-
geometry
I'm looking at an issue with upgrading a system from 14.3 -> 15.1.
-
geometry
I think /var overflowed.
-
geometry
`freebsd-update install` => "ld-elf.so.1: Shared object "libsys.so.7" not found, required by "libc.so.7""
-
geometry
Ohkay, `setenv PATH /rescue:"$PATH"` so still have the most crucial utilities.
-
rwp
Every time I see where BSD features such as /rescue are available I am reminded that FreeBSD is a Real Operating System there to help you not punish you like some other operating systems.
-
geometry
Rule 1: DON"T PANIC!
-
geometry
Rule 2: Keep calm.
-
kerneldove
in a jail config, can i use append instead of assign for every instance of a var? like exec.start += "foo";
-
kerneldove
i reorder them sometimes and get bit by the odd exec.start = "..."; (=, no +=)
-
kerneldove
if it's valid, i'd rather just use += everywhere
-
joemie
kerneldove: without actually knowing I removed the = once on exec.prestart (and only left with the +='s) and apparantly it never broke
-
kerneldove
i'll try that tyvm
-
kerneldove
i'm only using it on the lifecycle hooks, so exec.start/stop/poststop/prestart
-
joemie
#metoo
-
nimaje
karolyi: I think your problem report would have been better if you mentioned your use case of running fail2ban in a jail at the start, so the reader doesn't have to wonder why you would want to manage pf from a jail
-
kerneldove
if in jail config exec.prestart i create an epair, then rename it (exec.prestart += "ifconfig epair create" \n exec.prestart += "ifconfig epair0a foobar0a"), the jail temporarily uses epair0. so if a bunch of jails are configured this same way, then are configured to start in parallel, won't that mean using "epair0" could could get mixed up? like 1
-
kerneldove
jail while starting is epair0, another jail starting at the same time might get epair1, but then the rename part would fail from referencing the wrong epair
-
joemie
I determine which epair to create with "ifconfig bridge${vlan} addm ${epair}a" and have every jail definition have a ' $epair = "epair5"; # must be unique in every jail'
-
kerneldove
ya but that breaks down if you want to support jails having multiple network interfaces
-
joemie
ermm, yes, indeed (I do not have a use case for that)
-
kerneldove
so there's no way to atomically create and rename an epair nif?
-
Demosthenex
arg. so i have a local samba server (in a jail), and i don't generally care about the performance, but at the moment it keeps having issues with my music player, where it's halting reading a file frequently. if i restart the track (reread the file), it works
-
Demosthenex
as usual, nothing in the logs indicating the error
-
kerneldove
@joemie still there?
-
kerneldove
the longest epair i could make is epair11110(a/b), how's that make sense when ifconfig spec says name can be 15 chars long?
-
joemie
just, was driving home from work
-
polarian
I am having really weird behaviour with IPv6 and jails
-
polarian
neighbour solicit doesnt seem to be working despite icmpv6 being passed quickly as the first pf rule
-
polarian
I decided to ping6 the LLA of the host
-
polarian
and then global packets could pass
-
polarian
but before that they couldn't
-
polarian
wait no its working just fine
-
polarian
ugh
-
polarian
I asked this many times but I will ask this again, how do I specify multiple ifconfig command in rc.conf
-
polarian
I want to set a LLA of fe80::2/64 and also set the IPv6 address statically
-
polarian
but if I try to append them to the same ifconfig command in rc.conf
-
polarian
it errors
-
rtprio
ifconfig_blah0_aliasN=
-
polarian
N being?
-
polarian
anything?
-
rtprio
i think you'll want to start at 0
-
rtprio
search for _alias in `man rc.conf`
-
polarian
rtprio: I only see this being used for IPv4
-
rtprio
#ifconfig_em0_alias0="inet6 2001:db8:2::1 prefixlen 64" # Sample IPv6 alias
-
polarian
honestly it should work anyways, because ifconfig is run either way, I can just put inet6 in the alias even without ipv6_
-
polarian
yeah I know
-
rtprio
is in /etc/defaults/rc.conf
-
polarian
lemme test this
-
polarian
rtprio: thx
-
polarian
life saver
-
polarian
rtprio: will relay to doc@ because this is not in the handbook and would be EXTREMELY useful
-
kevans
kerneldove: oh I bet this is going to be a really hinky bug
-
kerneldove
i figured something out just by brainstorming. didn't see it in any docs so dunno if it's intended to work. ifconfig create epair myifname0
-
kevans
yeah, that's fine. officially that's just interface renaming
-
kerneldove
ah shit it only renames the a side of it, not the b side, due to the epair bug in freebsd
-
kerneldove
ffs that bug needs fixing lol
-
joemie
my b-side all are known by the name jail0
-
kerneldove
how can they all have the same name?
-
kerneldove
and anyway the point is there's no way to rename the b side because i need to know the epair unit number to then do that
-
kerneldove
and the epair unit numbering is really restrictive/weird
-
joemie
from the jail pov it doesn't really matter how they are known as
-
kerneldove
hmm
-
kerneldove
but it does because in the jail's exec.poststop you gotta delete it
-
kerneldove
well you can just destroy the a side, but that still requires knowing the exact nif
-
joemie
ifconfig ${epair}b name jail0
-
nimaje
I throught you could assign your own unit numbers when creating via ifconfig epair<number> create
-
kerneldove
you can't just ifconfig epair create in exec.prestart and somehow use a reference to the epair instance that was created
-
kerneldove
you can, but only kinda
-
kerneldove
joemie that depends on you being able to choose the $epair you want to use
-
joemie
the destroy only happens on the a-part: ifconfig ${epair}a destroy
-
joemie
yes, that's true
-
kerneldove
ya but your $epair still needs to be something you choose
-
joemie
correct, as stated before
-
kerneldove
so you can have gaps due to jails being temporarily disabled, no longer in service, etc
-
kerneldove
liek epair0, epair1, epair5...
-
joemie
the number of the epair is identical to the last octet of the ip address
-
nimaje
kerneldove: just tested ifconfig epair3 create works fine and creates epair3{a,b} without any need for having epair1 or epair2
-
kerneldove
k but what if you have have more than a /24 going to the box?
-
kerneldove
nimaje ya but try ifconfig epair000000010 and it fails but it should be allowed because nif names are limited to 15 chars
-
kerneldove
then, try ifconfig epair0010 and it fails because leading 0 are disallowed ig? because ifconfig epair1110 create works
-
kerneldove
that's what i mean by the epair naming restrictions are quirky and limiting
-
kevans
i'm planning to look into this when i have a minute
-
kerneldove
dude if we could just do ifconfig epair create name foobar0 and get foobar0a/b it would be perfect
-
kerneldove
kevans ok very cool! the bug causing trouble here is that ifconfig <epairif> name ... has a bug that only the a side is renamed, not the b side too
-
nimaje
well, how many epairs do you plan to use per jail? more than 10? if not you could use epair<id><digit> to name your epairs until that create name bug is fixed and you would be able to create at least 1000 jails, as ifconfig epair9999 create works too (epair99999 doesn't for some reason, but no idea how unit numbers work for network interfaces)
-
kerneldove
ya that was my idea, but that's how i found out ifconfig epair0...010 didn't work. the idea being nif names are 15 chars max, epair is 5 leaving 10, -1 for a/b, so 9 for the jail, then -1 so each jail can have up to 10 nifs, leaving 8, so epair000000010 is first jail nif on box, and first nif of jail
-
CrtxReavr
I used to admin hundreds of Solaris x86 9 & 10 boxes - most of them with Intel Gbit NICs.
-
nimaje
well, the number there is not just a name, so maybe that is why additional restrictions apply
-
kerneldove
gonna have to use 1 instead of 0 as base jail id
-
CrtxReavr
The driver had to be manually in stalled (well, it was part of the image we deployed).
-
kerneldove
then just deal with the limited length
-
CrtxReavr
But most NICs in Solaris were called <some letters><digit>
-
CrtxReavr
Bit the Intel gbit driver called the NIC e1000gX
-
CrtxReavr
That caused so many problems.
-
kerneldove
ifconfig epair11110 create is longest possible
-
kerneldove
ah no because epair99999 was rejected
-
kerneldove
epair1110-epair9999 is practical limit, + a/b
-
kerneldove
kevans ^ fwiw
-
kevans
kerneldove: ./if.h:56:#define IF_MAXUNIT 0x7fff /* historical value */
-
kerneldove
ahh
-
kerneldove
manage to find where the bug is that ifconfig epair create name foo only renames the a side of an epair?
-
kevans
kerneldove: that's not strictly a bug, renaming is a separate operation that happens after creation
-
kerneldove
but every other interface gets a complete, coherent rename, except epair
-
kerneldove
i think the a/b side split was an oversight
-
kevans
because every other interface doesn't have the janky paired-interface notion
-
kevans
:-)
-
kerneldove
but shouldn't our goal be to make it not janky? it doesn't seem like a flawed concept, just a lil buggy implementation
-
kevans
i think it's going to end up getting rewritten in some way in 16.0
-
kerneldove
wow, what's in store?
-
kevans
glebius is trying to re-work how operating between different vnets works
-
kevans
the current technique of creating it in the home vnet and 'moving' it out ends up creating a lot of hassle
-
kevans
so i think epair ends up getting hit hard here in some way
-
kerneldove
ya would be cool to refactor it so its init procedure is refactored to match how it works for host networking subsystem, just independent
-
polarian
hmmm yeah I cant get IPv6 networking to work in my jail unless I ping its LLA on the host os first
-
polarian
maybe there is a solicitation problem...
-
kerneldove
i have config snippet files for different daemons that i include in the config files for the daemons. where's the right place to copy that big dir tree of config snippet files?
-
kerneldove
i was thinking /usr/local/share/config-snippets
-
dnp1
If you are storing for your own use, it's your perogative. Backup's not withstanding, I currently keep a copy of my base configs in my ~
-
kerneldove
we do the thing like $id then use it as the last octet for the ip and other uses of vars for per-jail config. but what do you do to extend the convention for jails that have >1 network interface? create 10 versions of the vars? (jails can have up to 10 nifs in my convention) but then even if you do that, you gotta generate up to 10 blocks of the
-
kerneldove
network related exec.prestart/poststart/start/stop?
-
kerneldove
looking for ideas to make that nicer
-
Gedge
-
rtprio
drop.17es.dev/-GJ7bF7Ekoj any idea what's going on with all these in my zfs?
-
glenny2
is the output for sysctl dev.hdaa is safe to post online for troubleshooting?
-
nimaje
kevans: well, I would assume the renaming to apply to the pair when done as ifconfig epair create name something as I don't choose a part of the pair there
-
kerneldove
kevans 100% agree with nimaje there
-
kevans
yes, i don't think I'm arguing that you're wrong for expecting this
-
kevans
it's just not surprising because naming is a logically separate operation that happens on an interface
-
kevans
cloner drivers don't really get a vote in how renaming semantics work, you have to listen for renames and decide if you should do something about it
-
kevans
by the time that event comes in, you're unlocked and could already be in the process of being renamed again, iirc, so it's a little tricky
-
kevans
(then you also need to worry about racing against another thread trying to rename the other side of the pair, etc etc)
-
kevans
that also means you probably can't give them different names depending on where they're going, which maybe breaks something people do today
-
kevans
('them' being different sides of the epair; this one going in the host bridge you may want to name after a jail, while the jail side you might want to name 'wan0' or something)
-
LXGHTNXNG
yes, that's something i do today
-
kevans
i can see why one might choose to punt on figuring out how to handle renaming epairs specifically
-
rtprio
how would it not be safe?
-
nimaje
rtprio: I think I only saw something similar when docker decided to do some bullshit on some linux system that used zfs, because hashes are oviously good names for stuff without any further context (took a while to figuring out it was docker, as the dataset names didn't say anything about it and it just assumed it should make that mess, because it was running on zfs)
-
rwp
Given that ifconfig has worked like this for some years what's so hard about renaming both halfs of the epair? That's what I have always done. It works.
-
rwp
Example of creating an epair, renaming both sides of the pair, attaching it to the bridge, cleaning it up at jail shutdown.
bpa.st/ASPQ
-
kevans
i think the problem is that we have syntax for renaming-at-creation time, and it doesn't clearly indicate that it's actually a rename rather than atomic creation+rename
-
rwp
So... Improving the documentation would solve the problem?
-
rwp
It's really not a serious problem. Just perform the steps individually and it all works as expected.
-
rwp
I am not even sure how one would modify the ifconfig syntax for naming the associated device. Call it "name" for the first and "name2" for the associated pair?
-
kerneldove
just add nameall for multicomponent interfaces
-
kevans
i'm already sobbing
-
kerneldove
ifconfig epair create nameall foobar
-
kerneldove
nameeach maybe
-
rwp
I am with kevans already. You can't name both interfaces the same name.
-
kevans
this is also a problem for exactly one cloned interface type, no?
-
rwp
I think epair is the only thing that creates two devices in one step. So it is the only one that is susceptible to this.
-
kevans
i keep also paging in dirty stuff with nmdm, which isn't a netif at all but obviously has similar semantics
-
glenny2
i made a post on the FreeBSD forums about my sound card not outputting sound through the speakers. my post was awaiting approval. i don't think it got approved and i haven't received a reason as to why. what should i do?
-
mzar
glenny2: is your card supported ? what is your problem ?
-
glenny2
it's the Realtek ALC257. there is no output from the speakers. i've tried searching for a solution. i've added (i think correctly) the device to device.hints. i've tried making sure the sound card drivers are loaded, etc. every post i've searched i've tried.
-
glenny2
the mic input works but there is no output from the speakers. sysctl hdaa lists the speakers as [DISABLED]
-
mzar
what about 'cat /dev/sndstat' ? can you paste it somewhere ?
-
glenny2
mzar: some users here tried troubleshooting the problem here in the #channel but were largely unsuccessful
-
mzar
and show us
-
mzar
ok
-
mzar
so perhaps this device requires some platform-specific settings
-
glenny2
i tried adding the device to device.hints using the pin output (i think those are the correct terms) as this was successful for others with a similar issue
-
mzar
glenny2: have you tried switch units with command sysctl hw.snd.default_unit ?
-
glenny2
mzar: yes
-
glenny2
mzar: microphone input works correctly too
-
mzar
is it laptop ?
-
mzar
so input works
-
glenny2
mzar: yep
-
mzar
if your laptop yes not supported yet, you need something similiar to this review
reviews.freebsd.org/D49002
-
mzar
search reviews.freebsd.org, perhaps fix for your laptop is in the review
-
glenny2
mzar: i saw that but i don't know what to do with it or the patch
-
mzar
I made my Dell working this way
-
mzar
you have to apply it on the sources, rebuild and reinstall the kernel
-
glenny2
i don't think i have any sources?
-
mzar
if you really want to play with sources, you have to fetch them
-
glenny2
i'm just using whatever was installed from the USB install
-
glenny2
mzar: i don't want to play with sources really :( i haven't configured a kernel for linux in years. i don't know if i could do it on an OS i just started using a week or two ago
-
mzar
if you are not ready for the experimentation, plese wait until the official fix will be applied - but it will take some time - months
-
glenny2
that patch was made over a year ago
-
mzar
yes, perhaps years
-
glenny2
...really?
-
mzar
sure, but if you will help testing it, will give some feedback it will expedite the update
-
glenny2
and if i wait, and it isn't solved, i'll have to wait even longer...if ever
-
mzar
this way you can contribute
-
glenny2
i don't think this is a viable option. if i configure the kernel wrong, and the system breaks, it will take forever for my potato of a laptop to recompile.
-
glenny1
OS: Linux ('Gentoo' '2.18') (6.18.35-gentoo-dist) CPU: Intel(R) Pentium(R) Silver N6000 @ 1.10GHz MEM: 4 GB GPU: Intel(R) UHD Graphics (JSL) (Vulkan) UP: 6 days 18 hours 36 minutes 19 seconds ago
-
mzar
this OS is not supported here
-
glenny1
that's the hardware for the laptop
-
glenny1
i know. the devices are the same
-
glenny1
i don't have the /sysinfo command available on my FreeBSD machine as it's using a cloud based IRC client
-
mzar
yep, bulding kernel on latpop could be challenging, but with regard to configuration you are fine - just build GENERIC
-
rtprio
mzar: now to get my wifi card to work >:|
-
mzar
rtprio: you need CURRENT, fwget(8) and it will work
-
rtprio
for iwlwifi(4) ?
-
rtprio
i suppose current wouldl't hurt; it's a bit awkward being installed on a usb stick but i don't want to blast the os that's there until it know it works
-
ek
rtprio: Can you use another USB stick for -CURRENT?
-
bsdrobert
Recompiling the kernel on freebsd is easy and imo a right of passage.
-
LXGHTNXNG
Rite, not right.
-
rtprio
i don't have any wifi usb sticks, i don't think
-
bsdrobert
Thanks
-
mzar
bummer !
-
rtprio
i donno maybe, it's probably only 'b' if i do have one
-
ek
rtprio: Oh! I thought you meant you were running FBSD from a stick.
-
CrtxReavr
Anyone remember launching a FreeBSD install from a single floppy disk, via ppp & ftp?
-
mzar
sure, but you needed a bunch of floppies
-
ek
So, if you *DO* have another USB stick, maybe just run -CURRENT from that with your wifi USB and see if it works?
-
ek
Then, you don't need to upgrade your current system. Just run a live one.
-
mzar
yep, please follow ek's guidance and your wifi will work
-
rtprio
i'm just updating this fresh stick to 16
-
rtprio
it was just a test to see if 'having the firmware made it work' since the installer wasn't going to do that
-
ek
Fair enough.
-
ek
I'm curious to hear the results.
-
rtprio
well, they're in
-
rtprio
could not load binary firmware /boot/firmware/iwl-debug-yoyo.bin either
-
rtprio
RFIm is deactivated, reason = 4
-
mzar
bummer
-
ek
Bah!
-
rtprio
reason =4 is like 'fn key to make the wifi work' but that doesn't seem to do anything
-
ek
I haven't played with wireless in a while.
-
rtprio
on my lenovo x1 it just worked
-
rtprio
i'm considering swapping the cards
-
ek
I think I do have a laptop that I can use to test stuff. But, it's not a REALTEK.
-
bsdrobert
That reminds me of real talk by tupac shakur
-
spork_css
what is my best support venue for digging into a crazy drive controller problem? IRC is probably not the best...
-
spork_css
basically I saw some drive issues (SMART giving some poor numbers on SSDs), so i just assumed replacing drives would fix me right up, but no...
-
spork_css
new drives also just timing out then being tossed by the controller (mps). no load really.
-
spork_css
same hardware (Dell R720) ran vmware for quite a few years and putting FreeBSD on here (15.1) to test out Sylve has been quite a little ordeal (and I probably spent about $500 on drives I didn't need to, oops!).
-
spork_css
I am far from an expert on cross-flashing Dell/LSI RAID cards from IR to IT, but that is my biggest change.
-
rtprio
spork_css: are you using mr. sas
-
spork_css
I need to double-check cabling again and all, but it's a server with a drive backplane and all that so I doubt I'll find an issue there.
-
spork_css
mr. or mrs. SAS? :)
-
rtprio
i mean, MRSAS(4)
-
spork_css
mps
-
rtprio
i didn't have great luck without it
-
spork_css
wait is mrsas a driver or utility?
-
spork_css
pool: zroot
-
spork_css
state: SUSPENDED
-
spork_css
(can't look at the moment, oops)
-
rtprio
it's a driver
-
rtprio
that you put in your loader.conf
-
rtprio
i haven't flashed my lsi card either, it's on my list
-
spork_css
I think that driver is for something much newer than what I have. mps appears to be the right thing.
-
spork_css
way back in 8.4 we had some onboard LSI controllers and I just hated them. They seemed to work well elsewhere, but on FreeBSD kept running into problems not unlike what I'm seeing now, but there it seemed to correlate to load (these were PGSQL servers with a bunch of SSDs).
-
spork_css
It would dump a drive, I'd pull it, analyze it elsewhere, bring it back to the colo and then in a few months, different drive, different slot, same thing and it just continued until we brought in new hardware years later.
-
spork_css
I'm kind of thinking that since this is just a home server (used for work at times tho) and it's old VMs are not currently essential to anything I'm working on I should really dig in.
-
spork_css
But also in the past I've spent days on troubleshooting things, did a big bug writeup, but then couldn't get anyone interested in it.
-
spork_css
I found a few extra PCIe SATA cards last night while unpacking, considering putting those in and bypassing the onboard controller to see what happens and kind of write off drive/power/cabling issues.
-
spork_css
Then I could move to looking at why mps and these drives aren't happy. Problem moves to all slots (currently I have six SSDs in).
-
spork_css
I'm also a little concerned that the cross-flashing tool I used is quite old and maybe my mps firmware is just crap (I did update firmware on two samsung drives that are older).
-
dnp1
CrtxReavr: Not that far back for me, but I did build a freebsd router that would ppp dial on demand to connect ot my ISP when something on the network requested internet resources.
-
LXGHTNXNG
I don't want the majority of the world to live dial on demand, but I do want to live in a world where the majority could easily live dial on demand if they wanted or had to.
-
dnp1
That ship has probably sailed long ago.
-
spork_css
public-owned FTTH and you "dial" on demand to the ISP of your choice (dial = pick a VLAN). :)
-
bsdrobert
i dont miss 3kb/s
-
ewq
*sound of many modems dialing at once*
-
LXGHTNXNG
spork_css: that sounds like a fun utility billing puzzle. how do you decide "link activity" and then pass on fees from the ISP?
-
LXGHTNXNG
how do you make the network detect "oh, this ONT was active for this VLAN between now and now"
-
spork_css
Well, I think the owner of the infrastructure would probably mandate a particular ONT and such, so the customer couldn't just "fake" being another user.
-
spork_css
I'm going to assume that if things have progressed since the DSL days when I played with those access concentrators, this is probably a total no-brainer on billing/access control.
-
spork_css
The politics of it and finding ISPs wanting to compete in that scenario are the more difficult part. :)
-
LXGHTNXNG
I mean, once you have that, it's a puzzle in the sense of, "how do you consider the line active, should data have been sent within the last X minutes?", and "should ISPs be able to charge clock-on and clock-off fees?"
-
LXGHTNXNG
how do you ensure equitable accounting for: the fixed costs of the installed plant, the (minuscule, possibly left unaccounted for convenience's sake) incremental costs of delivering each data unit to/from the ISP, the ISP's opportunity costs in terms of address resource usage during that time, and the ISP's costs to transmit the packet onto the Internet?
-
LXGHTNXNG
having a static IP also throws the whole calculation because the ISP might on occasion need to dial *you*