-
ek
scoobybejesus: Maybe take a look at:
-
ek
-
ek
And, yes, you need to update the boot loader/code.
-
rtprio
is it normal for my other epairs to leak into a jail?
-
ek
rtprio: Kinda vague. What do you mean by "leak"?
-
ek
And are these VM epairs or something? VNET?
-
rtprio
vnet, yar
-
rtprio
ifconfig |grep e0a_ shows three other jails
-
ek
From the jail itself?
-
rtprio
yes, inside the jail itself
-
rtprio
and an unrelated bridge, and the parent interfaces
-
ek
Not normal in my experience. Each jail only shows it's own epair interface.
-
rtprio
hrm, curiously the interface for itself is missing
-
ek
But it's reachable on the network?
-
rtprio
oh shit, it's all wrong
-
rtprio
it attached to the bridge, not to vnet
-
ek
Ah. That would make more sense.
-
rtprio
it's not supposed to be
-
ek
Well, the vnet should utilize the bridge. But, connecting directly to the bridge would take vnet out of the setup.
-
ek
Of course, I'm not sure what your configuration is, exactly.
-
ek
But, when I use vnet, I have my bridge on whatever interface and then I create the vnet interfaces for the jails which are members of the bridge.
-
rtprio
i have a dedicated vnet -> bridge -> lagg for jails distinct than the lagg for the host
-
rtprio
but don't keep detailed notes to repeat the bastille create command as the last time, apparently
-
ek
rtprio: Fortunately, Bastille is pretty well documented (and somewhat simple.) I wouldn't be surprised if you can find that info rather quickly.
-
ek
Again, I'm not sure what your setup is, but if the LAGG is already setup, the bridge to that is the same as any other interface and then you'd just use that bridge for VNET.
-
rtprio
i just sed s/workinghost/desiredhost/ and replaced the config
-
ek
rtprio: Did it work?
-
rtprio
yeah, once i got the right lines in rc.conf
-
rtprio
moving from bhyve to jails turns out to be a pain in the ass
-
dnp1
rtprio: Got enough time in on jails to confirm if you perfer jail over bhyve?
-
rwp
For 15.1-RELEASE there is
download.freebsd.org/releases/amd64/15.1-RELEASE/base.txz which is the -p0 level. Is there a location to fetch a base.txz that is updated to the current 15.1-RELEASE-p1 version?
-
rwp
I can make one by compiling from source. But at the moment it would be more convenient to just fetch one.
-
rtprio
dnp1: well, not really, just started on jails
-
rtprio
my bhyve host has a ton more ram, but the jail host is newer/ faster cpu
-
imm__
Hi; the uname on 14.3 has changed after the latest p16 update, it now says "FreeBSD 14.3-RELEASE-p16 #0 -dirty: Tue Jun 30 11:19:56 UTC 2026"
-
imm__
Before it only said "FreeBSD 14.3-RELEASE-p14 GENERIC amd64", does anyone know why?
-
rwp
I don't know anything. But isn't 14.3 end-of-life?
-
imm__
From today :)
-
rwp
It is still under support for another 32 minutes in my timezone. But then that's it. :D
-
LXGHTNXNG
congration
-
madiaxa
hi!
-
madiaxa
dead chat :(
-
joemie
nope
-
madiaxa
oh
-
madiaxa
ho
-
madiaxa
hi*
-
joemie
good morning/afternoon/evening (depending on where you are). Morning for me
-
madiaxa
It's around midnight for me lol
-
madiaxa
I've been playing Deltarune (on FreeBSD obviously)
-
madiaxa
hi hhao
-
joemie
okay, I'm not a game player myself
-
madiaxa
what do you use FreeBSD for?
-
joemie
server (web, mail, database)
-
joemie
and I use it to be in irc (weechat)
-
madiaxa
so not as a daily driver?
-
madiaxa
that's what i use it for
-
madiaxa
i know barely anyone who daily drives it, it's mostly server ppl :(
-
madiaxa
well not that it's necessarily a bad thing
-
joemie
lots of people in this channel use it as workstation
-
joemie
you just managed to find one who doesn't :)
-
madiaxa
ah
-
madiaxa
my friends used to use FreeBSD but they switched back to linux :(
-
madiaxa
i'm gonna go
-
madiaxa
cya
-
newuser234
Can i use sendto() in capsicum mode ?
-
nimaje
I don't see a reason why you shouldn't be able to use it (if you have the right capabilities of course)
-
newuser234
I tied to use it on socket with CAP_RECV and CAP_SEND, but i got "sendto -1 errno 94 Not permitted in capability mode".
-
newuser234
On UDP datagram socket.
-
nimaje
was the socket connected? or did you have CAP_CONNECT? not sure if connecting to some host on the internet is permitted in capability mode
-
newuser234
I am doing recvfrom and then sendto.
-
newuser234
Sendto to adress got from recvfrom.
-
nimaje
seems like a pattern that would be good to support in capability mode, does it work with CAP_CONNECT? if not, then I suggest opening a problem report, likely needs a new capability then for exactly that pattern
-
newuser234
CAP_CONNECT doesynt work too.
-
newuser234
Thank you for your help.
-
DarkUranium
So, I've a question/problem. I have a jail (via the podman port) that has trouble reaching a bhyve VM on the same system (connected via VNET + bridge). Doing `ping $vm_ip` from the jail nets me a very high packet loss (around 5% on a good day, and upwards from there --- all the way to 100%) --- on Linux end, it looks like iptables is dropping packets due to an INVALID state.
-
DarkUranium
The VM (which is Linux) is bridging a bunch of IPs from its own podman. All but two (10.24.0.1, which routes to the VM's "host", and 10.24.0.3) have this behaviour --- the two exceptions (10.24.0.{1,3}) work 100% perfectly though.
-
DarkUranium
Doing the same ping from the host (not the jail) works perfectly fine, though, regardless of IP.
-
DarkUranium
I suspect the misconfiguration is on BSD end (since it works fine if I don't send the ping from a jail), but I'm not even sure as to where to start looking ..... any ideas? =\
-
DarkUranium
IOW, `[host's] jail -> VM -> podman` is broken for all (except 1), `host -> VM -> podman` is 100% fine.
-
DarkUranium
Dunno if there's a pattern, but from some quick & dirty tests just now:
-
DarkUranium
10.24.0.2 => 91.7% packet loss; .0.3 => 0%; .0.5 => 87.5%; .0.7 => 10.8%; .0.10 => 14.9
-
DarkUranium
(expect a ~5% variance, except for .0.3, where I've never ever observed a dropped packet)
-
DarkUranium
I'm, frankly, flabbergasted at this point. Something's obviously very wrong, but I'm having trouble narrowing it down.
-
DarkUranium
Well, NEVERMIND (I've just narrowed it down to a {docker,podman}-compose problem
-
DarkUranium
)
-
ibs
After update last week, Nextcloud's cron.php started complaining about "ps: cmd: keyword not found" and "ps: no valid keywords; valid keywords:". Anyone knows if this is a known issue?
-
rtprio
ibs: update from what to what? if it were a known issue the venue would probably nextcloud
-
rtprio
but take a peek at the file and find the ps call
-
hodapp
ugh, one of the best decisions I ever made was shitcanning Nextcloud
-
rtprio
hodapp: same
-
hodapp
switched to a combination of Immich, Radicale, and Syncthing
-
hodapp
and I never could understand how Nextcloud could fail so miserably at being behind a reverse proxy
-
hodapp
like, 20-30 lines of boilerplate configuration and *still* fucking things up at random
-
joemie
I read here of Nextcloud problems I don't have.
-
Ozymandias42
hodapp. What kind of nextcloud reverse proxy problems are we talking about? Works perfectly fine for me
-
hodapp
Ozymandias42: obscure problems around login flow and uploads are the ones I can recall. it requires special configuration.
-
Ozymandias42
In homelab setups or with SSO?
-
ibs
I should've checked bugzilla instead.. but people are aware and fixes are happening, I'm happy.
bugs.freebsd.org/bugzilla/show_bug.cgi?id=296323
-
Ozymandias42
Because I use it with two containers. Nginx and phpfpm and have that behind a k8s Traefik ingress as well. And for me everything works. Even caldav and carddav
-
hodapp
its caldav "worked" until I looked and it was inexplicably missing 30% of my contacts with no explanation
-
Ozymandias42
Ah. That sounds like a red flag indeed
-
joemie
I run NC in a jail (nginx+php_fpm) and the reverse proxy (nginx) in another (and postgresql in even another jail)
-
Ozymandias42
Haven't had that happen yet or haven't noticed at least. But makes sense that you switch to radicale then
-
Ozymandias42
joemie pretty much my setup. Just jails instead of k8s
-
Ozymandias42
You don't use redis or memcache btw?
-
joemie
redis I use indeed, but on a docker instance (on linux)
-
runxiyu
how do i set up the installer to use an http proxy and also connect to wifi properly?
-
runxiyu
if i go get a live system then type bsdinstall
-
runxiyu
it says
-
runxiyu
"wireless cannot be confiured without making changes to the local system!"
-
skered
In zfsize, setting quota and refquota the the same value is like a traditional partitioned device? It can got above the value (quota) but is guaranteed that value in space?
-
skered
can't go*
-
skered
I think I'm confusing that with refreservation and reservation
-
nsoci
list
-
rtprio
runxiyu: weird error but it sounds like it needs to put firmware on it?