00:08:42 scoobybejesus: Maybe take a look at: 00:08:45 https://forums.freebsd.org/threads/freebsd-zfs-upgrade-best-practice-question.91070/ 00:09:12 And, yes, you need to update the boot loader/code. 00:09:19 is it normal for my other epairs to leak into a jail? 00:09:48 rtprio: Kinda vague. What do you mean by "leak"? 00:10:13 And are these VM epairs or something? VNET? 00:10:20 vnet, yar 00:10:53 ifconfig |grep e0a_ shows three other jails 00:11:08 From the jail itself? 00:11:15 yes, inside the jail itself 00:11:29 and an unrelated bridge, and the parent interfaces 00:12:06 Not normal in my experience. Each jail only shows it's own epair interface. 00:12:28 hrm, curiously the interface for itself is missing 00:12:52 But it's reachable on the network? 00:13:03 oh shit, it's all wrong 00:13:11 it attached to the bridge, not to vnet 00:13:23 Ah. That would make more sense. 00:13:41 it's not supposed to be 00:15:01 Well, the vnet should utilize the bridge. But, connecting directly to the bridge would take vnet out of the setup. 00:15:25 Of course, I'm not sure what your configuration is, exactly. 00:16:01 But, when I use vnet, I have my bridge on whatever interface and then I create the vnet interfaces for the jails which are members of the bridge. 00:18:32 i have a dedicated vnet -> bridge -> lagg for jails distinct than the lagg for the host 00:19:33 but don't keep detailed notes to repeat the bastille create command as the last time, apparently 00:24:21 rtprio: Fortunately, Bastille is pretty well documented (and somewhat simple.) I wouldn't be surprised if you can find that info rather quickly. 00:25:37 Again, I'm not sure what your setup is, but if the LAGG is already setup, the bridge to that is the same as any other interface and then you'd just use that bridge for VNET. 01:05:23 i just sed s/workinghost/desiredhost/ and replaced the config 01:21:39 rtprio: Did it work? 01:28:58 yeah, once i got the right lines in rc.conf 01:29:46 moving from bhyve to jails turns out to be a pain in the ass 01:41:34 rtprio: Got enough time in on jails to confirm if you perfer jail over bhyve? 04:39:10 For 15.1-RELEASE there is https://download.freebsd.org/releases/amd64/15.1-RELEASE/base.txz which is the -p0 level. Is there a location to fetch a base.txz that is updated to the current 15.1-RELEASE-p1 version? 04:39:42 I can make one by compiling from source. But at the moment it would be more convenient to just fetch one. 04:58:11 dnp1: well, not really, just started on jails 04:59:11 my bhyve host has a ton more ram, but the jail host is newer/ faster cpu 05:19:03 Hi; the uname on 14.3 has changed after the latest p16 update, it now says "FreeBSD 14.3-RELEASE-p16 #0 -dirty: Tue Jun 30 11:19:56 UTC 2026" 05:19:58 Before it only said "FreeBSD 14.3-RELEASE-p14 GENERIC amd64", does anyone know why? 05:23:56 I don't know anything. But isn't 14.3 end-of-life? 05:25:37 From today :) 05:27:54 It is still under support for another 32 minutes in my timezone. But then that's it. :D 05:39:05 congration 06:15:40 hi! 06:20:33 dead chat :( 06:21:23 nope 06:21:28 oh 06:21:29 ho 06:21:30 hi* 06:21:57 good morning/afternoon/evening (depending on where you are). Morning for me 06:23:37 It's around midnight for me lol 06:23:46 I've been playing Deltarune (on FreeBSD obviously) 06:25:59 hi hhao 06:27:58 okay, I'm not a game player myself 06:29:11 what do you use FreeBSD for? 06:29:31 server (web, mail, database) 06:30:00 and I use it to be in irc (weechat) 06:30:35 so not as a daily driver? 06:30:43 that's what i use it for 06:32:03 i know barely anyone who daily drives it, it's mostly server ppl :( 06:32:14 well not that it's necessarily a bad thing 06:32:52 lots of people in this channel use it as workstation 06:33:10 you just managed to find one who doesn't :) 06:33:39 ah 06:33:50 my friends used to use FreeBSD but they switched back to linux :( 06:42:34 i'm gonna go 06:42:35 cya 07:44:44 Can i use sendto() in capsicum mode ? 07:56:11 I don't see a reason why you shouldn't be able to use it (if you have the right capabilities of course) 08:12:33 I tied to use it on socket with CAP_RECV and CAP_SEND, but i got "sendto -1 errno 94 Not permitted in capability mode". 08:13:02 On UDP datagram socket. 08:17:05 was the socket connected? or did you have CAP_CONNECT? not sure if connecting to some host on the internet is permitted in capability mode 08:19:26 I am doing recvfrom and then sendto. 08:23:04 Sendto to adress got from recvfrom. 08:27:47 seems like a pattern that would be good to support in capability mode, does it work with CAP_CONNECT? if not, then I suggest opening a problem report, likely needs a new capability then for exactly that pattern 08:31:21 CAP_CONNECT doesynt work too. 08:31:47 Thank you for your help. 09:52:45 So, I've a question/problem. I have a jail (via the podman port) that has trouble reaching a bhyve VM on the same system (connected via VNET + bridge). Doing `ping $vm_ip` from the jail nets me a very high packet loss (around 5% on a good day, and upwards from there --- all the way to 100%) --- on Linux end, it looks like iptables is dropping packets due to an INVALID state. 09:54:17 The VM (which is Linux) is bridging a bunch of IPs from its own podman. All but two (10.24.0.1, which routes to the VM's "host", and 10.24.0.3) have this behaviour --- the two exceptions (10.24.0.{1,3}) work 100% perfectly though. 09:54:30 Doing the same ping from the host (not the jail) works perfectly fine, though, regardless of IP. 09:55:00 I suspect the misconfiguration is on BSD end (since it works fine if I don't send the ping from a jail), but I'm not even sure as to where to start looking ..... any ideas? =\ 09:56:02 IOW, `[host's] jail -> VM -> podman` is broken for all (except 1), `host -> VM -> podman` is 100% fine. 09:56:42 Dunno if there's a pattern, but from some quick & dirty tests just now: 09:58:03 10.24.0.2 => 91.7% packet loss; .0.3 => 0%; .0.5 => 87.5%; .0.7 => 10.8%; .0.10 => 14.9 09:58:30 (expect a ~5% variance, except for .0.3, where I've never ever observed a dropped packet) 10:01:04 I'm, frankly, flabbergasted at this point. Something's obviously very wrong, but I'm having trouble narrowing it down. 10:13:40 Well, NEVERMIND (I've just narrowed it down to a {docker,podman}-compose problem 10:13:42 ) 12:38:41 After update last week, Nextcloud's cron.php started complaining about "ps: cmd: keyword not found" and "ps: no valid keywords; valid keywords:". Anyone knows if this is a known issue? 12:40:49 ibs: update from what to what? if it were a known issue the venue would probably nextcloud 12:40:59 but take a peek at the file and find the ps call 12:59:09 ugh, one of the best decisions I ever made was shitcanning Nextcloud 12:59:43 hodapp: same 13:01:06 switched to a combination of Immich, Radicale, and Syncthing 13:01:43 and I never could understand how Nextcloud could fail so miserably at being behind a reverse proxy 13:02:01 like, 20-30 lines of boilerplate configuration and *still* fucking things up at random 13:35:29 I read here of Nextcloud problems I don't have. 13:40:14 hodapp. What kind of nextcloud reverse proxy problems are we talking about? Works perfectly fine for me 13:47:35 Ozymandias42: obscure problems around login flow and uploads are the ones I can recall. it requires special configuration. 13:48:39 In homelab setups or with SSO? 13:49:52 I should've checked bugzilla instead.. but people are aware and fixes are happening, I'm happy. https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296323 13:50:02 Because I use it with two containers. Nginx and phpfpm and have that behind a k8s Traefik ingress as well. And for me everything works. Even caldav and carddav 13:51:10 its caldav "worked" until I looked and it was inexplicably missing 30% of my contacts with no explanation 13:51:34 Ah. That sounds like a red flag indeed 13:52:12 I run NC in a jail (nginx+php_fpm) and the reverse proxy (nginx) in another (and postgresql in even another jail) 13:52:25 Haven't had that happen yet or haven't noticed at least. But makes sense that you switch to radicale then 13:53:22 joemie pretty much my setup. Just jails instead of k8s 13:53:40 You don't use redis or memcache btw? 14:00:26 redis I use indeed, but on a docker instance (on linux) 14:32:48 how do i set up the installer to use an http proxy and also connect to wifi properly? 14:33:05 if i go get a live system then type bsdinstall 14:33:11 it says 14:33:21 "wireless cannot be confiured without making changes to the local system!" 15:10:28 In zfsize, setting quota and refquota the the same value is like a traditional partitioned device? It can got above the value (quota) but is guaranteed that value in space? 15:10:48 can't go* 15:14:26 I think I'm confusing that with refreservation and reservation 17:10:29 list 23:33:12 runxiyu: weird error but it sounds like it needs to put firmware on it?