-
grahamperrin
parv: the pages _around_ FreeBSD Journal are somewhat peculiar, in that the start is near the end (the foot).
-
grahamperrin
-
VimDiesel`
Title: FreeBSD Journal DE September/October 2022
-
ravella
meka: I got it working, thanks for all of your help :)
-
jmnbtslsQE
i thought that: if out xmit bridge0 recv gre0 matches for a packet, then surely via gre0 must match, right? i am seeing that out xmit bridge0 recv gre0 actually requires a separate rule
-
r0ni
is there a simple way to install an older port in the ports tree?
-
Guest706
hello how do I change the mirror to a faster oneÉ
-
Guest706
I have a computer that can download 1gb per second
-
Guest706
and its working at 100 kb per second
-
Guest706
its really horrible is there anything I can do
-
Guest706
its frustrating i always get bad luck and lose my time
-
Guest706
lol
-
Guest706
i just lost an hour was hoping to have it up and running in 15 minutes not a huge headache...
-
Erhard
-
VimDiesel`
Title: FreshPorts -- ports-mgmt/fastest_sites: Sort MASTER_SITE_* based upon TCP handshake times
-
Erhard
Never tried it, mind you
-
Erhard
If I am downloading an ISO I will use aria2c and list a few mirrors and make them all threaded.
-
Erhard
I can saturate 5Gbit like that
-
Erhard
-
VimDiesel`
Title: Finding the Fastest FreeBSD Mirror – adufray.com
-
Erhard
-
VimDiesel`
Title: A shell script to select the fastest freebsd-update mirror · GitHub
-
Erhard
etc...
-
Guest706
thank you Erhard
-
Erhard
With a Gig connection familiarize yourself with aria2c because it can help you make use of the bandwidth, even with a single server (much to the admin's chagrin of course)
-
Guest706
I have it installed at home it`s just teh school computers
-
Erhard
Cool.
-
Guest706
like right now I am using my computer through the cloud and ssh to be able to go on weechat
-
Guest706
freebsd installed
-
Guest706
but sort of fed up with these computers it`s just the problem is I am here at school and want to be able to do something
-
Guest706
but cant a lot of the time...
-
Guest706
they have some weird french canadian keyboard that I don`t know how to hit all the buttons correctly and so many user restrictions
-
Erhard
You at McGill?
-
Guest706
but they have virtual box and I thought freebsd was the fastest and easiest to install
-
Guest706
how did you knowÉ
-
Erhard
My son just graduated from there
-
Guest706
oh cool in what
-
Erhard
Software Engineering
-
Guest706
congratulations
-
Guest706
to your son
-
Erhard
Yeah, he already has a job
-
Guest706
i`m at uqam
-
Erhard
Ah, close enough
-
Guest706
sounds pretty awesome what kind of job I want to be able to get a job
-
Erhard
Just walked by there a couple weeks ago
-
Guest706
yes exactly one block
-
Guest706
one metro station place des arts basically and the next station is mcgill
-
Erhard
He is doing software engineeering for work. Already making total of 6 figures US.
-
Guest706
unbelievable and I can`t even get a job
-
Erhard
Not bad for a puk kid, lol
-
Guest706
pretty impressive
-
Erhard
What are you studying?
-
Guest706
software engineering but I have my Bachelors of Engineering
-
Erhard
Nice
-
Guest706
I am on the Masters level
-
Erhard
Cool
-
Guest706
yes it`s not bad but I somehow missed the money tree I guess
-
Guest706
I`m planning on doing a project on freebsd for my course
-
Erhard
Well, if you are in school it's different
-
Guest706
I graduated 12 years ago
-
Erhard
For the BS?
-
Erhard
And now doing an MS?
-
Guest706
Bachelor of Engineering
-
Erhard
Oh, I guess that is different
-
Guest706
B.Eng. but not an engineer I was a junior engineer and now a candidate for the profession
-
Erhard
His is a BS. Software Engineering at McGill is not in the faculty of engineering.
-
Guest706
we`re apparently not allowed to write that
-
Erhard
LOL. Yeah that is regulated aparently
-
Guest706
yes not the same degree
-
Guest706
I think mine was harder and more thorough but he probably has a higher gpa than I had of 2.37 and almost 2 degrees worth of credits
-
Guest706
I could literally get a Bachelor of Arts as well<
-
Erhard
Heh. HIs wasn't amazing, but I think it was over 3.
-
Guest706
I had personal problems social and it wasn`t the right school for me
-
Erhard
Yeah, stuff happenes
-
Guest706
I needed a sheltered environment they didn`t give me that
-
Guest706
I wanted to go to mit but I wasn`t going to get a scholarship there so my family was like we can`t afford it
-
Guest706
and no need it`s better to get the degree in Canada
-
Erhard
Yeah, expensive.
-
Erhard
Especially if you live there. MCGill is cheap if you live there. We had to pay wuite a bit
-
Guest706
yes so I got through in the end
-
Erhard
around 40k US a year
-
Erhard
INternational
-
Guest706
ouch
-
Erhard
Yeah about the samne as a good school here.
-
Erhard
Not ivy league, but a good school
-
Erhard
But it's more the person anyway.
-
Guest706
yes my parents put a trust fund for me I exhausted it in 4 years then I had my grandparents die and inherited money and my aunt grandfather`s sister
-
Erhard
And who you know.
-
Guest706
and then I got major money from the government
-
Erhard
Glad you made it happen without massive debt.
-
Guest706
and then my parents helped me a little bit and the costs are generally low
-
Guest706
well I had debt but I used my grandfather`s inheritance to pay for it
-
Erhard
My parents paid for my school so I wanted to pay for my kid's
-
Guest706
like 80000$
-
Erhard
Cool
-
Guest706
and the government paid me $700 a month for my rent but it was like 1100 and tutors extreme amounts, other costs, school itself, etc..
-
Guest706
like a little bit for food $300 a month , etc..
-
Erhard
Budgeting is a good life skill
-
Guest706
so between that, a student loan, a tiny bit of side income, and parents support I was more or less covered
-
Guest706
knick knack side income in different ways...
-
Erhard
Cool.
-
Guest706
and I didn`t do anything that was too extremely lavish in any way I just went to school, did some sports like tennis, skiing would be expensive but I had it very inexpensive with no hotels
-
Guest706
rollerblading , I worked at a gym so that was free with swimming, etc..
-
Guest706
they gave me a rate that it would cost me maybe $500 a year... yoga teacher training was an expense , car was not expensive
-
Guest706
they robbed me at one place for $2000 another place didn`t really rob me at all so I paid $1000+ but I got my money`s worth
-
Erhard
heh
-
Guest706
then never found a job in the field really
-
Guest706
didn`t really make any money worked hard though
-
Guest706
cause like I made some money from Amazon but then they stole it all from me, giving me credit card debt and taxes owing so that shouldn`t count as making anything...
-
Guest706
so then I got a good scholarship to go back to school
-
Guest706
it somehow doesn`t feel like it`s worth it but I think it is I`m probably getting more exerting myself like crazy here then I would sitting at home playing on freebsd I suppose
-
Erhard
Sweet. I gotta hit the hay. Good luck on everything. Have a good one.
-
Guest706
thanks good night
-
Guest706
e
-
Ltning
How can I get unabridged thread names from procstat -t ?
-
f451
hi, can recordsize property be set on a zvol? would it be usable to the guest OS
-
V_PauAmma_V
Ltning, have you tried libxo?
-
V_PauAmma_V
(There's no other way obvious to me.)
-
f451
does zfs compression still work if the zfs was set to encrypted at initial setup?
-
nimaje
afaik zfs should first do compression and then encryption so it should work
-
f451
ok so it's done on a block-by-block basis and not at the outset
-
f451
i guess that on install, if encryption is selected, then what happens is the flag is set but it doesn't happen till it's written to?
-
f451
(just trying to wrap my head around it)
-
meka
f451: I have ZFS with GELI encryption and ZFS compression. That way GELI is "under" ZFS. With ZFS native encryption, I'm almost sure it's compression first, encryption later (I didn't read the code, so don't trust me on this)
-
debdrup
-
VimDiesel`
Title: src - FreeBSD source tree
-
f451
meka: tyvm
-
debdrup
f451: zvols use volblocksize iirc
-
debdrup
see zfsprops(7)
-
f451
yeah that is neat ;)
-
f451
what the context is, is bhyve
-
f451
the compression context is the host zvol
-
f451
the encryption one, the guest
-
debdrup
zfs in-line compression happens at a record level, not at a block level
-
debdrup
and it'll only happen if it can compress by at least 12.5% (at least with lz4, which is the default)
-
f451
was going to go with zstd
-
debdrup
plus it needs to save at least one sector size of diskspace, otherwise it also doesn't help
-
debdrup
the lz4 early abort doesn't exist for zstd (not in a release, yet - but it might be in head; i watched a presentation about it being developed the other day)
-
f451
aha
-
debdrup
-
VimDiesel`
Title: Refining OpenZFS Compression by Rich Ercolani - YouTube
-
f451
compression in my context is the lesser value
-
debdrup
-
f451
the guest will be a nextcloud in a datacentre so encryption is important
-
VimDiesel`
Title: OpenZFS open encryption bugs (public RO) - Google Sheets
-
f451
oog
-
debdrup
remember that encryption (both GELI and ZFS in-line encryption) is only useful at-rest, so typically when the server is powered off
-
f451
not the guest only?
-
debdrup
well, that depends i guess
-
f451
what im trying to guard against is the host getting broken into and someone accessing the guest vm data
-
debdrup
if you've got a bhyve guest and encryption is used inside the hypervisor guest, it'll theoretically be at-rest (although depending on how your key invalidation works, a sufficiently motivated attacker could do host persistence and still access it
-
debdrup
GELI does proper key invalidation if memory serves
-
f451
was about to say
-
f451
also within the nextcloud itself, there is an addon available that encrypts the live data and ties that key to auth credentials i think
-
f451
hmm
-
debdrup
i'm not sure i'd put my trust in that
-
f451
so geli is the way to go it seems
-
f451
no - it doesn't encrypt the filemames funnily enough
-
f451
what the threat model is, is protection from gaining of unauthorised access
-
debdrup
GELI works at a different level; once something is encrypted with GELI and the key hasn't been used to unlock it, it just looks like a block of random data
-
debdrup
GBDE more so
-
f451
one is newer than the other isn't it
-
debdrup
GELI is newer
-
f451
big scary notice for gbde on the man page!
-
f451
i think gbde prob more suitable for a shell account where eg you have a dir with all yr credentians in that you want to keep secret
-
f451
s/credentians/credentials/g
-
f451
ok - think i know how to proceed
-
f451
debdrup: tyvm
-
debdrup
gbdes real advantage is that it's made for an adverserial environment where, as long as you can access the system before you're subject to rubberhose cryptoanalysis, you can use `gbde nuke` to provably get rid of it
-
debdrup
err, `gbde destroy`
-
debdrup
-
VimDiesel`
Title: GBDE - GEOM Based Disk Encryption :: FreeBSD Presentations and Papers
-
f451
thanks
-
f451
the environment this is for isn't adversarial like that
-
debdrup
for what it's worth, i used gbde for my buttcoin wallet back when that waste of electricity was possible to mine on a regular cpu, and then proceeded to forget the keyphrase, and i haven't been able to recover the key, even after talking with phk :P
-
f451
it's to protect against casual cracking/what if php/nginx/mysql/postgres breaks
-
f451
ahhh
-
f451
sorry to hear that
-
debdrup
eh, it's whatever
-
f451
you might be a theoretical millionaire
-
f451
xkcdpasswd is your friend
-
debdrup
meh
-
debdrup
the password had some 280 bits of entropy, so there's almost no way of remembering it no matter what
-
Ltning
V_PauAmma_V: Yeah, and just like with various other tools, output is truncated before it's even handed to libxo.
-
Ltning
(yes, it's pretty stupid, but apparently much harder to fix than one might think)
-
f451
debdrup: xkcdpass -d . -C random -n 10
-
f451
Charsetsize: 84
-
f451
ShannonEntropyBits: 400.36
-
debdrup
and how's that supposed to help me if i forget the password?
-
f451
that's a horse already bolted context
-
f451
i mean in future ;)
-
debdrup
i'm not interested in destroying the world by wasting electricity like that
-
f451
yup
-
f451
ive never been into it
-
f451
might be ameliorated using solar in a sunny climate
-
f451
make a fortune in the desert ;)
-
f451
the reason i posted the xkcd thing was that 10 words with dots and capitals have 400 bits of entropy and it surprised me, just 10 words
-
tao
it's supposed to be random unrelated words though. and good luck remembering 10 unrelated random words easily
-
tao
4 or 5 words is more likely
-
f451
i think if one can devise a silly story (the sillier and therefore the more rememberable) that links all the words in the order they should be in, then one would be able to remember them easier than expected
-
f451
i mean actors memorise whole screeds of text
-
tao
yes but the words are not meant to be linked to each other in anyway as that reduces the keyspace. if you do a story where a horse goes into a stable and make the words horsewalksstable an algorithm could work that out far more quickly than the horsebatterystaple
-
shiroyasha
People memorize Pi to I-don't-know-how-many decimals.
-
tao
it'll probably put you off ever changing the passphrase too
-
shiroyasha
10 completely random words sounds doable.
-
f451
the linking doesn't have to be logical in the understood sense. it just needs to be internally logical, in your mind. you get to choose the logic
-
tao
i do have a 64 character wifi password, because that mitigates brute force, that's made out of about 7 words and I can remember that to be honest. so maybe it's not so bad
-
debdrup
Memorizing pi means you're doing it regularly. I forgot the wallet passphrase because I didn't use it for several years.
-
debdrup
You're applying technical solutions to a problem that isn't technical in nature.
-
jafa
hi guys, does bsd have a concept of a tmp file (discard on close) that will use ram as much as possible and only write to disk if low on ram?
-
gman999
try `man 5 tmpfs` maybe?
-
jafa
tmpfs looks plausible - thanks
-
lisu
hi, anyone can help me with zpool import?
-
lisu
zpool import Segmentation fault (core dumped)
-
lisu
just zpool import (without name) and I got seg fault
-
lisu
anybody?
-
tsoome
lisu are you sure your kernel and userland bits are from the same build?
-
nimaje
jafa, (gman999): note tmpfs will at most use swap, depending on what you want mmap, memfd_open and shm_open are options
-
gman999
yes, tmpfs hungry
-
lisu
tsoome: init6 does the job, TY.
-
tsoome
:)
-
lisu
another question: can I mount btrfs under fbsd?
-
lisu
I just intalled fresh fbsd on baremetal and I need to transfer files from zfs to btrfs disk.
-
ravella
I finally figured out how to have a bhyve linux guest with audio on host, now I can stream widevine drm content without linuxulator :o
-
debdrup
jafa: check out mdmfs(8)
-
crest
lisu: unless you already have lots of data locked in a btrfs there are no good reasons to mount btrfs into freebsd
-
crest
but there is the fusefs-lkl package that may include what you're looking for
-
crest
it basically runs a stripped down linux kernel in userspace as fuse server
-
crest
but it's based on a fairly old kernel
-
crest
-
VimDiesel`
Title: FreshPorts -- sysutils/fusefs-lkl: Full-featured Linux BTRFS, Ext4, XFS as a FUSE module
-
lisu
yep, I readed this. thx. So ... freebsd is not so universal.
-
lisu
for now I got installed openzfs on manjaro, works well, this will do the job.
-
debdrup
linux doesn't support ufs, so it's not universal either - and ufs is both actively developed and dates back to 1980
-
lisu
true,
-
debdrup
nfs is the filesystem du jour for transferring between unix-likes, and linux doesn't support that properly either (no NFSv4 ACL support, and nothing is planned)
-
lisu
beside, as I got freebsd on ma laptop, Im will try to use this for my daily.
-
debdrup
that's a good start :)
-
lisu
freebsd is very well documented, but for example, I want to manage few wifi networks via gui... and networkmgr is compiling for 20 minutes...
-
ravella
the ghostbsd wifi manager? I think it is just a python script, what could it be compiling?
-
lisu
fbsd is similar to linux i've used to, but have own way to do simple things realy strange
-
lisu
-
VimDiesel`
Title: FreshPorts -- net-mgmt/networkmgr: FreeBSD/GhostBSD network connection manager
-
lisu
im installing from ports
-
lisu
now python 3.8 is building
-
ravella
ah, yeah Python sounds like a likely culprit
-
ravella
ports is kind of overkill for a newish user, but could be a good learning experience too
-
lisu
ports is nothing fancy, just another way to install
-
ravella
one good-kept secret is `bsdconfig networking` (surprised I didn't see it mentioned in the handbook), it's a simple tui-based wifi manager
-
ravella
I believe it is similar to the network selection that happens during system install, if not the same exact thing
-
» _xor notices that the RealTek(TM) driver is still...shakey
-
_xor
Heh, didn't know about net/realtek-re-kmod.
-
debdrup
question is, why are you building p orts instead of using packages?
-
lisu
so far so good, I got netmgr, but no wifi ...
-
lisu
installing from ports make error 1.... python got problem with somethink like pycairo/py3cairo.h... so... I got it from pkg.
-
lisu
works
-
lisu
now wifi drivers...
-
lisu
bsdconfig wireless -> very nice
-
ravella
I was annoyed that the 13.1 installer couldn't detect any networks, but if I dropped into a terminal afterwards and set it up manually it was fine
-
ravella
yeah, not sure why bsdconfig was removed from the handbook, it used to be mentioned in the installation section
-
ravella
I found it on an obscure fbsd user wiki page
-
lisu
init 6... and we will see what ive done ;)
-
lisu
nice, detecting wifi network, but cannot connect
-
ravella
lisu: can't connect in what sense? dhclient issues? Can you ping the gateway?
-
lisu
it looks like link connected, but dhcpdiscover gives time out, no dhcpoffers received...
-
lisu
strange, I got at least 3 wifi clients connected
-
ravella
is it an unprotected network?
-
ravella
I had an issue in a coffee shop a while back, although I think that bug was patched
-
lisu
this is wpa2-psk aes home network
-
Kalten
lisu: might it be, that you have limited the number of clients that may connect the dhcp server (disconnect another deviece first) or that the Mac adresses is not allowed in the dhcp server?
-
nacelle
probably typoed key
-
lisu
this is not a limit of my access point client, belive me.
-
lisu
key_mgmt=wpa-psk or wpa-psk2 ?
-
lisu
wrong way
-
ravella
I think wifi & driver issues would be solved in a week if we just donated coffee shop gift cards and laptops to all the devs :D
-
lisu
belive me... they will drink this coffee, and ...drink... and drink, and they say: this is more complicated than we think... ;)
-
lisu
just kidding
-
lisu
wlan0 ..... no link giving up.
-
lisu
i know
-
lisu
init 6
-
lisu
it will help ;)
-
lisu
nope
-
lisu
1 character missed in wpa_supplicant, but still somethink is strange about that wifi driver
-
lisu
but i must admite: freebsd is quite fast on my obsolete hardware
-
nacelle
attaching without anything else when you have the wrong key is normal
-
nacelle
you dont get to actually be on the network, but your client will try to transmit with that key anyways
-
lisu
failed to reach wpa_supplicant: wpa_cli(8) ping failed
-
lisu
what the hack?
-
lisu
I think, I know what is going on.... antenas in this laptop are disconnected... I forgot. Wifi works now. I was searching in software, but hardware wasnt right.
-
lisu
OK, have a nice day/night whatever. Thx for tips.
-
lisu
bye
-
Kalten
ROTFL ;-)
-
ravella
that's why every troubleshooting guide ever starts with "did you check the power?" :)
-
ravella
it's hard to fix a hardware issue in software
-
wr
best distro OS to use on a NAS?
-
Erhard
TrueNAS
-
Erhard
(which is modified FreeBSD)
-
dkeav
FreeBSD
-
dkeav
(which is unmodified FreeBSD)
-
Erhard
;-)
-
dkeav
cut out the middle man ;)
-
Erhard
Dunno, TrueNAS makes it very convenient, esp if you want a backup box. You can do it all manually yourself of course.
-
Erhard
I used to do it myself, but really been liking TrueNAS lately.
-
wr
dkeav, can i use it on a sinology?
-
dkeav
no that i know of
-
Erhard
Synology has its own OS.
-
Erhard
It's decent.
-
wr
dkeav, what do you think of OpenMediaVault?
-
dkeav
never heard of it