05:37:27 Hi. Can someone please currently fact check if the current freebsd version supports the built in wifi chip for the raspberry pi 3 or not? 07:46:25 i would be surprised 07:47:13 Matt|home: https://wiki.freebsd.org/arm/Raspberry%20Pi says no 09:11:27 how i go about about updating thin jails? would then simply make buildworld/installworld/make distribution with DESTDIR=/path/to/jail a way? 18:57:31 angry_vincent: That wouldn't be a thin jail any more. For my part, I avoid all the complexity and just don't use thin jails. Especially now with pkgbase, creating jails is *fast*. In fact, I've stopped using zfs send/receive to do it - the pkg based installs are *fast*. 19:00:17 I agree with mason . there's still some other benefits to zfs send/recv, but thin jails were a bad idea even 10 years ago. the problems outdo the benefits. 19:00:48 what's worse is that with pkgbase, 'thin' jails can have a whole new meaning :-) 19:17:10 Thin jails would be nice in a situation with limited storage on disk. I've not switched to pkgbase yet so will reserve opinion on that. 19:18:12 antranigv: curious what sort of problems are you referring to? I'm trying to learn jails and pros/cons hence the query. 19:18:22 'bsdinstall jail /some/jail' is also quite nice for thick jails. 19:18:53 mns: I was resisting until enough people had bled on it, and the pkgbase installer still breaks with distressing regularity, but to give you an example, a jail I built the other day with FreeBSD-set-minimal-jail-15.1 takes a whopping 137M, and that's a fully functional certificate authority server. 19:19:24 Current iteration - will likely change as I learn more: https://wiki.freebsd.org/MasonLoringBliss/PkgBaseChroot 19:20:45 a thin jail is more complicated because you have to create the tree manually, then mount it via nullfs in a custom fstab, and you have to rinse and repeat that process for every jail. 19:21:55 mns: Strong word of advice - if you're just starting off with jails, use the base system tools to manage them. Only change if you encounter difficulties. The base tools are quite usable. 19:24:08 (And if you encounter difficulties, ask here on or a mailing list before giving up!) 19:25:06 i agree with mason - start with a thick jail. use 'bsdinstall jail /some/path' to populate it. add something to /etc/jail.conf.d/name.conf, then jail -c name, youre pretty much good to go at that point. 19:31:12 fwiw I don't think thin jails are a bad idea, but they're not a good first step. 19:39:58 mason: I had initially started with bastille, but I wasn't learning anything. I dropped that and switched just working with jail.conf, especially once you could include files in it from /etc/jail.conf.d. As I've learnt a little more, I've started using variables, so most of my jails are similar. 137MB is pretty small. What is FreeBSD-set-minimal-jail-15.1 ? 20:02:08 i'd like to see if i can convert most of my jails to podman containers 20:02:10 mns: It's a pkgbase package that is tuned for jails, as opposed to VMs or hardware. 20:02:32 kevans: I was looking at that this morning. Docker networking still seems opaque to me. 20:02:46 I think dch is trying to improve the situation 20:03:41 he put out a call for ignorant buffoons like you and me somewhere else, this may be a good opportunity for us :-D https://reviews.freebsd.org/D58179 20:03:52 For Linux boxes, I quite like LXC, but I fear it rotting. So I've been pondering Docker. But everything is a struggle: "How do I get this to act like FreeBSD?" And I win the struggle most of the time, but lately I've been giving up more and just using FreeBSD jails. :P 20:04:02 Looking. 20:04:30 (i haven't had a chance to look yet, but if there's something still unclear we should complain about it) 20:04:32 Oh, neat. 20:04:49 Yeah. I'll do that. The green part on the right is pleasing. 20:06:56 i'd be quite happy to just rebuild my things upon an updated base container rather than updating them in-place 20:07:24 kevans: Ah, alright, that makes the appeal immediately visible then. 20:07:38 mostly i'm still thinking about storage organization and what i need to provide on the host for persistence 20:08:28 isnt that a problem that thin jails solve? well, i mean, you can share a common base system that is updated in just one place. 20:08:46 yeah, i mean- in-place updates are fine, but realistically most of my stuff touches very little from base and even if there is something custom there, I probably want to blow it away and do things 'better' 20:08:53 well, not necessarily 20:09:06 hold on, i think my baby's getting into some shit again 20:10:23 thin jails pose different risks; sure, you can update base in-place just once, but then you have to manage the logistics of package updates for all of these other things 20:10:38 hm right 20:10:49 depending on the nature of the base upgrade, that's not great 20:11:36 updating packages in the jails is a problem regardless of whether you have thin or thick jails, no? 20:11:40 minor version updates are fine, but if you need to do a major version hop then you're signing up for fun since you can't just do one jail at a time in isolation 20:12:10 mns: yes, but the question is whether I have to bring down all of my thin-jails or can do one thick jail at a time 20:13:22 kevans: good point, I've not had that many jails to run into that yet. 20:14:56 jails can get pretty interesting, you can also configure them to just contain a single binary and its dependencies. so less than the base system. 20:15:02 either way, in a container model I can presumably rebuild the container with an updated base and achieve pretty minimal downtime as I swap the container into production, modulo things that may require data migration (thinking of, e.g., postgres upgrades) 20:15:28 bsdrobert: how would you do that? 20:16:08 kevans: Or stuff them into Kubernetes and have a rolling upgrade! But don't do that. 20:17:08 you can do that by copying a binary on the host system, and all of its shared libraries (via ldd), then copy them over, so it's something you'd script. 20:18:46 i have written the script but dont really want to share links here, search github for anonssh 20:20:50 will do bsdrobert 20:20:51 thanks 20:25:51 Hm, looking at the live example at https://whiskey.skunkwerks.at/en/books/handbook/containers/ I immediately want to start changing things. 20:26:56 whiskey, skunk and austria with a dash of freebsd. 20:31:15 mns: i think this conversation has inspired me to take that code and turn it into something like 'minijail $(which irssi)' 20:32:12 I'll have to go through the Containers stuff now too. 20:32:26 Would be nice to use similar tooling to the rest of the world 20:32:55 mhm. 20:33:09 sure, to an extent. 21:25:22 * mason plays with pkgbasify for the first time. I was going to reinstall a box, but given that I'm willing to do that, I might as well try this first. 21:27:50 So, I'm really curious about this. Shouldn't pkgbasify set "enabled: no" in /etc/pkg/FreeBSD.conf? 21:27:56 s/no/yes/ 21:28:02 It exists as "no" after running it. 21:31:26 mason: I think you'll be pleasantly surprised with pkgbase. 21:31:56 So, pkgbasify creates a new FreeBSD-base.conf file in /usr/local/etc/pkg/repos that has it set to yes. 21:32:06 That overrides the /etc/pkg/*.conf files. 21:39:24 I haven't used pkgbasify in a while, so I'm not sure how much more refined it is now (since I've been on pkgbase already.) But, I do recall needing to point the pkgbase certs to a different location? 21:39:40 ... or the certs they're looking for didn't exist and I had to pull those manually or something. 21:39:49 Other than that, it's been quite solid ever since. 21:41:10 ek: Ah, sure enough. Thank you. 21:41:24 ek: It appears to have done everything on its own. 21:41:33 Sure thing. 21:42:02 Yeah. I would assume it's much more revised by now since it's becoming the norm/default moving forward. 21:43:28 The update process is much faster. Instead of waiting for 45 minutes for a "freebsd-update", it only takes ~30 seconds for a pkg upgrade. Vast difference. 21:43:37 Yes, I'm loving that. 21:44:34 It's pretty nice! 21:45:13 Also crazy handy for jail updates as well. Everything is just so much easier and faster. 21:45:32 Not that I don't appreciate freebsd-update. This is just a much more streamlined option. 21:58:28 to use pkgbase, do I need to be on 15.x? or will I be able to use it on 14.4 which is what I am on at the moment. 22:01:02 mns: you can use it on 14.x, but it's a little unfriendly 22:02:24 (e.g., you'll need to watch more closely for landmines when upgrading because 14 doesn't have the notion of sets? 22:02:29 s/?/)/ 22:03:52 Got it. Maybe that's another reason to get me motivated to move to 15. Most likely 15.0-STABLE 22:07:12 mns: You can definitely use pkgbasify to convert to pkgbase on 14.x. It's not terribly difficult. Like kevans said, just keep an eye on the first bits to make sure there aren't any errors or hiccups. 22:07:19 After that, you're pretty much all set. 22:07:55 But, I would pkgbasify and then use pkgbase to upgrade to 15. Might as well since it only takes a few seconds. 22:08:11 It isn't tedious. 22:12:03 ek: oooh that's a good point, that is what pkgbase is for anyway, so might as well use it for that. I just need to get some external storage for backups. I have a mini-pc with 8GB RAM and 128GB of storage (I think, have to see how I can find out the exact amount) 22:12:35 there used t b a magical diff invocation on the PkgBase wiki to pick up what packages you're missing that the repo has and vice-versa 22:12:42 but its my main system so don't want to have anything mess up. 22:13:05 though i guess if you're upgrading 14.x -> 15.x, you probably just upgrade to 15 and then immediately install a set 22:14:21 fwiw, i used pkgbase for a long time before 14.x successfully, so it certainly won't blow anything up 22:15:50 how did you use it before 14.x, didn't it come out with 14.x ? 22:16:07 it's existed in the tree for much longer than that 22:16:49 oh 22:17:24 I haven't gone tripping through the srouce tree 22:17:26 the first iteration of my personal pkgbase builder was committed in 2016 22:17:37 oh wow! 22:18:20 at the time i would've only been using it for embedded things, but it was more or less reasonable 22:19:02 I thought this was a new thing, so its not really new. 22:19:19 It's been in dev for a while. I've been using it for about 5 years myself. 22:19:21 no, though there was a lot more recent work on it 22:20:03 the basic idea has been set for many years, recent evolutions made it a lot more user-friendly 22:20:20 Most definitely. It's very easy to use now. 22:20:57 Got it. 22:38:45 alright downloaded pkgbasify 22:38:56 will go through it and see what it does and prepare accordingly