-
Remilia
very intrigued and confused by my manually edited configuration files in /usr/local/etc getting replaced by template ones after upgrading a package (it was a file related to that specific package), I was sure this cannot happen
-
» Remilia learns something new every day
-
antranigv
anyone here uses Kerberos? I have kerberos in a jail + nfs server + linux client working all fine, but I am not able to make macOS client work at all
-
Remilia
antranigv: which implementation do you have on FreeBSD?
-
antranigv
Remilia latest, so... MIT I think
-
Remilia
Mac OS is Heimdal if I recall right?
-
antranigv
it is? lemme check
-
antranigv
it just say "Kerberos 5 version 1.22.2"
-
Remilia
I think FreeBSD had Heimdal as the default
-
Remilia
> The Heimdal Kerberos implementation was explicitly developed outside of the US to avoid export regulations. The Heimdal Kerberos distribution is included in the base FreeBSD installation, and another distribution with more configurable options is available as security/heimdal in the Ports Collection.
-
Remilia
are you using krb5 from ports then
-
antranigv
no no, in FreeBSD 15 we moved to MIT.
-
Remilia
handbook needs updating
-
Remilia
I wonder what is with Mac OS... 10.2 had MIT, Monterey had Heimdal, ??
-
antranigv
yeah its weird.
-
nimaje
Remilia: if it is a config file then it should be marked as @sample in the pkg-plist and pkg will preserve your version, if it isn't marked @sample then pkg will override the file when upgrading
-
Remilia
nimaje: darn it
-
Remilia
it is just %%ETCDIR%%/config.kdl
-
nimaje
seems like you have to write a problem report
-
Remilia
going to make a quick patch first so I can attach that
-
Remilia
this really sucks because it was a somewhat complex configuration
-
nimaje
hm, pkg-plist contains %%ETCDIR%%/config.kdl %%ETCDIR%%/config.kdl.orig and %%ETCDIR%%/config.kdl.sample seems like someone wanted to use @sample but forgot to adjust the plist correctly and forgot to not install the .orig file from patching
-
mzar
@sample %%ETCDIR%%/config.kdl.sample is enough
-
Remilia
nimaje: yeah
-
Remilia
-
Remilia
wait darn the patch is not quite right
-
Remilia
nimaje: there's extra stuff in Makefile too so I'm amending my patch now haha (extra install invocations to add those .sample files manually, huh)
-
» Remilia is trying to figure out this @sample thing properly
-
mzar
-
Remilia
mzar: I read that an hour ago, thank you!
-
Remilia
nimaje: I wonder, if I am following an example from existing pkg-plists and it's not behaving in a way I expect, am I doing something really wrong :\
-
Remilia
taking `net-im/ejabberd/pkg-plist:@sample %%ETCDIR%%/inetrc.example %%ETCDIR%%/inetrc` as an example I added `@sample %%ETCDIR%%/config.kdl %%ETCDIR%%/config.kdl.sample` but `pkg remove` deletes the file even if it is modified...
-
Remilia
(`poudriere testport` passes)
-
dnp1
Remilia: `@sample %%ETCDIR%%/config.kdl.sample %%ETCDIR%%/config.kdl`
-
Remilia
I tried that too, sorry
-
Remilia
copied the wrong one
-
dnp1
" The format is @sample sample-file actual-config-file. "
-
Remilia
the one I pasted does not pass testport
-
Remilia
going to try again, maybe something went wrong :\
-
karolyi
just upgraded to 15.1-RELEASE-p1 from 14.4-RELEASE-p6, the dialog tool has disappeared. bsddialog is lacking the hotkey functionality
-
karolyi
also, I did not dare to risk the pkgbase update
-
Remilia
dnp1: testport'd again and for some reason that syntax does not work ha ha. the opposite (what I posted) passes but ???
-
Remilia
-
Remilia
so my problem becomes 'how do I pre-build rename files'
-
mzar
post-patch
-
Remilia
mzar: I refuse
-
Remilia
-
nimaje
hm, why does it not work with ${INSTALL_DATA} ? that should do exactly what you want as it just is install -m 0644
-
Remilia
nimaje: because you end up installing two files (.kdl, ,kdl.sample), which is incorrect in this case
-
Remilia
for @sample we want .sample in stagedir, nothing else, or we have to list it in pkg-plist and then it can't be .sample and will get deleted
-
nimaje
ah, you move inside STAGEDIR, ok
-
Remilia
I found lots of other ports that rename stock configuration files to .sample
-
Remilia
nimaje: yep, I tested it just now on my server and it finally does what I expected it to do: [varnish] [1/1] Deleting files for iocaine-3.5.0_1: 100% \ You may need to manually remove /usr/local/etc/iocaine/config.kdl if it is no longer needed.
-
Remilia
(after I deleted a single comment from the file)
-
» Remilia now needs to figure out everything back again
-
nimaje
I finally checked what is wrong with the ports feed, someone forgot that it is intendet for bots and put it behind bot protection…
bugs.freebsd.org/bugzilla/show_bug.cgi?id=296516
-
LXGHTNXNG
it could be put behind per IP and per subnet ratelimits
-
nimaje
I have no probem fetching the feed via my browser and via curl, just my feed reader (rss guard) had problems with it, but a workaround is setting the user agent to curl instead
-
karolyi
hey, did anything change since 14.4 in terms of pfctl calling from within a jail? my fail2ban jail started getting "pfctl: Operation not supported by device" after reinstalling its jail with 15 binaries. interestingly, 14 binaries didn't have this issue
-
rwp
If it is a vnet jail then all should work as expected. If it is not a vnet jail then how does that work? It's in a jail. Says me but you could convince me there is a use case for it.
-
karolyi
rwp: I've enabled access to /dev/pf in the jail, fail2ban runs there checking the logs, and adds bans to PF... at least it did until I've upgraded
-
karolyi
btw it's not a vnet jail
-
karolyi
now I'm trying to make sense of what happens but truss-ing a "pfctl -s rules" doesn't give much information
-
karolyi
the interesting thing is, it worked on 15 kernel and 14 userland, it doesn't with 15/15
-
karolyi
so I'm thinking something has changed in pfctl that does this
-
kevans
newer versions use netlink for some (most?) opes
-
kevans
ops
-
Remilia
all my opes, gone
-
karolyi
is that something I can enable within that jail?
-
karolyi
okay, I've reached an impasse. putting fail2ban in a vnet jail would only manage the jail's pf rules, and a non-vnet jail now just rejects pfctl requests
-
karolyi
fail2ban needs to run in the host
-
karolyi
alternatively, putting freebsd 14's pfctl into the jail as the path for it still exists, but it's a fugly hack I won't do
-
rwp
I guess you must have been running fail2ban in a jail on the root file system? So it was a process jail only in that case, since it had access to all files on the file system? I know that process jails are useful for trapping the process.
-
rwp
In the case of fail2ban it only processes local files. It doesn't have a large attack surface from the hostile Internet to attack it. So I have never considered running it inside of a process jail.
-
karolyi
it was my shtick to put everything possible into a jail so as to have as little as possible installed stuff on the host
-
rwp
In order for something to attack it that hostile actor would need to cause something malicious to be logged into a log file, and then fail2ban would need to read it. That's a stretch.
-
karolyi
turns out it was a bad idea with f2b
-
rwp
All of my jails have their own separate filesystem that they are running in a jail.
-
karolyi
same here, the logs were only a nullmount
-
karolyi
I could still chroot it and circumvent the issue but that seems to me an even bigger hack :)
-
rwp
But you wanted something inside the jail to affect something outside the jail.
-
karolyi
yeah, it's how it worked so far, with having /dev/pf in it
-
rwp
A chroot is a layer. And then the processes in the chroot could of course communicate outside the chroot.
-
runxiyu_
Should I add regression tests for bugs that I introduced and spotted during development?
-
runxiyu_
like, before even sending the patch anywhere
-
rwp
If somehow fail2ban turned evil then it would still be filesystem blocked from other files. Even if it can communicate out.
-
rwp
runxiyu_, If the project for which you are reporting a bug has regression tests and you can add one for it then yes that is appreciated. But if that is going to significantly delay reporting then I think you can go ahead and report it. (Says me who has no idea what project you are working with here.)
-
rwp
karolyi, Have you exhausted looking to see if there is a sysctl option which will re-enable the feature you have been using? I know there are many optional things that can be enabled.
-
runxiyu_
rwp: sorry, I mean
-
runxiyu_
I'm writing up a kernel patch to improve capsicum for jaildesc
-
runxiyu_
And there's a subtle point about somewhere where _SET looks appropriate but I should actually check for _SET|_ATTACH
-
runxiyu_
I'm thinking whether I should regress-test that
-
karolyi
rwp: there is allow.routing but no equivalent exists for pf
-
karolyi
D49843 = FreeBSD Phabricator revision for commit 3a53fe2cc4b7 ("jail: add allow.routing jail permission"), author Lexi Winter, it added a new jail permission allow.routing (sys/sys/jail.h: PR_ALLOW_ROUTING) letting a non-VNET jail modify the host's routing table via PRIV_NET_ROUTE, and flagged the netlink RTM_NEWROUTE/RTM_DELROUTE handlers (sys/netlink/route/rt.c) with RTNL_F_ALLOW_NONVNET_JAIL so they
-
karolyi
bypass the usual VNET-only restriction when that jail permission is set.
-
rwp
karolyi, I think that would be a reasonable thing to make a problem report since it removes a feature which had been working without any way to regain that capability. It might not have been explicitly meant to remove it.
-
karolyi
rwp: where do I do that?
-
karolyi
bugs.freebsd.org?
-
rwp
Yes. That's where I would make the report. The author of that commit you referenced <ivy> hasn't been seen in this channel since June 8th but often hangs out here. But it's been long enough that making a PR there seems reasonable. It's a behavior change. It's a regression for you.
-
karolyi
I'm making a report now
-
rwp
I have this idea that explicit changes in behavior that affect things should have a note of some sort in the release notes. That way we know it either is or is not a regression bug. Some things could go either way and unless you are deep into the code it can be hard to know sometimes.
-
karolyi
-
karolyi
full transparency, I've used claude code to have a go at the freebsd-src repo to get a glimpse of what I'm really facing, while I was expressing my concerns on here
-
rwp
It does read like an AI generated report. :-( I think most people will know this even though you didn't say it.
-
karolyi
AI or not, the crux of the matter is there in a detailed way, and the first paragraph is mine :) not AI
-
karolyi
not sure I would have been able to phrase it better btw, without risking a lot of follow-up questions
-
rwp
I agree that the main point of the report is true regardless and I think it is good to have it reported. I doubt this was an intentional change. I am thinking it just fell out of the intended change and wasn't noticed.
-
karolyi
well I need to put fail2ban over (with the tools I've made around it) over to the host jail nonetheless
-
rwp
Good luck and happy hacking!
-
kevans
Remilia: in my defense, I'm from the midwest bits of the US and we do a lot of opeing
-
karolyi
I've made a munin graph source for graphing the amount of bans per jail from its sqlite db
-
mason
karolyi: Coming at these things without slop will get you more credibility and traction.
-
karolyi
mason: again, the problem is that I'm unsure I could have phrased it better, since it's got a lot of technical detail and I'm not a freebsd dev
-
kevans
rwp: it was noticed, but netlink doesn't have a good answer at the moment
-
karolyi
kevans: I would be happy with an allow.pf sysctl similar to allow.routing
-
rwp
karolyi, You would be better off not including the technical detail then. Don't run faster than your angels can fly. The AI included a bunch of stuff only marginally relevant. Which is one of the fingerprints of AI generated reports.
-
LXGHTNXNG
I sometimes naturally speak like that, going off on weird tangents
-
karolyi
btw I was thinking about slowly getting over to VNET based jails, which is a PITA since I have an ansible based scriptset that creates my jails (of which I have 42 now)
-
rwp
It worked on 14. It fails on 15. That's succinct and anyone into that part of the code base will be able to reproduce it once asked to look at that detail. And they will know all of the things the AI is trying to helpfully educate us about which is all peripheral.
-
karolyi
now with this bug(?) surfacing, it seems I'll need to pick up the speed with that
-
mason
karolyi: Ironically, I'm moving the other way. Everything was VNET but I've come to appreciate the relative lightness of traditional jail networking, with pf.
-
rwp
If you have 42 non-vnet jails and they are doing good work for you then probably they should not be vnet jails. (Note that I *LOVE* vnet jails for creating a software defined networking environment for a test lab setup. Totally awesome.) But that does not sound like what you are doing. So I would not make converting to a vnet jail a priority.
-
karolyi
mason: if you would see my configuration, you wouldn't say it's light :)
-
karolyi
rwp: right now all my jails work after the upgrade, it's only the fail2ban one that hit this thing
-
mason
karolyi: Ignoring the bug, do you need to manipulate pf that way? This might be a little Rube Goldberg, but if you realize you need to add an address to a table, add it to a file and have something on the host going through regularly and parsing/processing those files per-jail.
-
rwp
Like mason if I can make something work in a non-vnet jail then that's my first choice. It's simpler. It keeps things simpler. I use vnet jails when I want to create a test environment to test something out and need, say, a dhcp server running to hand out many addresses or something.
-
mason
karolyi: For instance, I quite literally have a Perl script tailing logs, and then acting if a match is found. Your case would be far simpler, just seeing that a new line has been added, and either parsing the whole thing for changes, or just adding what's new, or whatever. Should be entirely doable with a couple minutes quick hacking.
-
mason
(My Perl script tailing logs is what I use instead of fail2ban, because in my experience, fail2ban fails2ban all too often.)
-
karolyi
mason: yeah I was thinking on it, especially after realizing what other tooling I have in that jail
-
mason
(My stuff might be described better as instaban.)
-
rwp
The fail2ban.log file could be tail'd and parsed.
-
karolyi
I just need to patch the direct pf manipulation over to this new method
-
rwp
But I would not Rube Goldberg this one. Because then your tail'd processing would be in another jail, right? Where does it end? Isn't fail2ban vetted well enough? It's a python program that runs on half of the Internet's systems already.
-
mason
karolyi: If you try this approach and hit any hurdles, I'd be more than happy to help. Should pfctl work from within jails? Sure, if that permission exists and works right. But don't let that stop you. :)
-
Remilia
kevans: nah you just reminded me of that hilarious post from those 'NFTs are definitely the future' years
-
mason
rwp: I'd think "on the host" rather than in another jail, but I don't know karolyi's firewalling set up so I'm guessing.
-
mason
rwp: If popularity mattered, we'd all agree that McDonald's is the world's finest cuisine.
-
rwp
I run it on the host. I think that's the normal configuration.
-
karolyi
mason: probably a quick script that uses inotify on the host can do the job, once I've modified fail2ban to emit the pf changes to files
-
mason
karolyi: Is the host Linux??
-
mason
Oh, we have some kind of inotify emulation now I guess.
-
karolyi
mason: I'm on FreeBSD 15.1 all the way :)
-
mason
I still have a lot of 14 deployed. Although it's a mix now - 14.4, 15.0, 15.1.
-
karolyi
it's the inotify python module, I've use it in other projects, works. probably uses kqueue as a backend
-
mason
Yeah. Useful.
-
rwp
mason, I take the point that popularity is not an indicator of the best thing. But it does get back to many eyes will find most bugs. And jails is specifically a security layer. So...
-
karolyi
btw the thing about the non-vnet jail is, it's got ipv4 on one interface (lo0) and ipv6 on another (bridge0). some daemons don't like such configurations, php-fpm would be one
-
mason
Anyway, I'll be doing projects off and on today, but if I can be of use, say the word and I imagine I'll be checking in at least hourly or thereabouts.
-
rwp
karolyi, Some VPS hosting providers split IPv4 & IPv6 onto different networking devices and it always makes me wonder why. And breaks a bunch of assumptions I had previously made and then had to modify to make work. Gah!
-
karolyi
mason: thanks for the offer, will let you know but I probably can get it done with a little hacking :) I want to keep the f2b jail as is, with as little work as possible
-
mason
karolyi: Good hunting then. :)
-
rwp
mason,
freebsd.org/releases/15.0R/relnotes "FreeBSD now natively implements the Linux inotify(2) interface. The system calls themselves are not API-compatible, but libc provides an API-compatible interface, so software which relies on inotify can be run unmodified. f1f230439fa4 (Sponsored by Klara, Inc.)"
-
rwp
Which is pretty cool! And something I have been anxiously waiting for so I can move some more things from linux over to FreeBSD. One of them is on my task goal list for today. :-)
-
Remilia
oh we can finally monitor directories whole
-
Remilia
actually, does syncthing build with it...
-
rwp
I haven't tried it yet but I'll be giving it a good workout very soon. This has been a feature I have been needing.
-
rwp
I have a setup on a linux system which uses it and this will allow me to convert it to FreeBSD. Woot!
-
kevans
yeah, inotify is quite handy
-
karolyi
oh, the python module is called watchdog... no idea why I was thinking inotify
-
kevans
the kqueue shim was fine, but iirc there are at least a few semantic differences that you can't adequately capture with kqueue at all
-
rwp
Remilia, I recently heard someone complaining about how syncthing was problematic because, up until now anyway, it wanted to use the inotify interface and it was not available on FreeBSD. I imagine that syncthing will now be hugely better. I don't know if it has already been converted or not.
-
karolyi
Supported Platforms: FreeBSD/BSD (kqueue)
-
Remilia
rwp: golang.org/x/sys/unix does not seem to do inotify on freebsd yet
-
karolyi
kevans: I remember reading about that somewhere (might have been years ago), but the way I use it, works. just getting notified if files change
-
rwp
Remilia, :-( Let's hope that gets improved soon then. However I am not using syncthing myself so this is just wishing for those that do use it to have a better day in the future.
-
Remilia
I have syncthing since it's kind of the best solution out of simple ones, but mine's got less than 15 files in the shared directory so it's fine
-
rwp
Remilia, Right! Small numbers of files are fine. In my inotify case it is watching 342,529 files which feels like a significant number.
-
Remilia
[19:52:16] <karolyi> I just need to patch the direct pf manipulation over to this new method
-
Remilia
^ but
-
Remilia
doesn't fail2ban support custom actions?
-
Remilia
do you really need to 'patch' it
-
Remilia
> An action is a shell command (or commands) that Fail2Ban executes at appropriate times. For example a ban action is executed when Fail2Ban invokes a ban against an IP address. Actions are normally defined by configuration files in the action.d subdirectory.
-
geometry
Which files are included in the compat14x and compat15x packages? (I'm pretty sure I found a listing previously, but...)
-
geometry
Ah, "compat14x-<arch>`, not "compat14x".
-
karolyi
Remilia: I'm creating a new action script, basically
-
kevans
runxiyu_: unless your regression test is adding massive amounts of overhead to the test suite for little gain, it's worth adding. particularly if it tests a subtle corner like that
-
runxiyu_
alright, ty
-
runxiyu_
its not much overhead imo
-
hernan604
hey guys, anyone using bastille jail here ? i noticed some hangs
-
hernan604
asking in #bastillebsd but that chan seems a bit slow
-
hernan604
ok, i think i was able to reproduce the problem at least in my setup:
-
hernan604
open screen (or tmux -- however i havent tested with tmux), create 2 windows in the screen. Go to window 1
-
hernan604
ensure the jail is stopped.
-
hernan604
run: sudo bastille console -a jailtest
-
hernan604
immediately press ctlr+a so screen/tmux switches to the other window (This hangs on for 1-2 seconds brefore it switches to the second window)
-
hernan604
im gonna try that again..
-
hernan604
wow, doing the same with "stop" also hangs.. for like 10 seconds
-
hernan604
on (screen/tmux)window#1 sudo bastille stop jailtest
-
hernan604
then immediately press ctrl+a to switch to the other window
-
hernan604
then wait... it hangs for 10 seconds before switching to the other window
-
hernan604
does that only happens to me ?
-
hernan604
(and i dont mean this is a bastille problem, i just want to know if there is a fix, or maybe its an only me problem)
-
rwp
hernan604, I think what you are seeing is that when bastille creates a new jail that it must do a lot of file copying and this uses a lot of file system I/O and probably a spike of memory use too. This is causing screen to not get full machine cycles and the visible pause until it can catch up.
-
rwp
You can probably get the same effect if you untar base.txz or cp -R a large directory tree or similar things that cause a lot of file copy activity all at once.
-
hernan604
rwp: right, that would "explain" why i get the same problem in another host that seems to hang randomly with the jails running
-
hernan604
but then its unusable
-
hernan604
if one single untar causes everything to hang, its "unusable"
-
hernan604
there must be some solution
-
hernan604
cant be that everyones jails hangs and nobody complains ? that makes no sense
-
hernan604
these random hangs would cause weeks of total time loss during a year
-
hernan604
maybe not weeks, but a good amount of lost processing time
-
karolyi
so my bridging-pfctl-between-jail-and-host script is done, and it works like a charm
-
rwp
hernan604, How long do these hangs last? I thought you said for like 10 seconds? No? Then things become responsive again?
-
rwp
What I described is just a momentary system saturation which eventually (like 10 seconds) sorts out and then things move on.
-
rwp
If it is like that then that's not what I would describe as unusuable. And that can be mitigated if the system has more RAM. That really only happens when the system is quite short on memory.
-
rwp
How much memory is on your system?
-
rwp
karolyi, Woot! \o/
-
karolyi
rwp: now let's wait for the response for my submitted bug :)
-
rwp
I subscribed to the bug so I could see what happened with it.
-
hernan604
rwp: yes 10 secs. 128gb ram
-
rwp
Well 128 GB of ram seems like it should be more than enough!
-
hernan604
only an nfs share running, plus this jail that hangs and the jail is brand new
-
rwp
Is it only around 10 seconds? In which case I would not call it a hang. I can see that the pause would be annoying. But a hang would be like you go off for an hour and it is still wedged up stuck. That's a hang.
-
hernan604
rwp: 10 seconds +-
-
hernan604
but it can affect other running processes
-
rwp
I also think that with 128 GB of RAM that it should not be pausing with a burst of file copy either. Keep asking this question. I don't know the answer but maybe someone else will be by who will have a suggestion.
-
hernan604
well it does affect.. because the processes become unresponsive
-
rwp
Permanently unresponsive?
-
hernan604
for the 10 seconds
-
rwp
Then it is not a hang.
-
rwp
I know we are just debating the words here but a hang has a specific meaning when debugging computer programs and it will lead to the wrong conclusion.
-
hernan604
well, if i run stuff in the host without a jail, it wouldnt hang... maybe thats what i will do
-
hernan604
rwp: well imagine i have 10 customers, 1 on each jail... and they are using the jails and it hangs randomly for 10 seconds, multiple times a day.... is this a good service ?
-
hernan604
imagine if everyones VPS hosting VM hangs for 10 seconds...
-
hernan604
randomly, everyday, all the time
-
hernan604
something wrong is not right
-
rwp
I wasn't saying that something was not wrong. I am just saying it isn't a hang.
-
rwp
And as I said, keep asking the question. I don't know the answer. But maybe someone else who happens by will know. And if not here then send an email to the questions⊙fo mailing list. More deep expertise there.
-
hernan604
well, its unresponsive, so i concluded its a hang
-
rwp
Or the web forums. But I never touch the web forums. Other people do though.
-
hernan604
ah good idea
-
hernan604
i created an issue in bastille github
-
rwp
Please say the URL here for that github issue so that curious lurkers can browse it too.