-
cyric
polarian: same as what buildworld builds, use src.conf(5), delete-old target is also aware of these settings
-
centrix
I consider installing freebsd as a host OS. How is the support for Win 11 + SecBoot + swtpm as a VM in FreeBSD?
-
centrix
It is crucial for me. If complicated I install Ubuntu/Debian instead.
-
nimaje1
should work fine by adding -l tpm,swtpm,/path/to/tpm.socket to the bhyve command line
-
centrix
nimaje1, "should" - thanks for paying attention, but I need to know 100% for the Wion 11 source is a company image. There's no room for casual deactivation of the SecBoot and/or tpm2 bypass.
-
centrix
A college of mine installed in Ubuntu with no problems. As I like freebsd I'd rather opt for the BSD, but if I have no choice ... Debian.
-
nimaje1
you probably have to test that yourself
-
centrix
nimaje1, I am. Thanks.
-
LXGHTNXNG
= ^
-
armin
-
Afterglow
did already: up 2 days, 7:27
-
armin
Afterglow: 👍
-
polarian
cyric: ah never heard about src.conf(5) thx
-
polarian
ooo you can really strip down your install with this
-
polarian
so for the syntax of src.conf, with/without values are ignored, so its just the environment variable without = and a value, separated by newlines?
-
mzar
polarian: how are you checking it ?
-
polarian
mzar: wdym
-
polarian
> The values of WITH_ and WITHOUT_ variables are ignored regardless of
-
polarian
their setting; even if they would be set to “FALSE” or “NO”. The
-
polarian
presence of an option causes it to be honored by make(1).
-
polarian
sorry I didnt strip the newlines :/
-
polarian
thats what I am referencing
-
polarian
so take WITHOUT_ACPI
-
polarian
do I need to set a value, as its ignored anyways
-
mzar
WITHOUT_ACPI=yes WITHOUT_ACPI=YES WITHOUT_ACPI=1 WITHOUT_ACPI=OK - this all should work
-
mzar
polarian: do you expect it to be broken ?
-
polarian
mzar: so you need to set a value but the value is ignored
-
polarian
the man page is not very specific about thisd
-
mzar
yep, that's how it's been working since ages
-
mzar
WITHOUT_ACPI=NO could be really misleading, so it's not recommended setting ;-)
-
mzar
#WITHOUT_ACPI=NO - that's OK
-
polarian
mzar: alright I assume 1 works too
-
polarian
1 and 0s
-
polarian
shorter to type
-
cyric
WITHOUT_ACPI= is even shorter :)
-
polarian
cyric: so you dont NEED a value then?
-
polarian
ffs this is confusing as fuck
-
polarian
the value is ignored right?
-
polarian
WITHOUT_ACPI is invalid I assume
-
cyric
correct, you don't need a value, only to set the variable
-
polarian
WITHOUT_ACPI= is then valid?
-
polarian
so as long as you have the = its fine?
-
cyric
yes!
-
polarian
alright thanks
-
polarian
I dont know why this has confused me so much
-
ghodawalaaman_
Hello
-
delgnam
Hi folks, trying to install freebsd on a desktop that I have, checked sha512sum is okay; copied it onto a ventoy drive, can't boot into the installer
-
delgnam
Mounting from cd9660:/dev/iso9660/15_0_RELEASE_AMD64_CD failed with error 19
-
ghodawalaaman_
delgnam: you are supposed to use mini-stick img
-
wavefunction
hah. Watching a 900GB tar assemble on a platter disk... I'm about 20% done and it's been an hour X-D
-
cavokz
wavefunction a new Netflix series? :)
-
delgnam
also, the drive is okay, booted some other isos on there. Only FreeBSD is failing for some reason :(
-
makr
why is pkg taking almost 1 gb to do an upgrade
-
makr
of memory
-
makr
been noticing it keeps getting killed by the OS because of hogging memory
-
makr
"Checking integrity...Child process pid=50693 terminated abnormally: Killed"
-
nxjoseph
makr, i don't know if it's normal for pkg to use that much memory or is it even a problem but, i guess you can try protect(1) to protect the job from getting killed
-
nerozero
-
nerozero
IPV6 BSD
-
makr
nxjoseph: thanks. i filed a ticket for it. this never used to happen before
-
nxjoseph
makr, i see, you are welcome
-
makr
2 gb to update 300 pkgs...i'm not too keen on pkgbase lol
-
shbrngdo
looks like tie to update kernel/world to -STABLE on everything
-
ghodawalaaman_
-
ghodawalaaman_
the mirrors are too slow
-
shbrngdo
ref CVE-2025-14558 - the link posted by nerozero
-
mzar
nerozero?
-
mzar
0-day ?
-
nerozero
sorry where AFK
-
nerozero
if you are not using IPv6 - you are safer
-
nerozero
if you are not using IPv6 - you are safe
-
nerozero
this issue not effects you
-
nerozero
but a lot of changes, update ASAP
-
rtprio
eh, i didn't it read it as a problem if you stay on your own trusted network
-
nerozero
If you have IPv6 and enabled Router Advertisements from your provided - you are effected
-
nimaje1
polarian: when using ´WITHOUT_ACPI=´ the value is the empty string
-
makr
why is the latest branch for freebsd 15 ports not working
-
makr
after doing echo 'FreeBSD: { url: "pkg+https://pkg.FreeBSD.org/${ABI}/latest" }' > /usr/local/etc/pkg/repos/FreeBSD.conf
-
makr
i get lots of errors and can't update, eg. pkg: Repository FreeBSD has a wrong packagesite, need to re-create database
-
mzar
is it exploited in the wild ?
-
polarian
nimaje1: yeah i realise that :)
-
nimaje1
makr: 15 renamed the repos, as the repo name FreeBSD would also fit for pkgbase too, so it is FreeBSD-base, FreeBSD-ports and FreeBSD-ports-kmods now
-
makr
thanks nimaje1, that fixed it
-
nimaje1
you should also change your -kmods repo to use pkg+https://pkg.FreeBSD.org/${ABI}/kmods_latest then
-
shbrngdo
handbook comment - maybe I was doing it wrong, ut I was looking for the current method of getting kernel source and it was difficult to pinpoint in the handbook. It oughtto be referenced in every section that discusses building the kernel, In My BombasticO Opinion (used to be). Had to resort to google searching... should be as easy as going to handbook and looking at chapters. FWIW
-
shbrngdo
mzar I am in the process of rebuilding my servr swith new FBSD, ports, and 8TB hard drive (old has 2TB and running 11).. So a kernel/world build is happening NOW. I did a quicky diff from 15-RELEASE installed source and there ARE a lot of changed files. Devs been busy.
-
shbrngdo
as for those behind firewall I am fuessing they may be ok using the erver as a gateway but I'll update them anyway to 14-STABLE(latest)
-
» shbrngdo ises IPv6 through he.net
-
mzar
tnanks for reporting shbrngdo; I am also still running FreeBSD, now mostly 15/stable, bu
-
mzar
but this machine runs 16.0-CURRENT #19 main-n282646-df6861d755c8: Fri Dec 19 18:08:48 CET 2025
-
shbrngdo
yeah it was 'cause I looked at the link nerozero posted, so all kudos to him. I'm just escalating the visibility a bit
-
shbrngdo
maybe worth a tpic mention
-
mzar
I am not much worried, rtsold is rarely run on servers
-
mzar
moreover, we at least need small exploit and bad guy with the access to the network
-
shbrngdo
well I'm not using dhclient on server either. I hav a somewhat pricey /29 now
-
mzar
does such exploit exist ?
-
LXGHTNXNG
«rtsold is rarely run on servers»
-
LXGHTNXNG
speak for yourself, many people have good reason to
-
mzar
OK, I am speaking for myself
-
shbrngdo
-
nimaje1
mzar: ACCEPT_RTADV is the thing to look out for
-
makr
nimaje1: i don't need to add _${VERSION_MINOR} like in /etc/pkg/FreeBSD.conf ?
-
ximon98
Is freebsd less code than linux
-
mzar
yes, that's common for my destkops
-
mzar
ximon98: is it an issue ?
-
shbrngdo
ximon - I could test that, compare size of FreeBSD sopource to Linux source. I don't have soyurce for the latest kernel, though and you'd have to include base gnu tool source as wwell.
-
shbrngdo
stupid keyboard. stupid cataracts.
-
nimaje1
makr: ah, yeah probably I just looked at usr.sbin/pkg/FreeBSD.conf.latest in the src repo, but yeah use what is in your /etc/pkg/FreeBSD.conf and change quarterly to latest
-
makr
done, thanks nimaje1 :)
-
nimaje1
mzar: I really don't understand why the code to react to Router Advertisement was put into rtsol too, its name suggests it only handles Router Solicitation
-
mzar
do you think that we need another daemon for this job ?
-
nimaje1
rtsol is no daemon, I think that part should be extracted with a better name, maybe rtadv-handler
-
mzar
3792 - ICs 0:00,02 /usr/sbin/rtsold -a -i 3796 - Is 0:00,00 rtsold: rtsold.llflags (rtsold) 3797 - Is 0:00,00 rtsold: rtsold.script (rtsold) 3799 - Is 0:00,00 rtsold: rtsold.sendmsg (rtsold) 3800 - Is 0:00,02 rtsold: system.syslog (rtsold)
-
mzar
it's a deamon /usr/sbin/rtsold: ELF 64-bit LSB pie executable, x86-64, version 1 (FreeBSD), dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 16.0 (1600007), FreeBSD-style, stripped
-
mzar
ha.. it looks like ACPI again doesn't power off the system on recent CURRENT
-
mzar
this issue became common in recent months
-
nimaje1
yeah, you can use it as a daemon if you want it to send Router Solicitation, but if you just have accept_rtadv it will be used to configure stuff in response to Router Advertisement but Solicitation are never in the picture then
-
nimaje
shbrngdo: another example why llms are not to be trusted, it confuses CVE-2025-14558 (rtsol) with CVE-2025-14769 (ipfw) there
-
flatdog
The buggers just throttled my access. Why didn't you plainly ban me?
-
aic
new phone who dis?
-
flatdog
Cheap way to deal with "unpleasant" members of the forums. F*** this.
-
aic
what was the flame war about?
-
aic
emacs vs. vim?
-
flatdog
There was no flame war at all. Relax.
-
flatdog
A single post, with a statement.
-
ant-x
nimaje, Generally, LLMs are not to be trusted because they a generators of Frankfurtean bullshit: <
scientificamerican.com/article/chat…isnt-hallucinating-its-bullshitting>
-
flatdog
About policy and politics. Iky subject.
-
flatdog
I hate them, both.
-
flatdog
One way or another, I will have my pun.
-
flatdog
Why send a private message if you know it cannot be read? Crivens, most likely. Explain here.
-
flatdog
Please explain, I will not take silence for an answer.
-
flatdog
Are we going back to commie Era? Censoring anything + 1? Hmmm... sad future dawns
-
flatdog
As long as I am not banned (no reason for that) I have the right to read my messages. Do you understand that?
-
flatdog
*private messages
-
flatdog
Good PR :)
-
kerneldove_
15.0 seems to be a really solid release. great job team!
-
satanist
I'm currently looking at the rtsol cve and I don't find the lack of quoting in resolvconf(8) which in the leads to the rce
-
satanist
is there a prove of concept for this cve?
-
rwp
satanist, The advisory listed the patches which fixed the problem. The patches were only for rtsol.c only and there were no changes for resolvconf.
-
rwp
-
satanist
the advisary claims: "A lack of quoting meant that shell commands pass as input to resolvconf(8) may be executed. [...] Systems running rtsol(8) or rtsold(8) are vulnerable to remote code execution"
-
rwp
I don't know but... I think they are talking about on the command line to resolvconf from rtsold and therefore it was lack of quoting from rtsold.
-
satanist
but resolvconf takes domains on stdin
-
rwp
I don't know anything about how rtsold is coded up. I would need to crawl through that source code to understand how it is working and what it is doing.