-
nimaje
did you check that it isn't just your browser giving you a cached image instead of making that request?
-
dvl
nimaje: I'm seeing the request arrive in the logs.
-
dvl
Also tried appending ?things to the URL
-
zilti
So, I started again from the Bastille example pf.conf and ended up with this:
termbin.com/4xh5 I don't get why this prevents my machine to reach tty login or start sshd.
-
dvl
zilti: It does not start sshd?
-
zilti
dvl: I mean, I have sshd_enable=YES. But as soon as I set pf_enable=YES and reboot, the machine will get stuck somewhere in the boot process after activating the network. No tty login prompt on the machine itself shows up, nor is it accessible over ssh
-
dvl
zilti: might be dns related, how long do you wait?
-
zilti
dvl: definitely not dns related, no amount of waiting fixes this
-
dvl
ouch
-
zilti
(yes, before identifying what causes this, I indeed let it be stuck in the boot process for 12 hours)
-
zilti
So it's nothing in the pf.conf?
-
zilti
Here's additionally my rc.conf:
termbin.com/my1y
-
cyric
zilti: press ^T and check where it's stuck?
-
zilti
cyric: Would that be Ctrl+T? I can't send these kinds of keycodes to the console. But the last thing it shows is "Security policy loaded: MAC/ntpd (mac_ntpd)".
-
cyric
yes, control-t which sends SIGINFO and should show you the current process running
-
cyric
other than that, you could try enabling rc_debug in rc.conf
-
zi
zilti: enable logging in pf.conf, setup pflogd, reboot, wait for breakage, examine log, profit
-
zilti
zi: okay. I enabled pflogd. Where do I put the logging statement in pf.conf?
-
zilti
-
zilti
It seems s3backer that is running on my server is getting blocked, as well as ntp, but I have a "pass out quick keep state"
-
zi
zilti: man pf.conf, search for log
-
zilti
zi: I can't put log on the "block" statement. PF complains when I try that.
-
zilti
Okay. Seems my pf config blocks all outgoing traffic.
-
SponiX
reminds me that I need to play the pf game again myself
-
SponiX
not feeling it tonight though
-
zilti
So, no idea how to allow outgoing traffic. That rule used to work, now it does not.
-
SponiX
but yeah, pretty sure pf default is "deny all" and you have to write rules on what to actually allow/pass
-
SponiX
when I was tinkering with pf my router was having problems. So I was setting there beating myself over pf rules when they might not even have been the issue
-
zilti
They definitely are here, though. When I turn on pf on the running machine, outgoing traffic stops to work. Stopping it makes it work again. I tried half a dozen variants on "pass out". "pass out all", "pass out keep state", "pass out all keep state", "pass out on $ext_if", "pass out on $ext_if keep state", all of them with and without "quick".
-
zilti
Nothing works.
-
zilti
...so, is there a solution to this, or is this a breaking bug in PF?
-
SponiX
what branch are you on?
-
makr
is there a way to run a one-off command in a sandboxed way?
-
makr
eg. letting it access only certain places on the filesystem
-
nimaje
capsicum or jails
-
makr
is there a capsicum utility?
-
makr
something like `capsicum-run prog`
-
ivy
makr: i've wished for this before, but i've never found such a thing. i did find a research paper discussing a prototype of it, but it didn't come with source code...
-
jemius
Morning. Is there any interest in adding the QUIC network protocol to the FreeBSD kernel? Some folks are working on that for Linux
-
antranigv
makr Jails would make more sense, and you can do that with the jail command if needed.
-
ivy
jails are not really ideal for sandbox a single command (although you can use them for that), we do need a better solution here
-
ivy
like, i don't really want to spawn a new jail just to run elinks every time i render an HTML email in mutt
-
dch
ivy: thee is somr prior art here, gimme a few minutes to find it
-
dch
aah yes val did some (awesome) work on this already
github.com/valpackett/capsicumizer
-
ivy
ah, i think i've seen this before but never got around to trying it - i wonder why it's archived
-
dch
ivy: IIRC val moved to codeberg & argentina
val.packett.cool reach out and ask
-
ivy
if this works it would be nice to have it in base :-)
-
dch
if you (or val ofc) is interested in picking this up I'm sure there would be a lot of interest
-
dch
and help too
-
ivy
i have enough stuff in progress at the moment i'm running out of disk space for source trees, but i will add it to my ever-expanding todo list :-)
-
» dch knows the feeling
-
makr
I found this talk too by Ryan Stone demoing a tool called caprun -
youtube.com/watch?v=TGA4wbjbqXc
-
makr
i can't find the code though
-
leah2
i use the repo pkg+https://pkg.FreeBSD.org/FreeBSD:14:amd64/latest but i can't find newer go than go121, shouldnt up to go124 be available there?
-
vkarlsen
leah2: Looks like there's a problem with it:
portsfallout.com/fallout/1116443
-
leah2
ah!
-
vkarlsen
I guess it didn't go
-
leah2
hehe
-
CrtxReavr
Where does the named ports store the hints file?
-
CrtxReavr
Nevermind.
-
n|Phreak
oh next to nim binary ?
-
n|Phreak
or nimble binary
-
n|Phreak
since the path is /usr/local/bin/nimble I have the cacert.pem in /usr/local/bin/
-
thorongil
hi there. i'm running 13.4-RELEASE-p3. an update was released, and i ran freebsd-update fetch and then freebsd-update install. the latter spit out a few errors: "install: ///usr/src/secure/caroot/blacklisted/INS@LId18q: No such file or directory" and three other files. is this something to worry about?
-
llua
Hey, i am trying to use texi2dvi but it throws an error about not finding a `tex' binary.
paste.rs/i69cB
-
llua
i have the package texlive-base installed but it doesn't provide a tex binary either
-
vortexx
rwp: you may or not recall I had an external usb drive having issues, I finally got round to fishing out a s-ata cable and testing the drive directly, it is still working luckily. Just need a new usb enclosure
-
llua
apparently tex is in tex-basic-engines
-
jbo
any wine experts around?
-
ivy
would a cider expert do?
-
jbo
potentially
-
jbo
I'm trying to run factorio under wine. I had that working a few months back
-
jbo
now this (new/different machine):
paste.jvnv.net/view/I5hQr
-
jbo
fairly sure that factorio.exe is a 64-bit executable
-
jbo
can't even run winetricks:
paste.jvnv.net/view/4fZ4B
-
that_lurker
does the native linux version not work on freebsd?
-
jbo
no idea, never tried
-
dvl
Anyone running zfsd? Did you do anything in particular to configure it? I just added my first hot-spare to a zpool.
-
ivy
dvl: noooooooo don't use hot spares!!
-
ivy
dvl: keep a cold spare or at least an online device not attached to a pool. otherwise your zpool will randomly decide to attach its hot spare due to a temporary cabling issue or something like that
-
ivy
the only reason you need a hot spare is if you're sending a system to Antarctica and literally can't monitor it or log in to replace a failed disk with the spare
-
dvl
-
ivy
dvl: sure
-
dvl
ivy: thanks, please reload.
-
ivy
i'm not sure the way you've quoted it adds anything to the content, but ok :-)
-
dvl
OK, with that, it's time for off-computer stuff. Later. Thanks again.
-
cyric
dvl: there's better reasoning at point 12 here:
nex7.blogspot.com/2013/03/readme1st.html
-
mzar
dvl: I have not hot spares, but responded on the media
-
mzar
anyway, zfsd could be handy
-
ivy
oh, was there any disagreement with my advice to not use hot spares? i assumed this was simply common knowledge nowadays
-
mzar
I don't know; who objected ?
-
mzar
I like to reason with dvl on the media, but I am still missing TechSnap series where he was the host
-
ivy
mzar: i don't know, but i have the impression dvl was not taking my suggestion seriously. which it was meant to be even if i phrased it in an IRC-like way
-
ivy
there is basically zero to ever use a hot spare in a modern storage environment except in very unusual circumstances
-
mzar
yep, at some point you stop to take all the suggestions seriously ;-)
-
rwp
It does seem that, say, if someone were to use a hotspare with raidz1 then instead raidz2 is preferred. And if someone were going to use a hotspare with raidz2 then raidz3 is preferred.
-
ivy
rwp: i think there's a more persuasive argument for using hot spares with mirror-stripes, where you can't just "add another disk", but i don't think it's a good argument because asking the system to make an objective assessment of its own state is just never going to be reliable
-
mzar
what about cold spares ? aren't they useful ?
-
ivy
yes, cold spares and/or warm spares are very useful and everyone should have those
-
mzar
keeping your spares cold is 100% conformant with the paradigm of green computing
-
ivy
well, you can have a 'warm' spare that you keep powered down if you're concerned about that
-
ivy
the power use of a single is pretty minor though, in most systems which are likely to care enough about their data to have sparess
-
ivy
s/single/single disk/
-
mzar
but you can always hotplug cold spare, it's what hotswap was invented for
-
ivy
yes, but you need physical access to that, so whether you use cold or warm spare depends on that
-
rwp
dvl, If you search for "sudo sudo" in that article you might make an edit as that seems to be a sudo too many. :-)
-
mzar
good point, I believe that dvl still has this access ?
-
rwp
It's his other diary, so yes. :-)
-
rwp
Keeping the hotspare warmed up also adds spinning hours to the drive the same as the other drives. Now maybe that does not matter at all if the head remains parked. But the simple measure of using power on hours to determine aproximate age of the drive is fuzzier in that case.
-
rwp
I have this vision of somehow keeping a stack of storage devices in a box magazine such that they are available and ready to be inserted into a system on one side of it while another device removes failed drives from the other side.
-
mzar
agreed, so we can draw the conclusions for dvl: running zfsd could be useful anytime, but you'd better keep your spares cold
-
ivy
mzar: i disagree, running zfsd is never useful, use warm or cold spares instead
-
ivy
that is the point i was making originally
-
mzar
ivy: zfsd could be handy if the children have access to hot swap bays and randmoly replug the drives
-
ivy
a rifle might be more useful in that situation
-
mzar
how so ?
-
ivy
shoot the children, problem solved
-
rwp
But then there is the Hansel & Gretel rebuttal.
-
mzar
that's against the spirit of this channel, in the past debdrup or koobs banned for weeks for such the suggestions ivy
-
ivy
if the children shoot you, the problem is also solved, in that you no longer need to worry about your disks
-
mzar
good night
-
rwp
Let's move on to happier topics.
-
debdrup
I'm wondering if people are using zstd to its fullest effect? Admittedly it does require you to use SAS enclosures with SES, and have autoexpand and autoreplace enabled as well - but if setup properly, zstd allows you to pull out a drive, insert another drive, have the zpool automatically replace the old vdev with the new one, and once you've done that with all the disks in a vdev, the vdev will expand.
-
nimaje
what has zstd to do with autoexpand?
-
debdrup
s/zstd/zfsd/
-
morpho
does freebsd work on any SBCs
-
morpho
looking for recommendations to be honest, something with opengl or vulkan drivers would be great, if somebody knows of something like that