00:06:27 rwp: https://github.com/BastilleBSD/bastille/issues/1573 00:14:24 hernan604: Sad at the state of PowerPC support in FreeBSD? 00:16:48 I would love to upgrade this machine to 128GB or better yet 256GB of memory; VMs tend to me limited by your system's memory. 00:18:13 I have 43 jails running currently on 64GB ram 00:19:28 hernan604: just out of curiosity, you've mentioned that you thought the hang is io-bound. did you try running "iostat -x -z 1" and see if around the hangs there are excessive reads/writes? 01:04:06 karolyi: https://termbin.com/oljh 01:04:59 karolyi: do you use screen or tmux ? 01:05:06 maybe you could try yourself ? 01:05:39 start or stop a bastille jail and press ctrl+a to switch to another window (then it hangs for some seconds) 01:17:57 hernan604: I don't use bastille but what you've pasted is nothing, no IO load at all 01:18:08 must be something else then 01:20:34 karolyi: right 09:16:34 phabricator 429'ing me :( 09:19:26 i'll .... 09:19:28 just send a patch I guess? 09:53:03 mason: you've mentioned you're going the "other way" with VNET jails, as in going back to non-VNET ones like I have. just out of curiosity, what's the complexity you don't like with the VNET jails? I'm thinking they must be not hard to set up, although I don't have a single one. I also thought FreeBSD is deprecating non-VNET jails so I'd have to switch over, over time 09:55:47 no-VNET jails work just fine 09:55:54 there is less overhead 09:57:16 less overhead => better network performance, more PPS 10:01:31 karolyi: what are you using 43 jails for? 10:03:17 mzar: lots of small websites, services: prosody, matrix, yourls, unbound, named(bind), coturn, jitsi, go-away/sarracenia, fail2ban, nginx, teamspeak, a separate mailserver jail with dovecot/postfix/SA/etc, roundcube, buildbot... the list goes on 10:03:33 lots of jails with php-fpm and uwsgi 10:03:44 very nice 10:04:09 is the bug report about PF not being supported from within the jail yours ? 10:04:16 yep 10:04:31 OK, so fail2ban has problems now ? 10:05:13 if it runs within a non-vnet jail managing pf, then yes. it's what I've hit, but already got it working with a little script- and prompt-fu in python 10:06:06 perhaps it should be allowed, for all firewalls, like routing updates 10:08:20 I mean there's an 'allow.routing' for a similar purpose 10:08:34 so one could argue for an 'allow.pf' 10:09:47 for the meantime, https://git.ksol.io/karolyi/pf-fail2ban-file-action 10:12:41 karolyi: good point, let's raise this on the net@ mailing list 10:13:25 it was already in the opening post if one reads carefully :) 10:14:11 mzar: I'm just realizing you're Marek 10:14:14 o/ 10:14:34 I am also 100% addicted to non-VNET jails, and have only a few VNET-enabled ones - sometimes VNET demand is indispensable 10:15:00 yes, you can chcke it with /whois 10:15:59 I read somewhere around when VNET was introduced that non-VNET will be phased out over time, which kinda made me anxious, but good to know that so many people are still relying on it that probably it's not gonna happen 10:16:17 FWIW, sysutils/ezjail got small update recently, so people will no longer claim that's not maintained 10:16:34 I use my own ansible playbooks for building my jails 10:16:46 comes super handy when making updates 10:16:50 neat 10:17:28 karolyi: AFAIK there are no plans do deprecate non-VNET jails 10:17:41 https://git.ksol.io/karolyi/ansible-freebsd-jailhost-tools btw 10:18:23 forgejo is also one of my 43 jails :) 10:18:29 * mzar bookmarks it 10:19:09 doesn't handle vnet though so the only thing it can create is non-vnet which is what I'm using 10:19:35 what doesn't handle vnet ? 10:19:47 the playbook. it only creates non-vnet jails 10:20:00 you can extend it 10:20:17 I was thinking on it, yes 10:20:31 I am using ezjail for decates, and it supports vnet jails, though it's not docummented 10:20:43 s/decates/decades 10:20:49 I also took a quick peek into that bastille thing yesterday, crazy someone did it in shellscript entirely 10:21:30 I have to go, have a nice jailing ! BBL 10:22:00 mzar: my playbook relies on a template jail that gets cloned and then I did quita a bit of wizardry in ansible (at least it counted as such back when I've had to "exploit" things in it) to achieve deploying the jails properly 10:22:28 the vars['somevar'] wasn't really public at first 10:23:22 also the package revalidator evolved quite a bit and still has to with introducing the new package sources 10:23:56 but that's only necessary if you use a local pkgmirror (nginx acting as a cache) 10:26:08 oh, bbye 10:39:49 that's great stuff, Laszlo 10:39:52 nice work 10:40:25 43 jails, wow 11:14:54 st_iron: I didn't tell it to flex but thx anyways :) 13:59:39 karolyi: yeah, it's fine, i just dropped my jaw with my 8 production jails :D 14:03:50 well, not counting my bhyve vms 16:55:40 I have already bought some cheap (scary) replacement SSDs so I'll have a combo of 2 off-brand SSDs and one Samsung 870, but I'm wondering if anyone more familiar with LSI controllers has any thoughts on these messages that started popping up the other day... 16:55:41 https://paste.debian.net/hidden/b6012ee7 16:58:06 What's odd is prior to this there was nothing of note logged in the past week. I saw one SSD was showing high wearout, so I replaced it. That drive, brand new Samsung 870 ($200 for 512GB!) is da4 which is the first error logged. Then it seems like all hell breaks loose and all the drives go crazy. 16:58:32 This is an OLD Dell R720 with a Dell-branded LSI controller flashed to IT firmware. 17:19:08 SMART info pulled from scrollback - da0 is just gone, da1 and da2 clearly have issues, da4 is new and looks fine, which makes me wonder why it's showing up with issues right at boot... https://paste.debian.net/hidden/0aa32aa7 17:19:54 I've had weird stuff long ago with LSI controllers and SATA drives so now I always get a little suspicious about whether I'm seeing a true drive issue or a controller issue. 17:21:12 and googling some of the controller messages brings up ancient bugs in bugzilla, some starting way back in the 11.x days and still getting new comments in 2025. 17:26:15 hey, if I have a freebsd 15.1 install where I selected pkgbase during the install, is it expected that FreeBSD-base is enabled=no in /etc/pkg/FreeBSD.conf? 17:34:29 It's expected and wrong and should be fixed 17:38:42 anything else I should configure before updating to make sure my local config file modifications don't get clobbered? also, do I need to enable anything further to get updates for base and kernel and etc.? 17:39:08 the current update list looks pretty comprehensive but i've only recently converted from truenas to freebsd so still have a lot to learn 17:46:11 I should do that too with my truenas... it's abandonware 18:00:21 it's worth it. was getting pretty leery of the lack of updates for 13.x and am pretty happy with the current setup 18:36:23 karolyi: I'm fine with VNET jails but they're unnecessary complexity internally. More moving parts. And if that's not needed, why have it? Here is my guide for using VNET with jails. Compare a non-VNET equivalent and it's dramatically less. https://wiki.freebsd.org/MasonLoringBliss/JailsEpair 18:37:04 So, if I need a jail to be a DHCP client, I'll use VNET. Otherwise, I'm leaning hard towards simplicity. 20:07:57 mason: hear hear, I'd also like to keep my non-vnet jails :) 20:47:17 187 Uncorrectable_Error_Cnt -O--CK 096 096 000 - 39748 20:47:34 should an ssd with numbers like this not be marked as "bad" by SMART? 20:48:32 I also kind of feel like this should qualify as "bad"? 20:48:33 # 1 Extended offline Completed: read failure 90% 33542 1548176 20:48:54 I hate SMART stuff, totally inscrutable no matter how much I poke at it. 20:49:26 ¯\_💩_/¯ SMART overall-health self-assessment test result: PASSED 20:50:22 This kind of wording also makes me bonkers: "When the command that caused the error occurred, the device was active or idle." 20:50:39 Makes me feel like there's a third state besides active or idle. 20:54:23 SMART is really terrible. It never predicts a failure for me. But I do use it to confirm problems when I am seeing failures. 20:55:22 Almost everything about it is vendor defined. And no vendor wants to have their devices fail their own definition. So they mostly never say the device is failed. Even if it is failing a lot of things. 20:55:44 Meanwhile... To avoid the problem being controller or cables or other things, I always test the device in another completely independent system. 20:56:51 I have a "bench" system, a zimaboard system, with two SATA cables right there easy to plug in a SATA device. (Not for SAS, obviously.) And then I will run tests on it there. If it fails both places then it is the device. If it passes there then maybe I have a bad cable or power cord instead. 21:53:51 rwp: don't we all... https://i.imgur.com/cC5oDx3.jpeg 21:54:32 Is there a legit reason ftp-archive.freebsd.org is throttled to about 1MB/s? 21:55:22 It's so painful, and it looks like they really push unsupported releases off the main server quickly (trying to get a 13.x image so I can fix my bootblocks so I can update to something supported). 21:57:48 Oh, I see it's also 96.47.72.116/ftp0 is slow, but going in parallel to both it's 1MB/s each. 21:58:04 Weird TE, you'd think they'd want people in and out of there as quickly as possible. 22:13:31 spork_css, Yup! Though I think my area might have a little less dust on it. :-) 22:14:14 I doubt ftp is being bandwidth limited. More likely it is getting pummeled by botnet scrapers and you are just a single thread competing with hundreds of other threads and so only getting the slip of what is left. 22:15:17 I'll eat my shoe if it's not a per-connection limit. you can stack up 10 1MB/s downloads... 22:17:16 I think the main ftp site has the geo-guessing DNS on it, and they probably drive traffic to other sites, but ftp-archive isn't officially mirrored anywhere so it suffers the same fate as the main site.