github OpenVoxProject/openvox 9.0.0

4 hours ago

🎉 This is the first release in the OpenVox 9 series! Major thanks to the amazing Vox Pupuli community for making this release happen. This release would not exist without everyone who submitted pull requests, filed bugs, tested pre-releases, and joined the discussions about what should change. 🎉

Major changes:

  • Ruby 4.0.7
  • OpenFact 6.2.1
  • OpenSSL 3.5.9 (the OpenSSL LTS)
  • Windows agents are now built against msys2. The filename now denotes it as windows-msys2-x64.msi. This brings improvements to our build process, but should be transparent to users.

Upgrading from OpenVox 8

  1. Configure the openvox9 repositories. Install the openvox9-release package for your platform from https://yum.voxpupuli.org/ or https://apt.voxpupuli.org/. MacOS packages are at https://downloads.voxpupuli.org/mac/openvox9/ and the Windows package is at https://downloads.voxpupuli.org/windows/openvox9/.
  2. Upgrade server hosts as a set. The 8.x openvox-server and openvoxdb packages require openvox-agent < 9.0.0, and the 9.x packages require openvox-agent >= 9.0.0. Upgrade the agent, server, and database packages on a server host, then the agents in the rest of your fleet.
  3. Ensure server is set in puppet.conf on every agent before upgrading if they currently rely on the default puppet. OpenVox 9 no longer falls back to the server name puppet by default when server is not set. Agents configured with server_list, DNS SRV records, or ca_server and report_server are not affected.
  4. Decide what happens to reports. The default of the reports setting changed from store to none. A server that should keep writing YAML reports to reportdir needs reports = store in puppet.conf. Servers that set reports explicitly (for example puppetdb or foreman) are not affected.
  5. Ensure Java 21 or 25 are available on server hosts. If /etc/sysconfig/puppetserver, /etc/default/puppetserver, /etc/sysconfig/puppetdb, or /etc/default/puppetdb sets JAVA_BIN to anything other than /usr/bin/java, ensure it points to a Java 21 or 25 binary or remove the line.
  6. Check Ruby code against Ruby 4.0. Custom types, providers, functions, facts, report processors, and gems now run on Ruby 4.0 on agents and on JRuby 10.1 on the server. Gems installed into the agent's Ruby with /opt/puppetlabs/puppet/bin/gem must be installed again after the upgrade because the gem directory moves from lib/ruby/gems/3.2.0 to lib/ruby/gems/4.0.0. Gems installed with puppetserver gem stay in place but must work on Ruby 4.0.
  7. Replace --configprint. The puppet agent --configprint option and the configprint setting are gone. Use puppet config print.
  8. Merge the new default auth.conf on the server. The package manager keeps a modified /etc/puppetlabs/puppetserver/conf.d/auth.conf and drops the new default next to it (auth.conf.rpmnew or auth.conf.dpkg-dist). The new default restricts filebucket reads and allows the server to clear its own environment cache
  9. Check the Jetty 12 bootstrap entry if you skipped 8.14.1. Server and database hosts that were upgraded from 8.14.0 or earlier with a modified /etc/puppetlabs/puppetdb/bootstrap.cfg need jetty10-service replaced with puppetlabs.trapperkeeper.services.webserver.jetty-service/jetty-service. See the 8.14.1 entries in the OpenVox Server and OpenVoxDB 8 release notes.
  10. Check platform support. See the platform lists in each section below.

Components

Component 8.29.0 9.0.0
Ruby 3.2.11 4.0.7
OpenSSL 3.0.22 3.5.9
OpenSSL FIPS provider build (FIPS packages) 2025.12.17.1 2025.12.17.1
OpenFact 5.6.1 6.2.1
puppet-resource_api 1.9.2 2.0.1
puppet-ca-bundle 1.1.0 (PEM bundle and Java keystore) 1.2.0 (PEM bundle only)
libxml2 2.15.3 2.15.4
curl 8.22.0 not shipped
ruby-shadow 2.5.1 patched fork (commit bc7752a9)

Vendored modules:

Module 8.29.0 9.0.0
puppetlabs-augeas_core 1.5.0 2.0.1
puppetlabs-cron_core 1.3.0 2.0.2
puppetlabs-host_core 1.3.0 2.0.1
puppetlabs-mount_core 1.3.0 1.3.0
puppetlabs-scheduled_task 3.2.0 5.0.0
puppetlabs-selinux_core 1.4.0 2.0.1
puppetlabs-sshkeys_core 2.5.0 3.0.2
puppetlabs-yumrepo_core 2.1.0 3.0.1
puppetlabs-zfs_core 1.6.1 2.0.1
puppetlabs-zone_core 1.2.0 removed

Unchanged: libffi 3.8.0, libyaml 0.2.5, augeas 1.14.1, ruby-augeas 0.6.0, readline 8.1.2, virt-what 1.27, dmidecode 3.7, ruby-selinux 3.9, and the vendored gems concurrent-ruby 1.3.8, hiera-eyaml 5.0.1, net-ssh 7.3.3, rexml 3.4.4, ffi 1.17.4, gettext 3.5.2, fast_gettext 2.4.0, hocon 1.4.0, locale 2.1.5, thor 1.5.0, highline 3.1.2, deep_merge 1.2.2, erubi 1.13.1, optimist 3.2.1, semantic_puppet 1.1.1, sys-filesystem 1.6.0, ruby-dbus 0.25.0, CFPropertyList 4.0.0, minitar 1.1.0. The base64 and multi_json gems are no longer vendored.

The Ruby standard library gems moved with Ruby. Notable versions: resolv 0.7.2 (was 0.2.3), erb 6.0.7 (was 4.0.3.1), json 2.18.0 (was 2.6.3), openssl gem 4.0.2 (was 3.1.0), psych 5.3.1 (was 5.0.1), uri 1.1.1 (was 0.12.5), net-http 0.9.1 (was 0.4.1), RubyGems 4.0.20 and Bundler 4.0.20 (were 3.4.19 and 2.4.19). set and pathname are no longer separate gems, and cgi and readline-ext are no longer shipped.

Breaking changes

  • No default server. The server setting no longer defaults to puppet. Any run that would fall back on server without the setting configured fails with an error that tells you to run puppet config --section main set server YOUR_SERVER_NAME. Agents that resolve their server through server_list, DNS SRV records, or an explicit server on the command line are not affected, and ca_server and report_server satisfy the check for the CA and report services. (#536, #623, #659, #661)
  • Reports are off by default. The default of reports changed from store to none. (#583)
  • Deferred values are evaluated before the catalog is applied again. The default of preprocess_deferred is true again, because too many types and providers expect resolved values. Set preprocess_deferred = false to keep the lazy evaluation that OpenVox 8 used by default. (#462)
  • File content that looks like a checksum is literal content. A content value such as {md5}... no longer triggers a filebucket lookup and no longer warns. The checksum form is still recognized when the catalog carries the actual content separately. (#170)
  • Removed settings, options, and APIs. --configprint and the configprint setting (use puppet config print), the pluginsync setting, the hiera indirector terminus, the data_binding_terminus setting, the encoding argument of regsubst, the legacy PAL script evaluation APIs, and the pe_serverversion fact are gone. (#374, #389, #384, #385, #391, #393, #397)
  • The zone_core module is no longer vendored. Solaris zone management needs the module installed separately. (#592)
  • The systemd service provider no longer falls back to SysVInit on Debian. invoke-rc.d and init script inspection are no longer consulted to decide whether a service is enabled. (#562)
  • The Java keystore is gone from the runtime. /opt/puppetlabs/puppet/ssl/puppet-cacerts is no longer shipped. The PEM bundle at /opt/puppetlabs/puppet/ssl/cert.pem remains. (#593)
  • OpenFact 6 is required. The openvox gem depends on openfact ~> 6.0 and needs Ruby 3.2 or newer. (#577, #442, #519)
  • New major versions of the vendored modules. See the table above. The modules were updated for the newer Ruby and may have dropped support for older Puppet versions; check their changelogs if you pin them in a Puppetfile. (#589)
  • The openvox gem ships platform builds. Besides the generic gem there are universal-darwin (adds CFPropertyList) and x64-mingw-ucrt (adds ffi, minitar, win32ole) builds. The x64-mingw32 and x86-mingw32 platforms are dropped. (#607)

OpenFact 6

OpenFact 6.2.1 replaces 5.x. Changes that affect custom facts and facter users:

  • Facter::Util::Resolution.which and .exec print deprecation warnings. Use Facter::Core::Execution.which and Facter::Core::Execution.execute(command, on_fail: nil) instead; see https://voxpupuli.org/blog/2026/09/08/cleaning-up-deprecation-warnings/ for the details and the behavior difference of execute.
  • The time_limit and limit aliases of the timeout option of Facter::Core::Execution.execute are deprecated.
  • The deprecated ldapname fact option is removed.
  • The executable search path includes the common elements of $PATH.
  • Ruby older than 3.0 is no longer supported by the gem.
  • Fixes: log timestamp formatting, partial EC2 metadata results are rejected and a failed EC2 root metadata request is treated as no metadata, and the FQDN lookup in the hostname resolvers is bounded.

Release notes: https://github.com/OpenVoxProject/openfact/releases/tag/6.0.0, https://github.com/OpenVoxProject/openfact/releases/tag/6.1.0, https://github.com/OpenVoxProject/openfact/releases/tag/6.2.0, https://github.com/OpenVoxProject/openfact/releases/tag/6.2.1

Other changes

  • The agent logs an error when the catalog it received was compiled for a different certname, which happens with cloned images that keep a cached catalog or with a misrouting load balancer. (#568)
  • A forked agent run is killed when it outlives runtimeout, a RunTimeoutError during fact collection is no longer swallowed, and the daemon waits for its certificate in the forked child instead of blocking the daemon. (#642, #643, #683)
  • Puppet.features.posix? no longer depends on the syslog library, which is not a default gem in current Ruby; this fixes Cannot determine basic system flavour on such installations. (#458)
  • The filebucket REST terminus honors the server given in the request. (#368)
  • Deferred resolution of Puppet language functions works again. (#350)
  • Loading facts is logged once per run, and redeclaring a node parameter with the same value is a notice instead of a warning. (#656, #626)
  • The apt package provider no longer passes the deprecated --force-yes option. (#560)
  • The Puppet::Util environment wrapper methods (get_env, set_env, clear_environment, merge_environment, get_environment) print deprecation warnings. The source_permissions file parameter and the filetimeout setting are no longer deprecated. (#417, #418, #419)
  • Debian packages now install /etc/default/puppet, which sets PUPPET_EXTRA_OPTS for the systemd unit, and the unit no longer warns about an unset variable. (#645, #644, #688)
  • The Windows package is built with MSYS2 and the UCRT toolchain, the same x64-mingw-ucrt platform as upstream Ruby. Precompiled gems such as nokogiri install on Windows nodes without build tools. (#468)
  • Documentation, help output, and default configuration files use the OpenVox name and link to docs.openvoxproject.org, and the man pages build reproducibly.

Runtime changes between the 8.x and main lines of puppet-runtime are listed in the puppet-runtime releases, https://github.com/OpenVoxProject/puppet-runtime/releases.

Platforms

Removed vs 8.x: EL 7, Amazon Linux 2, Fedora 42, Ubuntu 25.04.

Security issues resolved since openvox-agent 8.29.0

Identifier Severity Resolved by
CVE-2026-84782 High pkg:github/openssl/openssl@3.5.9
CVE-2026-35189 Low pkg:github/openssl/openssl@3.5.9
CVE-2026-54872 Low pkg:github/openssl/openssl@3.5.9
CVE-2026-75805 Low pkg:github/openssl/openssl@3.5.9
CVE-2026-75806 Low pkg:github/openssl/openssl@3.5.9
CVE-2026-77696 Low pkg:github/openssl/openssl@3.5.9
CVE-2026-80212 not rated upstream pkg:gem/resolv@0.7.2 (Ruby 4.0.7)
CVE-2026-80213 not rated upstream pkg:gem/resolv@0.7.2 (Ruby 4.0.7)

The six OpenSSL issues were published on September 29, 2026 and affect the OpenSSL 3.0. OpenSSL 3.5.9 also fixes CVE-2026-35191, CVE-2026-42772, CVE-2026-54873, CVE-2026-54875, CVE-2026-72897, CVE-2026-75804, and CVE-2026-84784, which OpenSSL does not list as affecting the 3.0 line.

libxml2 2.15.4 contains security fixes without CVE identifiers: an out-of-bounds read in the regular expression engine, missing overflow checks in dict.c, uri.c, and valid.c, an overflow check in XPointer evaluation, and an integer overflow check before the I/O write callback.

What's Changed

Breaking Changes 🛠

New Features 🎉

Bug Fixes 🐛

  • avoid badly anchored regular expression by @corporate-gadfly in #414
  • Manage group members on EL 10 without libuser by @Sharpie in #476
  • Fix File.open Ruby 3.2 regression in FileSystem::Uniquefile by @JonasVerhofste in #450
  • Tolerate concurrent creation of directories by @Sharpie in #506
  • Fix handling of Puppet::Pops serialization issues by @seanmil in #502
  • Fix regex node lookup regression from PUP-11515 by @corporate-gadfly in #481
  • Copy input mtime to files generated by puppet generate types by @silug in #522
  • Update ca_last_update/crl_last_update on HTTP 304 by @bastelfreak in #524
  • fix: Pacman provider uses unrecognized option '--update' by @fmichea in #451
  • Fix filebucket REST terminus to support request.server by @mdechiaro in #368
  • fix: Deferred resolution of Puppet-language functions (e.g. mocks in tests) failing due to lack of :global_scope by @griggi-ws in #350
  • Report errors when renewing a certificate fails by @jay7x in #610
  • puppet generate: print module directory when types are missing by @Sharpie in #617
  • Fix excessive reads of /proc/mounts by @jenxie in #620
  • Pin json below 3 to unblock CI by @miharp in #655
  • print "Loading facts" just once by @bastelfreak in #656
  • Only require the server setting when no explicit server is given by @silug in #659
  • Install the service defaults file on Debian by @jcharaoui in #645
  • Kill the forked agent run if it outlives runtimeout by @silug in #642
  • Do not swallow RunTimeoutError while collecting facts by @silug in #643
  • Wait for certificates in the forked child, not in the daemon by @silug in #683
  • packaging: ensure every systemd-distro get a service file by @bastelfreak in #688
  • openfact: Update 6.2.0 -> 6.2.1 by @OpenVoxProjectBot in #692

Documentation Updates 📚

  • Document cross-node read exposure of a central filebucket by @silug in #585

Dependency Updates ⬆️

Other Changes

New Contributors

Full Changelog: 8.26.2...9.0.0

Don't miss a new openvox release

NewReleases is sending notifications on new releases.