returns a recordset containing interface names (using descriptive names where available), MAC addresses, IP addresses, organization names, and first/last seen timestamps. The SettingsController provides the necessary API bindings to manage the hostdiscovery configuration model.

src/opnsense/mvc/app/controllers/OPNsense/Hostdiscovery/Api · high confidence

New Host Discovery Settings Controller

A new SettingsController has been added for the Hostdiscovery module, enabling the configuration interface for automatic neighbor discovery. This controller initializes the settings view and includes the moment.js library to support consistent datetime formatting in the user interface.

src/opnsense/mvc/app/controllers/OPNsense/Hostdiscovery · high confidence

New Hostdiscovery settings page with automatic host discovery and sorting

A new Hostdiscovery settings view has been added, introducing a tabbed interface for managing automatic network host discovery. The 'Discovered Hosts' tab displays a grid of detected devices showing interface, IP address, MAC address, organization, and timestamps for first and last seen events. By default, the host list is sorted by the 'last\_seen' timestamp in descending order, and timestamps are formatted as ISO datetimes. The page includes a reconfigure action button to apply service changes.

src/opnsense/mvc/app/views/OPNsense/Hostdiscovery · high confidence

New Hostwatch model for configurable host discovery

A new Hostwatch model has been added to the Hostdiscovery module, introducing a configuration interface for host discovery. This model allows users to enable or disable the feature, toggle promiscuous mode (defaulting to disabled), enable verbose logging, specify networks to skip, set expiration intervals for IPv4 and IPv6 entries, and select the network interfaces to monitor.

src/opnsense/mvc/app/models/OPNsense/Hostdiscovery · high confidence

New IDS API controllers for service management and settings

The Intrusion Detection System module now exposes dedicated API controllers (ServiceController and SettingsController) to manage the IDS service lifecycle and configuration. ServiceController provides actions to reconfigure the service (including automatic cron job creation for rule updates), update rules, reload the Suricata ruleset, and query alerts with search and pagination support. SettingsController exposes endpoints to search installed rules with metadata filtering, retrieve detailed rule information (including CVE/URL references), and list rule metadata, enabling the frontend to manage IDS settings and rule adjustments via the new API layer.

src/opnsense/mvc/app/controllers/OPNsense/IDS/Api · high confidence

New IDS policy editor and unified index view

The Intrusion Detection System interface now includes a dedicated Policy editor (policy.volt) that allows users to define rule adjustments and manage policy content via a tabbed grid interface, alongside a new main index view (index.volt) that consolidates general settings, rule file management, and alert logging into a single page with improved tab-based navigation and dynamic metadata filtering.

src/opnsense/mvc/app/views/OPNsense/IDS · high confidence

New IPsec MVC views for connections, sessions, and security policies

The IPsec management interface now includes new MVC view templates for Connections, Key Pairs, Leases, Pre-Shared Keys, Security Association Database (SAD), Sessions, Settings, Security Policy Database (SPD), Tunnels, and VTI. These views replace legacy PHP templates with a unified UIBootgrid-based interface, providing consistent data grids, inline editing, and service control updates for managing IPsec configurations and monitoring active sessions.

src/opnsense/mvc/app/views/OPNsense/IPsec · high confidence

New IPsec field type models for the MVC module

The IPsec configuration model now includes dedicated field type classes to support the new MVC-based interface. These additions include CharonLogLevelField for controlling debug verbosity, IPsecProposalField for defining cipher suites (including AEAD and post-quantum options), and specialized fields for managing connections, IKE addresses, IP pools, Security Policy Database (SPD) entries, and Virtual Tunnel Interfaces (VTI). These components provide the underlying data structures and validation logic required for the updated IPsec configuration UI.

src/opnsense/mvc/app/models/OPNsense/IPsec/FieldTypes · high confidence

New Kea DHCP management scripts for lease control and prefix delegation

This change introduces a suite of new Python scripts in src/opnsense/scripts/kea to manage Kea DHCP operations. The new get\_kea\_leases.py script fetches active leases and identifies reserved clients by matching against configuration, while del\_kea\_leases.py allows deleting specific IPv4 and IPv6 leases (including distinguishing IA\_NA and IA\_PD types). The kea\_prefix\_watcher.py script monitors DHCPv6 Prefix Delegation (PD) leases and automatically installs corresponding IPv6 routes, using the hostwatch service to resolve link-local next-hop addresses. Additionally, kea\_prefix\_renew.py handles dynamic prefix renewal by wiping and regenerating leases, and kea\_dhcp\_options.py provides a lookup for assigned and unassigned DHCP option codes. These scripts rely on a new lib/kea\_ctrl.py module to communicate with the Kea control socket.

src/opnsense/scripts/kea · high confidence

New Kea DHCP management views and lease grids

The Kea DHCP service interface now includes dedicated view templates for the control agent, DDNS, DHCPv4, and DHCPv6 settings, as well as new lease monitoring grids for both IPv4 and IPv6. These views introduce tabbed navigation for subnets, reservations, options, and HA peers, with grids that support grouping by subnet or interface. The lease grids allow filtering by interface, display lease states (assigned, expired, etc.), and provide direct actions to delete leases or add/find reservations. The interface also supports CSV import/export for reservations and uses a centralized apply button for reconfiguring the service.

src/opnsense/mvc/app/views/OPNsense/Kea · high confidence

New MVC API controllers for system diagnostics

The Diagnostics API layer has been expanded with new MVC controllers to expose system monitoring and troubleshooting tools via the API. ActivityController provides system activity data, while CpuUsageController exposes CPU type details and streams real-time CPU usage. DnsController adds reverse DNS lookup capabilities, and DnsDiagnosticsController allows executing DNS queries against configured servers. FirewallController now handles firewall log retrieval, streaming, filtering, statistics, and state querying. InterfaceController exposes ARP/NDP tables, routing tables, and interface name mappings. LogController manages log viewing, exporting, and live streaming across modules. NetflowController and NetworkinsightController provide configuration, status, and traffic analysis data. PacketCaptureController and PingController manage packet capture and ping diagnostic jobs.

src/opnsense/mvc/app/controllers/OPNsense/Diagnostics/Api · high confidence

New MVC core library components for configuration and backend communication

The system introduces a new set of core library classes in the MVC architecture to handle configuration management and backend interactions. This includes a new Config class for reading and writing the system XML configuration, a Backend class to manage communication with the configd daemon via sockets, and utility classes like File and FileObject for secure file handling with proper permissions. Additionally, a ConfigMaintenance class is added to support configuration resets and legacy path management, while Shell and SanitizeFilter provide safer command execution and input validation.

src/opnsense/mvc/app/library/OPNsense/Core · high confidence

New MVC default layout with integrated UI behaviors

The default view layout for the new MVC framework has been introduced, establishing the base HTML structure and client-side behavior for the interface. This layout integrates CSRF token injection for all AJAX requests, implements a global error handling mechanism that displays user-friendly dialogs for API failures (excluding specific upgrade status endpoints), and adds logic to automatically hide empty menu items and manage submenu collapse states. It also includes a live menu search feature that fetches results via API and a collapsible table header interaction, ensuring a consistent and functional user experience across MVC pages.

src/opnsense/mvc/app/views/layouts · high confidence

New MVC field types for authentication and user management

This change introduces a new set of model field types in the \OPNsense\\Auth\\FieldTypes\ namespace to support the migration of Users and Groups to the MVC/API architecture. These new fields provide specialized handling for authentication data: \UidField\ and \GidField\ automatically generate unique numeric IDs (starting at 2000) and enforce integer validation; \UsernameField\ allows long alphanumeric or email-style usernames for non-local users without shell accounts; \ApiKeyField\ manages key/secret pairs with base64 encoding; \StoreB64Field\ handles base64-encoded storage; \ExpiresField\ validates expiration dates; \MemberField\ and \PrivField\ provide dropdown lists for user and privilege selection; and \GroupMembershipField\ manages group membership mappings.

src/opnsense/mvc/app/models/OPNsense/Auth/FieldTypes · high confidence

New MVC field types for firewall aliases, rules, and NAT configuration

This change introduces a suite of new Model-View-Controller (MVC) field types in the firewall module to modernize how configuration data is validated, serialized, and displayed. Key additions include AliasContentField, AliasNameField, and AliasField to handle alias content validation, name restrictions (including reserved keywords and digit-starting rules), and dynamic alias statistics. FilterRuleField and SourceNatRuleField now provide structured serialization for firewall and source NAT rules, mapping internal model properties to the underlying packet filter configuration. Supporting types like FilterSequenceField and DNatSequenceField manage rule ordering, while GroupField and GroupNameField handle interface and system group definitions with specific naming constraints. Additional fields such as CategoryField, ScheduleField, and InterfaceField provide dropdown lists for categorization, scheduling, and interface selection, ensuring consistent data entry across the firewall configuration interface.

src/opnsense/mvc/app/models/OPNsense/Firewall/FieldTypes · high confidence

New MVC field types for interface configuration

The Interfaces settings now use a comprehensive set of new MVC model field types to handle configuration data. These include BridgeMemberField for selecting bridge members, DUIDField with validation for DHCPv6 identifiers, DeviceField for interface selection with dynamic icons, and GatewayField for gateway assignment. DHCP configuration is supported by Dhcp4/6RequestOptionsField and Dhcp4/6SendOptionsField with strict option validation. Network interface settings are managed via NetworkInterfaceField with legacy data conversion, while LinkAddressField handles IP address and interface linking. Additional fields include IfDescField for descriptions, LaggInterfaceField for link aggregation parents, MediaTypesField for media options, NeighborField for ARP/NDP entries, VipField for virtual IP formatting, and VipInterfaceField for VIP interface selection.

src/opnsense/mvc/app/models/OPNsense/Interfaces/FieldTypes · high confidence

New MVC firewall rule engine components

The firewall ruleset generation is now handled by a new set of MVC-based rule classes (FilterRule, ForwardRule, DNatRule, SNatRule, NptRule, and Plugin) that replace the legacy procedural code. These classes provide a structured way to parse, validate, and render firewall rules, including support for advanced features like reply-to gateways, NAT reflection, and IPv6 NPT. The Plugin class manages interface and gateway mappings, ensuring consistent rule generation across different firewall types.

src/opnsense/mvc/app/library/OPNsense/Firewall · high confidence

New MVC model field types for configuration management

The MVC model framework introduces a comprehensive set of new field types in the \FieldTypes\ directory to handle configuration data binding and validation. These include \ArrayField\ for managing repeating configuration entries, \BaseListField\ and \BaseSetField\ for handling option lists and comma-separated values, and specialized types such as \AutoNumberField\ for automatic sequence generation, \Base64Field\ for encoded data, \AuthGroupField\ and \AuthenticationServerField\ for system authentication entities, and \CertificateField\ for certificate selection. These components provide the underlying structure for the new Model-View-Controller interface, enabling consistent validation, sorting, and data manipulation across the OPNsense configuration system.

src/opnsense/mvc/app/models/OPNsense/Base/FieldTypes · high confidence

New MVC-based ACL model and core permission definitions

The system introduces a new PHP model class (ACL.php) that loads and parses ACL definitions from XML files, providing a structured way to manage access control lists within the MVC framework. This change is accompanied by a new core ACL.xml file that defines specific permissions for various system and diagnostic pages, such as Dashboard, System Status, Firewall Aliases, and Packet Capture, establishing the foundational access control rules for these UI components.

src/opnsense/mvc/app/models/OPNsense/Core/ACL · high confidence

New MVC-based Firewall API controllers for Aliases, Categories, Groups, and NAT

This change introduces a suite of new API controllers in the Firewall module, replacing legacy implementations with a modern MVC architecture. The new controllers include AliasController and AliasUtilController for managing firewall aliases (including real-time table updates and category support), CategoryController for organizing rules and aliases with color-coded categories, GroupController for interface groups, and FilterBaseController as a shared base for rule handling. Additionally, DNatController and FilterController provide the new API endpoints for Destination NAT and Firewall rules, featuring support for automatic rules, category filtering, and improved sorting. These controllers establish the backend foundation for the new firewall UI, enabling features like category-based organization, better performance with large rule sets, and consistent data handling across the firewall configuration.

src/opnsense/mvc/app/controllers/OPNsense/Firewall/Api · high confidence

New MVC-based diagnostic views for ARP, DNS, firewall logs, states, and system health

The Diagnostics section now uses new MVC view templates (arp, dns\_diagnostics, fw\_log, fw\_pftop, fw\_states, fw\_stats, health, log) that replace legacy PHP pages. These views provide a consistent interface for managing ARP tables (with optional name resolution and flush), running DNS diagnostics, viewing firewall logs with a ring-buffer approach, filtering and killing firewall states, viewing firewall statistics via NVD3 charts, and managing system health RRD graphs. The changes improve usability with features like rule-based filtering for firewall states and logs, hostname resolution options, and better graph management.

src/opnsense/mvc/app/views/OPNsense/Diagnostics · high confidence

New Message model class for structured validation feedback

A new Message class has been added to the OPNsense Base models to provide a structured container for validation feedback. This class stores a message string, an associated field name, and a type, allowing the system to present more granular and context-aware error or status messages to users during form validation and data processing.

src/opnsense/mvc/app/models/OPNsense/Base/Messages · high confidence

New NetFlow aggregation and reporting scripts

The netflow script directory now includes a new flowd aggregator (flowd\_aggregate.py) that processes flowd logs into SQLite databases for reporting, along with supporting scripts for exporting detailed data (export\_details.py), fetching timeseries (get\_timeseries.py), retrieving top usage (get\_top\_usage.py), and viewing flowctl statistics (flowctl\_stats.py). A new utility (dump\_log.py) allows dumping parsed flow logs, while flush\_all.sh provides a way to clear all local netflow data. These scripts are written in Python 3 and form the backend for the Network Insight and Reporting features.

src/opnsense/scripts/netflow · high confidence

New NetFlow data aggregation for interfaces, ports, and source addresses

The NetFlow reporting system now includes a new data aggregation layer that pre-computes traffic statistics into SQLite databases, enabling faster and more detailed network insight views. This change introduces aggregators for interface totals (tracking in/out direction), destination port totals, and source address totals, along with a detailed source address view that tracks specific service ports and protocols. These aggregations support multiple time resolutions (30 seconds to 1 day) with configurable retention periods, allowing users to analyze traffic patterns over varying timeframes without querying raw flow data.

src/opnsense/scripts/netflow/lib/aggregates · high confidence

New OpenVPN client export formats and options

The OpenVPN client export system has been expanded to support additional output formats and configuration options. Users can now export configurations as a ZIP archive (ArchiveOpenVPN) or a Viscosity-compatible .visz file (ViscosityVisz), in addition to the existing plain .ovpn file. The export logic now supports TLS-crypt-v2 keys, Windows certificate store integration (cryptoapi), static challenge (OTP) options, and the auth-nocache directive. The underlying export architecture has been refactored into a provider-based system (BaseExporter, IExportProvider, ExportFactory) to facilitate these new formats.

src/opnsense/mvc/app/library/OPNsense/OpenVPN · high confidence

New Python utility modules for logging, database, and TLS handling

This change introduces several new Python helper modules in the site-python directory to support core system functions. The new log\_helper module provides a reverse\_log\_reader for efficient log parsing, while duckdb\_helper and sqlite3\_helper add support for DuckDB and SQLite databases, including integrity checks, repairs, and export/import capabilities. Additionally, tls\_helper provides a wrapper for the requests library to apply platform-specific TLS settings from openssl.cnf, and daemonize.py adds a utility for managing system daemons.

src/opnsense/site-python · high confidence

New SPDX 3 SBOM generator tool in contrib/spdx-sbom

A new Python-based utility has been added at contrib/spdx-sbom that generates SPDX 3.0.1 formatted Software Bill of Materials (SBOM) files. The tool, invoked via spdx-generator.py \<package-name\>, queries the local package database (pkg) to extract package metadata, versions, licenses, and dependency relationships, then outputs a JSON-LD SBOM document. This provides a standardized way to inspect and export the software composition of installed packages.

contrib/spdx-sbom · high confidence

New Traffic Shaper UI with tabbed configuration and live statistics

The Traffic Shaper interface has been replaced with a new MVC-based view featuring three tabs for managing Pipes, Queues, and Rules. Users can now import and export configurations via CSV, toggle rule states directly from the grid, and perform a global flush/reload action with confirmation. A dedicated Statistics tab provides a live breakdown of traffic activity, displaying packet and byte counts for pipes, queues, and individual rules, along with active flow details.

src/opnsense/mvc/app/views/OPNsense/TrafficShaper · high confidence

New Trust management API and UI controllers

This change introduces the backend API and UI controllers for the new System Trust management feature. The new \CaController\, \CertController\, \CrlController\, and \SettingsController\ classes in the \Api\ namespace provide the REST endpoints for managing Certificate Authorities, certificates, and CRLs, including logic for linking CAs to certificates and triggering trust configuration updates. The corresponding UI controllers in the parent \Trust\ namespace wire these APIs to the web interface, rendering the specific forms and grids for each trust component.

src/opnsense/mvc/app/controllers/OPNsense/Trust/Api · high confidence

New Trust management interface with CA, Certificate, CRL, and Settings views

The System: Trust section now features dedicated MVC views for managing Certificate Authorities (ca.volt), Certificates (cert.volt), Certificate Revocation Lists (crl.volt), and global Trust settings (settings.volt). These views introduce a unified grid-based interface allowing users to view, search, and filter trust objects, with specific capabilities such as downloading certificates in various formats (including PKCS\#12), viewing raw certificate info, and configuring signature algorithm constraints. The Settings view adds a toggle to enable configuration constraints for trust objects.

src/opnsense/mvc/app/views/OPNsense/Trust · high confidence

New Trust management models and settings

This change introduces the new MVC models for the Trust subsystem, including Certificate Authorities (Ca), Certificates (Cert), and General settings (General). The General model adds a validation rule that prevents enabling 'config constraints' unless at least one of the specific constraint options (CipherString, Ciphersuites, groups, MinProtocol, MinProtocol\_DTLS, or SignatureAlgorithms) is also set. It also includes a migration (M1\_0\_2) that automatically upgrades any faulty DTLSv1.1 minimum protocol setting to DTLSv1.2. The Cert model adds logic to link certificates to CAs based on issuer subject matching, and the Ca model provides a helper to retrieve CAs by reference ID.

src/opnsense/mvc/app/models/OPNsense/Trust · high confidence

New and updated validation constraints for model fields

The validation framework in src/opnsense/mvc/app/models/OPNsense/Base/Constraints now includes several new constraint types to enforce more complex field relationships: AllOrNoneConstraint ensures fields are either all filled or all empty; DependConstraint requires referenced fields to be empty if the current field is empty; SetConstraint requires referenced fields to be unset if the current field is unset; SetIfConstraint forces fields to be set based on another field's value; ComparedToFieldConstraint validates numeric ranges against other fields; and SingleSelectConstraint ensures only one option is selected from a group. Additionally, UniqueConstraint has been updated to support case-insensitive checks and validation of added fields.

src/opnsense/mvc/app/models/OPNsense/Base/Constraints · high confidence

New authentication scripts for user and group management

Added four new PHP scripts in src/opnsense/scripts/auth to handle user and group synchronization and listing. add\_user.php creates new users with generated passwords and saves them to the configuration. list\_group\_members.php outputs a JSON map of group names to their member usernames, supporting comma-separated member lists. sync\_user.php synchronizes local system users with the configuration, handling creation, updates, and deletions, and signals the backend when changes occur. sync\_group.php synchronizes local system groups with the configuration, handling creation, updates, and deletions.

src/opnsense/scripts/auth · high confidence

New console shell menu scripts for firewall management

The console shell menu now includes a set of new interactive scripts to manage the firewall directly from the command line. Users can view a detailed network banner with IPv4/IPv6 addresses and SSL/SSH fingerprints (banner.php), perform factory resets (defaults.php), manage firmware updates and view changelogs (firmware.sh), reboot or halt the system (reboot.php, halt.php), change the root password (password.php), run network diagnostics (ping.php), restore configuration backups with a diff view (restore.sh), and configure interface IP addresses and ports (setaddr.php, setports.php).

src/opnsense/scripts/shell · high confidence

New development and linting scripts for code quality and dashboard ACLs

Added several new shell and Perl scripts to the Scripts directory to improve code quality checks and development workflows. The new \class-filename.sh\ script validates that PHP class names match their file names, while \class-import.sh\ detects stale or unused \use\ imports in PHP files. A new \dashboard-acl.sh\ script ensures that JavaScript dashboard widgets have corresponding ACL definitions and that their registered endpoints match their actual AJAX calls. Additional utilities include \unused-functions.sh\ for finding unused shell functions, \cleanfile\ for normalizing whitespace, \license\ for generating copyright headers, and \version.sh\ for deriving version information from Git.

Scripts · high confidence

New dnsmasq helper scripts for DHCP options and lease management

Added three new Python scripts to the dnsmasq directory: \dnsmasq\_dhcp\_options.py\ generates a JSON list of DHCP option codes (common, assigned, and unassigned) by parsing IANA data and dnsmasq help output; \dnsmasq\_watcher.py\ acts as a daemon that monitors ISC DHCP server lease files, validates hostnames, and updates a dnsmasq configuration file with dynamic host entries, triggering a SIGHUP to reload dnsmasq when changes occur; and \get\_dnsmasq\_leases.py\ parses the dnsmasq lease file to output a JSON list of active leases, including hardware addresses and interface mappings for both IPv4 and IPv6 clients.

src/opnsense/scripts/dnsmasq · high confidence

New field types for Diagnostics Packet Capture configuration

Added HostField and InterfaceField model components to support the new Packet Capture diagnostics feature. The HostField validates input strings containing network addresses (IPs, subnets, MAC addresses) combined with logical operators (and, or, not), ensuring syntactic correctness for host selection. The InterfaceField dynamically populates a dropdown list of available network interfaces by reading the system configuration and querying the current interface status, allowing users to select specific interfaces for packet capture.

src/opnsense/mvc/app/models/OPNsense/Diagnostics/FieldTypes · high confidence

New firewall diagnostics library for state and session analysis

The \src/opnsense/scripts/filter/lib\ directory now contains a new Python library (\\_\init\\_.py\ and \states.py\) that provides core utilities for firewall diagnostics. This includes an asynchronous DNS resolver for efficient hostname lookups, a wildcard netmask iterator for alias handling, and an address parser that improves the parsing of IPv4/IPv6 states from \pfctl\. The library also introduces logic to fetch rule labels from the active ruleset and parse \pfctl\ state output to support filtering by network clauses and rule descriptions, laying the groundwork for the new Sessions and States diagnostic views.

src/opnsense/scripts/filter/lib · high confidence

New interface management and diagnostic scripts

The system introduces a suite of new backend scripts in src/opnsense/scripts/interfaces to modernize interface configuration and diagnostics. This includes apply\_pending\_if\_changes.php for handling deferred interface updates, capture.py for managing packet capture jobs, and ifctl.sh for centralized control of network interfaces (nameservers, routes, prefixes). Additionally, new diagnostic tools like list\_arp.py and list\_ndp.py provide ARP/NDP table listings with manufacturer lookups, while gen\_duid.php generates DHCPv6 DUIDs and carp\_global\_status.php/carp\_set\_status.php manage CARP high-availability states.

src/opnsense/scripts/interfaces · high confidence

New manual pages for core system utilities

Added manual pages for several core system utilities, including configctl, ifctl, opnsense-beep, opnsense-crypt, opnsense-importer, opnsense-installer, opnsense-log, opnsense-shell, and opnsense-version. These pages document the available command-line options, usage modes, and file paths for each utility, providing administrators with reference material for system configuration, network interface management, import/export operations, and version metadata retrieval.

src/man · high confidence

New monit monitoring scripts for CARP and gateway health

Added three new scripts to the monit directory to enhance system monitoring: \carp\_status.php\ reports the state of CARP interfaces (MASTER, BACKUP, or mixed) to detect failover issues; \gateway\_alert.php\ checks gateway groups for down states, packet loss, or high latency and alerts when tiers are offline; and \setup.sh\ ensures the monit configuration file has secure permissions (600).

src/opnsense/scripts/monit · high confidence

New physical\_interface macro for interface name resolution

A new shared macro named physical\_interface has been added to the OPNsense template system. This macro resolves a logical interface name (such as 'lan') to its corresponding physical interface name (such as 'em0') by querying the system's interface configuration. If the logical interface is not found in the configuration, the macro returns the input name unchanged, ensuring graceful handling of missing or undefined interfaces.

src/opnsense/service/templates/OPNsense/Macros · high confidence

New pluggable backup provider framework with improved encryption

The backup system has been refactored to support a pluggable provider architecture, introducing a new \BackupFactory\ to discover and manage providers, an \IBackupProvider\ interface for defining custom connectors, and a \Base\ class that centralizes encryption and decryption logic. This change upgrades the default encryption for local backups to use AES-256-CBC with SHA-512 and PBKDF2, replacing the previous MD5-based method, while maintaining backward compatibility for decrypting older backups. The framework also ensures that backup passphrases are handled securely via file-based input to OpenSSL, preventing them from appearing in process listings.

src/opnsense/mvc/app/library/OPNsense/Backup · high confidence

New routing and gateway management scripts

The system introduces a new set of Python and PHP scripts in src/opnsense/scripts/routes to handle routing table operations and gateway monitoring. These include show\_routes.py for displaying the routing table, del\_route.py for manually deleting static routes, gateways.php for listing gateways and gateway groups, gateway\_status.php for reporting gateway health metrics (status, loss, delay), and gateway\_watcher.php for continuously monitoring gateway states and triggering configuration reloads on state changes. This replaces legacy mechanisms with a more structured, script-based approach for route and gateway management.

src/opnsense/scripts/routes · high confidence

New shaper statistics parsing library

A new Python library has been added to parse traffic shaper statistics from the system. It provides functions to extract and structure data from dnctl pipe, queue, and scheduler states, as well as ipfw rules, enabling more detailed traffic breakdown and monitoring capabilities for the shaper interface.

src/opnsense/scripts/shaper/lib · high confidence

New syslog index controller with local settings and destination management

The Syslog module now includes a dedicated IndexController that renders the main logging interface. This controller exposes a read-only local settings form and provides the necessary form and grid components for managing syslog-NG destinations via a dialog, enabling users to configure remote logging targets directly from the index page.

src/opnsense/mvc/app/controllers/OPNsense/Syslog · high confidence

New syslog log format parsers for Service Logs and epoch timestamps

The system now includes dedicated parsers for Service Log entries (formatted with ISO-style timestamps) and epoch-based syslog lines, in addition to existing standard syslog and RFC5424 support. This enables the logging subsystem to correctly parse and display entries from services that output logs in these specific formats, improving visibility into service activity during the current boot session.

src/opnsense/scripts/syslog/logformats · high confidence

New system administration utilities and shell interface

This release introduces several new command-line tools in /usr/sbin to streamline system management and configuration. The new opnsense-shell replaces the previous console menu, offering a unified interface for tasks like setting interface IPs, resetting passwords, and reloading services. A new opnsense-crypt utility allows administrators to encrypt or decrypt configuration files using a secret key, enhancing security for backups. The opnsense-version command has been expanded to support detailed version reporting, including architecture, ABI, and hash information, while opnsense-log provides a simplified way to view and list system logs. Additionally, pluginctl has been significantly enhanced with new modes for managing services, flushing configuration properties, and retrieving interface details, and a new carp\_service\_status script enables automatic CARP demotion/promotion based on service health.

src/sbin · high confidence

New system utility scripts for activity, boot environments, and certificate management

This update introduces a suite of new backend scripts in src/opnsense/scripts/system to support enhanced system monitoring and configuration capabilities. The new activity.py script provides detailed process activity data via the top command, while bectl.py adds support for managing ZFS boot environments (create, activate, clone, destroy). Certificate management is expanded with certctl.py, a Python-based re-implementation of FreeBSD's certctl for trust store operations, and cert\_fetch\_local.py for fetching locally managed certificates. Additionally, crl\_fetch.py automates the downloading and validation of Certificate Revocation Lists from configured distribution points, and disk\_info.py provides structured disk usage statistics. These scripts form the backend foundation for the new System Trust settings, Boot Environment snapshots, and system activity monitoring features.

src/opnsense/scripts/system · high confidence

New template helper functions for configuration rendering

A new \template\_helpers.py\ module has been introduced in the addons service, providing a suite of helper functions for configuration templates. These include utilities to safely navigate configuration data (\getNodeByTag\, \exists\, \empty\), ensure list consistency (\toList\), and resolve interface names (\physical\_interface\, \physical\_interfaces\). Additionally, new helpers support IPv6 formatting with optional brackets (\host\_for\_port\, \host\_with\_port\, \is\_ipv6\) and UUID resolution (\getUUIDtag\, \getUUID\), enhancing the flexibility and robustness of template rendering for users.

src/opnsense/service/modules/addons · high confidence

SSH algorithm query utility added

A new Python script (ssh\_query.py) has been added to the OpenSSH configuration scripts to query and report available SSH algorithms (key exchange, MAC, cipher, key, and key-signature) supported by the installed SSH client. This utility outputs the results as JSON, enabling the system to dynamically determine supported cryptographic options for configuration purposes.

src/opnsense/scripts/openssh · high confidence

Syslog API endpoints for service management and destination settings

New API controllers have been added to the Syslog module to expose service control and configuration management. The ServiceController provides a reset action to clear local logging and a stats action that retrieves syslog-ng statistics, enriches them with destination descriptions, and supports pagination, sorting, and search filtering. The SettingsController exposes standard CRUD operations for syslog destinations, including searching, retrieving, adding, updating, deleting, and toggling the enabled state of individual destination entries.

src/opnsense/mvc/app/controllers/OPNsense/Syslog/Api · high confidence

Traffic shaper model introduces CoDel/PIE scheduling and bandwidth validation

The TrafficShaper model now supports FlowQueue-CoDel and FlowQueue-PIE scheduling algorithms for pipes and queues, allowing users to configure specific CoDel parameters (target, interval, ECN) and PIE enablement. The model enforces mutual exclusivity between CoDel and PIE via validation constraints. Additionally, bandwidth configuration is now validated against a maximum limit (4294967295 bps) adjusted for the selected metric (bit/s, kbit/s, Mbit/s, Gbit/s), and new fields for delay, buckets, and queue masking (including IPv6) are available for pipe and queue definitions.

src/opnsense/mvc/app/models/OPNsense/TrafficShaper · high confidence

Unbound DNS blocklist matching moved to a dedicated Python module

The Unbound DNS service now uses a new Python-based module (dnsbl\_module.py) to intercept DNS queries and apply blocklist policies, replacing the previous implementation. This change introduces a new command-line tool (dnsbl\_match.py) that allows administrators to test blocklist matching against specific domains and source addresses, facilitating easier verification of blocklist configurations.

src/opnsense/scripts/unbound-dnsbl · high confidence

User-configurable lighttpd module settings for the webgui

A new configuration directory (conf.d) has been added to the lighttpd webgui setup, allowing users to enable and customize additional lighttpd modules. This change introduces an example configuration file for mod\_extforward, which enables the extraction of real client IPs from reverse proxy headers (such as X-Forwarded-For) for accurate logging. Users can now create their own .conf files in this directory to manage module loading order and specific module settings.

_src/etc/lighttpd\webgui · high confidence

WireGuard tunnel management and diagnostics scripts added

New utility scripts have been introduced to the WireGuard subsystem to improve tunnel lifecycle management and operational visibility. The \wg-service-control.php\ script now handles instance startup and shutdown, including dynamic interface creation, IP alias assignment, and automatic route installation for peer subnets, while also supporting a debug flag to toggle interface logging without requiring a service restart. Additionally, \reresolve-dns.py\ ensures DNS resolution stability by re-applying allowed-ips and endpoints for peers that have not completed a handshake recently, and \wg\_show.py\ provides a JSON-based interface for querying current WireGuard interface and peer status, including handshake times and transfer statistics.

src/opnsense/scripts/wireguard · high confidence

Removals

Cleanup of stale configuration file

The file previously located at cf/conf/trigger\_initial\_wizard has been removed and replaced with a placeholder in src/etc/rc.carp\_service\_status.d. This change appears to be a housekeeping step, likely cleaning up unused or obsolete configuration triggers, rather than introducing new CARP functionality.

_src/etc/rc.carp\_service\status.d · medium confidence

Removal of legacy boot, configuration, and system files

This change removes a large set of legacy and default files from the system, including \usr/boot/device.hints\_wrap\ and \usr/boot/loader.conf\_wrap\ (boot hints and loader settings), \usr/cf/conf/trigger\_initial\_wizard\ and \usr/conf.default/config.xml\ (default configuration and wizard triggers), and various files under \usr/etc/\ such as \bogons\, \dh-parameters\, \devd.conf\, \gettytab\, \disktab\, and \ecl.php\. It also deletes several PHP include files from \usr/etc/inc/\ (e.g., \CHAP.inc\, \IPv6.inc\, \PEAR.inc\, \auth.inc\) that are no longer needed or have been replaced. For users, this means the system no longer ships with these specific default configurations, legacy device hints, and bundled PHP libraries, reflecting a cleanup and migration of the underlying system structure.

usr · high confidence

Removal of legacy configuration files and embedded PHP libraries

The system has removed a large number of legacy configuration files and embedded PHP libraries from the etc directory. This includes the deletion of static data files such as country codes (ca\_countries), disk geometry tables (disktab), framebuffer tables (fbtab), and terminal configuration tables (gettytab). Additionally, several PHP include files (inc) have been removed, such as CHAP.inc, PEAR.inc, and various SASL client implementations, indicating a cleanup of deprecated or unused code components.

etc · high confidence

Removal of legacy sbin helper scripts

The system no longer includes the \athctrl.sh\ and \dhclient-script\ utilities in the sbin directory. \athctrl.sh\, which previously configured IFS parameters for Atheros wireless interfaces, has been removed. Additionally, the \dhclient-script\, which handled DHCP client actions such as setting hostnames, managing IP aliases, and configuring firewall states via pfctl, is no longer present.

sbin · high confidence

Removal of temporary pre- and post-upgrade scripts

The temporary shell and PHP scripts located in the tmp directory (post\_upgrade\_command, post\_upgrade\_command.php, and pre\_upgrade\_command) have been removed. These scripts previously handled specific upgrade-side effects such as mounting the filesystem as read-write, detecting interactive logins, configuring serial console settings, syncing Git repositories, and cleaning up obsolete files. Their removal indicates that this upgrade logic has been migrated elsewhere or is no longer required in this location.

tmp · high confidence

Architecture

Build system refactored into modular Makefile components

The build system in the Mk directory has been restructured from a monolithic structure into distinct, modular Makefile files (common.mk, core.mk, defaults.mk, git.mk, lint.mk, style.mk, sweep.mk, and version.mk). This change introduces dedicated targets for automated code quality checks (linting shell scripts, XML models, PHP syntax, and style compliance), code sweeping (formatting PHP and model XML, cleaning whitespace), and streamlined Git operations (branch management, cherry-picking, and tagging). It also centralizes build defaults, dependency definitions, and package metadata handling, providing a more maintainable and consistent foundation for building and validating the system.

Mk · high confidence

Centralized configd action definitions moved to actions.d

The system has migrated the configuration for configd service actions from scattered legacy locations into a structured directory at src/opnsense/service/conf/actions.d. This change introduces dedicated configuration files for various subsystems—including authentication, captive portal, firewall filtering, firmware management, and network interfaces—standardizing how backend commands are registered and executed. For users, this represents a backend architectural improvement that consolidates service control logic, ensuring more consistent and maintainable handling of system operations without altering the visible user interface.

src/opnsense/service/conf/actions.d · high confidence

New Trust Store abstraction layer for certificate management

A new \Store\ class has been introduced in the \OPNsense\\Trust\ namespace to serve as a wrapper around the legacy trust store functionality. This change centralizes certificate operations, providing static methods to retrieve CA and user certificates (\getCACertificate\, \getCertificate\), parse X.509 details (including subject alternative names, issuer, and serial number), and handle certificate signing and SSL option generation. For users, this represents a refactoring of the backend certificate handling logic to improve code reusability and maintainability within the MVC architecture, ensuring consistent parsing and storage of certificate metadata.

src/opnsense/mvc/app/library/OPNsense/Trust · high confidence

New pluggable authentication framework with factory and connectors

The authentication library has been refactored into a modular, pluggable architecture. A new \AuthenticationFactory\ now dynamically discovers and instantiates authenticator connectors (such as Local, LDAP, RADIUS, TOTP, API, and Voucher) that implement the \IAuthConnector\ interface, replacing the previous monolithic logic. This change introduces a standardized service binding via the \IService\ interface, allowing different services (like PAM or captive portal) to select from configured authentication servers. Users benefit from a more consistent and extensible authentication backend that cleanly separates connector implementations from the core factory logic.

src/opnsense/mvc/app/library/OPNsense/Auth · high confidence

Behavioural changes

Add Bootstrap Glyphicons SVG font to the dark theme

The opnsense-dark theme now includes the bootstrap glyphicons-halflings-regular.svg font file, ensuring that icon glyphs used throughout the interface render correctly in the dark theme environment.

src/opnsense/www/themes/opnsense-dark/assets · high confidence

A new template file (python3.link.in) has been added to the build system to generate a symbolic link for the Python 3 executable at build time, using a placeholder for the core Python version dot.

src/bin · medium confidence

Added initial migration stubs for Captive Portal and Traffic Shaper models

New version 1.0.0 migration classes (M1\_0\_0.php) have been added for the Captive Portal and Traffic Shaper models. These empty migration stubs establish the baseline version for these components, allowing the system to track and manage future schema or configuration changes for these specific areas.

src/opnsense/mvc/app/models/OPNsense/CaptivePortal/Migrations, src/opnsense/mvc/app/models/OPNsense/TrafficShaper/Migrations · high confidence

Authentication script now returns JSON properties for supported services

The opnsense-auth script in src/libexec has been updated to parse additional authentication properties (such as framed IP addresses and groups) and return them as JSON-encoded data to the caller. This change enables the authentication framework to pass extra context back to services that require it, while explicitly excluding the 'squid' service to work around a known issue where passing these properties causes failures. For most existing services, this remains a non-breaking change as they primarily rely on the exit code.

src/libexec · high confidence

Automated firmware configuration refresh and stale file cleanup during updates

A new update hook script (10-refresh.sh) has been introduced to run during the update process. This script ensures that relevant firmware configuration files are refreshed by invoking the configure\_firmware script and automatically removes stale .pyc files from the /usr/local/opnsense directory that are not handled by the package manager.

src/etc/rc.syshook.d/update · high confidence

Automated migration of legacy firmware, HA, and tunables settings

The system now automatically migrates legacy configuration data during upgrades to ensure compatibility with the current MVC architecture. For firmware settings, old 'devel' types are mapped to 'business' and subscription details are extracted from the mirror URL, while obsolete flavour entries are cleared. High Availability (HA) settings are migrated to use a unified 'syncitems' list and the legacy 'pfsyncenabled' flag is folded into the 'pfsyncinterface' setting, with the pfsync version defaulting to 1301 for upgrades to preserve existing behavior. Additionally, legacy 'sharednet' tunables are converted into specific network tunables (disabling ARP movement logging) and the old configuration block is removed.

src/opnsense/mvc/app/models/OPNsense/Core/Migrations · high confidence

Automatic state cleanup for unreachable or lower-priority gateways

The monitor hook now includes a recovery script that actively kills existing connection states when a gateway becomes unreachable or when a higher-priority gateway becomes available. This ensures that traffic is immediately rerouted to the correct path, preventing stale connections from persisting on failed or superseded links.

src/etc/rc.syshook.d/monitor · high confidence

Bootstrap 3.4.1 stylesheets integrated into the OPNsense theme

The OPNsense web interface now uses the Bootstrap 3.4.1 stylesheet library, replacing the previous version. This update brings the standard Bootstrap 3.4.1 styling for core UI components—including alerts, buttons, forms, navigation, and grid layouts—to the OPNsense dashboard and configuration pages, ensuring consistent visual presentation and behavior across the interface.

src/opnsense/www/themes/opnsense/assets/stylesheets/bootstrap · high confidence

CARP and network interface event handling reconfigured

The devd configuration has been updated to improve network state management. A new carp.conf file now explicitly handles CARP state transitions (MASTER, BACKUP, and INIT) by invoking configctl, ensuring proper event capture for CARP interfaces. Additionally, ifnet.conf has been rewritten to ensure configd receives both LINK\_UP and LINK\_DOWN events for wired (ethernet) and wireless (802.11) devices, and it disables the legacy /etc/pccard\_ether script for non-USB devices to prevent unwanted reconfiguration.

src/etc/devd · high confidence

CARP state changes now trigger service reconfiguration for DHCP Relay, OpenVPN, PPP, and WireGuard

The CARP hook system now automatically reconfigures specific services when the node's CARP role changes (e.g., switching between MASTER and BACKUP). New hook scripts ensure that DHCP Relay instances restart if CARP tracking is enabled, PPP connections are suspended or restored based on the CARP state, and both OpenVPN and WireGuard services are reconfigured to adapt to the new high-availability status.

src/etc/rc.syshook.d/carp · high confidence

Captive Portal UI migrated to new MVC framework

The Captive Portal interface has been rewritten using the new MVC framework and standards. This change introduces new controller classes (IndexController, SessionController, VoucherController) that serve the zone management, client session overview, and voucher frontend pages respectively, replacing the previous implementation.

src/opnsense/mvc/app/controllers/OPNsense/CaptivePortal · high confidence

Captive Portal model introduces zone-based configuration and template management

The Captive Portal model has been restructured to support a zone-based architecture, allowing administrators to define multiple zones with distinct settings such as interfaces, authentication servers, timeouts, and allowed MAC addresses. This change adds support for configuring idle and hard timeouts, enforcing group-based authentication, and managing custom login templates. It also introduces options to disable automatic firewall rules, send accounting requests, and include extended pre-authentication data, providing finer control over captive portal behavior and security policies.

src/opnsense/mvc/app/models/OPNsense/CaptivePortal · high confidence

Captive portal library refactored with new accounting and host lookup modules

The captive portal library has been reorganized into a new directory structure, introducing dedicated modules for database management, IPFW-based accounting, and ARP/host lookup. The new db.py module initializes a SQLite database with migrations for session restrictions and accounting state, while ipfw.py implements traffic accounting using ipfw rules and tables. The arp.py module now parses host discovery data in ISO 8601 format and handles JSON parsing errors safely. Additionally, pf.py provides IPv6-aware table management for the packet filter, and daemonize.py standardizes daemon startup with privilege dropping and logging.

src/opnsense/scripts/captiveportal/lib · high confidence

Captive portal scripts migrated to new location with accounting and template updates

The captive portal backend scripts have been moved from src/opnsense/scripts/OPNsense/CaptivePortal to src/opnsense/scripts/captiveportal. This change includes a new allow.py script that now passes the zoneid parameter to the accounting function, fixes a regression where allowed addresses were missing from session IPs, and excludes IPv4 from roaming logic. The cp-background-process.py script now handles IPv6 support and adjusts the accounting interval to match the Acct-Interim-Interval setting. Additionally, the generate\_certs.php script has been cleaned up to remove legacy config dependencies and unused certificates, while the process\_accounting\_messages.php script has been updated to re-introduce hash lookup for accounting purposes.

src/opnsense/scripts/captiveportal · high confidence

Centralized IPv6 prefix and interface auto-configuration data access

This change introduces two new classes in the Interface library to standardize how dynamic network configuration data is accessed. The new Autoconf class provides a unified static interface to retrieve interface properties (such as nameservers, routers, prefixes, and search domains) collected by the ifctl utility, replacing scattered direct file reads. Additionally, the Idassoc class implements logic to calculate and return IPv6 prefix information for interfaces using identity associations (idassoc6), including on-link, allocated, and associated prefixes. This centralization ensures that services like Kea DHCPv6 can reliably access consistent prefix state data, preventing crashes during initial configuration generation when real prefixes are not yet available.

src/opnsense/mvc/app/library/OPNsense/Interface · high confidence

Configurable configd environment and new service action definitions

The configd service now supports a configurable environment, explicitly setting the PATH, HOME, and REQUESTS\_CA\_BUNDLE variables in the new configd.conf file to ensure consistent system certificate usage. Additionally, a new actions\_service.conf file defines standard service management actions (start, stop, restart, status, list) that delegate to the pluginctl utility, replacing previous hardcoded or script-based implementations.

src/opnsense/service/conf · high confidence

Configurable hostwatch discovery and cleanup intervals

The hostwatch service now supports configurable IPv4 and IPv6 expiration intervals, allowing administrators to define how long discovered hosts remain in the neighbor table before being cleaned up. This change introduces new settings for expire4\_interval and expire6\_interval, which are passed to the hostwatch daemon via command-line flags, providing more granular control over network discovery data retention compared to the previous default behavior.

src/opnsense/service/templates/OPNsense/Hostdiscovery · high confidence

Core system models migrated to the MVC framework

The core system configuration models—Access Control (ACL), Firmware, High Availability Sync (Hasync), Initial Setup Wizard, and System Tunables—have been rewritten as MVC models. This migration introduces structured validation for firmware subscription keys and wizard inputs, supports configurable user landing pages and source-network constraints in ACLs, and updates HA sync defaults (such as pfsync version 1500) to align with the new framework.

src/opnsense/mvc/app/models/OPNsense/Core · high confidence

Core version metadata now includes product tier and nickname

The core version metadata file has been renamed to 'core' and expanded to include new fields such as 'product\_tier' (set to 1) and 'product\_nickname', alongside existing product identifiers like series and ABI. This change ensures that the core package metadata exposes additional context about the product's tier and branding, which can be used by the system to better identify and manage core components and their relationships with other packages.

src/opnsense/version · high confidence

Cron job command migrations for Unbound and firmware updates

The system now automatically updates legacy cron job definitions to their current command names during migration. Specifically, Unbound DNSBL jobs previously using the 'unboundplus' command are updated to 'unbound', and firmware-related jobs are renamed from 'firmware changelog fetch' to 'firmware changelog cron' and from 'firmware probe' to 'firmware poll'. Additionally, IPsec reconfiguration jobs are migrated from 'ipsec reconfigure' to 'ipsec reload'. These changes ensure that scheduled tasks continue to function correctly after upgrades without manual intervention.

src/opnsense/mvc/app/models/OPNsense/Cron/Migrations · high confidence

Cron job generation now respects enabled/disabled status and uses safer parameter escaping

The cron template system has been updated to generate user crontabs that only include jobs marked as enabled, preventing disabled tasks from running. Additionally, command arguments and parameters are now escaped using shlex functions to handle special characters and options starting with minus signs correctly, addressing previous issues where shlex.quote behavior broke certain command-line options.

src/opnsense/service/templates/OPNsense/Cron · high confidence

DHC Relay configuration model introduces validation and CARP tracking

The DHC Relay service now enforces stricter configuration rules: users can no longer mix IPv4 and IPv6 addresses within a single destination, and each relay interface is limited to one destination per address family. Additionally, relays can now be configured to track CARP virtual IPs via the new \carp\_depend\_on\ field, and the model supports custom DHCP agent circuit and remote ID options.

src/opnsense/mvc/app/models/OPNsense/DHCRelay · high confidence

DHCP Relay GUI now displays relay status and uses snake\_case API endpoints

The DHCP Relay configuration page has been updated to include a 'Status' column in the relays table, allowing users to see the current state of each relay directly in the interface. Additionally, the underlying API calls for managing relays and destinations have been standardized to use snake\_case notation (e.g., /api/dhcrelay/settings/get\_relay/), ensuring consistency with the broader MVC framework changes.

src/opnsense/mvc/app/views/OPNsense/DHCRelay · high confidence

Dashboard widgets rewritten with new base classes and Chart.js v4 support

The dashboard widget system has been refactored to use new base classes (BaseWidget, BaseTableWidget, BaseGaugeWidget) that provide a consistent foundation for all widgets. This change introduces support for Chart.js v4, enabling new visualization capabilities like the CPU usage widget with selectable graph types (total, intr, user, sys) and the Disk widget with a detailed breakdown view. Existing widgets such as Announcements, CARP, Certificates, Dnsmasq Leases, and Firewall have been updated to use these new base classes, improving consistency and maintainability. The refactoring also includes improvements to widget configuration, data handling, and responsive design.

src/opnsense/www/js/widgets · high confidence

Deprecation of opnsense sudoers configuration

The specific sudoers configuration file for opnsense has been marked as obsolete and retained only for reference. Users should refer to the 20-sudoers file for current configuration settings, as this specific file is scheduled for removal in version 26.7.

src/etc/sudoers.d · high confidence

Diagnostics pages migrated to MVC controllers

The Diagnostics section of the web interface has been refactored from legacy PHP pages to the MVC framework. This change introduces dedicated controllers for system activity, DNS diagnostics, firewall logs and statistics, interface details (ARP, NDP, routing, VIPs, netstat), logging, netflow, network insight, packet capture, ping, port probe, system memory, system health, traceroute, and traffic. Users will see these diagnostics tools served through the new MVC structure, which standardizes the UI and integrates them with the modern frontend components.

src/opnsense/mvc/app/controllers/OPNsense/Diagnostics · high confidence

Diagnostics settings migration to MVC model

The Diagnostics settings have been converted to the MVC architecture, introducing a new migration script (M1\_0\_0) for the SystemHealth model. This migration automatically transfers the RRD (Round Robin Database) enable status from the legacy configuration to the new model and cleans up the old configuration entries to ensure a smooth transition for existing users.

src/opnsense/mvc/app/models/OPNsense/Diagnostics/Migrations · high confidence

Diagnostics tools migrated to MVC model structure

The configuration models for core diagnostics tools—Ping, DNS Lookup, Port Probe, Traceroute, Packet Capture, and NetFlow—have been converted to the MVC framework. This migration introduces standardized XML-based model definitions that enforce input validation (such as valid hostnames, IP addresses, and port ranges) and define specific settings like protocol families (IPv4/IPv6), interface selection, and NetFlow collection timeouts. Users benefit from consistent form behavior, improved data integrity checks, and unified configuration management across all network diagnostic utilities.

src/opnsense/mvc/app/models/OPNsense/Diagnostics · high confidence

Dnsmasq field validation and migration improvements

The Dnsmasq configuration model now enforces stricter validation for hostnames and domains, ensuring labels comply with RFC1035 standards (1–63 characters, alphanumeric with hyphens/underscores) and optionally limiting total domain length to 255 characters. The DomainIPField has been updated to allow the IP address portion to be cleared (empty), and legacy XML structures containing host/domain pairs are automatically flattened and migrated to the new format. Additionally, the RangeAddressField now correctly handles IPv6 ranges that start with '::' by validating them as valid IPv6 addresses.

src/opnsense/mvc/app/models/OPNsense/Dnsmasq/FieldTypes · high confidence

Dnsmasq migration normalizes interfaces and migrates domain-based hostnames

The Dnsmasq configuration migration (M1\_0\_0) now ensures that stale interface selections do not cause validation errors by normalizing the interface value. Additionally, it handles legacy host entries where the hostname field was empty but a domain was specified: the migration automatically copies the domain value into the hostname field and clears the domain field, ensuring existing host records are correctly formatted for the current model structure.

src/opnsense/mvc/app/models/OPNsense/Dnsmasq/Migrations · high confidence

Dnsmasq model migration to MVC with enhanced validation and new configuration options

The Dnsmasq service configuration model has been migrated to the MVC architecture, introducing stricter validation rules and new configuration capabilities. Users will see enforced uniqueness for DHCP IP addresses and CNAMEs, with specific checks preventing duplicate IPs in DHCP reservations and overlapping CNAMEs with host overrides. The model now supports new features including CNAME configuration for host overrides, IPset support for domain overrides, and refined DHCP range validation (requiring end addresses for 'Range' type domains). Additionally, the configuration schema now includes fields for DNS port selection, logging controls (log\_dhcp, log\_quiet), and DHCPv6 options, providing more granular control over the Dnsmasq service behavior.

src/opnsense/mvc/app/models/OPNsense/Dnsmasq · high confidence

Dnsmasq service migrated to MVC/API architecture

The Dnsmasq configuration and management interface has been migrated from the legacy system to the modern MVC/API framework. This change introduces new API controllers for handling leases, service status, and settings, replacing the previous implementation. Users will now interact with the Dnsmasq DNS and DHCP settings through the updated API endpoints, which support features such as safe deletion of tags, protocol-based filtering in the leases view, and CSV import/export for host overrides.

src/opnsense/mvc/app/controllers/OPNsense/Dnsmasq/Api · high confidence

Dynamic aliases now include Captive Portal zones and interface networks

The firewall alias system now automatically generates dynamic aliases for Captive Portal zones (marked as type 'external') and local interface networks (marked as type 'internal'). This allows these resources to be directly referenced in firewall rules without manual maintenance, resolving issues where Captive Portal zones were previously unavailable for rule targeting.

src/opnsense/mvc/app/models/OPNsense/Firewall/DynamicAliases · high confidence

Firewall UI migrated to MVC architecture

The Firewall management interface has been migrated from the legacy PHP-based UI to the modern Model-View-Controller (MVC) framework. This change introduces dedicated controllers for all firewall components—including filter rules, NAT (Source, Destination, One-to-One, NPT), Aliases, Groups, Categories, and Settings—ensuring a consistent, grid-based user experience across the entire firewall configuration section.

src/opnsense/mvc/app/controllers/OPNsense/Firewall · high confidence

Firewall UI migrated to MVC with new alias, category, and migration views

The legacy PHP-based Firewall views have been replaced with new MVC Volt templates, introducing a modernized user interface for managing firewall components. The new alias management view (alias.volt) features a Tabulator-based grid with virtual DOM support, category-based filtering, and color-coded category indicators. A new category management view (category.volt) allows users to organize aliases with color coding and CSV import/export capabilities. The migration assistant view (firewall\_migration.volt) provides a guided workflow for transitioning from legacy firewall rules to the new MVC-based system, including rule export/import and legacy rule removal. Group management (group.volt) now uses the MVC grid pattern with interface linking. NAT rule management (nat\_rule.volt) includes tree view support and Source NAT mode awareness. Settings management (settings.volt) has been migrated to the MVC pattern with unified form handling.

src/opnsense/mvc/app/views/OPNsense/Firewall · high confidence

Firewall configuration migrated to new MVC model architecture

The Firewall module's configuration models (Aliases, Categories, Destination NAT, Firewall Rules, and Interface Groups) have been migrated to the new Model-View-Controller (MVC) framework. This change introduces new model classes and XML definitions that enforce stricter validation rules—such as ensuring address types match the selected IP protocol version and preventing invalid combinations of fields like 'any' with other aliases. It also adds new capabilities like firewall rule categories with color coding, improved alias management with authentication support, and refined Source/Destination NAT options, while maintaining backward compatibility through migration scripts.

src/opnsense/mvc/app/models/OPNsense/Firewall · high confidence

Firewall diagnostics scripts rewritten in Python 3

The firewall diagnostics and management scripts in src/opnsense/scripts/filter have been converted from Python 2 to Python 3. This update replaces legacy implementations with modern Python 3 code for listing and managing firewall states, tables, and rules, ensuring compatibility with the current system runtime and improving the reliability of diagnostic commands like state listing and table management.

src/opnsense/scripts/filter · high confidence

Firewall menu structure migrated to MVC with legacy fallbacks

The Firewall section of the web interface now uses a new MVC-based menu system defined in Menu.php and Menu.xml. This introduces a 'Migration assistant' entry that appears when legacy firewall rules or outbound NAT rules are present, guiding users to the new MVC pages. The menu dynamically lists interface-specific rule pages for both the new MVC filter rules and legacy rules (if firewall\_rules.php exists), and includes legacy Outbound NAT access if firewall\_nat\_out.php is present. The static menu definition also establishes the structure for Source NAT, Destination NAT, One-to-One NAT, and NPTv6 under the NAT submenu, along with a Settings page.

src/opnsense/mvc/app/models/OPNsense/Firewall/Menu · high confidence

Firmware update scripts restructured into modular components

The firmware update backend has been refactored from a monolithic script into a modular system of specialized shell scripts (bogons, changelog, check, cleanup, connection, health, install, lock, query, etc.) orchestrated by a central launcher. This change improves maintainability and allows individual update tasks—such as bogon table updates, changelog fetching, and health audits—to be executed independently and safely via the launcher, which handles locking, environment initialization, and output piping.

src/opnsense/scripts/firmware · high confidence

Health reporting scripts refactored and migrated to Python 3

The health reporting backend in src/opnsense/scripts/health has been rewritten to use Python 3, replacing the previous implementation. This change introduces new scripts for fetching RRD data (fetchData.py), listing available reports with metadata (listReports.py), and flushing RRD files (flush\_rrd.py), while the PHP-based updater (updaterrd.php) now utilizes the OPNsense MVC framework and RRD factory for data collection. The refactoring specifically addresses issues with RRD files containing single measurements and ensures NaN values are handled correctly, improving the reliability of system health statistics.

src/opnsense/scripts/health · high confidence

IPsec API controllers migrated to MVC architecture

The IPsec management interface has been refactored to use the MVC framework, replacing the legacy subsystem with a set of dedicated API controllers. This change introduces new endpoints for managing IPsec Connections, Key Pairs, Pre-Shared Keys, and Tunnel Settings via the \swanctl\ model, while also providing controllers for reading runtime status (Sessions, Security Association Database, Security Policy Database) and managing legacy configuration compatibility. Users will experience a more consistent and performant management interface for configuring and monitoring IPsec tunnels.

src/opnsense/mvc/app/controllers/OPNsense/IPsec/Api · high confidence

IPsec configuration migration for version 1.0

This update introduces a series of configuration migrations (M1\_0\_0 through M1\_0\_4) that automatically update existing IPsec settings to the new model structure. The process initializes missing request IDs for Phase 2 entries, consolidates pre-shared keys from legacy user and mobile key sections into a unified module, and moves advanced settings such as syslog options, passthrough networks, and VPN rule disabling to their correct locations. Additionally, it migrates mobile client attributes—including DNS, WINS, domain, banner, and RADIUS configurations—into the Charon plugin settings, ensuring a seamless transition without manual intervention.

src/opnsense/mvc/app/models/OPNsense/IPsec/Migrations · high confidence

IPsec management scripts migrated to Python 3 and swanctl

The IPsec diagnostic and management scripts in src/opnsense/scripts/ipsec have been rewritten in Python 3 to replace the legacy stroke-based implementation. These scripts now interact with the swanctl daemon via the vici interface to provide status, Security Association Database (SAD), and Security Policy Database (SPD) information, as well as connection control and lease listing. Additionally, the legacy interface reload script has been replaced by a Python script that retrieves the current swanctl configuration, and a new event handler supports dynamic Virtual Tunnel Interface (VTI) and manual SPD configuration based on connection events.

src/opnsense/scripts/ipsec · high confidence

IPsec model validation and configuration schema updates

The IPsec configuration models now enforce stricter validation rules and support new cryptographic options. Key pairs are validated to ensure public and private keys match, and RSA/ECDSA key types are supported. Post-quantum key exchange methods (mlkem) are restricted to IKEv2 connections. Virtual Tunnel Interfaces (VTIs) now require matching protocol families for local/remote and tunnel addresses, and Security Policy Database (SPD) entries must specify either a reqid or a connection child. Remote authentication now supports certificate or authority matching, but not both simultaneously.

src/opnsense/mvc/app/models/OPNsense/IPsec · high confidence

OpenVPN server connections now more reliably determine the tunnel gateway address by falling back to parsing interface details when standard variables are unavailable, ensuring correct routing setup. The link-up and link-down scripts have been updated to use the ifctl utility for route management and to trigger interface IP updates, while the system no longer flushes the state table or reloads on disconnect, resulting in smoother connection handling.

src/etc/inc/plugins.inc.d/openvpn · high confidence

Improved certificate management with external source support and lazy loading

The Trust model field types now support loading certificates from external configuration directories (e.g., /usr/local/etc/ssl/ext\_sources/) alongside locally managed ones, allowing users to reference certificates not created within OPNsense. Additionally, the Certificate model now supports lazy loading, which skips the parsing of dynamic content during export operations to improve performance, and includes stricter validation for certificate reference IDs to prevent migration issues.

src/opnsense/mvc/app/models/OPNsense/Trust/FieldTypes · high confidence

Interface management pages migrated to MVC and Bootgrid

The Interface configuration pages (Assignments, Bridge, GIF, GRE, LAGG, Loopback, Neighbor, Overview, Settings, Virtual IPs, VLAN, VXLAN, and Wireless) have been rewritten as new MVC view files. These pages now use the Bootgrid UI component to fetch and display data via dedicated API endpoints (e.g., /api/interfaces/assignment/), replacing the previous implementation. This change introduces a consistent, grid-based interface for managing all interface types and their sub-configurations.

src/opnsense/mvc/app/views/OPNsense/Interface · high confidence

Interfaces menu structure migrated to MVC model

The Interfaces section of the web UI menu has been refactored from static XML definitions to a dynamic MVC model. The new Menu.php class now programmatically constructs the menu hierarchy by reading the system configuration, ensuring that interface groups and individual interfaces are listed in the correct order and that wireless status tabs are dynamically generated for WLAN interfaces. This change aligns the Interfaces menu with the broader MVC migration effort, replacing the previous static XML approach with a code-based implementation that handles interface descriptions, group memberships, and ordering logic directly.

src/opnsense/mvc/app/models/OPNsense/Interfaces/Menu · high confidence

Interfaces: Migrate configuration and management to MVC/API controllers

The Interfaces settings page now uses a new MVC/API architecture, replacing the legacy implementation with dedicated controllers for managing interface assignments, bridges, GIFs, GREs, LAGGs, loopbacks, neighbors, VIPs, and VLANs. This change provides a consistent, modern API for all interface types, ensuring proper configuration locking, improved validation, and cleaner separation of concerns for interface management tasks.

src/opnsense/mvc/app/controllers/OPNsense/Interfaces/Api · high confidence

Interfaces: Migrate configuration pages to MVC framework

The Interfaces configuration pages (including Assignment, Bridge, GIF, GRE, LAGG, Loopback, Neighbor, Overview, Settings, Virtual IP, VLAN, VXLAN, and Wireless) have been migrated to the MVC framework. This change replaces the legacy implementation with new controller classes that serve the corresponding UI views and forms, ensuring a consistent and modern interface for managing network interfaces.

src/opnsense/mvc/app/controllers/OPNsense/Interfaces · high confidence

Introduce IPFW-based firewall and traffic shaping configuration templates

The system now generates firewall rules and traffic shaping configurations using the IPFW framework instead of the previous method. This change introduces new template files that define the rc.conf settings, main IPFW ruleset, and address tables. For users, this means the Captive Portal now utilizes IPFW zones for interface-based access control and accounting, while the Traffic Shaper generates specific IPFW rules that support advanced options like DSCP marking, TCP ACK filtering, and interface-specific direction handling. The configuration also ensures that localhost traffic is correctly handled and that unmatched traffic is explicitly blocked.

src/opnsense/service/templates/OPNsense/IPFW · high confidence

Introduce new default configuration and boot scripts

The system now ships with a new default configuration sample (config.xml.sample) that sets the default timezone to Etc/UTC, the DHCP domain to 'internal', and enables Dnsmasq as the default IPv6 provider. A new IPv6 bogons sample file (bogonsv6.sample) is added to define blocked IPv6 ranges. Additionally, the boot sequence is restructured with new rc scripts (rc.bootup, rc.configure\_firmware, etc.) that enforce the default firewall policy before interface configuration to prevent local service exposure during boot.

src/etc · high confidence

Introduce standardized MVC form and layout partials

The layout partials have been replaced with a new set of reusable MVC templates, including base\_form, base\_dialog, base\_apply\_button, base\_bootgrid\_table, and base\_menu\_system. This change standardizes the rendering of configuration forms, dialogs, and navigation menus across the web interface, introducing features such as collapsible form sections, integrated search within dialogs, a centralized apply button with progress feedback, and a consistent grid/table layout for data lists.

_src/opnsense/mvc/app/views/layout\partials · high confidence

Introduction of a custom OpenSSL configuration file for certificate generation

The system now uses a dedicated OpenSSL configuration file (opnsense.cnf) for generating certificates and certificate signing requests (CSRs). This change replaces the previous reliance on default OpenSSL settings or external templates, allowing for consistent, system-defined policies for certificate validity (set to 825 days), key usage, and distinguished name requirements. Users will benefit from standardized certificate generation that aligns with OPNsense's specific security policies, including support for Subject Alternative Names (SANs) and specific key usage extensions like 'IP security IKE intermediate' for server certificates.

src/etc/ssl · high confidence

Intrusion Detection System configuration migrations

This update adds a series of migration scripts for the Intrusion Detection System (IDS) model to handle upgrades between versions. M1\_0\_0 initializes version tracking. M1\_0\_2 disables user-defined rules that use deprecated GeoIP settings and appends a note to their descriptions. M1\_0\_6 migrates legacy file download filters into the new policy system. M1\_0\_7 updates the Emerging Threats (et-open) ruleset configuration for Suricata 5 compatibility by mapping old rulesets to new ones (e.g., current\_events to phishing/exploit\_kit, trojan to coinminer/malware) and removing the deprecated trojan ruleset. M1\_1\_1 clears the deprecated 'ac-bs' Multi-Pattern Matching algorithm. M1\_1\_2 migrates legacy IPS mode settings to the new 'netmap' capture mode.

src/opnsense/mvc/app/models/OPNsense/IDS/Migrations · high confidence

Kea DHCP: Added validation for static routes and pool configurations

The Kea DHCP service now includes specific field validators to ensure configuration integrity. A new KeaClasslessStaticRouteField validates DHCP Option 121 (Classless Static Routes), requiring entries to be valid destination network and router IP pairs. Additionally, KeaStaticRoutesField validates standard static route entries as destination and router IP pairs, while KeaPoolsField enforces that defined IP ranges or subnets are strictly contained within their assigned subnet, preventing invalid pool assignments.

src/opnsense/mvc/app/models/OPNsense/Kea/FieldTypes · high confidence

Local MAC vendor lookup data added

A local OUI (Organizationally Unique Identifier) database file (contrib/ieee/oui.csv) has been added to support MAC address vendor identification. This change replaces the previous external netaddr dependency with a simple, self-contained implementation for mapping MAC prefixes to manufacturer names.

contrib/ieee · high confidence

Local OUI vendor lookup replaces external dependency

The interface library now uses a local implementation to map MAC addresses to vendor names by reading the IEEE OUI CSV file at /usr/local/opnsense/contrib/ieee/oui.csv. This change removes the previous external dependency for MAC vendor mapping, ensuring that vendor identification remains available even if external services are unreachable, and improves reliability by relying on a static local database.

src/opnsense/scripts/interfaces/lib · high confidence

Migrate Gateway Groups and Gateways to MVC API controllers

The Routing module's Gateway Groups and Gateways configuration interfaces have been migrated to the MVC framework. This introduces new API controllers (GroupSettingsController and SettingsController) that handle CRUD operations, search, and reconfiguration for gateway groups and individual gateways. The migration includes specific behavioral improvements: gateway deletion is now prevented if a gateway is bound to an interface, and the search API ensures proper data types are emitted when configuration daemon actions fail, addressing previous inconsistencies and potential errors.

src/opnsense/mvc/app/controllers/OPNsense/Routing/Api · high confidence

Migrate Gateway and Gateway Groups configuration to MVC

The Routing module's configuration interfaces for Gateways and Gateway Groups have been migrated to the MVC framework. This introduces new controllers (ConfigurationController and GatewayGroupsController) that serve the settings pages, utilizing MVC-specific form definitions and grid components to manage gateway and gateway group configurations.

src/opnsense/mvc/app/controllers/OPNsense/Routing · high confidence

Migrate OpenVPN Client Specific Overrides to MVC

The OpenVPN Client Specific Overrides configuration has been migrated to the MVC/API architecture, resolving issues with the previous redirect-gateway implementation and improving the handling of client authentication overrides. This change ensures that overrides are correctly saved on client connect and cleaned up on disconnect, eliminating the need to flush all overrides when a server or client configuration changes.

src/etc/inc/plugins.inc.d · high confidence

Migrate User and Group management to the new MVC model layer

The User and Group configuration models have been rewritten to use the new MVC framework, introducing dedicated model classes (User, Group, Priv) and XML definitions. This migration adds support for new user attributes including API keys, landing page preferences, and menu favorites, while enforcing stricter validation such as preventing the root user's name from being changed and requiring passwords for new accounts. Group management now includes a new 'Source Networks' field to constrain endpoint access based on the user's source address.

src/opnsense/mvc/app/models/OPNsense/Auth · high confidence

Migrate User, Group, and Privilege management to MVC controllers

The User, Group, and Privilege management interfaces in the Authentication section have been migrated to the MVC framework. New controllers (UserController, GroupController, PrivController) now handle these pages, loading their respective forms and grids via the API. The User controller also includes specific JavaScript and CSS assets for QR code generation and date picking, indicating enhanced functionality for user profile management.

src/opnsense/mvc/app/controllers/OPNsense/Auth · high confidence

Migrate Users, Groups, and Privileges to MVC/API with enhanced grid features

The Users, Groups, and Privileges management pages have been migrated to a new MVC/API architecture, replacing the previous implementation with modern Bootgrid-based interfaces. This change introduces several user-facing improvements: the Users grid now supports direct export/import of user data, displays approximate expiration status for accounts, and includes new command buttons to search for associated certificates and generate/download API keys for individual users. The Privileges page has been simplified by removing the ability to add or delete privileges directly from the grid view. Additionally, styling conflicts have been resolved and URL hash handling in links has been fixed to ensure correct menu navigation after redirection.

src/opnsense/mvc/app/views/OPNsense/Auth · high confidence

Migrate core system pages to the MVC architecture

The core system interface pages—including Dashboard, Services, Firmware, License, Reboot, Halt, Snapshots, Tunables, Initial Setup, and High Availability (Hasync)—have been ported from the legacy codebase to the new Model-View-Controller (MVC) structure. This change modernizes the underlying framework for these administrative functions, ensuring consistent routing and view handling across the system's foundational settings and maintenance tools.

src/opnsense/mvc/app/controllers/OPNsense/Core · high confidence

Migrate gateway and gateway group configuration to MVC models

The gateway and gateway group configuration logic has been migrated to the MVC framework. New model files (GatewayGroups.php, Gateways.php, and their XML definitions) now handle validation, data storage, and configuration management for these components. This change introduces stricter validation rules, such as preventing name changes on existing gateways and groups, ensuring unique monitor IPs, and enforcing that gateway group tiers contain at least one member. It also standardizes the configuration structure by replacing individual tier fields with a unified 'tiers' array in the data model.

src/opnsense/mvc/app/models/OPNsense/Routing · high confidence

Migrate gateway and gateway group field types to MVC

The gateway and gateway group configuration fields have been migrated to the MVC model layer. This introduces new field types (GatewayField and GatewayGroupItemField) that handle data storage and validation, including setting a default data length of 1 byte for single gateways to prevent potential packet drops and managing tiered gateway group assignments.

src/opnsense/mvc/app/models/OPNsense/Routing/FieldTypes · high confidence

Migrate gateway configuration to the new MVC model

The system now migrates existing gateway settings from the legacy configuration structure into the new MVC-based model. This process converts legacy 'dynamic' gateway values to empty strings, normalizes implied boolean flags (such as default gateway, disabled, and force\_down) into explicit '1' or '0' values, and applies default values for priority, IP protocol, and weight if they are missing. The migration also ensures that time periods for gateway monitoring are adjusted if they were previously set too low, and it logs any validation errors that cause a gateway to be skipped during the transition.

src/opnsense/mvc/app/models/OPNsense/Routing/Migrations · high confidence

Migrate interface configuration models to MVC framework

The interface configuration models for Bridge, GIF, GRE, LAGG, Loopback, Neighbor, Network Interface, Settings, and Virtual IPs have been converted to the MVC framework. This change introduces new model classes and XML definitions that replace the legacy configuration handling, providing structured validation for settings such as bridge spanning-tree parameters, tunnel address family consistency, LAGG member uniqueness, and Virtual IP subnet constraints.

src/opnsense/mvc/app/models/OPNsense/Interfaces · high confidence

Migrate legacy DHCP relay configurations to the new unified model

The system now automatically migrates existing DHCP relay settings from the legacy configuration nodes (dhcrelay for IPv4 and dhcrelay6 for IPv6) into the new unified DHCRelay model structure. This process converts the previous flat interface and server settings into structured relay and destination entries, ensuring that your existing IPv4 and IPv6 relay rules are preserved and functional under the new architecture, after which the old configuration nodes are removed.

src/opnsense/mvc/app/models/OPNsense/DHCRelay/Migrations · high confidence

Migrate legacy firewall configuration to MVC models

This update introduces a series of migration scripts (M1\_0\_0 through MFP1\_0\_9) that automatically convert legacy firewall settings into the new Model-View-Controller (MVC) structure. Users will see their existing firewall aliases, NAT rules (including NPTv6 and one-to-one NAT), filter rules, and scrub options automatically migrated to the new system. The migration handles data normalization, such as converting legacy port ranges and address formats, and ensures that legacy configuration nodes are cleaned up after the transfer to prevent conflicts.

src/opnsense/mvc/app/models/OPNsense/Firewall/Migrations · high confidence

Migrate legacy system and wireless interface settings to new MVC models

This change introduces migration scripts that move configuration data from the legacy system-level settings (such as DHCPv6 debug, no-release, checksum offloading, and IPv6 settings) and legacy wireless interface configurations into the new MVC-based models. For system settings, existing values are transferred to the new model structure with appropriate defaults applied, and the old system-level keys are removed from the configuration. For wireless interfaces, legacy wireless properties (including WEP/WPA keys, IEEE 802.1x settings, and mode flags like pureg/puren/turbo) are migrated into the new clone-based model structure, ensuring that only one clone per interface is marked as the primary (use\_common) while others are secondary, and the old wireless configuration nodes are cleaned up.

src/opnsense/mvc/app/models/OPNsense/Interfaces/Migrations · high confidence

Migrate package repository configuration to OPNsense.conf and introduce shadow files

The package manager configuration has been migrated from the legacy origin.conf file to a new OPNsense.conf structure. To support future compatibility with pkg 1.20 and allow for selective repository enabling, shadow configuration files (FreeBSD.conf.shadow, OPNsense.conf.shadow.in, and OPNsense-aux.conf.shadow.in) have been introduced. These shadow files define the default state of repositories, such as disabling FreeBSD-base and ports by default and setting the OPNsense-aux repository to disabled unless explicitly checked, ensuring a smoother transition and better control over which package sources are active.

src/etc/pkg/repos · high confidence

Migration to new MVC framework with updated routing and error handling

The web interface has been migrated from the legacy Phalcon application to a new MVC framework, introducing new entry points at /ui/ and /api/. This change updates how requests are routed, including a fallback to the core index page for unroutable UI requests and specific handling for legacy password management URLs. Error handling has been restructured: API errors now return structured JSON responses with HTTP status codes, while unhandled UI exceptions redirect users to a crash reporter page. Additionally, static assets are now served with cache-busting hashes based on file modification times to ensure proper caching behavior.

src/opnsense/www · high confidence

Migration to syslog-ng and unified logging infrastructure

The system logging backend has been migrated from the legacy syslogd to syslog-ng, introducing a more robust and flexible logging architecture. This change includes the removal of the previous syslogd workaround, the consolidation of core syslog facilities into the core plugin, and the addition of TLS transport options for remote logging targets. Users will benefit from improved reliability in log forwarding, better handling of remote syslog configurations, and a unified logging flow that reduces spurious errors and simplifies debugging across the system.

src/etc/inc · high confidence

Migration to syslog-ng with TLS support and local log management

The system logging infrastructure has been replaced with syslog-ng, introducing new configuration templates for managing log destinations and local storage. Users can now configure remote logging targets with TLS transport (supporting both IPv4 and IPv6) and RFC5424 compliance, including automatic handling of CA/CRL directories and certificate files. Local logging is now managed via a new newsyslog configuration and specific syslog-ng destination files, ensuring proper log rotation and file creation. Additionally, the system includes dedicated handlers for lockout events and configuration change events, routing them to specific scripts or destinations for enhanced monitoring and security auditing.

src/opnsense/service/templates/OPNsense/Syslog · high confidence

Monit configuration migration and service path updates

The Monit model migration scripts have been updated to handle configuration changes during upgrades. M1\_0\_0 initializes default system and filesystem services with associated resource tests (CPU, memory, load average, etc.) and inherits SMTP settings from the system notifications. Subsequent migrations (M1\_0\_6, M1\_0\_7) add default tests for program status changes and gateway alerts, linking them to new custom services (carp\_status\_change, gateway\_alert). M1\_0\_8 ensures test types are correctly assigned based on conditions. Finally, M1\_0\_14 updates the file paths for the carp\_status and gateway\_alert scripts to reflect their new location under /usr/local/opnsense/scripts/monit/.

src/opnsense/mvc/app/models/OPNsense/Monit/Migrations · high confidence

NTP status page now displays GPS data and uses AJAX-driven table

The NTP status view has been refactored to use an MVC-based Volt template that loads the NTP peer table via AJAX from the API, replacing the previous static rendering. This change introduces a new GPS Information section that displays latitude, longitude, altitude, and satellite usage details when available, including a link to view the location on Google Maps. The table headers and status/type columns now include tooltips for additional context, improving the clarity of the NTP synchronization status for users.

src/opnsense/mvc/app/views/OPNsense/Ntpd · high confidence

Native OPNsense validators replace Phalcon dependencies

The validation layer in the MVC models has been decoupled from the Phalcon framework by introducing a set of native validators in the OPNsense\\Base\\Validators namespace. This change replaces Phalcon's built-in validators (PresenceOf, Url, Regex, Numericality) and adds a new CallbackValidator, allowing configuration validation to function independently of the underlying Phalcon version. Users benefit from a more stable validation foundation that is no longer tied to specific Phalcon API changes, ensuring consistent behavior across framework upgrades.

src/opnsense/mvc/app/models/OPNsense/Base/Validators · high confidence

New Cron job management interface with inline editing and reconfiguration

The Cron settings view has been replaced with a new Volt template that provides a grid-based interface for managing scheduled jobs. Users can now edit individual jobs via an inline dialog that automatically triggers a cron reconfiguration upon saving, ensuring changes are applied immediately. The interface also includes a dedicated 'Apply' button for batch changes and utilizes a standardized bootgrid table for job listing.

src/opnsense/mvc/app/views/OPNsense/Cron · high confidence

New GeoIP configuration and alias table generation templates

The firewall service now uses dedicated Jinja2 templates to generate its configuration files. A new \filter\_geoip.conf\ template manages the GeoIP data source URL, supporting custom URLs, or automatically falling back to the Deciso mirror for business edition subscribers. Additionally, a new \filter\_tables.conf\ template generates the firewall alias table definitions, handling various alias types (URL, JSON, dynamic IPv6, MAC, etc.) with specific TTLs and interface mappings, and includes a new \+TARGETS\ file to ensure these configuration files are properly deployed.

src/opnsense/service/templates/OPNsense/Filter · high confidence

New MVC base controller classes for API and UI rendering

The \src/opnsense/mvc/app/controllers/OPNsense/Base\ directory now contains the foundational classes for the new MVC framework, replacing the legacy implementation. \ControllerRoot\ handles core authentication, session management, and language localization. \ControllerBase\ manages the UI rendering pipeline, including the Volt template engine and standard JavaScript/CSS includes. \ApiControllerBase\ provides the base for API endpoints, featuring a robust \searchRecordsetBase\ method for recordset searching, sorting, and pagination, as well as CSV export capabilities. \ApiMutableModelControllerBase\ and \ApiMutableServiceControllerBase\ offer reusable logic for managing configuration models and service lifecycle actions (start/stop/restart), while new exception classes (\UserException\, \UserWarningException\, etc.) standardize error handling and HTTP status reporting.

src/opnsense/mvc/app/controllers/OPNsense/Base · high confidence

New MVC controllers for Traffic Shaper UI and statistics

The Traffic Shaper interface now uses new MVC controllers (IndexController and ServiceController) to serve the main configuration page and statistics. The IndexController loads form definitions for pipes, queues, and rules, while the ServiceController provides a statistics action, replacing the previous legacy PHP-based page structure with a modern API-enabled frontend.

src/opnsense/mvc/app/controllers/OPNsense/TrafficShaper · high confidence

New MVC exception hierarchy for dispatch errors

The MVC layer now includes a dedicated set of exception classes under the \OPNsense\\Mvc\\Exceptions\ namespace to handle dispatch-related issues. A new base \DispatchException\ class has been introduced, with specific subclasses added for \ClassNotFoundException\, \InvalidUriException\, \MethodNotFoundException\, and \ParameterMismatchException\. This structure allows for more precise error handling and reporting when specific dispatch conditions are encountered.

src/opnsense/mvc/app/library/OPNsense/Mvc/Exceptions · high confidence

New MVC menu system with caching and graceful error handling

The navigation menu is now generated by a new MVC-based system that collects XML definitions from module directories, merges them into a cached file, and serves them to the UI. This change improves performance through caching and ensures the interface remains stable by logging errors for malformed menu XML files instead of crashing the application.

src/opnsense/mvc/app/models/OPNsense/Base/Menu · high confidence

New MVC views for core system pages

The Configuration History, Dashboard, Defaults, Firmware, Halt, High Availability (sync and status), Initial Setup, License, 404, Reboot, and Services pages have been migrated to the MVC view layer. This migration introduces a modernized user interface with improved responsiveness, dynamic widget management on the dashboard, and consistent styling across core system administration areas.

src/opnsense/mvc/app/views/OPNsense/Core · high confidence

New Monit status and configuration views

The Monit service now features new MVC-based views for the status page and general configuration. The status page dynamically loads HTML content via an API call to display real-time monitoring information, while the configuration interface provides a tabbed layout for managing general settings, alerts, services, and service tests with dynamic field visibility based on service types.

src/opnsense/mvc/app/views/OPNsense/Monit · high confidence

New PAM-based authentication and shell timeout configuration

The system now uses PAM (Pluggable Authentication Modules) for SSH and local console login, integrating the custom pam\_opnsense.so module alongside standard unix authentication to support local account locking. Additionally, a new csh configuration allows administrators to set a system-wide autologout timeout for csh/tcsh sessions, and the Message of the Day (MOTD) has been updated with a new logo and links to the Reddit community.

src/opnsense/service/templates/OPNsense/Auth · high confidence

New Python-based NetFlow log parser and aggregation library

The NetFlow processing pipeline in src/opnsense/scripts/netflow/lib has been replaced with a new pure-Python implementation. This change introduces a new flow parser (flowparser.py) that reads binary flowd logs, handles struct unpacking errors gracefully, and maps interface indexes to names. It also adds an aggregation layer (aggregate.py) that stores processed data in SQLite with UTC timestamps and metadata tracking. This new library serves as the backend for the flowd aggregator, improving reliability and performance over the previous implementation.

src/opnsense/scripts/netflow/lib · high confidence

New UIModelGrid helper and XSS-safe ViewTranslator

The MVC base library now includes a new UIModelGrid helper class that simplifies grid data fetching by retrieving descriptive values directly from the model and supporting multi-clause search phrases, and a new ViewTranslator class that wraps Phalcon's Gettext adapter to ensure all translated strings are automatically HTML-safe, preventing XSS vulnerabilities in the UI.

src/opnsense/mvc/app/library/OPNsense/Base · high confidence

New boot loader branding and logo assets for OPNsense

The boot loader now includes dedicated Lua scripts to render the OPNsense brand identity and a themed hourglass logo during startup. Specifically, \brand-opnsense.lua\ registers the OPNsense ASCII art logo with the boot drawer, while \logo-hourglass.lua.in\ defines a colored hourglass graphic (with series text substitution) to replace the previous default visuals, aligning the boot-time appearance with the 15.x release branding.

src/root · high confidence

New boot-time service hooks for interface, system, and VPN configuration

The system now executes a series of new startup hooks in /etc/rc.syshook.d/start to standardize post-boot configuration. These hooks ensure that IPv4 and IPv6 interfaces are reconfigured if pending changes exist, restart syslog to apply dynamic addressing, re-apply sysctl tunables after module loading, restart cron, configure OpenVPN instances, and set CARP preempt settings. This change centralizes these tasks using configctl and pluginctl, improving reliability for static setups and dynamic backend scripts.

src/etc/rc.syshook.d/start · high confidence

New end-of-life upgrade guidance in the web GUI

A new upgrade page (upgrade.html.in) has been added to the firmware data directory to guide users when their current OPNsense series has reached end-of-life. The page explains that upgrading to the next series is seamless via the web GUI, while also offering alternative methods such as importing configuration with a new installation image (supporting ZFS or UFS) or performing a console/SSH upgrade via option 12. It advises users to review migration notes, back up their configuration, preview the new version, and create VM or ZFS snapshots before proceeding.

src/opnsense/data/firmware · high confidence

New stop hooks for beep, FreeBSD services, and config locking

The system now executes specific actions when stopping services: it triggers the OPNsense beep utility, stops FreeBSD local services via the rc.freebsd script, and ensures exclusive locking on the configuration file (/conf/config.xml) during the stop phase to prevent concurrent modifications.

src/etc/rc.syshook.d/stop · high confidence

OpenVPN Client Specific Overrides migrate to MVC model

The OpenVPN Client Specific Overrides (CSO) configuration has been migrated from the legacy XML config structure to the new MVC model. Existing CSO settings are automatically imported into the new model during the upgrade process, and the old configuration entries are removed after the migration completes, ensuring a seamless transition for users managing per-client VPN overrides.

src/opnsense/mvc/app/models/OPNsense/OpenVPN/Migrations · high confidence

OpenVPN MVC field types for instances, servers, and validation

The OpenVPN configuration model now uses dedicated MVC field types to handle instance references, server selection, and input validation. The InstanceField automatically generates virtual properties for runtime files (such as config, PID, and socket paths) based on the instance UUID, while the OpenVPNServerField provides a unified, cached dropdown of available OpenVPN servers (both legacy and MVC-managed) for selection. Additionally, the RemoteHostField now validates comma-separated host:port entries to ensure valid hostnames or IPs and ports within the 1-65535 range, and the VPNIdField ensures unique VPN IDs by checking against legacy reserved IDs and auto-assigning the next available ID if none is provided.

src/opnsense/mvc/app/models/OPNsense/OpenVPN/FieldTypes · high confidence

OpenVPN MVC model migration and export configuration support

The OpenVPN configuration models have been migrated to the MVC framework, introducing new model classes (Export.php, OpenVPN.php) and XML definitions (Export.xml, OpenVPN.xml) to manage server instances, client-specific overrides, and export presets. This change adds validation logic for server directives (enforcing /29 or smaller subnets unless using p2p topology), client authentication requirements, and keepalive timing constraints. It also introduces new configuration options including DCO (Data Channel Offload) support for UDP, optional OCSP checks, route-metric pushing, and specific export features like auth-nocache, static challenge (OTP), and cryptoapi certificate loading.

src/opnsense/mvc/app/models/OPNsense/OpenVPN · high confidence

OpenVPN authentication and session management refactored to new scripts

The OpenVPN backend in src/opnsense/scripts/openvpn has been replaced with a new set of dedicated scripts to handle the full client lifecycle. Authentication is now managed by user\_pass\_verify.php, which supports deferred auth, static-challenge PIN/password handling, and group membership validation. Certificate verification is handled by tls\_verify.php, which enforces certificate depth limits and optional OCSP checks. Client connection and disconnection are now processed by client\_connect.php (which generates Client Specific Overrides) and client\_disconnect.sh (which flushes pf state). Service control, interface setup, and CARP status tracking are centralized in ovpn\_service\_control.php, while ovpn\_status.py and kill\_session.py provide modern JSON-based status reporting and session termination. A new ovpn\_event.py dispatcher routes OpenVPN events to these handlers, and genkey.py supports TLS-crypt-v2 key generation.

src/opnsense/scripts/openvpn · high confidence

OpenVPN management interface migrated to MVC

The OpenVPN administration views (Client Specific Overrides, Instances, Status, and Client Export) have been rewritten to use the MVC framework. This migration introduces a consistent UI architecture across all OpenVPN management pages, utilizing the base\_bootgrid\_table component for data grids and standardizing dialog handling. Users will see a unified interface for managing OpenVPN instances, viewing connection status, configuring client-specific overrides, and exporting client certificates, with improved responsiveness and consistent styling.

src/opnsense/mvc/app/views/OPNsense/OpenVPN · high confidence

OpenVPN management migrated to the MVC framework

The OpenVPN administration interface has been rebuilt using the MVC architecture, replacing the legacy implementation. This change introduces new API controllers for managing Client Specific Overrides, OpenVPN Instances (including static key generation), and the Client Export process, alongside a refactored Connection Status view. Users will experience improved consistency across the OpenVPN settings pages, better handling of server and client session data, and a more robust foundation for future feature additions.

src/opnsense/mvc/app/controllers/OPNsense/OpenVPN/Api · high confidence

Package installation now configures system hooks and root shell

The OPNsense package now automatically registers the custom 'opnsense-shell' and 'opnsense-installer' shells in /etc/shells and sets the root user's default shell to opnsense-shell. It also injects hooks into /etc/rc and /etc/rc.shutdown to ensure the local rc(8) scripts are executed during boot and shutdown, and starts the configd service. On uninstall, the root shell is reverted to /bin/csh and the hooks are removed.

(repo-wide) · high confidence

Pluggable firmware repository scripts with subscription and auxiliary support

The firmware update mechanism now uses a pluggable script system located in src/opnsense/scripts/firmware/repos, allowing repository logic to be provided by plugins. The new OPNsense.php script handles repository configuration by supporting business mirror subscriptions (appending a subscription path to the mirror URL), selecting the appropriate firmware flavour, and enabling auxiliary repositories via the -E flag when configured. It also automatically clears the core license file if no subscription key is set, ensuring that non-subscribed users do not retain stale license data.

src/opnsense/scripts/firmware/repos · high confidence

Radvd settings and service management migrated to MVC/API controllers

The Radvd (Router Advertisement) configuration interface has been updated to use the modern MVC/API architecture. This change introduces new API controllers for managing Radvd settings and service actions, allowing users to configure router advertisements and trigger service reconfigurations through the standardized API endpoints rather than legacy mechanisms.

src/opnsense/mvc/app/controllers/OPNsense/Radvd/Api · high confidence

Radvd settings page migrated to MVC/API architecture

The Radvd (Router Advertisement) configuration interface has been refactored to use the modern MVC and API framework. The previous implementation has been replaced with a new SettingsController and Volt view that drive the UI via JSON API endpoints (e.g., /api/radvd/settings/), enabling dynamic table loading and form dialogs without full page reloads.

src/opnsense/mvc/app/controllers/OPNsense/Radvd, src/opnsense/mvc/app/views/OPNsense/Radvd · high confidence

Redesign of dashboard widgets, modals, and data tables

The Opnsense theme has been updated to improve the visual consistency and usability of the user interface. The dashboard now features a refreshed layout for widgets, including better alignment for headers and controls, along with specific styling adjustments to ensure ChartJS v4 graphs render correctly. Modal dialogs (bootstrap-dialog) have been restyled with distinct header colors for different alert types (info, success, warning, danger) and improved icon animations. Additionally, the data grid component has been replaced with Tabulator, which introduces a new table theme with custom row highlighting, pagination styling, and support for grouped data views.

src/opnsense/www/themes/opnsense/assets/stylesheets · high confidence

Refactor NTP status page to use MVC architecture

The NTP status page has been refactored to follow the MVC pattern, replacing the previous implementation with dedicated controllers. A new ServiceController provides API endpoints for fetching NTP server status and GPS data, along with metadata definitions for server attributes and connection symbols to support the UI. A new StatusController handles the page rendering by picking the appropriate view template. This change streamlines the backend logic and aligns the NTP status display with the rest of the UI framework.

src/opnsense/mvc/app/controllers/OPNsense/Ntpd · high confidence

Refactored NTP status script to use Shell class and parse GPS data

The ntpd status script has been refactored to use the Shell class for safer command execution and to properly handle newlines in ntpq output. It now parses GPS NMEA sentences (GPRMC, GPGGA, GPGLL) to provide detailed location and satellite information, including support for SureGPS boards via GSV message parsing.

src/opnsense/scripts/ntpd · high confidence

Refactored RRD data collection types to use a new Base class and Shell integration

The RRD data collection library has been refactored to replace the previous base class with a new \OPNsense\\RRD\\Types\\Base\ class that utilizes the \Shell\ class for executing \rrdtool\ commands. This change introduces a standardized structure for system metrics, including Gateway Quality, Mbuf, Memory, NTP, OpenVPN, Packets, Processor, States, Temperature, Traffic, and Wireless types. Each type now explicitly defines its datasets (e.g., memory active/inactive/free, packet pass/block counts) and Round Robin Archive (RRA) configurations, ensuring consistent data collection and storage for system health monitoring.

src/opnsense/scripts/health/library/OPNsense/RRD/Types · high confidence

Refactored RRD statistics collection with new modular collectors

The RRD reporting infrastructure has been replaced with a new modular architecture in the \OPNsense\\RRD\ namespace. A new \Factory\ class now dynamically discovers and executes statistics collectors located in the \Stats\ directory, while a \Base\ class provides shared utilities for shell commands and system metadata. This change introduces specific new collectors for Gateway Quality, Interfaces, Mbufs, Memory (including ZFS ARC and laundry mapping), NTP, OpenVPN, Processor, States, and Temperature, replacing the previous implementation to improve maintainability and data accuracy.

src/opnsense/scripts/health/library/OPNsense/RRD/Stats · high confidence

Refactored Tunables settings to use MVC model with lazy loading

The System Settings: Tunables page has been refactored to use a new MVC-based model (TunableField) that replaces the previous implementation. This change introduces lazy loading for tunable data, meaning system sysctl values are only fetched when the settings page is actually accessed, rather than at every model load. The model consolidates tunable handling by merging static defaults and current runtime values, and it deprecates the use of the literal string 'default' for unset values in favor of empty strings. This improves performance and aligns the tunables configuration with the broader MVC migration effort.

src/opnsense/mvc/app/models/OPNsense/Core/FieldTypes · high confidence

Refactored boot-time initialization into modular rc.subr.d scripts

The system's boot sequence has been reorganized by moving specific initialization tasks into dedicated scripts under src/etc/rc.subr.d. This change introduces new modules for crash dump handling (crashdump), live mode installer setup (livemode), PHP environment configuration (php), swap management (swapon), and temporary/variable directory management (tmp, var). Users will see more structured handling of boot-time resources, including improved crash dump device configuration, explicit PHP session and cache directory setup with correct ownership, and configurable memory-disk (tmpfs) sizing for /tmp and /var/log based on system memory limits.

src/etc/rc.subr.d · high confidence

Refactored firewall alias resolution with new parsers and async DNS

The alias resolution engine in the firewall filter scripts has been refactored into a modular library under src/opnsense/scripts/filter/lib/alias. This change introduces a new base parser architecture and specific parsers for handling various alias types, including GeoIP, BGP ASN, interface addresses, ARP cache, and authentication groups (such as OpenVPN user groups). A key behavioral improvement is the integration of an asynchronous DNS resolver, which significantly speeds up the resolution of hostnames in URL and standard aliases by batching requests. The update also adds support for parsing JSON payloads from URLs using jq, allows custom HTTP authorization headers for URL-based aliases, and improves the reliability of alias updates by preventing unnecessary disk writes and handling edge cases like time drift and missing database files.

src/opnsense/scripts/filter/lib/alias · high confidence

Refactored system status mechanism with persistent, scoped notifications

The system status collection logic has been replaced with a new architecture that supports persistent notifications and page-specific scoping. The new \AbstractStatus\ base class allows individual status checks to define whether they are banners, their priority, and which UI pages (scopes) they apply to, while \SystemStatus\ now dynamically loads and filters these checks based on the current context. This change ensures that status messages are only displayed where relevant and can persist across page loads if configured, improving the clarity and relevance of system alerts in the UI.

src/opnsense/mvc/app/library/OPNsense/System · high confidence

Removal of legacy boot configuration and device hint files

The system no longer includes the \device.hints\_wrap\ and \loader.conf\_wrap\ files, which previously provided static configuration for legacy hardware (such as ISA devices, floppy controllers, and specific ATA settings) and boot loader behavior (including console output, autoboot delays, and memory limits). Users relying on these specific hardcoded hints or loader settings will need to adjust their boot configuration through other means, as these defaults have been removed.

boot · high confidence

Removal of root shell configuration files

The root user's shell initialization files (.profile, .shrc, and .tcshrc) have been removed from the system. This change eliminates the previous behavior where interactive logins (via SSH or specific terminal types) would automatically execute /etc/rc.initial, and it removes the custom tcsh prompt, color settings, and key bindings that were previously applied to the root shell environment.

root · high confidence

Replace Phalcon MVC framework with custom OPNsense implementation

The internal MVC framework has been replaced with a custom implementation (Controller, Dispatcher, Router, Request, Response, Session, Security, Headers) to remove the Phalcon dependency. This change introduces a new routing system that normalizes path slashes and supports case-insensitive namespace resolution for backwards compatibility, while the Dispatcher now uses reflection to validate controller actions and parameters before execution. The Request class provides unified access to query, post, and raw body data, and the Response class handles JSON encoding with UTF-8 error protection and stream output cleansing. Session handling has been updated to clone data on construction to prevent locking issues, and Security now safeguards CSRF token checks against missing POST items.

src/opnsense/mvc/app/library/OPNsense/Mvc · high confidence

Replace Phalcon configuration with custom AppConfig class

The application configuration system has been refactored to remove the dependency on Phalcon's built-in configuration components. A new custom \AppConfig\ class now manages application settings, providing methods to merge configuration data and update specific properties via dot notation. The \config.php\ file now instantiates this new class with standard paths for controllers, models, views, and libraries, while \loader.php\ utilizes this configuration to register the custom autoloader.

src/opnsense/mvc/app/config · high confidence

Replaced Phalcon autoloader with a custom OPNsense implementation

The system's class loading mechanism has been updated to use a new, simplified custom autoloader located in src/opnsense/mvc/app/library/OPNsense/Autoload/Loader.php, replacing the previous Phalcon-based autoloader. This change modifies how PHP classes are discovered and loaded at runtime by iterating through configured probe directories, which may impact application startup behavior and dependency resolution within the MVC framework.

src/opnsense/mvc/app/library/OPNsense/Autoload · high confidence

Restructure early boot hooks and introduce CARP maintenance mode support

The early boot initialization sequence has been reorganized into dedicated scripts within the new rc.syshook.d/early layout. The upgrade process (05-upgrade) now explicitly handles kernel, bootloader, and package stages with immediate reboots if needed. Configuration daemon startup (10-configd) and template generation (15-templates) are separated into their own steps. A new CARP hook (90-carp) has been added to support maintenance mode: if the configuration specifies virtualip\_carp\_maintenancemode, the system forces CARP demotion to prevent premature master switching, and triggers a service status event to ensure proper state synchronization.

src/etc/rc.syshook.d/early · high confidence

Restructured High Availability XML-RPC sync and service management

The High Availability XML-RPC backend has been reorganized into modular include files (legacy.inc, service.inc, test.inc) to improve maintainability and fix synchronization behaviors. The legacy module now handles configuration merging with specific logic to preserve 'nosync' Virtual IPs during HA sync, preventing duplicate records and ensuring local VIP settings are respected. A new service module exposes functions to list, start, stop, and restart services via XML-RPC, while also reloading configuration templates. These changes refine how the secondary node applies configuration updates from the primary, particularly regarding Virtual IP handling and service state synchronization.

src/etc/inc/xmlrpc · high confidence

Restructured PHP configuration and increased memory limits

The WebGUI now uses a centralized php.ini template that increases the default memory limit to 1GB and configures session storage in a dedicated directory (/var/lib/php/sessions). This change also adjusts error reporting behavior based on the deployment mode (showing full errors in production vs. filtered errors otherwise) and sets specific upload and execution time limits to support larger operations.

src/opnsense/service/templates/OPNsense/WebGui · high confidence

Restructured bootloader configuration into modular loader chunks

The system bootloader configuration has been reorganized from a single file into a modular directory structure under /boot/loader.conf.d (exposed here as src/etc/rc.loader.d). This change introduces distinct configuration files for branding (setting the Opnsense logo and menu title), general settings (such as the autoboot delay), critical kernel modules (ensuring essential networking and firewall modules like carp, pf, and various interfaces load early to prevent race conditions), and ZFS requirements. A new banner file also informs users that custom changes should be made via loader.conf.local or the GUI to avoid being overwritten.

src/etc/rc.loader.d · high confidence

Rewritten static routing interface with apply-based configuration

The static routing management page has been rewritten to use a new MVC view structure, replacing the previous implementation. This change introduces a bootgrid-based table for managing routes and integrates a dedicated 'Apply' button that triggers a reconfiguration endpoint (/api/routes/routes/reconfigure) rather than saving changes immediately. The interface now includes specific user guidance warning against entering static routes for networks assigned to local interfaces, ensuring users only configure routes for networks reachable via different routers.

src/opnsense/mvc/app/views/OPNsense/Routes · high confidence

Router Advertisements migrated to MVC/API with new configuration options

The Router Advertisements (Radvd) settings have been migrated from the legacy configuration system to the new MVC/API architecture, introducing a dedicated menu item under Services. This change includes a migration script that automatically transfers existing DHCPv6 router advertisement settings to the new model, ensuring continuity for current users. The new configuration model adds support for NAT64 prefixes (nat64prefix), allows users to control the IPv6 hop limit (AdvCurHopLimit), and introduces options to remove advertisements and routes on exit (RemoveAdvOnExit). Additionally, a new validation field ensures that the source address for router advertisements is a valid IPv6 link-local virtual IP assigned to the selected interface.

src/opnsense/mvc/app/models/OPNsense/Radvd · high confidence

Routing configuration UI migrated to MVC Bootgrid tables

The Gateway and Gateway Groups configuration pages now use a new MVC-based interface powered by UIBootgrid tables. This change replaces the previous implementation with a standardized view structure that includes integrated search, edit, and delete actions via API endpoints (e.g., /api/routing/settings/ and /api/routing/group\_settings/). Users will see a consistent table layout with formatters for gateway status, priority, and group tier details, along with automatic handling of edit dialogs and apply buttons for reconfiguration.

src/opnsense/mvc/app/views/OPNsense/Routing · high confidence

Shaper service rewritten with new startup, synchronization, and statistics scripts

The shaper subsystem in src/opnsense/scripts/shaper has been restructured to improve reliability and performance. A new start.sh script now manages the initialization of dnctl and ipfw services, including a new sync\_fw\_hooks.py utility that ensures correct firewall hook ordering via pfilctl. The setup.sh script now explicitly configures dummynet sysctls (io\_fast, hash\_size) before module load. Additionally, a flush\_all.sh script provides a centralized way to clear ipfw rules, pipes, and queues, while update\_tables handles dynamic IP table management. The legacy rc.reload\_all PHP script has been replaced by dummynet\_stats.py, which collects and outputs current shaper statistics (pipes, queues, scheds, rules) in JSON format for the API.

src/opnsense/scripts/shaper · high confidence

Split sample file handling into distinct @sample and @shadow keywords

The package installation keywords for handling configuration sample files have been split into two distinct behaviors: @sample and @shadow. Previously, a single keyword handled both scenarios, but now @sample preserves user-modified configuration files during uninstall (removing them only if they match the original sample), while @shadow unconditionally removes the generated configuration file upon uninstall. This change allows packagers to explicitly choose whether user customizations should be preserved or cleaned up when the package is removed.

Keywords · high confidence

Standardized service management for Captive Portal, Configd, NetFlow, and Flowd Aggregate

The system now uses dedicated FreeBSD rc.d scripts to manage the lifecycle of key background services. Captive Portal is now controlled via a new rc script that handles zone bootstrapping, SSL certificate generation, and lighttpd instance management. Configd has a new rc script that ensures the Python 3 daemon starts correctly and waits for its socket to become available. NetFlow and Flowd Aggregate also gain standard rc scripts, allowing users to enable, start, stop, and check the status of NetFlow collection and flow aggregation via standard service commands. This change provides a more robust and consistent way to manage these services during system boot and shutdown.

src/etc/rc.d · high confidence

Static routes now enforce protocol matching between network and gateway

The static routes configuration now validates that the IP protocol of the selected gateway matches the network's protocol (IPv4 vs IPv6). The model enforces this by checking the gateway's IP family against the network's family, preventing mismatches such as assigning an IPv4 gateway to an IPv6 network. An exception is included to allow RFC 5549 configurations, where IPv4 traffic is routed to an IPv6 next-hop hardware address. This validation is supported by a migration script that converts existing 'disabled' flags to the new 'enabled' boolean field structure.

src/opnsense/mvc/app/models/OPNsense/Routes · high confidence

Structured local syslog filtering for individual services

The local syslog configuration has been reorganized into dedicated filter files for specific services (such as audit, configd, dhcrelay, firewall, ipsec, kea, openvpn, suricata, and wireguard). This change ensures that logs from each service are captured in their own separate log files rather than mixing into a single general log, which simplifies troubleshooting and log management for these components.

src/opnsense/service/templates/OPNsense/Syslog/local · high confidence

Support for dynamic DNS and manual SPD entries via event hooks

IPsec configuration now supports dynamic DNS scenarios by optionally hooking Virtual Tunnel Interface (VTI) setup to the connection up event. Additionally, the system introduces an event handler for manual Security Policy Database (SPD) entries when a request ID (reqid) is specified, allowing these entries to be linked to their parent connections. This is implemented through a new \reqid\_events.conf\ template that generates configuration for both SPDs and VTIs based on their enabled status and specific attributes like reqid and connection\_child.

src/opnsense/service/templates/OPNsense/IPsec · high confidence

Suricata backend scripts refactored and migrated to Python 3

The Intrusion Detection/Prevention System backend scripts in src/opnsense/scripts/suricata have been rewritten in Python 3 and restructured to use a shared rule cache. This change introduces new scripts for managing alert logs (including the ability to drop specific logs), querying alerts with filters, and listing available rulesets. The rule installation process now generates a YAML manifest of installed files and supports applying configuration changes like enabling/disabling rules or modifying actions directly during installation. Additionally, the rule updater now supports version checking to skip redundant downloads and handles required files more robustly.

src/opnsense/scripts/suricata · high confidence

Suricata configuration templates and rule management infrastructure

The Intrusion Detection System now generates its configuration files from a new set of Jinja2 templates located in the service templates directory. This change introduces structured management for Suricata, including a new \suricata.yaml\ template that supports advanced logging options such as HTTP and TLS inspection, JA4 fingerprinting, and configurable payload logging. It also adds templates for rule policies (\rule-policies.config\), rule updates (\rule-updater.config\), and user-defined rules (\OPNsense.rules\), allowing for granular control over rule actions and bypass settings. Additionally, the system now includes templates for log rotation (\newsyslog.conf\) and service startup (\rc.conf.d\), ensuring that Suricata runs correctly in IDS, IPS (netmap/divert), or pcap modes with appropriate interface bindings and logging behaviors.

src/opnsense/service/templates/OPNsense/IDS · high confidence

Suricata rule management refactored into Python modules

The Intrusion Detection/Prevention System's rule management backend has been rewritten from PHP to Python. This change introduces dedicated Python modules for downloading rules (downloader.py), parsing rule metadata (metadata.py), and managing the rule cache (rulecache.py), replacing the previous PHP-based implementation to improve maintainability and performance.

src/opnsense/scripts/suricata/lib · high confidence

Syslog destination validation and TLS support

The Syslog model now enforces stricter validation for remote logging destinations: it ensures the transport protocol (IPv4 vs IPv6) matches the address family of the specified hostname and requires a certificate when using TLS transports (tls4/tls6). Additionally, the destination configuration schema now includes TLS transport options (TLS(4) and TLS(6)) alongside existing UDP/TCP variants, allowing users to configure encrypted syslog forwarding.

src/opnsense/mvc/app/models/OPNsense/Syslog · high confidence

Syslog logging infrastructure rewritten with new Python-based tools

The syslog handling scripts in src/opnsense/scripts/syslog have been replaced with a new set of Python and PHP utilities. This introduces a new log matching engine (log\_matcher.py) that supports case-insensitive clause matching and time-constrained searches via a valid\_from parameter. A new streaming log handler (streamLog.py) enables real-time log viewing, while a lockout handler (lockout\_handler) now actively blocks IPs after failed SSH or Web GUI attempts. Log management is improved with a new archive script (log\_archive) that enforces maximum file sizes and rotation, and a certificate generation script (generate\_certs.php) now automatically manages TLS certificates for syslog destinations.

src/opnsense/scripts/syslog · high confidence

Syslog settings migration to shared model

A new migration script (M1\_0\_2) has been added to the Syslog module to automatically migrate existing local logging configuration into the new shared model structure. This ensures that current user settings for local logging enablement, maximum file size, and log preservation limits are correctly transferred during the upgrade process.

src/opnsense/mvc/app/models/OPNsense/Syslog/Migrations · high confidence

Syslog settings page restructured with new tabs and reset capability

The Syslog configuration interface has been reorganized into three distinct tabs: Local, Remote, and Statistics. The Local tab now hosts the primary settings form, while the Remote tab utilizes a bootgrid table for managing syslog destinations. A new Statistics tab displays source-level logging metrics in a read-only grid. Additionally, a 'Reset Log Files' button has been added to the Local tab, allowing users to clear all local log data after confirmation, and the remote destination configuration now supports dynamic transport type selection.

src/opnsense/mvc/app/views/OPNsense/Syslog · high confidence

Syslog source configuration updates for kernel and Unbound logs

The syslog source templates have been updated to ensure proper log collection for specific services. A new local source configuration now captures kernel messages from /dev/klog and includes the required syslog-protocol flags for Unix domain sockets to resolve RFC5424 compatibility issues on FreeBSD 12. Additionally, a new source definition for Unbound has been added to capture its logs from its specific Unix socket path, also applying the necessary protocol flags.

src/opnsense/service/templates/OPNsense/Syslog/sources · high confidence

System Trust settings now configure OpenSSL providers and protocol constraints

The System: Trust settings page now allows users to configure OpenSSL behavior directly via the new \openssl.cnf\ template. This includes enabling the legacy provider by default to support older cryptographic algorithms, and applying user-defined constraints such as minimum protocol versions, cipher suites, signature algorithms, and groups. These settings are flushed to both \/usr/local/openssl/openssl.cnf\ and \/etc/ssl/openssl.cnf\ to ensure system-wide consistency.

src/opnsense/service/templates/OPNsense/Trust · high confidence

System status checks migrated to persistent, scoped banner notifications

The system status mechanism has been refactored to use a new persistent notification framework, replacing the previous ad-hoc notices. This change introduces a suite of dedicated status classes (e.g., CaptivePortalStatus, DiskSpaceStatus, various OverrideStatus classes) that display targeted warnings or notices as persistent banners on specific UI pages. Users will now see immediate, context-aware alerts for issues such as configuration overrides in services like Unbound, IPsec, and IDS, as well as system-level conditions like live media mode, disk space thresholds, and booting states, ensuring these critical details are visible without requiring navigation to separate status pages.

src/opnsense/mvc/app/library/OPNsense/System/Status · high confidence

Traffic shaper configuration moved to the dnctl service

The system now manages traffic shaping rules via the dedicated dnctl service instead of the previous method. This change introduces a new configuration file (dnctl.conf) that generates dummynet pipe and queue definitions, including support for IPv6 masks (/128) and CIDR notation, and ensures the dnctl service starts before pf. Users will notice that shaper settings are now applied through this new service infrastructure.

src/opnsense/service/templates/OPNsense/Shaper · high confidence

UI theme overhaul with new dialog, dashboard, and table styling

The Opnsense theme CSS has been updated to improve the visual consistency and usability of the interface. New styles have been added for modal dialogs (bootstrap-dialog.css) to support distinct header colors for different alert types and icon spinners. The dashboard layout (dashboard.css) now features refined widget styling, including improved spacing, alignment, and ChartJS canvas handling. Table rendering has been significantly enhanced (opnsense-bootgrid.css) by introducing comprehensive theming for the Tabulator library, replacing the previous bootgrid styles with a cleaner look for headers, rows, and pagination. Additionally, tokenized input fields (tokenize2.css) have been restyled to match the new theme, ensuring consistent appearance for multi-select inputs.

src/opnsense/www/themes/opnsense/build/css · high confidence

Unbound DNS API controllers migrated to MVC

The Unbound DNS service API has been migrated to the MVC architecture, introducing new controllers for diagnostics, overview, service management, and settings. This change provides dedicated API endpoints for retrieving Unbound statistics and cache dumps, viewing query statistics and blocklist categories, managing DNS-over-TLS forwarders, and handling blocklist updates and host overrides, replacing the previous legacy implementation.

src/opnsense/mvc/app/controllers/OPNsense/Unbound/Api · high confidence

Unbound DNS configuration migration to new MVC model

The Unbound DNS service configuration is migrated from legacy XML nodes to the new MVC model structure. This process consolidates settings from various legacy locations—including the 'unboundplus' plugin, 'unbound' service, and 'ExtendedDnsbl' plugin—into the unified OPNsense Unbound model. Specific changes include moving domain overrides to Query Forwarding, converting host records to support RR types (A, AAAA, MX), migrating ACLs with network-based actions, merging extended blocklists into the core DNSBL system, and normalizing advanced settings like cache sizes and interface selections. Legacy configuration nodes are cleaned up after the migration to ensure a clean state.

src/opnsense/mvc/app/models/OPNsense/Unbound/Migrations · high confidence

Unbound DNS configuration templates restructured into modular components

The Unbound DNS service configuration generation has been refactored from a monolithic structure into distinct, modular configuration files (access\_lists.conf, advanced.conf, blocklists.conf, dot.conf, private\_domains.conf, safesearch.conf, and unbound\_dhcpd.conf). This change separates concerns for access control lists, advanced server settings, blocklist management, DNS-over-TLS forwarding, private domain handling, safe search enforcement, and DHCP integration. Users will see these specific configuration areas managed through their respective templates, with domain overrides migrated to the dot.conf template and blocklist sources updated to use new mirror URLs and supported lists like hagezi and Firebog.

src/opnsense/service/templates/OPNsense/Unbound · high confidence

Unbound DNS management interface migrated to MVC

The Unbound DNS service configuration pages (General, Advanced, ACLs, Overrides, DNSBL, DoT, Overview, and Stats) have been converted to the MVC architecture. This migration replaces the legacy PHP-based views with new Volt templates that utilize the unified Bootgrid table component for data grids, standardizing the user interface and improving consistency across the Unbound settings.

src/opnsense/mvc/app/views/OPNsense/Unbound · high confidence

Unbound DNS model validation and alias management

The Unbound DNS configuration model now enforces stricter validation rules and provides better alias management. Users will see validation errors if they attempt to set the DNS port to a value already in use by another service, or if they configure DNS blocklists with mixed IP protocol families (IPv4/IPv6) or inconsistent subnet sizes. Additionally, host overrides now reject hostnames ending with a trailing dot, and the system tracks alias references to prevent conflicts.

src/opnsense/mvc/app/models/OPNsense/Unbound · high confidence

Unbound DNS reporting and management scripts rewritten in Python 3 with DuckDB backend

The Unbound DNS reporting and management infrastructure in src/opnsense/scripts/unbound has been rewritten in Python 3, replacing the previous shell-based and legacy Python implementations. The new logger.py script now uses DuckDB to store query data, enabling faster analytics and persistent reporting without the CPU overhead of index maintenance. A new wrapper.py script provides a unified Python interface for querying Unbound stats, cache, and local zones, while start.sh, cache.sh, and check.sh have been updated to support the new architecture, including cache dump/load/flush capabilities and improved error handling. The blocklists.py script introduces a structured command-line interface for managing blocklist policies, and unbound\_watcher.py has been refactored to use Python's subprocess and daemonize libraries for more robust DHCP lease monitoring.

src/opnsense/scripts/unbound · high confidence

Unbound DNS settings pages migrate to MVC controllers

The Unbound DNS configuration interface has been migrated from the legacy PHP-based architecture to the MVC framework. This change introduces dedicated controllers for each settings section—General, Advanced, ACLs, Overrides, DNSBL, DoT, Forwarding, Stats, and Overview—ensuring a consistent, modern user experience for managing DNS resolution, access control, and reporting.

src/opnsense/mvc/app/controllers/OPNsense/Unbound · high confidence

Unbound DNS: New interface and alias field types for MVC migration

The Unbound General page now uses new MVC field types to improve configuration handling. The UnboundInterfaceField now explicitly includes OpenVPN interfaces in the interface selection list, allowing users to bind Unbound to these virtual interfaces. Additionally, the new AliasReflector field type manages host aliases by splitting host/domain names and synchronizing changes directly with the underlying alias configuration, ensuring that adding or removing aliases in the Unbound settings updates the global alias list correctly.

src/opnsense/mvc/app/models/OPNsense/Unbound/FieldTypes · high confidence

Unbound DNSBL module refactored into Python with improved policy matching and logging

The Unbound DNSBL library has been rewritten in Python, replacing the previous PHP-based configuration sync script. This change introduces a new \Query\ class to safely parse DNS request and response states, and a \DNSBL\ class that handles dynamic blocklist loading and policy matching. A key behavioral improvement is the disabling of caching for domains that match a blocklist policy, ensuring that queries from different source networks are correctly evaluated against their specific rules. Additionally, a new \Logger\ class manages query logging via a named pipe, buffering entries when the backend is unavailable, while utility functions provide safer object path traversal.

src/opnsense/scripts/unbound-dnsbl/lib · high confidence

Unbound blocklist processing restructured with caching and wildcard support

The Unbound DNS blocklist handling has been refactored to improve reliability and flexibility. The system now caches downloaded blocklists locally to reduce network load and speed up processing, while also supporting wildcard domain entries in blocklists. Additionally, whitelist (passlist) management has been moved from a pre-filtering option to a dedicated plugin-based handler, allowing for more granular control over which domains are excluded from blocking rules.

src/opnsense/scripts/unbound/blocklists · high confidence

Unified authentication service implementations for WebGui, System, and IPsec

The authentication logic for the Web GUI, system console (including SSH, su, and sudo), and IPsec mobile clients has been consolidated into a unified service framework. New service classes (WebGui, System, and IPsec) now implement the standard \IService\ interface, allowing each component to declare its supported authenticators (such as Local Database or external sources) and enforce specific access constraints, such as requiring IPsec users to belong to a designated local group. This change standardizes how these distinct entry points handle user identity and authorization checks.

src/opnsense/mvc/app/library/OPNsense/Auth/Services · high confidence

Updated Captive Portal default login template to Bootstrap 3.4.1

The default Captive Portal login page now uses Bootstrap v3.4.1 instead of v3.3.5. This update brings the latest styling, component fixes, and glyph icons to the captive portal interface, ensuring a more consistent and modern look for users authenticating on the network.

_src/opnsense/scripts/captiveportal/htdocs\default · high confidence

Updated IXR XML-RPC library to version 1.7.4

The contrib/IXR/IXR\_Library.php file has been replaced with version 1.7.4 of the Incutio XML-RPC Library. This update addresses PHP 8 compatibility issues, specifically correcting the constructor format and resolving deprecation warnings related to non-canonical type casts (double, boolean) and the count() function. It also removes unnecessary trimming of XML values and replaces the deprecated curl\_close() usage, ensuring stable operation of High Availability status checks and other XML-RPC dependent features on modern PHP versions.

contrib/IXR · high confidence

Updated OPNsense package repository fingerprint for 2026-06-08

The trusted fingerprint file for the OPNsense package repository has been updated to reflect the correct SHA-256 hash for the 2026-06-08 release. This change corrects a previous error where the 26.7 fingerprint was incorrectly copied from the 26.1 release, ensuring that package verification uses the accurate cryptographic signature for the current software version.

src/etc/pkg/fingerprints/OPNsense/trusted · high confidence

Updated Unbound root hints to December 2023

The Unbound DNS resolver now uses a fresh copy of the root hints file (root.min.hints) updated as of December 20, 2023. This ensures the resolver has the latest authoritative root server addresses, which can improve DNS resolution reliability and performance by reducing reliance on potentially stale cached root server information.

src/opnsense/data/unbound · high confidence

Updated bootstrap-select styling assets

The LESS source files for the bootstrap-select component have been updated to version 1.9.3, introducing new styling rules for dropdown toggles, error states, and disabled interactions, along with updated variable definitions for colors and z-indexing to ensure proper layering with modals and the navbar.

src/opnsense/www/themes/opnsense/assets/stylesheets/bootstrap-select · high confidence

Updated revoked package signing fingerprints for pkg.opnsense.org

The revoked fingerprint list for the OPNsense package repository has been updated with 21 new entries spanning from 2015 to 2026. These additions record historical SHA-256 keys that are no longer valid, ensuring the system correctly rejects packages signed with obsolete credentials during updates.

src/etc/pkg/fingerprints/OPNsense/revoked · high confidence

Upgrade Font Awesome icons to version 6

The Font Awesome icon library in the web interface has been upgraded from version 5 to version 6.7.1. This update replaces the previous icon set with new styles, animations, and a broader range of icons, which may alter the appearance of existing UI elements and require updates to icon class names in custom themes or scripts.

src/opnsense/www/assets · high confidence

Upgrade sanity checks for package manager compatibility

A new pre-upgrade sanity check script (10-sanity.sh) has been added to the upgrade process to verify the system's readiness before proceeding. This script ensures that the core package name can be determined, the package manager (pkg-static) is installed, the core package is recognized by the package database, and the package manager is compatible with the OPNsense product. If any of these checks fail, the upgrade process will halt with a descriptive error message, preventing potential issues during the upgrade.

src/etc/rc.syshook.d/upgrade · high confidence

WireGuard API refactoring and client configuration enhancements

The WireGuard API controllers have been restructured into dedicated modules (Client, Server, General, Service) to improve code organization. This change introduces new capabilities for managing client configurations, including a new API endpoint to generate pre-shared keys and a client builder feature that allows generating client configuration files while automatically storing the public keys on the firewall. The service controller now handles interface registration and reconfiguration more robustly, and the status display logic has been updated to correctly identify peers by name even when public keys overlap between different instances, as well as to track peer online/offline status based on handshake age.

src/opnsense/mvc/app/controllers/OPNsense/Wireguard/Api · high confidence

WireGuard diagnostics and configuration UI enhancements

The WireGuard interface now includes a dedicated diagnostics view that displays a unified grid of both VPN instances and peers, allowing users to filter by type and monitor real-time status (Online/Offline/Stale), handshake ages, and data transfer volumes. In the general configuration view, the peer generator has been improved with a server filter to select the target instance, and key generation buttons for both server keypairs and client pre-shared keys have been moved directly into their respective forms for easier access.

src/opnsense/mvc/app/views/OPNsense/Wireguard · high confidence

WireGuard interface restructured with dedicated controllers and diagnostics

The WireGuard management interface has been refactored to use dedicated MVC controllers for general settings and diagnostics. The new GeneralController now explicitly loads forms for both WireGuard servers and clients, including a new 'Config Builder' dialog that allows users to generate client configuration files and store their public keys on the firewall. A new DiagnosticsController has been added to provide a separate diagnostics view, while the GeneralController also integrates QR code generation libraries to facilitate client configuration sharing.

src/opnsense/mvc/app/controllers/OPNsense/Wireguard · high confidence

WireGuard model schema restructured with mandatory network masks and peer generator storage

The WireGuard configuration models have been updated to enforce stricter validation and support new client-side features. The \Client\ model now includes fields for storing peer generator output (private key, endpoint, DNS, and allowed IPs) and enforces a unique constraint on the public key relative to the server address and port. A new \M1\_0\_0\ migration automatically appends \/32\ or \/128\ netmasks to existing tunnel addresses to satisfy the new \NetMaskRequired\ validation, ensuring compatibility with FreeBSD 15. The \Server\ model now allows instance IDs to start at 0 and includes a debug flag for logging.

src/opnsense/mvc/app/models/OPNsense/Wireguard · high confidence

WireGuard server configuration template added

A new Jinja2 template for generating WireGuard server configuration files has been introduced. This template iterates through defined server instances and their associated peers, outputting the standard \[Interface\] and \[Peer\] sections including private keys, listen ports, preshared keys, endpoints, allowed IPs, and persistent keepalive settings. This change establishes the mechanism for rendering the active WireGuard server configuration on the firewall.

src/opnsense/service/templates/OPNsense/Wireguard · high confidence

configd action execution engine refactored to use a plugin-based architecture

The configd service now uses a new ActionFactory to dynamically load and execute actions, replacing the previous monolithic implementation. This change introduces distinct action types—inline (for template management and config lookups), script (for standard command execution), script\_output (for cached script results), stream\_output (for real-time output streaming), and none (for unknown types)—each inheriting from a common BaseAction. Users benefit from improved reliability through better error handling, support for caching script outputs via cache\_ttl, and the ability to stream long-running process output directly to the client.

src/opnsense/service/modules/actions · high confidence

configd backend service rewritten with new template engine and modular architecture

The configd service module has been restructured into a modular Python package, introducing a new Jinja2-based template engine for generating configuration files and a refactored daemon handler for processing commands via Unix domain sockets. This change adds support for advanced template features such as IDNA encoding, shell parameter escaping, and strict mode targeting, while also improving error reporting, logging, and session context handling for the backend service.

src/opnsense/service/modules · high confidence

configd service and control tools rewritten in Python 3

The configd process coordinator and its command-line utilities (configd\_ctl.py, template\_ctl.py) have been rewritten from PHP to Python 3. This change introduces a new daemon wrapper (configd.py) that automatically restarts the service if it crashes unexpectedly, and updates the client tools to use a Unix domain socket for communication. Users benefit from improved stability through automatic restarts, better handling of event handlers, and the ability to flush command caches or detach long-running actions via new command-line flags.

src/opnsense/service · high confidence

Test coverage

Added migration test fixtures for BaseModel; Added test configuration for OPNsense MVC application; Added unit tests for BaseModel validation constraints; Added unit tests for Core Config and Shell utilities; Added unit tests for Dnsmasq HostnameField validation; Added unit tests for FilterRule generation; Added unit tests for IPv6 track6 prefix ID and delegation logic; Added unit tests for Kea DHCP option data field encoding; Added unit tests for Unbound DNSBL script components; Added unit tests for field comparison and uniqueness constraints; Added unit tests for firewall alias parsers; Added unit tests for the ACL model; Initial PHPUnit test framework setup for MVC components; Initial unit tests for configd core and template modules; Initial unit tests for the BaseModel class; Unit tests added for MVC Base FieldTypes.

Dependencies

Add Tokenize2 and update datepicker library

The web interface now includes the Tokenize2 library (v1.3.3) for improved token input handling, along with its license file. Additionally, the bootstrap-datepicker component has been updated to version 1.7.1.

src/opnsense/www/js · high confidence

Upgrade jQuery to version 3.5.1

The web interface has upgraded the jQuery library from version 3.4.1 to 3.5.1. This update addresses end-of-life concerns and improves compatibility with modern browser standards. The previous version (3.4.1) is retained on disk to ensure smoother migrations for any third-party plugins that may still depend on it.

src/www · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 33.

Lenses

  • Code Health 39
  • Architecture 89
  • Maturity 59
  • Readiness 24
  • Security 63
  • Accessibility 28

Changes since last survey

  • 300 commits — 254 feature/other, 46 fixes

By area

  • src/opnsense — 207 commits
  • src/etc — 60 commits
  • src/www — 23 commits
  • (root) — 6 commits
  • Mk/core.mk — 1 commit
  • Mk/version.mk — 1 commit
  • contrib/spdx-sbom — 1 commit
  • src/sbin — 1 commit

Notable commits

  • fix: Firewall: NAT: Destination NAT - fix missing "well-known" in local-port, closes https://github.com/opnsense/core/issues/10612
  • fix: Firewall: NAT: Source NAT: Fix port normalization in the Migration Assistance rule export
  • fix: Firewall: NAT: Source NAT: fix port alias and well known port usage in target_port (#10793)
  • fix: MVC: UI: base_tabs_header fix tab activation (#10606)
  • fix: MVC:ui - regression in 3d9cccfe4038802807219621ddd49cf668a05144, breaks collapse/static keywords, should fix https://github.com/opnsense/core/issues/10601
  • fix: MVC:ui Fix collapsible form section rendering in base_form.volt in f8c0ba6 (#10604)
  • fix: Reporting: NetFlow - fix previous "TypeError: can't compare offset-naive and offset-aware datetimes". for https://github.com/opnsense/core/issues/10689
  • fix: Revert "interfaces: anchor accept_rtadv in interface_dhcpv6_configure() #10828"
  • fix: Services: Kea DHCPv4/6: fix leases sorting (#10823)
  • fix: System: fix separator of previous c8fd35b
  • fix: acl: add missing and fix some issues
  • fix: captive portal: fix PHP warning here too
  • fix: dashboard: fix JavaScript bugs in dashboard widget code (#10460)
  • fix: dnsmasq: leases sorting fixes (#10790)
  • fix: firewall: fix empty menu container
  • fix: firewall: fix loopback address in private defintions; closes #10694
  • fix: firewall: fix stale imports
  • fix: firmware: fix advanced/help display on mocked firmware page form
  • fix: interfaces: fix API ACL patters for GIF/GRE; closes #10871
  • fix: interfaces: fix PHP warnings and do not write unset ones
  • …and 280 more

Architecture

  • 0 containers · 1 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

opnsense/core was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 227bbd3d120e7a01562236239b3ad778ecb56d7a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.