🎉 This is the first release in the OpenVox 9 series! Major thanks to the amazing Vox Pupuli community for making this release happen. This release would not exist without everyone who submitted pull requests, filed bugs, tested pre-releases, and joined the discussions about what should change. 🎉
Major changes:
- Ruby 4.0.7
- OpenFact 6.2.1
- OpenSSL 3.5.9 (the OpenSSL LTS)
- Windows agents are now built against msys2. The filename now denotes it as windows-msys2-x64.msi. This brings improvements to our build process, but should be transparent to users.
Upgrading from OpenVox 8
- Configure the
openvox9repositories. Install theopenvox9-releasepackage for your platform from https://yum.voxpupuli.org/ or https://apt.voxpupuli.org/. MacOS packages are at https://downloads.voxpupuli.org/mac/openvox9/ and the Windows package is at https://downloads.voxpupuli.org/windows/openvox9/. - Upgrade server hosts as a set. The 8.x openvox-server and openvoxdb packages require openvox-agent < 9.0.0, and the 9.x packages require openvox-agent >= 9.0.0. Upgrade the agent, server, and database packages on a server host, then the agents in the rest of your fleet.
- Ensure
serveris set inpuppet.confon every agent before upgrading if they currently rely on the defaultpuppet. OpenVox 9 no longer falls back to the server namepuppetby default whenserveris not set. Agents configured withserver_list, DNS SRV records, orca_serverandreport_serverare not affected. - Decide what happens to reports. The default of the reports setting changed from
storetonone. A server that should keep writing YAML reports toreportdirneedsreports = storeinpuppet.conf. Servers that setreportsexplicitly (for example puppetdb or foreman) are not affected. - Ensure Java 21 or 25 are available on server hosts. If
/etc/sysconfig/puppetserver,/etc/default/puppetserver,/etc/sysconfig/puppetdb, or/etc/default/puppetdbsetsJAVA_BINto anything other than/usr/bin/java, ensure it points to a Java 21 or 25 binary or remove the line. - Check Ruby code against Ruby 4.0. Custom types, providers, functions, facts, report processors, and gems now run on Ruby 4.0 on agents and on JRuby 10.1 on the server. Gems installed into the agent's Ruby with
/opt/puppetlabs/puppet/bin/gemmust be installed again after the upgrade because the gem directory moves fromlib/ruby/gems/3.2.0tolib/ruby/gems/4.0.0. Gems installed withpuppetserver gemstay in place but must work on Ruby 4.0. - Replace
--configprint. The puppet agent--configprintoption and theconfigprintsetting are gone. Usepuppet config print. - Merge the new default auth.conf on the server. The package manager keeps a modified
/etc/puppetlabs/puppetserver/conf.d/auth.confand drops the new default next to it (auth.conf.rpmneworauth.conf.dpkg-dist). The new default restricts filebucket reads and allows the server to clear its own environment cache - Check the Jetty 12 bootstrap entry if you skipped 8.14.1. Server and database hosts that were upgraded from 8.14.0 or earlier with a modified
/etc/puppetlabs/puppetdb/bootstrap.cfgneedjetty10-servicereplaced withpuppetlabs.trapperkeeper.services.webserver.jetty-service/jetty-service. See the 8.14.1 entries in the OpenVox Server and OpenVoxDB 8 release notes. - Check platform support. See the platform lists in each section below.
Components
| Component | 8.29.0 | 9.0.0 |
|---|---|---|
| Ruby | 3.2.11 | 4.0.7 |
| OpenSSL | 3.0.22 | 3.5.9 |
| OpenSSL FIPS provider build (FIPS packages) | 2025.12.17.1 | 2025.12.17.1 |
| OpenFact | 5.6.1 | 6.2.1 |
| puppet-resource_api | 1.9.2 | 2.0.1 |
| puppet-ca-bundle | 1.1.0 (PEM bundle and Java keystore) | 1.2.0 (PEM bundle only) |
| libxml2 | 2.15.3 | 2.15.4 |
| curl | 8.22.0 | not shipped |
| ruby-shadow | 2.5.1 | patched fork (commit bc7752a9) |
Vendored modules:
| Module | 8.29.0 | 9.0.0 |
|---|---|---|
| puppetlabs-augeas_core | 1.5.0 | 2.0.1 |
| puppetlabs-cron_core | 1.3.0 | 2.0.2 |
| puppetlabs-host_core | 1.3.0 | 2.0.1 |
| puppetlabs-mount_core | 1.3.0 | 1.3.0 |
| puppetlabs-scheduled_task | 3.2.0 | 5.0.0 |
| puppetlabs-selinux_core | 1.4.0 | 2.0.1 |
| puppetlabs-sshkeys_core | 2.5.0 | 3.0.2 |
| puppetlabs-yumrepo_core | 2.1.0 | 3.0.1 |
| puppetlabs-zfs_core | 1.6.1 | 2.0.1 |
| puppetlabs-zone_core | 1.2.0 | removed |
Unchanged: libffi 3.8.0, libyaml 0.2.5, augeas 1.14.1, ruby-augeas 0.6.0, readline 8.1.2, virt-what 1.27, dmidecode 3.7, ruby-selinux 3.9, and the vendored gems concurrent-ruby 1.3.8, hiera-eyaml 5.0.1, net-ssh 7.3.3, rexml 3.4.4, ffi 1.17.4, gettext 3.5.2, fast_gettext 2.4.0, hocon 1.4.0, locale 2.1.5, thor 1.5.0, highline 3.1.2, deep_merge 1.2.2, erubi 1.13.1, optimist 3.2.1, semantic_puppet 1.1.1, sys-filesystem 1.6.0, ruby-dbus 0.25.0, CFPropertyList 4.0.0, minitar 1.1.0. The base64 and multi_json gems are no longer vendored.
The Ruby standard library gems moved with Ruby. Notable versions: resolv 0.7.2 (was 0.2.3), erb 6.0.7 (was 4.0.3.1), json 2.18.0 (was 2.6.3), openssl gem 4.0.2 (was 3.1.0), psych 5.3.1 (was 5.0.1), uri 1.1.1 (was 0.12.5), net-http 0.9.1 (was 0.4.1), RubyGems 4.0.20 and Bundler 4.0.20 (were 3.4.19 and 2.4.19). set and pathname are no longer separate gems, and cgi and readline-ext are no longer shipped.
Breaking changes
- No default
server. Theserversetting no longer defaults topuppet. Any run that would fall back onserverwithout the setting configured fails with an error that tells you to runpuppet config --section main set server YOUR_SERVER_NAME. Agents that resolve their server throughserver_list, DNS SRV records, or an explicit server on the command line are not affected, andca_serverandreport_serversatisfy the check for the CA and report services. (#536, #623, #659, #661) - Reports are off by default. The default of
reportschanged fromstoretonone. (#583) - Deferred values are evaluated before the catalog is applied again. The default of
preprocess_deferredistrueagain, because too many types and providers expect resolved values. Setpreprocess_deferred = falseto keep the lazy evaluation that OpenVox 8 used by default. (#462) - File content that looks like a checksum is literal content. A
contentvalue such as{md5}...no longer triggers a filebucket lookup and no longer warns. The checksum form is still recognized when the catalog carries the actual content separately. (#170) - Removed settings, options, and APIs.
--configprintand theconfigprintsetting (usepuppet config print), thepluginsyncsetting, thehieraindirector terminus, thedata_binding_terminussetting, the encoding argument ofregsubst, the legacy PAL script evaluation APIs, and thepe_serverversionfact are gone. (#374, #389, #384, #385, #391, #393, #397) - The
zone_coremodule is no longer vendored. Solaris zone management needs the module installed separately. (#592) - The systemd service provider no longer falls back to SysVInit on Debian.
invoke-rc.dand init script inspection are no longer consulted to decide whether a service is enabled. (#562) - The Java keystore is gone from the runtime.
/opt/puppetlabs/puppet/ssl/puppet-cacertsis no longer shipped. The PEM bundle at/opt/puppetlabs/puppet/ssl/cert.pemremains. (#593) - OpenFact 6 is required. The
openvoxgem depends onopenfact ~> 6.0and needs Ruby 3.2 or newer. (#577, #442, #519) - New major versions of the vendored modules. See the table above. The modules were updated for the newer Ruby and may have dropped support for older Puppet versions; check their changelogs if you pin them in a Puppetfile. (#589)
- The
openvoxgem ships platform builds. Besides the generic gem there areuniversal-darwin(adds CFPropertyList) andx64-mingw-ucrt(adds ffi, minitar, win32ole) builds. Thex64-mingw32andx86-mingw32platforms are dropped. (#607)
OpenFact 6
OpenFact 6.2.1 replaces 5.x. Changes that affect custom facts and facter users:
Facter::Util::Resolution.whichand.execprint deprecation warnings. UseFacter::Core::Execution.whichandFacter::Core::Execution.execute(command, on_fail: nil)instead; see https://voxpupuli.org/blog/2026/09/08/cleaning-up-deprecation-warnings/ for the details and the behavior difference ofexecute.- The
time_limitandlimitaliases of thetimeoutoption ofFacter::Core::Execution.executeare deprecated. - The deprecated
ldapnamefact option is removed. - The executable search path includes the common elements of
$PATH. - Ruby older than 3.0 is no longer supported by the gem.
- Fixes: log timestamp formatting, partial EC2 metadata results are rejected and a failed EC2 root metadata request is treated as no metadata, and the FQDN lookup in the hostname resolvers is bounded.
Release notes: https://github.com/OpenVoxProject/openfact/releases/tag/6.0.0, https://github.com/OpenVoxProject/openfact/releases/tag/6.1.0, https://github.com/OpenVoxProject/openfact/releases/tag/6.2.0, https://github.com/OpenVoxProject/openfact/releases/tag/6.2.1
Other changes
- The agent logs an error when the catalog it received was compiled for a different certname, which happens with cloned images that keep a cached catalog or with a misrouting load balancer. (#568)
- A forked agent run is killed when it outlives
runtimeout, aRunTimeoutErrorduring fact collection is no longer swallowed, and the daemon waits for its certificate in the forked child instead of blocking the daemon. (#642, #643, #683) Puppet.features.posix?no longer depends on thesysloglibrary, which is not a default gem in current Ruby; this fixesCannot determine basic system flavouron such installations. (#458)- The filebucket REST terminus honors the server given in the request. (#368)
- Deferred resolution of Puppet language functions works again. (#350)
Loading factsis logged once per run, and redeclaring a node parameter with the same value is a notice instead of a warning. (#656, #626)- The apt package provider no longer passes the deprecated
--force-yesoption. (#560) - The
Puppet::Utilenvironment wrapper methods (get_env,set_env,clear_environment,merge_environment,get_environment) print deprecation warnings. Thesource_permissionsfile parameter and thefiletimeoutsetting are no longer deprecated. (#417, #418, #419) - Debian packages now install
/etc/default/puppet, which setsPUPPET_EXTRA_OPTSfor the systemd unit, and the unit no longer warns about an unset variable. (#645, #644, #688) - The Windows package is built with MSYS2 and the UCRT toolchain, the same
x64-mingw-ucrtplatform as upstream Ruby. Precompiled gems such as nokogiri install on Windows nodes without build tools. (#468) - Documentation, help output, and default configuration files use the OpenVox name and link to docs.openvoxproject.org, and the man pages build reproducibly.
Runtime changes between the 8.x and main lines of puppet-runtime are listed in the puppet-runtime releases, https://github.com/OpenVoxProject/puppet-runtime/releases.
Platforms
Removed vs 8.x: EL 7, Amazon Linux 2, Fedora 42, Ubuntu 25.04.
Security issues resolved since openvox-agent 8.29.0
| Identifier | Severity | Resolved by |
|---|---|---|
| CVE-2026-84782 | High | pkg:github/openssl/openssl@3.5.9
|
| CVE-2026-35189 | Low | pkg:github/openssl/openssl@3.5.9
|
| CVE-2026-54872 | Low | pkg:github/openssl/openssl@3.5.9
|
| CVE-2026-75805 | Low | pkg:github/openssl/openssl@3.5.9
|
| CVE-2026-75806 | Low | pkg:github/openssl/openssl@3.5.9
|
| CVE-2026-77696 | Low | pkg:github/openssl/openssl@3.5.9
|
| CVE-2026-80212 | not rated upstream | pkg:gem/resolv@0.7.2 (Ruby 4.0.7)
|
| CVE-2026-80213 | not rated upstream | pkg:gem/resolv@0.7.2 (Ruby 4.0.7)
|
The six OpenSSL issues were published on September 29, 2026 and affect the OpenSSL 3.0. OpenSSL 3.5.9 also fixes CVE-2026-35191, CVE-2026-42772, CVE-2026-54873, CVE-2026-54875, CVE-2026-72897, CVE-2026-75804, and CVE-2026-84784, which OpenSSL does not list as affecting the 3.0 line.
libxml2 2.15.4 contains security fixes without CVE identifiers: an out-of-bounds read in the regular expression engine, missing overflow checks in dict.c, uri.c, and valid.c, an overflow check in XPointer evaluation, and an integer overflow check before the I/O write callback.
What's Changed
Breaking Changes 🛠
- Decouple :posix feature from :syslog library check by @silug in #458
- remove pe_serverversion fact by @corporate-gadfly in #397
- return to preprocessing deferred functions by default by @binford2k in #462
- Raise minimum Ruby version to 3.2.0 by @silug in #442
- Remove configprint setting by @silug in #374
- Remove legacy PAL script eval APIs by @silug in #393
- Remove regsubst encoding argument by @silug in #391
- Remove pluginsync setting by @silug in #389
- More secure default server setting by @corporate-gadfly in #536
- Promote openfact 6.0.0 into main by @OpenVoxProjectBot in #575
- Remove hiera indirector by @silug in #384
- openfact: Require 6.x by @bastelfreak in #577
- Remove data-binding settings by @silug in #385
- Allow file content that looks like a checksum. by @jeremie-pierson in #170
- Change reports default from "store" to "none" by @Sharpie in #583
- puppet-runtime: update 2026.07.16.1->2026.08.04.1 / removed java keystores by @bastelfreak in #593
- Remove zone_core module by @bastelfreak in #592
- Update vendored modules to latest versions by @bastelfreak in #589
- refactor(service/systemd): remove Debian SysVInit compatibility fallback by @TheMeier in #562
- raise ArgumentError for root when server is unset by @corporate-gadfly in #623
New Features 🎉
- Promote openfact 5.6.1 into main by @OpenVoxProjectBot in #436
- Add platform definitions for Fedora 44 by @Sharpie in #455
- Add windows-msys2-x64 build for OpenVox 9 by @Sharpie in #468
- Replace deprecated
--force-yesapt-getoption by @jay7x in #560 - Update CFPropertyList requirement from >= 3.0.6, < 4 to ~> 4.0 by @dependabot[bot] in #509
- rubocop: cleanup formatting and whitespace by @bastelfreak in #594
- feat: add multi platform builds by @rwaffen in #607
- Promote openfact 6.1.0 into main by @OpenVoxProjectBot in #668
- openfact: update 6.1.0 -> 6.2.0 by @OpenVoxProjectBot in #677
Bug Fixes 🐛
- avoid badly anchored regular expression by @corporate-gadfly in #414
- Manage group members on EL 10 without libuser by @Sharpie in #476
- Fix File.open Ruby 3.2 regression in FileSystem::Uniquefile by @JonasVerhofste in #450
- Tolerate concurrent creation of directories by @Sharpie in #506
- Fix handling of Puppet::Pops serialization issues by @seanmil in #502
- Fix regex node lookup regression from PUP-11515 by @corporate-gadfly in #481
- Copy input mtime to files generated by puppet generate types by @silug in #522
- Update ca_last_update/crl_last_update on HTTP 304 by @bastelfreak in #524
- fix: Pacman provider uses unrecognized option '--update' by @fmichea in #451
- Fix filebucket REST terminus to support request.server by @mdechiaro in #368
- fix:
Deferredresolution of Puppet-language functions (e.g. mocks in tests) failing due to lack of:global_scopeby @griggi-ws in #350 - Report errors when renewing a certificate fails by @jay7x in #610
- puppet generate: print module directory when types are missing by @Sharpie in #617
- Fix excessive reads of /proc/mounts by @jenxie in #620
- Pin json below 3 to unblock CI by @miharp in #655
- print "Loading facts" just once by @bastelfreak in #656
- Only require the server setting when no explicit server is given by @silug in #659
- Install the service defaults file on Debian by @jcharaoui in #645
- Kill the forked agent run if it outlives runtimeout by @silug in #642
- Do not swallow RunTimeoutError while collecting facts by @silug in #643
- Wait for certificates in the forked child, not in the daemon by @silug in #683
- packaging: ensure every systemd-distro get a service file by @bastelfreak in #688
- openfact: Update 6.2.0 -> 6.2.1 by @OpenVoxProjectBot in #692
Documentation Updates 📚
Dependency Updates ⬆️
- Update rubocop requirement from ~> 1.86.1 to ~> 1.87.0 by @dependabot[bot] in #465
- Update rspec-its requirement from ~> 1.1 to ~> 2.0 by @dependabot[bot] in #55
- Update json-schema requirement from >= 2, < 6 to >= 2, < 7 by @dependabot[bot] in #192
- Promote puppet-resource_api 2.0.1 into main by @OpenVoxProjectBot in #517
- Promote puppet-runtime 2026.07.06.1 into main by @OpenVoxProjectBot in #516
- Promote module-puppetlabs-scheduled_task v4.0.3 into main by @OpenVoxProjectBot in #528
- Promote openfact 5.7.0 into main by @OpenVoxProjectBot in #541
- Update rubocop requirement from ~> 1.87.0 to ~> 1.88.2 by @dependabot[bot] in #535
- Update rdoc requirement from ~> 6.0, < 6.4.0 to ~> 8.0 by @dependabot[bot] in #510
- Update rubocop requirement from ~> 1.88.2 to ~> 1.89.0 by @dependabot[bot] in #601
- Update rubocop requirement from ~> 1.89.0 to ~> 1.90.0 by @dependabot[bot] in #622
- build(deps-dev): update rubocop requirement from ~> 1.90.0 to ~> 1.91.0 by @dependabot[bot] in #670
Other Changes
- Add release version check and stop trying to bump to an RC version by @nmburgan in #413
- Changes to prepare for 8.x branching by @nmburgan in #425
- Change branch name in promote workflow by @nmburgan in #428
- Promote puppet-runtime 2026.05.07.1 into main by @OpenVoxProjectBot in #429
- Update acceptance defaults and descriptions for OpenVox 9 by @nmburgan in #431
- Switch from puppet-strings to openvox-strings by @tuxmea in #434
- Promote puppet-runtime 2026.05.20.1 into main by @OpenVoxProjectBot in #453
- Add JRuby 10.0.5.0 and 10.1.0.0 to test matrix by @silug in #463
- CI: Use bot account for backports by @bastelfreak in #472
- Promote puppet-runtime 2026.06.09.1 into main by @OpenVoxProjectBot in #479
- Add arm64 support to acceptance by @jpartlow in #495
- Remove source_permissions deprecation warning by @silug in #418
- add runtime deprecation warnings to Puppet::Util ENV wrappers by @silug in #417
- CI: Speed up JRuby and Windows spec runs by @silug in #525
- Remove filetimeout deprecation warning by @silug in #419
- Promote puppet-runtime 2026.07.16.1 into main by @OpenVoxProjectBot in #553
- Set
PUPPET_EXTRA_OPTSvariable to empty by @corporate-gadfly in #559 - Improve manpage reproducibility by @jcharaoui in #570
- Fix a small typo in the markdown docs by @jcharaoui in #569
- Update URLs in default config files by @jcharaoui in #572
- Fix "translates custom oids to their long name" test by @anthonyryan1 in #488
- Replace 'master' terminology with 'server' by @silug in #348
- User resource pw provider: Switches a couple commands to the safer array syntax by @binford2k in #567
- Rebrand Puppet -> OpenVox and fix links by @silug in #530
- Add man page validation to CI by @silug in #580
- Address review feedback from #530 by @silug in #579
- Remove bashism from pre/post-install scripts by @sideeffect42 in #573
- Validate that the catalog is compiled for this node by @binford2k in #568
- Update JRuby 10.1 test cell to 10.1.1.0 by @Sharpie in #584
- Remove unloadable CC-BY-1.0 RDoc template and generator by @silug in #587
- Remove setup.ps1 Cygwin setup script by @Sharpie in #591
- Request report storage explicitly in cached-catalog drift test by @silug in #598
- Update filebucket content acceptance tests for literal checksum semantics by @silug in #602
- Compare facterversion against installed facter in acceptance test by @silug in #597
- Migrate lookup acceptance tests to Hiera 5 data providers by @silug in #596
- Fix a small typo in the markdown docs (redux) by @jcharaoui in #603
- fix links to point to docs.openvoxproject.org by @corporate-gadfly in #609
- puppet node: redeclare to identical values is a
noticenot a warning. by @jcpunk in #626 - Promote puppet-runtime 2026.09.02.1 into main by @OpenVoxProjectBot in #628
- Fix systemd unreferenced variable warning on Debian by @jcharaoui in #644
- Increase delay affordance in waitforlock test by @jcharaoui in #641
- Accept ca_server and report_server without server when running as root by @silug in #661
- puppet-runtime: Update 2026.09.02.1 -> 2026.09.24.1 by @OpenVoxProjectBot in #684
- Document --environment in puppet agent help by @miharp in #653
- Promote puppet-runtime 2026.09.29.1 into main by @OpenVoxProjectBot in #694
- Skip the tests that need jruby-openssl in FIPS mode by @nmburgan in #696
New Contributors
- @tuxmea made their first contribution in #434
- @JonasVerhofste made their first contribution in #450
- @fmichea made their first contribution in #451
- @jcharaoui made their first contribution in #570
- @anthonyryan1 made their first contribution in #488
- @mdechiaro made their first contribution in #368
- @sideeffect42 made their first contribution in #573
- @jeremie-pierson made their first contribution in #170
- @TheMeier made their first contribution in #562
- @jenxie made their first contribution in #620
- @jcpunk made their first contribution in #626
- @miharp made their first contribution in #655
Full Changelog: 8.26.2...9.0.0