-
mjp
bystander: hey, there are flames pooring out of the windows on your house
-
mjp
home owner: well if you expect me to do anything about it, you'll need to lodge a formal request for me to look into it
-
ant-x
Wrong analogy, methinks.
-
ant-x
By the way, I have had good experience with that bug tracker: a problem I reported was fixed after 1.5 years or so.
-
mjp
if you give that page a read, you can see that the project has serious resource and governance problems. to the point where i'm questioning if the operating system is even safe to run anymore
-
heston76
Tinhead bot seems to have lost it's marbles in #freebsd-bugs
-
mjp
i love freebsd and have used it for decades, but if the project cannot address or at least respond to these issues, i'll have to seriously consider moving to a more mature/supported os like debian
-
ant-x
mjp, if it is your won article -- great. You could initiate a productive discussion of it on the mailing lists, more suitable to lengthy discourse than IRC. (my personal opinion)
-
ant-x
mjp, there are other BSDs, as well.
-
mjp
i'm a user/sysadmin with a full time job and a family, i don't have time to contribure to the project
-
LXGHTNXNG
talking a high and mighty game about governance issues makes you sound like a strasserite
-
mjp
i think if the project is not able or willing to take security seriously, state it and make everyone aware, don't pretend otherwise
-
ant-x
mjp, reporting a problem is a tiny fraction of effort of having it fixed.
-
mjp
i dont think anyone would disagree with that
-
LXGHTNXNG
you might be right, but you are at this juncture a disruptive presence
-
mjp
i dont see the project even acknowledging long standing problems, let alone having a plan to address them
-
mjp
wake up calls usually are disruptive
-
mjp
that is the point?
-
LXGHTNXNG
linking master→main under «political commits» really does stand you out as a fascist. please just leave.
-
mjp
bystander: hey, there are flames pooring out of the windows on your house. home owner: you are at this juncture a disruptive presence
-
mjp
ok
-
LXGHTNXNG
analogy incorrect
-
LXGHTNXNG
if you're going to switch to a different OS because of this - switch
-
LXGHTNXNG
it's that simple. if you don't want to visit the house you think is burning, don't visit the house
-
mewt
building stuff as root doesn't seem great
-
mewt
i will probably apply some of their recommendations, at least
-
mjp
i like the house, i have lived here for decades, i dont want to leave
-
heston76
mjp: Then the solution is to constructively contribute. End of story.
-
mjp
i also have a landlord advising me "well if you dont like burning to death, just leave!"
-
mjp
i don't think if fair to blame users of the OS for not fixing its shortcomings, its perfectly valid to just be a user and not contribute
-
ant-x
mjp, no contribution -- no complaint.
-
mjp
is that an offical rule of the freebsd project?
-
mewt
i also like it, i can't yet evaluate the difficulty of each proposed change here but running any WAN-facing freebsd i probably should put it on to-do...
-
mjp
or some BOFH quip from the 90s?
-
ant-x
mjp, I think it is common sense. And of course, reporting bugs in the tracker counts as a contribution.
-
LXGHTNXNG
do we have literally an moderator on deck right now
-
mewt
i will agree some of the listed things are not really "bugs" per se
-
mjp
if you read the article. many problems have been reported to the project, and ignored? how would creating a bug report for an ignore bug report help?
-
mewt
like, if you have configured swap not to be encrypted, and it's not encrypted, that is correct behavior for the setting
-
LXGHTNXNG
also you have included your X account name at the top of this page of yours. in 2026. that puts you in the lunduke set
-
mjp
i'm not attacking the people or the project, but I think an honest conversation and response is warranted
-
mjp
encrypted swap is what i would consider one of the lesser problems raised here
-
ant-x
mjp, a bug report /will/ help, because it will stay open and sore the eyes of the developers.
-
mewt
(this is a recommendation i will probably take)
-
mewt
yeah, was first example, not necessarily most important. i just mean reporting as bugs seems wrong for some of them, so I wouldn't know where it would be considered constructive to raise the issue etc etc
-
mjp
i don't see how making developers have even more sore eyes than they already do would help them when they are already overwhelmed and overworked
-
mewt
now i'm a bit confused, what are you advocating if not for the issues to be fixed?
-
ant-x
mewt, report /any/ problem to the bug tracker. Mine was not a bug, either: <
bugs.freebsd.org/bugzilla/show_bug.cgi?id=280941> .
-
mewt
interesting, ok
-
LXGHTNXNG
mewt: basically telling us to stop using freeBSD while advertising his (he's a he. i just know it. no woman writes a web like that and is also openly christian.) website with linux hardening tips to us.
-
» LXGHTNXNG sets a stopwatch
-
mewt
hmm
-
mjp
most of the article touches on more than "bugs" suitable for reporting in a tracker, they touch on the stated priorities and goals of the project vs actual reality on the ground, it needs high level evaluation and intevention
-
mjp
LXGHTNXNG: if you are talking about me, you are making some very bad assumptions and are not good at trying to doxx people
-
LXGHTNXNG
I'm not interested in doxing you.
-
mjp
I don't even use X btw, so not sure who's X acct you are talking about?
-
LXGHTNXNG
We're assuming that you wrote the article because you passed it us without any indication that you got it from somewhere else.
-
mewt
the author is not mjp i don't think, the author is a name i've seen around as an arch maintainer before
-
LXGHTNXNG
blakkheim iirc
-
mewt
yes
-
LXGHTNXNG
for some reason there's some negative emotional valence stored against tha name in my memory banks but I can't know what it is
-
LXGHTNXNG
okay. mjp you're forgiven, but all of my comments apply to blakkheim
-
LXGHTNXNG
consider the source before you send things
-
LXGHTNXNG
that's all I will say.
-
mewt
i think my comments on the Xitter profile are off topic, i do find it a bit off-putting. i'm willing to entertain the recommendations given anyways
-
mjp
LXGHTNXNG: you (no one else, not 'we') made wrong assumptions. I have not done anything wrong, i dont need your forgiveness. maybe ease up on the ad hominems though?
-
LXGHTNXNG
unforgiven then. and ignored
-
ant-x
mjp, try the mailing lists with those higher-level concerns.
-
mjp
I just realised today that the article was first published over 3 years ago
-
ant-x
I doubt lots all of the problems mentioned in it are fixed now.
-
mason
Oh, hm. blakkheim used to be a regular in here, and was a FreeBSD person, but it was years ago. Anyway, most of the things in that article can be taken as hints for how to configure things. I think there are things in there worthy of being formal bugs, but it'll take some research. Not everything he says there is valid.
-
mason
IIRC, he was, among other things, the first audio engineer for BSD Now.
-
siracha
o
-
Koston
well, this is novel. my small router PC likes to f*ing REBOOT randomly when a network cable is physically disconnected O_o
-
jmnbtslsQE
mjp: to be honest, as a random user/admin, i think your overall stance is reasonable, but that article if you look more deeply into some items they're exagerated, and many of the issues relate to many years ago and are no longer applicable
-
jmnbtslsQE
but i think it's good for everyone to fundamentally reconsider and re evaluate their security in the current era, with what's happening with AI
-
jmnbtslsQE
(to what you saida bout the publish date, yea i think it was quite some years ago that it was published)
-
vkarlsen
RoL, reboot on lan
-
Koston
jmnbtslsQE: I recall first seeing this rant years ago, like a decade or more - "freebsd defaults are insecure". at least back then it was too far detached from objectivity to be taken seriously by anyone except those who already had something against freebsd and wanted to reinforce their stance
-
hodapp
and "$project owes me something, I would like to speak to a manager" reaction rarely gets anywhere
-
Koston
yep, there's a curious illusion among users and many devs too that having more users has any intrinsic value
-
CrtxReavr
I'm at 13.4-RELEASE-p1 on this one box. . . can I build & install 14.x, or should I stop at a later 13.x first?
-
ivy
CrtxReavr: if you're using installworld, you should be fine to upgrade directly. if you're using freebsd-update, upgrade to the latest 13.x release and make sure you have all freebsd-update errata installed
-
CrtxReavr
bah
-
CrtxReavr
So rusty on this. . .
-
CrtxReavr
So according to ./sys/conf/newvers.sh I have a 13.4-RELEASE-p5 tree.
-
CrtxReavr
How do I get it to 14.4-R in the age of git?
-
CrtxReavr
There's also this ./stand/common/ tree.
-
jmnbtslsQE
is it already a git repository? you could git pull then checkout the git tag for 14.4 release
-
nxjoseph
is it a git-cloned tree? /usr/src. what does git status say?
-
CrtxReavr
It is a git repo.
-
CrtxReavr
er - git clone
-
nxjoseph
try this - git checkout releng/14.4
-
nxjoseph
also `git pull` to update
-
CrtxReavr
-
nxjoseph
i see
-
nxjoseph
you seem to have modified some files, is that you or freebsd-update done it? probably the latter.
-
CrtxReavr
# git checkout releng/14.4
-
CrtxReavr
error: pathspec 'releng/14.4' did not match any file(s) known to git
-
CrtxReavr
nxjoseph, that was the patch for the recent dhclient RCE.
-
nxjoseph
Ah I see, thanks
-
nxjoseph
git pull origin releng/14.4
-
nimaje
hm, try git fetch first
-
CrtxReavr
hehe
-
CrtxReavr
Can we get an agreement on commands?
-
nxjoseph
all sort of works the same :D
-
CrtxReavr
'git pull origin releng/14.4' is 'Receiving objects'
-
CrtxReavr
Half way there.
-
nxjoseph
Good
-
CrtxReavr
'resolving deltas'
-
nimaje
git pull is git fetch + git merge, it brings your local branch up to date too (but I think in this case it makes a mess, because your local branch is releng/13.4 and the one you are pulling is releng/14.4)
-
nxjoseph
nimaje, right, thanks
-
CrtxReavr
-
CrtxReavr
Just follow those three commands, or. . .
-
nxjoseph
i believe git checkout should work now - git checkout releng/14.4
-
CrtxReavr
nimaje, you have input on that?
-
CrtxReavr
nxjoseph, that based on what you saw in my bpaste link?
-
nxjoseph
yes
-
CrtxReavr
error: pathspec 'releng/14.4' did not match any file(s) known to git
-
nxjoseph
hmm, git checkout origin/releng/14.4
-
CrtxReavr
error: pathspec 'origin/releng/14.4' did not match any file(s) known to git
-
CrtxReavr
I think I'll try those three commands.
-
nxjoseph
:/
-
nxjoseph
can you share output of git branch -r
-
nimaje
git switch is a bit nicer there as it only takes branches, so git can't confuse if you meant a branch or a path
-
nxjoseph
hmm, maybe try switch then
-
CrtxReavr
-
nxjoseph
thanks, it seems like the pull command didn't work or what? :/
-
nxjoseph
maybe nimaje can help better, sorry
-
nimaje
probably the fetch part of the pull didn't happen then as it detected it can't put the branches together
-
CrtxReavr
The three commands from the "hints" I pasted compeleted without error or output.
-
CrtxReavr
nimaje, 'fetch part of the pull that didn't happen'? How do I do that.
-
nimaje
try git fetch and if that doesn't give you the releng/14.4 in git branch -r then try git fetch origin releng/14.4
-
CrtxReavr
'k
-
CrtxReavr
'git fetch' running.
-
CrtxReavr
branch -r still showing origin/releng/13.4
-
nxjoseph
> then try git fetch origin releng/14.4
-
CrtxReavr
Okay, apparently this is a mess:
bpa.st/7PUA
-
nxjoseph
sorry for the bad experience
-
CrtxReavr
Dont' appologize.
-
CrtxReavr
Should I 'rm -rf /usr/src/*' and start over?
-
nimaje
hm, what does ls .git/refs/remotes/origin/releng say?
-
CrtxReavr
13.4
-
CrtxReavr
When I ran 'git fetch' it did print:
-
CrtxReavr
* [new tag] release/14.4.0-p4 -> release/14.4.0-p4
-
CrtxReavr
Amonst lots of other output.
-
nimaje
hm, strange what is configured as origin in .git/config ?
-
CrtxReavr
-
nxjoseph
oh, i think fresh start might be better :p
-
nxjoseph
it seems to be configured only for the specific branch releng/14.3
-
nxjoseph
i am not that pro to manually edit .git/config
-
nimaje
try changing that to fetch = +refs/heads/*:refs/remotes/origin/* instead of hard coding 13.4 there
-
CrtxReavr
nimaje, you concur?
-
nxjoseph
hmm, hope that fixes it
-
CrtxReavr
-
nimaje
yes
-
CrtxReavr
Oh, should I nuke that [branch "releng/13.4"] stanza?
-
nimaje
no, you can leave that, it just tells git that your local releng/13.4 branch comes from the one from the remote origin
-
CrtxReavr
Okay, so now what - git fetch again?
-
CrtxReavr
git fetch origin releng/14.4
-
CrtxReavr
That one?
-
nimaje
yes
-
CrtxReavr
-
nxjoseph
cool!
-
nimaje
now git switch releng/14.4 should create a local branch releng/14.4 from the one from origin I think, if it doesn't try with -c
-
nxjoseph
i think it's time to switch/checkout now
-
CrtxReavr
Griping about the patch to sbin/dhclient/dhclient.c
-
nimaje
ah, yeah, there was that. What patch is that? do you still need it?
-
CrtxReavr
RCE in dhclient
-
CrtxReavr
Just last week.
-
CrtxReavr
Actualy, maybe a couple weeks ago.
-
CrtxReavr
Do I checkout releng/14.4 or origin/releng/14.4 ?
-
CrtxReavr
I'm gonna try just releng/14.4
-
CrtxReavr
git checkout releng/14.4
-
nxjoseph
good luck! :)
-
CrtxReavr
Switched to a new branch 'releng/14.4'
-
nxjoseph
congratz!
-
CrtxReavr
Can I start building?
-
heston76
Does git status show you are up to date?
-
CrtxReavr
-
nxjoseph
> Your branch is up to date with 'origin/releng/14.4'.
-
nxjoseph
it seems so.
-
CrtxReavr
Bitches about an old kernel config file, but I guess that's fine - gonna update that anyways.
-
CrtxReavr
so this is a remote upgrade. . . should I install and boot the the new kernel before doing installworld & mergemaster, or should I be okay to do them both together for the first boot?
-
CrtxReavr
feels like 13.4 to 14.4 is a big leap.
-
kevans_
you will want to be booted into the new kernel before installing world, yes
-
kevans_
otherwise things will be quickly hosed on the running system and it'll be considerably more annoying to work through the remaining steps
-
CrtxReavr
kevans_, even though my only access is via ssh?
-
kevans_
CrtxReavr: maybe especially because your only access is via ssh
-
kevans_
userland will almost certainly cease to function as soon as installworld is finished, if not in the middle of it
-
skered
I get the feeling that my env. is corrupt some how. For the past week buildworld buildkernel has been failing with from what appears to be may failing bison and/or crunchgen mainly resuce.mk. I don't think it's -j issue or WITH_CCACHE_BUILD issue. yet it always errors.
-
skered
I see from ci.freebsd.org the build of main and 14.4 are fine.
-
skered
So I'm guessing it's something on my side.
-
CrtxReavr
How's it failing? sig11?
-
skered
-
skered
It seem to between that and crunchgen error 1
-
kerneldove
o/
-
kerneldove
i'm getting back into server stuff, got a freebsd server installed. now i'm trying to get bhyve-vm up and running. i have a guest installed and running but it can't get network access. i realized i don't have a bridge created and bhyve-vm is configured with switch_list="bridge0", type_bridge0="manual", bridge_bridge0="bridge0", so i gotta create my
-
kerneldove
own. i remember in the past there was a lot of conflicting info on whether the vm host should keep its ip on its interface, or if the ip should be moved to the bridge interface. any guidance greatly appreciated, i want to make sure to do everything right this time
-
kerneldove
"To allow the host to communicate with bridge members, IP addresses should be assigned to the if_bridge interface itself, not to the bridge's member interfaces." (
man.freebsd.org/cgi/man.cgi?query=b…ion=4&manpath=freebsd-release-ports) but then "The bridge(4) interface doesn't need an IP address."
-
kerneldove
-
ivy
kerneldove: the IP address should be on the bridge interface or a vlan subinterface of the bridge, not on a member
-
kerneldove
so was SirDice wrong there or am i misunderstanding something?
-
ivy
he's correct to say it doesn't *need* an IP address. but if you want the host to have an IP address in the bridged subnet(s), that IP address goes on the bridge
-
kerneldove
my lan is 10.1.1.0/24. my server is 10.1.1.15, and the vms will use 10.1.1.16-19. what are the "bridged subnet(s)" there?
-
kerneldove
sorry, my lan's subnet is*
-
ivy
10.1.1.0/24 is a subnet
-
kerneldove
and that's the same as "bridged subnet"?
-
ivy
when i say "bridged subnet", i just mean a subnet with traffic going through the bridge. does traffic in 10.1.1.0/24 go though the bridge? then yes
-
luser
I'm assuming ivy means: if the server interface is igc0 and typically gets the IP address 10.1.1.15, then you'd assign that IP to bridge0 and igc0 no longer gets an IP.
-
kerneldove
and igc0 becomes a member of bridge0
-
kerneldove
ok got it
-
kerneldove
tyvm for clearing the confusion for me
-
luser
kerneldove yes, I forgot that bit.
-
kerneldove
my server has 4 phsyical ports that i make a lagg0 over and assign an ip to. i assume that i make lagg0 the bridge0 member and move the ip assignment to bridge0, correct?
-
luser
Yes.
-
kerneldove
ok thx a lot ppl