-
goonmorning
I found that my vnet jails can have access to the internet just a short moment I add external interface into the bridge of vnet jails. What could be the issue?
-
goonmorning
I am trying to give them all internet access
-
goonmorning
I can see my nat working for the short moment only
-
goonmorning
more precisely, it allowed first 20 pings
-
goonmorning
should I just make a weirdly working vnet jails system whose bridge is unplugged and unplugged every some seconds
-
ivy
i wonder what is going on here:
le-fay.org/tmp/30d/shutdown.txt - i've seen this on a lot of systems, random processes get SIGSEGV during shutdown for no apparently reason, it feels like a bug
-
kevans
ivy: it sounds familiar, but I'm trying to remember why
-
ivy
kevans: oh god are you going to make me fix another one of your bugs
-
kevans
not my bug :-p
-
kevans
for some reason I thought we migrated to cpu 0 and went single thread before that point in shutdown/reboot, but I seem to be hallucinating that
-
ivy
this is (still) under Xen fwiw and i know Xen is a bit weird
-
ivy
but i'm sure i've seen it on native amd64 system
-
ivy
kevans: there may be something else going on here (with wg), the system boots with ipv6-only kernel but won't authenticate kerberos clients over the wireguard tunnel even though BGP seems to come up okay...
-
ivy
i suspect this might be a configuration issue though
-
xxy
i install node.js from ports according tutorial:
docs.vultr.com/how-to-install-node-js-and-npm-on-freebsd-14-0, then in "make install" stage, it prompt error"
paste.centos.org/view/3e57ce96", should i build a empty file with name "metadir.node22"?
-
xxy
or there are other methods to fix this ?
-
kevans
ivy: hmm, that's weird
-
ivy
i may actually sit down and debug this now because this shouldn't be happening
-
ivy
oh hah
-
ivy
remote-control:
-
ivy
control-enable: yes
-
ivy
control-interface: 127.0.0.1
-
ivy
control-interface: ::1
-
ivy
apparently this makes unbound refuse to start
-
goonmorning
my vnets can have internet access until I get a message: kernel: arp: xx:xx:xx:xx:xx:xx is using my IP address 10.xx.xx.1 on bridgefoo
-
goonmorning
where might have been configured funny here?
-
jauntyd
two or more machines are using the same IP address probably
-
goonmorning
hmmm
-
rwp
How are you assigning addresses to the jails behind the NAT?
-
goonmorning
-
goonmorning
I was given the second nic with the private ip 10.0.48.1 for the instance
-
goonmorning
sorry it is 10.0.48.10
-
jauntyd
what is the first NICs IP?
-
goonmorning
10.0.12.155 and 10.0.14.35
-
goonmorning
i need two ips for fib0
-
jauntyd
is this at a service you're renting?
-
goonmorning
aws
-
jauntyd
oh
-
goonmorning
si
-
jauntyd
i'm going to step aside because idk if it is smart to change the bridge or router
-
jauntyd
sorry i couldn't help more
-
goonmorning
please enlighten me in both scenarios
-
jauntyd
i would say the safe option is to change the bridge ip
-
jauntyd
hmm
-
goonmorning
I am a veezual learner. Can you show me some example?
-
jauntyd
-
jauntyd
you can restart networking with reboot: "service netif restart && service routing restart"
-
jauntyd
without*
-
jauntyd
goonmorning: are you alive?
-
goonmorning
yes and
-
jauntyd
>.<
-
goonmorning
hmm
-
jauntyd
did anything blow up?
-
goonmorning
it didn't work. Unfortunately didn't blow neither up.
-
goonmorning
I feel I have skipped too many pages of books
-
goonmorning
jauntyd it works!
-
goonmorning
thanks you
-
jauntyd
I'm going to find a paper bag
-
jauntyd
you're welcome
-
goonmorning
I don't need to go back to read. I am so happy
-
jauntyd
is this your first experience with FreeBSD?
-
radhitya
FreeBSD srv 14.0-RELEASE-p6 FreeBSD 14.0-RELEASE-p6
-
radhitya
\o/ i'm happy with freebsd
-
radhitya
i'm currently running email and shared computer with that
-
jauntyd
excellent!
-
radhitya
`shell`
-
radhitya
i mean that
-
radhitya
thank you, jauntyd
-
jauntyd
welcome
-
ivy
radhitya: you should probably upgrade as 14.0 is EOL :-d
-
jauntyd
^
-
radhitya
ivy: ah thank you
-
radhitya
let me try
-
ivy
14.s is current
-
ivy
er, 14.0
-
ivy
er
-
ivy
14.1
-
ivy
damnit
-
jauntyd
hehe
-
ivy
typing is hard
-
jauntyd
I've never made a mistake ;)
-
radhitya
ok, wish me luck :)
-
jauntyd
good luck hombre
-
goonmorning
jauntyd: it is my first infra
-
radhitya
freebsd-update fetch
-
radhitya
src component not installed, skippesadasdasad
-
radhitya
wish me luck
-
ivy
radhitya: fwiw, X.0 release usually have a slightly shorter support period than other releases
-
goonmorning
I think eating own dog food is not so effective if you don't use for work
-
goonmorning
I will be back once I get stuck
-
goonmorning
have all good days
-
kevans
ivy: huh?
-
ivy
kevin: huh what?
-
ivy
is that not true anymore?
-
ivy
i'm sure it used to be
-
kevans
not supposed to be, no
-
ivy
hmm
-
kevans
it would be fair to say that the status quo up until recently has been that the schedule's been fairly chaotic and that may have accidentally been the case, but with a five year branch lifetime you should've been seeing roughly one a year
-
kevans
the new policy offers a vast improvement where we have more firm release targets
-
kevans
s/targets/target dates/
-
ivy
just looking at
en.wikipedia.org/wiki/FreeBSD_version_history#Version_history it seems like it was, but maybe that wasn't intentional
-
kevans
I can't speak for anything before 11.0 personally
-
ivy
(e.g. 6.x, 7.x)
-
kevans
11.x or 10.x was where the five-year stable branch model was enacted, IIRC, and 10.4/11.0 are the first releases I was around for
-
ivy
ah i may be remembering something from before then
-
kevans
yeah, I see 9.x was pretty wild. 10.x was kind of approaching our just-ending cadence
-
ivy
fricking zoomers, it was better when X.0 release was only supported for 3 days, etc. etc.
-
kevans
=D
-
ivy
also i never remember having a wireguard crash on 3-STABLE just fyi
-
ivy
(remember when you had to run -stable to get security patches? then they introduced this newfangled 'p1' stuff)
-
kevans
no i'm young
-
ivy
we should just ditch these release and make main a rolling release
-
ivy
formalise stabweek
-
ivy
so much less effort doing MFCs and stuff
-
kevans
there's already some wanting to move towards even greater reduction in what we MFC
-
ivy
not that i have a vote, but i'd be in favour of that
-
kevans
i think it'd be good for perception, right now I think people expect us to MFC a lot more than we do and there's some wild inconsistency from committer-to-committer in their own personal MFC policy
-
ivy
the other day i got a notification that someone MFC'd my netstat -W patch
-
ivy
ok it's a cool patch and everyone loves it, phoronic was literally demanding this be backported because stable/14 is unusable without it, but i wonder if this is really true
-
kevans
if the policy is to MFC much less, then we're not disappointing people as much when we just want to keep the branch stable
-
ivy
perhaps people could wait until 15.0 to have better netstat
-
kevans
oh, phoronix thought it was a good idea? must've actually been a terrible move :-)
-
ivy
the way i see it, main is so stable nowadays that everyone is running main
-
ivy
Netflix runs main, right?
-
ivy
so there's really no real reason to have older tags at all other than to say "this is a version of the OS we think is stable"
-
kevans
yeah, but they also have a really excellent engineering team to smooth operations over if they have problems
-
» kevans has no opinion but tends to lean towards stable personally
-
ober
their use case may not cover everything
-
ivy
just tag main once a year and call it 15.0, 16.0, 17.0, etc
-
ivy
if any bugs come up, MFC those and call it 15.0.1
-
ivy
i bet this would make it *easier* to support older release for longer because you're not dealing with so many divergant branches
-
ivy
+ more people using main means more stable releases in the future, more testing, etc
-
kevans
i think it's a lot easier to make this argument with pkgbase on the horizon
-
ivy
can you just vote me into core@ and i will make this happen
-
kevans
i don't want to do source-based upgrade of a fleet. freebsd-update-server is kind of a pain to setup, but pkgbase is damn near trivial to deploy
-
ivy
oh yeah i've been using pkgbase forever i forget that's not standard sometimes
-
kevans
yeah
-
ivy
but it will be by 15.0 release right? :-d
-
kevans
I started in *checks notes* late 2016
-
ivy
we could just make pkgbase base and rename the entire project to PkgBSD and then release PkgBSD 1.0
-
ivy
follow me for more excellent releng ideas
-
kevans
ma'am this is RebuildLLVMBSD. please step off with your renaming ideas.
-
» kevans launches tomatoes
-
kevans
it's a good thing this isn't a venue for strictly professional discussion
-
ivy
god i try to contribute and you throw tomatoes at me, this is why BSD is dying
-
kevans
=D
-
kevans
okay, i've got to go snore. o/
-
ivy
wow now you're saying i'm so boring i send you to sleep
-
ivy
enjoy your life, kevin!
-
ivy
god this has upset me so much, i have to go downstairs and find more vodka
-
ivy
look upon me and despair, freebsd community, for this is what thou hast wrought
-
radhitya
ls
-
radhitya
eh sorry
-
jauntyd
hi radhitya
-
goonmorning
hello
-
|cos|
morning,
-
goonmorning
I have two vnet jails and only one has internet access via a bridge. What could be the issue?
-
goonmorning
I just tested with three vnet jails and it is only the first vnet jail who can i have an internet access
-
goonmorning
os is stable but a programmer can use it unstable ;0
-
xxy
my sound card Realtek ALC662 have large noise, can i change sound device to Nvidia device ,
paste.centos.org/view/03d2d215, if it can , how to do it
-
ei
xxy: try sysctl hw.snd.default_unit
-
istevenmon
has anyone tried using openiked for simple ipsec vpn? Even though the config file syntax is OK I seem to be missing something, when I start the daemon I get this error and I don't see any connection request being generated: udp_bind: failed to bypass IPsec on IKE socket: Protocol not available
-
istevenmon
ha! the ipsec module was not loaded in the kernel :')
-
f451
kevans: i thought this was RebuildRustBSD ;)
-
zBeeble
evil thought: if web assembly runs clang/llvm now, how long until we can boot FreeBSD in Mozilla.
-
rwp
People can boot a Linux kernel there now. So when someone does the work to set it up for a FreeBSD kernel then it can be done.
-
johnjaye
zBeeble: i did that yesterday. copy.sh/v86
-
goonmorning
morgen
-
debdrup
johnjaye: well that's slightly terrifying :D
-
johnjaye
heh. honestly i just wanted to look up a manpage. which i could probably have just done from the website anyway
-
nsoci
hi. does anyone using luakit browser? How safe/secure is to compare to firefox, please?
-
debdrup
i wonder how these questions end up in #freebsd
-
mns
inside of a jail, what is the accurate way of determining the version of FreeBSD being used?
-
futune
is there a problem with freebsd-version?
-
mns
I created the jail using bastille, so I was thinking it would be 13.2-RELEASE-p8, but uname returns 14.1-RELEASE-p5, as does freebsd-version -r
-
futune
I just tested in a 13.3 jail on a 14.1 host, it returns correctly
-
mns
freebsd-version -u returns 13.2-RELEASE-p8
-
mns
futune: freebds-version -ur return the same values for you?
-
mns
*freebsd-version
-
futune
with -ur it returns 14.1-RELEASE-p5 on the first line and 13.3-RELEASE-p4 on the second line, which are the correct versions for host and jail
-
futune
I guess the first line might be kernel? It's the same as host, in any case
-
mns
ok so jail version should be -u and host is -r.
-
mns
-k would be kernel and you can't get that inside a jail
-
futune
indeed, can confirm
-
mns
so I can't use uname -a, I have to use freebsd-version -u when trying to determine the version of a jail
-
mns
thanks for confirming. I thought I was doing something wrong. This is the first time that my jails and host OS are not the same OS
-
mns
or rather, not the same OS version
-
futune
no problem, hope your project goes well
-
debdrup
uname is derived from a sysctl, so no it won't work for the userland, as sysctls come from the kernel