-
rtj
-
rtj
I've had pretty good luck running about everything in hyperv.
-
deimosBSD
i'm testing vm-bhyve to run some bhyve vms, i can't get it to boot anything uefi (openbsd, freebsd, arch, alpine) and yes, I have bhyve-firmware installed
-
rtprio
deimosBSD: what about edk2-bhyve ?
-
rtprio
and what's the log say / what happens
-
deimosBSD
yeah, i have that
-
deimosBSD
the vm-bhyve.log claims the vm starts fine
-
TommyC
deimosBSD: How are you pointing bhyve to the uefi firmware?
-
deimosBSD
yet console is blank as is vnc
-
deimosBSD
vm-bhyve finds it correctly
-
rtprio
you should see some efi shiz from watching `vm console`
-
rtprio
TommyC: doesn't it just magically find it from /EFI ? i haven't had to do anything like that
-
rtprio
just loader="uefi"
-
TommyC
Last time I played with bhyve, it did find the bhyve-firmware stuff automagically but it didn't for edk2's firmware.
-
rtprio
Dec 31 23:36:52: [bhyve options: -c 1 -m 1G -Hwl bootrom,/usr/local/share/uefi-firmware/BHYVE_UEFI.fd -w -U 26d828ee-a834-11ee-bbca-782bcb32b758 -u]
-
rtprio
and that file is there, yeah?
-
deimosBSD
here's what I see, all throw away vm,
paste.zw.is/upload/QdJlva
-
deimosBSD
and yes, the /usr/local/share/uefi-firmware/ points to ../edk2-bhyve/ files correct
-
rtprio
i remember i had to do some weird set tty on the openbsd installer
-
rtprio
but i don't know if that was fixed
-
deimosBSD
the tty is sorta normal for serial coms, but this is supposed to provide full uefi graphics, right?
-
deimosBSD
fwiw, this is the config from the vm create command:
paste.zw.is/upload/dJzOvd
-
deimosBSD
which is just based on the template for openbsd.conf
-
deimosBSD
if i remove the graphics lines, i get nothing from console
-
kerneldove_
where should we look for patch level changelog? i wanna see if 14.3-p5 needs to be upgraded to p6 or p7
-
deimosBSD
-
nimaje
also look up a bit for the security advisories
-
kerneldove_
ok ty
-
kerneldove_
rtj rust would have prevented most of those jail escapes
-
kerneldove_
ah ya, rust mentioned in later slide
-
kerneldove_
ivy ^
-
rtj
How can you oxidase the code?
-
kerneldove_
well like the slide in that talk says, start with adding the infra for rust support, then start writing new code in rust, then over time rewrite old code in rust
-
rtj
Yes, I was just trying to be silly. I guess you could put the code on spinning drives and they'd rust. I'll see myself out.
-
kerneldove_
will you be here all week? :)
-
deimosBSD
perhaps all year
-
deimosBSD
now my test vm is both running and not running
-
deimosBSD
back to reading the source for vm-bhyve
-
SponiX
hodapp: I have never really got the container hype... I understand it can help with security, but with my systems just being for friends and family, I've never really felt the need
-
SponiX
Sometimes a single podman/docker command to deploy something that would otherwise be complicated can be nice. But most of the times things are straight forward enough I'd rather just do them on the Host OS itself
-
Macer
yeah kind of weird. linux tends to set cores .. but fbsd is all the cores when it comes to throttling with powerd
-
LXGHTNXNG
rust is an unstable language without a formal standard
-
Macer
so it seems like powerd adjusts all cores at once instead of one at a time
-
hodapp
SponiX: so, the security argument is meh as their isolation often isn't great, but for me they shine in situations where you need to lock down the exact context something runs in - and that's great for things like reproducible builds where you can guarantee that outside things or previous builds aren't leaking in, or for running unit tests, or for demonstrating a minimum test case for a supposed
-
hodapp
bug
-
hodapp
SponiX: if you have software that was written like shit in the first place, and it just assumes it can throw things around all over and control the whole OS (without any real excuse for needing this), containers are a really effective way of deploying it while limiting the blast radius. a lot of "real" software is, annoyingly, this.
-
hodapp
my problem is when people look at this last effect, and go "oh, since Docker exists, I may as well write the software to completely depend on it!" and throw out the idea of ever picking the right abstraction
-
LXGHTNXNG
zfs question: is a jailed dataset supposed to return permission denied to jail root attempting `zfs snap`?
-
deimosBSD
welp, my openbsd pf rules work "as is" in freebsd pf now
-
rtprio
magic
-
mzar
thanks for testing deimosBSD
-
deimosBSD
at least something worked correctly today
-
mzar
ha.. everything works correctly today ;-p
-
Macer
LXGHTNXNG: i think you have to give it permission for zfs
-
nwe
hello guys, what do you think.. will it work to play windows games like WoW, minecraft etc via wine in freebsd? I played WoW for around 15 years ago on linux wine and thats worked fine..
-
nwe
otherwise I need to upgrade this old computer so I can install newer windows 11 so my kid can play some games atleast :P
-
mzar
LXGHTNXNG: please let me know whether is it possible to access snapdir from the jail
-
mzar
LXGHTNXNG: snaphoting can be done by host's root
-
mzar
snapshoting by jail's root never worked for me, but the problem with accessing snaphot dir from the jails is worse
-
nimaje
nwe: wine should work about as good as on linux
-
nwe
nimaje: thanks! at the moment I have some problem with my poor usb-wifi dongle going really slow :P
-
nwe
pkg install chromium going in 32kb/s :P
-
nwe
as in the old days :P
-
tarel2
How many of you just run freebsd ? No Linux or Windows in the mix?
-
nimaje
why do you ask? Some here I would think, but not really able to guess a number
-
tarel2
I recently got into freebsd , I just wonder what other setup are like
-
tarel2
I have Windows 10 , Debian , Gentoo , freebsd
-
tarel2
I have run freebsd and openbsd on the pi ,but not on a normal desktop
-
lockna
I use Windows (just for gaming), Linux (if I contribute to something linux only) and daily driving FreeBSD
-
tarel2
Nice setup lockna
-
tarel2
So all UEFI based systems?
-
lockna
Yes, everything runs on my PC. Only got a macbook which runs Asahi Linux when I'm off for work.
-
lockna
Why you having two linux distros?
-
tarel2
Well, my point is to try to make a system the way I want.
-
tarel2
Gentoo was extreme all command line , small as I could get and still do what I normally do , coding , web and watch movies
-
lockna
and what do you use debian fore?
-
tarel2
I had been using Ubuntu for most of the 18 years I have been using Linux so , I thought why not try the base
-
tarel2
just got it so I could pick the gui after
-
lockna
Ah, okay
-
tarel2
over the years I had tried going down the rabbit hole distro wise. and I thought , never tried Debian
-
lockna
true, often gets overlooked
-
tarel2
What I have done is Ubuntu as my base , ventured out , void , Arch , Gentoo when I felt like really trying . One time Windows , Linux , freebsd
-
tarel2
recently last 5 years , dual boot , bios and uefi , is that what you call it
-
ck45
hello! I'm building a kernel module from my home directory. it contains a bunch of code not written by myself which has some compile time warnings. I'd like to ignore those warnings ("for now"). what I've tried so far: `make WERROR="-Wno-cast-qual"` - I can see the flag in the compiler command line, but there's also a `-Wcast-qual`, which seems to override it. I've also tried to dabble with /etc/src.conf (WITHOUT_WARNS, WITHOUT_WERROR), but I haven't had any
-
ck45
success (luck) so far. I assume that's a quite easy task if you know the build system a bit better. can somebody help?
-
ck45
hm, something I've tried before, but I might have made a mistake: It seems setting WERROR="" and WARNS="-Wno-cast-qual" in the Makefile helps. let me double check
-
nimaje
let me try my crystal ball, maybe that lets me see what build system that kernel module you have from somewhere uses and how it works -- nope, my crystel ball is still broken
-
Remilia
ck45: I'm not sure what you mean, compiler warnings should not abort compilation
-
ck45
Remilia: there's a flag that turns warnings into errors:
clang.llvm.org/docs/UsersManual.html#cmdoption-Werror - it makes sense to be stricter e.g. for the kernel code. I think the flag is added here:
github.com/lattera/freebsd/blob/mas…er/share/mk/bsd.sys.mk#L35C1-L35C11 but I have/had some trouble disabling it
-
Remilia
oh
-
Remilia
I thiink WITHOUT_WERROR=1 worked fine for me before yeah
-
Remilia
but that was in the past
-
ck45
did you pass it to make or in src.conf?
-
ck45
well, seems I have found an equilibrium and it now works. I will check a bit later if it's reproducible
-
tarel2
Tell the makers of freebsd thanks from me
-
lts
tarel2: you can also do
freebsd.org/donations
-
mzar
sure, you can, you can give a few bucks and it will make you happier tarel2
-
dogg0
i just saw this as #freewilly
-
dogg0
#freebsd!
-
dogg0
not as in beer, not as in speech, but as a verb, et tu
-
tarel2
Why chose freebsd over Linux? Both unix like but freebsd is smaller. Do you just stick to the few thing you do and not venture out? Or more like freebsd , some Linux when need and Windows when you want to play games?
-
Remilia
tarel2: neither is UNIX
-
Remilia
they are Unix-like and partially POSIX-compliant
-
nimaje
well, freebsd has one of the largest package repos, so why would the smaller base be a disadvantage?
-
nxjoseph
sorry for non-topic: hi there, does anybody know how can I make the make env "I_DONT_CARE_IF_MY_BUILDS_TARGET_THE_WRONG_RELEASE" work in the poudriere?
-
tarel2
So what is a real unix?
-
Remilia
a real UNIX system is anything Open Group has certified as UNIX
-
Remilia
AIX would be an example
-
Remilia
a UNIX has to conform to POSIX and SUS
-
la_mettrie
*real -> official
-
tarel2
Looking at say Windows , more app , Linux not as many , Mac less , keep going down , where does freebsd land. That is my only point
-
nimaje
some version of apples mac os was certified UNIX
-
Remilia
nimaje: all versions since 10.5 excluding 10.6
-
tarel2
That is odd to me finding out Mac is like based on freebsd or something like that unix-like os
-
Remilia
Mac OS uses a mach-like kernel with heavily modified parts of FreeBSD userland
-
Remilia
well, it was originally Mach but they introduced a whole lot of changes so it is no longer fully microkernel (then again this is off topic)
-
tarel2
The one time , I ran mac on their pc , it was ok.
-
tarel2
freebsd a modded version run the ps 4 ?
-
tarel2
I would love to look under the hood , not I have run os and knew what I am doing
-
polarian
-
DaliborFox
on the contrary, it's way better when responsible security researchers find and thisclose the information, like they did here
-
DaliborFox
*disclose
-
antranigv
yes, crest has done a very good job with this. as well as the people who responded to it.
-
antranigv
hey crest you are popular. again. yeeeeey.
-
crest
?
-
crest
what have i done this time?
-
nimaje
the important part there is "We’ve responsibly disclosed our findings to the FreeBSD security team and are collaborating with them on fixes."
-
crest
i just asked if they're willing to document their dev setup
-
crest
which they promised a writeup on
-
crest
i'm a bit pissed by how much worse my communication with the security team went
-
crest
it felt like screaming into a black hole that didn't even acknowledge my report
-
crest
despite including an already weaponized exploit as PoC
-
crest
*sigh*
-
deimosBSD
polarian: iirc, most of the risk was in the old ipfilter firewall code and interfaces
-
polarian
deimosBSD: classic freebsd not removing legacy code then?
-
polarian
shame
-
mzar
ipfilter is oldest one, and when Darren was writing the code, there were different times
-
» mzar wonders who really uses ipfilter in 2025
-
deimosBSD
i'm sure someone, somewhere uses ipfilter still, which is why the code still exists
-
deimosBSD
but i could be wrong about the whole topic
-
deimosBSD
maybe it's the secret bypass_kernel_security_for_perf() syscall in jails. ;)
-
Remilia
is ipfilter even loaded by default
-
mzar
Remilia: no, neither it's exposed to the jails
-
deimosBSD
I really wish there was a transcript of this talk with slides, not making me actually watch the video.
-
Remilia
same
-
deimosBSD
i hear "ai" solves this.
-
deimosBSD
;)
-
Remilia
the video has 'auto' captions which are terrible
-
Remilia
'a security analysis of Freebies EJLs'
-
mzar
it was a nice talk, a lot of work was needed to complete this PoC breakout, and it should be highly appreciated that those guys have taken whole effort
-
Remilia
deimosBSD: mentions ipsec, carp, wifi (lol), NFS, pf, ipfilter and ipfw at least
-
Remilia
plus interface ioctls
-
crest
don't watch the video 39c3 videos on youtube *sigh*
-
Remilia
crest: what do you mean?
-
Remilia
I can't parse your sentence, sorry :(
-
» Remilia is English-as-4th-language
-
LXGHTNXNG
there's a superfluous word «video» before «39c3», Remilia
-
Remilia
oh
-
LXGHTNXNG
«don't watch the 39c3 videos on youtube»
-
Remilia
well, I am watching it on media.ccc.de
-
LXGHTNXNG
very good
-
TommyC
What's wrong with watching it on YouTube?
-
Remilia
and that is where the 'auto' captions are from
-
LXGHTNXNG
freebsie ejls
-
LXGHTNXNG
freebies ejls*
-
LXGHTNXNG
hilarious
-
deimosBSD
i'm downloaded it and am watching with mpv
-
deimosBSD
(imagine that is correct english)
-
TommyC
s/i'm/i/
-
Remilia
I feel like automated captions should be last resort when it's anything outside typical time-wasting stand-up type meeting thing
-
Remilia
and lack of proper CCs is a show of disrespect to people with hearing issues
-
TommyC
"Translators are expensive." -- upper management
-
Remilia
this isn't even about translation
-
Remilia
just closed captions
-
» Remilia is a translator by education and trade
-
Remilia
also yeah… expensive… €0.045 per source word ahahaha
-
DaliborFox
TommyC: Who needs translations, when you can just set the captioning to the wrong language? :D I sometimes attend such meetings, and have to hold my temper from cracking up at times
-
TommyC
DaliborFox: I sometimes like to read Dutch because the language itself can be funnny. :3
-
Remilia
DaliborFox: you don't even need wrong language, you need non-native speaker accents
-
Remilia
and Teams and Meet both descend into chaos
-
Remilia
(also, uncommon/non-English names)
-
crest
Remilia: sorry i'm operating on 2 hours of sleep
-
mzar
crest: it's time to hit the sack, your shift here is over !
-
crest
i assumed the bad auto subs where added by youtube because people tend to watch it there instead of on media.ccc.de or the live/timeshift streaming service
-
crest
mzar: too bad my train from hamburg to berlin took a "little" detour because on track is closed by construction
-
mzar
ha... it happens, I am sorry to hear that, and I hope you'll be able to have at least nap there
-
crest
and on the other some damned idiot decided that today is a great day for suicide by train
-
mzar
it's end of the year, a week after solstice, people suffer from lack of sunlight and it happens
-
» ant-x looks for a bottle of Vitamin D3
-
crest
so the train had to detour via hannover
-
mzar
that's not so bad, you still could have severe winter storm or terrorist attack, let's hope it will get solved and you'll be able to get back home before end of the year
-
crest
if you have to use a vehicle use your own and don't fuck up a train driver's life on your way out
-
LXGHTNXNG
deimosBSD: the perfect tense in the active voice is formed with «to have». so it'd be «i've downloaded it».
-
mzar
interesting English 101 ongoing here
-
deimosBSD
LXGHTNXNG: grazie
-
LXGHTNXNG
we don't have a two-auxiliary system like italian
-
mzar
but both are indo-european languages, so learning is easy
-
LXGHTNXNG
overstated
-
LXGHTNXNG
the lexicon is almost completely different when you move away from sciencey words
-
LXGHTNXNG
but this has already gone too far for here, let's go to #freebsd-social if we want to continue
-
mzar
hha... yep, but this channel could also become #social, we are building wider community
-
Remilia
mzar: you're welcome to easily learn Basque or Finnish/Estonian
-
Remilia
or Russian (at a level that does not make people point and laugh)
-
Remilia
at least Russian only has 6-7 grammatical cases unlike Finnish
-
mzar
Remilia Finnish/Estonian/Hungarian are from different family, Basque - too far for me to go there
-
Remilia
mzar: I'm not sure what you mean, they are Indo-European
-
LXGHTNXNG
they aren't.
-
LXGHTNXNG
Finnish and the gang are Finno-Ugric, which is only related by a couple of loanwords to IE
-
Remilia
oh wait, right, Uralic
-
Remilia
I am running on a 40 minute nap
-
Remilia
though to me they are all weird because my native language is Ainu :D
-
LXGHTNXNG
Basque is a paleo-european language of the Vasconic family (of which it's the only surviving descendant as well as one of like four or five descendants of which we have any records at all), one of the last remnants of the languages once spoken by archaic Europeans before the proto-Ukrainians arrived with their bubonic plague and their indo-european languages. Etruscan, which we do not have
-
LXGHTNXNG
complete records of and which is extinct, is either a language isolate or of a "Tyrsenian" (if I spelled that right) family, not related to the Vasconic languages
-
Remilia
wtf are 'proto-Ukrainians'
-
ant-x
Remilia, 0.045 per source word? Poor human ranlators, having to complete with the artificial idiot...
-
ant-x
* compete
-
Remilia
ant-x: sometimes you can get 0.055 but 0.045 is very common for freelance work in my original language pair (RU→JA) and also in EN→RU
-
Remilia
getting anything RU→JA consistently is a pipe dream outside government work anyway
-
Remilia
should not have majored in Russian :D
-
ant-x
I am Russian. Which language is JA? Not Japanese?
-
ant-x
^ So it /is/ Japanese, and not jp.
-
ant-x
Remilia, I misread 0.045 for 0.0045. 20 words to a Euro actally sounds good to me.
-
Remilia
ant-x: yeah you typically can earn around 400-500 a month if you are lucky
-
LXGHTNXNG
Remilia: I am referring to the Indo-Europeans who had domesticated horses but not invented agriculture and lived in what's now southern Ukraine and southwestern Russia, before moving north, west and east
-
LXGHTNXNG
it's a misleading term
-
Remilia
LXGHTNXNG:
history.stackexchange.com/a/17399 see here and forget that bs
-
Remilia
has maps included and full explanation
-
ant-x
Remilia, I remember that in the 1930ies writers of weird fiction (Lovecraft and friends) were paid 0.01$ per word for original fiction rather than translation.
-
LXGHTNXNG
respectfully, "indo-europeans out from yamnaya is bullshit" is not a conversation for #freebsd.
-
Remilia
ant-x: you are always paid per source of course
-
ant-x
But nowadays you are allowed to cheat with GoogleTranslatin &c?
-
Remilia
why would you ever do that
-
ant-x
/I/ would not, but peole routinly do it to save effort.
-
Remilia
LXGHTNXNG: there are Strange People pushing 'proto-Ukrainians' pseudoscientific stuff that was thoroughly debunked before
-
ant-x
^ They would run the entire text through Google Translate, make a few amendments, and call it a job done.
-
Remilia
and indeed, pseudoscience should be off topic anywhere
-
ant-x
You talking about the great ancient civilisation that dug out the black sea :-?
-
Remilia
ant-x: I'd share my thoughts on MTL but this is not the right channel and you aren't in #freebsd-social
-
ant-x
Right.
-
ant-x
Perhaps, I'll see you there sometime.
-
LXGHTNXNG
Cripes.
-
ant-x
Is anyone here using the X11's starndard windows manage, twm, on their FreeBSD machine?
-
ant-x
* window manager
-
LXGHTNXNG
1. why would i 2. maybe i should (re?) try it sometime
-
ant-x
LXGHTNXNG, small & beautiful & ususual: <
cpcnw.co.uk/twm/twmrc.htm> .
-
Remilia
I simply remain a windowmaker user
-
ant-x
Better than widomaker :-)
-
ant-x
^ as I frequently mistype the word.
-
Remilia
I think it was the nicest WM I tried in 1998 and it stuck
-
Remilia
(that is, nicest after IID)
-
Remilia
but you can't have IID on FreeBSD so
-
» ant-x loves Windows 98 interface, and GTK2.
-
Remilia
was IID's window manager called 4Dwm I forgot
-
ant-x
I asked about twm because I have problems with using it with complicated software such as Firefox.
-
ant-x
What is IID?
-
Remilia
IRIX Interactive Desktop
-
ant-x
^ It is a beauty, confirmed.
-
ant-x
I dislike vector interfaces, and most of the time vector fonts as well.