09:26:39 very intrigued and confused by my manually edited configuration files in /usr/local/etc getting replaced by template ones after upgrading a package (it was a file related to that specific package), I was sure this cannot happen 09:27:19 * Remilia learns something new every day 09:46:59 anyone here uses Kerberos? I have kerberos in a jail + nfs server + linux client working all fine, but I am not able to make macOS client work at all 09:52:23 antranigv: which implementation do you have on FreeBSD? 09:52:36 Remilia latest, so... MIT I think 09:52:54 Mac OS is Heimdal if I recall right? 09:53:36 it is? lemme check 09:54:40 it just say "Kerberos 5 version 1.22.2" 09:54:44 I think FreeBSD had Heimdal as the default 09:55:15 > The Heimdal Kerberos implementation was explicitly developed outside of the US to avoid export regulations. The Heimdal Kerberos distribution is included in the base FreeBSD installation, and another distribution with more configurable options is available as security/heimdal in the Ports Collection. 09:55:26 are you using krb5 from ports then 09:56:41 no no, in FreeBSD 15 we moved to MIT. 10:03:33 handbook needs updating 10:04:53 I wonder what is with Mac OS... 10.2 had MIT, Monterey had Heimdal, ?? 10:05:18 yeah its weird. 10:28:40 Remilia: if it is a config file then it should be marked as @sample in the pkg-plist and pkg will preserve your version, if it isn't marked @sample then pkg will override the file when upgrading 10:45:15 nimaje: darn it 10:45:31 it is just %%ETCDIR%%/config.kdl 10:46:29 seems like you have to write a problem report 10:46:53 going to make a quick patch first so I can attach that 10:48:27 this really sucks because it was a somewhat complex configuration 10:53:26 hm, pkg-plist contains %%ETCDIR%%/config.kdl %%ETCDIR%%/config.kdl.orig and %%ETCDIR%%/config.kdl.sample seems like someone wanted to use @sample but forgot to adjust the plist correctly and forgot to not install the .orig file from patching 10:55:32 @sample %%ETCDIR%%/config.kdl.sample is enough 10:56:37 nimaje: yeah 10:59:58 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296506 done 11:08:49 wait darn the patch is not quite right 11:16:53 nimaje: there's extra stuff in Makefile too so I'm amending my patch now haha (extra install invocations to add those .sample files manually, huh) 12:02:35 * Remilia is trying to figure out this @sample thing properly 12:08:15 Remilia: https://docs.freebsd.org/en/books/porters-handbook/book/#plist-config 12:11:25 mzar: I read that an hour ago, thank you! 12:13:18 nimaje: I wonder, if I am following an example from existing pkg-plists and it's not behaving in a way I expect, am I doing something really wrong :\ 12:15:23 taking `net-im/ejabberd/pkg-plist:@sample %%ETCDIR%%/inetrc.example %%ETCDIR%%/inetrc` as an example I added `@sample %%ETCDIR%%/config.kdl %%ETCDIR%%/config.kdl.sample` but `pkg remove` deletes the file even if it is modified... 12:16:01 (`poudriere testport` passes) 12:22:22 Remilia: `@sample %%ETCDIR%%/config.kdl.sample %%ETCDIR%%/config.kdl` 12:23:01 I tried that too, sorry 12:23:05 copied the wrong one 12:23:08 " The format is @sample sample-file actual-config-file. " 12:23:18 the one I pasted does not pass testport 12:24:37 going to try again, maybe something went wrong :\ 12:34:52 just upgraded to 15.1-RELEASE-p1 from 14.4-RELEASE-p6, the dialog tool has disappeared. bsddialog is lacking the hotkey functionality 12:35:07 also, I did not dare to risk the pkgbase update 12:49:39 dnp1: testport'd again and for some reason that syntax does not work ha ha. the opposite (what I posted) passes but ??? 12:55:21 https://docs.freebsd.org/en/books/porters-handbook/book/#plist-keywords-examples looks like that is the right syntax 13:12:12 so my problem becomes 'how do I pre-build rename files' 13:30:57 post-patch 13:44:08 mzar: I refuse 14:06:29 https://bugs.freebsd.org/bugzilla/attachment.cgi?id=272486&action=diff and now it is Done 14:33:40 hm, why does it not work with ${INSTALL_DATA} ? that should do exactly what you want as it just is install -m 0644 14:34:29 nimaje: because you end up installing two files (.kdl, ,kdl.sample), which is incorrect in this case 14:35:53 for @sample we want .sample in stagedir, nothing else, or we have to list it in pkg-plist and then it can't be .sample and will get deleted 14:36:45 ah, you move inside STAGEDIR, ok 14:36:49 I found lots of other ports that rename stock configuration files to .sample 14:37:40 nimaje: yep, I tested it just now on my server and it finally does what I expected it to do: [varnish] [1/1] Deleting files for iocaine-3.5.0_1: 100% \ You may need to manually remove /usr/local/etc/iocaine/config.kdl if it is no longer needed. 14:37:58 (after I deleted a single comment from the file) 14:40:45 * Remilia now needs to figure out everything back again 15:51:34 I finally checked what is wrong with the ports feed, someone forgot that it is intendet for bots and put it behind bot protection… https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296516 15:55:47 it could be put behind per IP and per subnet ratelimits 15:57:51 I have no probem fetching the feed via my browser and via curl, just my feed reader (rss guard) had problems with it, but a workaround is setting the user agent to curl instead 16:36:35 hey, did anything change since 14.4 in terms of pfctl calling from within a jail? my fail2ban jail started getting "pfctl: Operation not supported by device" after reinstalling its jail with 15 binaries. interestingly, 14 binaries didn't have this issue 16:40:59 If it is a vnet jail then all should work as expected. If it is not a vnet jail then how does that work? It's in a jail. Says me but you could convince me there is a use case for it. 16:42:47 rwp: I've enabled access to /dev/pf in the jail, fail2ban runs there checking the logs, and adds bans to PF... at least it did until I've upgraded 16:42:57 btw it's not a vnet jail 16:45:17 now I'm trying to make sense of what happens but truss-ing a "pfctl -s rules" doesn't give much information 16:46:29 the interesting thing is, it worked on 15 kernel and 14 userland, it doesn't with 15/15 16:46:46 so I'm thinking something has changed in pfctl that does this 16:51:35 newer versions use netlink for some (most?) opes 16:51:36 ops 16:53:21 all my opes, gone 16:54:50 is that something I can enable within that jail? 17:45:09 okay, I've reached an impasse. putting fail2ban in a vnet jail would only manage the jail's pf rules, and a non-vnet jail now just rejects pfctl requests 17:47:49 fail2ban needs to run in the host 17:49:37 alternatively, putting freebsd 14's pfctl into the jail as the path for it still exists, but it's a fugly hack I won't do 17:53:41 I guess you must have been running fail2ban in a jail on the root file system? So it was a process jail only in that case, since it had access to all files on the file system? I know that process jails are useful for trapping the process. 17:54:30 In the case of fail2ban it only processes local files. It doesn't have a large attack surface from the hostile Internet to attack it. So I have never considered running it inside of a process jail. 17:55:14 it was my shtick to put everything possible into a jail so as to have as little as possible installed stuff on the host 17:55:18 In order for something to attack it that hostile actor would need to cause something malicious to be logged into a log file, and then fail2ban would need to read it. That's a stretch. 17:55:32 turns out it was a bad idea with f2b 17:55:57 All of my jails have their own separate filesystem that they are running in a jail. 17:56:19 same here, the logs were only a nullmount 17:56:53 I could still chroot it and circumvent the issue but that seems to me an even bigger hack :) 17:56:56 But you wanted something inside the jail to affect something outside the jail. 17:57:48 yeah, it's how it worked so far, with having /dev/pf in it 17:57:56 A chroot is a layer. And then the processes in the chroot could of course communicate outside the chroot. 17:58:27 Should I add regression tests for bugs that I introduced and spotted during development? 17:58:37 like, before even sending the patch anywhere 17:58:40 If somehow fail2ban turned evil then it would still be filesystem blocked from other files. Even if it can communicate out. 17:59:54 runxiyu_, If the project for which you are reporting a bug has regression tests and you can add one for it then yes that is appreciated. But if that is going to significantly delay reporting then I think you can go ahead and report it. (Says me who has no idea what project you are working with here.) 18:01:16 karolyi, Have you exhausted looking to see if there is a sysctl option which will re-enable the feature you have been using? I know there are many optional things that can be enabled. 18:01:28 rwp: sorry, I mean 18:01:39 I'm writing up a kernel patch to improve capsicum for jaildesc 18:02:01 And there's a subtle point about somewhere where _SET looks appropriate but I should actually check for _SET|_ATTACH 18:02:09 I'm thinking whether I should regress-test that 18:03:40 rwp: there is allow.routing but no equivalent exists for pf 18:04:23 D49843 = FreeBSD Phabricator revision for commit 3a53fe2cc4b7 ("jail: add allow.routing jail permission"), author Lexi Winter, it added a new jail permission allow.routing (sys/sys/jail.h: PR_ALLOW_ROUTING) letting a non-VNET jail modify the host's routing table via PRIV_NET_ROUTE, and flagged the netlink RTM_NEWROUTE/RTM_DELROUTE handlers (sys/netlink/route/rt.c) with RTNL_F_ALLOW_NONVNET_JAIL so they 18:04:29 bypass the usual VNET-only restriction when that jail permission is set. 18:05:16 karolyi, I think that would be a reasonable thing to make a problem report since it removes a feature which had been working without any way to regain that capability. It might not have been explicitly meant to remove it. 18:08:45 rwp: where do I do that? 18:08:51 bugs.freebsd.org? 18:14:01 Yes. That's where I would make the report. The author of that commit you referenced hasn't been seen in this channel since June 8th but often hangs out here. But it's been long enough that making a PR there seems reasonable. It's a behavior change. It's a regression for you. 18:16:45 I'm making a report now 18:20:31 I have this idea that explicit changes in behavior that affect things should have a note of some sort in the release notes. That way we know it either is or is not a regression bug. Some things could go either way and unless you are deep into the code it can be hard to know sometimes. 18:25:03 rwp: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296521 18:26:07 full transparency, I've used claude code to have a go at the freebsd-src repo to get a glimpse of what I'm really facing, while I was expressing my concerns on here 18:38:39 It does read like an AI generated report. :-( I think most people will know this even though you didn't say it. 18:39:08 AI or not, the crux of the matter is there in a detailed way, and the first paragraph is mine :) not AI 18:39:57 not sure I would have been able to phrase it better btw, without risking a lot of follow-up questions 18:39:59 I agree that the main point of the report is true regardless and I think it is good to have it reported. I doubt this was an intentional change. I am thinking it just fell out of the intended change and wasn't noticed. 18:40:55 well I need to put fail2ban over (with the tools I've made around it) over to the host jail nonetheless 18:41:25 Good luck and happy hacking! 18:41:30 Remilia: in my defense, I'm from the midwest bits of the US and we do a lot of opeing 18:41:50 I've made a munin graph source for graphing the amount of bans per jail from its sqlite db 18:42:43 karolyi: Coming at these things without slop will get you more credibility and traction. 18:43:27 mason: again, the problem is that I'm unsure I could have phrased it better, since it's got a lot of technical detail and I'm not a freebsd dev 18:43:40 rwp: it was noticed, but netlink doesn't have a good answer at the moment 18:44:34 kevans: I would be happy with an allow.pf sysctl similar to allow.routing 18:44:42 karolyi, You would be better off not including the technical detail then. Don't run faster than your angels can fly. The AI included a bunch of stuff only marginally relevant. Which is one of the fingerprints of AI generated reports. 18:45:46 I sometimes naturally speak like that, going off on weird tangents 18:46:19 btw I was thinking about slowly getting over to VNET based jails, which is a PITA since I have an ansible based scriptset that creates my jails (of which I have 42 now) 18:46:28 It worked on 14. It fails on 15. That's succinct and anyone into that part of the code base will be able to reproduce it once asked to look at that detail. And they will know all of the things the AI is trying to helpfully educate us about which is all peripheral. 18:47:46 now with this bug(?) surfacing, it seems I'll need to pick up the speed with that 18:47:47 karolyi: Ironically, I'm moving the other way. Everything was VNET but I've come to appreciate the relative lightness of traditional jail networking, with pf. 18:48:14 If you have 42 non-vnet jails and they are doing good work for you then probably they should not be vnet jails. (Note that I *LOVE* vnet jails for creating a software defined networking environment for a test lab setup. Totally awesome.) But that does not sound like what you are doing. So I would not make converting to a vnet jail a priority. 18:48:15 mason: if you would see my configuration, you wouldn't say it's light :) 18:49:14 rwp: right now all my jails work after the upgrade, it's only the fail2ban one that hit this thing 18:49:15 karolyi: Ignoring the bug, do you need to manipulate pf that way? This might be a little Rube Goldberg, but if you realize you need to add an address to a table, add it to a file and have something on the host going through regularly and parsing/processing those files per-jail. 18:49:52 Like mason if I can make something work in a non-vnet jail then that's my first choice. It's simpler. It keeps things simpler. I use vnet jails when I want to create a test environment to test something out and need, say, a dhcp server running to hand out many addresses or something. 18:50:46 karolyi: For instance, I quite literally have a Perl script tailing logs, and then acting if a match is found. Your case would be far simpler, just seeing that a new line has been added, and either parsing the whole thing for changes, or just adding what's new, or whatever. Should be entirely doable with a couple minutes quick hacking. 18:51:14 (My Perl script tailing logs is what I use instead of fail2ban, because in my experience, fail2ban fails2ban all too often.) 18:51:29 mason: yeah I was thinking on it, especially after realizing what other tooling I have in that jail 18:51:34 (My stuff might be described better as instaban.) 18:51:36 The fail2ban.log file could be tail'd and parsed. 18:52:16 I just need to patch the direct pf manipulation over to this new method 18:52:27 But I would not Rube Goldberg this one. Because then your tail'd processing would be in another jail, right? Where does it end? Isn't fail2ban vetted well enough? It's a python program that runs on half of the Internet's systems already. 18:52:28 karolyi: If you try this approach and hit any hurdles, I'd be more than happy to help. Should pfctl work from within jails? Sure, if that permission exists and works right. But don't let that stop you. :) 18:52:32 kevans: nah you just reminded me of that hilarious post from those 'NFTs are definitely the future' years 18:52:58 rwp: I'd think "on the host" rather than in another jail, but I don't know karolyi's firewalling set up so I'm guessing. 18:53:36 rwp: If popularity mattered, we'd all agree that McDonald's is the world's finest cuisine. 18:53:44 I run it on the host. I think that's the normal configuration. 18:53:58 mason: probably a quick script that uses inotify on the host can do the job, once I've modified fail2ban to emit the pf changes to files 18:54:07 karolyi: Is the host Linux?? 18:54:20 Oh, we have some kind of inotify emulation now I guess. 18:54:24 mason: I'm on FreeBSD 15.1 all the way :) 18:54:55 I still have a lot of 14 deployed. Although it's a mix now - 14.4, 15.0, 15.1. 18:55:01 it's the inotify python module, I've use it in other projects, works. probably uses kqueue as a backend 18:55:17 Yeah. Useful. 18:55:23 mason, I take the point that popularity is not an indicator of the best thing. But it does get back to many eyes will find most bugs. And jails is specifically a security layer. So... 18:56:20 btw the thing about the non-vnet jail is, it's got ipv4 on one interface (lo0) and ipv6 on another (bridge0). some daemons don't like such configurations, php-fpm would be one 18:57:02 Anyway, I'll be doing projects off and on today, but if I can be of use, say the word and I imagine I'll be checking in at least hourly or thereabouts. 18:57:39 karolyi, Some VPS hosting providers split IPv4 & IPv6 onto different networking devices and it always makes me wonder why. And breaks a bunch of assumptions I had previously made and then had to modify to make work. Gah! 18:57:45 mason: thanks for the offer, will let you know but I probably can get it done with a little hacking :) I want to keep the f2b jail as is, with as little work as possible 18:58:09 karolyi: Good hunting then. :) 18:59:25 mason, https://www.freebsd.org/releases/15.0R/relnotes/ "FreeBSD now natively implements the Linux inotify(2) interface. The system calls themselves are not API-compatible, but libc provides an API-compatible interface, so software which relies on inotify can be run unmodified. f1f230439fa4 (Sponsored by Klara, Inc.)" 19:00:06 Which is pretty cool! And something I have been anxiously waiting for so I can move some more things from linux over to FreeBSD. One of them is on my task goal list for today. :-) 19:01:05 oh we can finally monitor directories whole 19:01:48 actually, does syncthing build with it... 19:01:51 I haven't tried it yet but I'll be giving it a good workout very soon. This has been a feature I have been needing. 19:02:15 I have a setup on a linux system which uses it and this will allow me to convert it to FreeBSD. Woot! 19:03:43 yeah, inotify is quite handy 19:04:08 oh, the python module is called watchdog... no idea why I was thinking inotify 19:04:45 the kqueue shim was fine, but iirc there are at least a few semantic differences that you can't adequately capture with kqueue at all 19:04:49 Remilia, I recently heard someone complaining about how syncthing was problematic because, up until now anyway, it wanted to use the inotify interface and it was not available on FreeBSD. I imagine that syncthing will now be hugely better. I don't know if it has already been converted or not. 19:05:10 Supported Platforms: FreeBSD/BSD (kqueue) 19:05:40 rwp: golang.org/x/sys/unix does not seem to do inotify on freebsd yet 19:06:31 kevans: I remember reading about that somewhere (might have been years ago), but the way I use it, works. just getting notified if files change 19:07:23 Remilia, :-( Let's hope that gets improved soon then. However I am not using syncthing myself so this is just wishing for those that do use it to have a better day in the future. 19:08:37 I have syncthing since it's kind of the best solution out of simple ones, but mine's got less than 15 files in the shared directory so it's fine 19:10:41 Remilia, Right! Small numbers of files are fine. In my inotify case it is watching 342,529 files which feels like a significant number. 19:13:59 [19:52:16] I just need to patch the direct pf manipulation over to this new method 19:14:02 ^ but 19:14:09 doesn't fail2ban support custom actions? 19:14:18 do you really need to 'patch' it 19:16:41 > An action is a shell command (or commands) that Fail2Ban executes at appropriate times. For example a ban action is executed when Fail2Ban invokes a ban against an IP address. Actions are normally defined by configuration files in the action.d subdirectory. 19:17:07 Which files are included in the compat14x and compat15x packages? (I'm pretty sure I found a listing previously, but...) 19:23:21 Ah, "compat14x-`, not "compat14x". 19:24:29 Remilia: I'm creating a new action script, basically 19:56:41 runxiyu_: unless your regression test is adding massive amounts of overhead to the test suite for little gain, it's worth adding. particularly if it tests a subtle corner like that 19:57:06 alright, ty 19:57:12 its not much overhead imo 21:40:00 hey guys, anyone using bastille jail here ? i noticed some hangs 21:40:12 asking in #bastillebsd but that chan seems a bit slow 21:41:59 ok, i think i was able to reproduce the problem at least in my setup: 21:41:59 open screen (or tmux -- however i havent tested with tmux), create 2 windows in the screen. Go to window 1 21:42:02 ensure the jail is stopped. 21:42:05 run: sudo bastille console -a jailtest 21:42:07 immediately press ctlr+a so screen/tmux switches to the other window (This hangs on for 1-2 seconds brefore it switches to the second window) 21:42:10 im gonna try that again.. 21:42:13 wow, doing the same with "stop" also hangs.. for like 10 seconds 21:42:15 on (screen/tmux)window#1 sudo bastille stop jailtest 21:42:18 then immediately press ctrl+a to switch to the other window 21:42:21 then wait... it hangs for 10 seconds before switching to the other window 21:42:23 does that only happens to me ? 21:42:51 (and i dont mean this is a bastille problem, i just want to know if there is a fix, or maybe its an only me problem) 22:04:54 hernan604, I think what you are seeing is that when bastille creates a new jail that it must do a lot of file copying and this uses a lot of file system I/O and probably a spike of memory use too. This is causing screen to not get full machine cycles and the visible pause until it can catch up. 22:05:55 You can probably get the same effect if you untar base.txz or cp -R a large directory tree or similar things that cause a lot of file copy activity all at once. 22:27:20 rwp: right, that would "explain" why i get the same problem in another host that seems to hang randomly with the jails running 22:27:33 but then its unusable 22:28:40 if one single untar causes everything to hang, its "unusable" 22:28:50 there must be some solution 22:29:13 cant be that everyones jails hangs and nobody complains ? that makes no sense 22:33:48 these random hangs would cause weeks of total time loss during a year 22:34:22 maybe not weeks, but a good amount of lost processing time 23:37:53 so my bridging-pfctl-between-jail-and-host script is done, and it works like a charm 23:40:00 hernan604, How long do these hangs last? I thought you said for like 10 seconds? No? Then things become responsive again? 23:40:33 What I described is just a momentary system saturation which eventually (like 10 seconds) sorts out and then things move on. 23:41:27 If it is like that then that's not what I would describe as unusuable. And that can be mitigated if the system has more RAM. That really only happens when the system is quite short on memory. 23:41:50 How much memory is on your system? 23:42:00 karolyi, Woot! \o/ 23:43:04 rwp: now let's wait for the response for my submitted bug :) 23:43:29 I subscribed to the bug so I could see what happened with it. 23:43:39 rwp: yes 10 secs. 128gb ram 23:43:57 Well 128 GB of ram seems like it should be more than enough! 23:44:02 only an nfs share running, plus this jail that hangs and the jail is brand new 23:44:58 Is it only around 10 seconds? In which case I would not call it a hang. I can see that the pause would be annoying. But a hang would be like you go off for an hour and it is still wedged up stuck. That's a hang. 23:45:33 rwp: 10 seconds +- 23:45:47 but it can affect other running processes 23:46:01 I also think that with 128 GB of RAM that it should not be pausing with a burst of file copy either. Keep asking this question. I don't know the answer but maybe someone else will be by who will have a suggestion. 23:46:02 well it does affect.. because the processes become unresponsive 23:46:30 Permanently unresponsive? 23:46:39 for the 10 seconds 23:46:46 Then it is not a hang. 23:47:13 I know we are just debating the words here but a hang has a specific meaning when debugging computer programs and it will lead to the wrong conclusion. 23:47:25 well, if i run stuff in the host without a jail, it wouldnt hang... maybe thats what i will do 23:48:29 rwp: well imagine i have 10 customers, 1 on each jail... and they are using the jails and it hangs randomly for 10 seconds, multiple times a day.... is this a good service ? 23:48:50 imagine if everyones VPS hosting VM hangs for 10 seconds... 23:48:57 randomly, everyday, all the time 23:49:23 something wrong is not right 23:50:26 I wasn't saying that something was not wrong. I am just saying it isn't a hang. 23:51:08 And as I said, keep asking the question. I don't know the answer. But maybe someone else who happens by will know. And if not here then send an email to the questions⊙fo mailing list. More deep expertise there. 23:51:22 well, its unresponsive, so i concluded its a hang 23:51:23 Or the web forums. But I never touch the web forums. Other people do though. 23:51:48 ah good idea 23:52:02 i created an issue in bastille github 23:52:34 Please say the URL here for that github issue so that curious lurkers can browse it too.