01:45:02 Hmm, `freebsd-update upgrade -r 15.1-RELEASE` failed to recover from lost files in /var. :-( 01:45:37 "freebsd-update: Cannot upgrade from 15.1-RELEASE to itself" 01:45:58 Unfortunately it is pretty clear only a portion of the update got done. :-( 01:46:43 Are "Distribution Sets" being deprecated? 01:47:26 I see the sense in doing so, but nothing has explicitly stated such. 01:55:55 geometry: generally, though i wouldn't be surprised to see a tool pop up to quickly assemble distset lookalikes from a pkgbase repo 02:06:40 Would make some sense, but right now I'm getting a feeling of being pushed towards packages which hints at someone hoping for deprecation. 02:12:32 right, at some point they don't make as much sense to promote as a first-class citizen because their use is inherently not compatible with pkgbase 02:12:53 freeebsd-update will not be a thing in its current form in 16, so you'll just have the one option for updating provided by the project, at least 02:13:42 heyy, there's a broken link on freebsd documentation: https://man.freebsd.org/cgi/man.cgi?query=sysinstall&sektion=8&format=html 02:14:00 linked from here: https://docs.freebsd.org/en/articles/remote-install/ 02:16:48 ahhhh, worms!! 02:17:43 (sysinstall was removed from base 15 years ago) 02:19:53 Was that /stand/sysinstall? 02:20:28 really? no more freebsd-update? :( 02:20:48 i know fbsd was sort of leaning that way but that's kind of depressing 02:25:20 yes, pkgbase makes much more sense for the kind of job that freebsd-update grew into, especially in 2026 02:25:46 My nobody take: change is constant, innovation requires change, and FreeBSD do a good job at keeping a system that feels familiar over many decades. 02:26:10 Handy if lots of people rebuild only kernel/basic userspace shell utils OR add-on extra complicated software; yet worse if most people do both or neither (also worse for reducing redundancy). 02:27:14 Essentially all Linux distributions have been using a single tool for everything since the mid-1990s so FreeBSD seems almost behind here. 02:27:57 Linux has no stability though. I mean, the kernel does. But userland is constantly reinventing itself. It's very hard to stay 'current' on Linux. 02:39:57 dch i'm looking at security.mac.ipacl.rules, is there any way to append rules to it so i don't have to assign it to 1 super giant long string with all rules for all jails? 02:45:04 Anyway I'm looking at a system with a failed upgrade (issue with /var); I got a 15.1 kernel in, but userspace is essentially all still 15.1 and I'm unsure how to get the upgrade done. :-( 02:46:18 revert from a backup or snapshot and try again 02:46:34 geometry. fixed in 17.4.x 02:49:38 Appears the metadata signatures for 14.3 have been removed from the update servers (otherwise --currently-running might work). 02:52:25 Backups would take a while (still figuring out how they were setup). 04:39:56 for a single jail application ( i.e i want to run only one application with postgresql backend ) what's the best approach - thick, thin jail? it is a thinkpad t480 laptop, would not be used by anyone but me. so, then, what networking for the jail? i recalling vnet is not working with wifi ( is what currently thi laptop using for connection ) 04:41:28 my router has static ( real, "white" ip ) and i personally would like jail to not interact with rest of devices connected to router but only 1 single ip. is this possible? 04:48:50 all my jails (15) are thin, and all have a single function. All of them are vnets, and I'm not sure why this wouldn't work on wifi: in the end it's an NIC connected to a bridge. You can pf a jail, if needed 04:58:31 ok, thx 05:11:02 reason vor vnet+wifi quirks is the mac address randomization i guess. 05:39:15 https://henryleach.com/2025/04/vnet-jails-with-dhcp-on-freebsd 05:39:24 apparantly it can be done 05:39:44 but you have to use a bridge 05:42:34 ah, the issue is that the 802.11 header uses the space the bridge needs, but there seems to be a workaround 09:03:16 my lan is 192.168.0.0/24. is it possible for vms on a few different boxes on my lan to be connected with their own private network using 192.168.1.0/24 and have them somehow communicate with each other over the lan network? 09:47:20 on host just give it 192.168.1.1 gateway IP, then set VMs gateway to that 09:48:16 vm host can have .1.1 gateway, but keep the .0.1 as default gateway? 09:51:46 you have your bridge setup? 09:56:20 on the vm host? ya 09:57:16 the vms all get 2 nifs, 1 for 0.0/24 space which gets lan device access and internet through lan gateway, and another nif for their private x.0/24 space 09:57:43 vm to vm over private network works fine if the vms are on same vm host through the bridge 09:58:09 what i'm wondering how to do is vm to vm private network if the vms are on diff boxes on the lan 09:58:26 static routes 10:01:25 if you have like 192.168.0.1 on one box with gateways all behind, and like 192.168.1.1 on another with VMs behind that, create a static route for 192.168.1.0\24 to 192.168.1.1 type thing, then do same thing on othre one 10:02:08 s/gateways/VMs 10:09:31 ok ty 10:20:34 route add -net 192.168.1.0/24 192.168.1.1 on 192.168.0.1 host, then route add -net 192.168.0.0/24 192.168.0.1 on 192.168.1.1 host basically 10:22:54 i toss my static routes in /etc/rc.conf so survives reboots 11:52:03 Is there a way to find files that are left over after a freebsd-update run (or any other files in system directories that should not be there)? I thought the mtree files would do, but they only seem to track directories.. 11:55:25 hmm i'm not sure Ltning but most files should be kept or replaced? only configuration files from obsolete packages might persist 11:55:48 No, library files and even some binaries that may have moved around or whatnot 11:56:26 The third freebsd-update step would remove them, but I have several systems where the "freebsd-update cron" run has trampled on that, effectively resetting the state and making it impossible to run that third step 12:02:50 "make check-old" and "delete-old" will do the trick on a source-based installation, it seems 12:29:30 yeah sorry Ltning i haven't ever actually used freebsd-update in a loooong time, pkg is my bb 12:29:41 is it bad security to configure servers to reply to pings? i was thinking maybe it would give ddos'ers usable info like how effective their ddos is 12:30:10 well it's nice to be able to see if a server is online 12:30:15 Well pkg has the same problem 12:30:33 And finding files that don't belong in e.g. /usr/bin or /lib would be useful 12:31:01 ya it is nice but is it bad security? 12:31:09 and to see if a server's online you can just ssh in no? 12:31:15 or check the service it runs 12:33:35 ICMP echo can be allowed, but you may want to rate limit it on the border firewall 14:24:05 do you guys consider firewall config part of network config, or are they siblings? 14:54:37 a way i like to manage firewall rules is, i put interface group names on different interfaces, then i make firewall (pf) rules based on interface groups, so that rules apply to interface group names but not physical interfaces. so i'll make rules for the 'public' group, not the bge0 physical interface. is that good or dumb? 15:01:28 how often do you have more than one interface using the same rules ("group")? 15:02:47 pretty often ig? like 1 lan nif and 1 private network nif, both allow icmp in/out 15:03:14 it's really more about decoupling rule themes from physical ports tho 15:03:42 otherwise the same 'webserver' rules on a box with bge0 physical interface have to be updated to use lagg0 on a multiport box with lagg setup 15:04:04 so i just have webserver ports use 'public' then put public on bge0 on 1 box, and lagg0 on another box 15:04:08 oh, I solve that problem by just aliasing the interface 15:04:13 (in the pf config) 15:04:21 what's that like? 15:04:36 just variable declaration in pf 15:04:37 like: 15:04:44 if_public="ix0" 15:04:52 then I use $if_public in all the rules 15:05:02 and another machine might just do if_public="igb0" 15:05:23 ah 15:05:30 i wonder if 1 way is better 15:05:46 can you put () around if_public so it updates with its ip changes? 15:05:51 i do (public) 15:06:44 that I do in the rule itself where necessary 15:07:01 the thing I just showed is purely to abstract away the interface naming that can differ 15:07:14 I typically name them if_lan0, if_lan1, if_wan0 etc. 15:07:15 ya that's what i use interface group name for 15:07:28 i use public, private... 15:08:00 I don't use public/private because some boxes have more than one "private" segment 15:08:10 hence if_lan0, if_lan1 etc 15:08:24 just to be clear: I am not giving advice, I am just sharing what I'm doing. 15:08:34 ya it's a good point 15:09:10 ig i haven't had complex enough setups to run into that but fair point. most i have is 2 logical nifs on a box 16:05:37 hello 16:05:58 Anyone there? 16:07:15 only if you ask a real question 16:07:57 * MelanieUrsidino sighs 16:07:57 Does FreeBSD detect the brightness keys by default kinda like Linux does? 16:08:06 On what computer? 16:08:22 Toughbook CF-54 16:08:34 Are you asking because you tried it and they didn't work? 16:08:52 Yes 16:09:03 Okay. 16:09:43 X running or not running? A wayland compositor? Or just at the tty? 16:10:14 Confession: I don't currently have FreeBSD on a laptop to try things with, but I do distinctly recall I had to load a special kernel module to be able to modulate screen brightness at all, and I don't remember the brightness buttons reliably working outside of Xorg. 16:10:31 though I don't think I remember them working *in* Xorg either... 16:10:31 tty only 16:10:55 I will try with Xorg though 16:11:06 do you get anything when you run `cat /var/run/devd.seqpacket.pipe` and try to raise or lower the brightness 16:11:39 no 16:12:45 okay, that was just a silly diversion. also you'd need something listening for the brightness keys and executing brightness change commands in response to them to have brightness keys work in Xorg; though you'd be able to see them being recognized in `xinput test-xi2` 16:13:37 do you have the kernel module acpi_panasonic loaded 16:13:45 yeah, that's the one. 16:14:06 in wayland i needed to bind it myself to run `backlight +10` or similar 16:14:23 I will load the kernel module 16:14:29 sorry, that about Xorg recognizing was a wrong diversion, you'd need the acpi_panasonic kernel module 16:14:41 Thanks :) 16:16:25 in the end i found a 'day' and 'night' hotkey ended up being more useful 16:20:58 Hey, just to be honest, I hadn't actually tried the keys yet when you asked, but I wanted to make sure they'd work. Thank you for the proactive help, it really prevented a future issue for me! 16:22:44 freebsd laptop project is really smart i'm glad they're doing it 16:23:10 would love to see a touch screen layer next so we can run freebsd-based tablets and even phones 16:25:06 i wonder why those kernel modules aren't autoloaded when a suitable computer is detected 16:29:02 ya good point melanie. there's gotta be an answer, and maybe the answer is a bug? 16:30:51 I just hook up a hotkey to backlight(8) 16:31:10 ah, rtprio already mentioned this 17:04:32 kerneldove: My Framework is touch 17:12:13 dnp1 time for fbsd tablet then. ipad killer 17:15:21 hahaha, no 17:16:43 Year of the FreeBSD tablet. 17:19:44 I wouldn't call it an ipad, lol. But it does have touch support. Not a feature that I choose to use though. Just a portable workstation for me. 17:27:13 rtprio no vision. ppl like you are why fbsd rotted being server only till 5 min ago 17:28:50 i'm imaging a tablet with broken sound and flakey wifi. perhaps great for my three year old to play tux racer silently, but otherwise 18:08:43 broken imagination 18:09:30 ok then, make it happen 18:26:05 or how about you just don't shit on every good idea like the idiots 10 years ago who said freebsd is server only 18:26:50 i show some excitement over something cool that could happen next with freebsd and you just go "hahaha, no". fucking negative asshole 18:27:16 old crank 18:36:33 woah chill out 18:51:42 lol he's always like this. actual banana 18:52:38 «FreeBSD is server-only», I say, when the only thing that stops me from using it on my desktop is want of GPU support. 18:52:58 (And that may not be FreeBSD's fault!) 18:53:02 It's really a pleasure to operate as a desktop OS. 18:53:22 i've used it as a desktop since 2000 19:48:05 Main daily driver here - 15.1-STABLE FreeBSD 15.1-STABLE stable/15-n284336-034e21efa19d GENERIC amd64 19:48:25 And all of my servers are as well 19:48:55 Not a perfect dektop, but functional. 19:51:17 Finally took the plunge and convered from MacOS to FreeBSD. For two reasons. I needed to refresh my aging hardware, and I was tired of paying for a financial application subcription, that wasn't doing the only thing that I had wanted it for. Fully moved to FreeBSD and gnucach. 19:53:58 kerneldove, can you please dial back the attitude a bit? 19:54:48 for what it's worth, all my desktops are baremetal FreeBSD, not even dualboot. 19:55:06 Same 19:55:35 Desktop != tablet though. 19:55:53 Slow and steady improvement over the years. 21:36:33 I've only found it slightly tricky on laptops which were handed down from work, and mainly due to wifi (Dell). Desktops mostly work fine. 21:37:04 What version of `pkg` is 15.1-RELEASE supposed to install? 21:37:55 I saw an intermediate step where it looked like 2.7.5 was installed, but after completing the upgrade instructions I see 2.6.2. 21:39:00 i think it depends if you're _quarterly or _latest 21:40:10 Quarterly. 21:41:15 Almost behaves as if 15.1 installs 2.7.5, but quarterly overrides with 2.6.2. 21:46:15 the most graphical thing I would like is for mpv to support vaapi, and that mostly works, so I'm happy :) 21:48:02 if you switch to _latest you'd get that version, but i don't think it will pose you any problems 22:06:21 rtprio: I'm optimistic that is the situation, but I've got an unpleasant suspicion some goof occurred with the update servers. 22:21:24 two zpool read errors, but no files affected... 22:21:26 hmm 22:23:09 might be drive connection 22:23:13 or hba 22:28:17 https://www.freshports.org/ports-mgmt/pkg/ - confirms quaterly as 2.6.2 and latest as 2.7.5. In the ports tree. 22:28:25 geometry: How does pkg repos look 22:28:49 yourfate: nah smart has 24+ errors reported within the last 10 hrs 22:28:54 the disk is probably on deaths door 22:29:14 "pkg: warning: database version 39 is newer than libpkg(3) version 38, but still compatible" 22:29:56 Pretty sure part of the `freebsd-update` process upgraded the databases, yet then `pkg` installs the older version. 22:46:02 meh seems like I lost a sector 22:46:40 polarian: Most reliable SMART attribute is Reallocated Sectors, if it starts increasing the disk is EOL. 22:47:28 geometry: yeah I know, I lost one sector :) 22:47:39 I am determined to run this disk to death 22:47:44 its... 15 yrs old I think? 22:47:52 I have ran it in this laptop for 2 maybe 3 years now 22:48:01 still going! 22:48:11 its been to EuroBSDCon 2024 with me, EuroBSDCon 2025 22:48:15 FOSDEM 2025, FOSDEM 2026 22:48:17 :3 22:48:18 Few years back I had 2 disks reallocating ~10 sectors per week and I replaced both, though I suspect both were 1 month older before replacement. 22:48:38 yeah im talking about a single sector right now 22:48:46 this is the first sector to go 22:48:52 unless the smart data has been altered 22:49:04 reallocated sectors is 0, but one is waiting reallocation 22:49:09 I suspect they may still be operational, though I'm not going to do anything besides recycle them. 22:49:35 run them in a RAID 0 cluster for cheap temp storage 22:49:55 if they are fast enough, its useful for things like building ports 22:50:09 why would I want to waste life on good SSDs for that? :p 22:50:10 Pending sectors can simply mean it is taking a closer look, it read okay, but the controller didn't like something. 22:51:22 welp 20 mins left of my scrub to go 22:51:32 I wonder if this was the bad sector I ignored last time :p 22:51:35 probably is 22:53:14 I've seen what appeared to be a HBA trusting the disks to honor committed sectors, yet the extra layer slowed things just enough for the OS synchronize command to not quite complete. 22:53:41 yeah I have heard HBA horror stories 22:53:47 luckily I have never admined a huge enough cluster to worry 22:53:49 :P 22:55:01 So have I, but the problem is 1GB of flash/capacitor-backed cache does wonders for performance. 22:55:37 I hope the cache gets written before its purged due to power failure... 22:55:46 in any case zfs can recover most things 22:56:05 other than filesystem corruption, then you are fucked 22:56:13 That is the point of having a rather large capacitor. 22:56:40 or you know, dont trust the cap and properly UPS production servers :p 22:57:04 my laptop HDD is 320GB 22:57:08 its two 160GB platters 22:57:10 stacked 22:57:14 2.5" 22:57:18 That is plan A, flash+cap is somewhere about Plan D. 22:57:41 meanwhile "modern" (like last 5 years) 2.5" HDDs can fit 1-2TB per platter 22:57:50 I wonder if we still get stacked 2.5" platters 22:57:58 afaik the seagate 1tb 2.5" are single platter 22:59:34 I had moved my threshold to not buying disks of less than 3TB, but I'm unsure of that in present economic conditions. 23:01:56 geometry: I just store as little data as feasibly possible :p 23:02:05 economical, and makes it easier 23:06:46 My data storage has only grown over the years. 23:07:28 my backups have festered over the years 23:18:05 I recall when that 300MB hard drive seemed huge.