-
geometry
Hmm, `freebsd-update upgrade -r 15.1-RELEASE` failed to recover from lost files in /var. :-(
-
geometry
"freebsd-update: Cannot upgrade from 15.1-RELEASE to itself"
-
geometry
Unfortunately it is pretty clear only a portion of the update got done. :-(
-
geometry
Are "Distribution Sets" being deprecated?
-
geometry
I see the sense in doing so, but nothing has explicitly stated such.
-
kevans
geometry: generally, though i wouldn't be surprised to see a tool pop up to quickly assemble distset lookalikes from a pkgbase repo
-
geometry
Would make some sense, but right now I'm getting a feeling of being pushed towards packages which hints at someone hoping for deprecation.
-
kevans
right, at some point they don't make as much sense to promote as a first-class citizen because their use is inherently not compatible with pkgbase
-
kevans
freeebsd-update will not be a thing in its current form in 16, so you'll just have the one option for updating provided by the project, at least
-
codegirl
-
codegirl
-
kevans
ahhhh, worms!!
-
kevans
(sysinstall was removed from base 15 years ago)
-
dnp1
Was that /stand/sysinstall?
-
Macer
really? no more freebsd-update? :(
-
Macer
i know fbsd was sort of leaning that way but that's kind of depressing
-
kevans
yes, pkgbase makes much more sense for the kind of job that freebsd-update grew into, especially in 2026
-
bsdrobert
My nobody take: change is constant, innovation requires change, and FreeBSD do a good job at keeping a system that feels familiar over many decades.
-
geometry
Handy if lots of people rebuild only kernel/basic userspace shell utils OR add-on extra complicated software; yet worse if most people do both or neither (also worse for reducing redundancy).
-
geometry
Essentially all Linux distributions have been using a single tool for everything since the mid-1990s so FreeBSD seems almost behind here.
-
bsdrobert
Linux has no stability though. I mean, the kernel does. But userland is constantly reinventing itself. It's very hard to stay 'current' on Linux.
-
kerneldove
dch i'm looking at security.mac.ipacl.rules, is there any way to append rules to it so i don't have to assign it to 1 super giant long string with all rules for all jails?
-
geometry
Anyway I'm looking at a system with a failed upgrade (issue with /var); I got a 15.1 kernel in, but userspace is essentially all still 15.1 and I'm unsure how to get the upgrade done. :-(
-
llua
revert from a backup or snapshot and try again
-
AuthenticAMD
geometry. fixed in 17.4.x
-
geometry
Appears the metadata signatures for 14.3 have been removed from the update servers (otherwise --currently-running might work).
-
geometry
Backups would take a while (still figuring out how they were setup).
-
angry_vincent
for a single jail application ( i.e i want to run only one application with postgresql backend ) what's the best approach - thick, thin jail? it is a thinkpad t480 laptop, would not be used by anyone but me. so, then, what networking for the jail? i recalling vnet is not working with wifi ( is what currently thi laptop using for connection )
-
angry_vincent
my router has static ( real, "white" ip ) and i personally would like jail to not interact with rest of devices connected to router but only 1 single ip. is this possible?
-
joemie
all my jails (15) are thin, and all have a single function. All of them are vnets, and I'm not sure why this wouldn't work on wifi: in the end it's an NIC connected to a bridge. You can pf a jail, if needed
-
angry_vincent
ok, thx
-
angry_vincent
reason vor vnet+wifi quirks is the mac address randomization i guess.
-
joemie
-
joemie
apparantly it can be done
-
joemie
but you have to use a bridge
-
joemie
ah, the issue is that the 802.11 header uses the space the bridge needs, but there seems to be a workaround
-
kerneldove
my lan is 192.168.0.0/24. is it possible for vms on a few different boxes on my lan to be connected with their own private network using 192.168.1.0/24 and have them somehow communicate with each other over the lan network?
-
xway
on host just give it 192.168.1.1 gateway IP, then set VMs gateway to that
-
kerneldove
vm host can have .1.1 gateway, but keep the .0.1 as default gateway?
-
xway
you have your bridge setup?
-
kerneldove
on the vm host? ya
-
kerneldove
the vms all get 2 nifs, 1 for 0.0/24 space which gets lan device access and internet through lan gateway, and another nif for their private x.0/24 space
-
kerneldove
vm to vm over private network works fine if the vms are on same vm host through the bridge
-
kerneldove
what i'm wondering how to do is vm to vm private network if the vms are on diff boxes on the lan
-
xway
static routes
-
xway
if you have like 192.168.0.1 on one box with gateways all behind, and like 192.168.1.1 on another with VMs behind that, create a static route for 192.168.1.0\24 to 192.168.1.1 type thing, then do same thing on othre one
-
xway
s/gateways/VMs
-
kerneldove
ok ty
-
xway
route add -net 192.168.1.0/24 192.168.1.1 on 192.168.0.1 host, then route add -net 192.168.0.0/24 192.168.0.1 on 192.168.1.1 host basically
-
xway
i toss my static routes in /etc/rc.conf so survives reboots
-
Ltning
Is there a way to find files that are left over after a freebsd-update run (or any other files in system directories that should not be there)? I thought the mtree files would do, but they only seem to track directories..
-
rdr
hmm i'm not sure Ltning but most files should be kept or replaced? only configuration files from obsolete packages might persist
-
Ltning
No, library files and even some binaries that may have moved around or whatnot
-
Ltning
The third freebsd-update step would remove them, but I have several systems where the "freebsd-update cron" run has trampled on that, effectively resetting the state and making it impossible to run that third step
-
Ltning
"make check-old" and "delete-old" will do the trick on a source-based installation, it seems
-
rdr
yeah sorry Ltning i haven't ever actually used freebsd-update in a loooong time, pkg is my bb
-
kerneldove
is it bad security to configure servers to reply to pings? i was thinking maybe it would give ddos'ers usable info like how effective their ddos is
-
rdr
well it's nice to be able to see if a server is online
-
Ltning
Well pkg has the same problem
-
Ltning
And finding files that don't belong in e.g. /usr/bin or /lib would be useful
-
kerneldove
ya it is nice but is it bad security?
-
kerneldove
and to see if a server's online you can just ssh in no?
-
kerneldove
or check the service it runs
-
Ltning
ICMP echo can be allowed, but you may want to rate limit it on the border firewall
-
kerneldove
do you guys consider firewall config part of network config, or are they siblings?
-
kerneldove
a way i like to manage firewall rules is, i put interface group names on different interfaces, then i make firewall (pf) rules based on interface groups, so that rules apply to interface group names but not physical interfaces. so i'll make rules for the 'public' group, not the bge0 physical interface. is that good or dumb?
-
jbo
how often do you have more than one interface using the same rules ("group")?
-
kerneldove
pretty often ig? like 1 lan nif and 1 private network nif, both allow icmp in/out
-
kerneldove
it's really more about decoupling rule themes from physical ports tho
-
kerneldove
otherwise the same 'webserver' rules on a box with bge0 physical interface have to be updated to use lagg0 on a multiport box with lagg setup
-
kerneldove
so i just have webserver ports use 'public' then put public on bge0 on 1 box, and lagg0 on another box
-
jbo
oh, I solve that problem by just aliasing the interface
-
jbo
(in the pf config)
-
kerneldove
what's that like?
-
jbo
just variable declaration in pf
-
jbo
like:
-
jbo
if_public="ix0"
-
jbo
then I use $if_public in all the rules
-
jbo
and another machine might just do if_public="igb0"
-
kerneldove
ah
-
kerneldove
i wonder if 1 way is better
-
kerneldove
can you put () around if_public so it updates with its ip changes?
-
kerneldove
i do (public)
-
jbo
that I do in the rule itself where necessary
-
jbo
the thing I just showed is purely to abstract away the interface naming that can differ
-
jbo
I typically name them if_lan0, if_lan1, if_wan0 etc.
-
kerneldove
ya that's what i use interface group name for
-
kerneldove
i use public, private...
-
jbo
I don't use public/private because some boxes have more than one "private" segment
-
jbo
hence if_lan0, if_lan1 etc
-
jbo
just to be clear: I am not giving advice, I am just sharing what I'm doing.
-
kerneldove
ya it's a good point
-
kerneldove
ig i haven't had complex enough setups to run into that but fair point. most i have is 2 logical nifs on a box
-
Gactic37
hello
-
Gactic37
Anyone there?
-
bdrewery
only if you ask a real question
-
» MelanieUrsidino sighs
-
Gactic37
Does FreeBSD detect the brightness keys by default kinda like Linux does?
-
MelanieUrsidino
On what computer?
-
Gactic37
Toughbook CF-54
-
MelanieUrsidino
Are you asking because you tried it and they didn't work?
-
Gactic37
Yes
-
MelanieUrsidino
Okay.
-
MelanieUrsidino
X running or not running? A wayland compositor? Or just at the tty?
-
MelanieUrsidino
Confession: I don't currently have FreeBSD on a laptop to try things with, but I do distinctly recall I had to load a special kernel module to be able to modulate screen brightness at all, and I don't remember the brightness buttons reliably working outside of Xorg.
-
MelanieUrsidino
though I don't think I remember them working *in* Xorg either...
-
Gactic37
tty only
-
Gactic37
I will try with Xorg though
-
MelanieUrsidino
do you get anything when you run `cat /var/run/devd.seqpacket.pipe` and try to raise or lower the brightness
-
Gactic37
no
-
MelanieUrsidino
okay, that was just a silly diversion. also you'd need something listening for the brightness keys and executing brightness change commands in response to them to have brightness keys work in Xorg; though you'd be able to see them being recognized in `xinput test-xi2`
-
MelanieUrsidino
do you have the kernel module acpi_panasonic loaded
-
rtprio
yeah, that's the one.
-
rtprio
in wayland i needed to bind it myself to run `backlight +10` or similar
-
Gactic37
I will load the kernel module
-
MelanieUrsidino
sorry, that about Xorg recognizing was a wrong diversion, you'd need the acpi_panasonic kernel module
-
Gactic37
Thanks :)
-
rtprio
in the end i found a 'day' and 'night' hotkey ended up being more useful
-
Gactic37
Hey, just to be honest, I hadn't actually tried the keys yet when you asked, but I wanted to make sure they'd work. Thank you for the proactive help, it really prevented a future issue for me!
-
kerneldove
freebsd laptop project is really smart i'm glad they're doing it
-
kerneldove
would love to see a touch screen layer next so we can run freebsd-based tablets and even phones
-
MelanieUrsidino
i wonder why those kernel modules aren't autoloaded when a suitable computer is detected
-
kerneldove
ya good point melanie. there's gotta be an answer, and maybe the answer is a bug?
-
jbo
I just hook up a hotkey to backlight(8)
-
jbo
ah, rtprio already mentioned this
-
dnp1
kerneldove: My Framework is touch
-
kerneldove
dnp1 time for fbsd tablet then. ipad killer
-
rtprio
hahaha, no
-
skered
Year of the FreeBSD tablet.
-
dnp1
I wouldn't call it an ipad, lol. But it does have touch support. Not a feature that I choose to use though. Just a portable workstation for me.
-
kerneldove
rtprio no vision. ppl like you are why fbsd rotted being server only till 5 min ago
-
rtprio
i'm imaging a tablet with broken sound and flakey wifi. perhaps great for my three year old to play tux racer silently, but otherwise
-
kerneldove
broken imagination
-
rtprio
ok then, make it happen
-
kerneldove
or how about you just don't shit on every good idea like the idiots 10 years ago who said freebsd is server only
-
kerneldove
i show some excitement over something cool that could happen next with freebsd and you just go "hahaha, no". fucking negative asshole
-
kerneldove
old crank
-
rtprio
woah chill out
-
nesta
lol he's always like this. actual banana
-
MelanieUrsidino
«FreeBSD is server-only», I say, when the only thing that stops me from using it on my desktop is want of GPU support.
-
MelanieUrsidino
(And that may not be FreeBSD's fault!)
-
MelanieUrsidino
It's really a pleasure to operate as a desktop OS.
-
rtprio
i've used it as a desktop since 2000
-
dnp1
Main daily driver here - 15.1-STABLE FreeBSD 15.1-STABLE stable/15-n284336-034e21efa19d GENERIC amd64
-
dnp1
And all of my servers are as well
-
dnp1
Not a perfect dektop, but functional.
-
dnp1
Finally took the plunge and convered from MacOS to FreeBSD. For two reasons. I needed to refresh my aging hardware, and I was tired of paying for a financial application subcription, that wasn't doing the only thing that I had wanted it for. Fully moved to FreeBSD and gnucach.
-
jbo
kerneldove, can you please dial back the attitude a bit?
-
jbo
for what it's worth, all my desktops are baremetal FreeBSD, not even dualboot.
-
dnp1
Same
-
dnp1
Desktop != tablet though.
-
dnp1
Slow and steady improvement over the years.
-
topcat001
I've only found it slightly tricky on laptops which were handed down from work, and mainly due to wifi (Dell). Desktops mostly work fine.
-
geometry
What version of `pkg` is 15.1-RELEASE supposed to install?
-
geometry
I saw an intermediate step where it looked like 2.7.5 was installed, but after completing the upgrade instructions I see 2.6.2.
-
rtprio
i think it depends if you're _quarterly or _latest
-
geometry
Quarterly.
-
geometry
Almost behaves as if 15.1 installs 2.7.5, but quarterly overrides with 2.6.2.
-
topcat001
the most graphical thing I would like is for mpv to support vaapi, and that mostly works, so I'm happy :)
-
rtprio
if you switch to _latest you'd get that version, but i don't think it will pose you any problems
-
geometry
rtprio: I'm optimistic that is the situation, but I've got an unpleasant suspicion some goof occurred with the update servers.
-
polarian
two zpool read errors, but no files affected...
-
polarian
hmm
-
yourfate
might be drive connection
-
yourfate
or hba
-
dnp1
freshports.org/ports-mgmt/pkg - confirms quaterly as 2.6.2 and latest as 2.7.5. In the ports tree.
-
dnp1
geometry: How does pkg repos look
-
polarian
yourfate: nah smart has 24+ errors reported within the last 10 hrs
-
polarian
the disk is probably on deaths door
-
geometry
"pkg: warning: database version 39 is newer than libpkg(3) version 38, but still compatible"
-
geometry
Pretty sure part of the `freebsd-update` process upgraded the databases, yet then `pkg` installs the older version.
-
polarian
meh seems like I lost a sector
-
geometry
polarian: Most reliable SMART attribute is Reallocated Sectors, if it starts increasing the disk is EOL.
-
polarian
geometry: yeah I know, I lost one sector :)
-
polarian
I am determined to run this disk to death
-
polarian
its... 15 yrs old I think?
-
polarian
I have ran it in this laptop for 2 maybe 3 years now
-
polarian
still going!
-
polarian
its been to EuroBSDCon 2024 with me, EuroBSDCon 2025
-
polarian
FOSDEM 2025, FOSDEM 2026
-
polarian
:3
-
geometry
Few years back I had 2 disks reallocating ~10 sectors per week and I replaced both, though I suspect both were 1 month older before replacement.
-
polarian
yeah im talking about a single sector right now
-
polarian
this is the first sector to go
-
polarian
unless the smart data has been altered
-
polarian
reallocated sectors is 0, but one is waiting reallocation
-
geometry
I suspect they may still be operational, though I'm not going to do anything besides recycle them.
-
polarian
run them in a RAID 0 cluster for cheap temp storage
-
polarian
if they are fast enough, its useful for things like building ports
-
polarian
why would I want to waste life on good SSDs for that? :p
-
geometry
Pending sectors can simply mean it is taking a closer look, it read okay, but the controller didn't like something.
-
polarian
welp 20 mins left of my scrub to go
-
polarian
I wonder if this was the bad sector I ignored last time :p
-
polarian
probably is
-
geometry
I've seen what appeared to be a HBA trusting the disks to honor committed sectors, yet the extra layer slowed things just enough for the OS synchronize command to not quite complete.
-
polarian
yeah I have heard HBA horror stories
-
polarian
luckily I have never admined a huge enough cluster to worry
-
polarian
:P
-
geometry
So have I, but the problem is 1GB of flash/capacitor-backed cache does wonders for performance.
-
polarian
I hope the cache gets written before its purged due to power failure...
-
polarian
in any case zfs can recover most things
-
polarian
other than filesystem corruption, then you are fucked
-
geometry
That is the point of having a rather large capacitor.
-
polarian
or you know, dont trust the cap and properly UPS production servers :p
-
polarian
my laptop HDD is 320GB
-
polarian
its two 160GB platters
-
polarian
stacked
-
polarian
2.5"
-
geometry
That is plan A, flash+cap is somewhere about Plan D.
-
polarian
meanwhile "modern" (like last 5 years) 2.5" HDDs can fit 1-2TB per platter
-
polarian
I wonder if we still get stacked 2.5" platters
-
polarian
afaik the seagate 1tb 2.5" are single platter
-
geometry
I had moved my threshold to not buying disks of less than 3TB, but I'm unsure of that in present economic conditions.
-
polarian
geometry: I just store as little data as feasibly possible :p
-
polarian
economical, and makes it easier
-
dnp1
My data storage has only grown over the years.
-
polarian
my backups have festered over the years
-
geometry
I recall when that 300MB hard drive seemed huge.