-
spork_css
sambala: had a heck of a time finding out, closest I got was a bug report that notes a change in the rc.d/ipsec script to change "nojail" to "nojailvnet", but nothing in the vnet or jail handbook sections.
-
bsdrobert
ssh robert⊙4 - IPSEC in a VNET jail, possible?
-
bsdrobert
there's a complee answer there, just tried.
-
skered
c ear
-
spork_css
bsdrobert: I don't really follow, there's an answer where? or is this a mis-paste (noting the ssh command)?
-
jmnbtslsQE
spork_css: i recommend strongswan
-
jmnbtslsQE
it looks like the ipsec rc script is a wrapper around manualy specifying your ipsec state which would not be recommended for a normal installation
-
jmnbtslsQE
in theory, there is no difference to running outside a jail
-
GoSox
can you create apple-compatible .dmg disk images on freebsd?
-
sambala
is a jail more secure than a kvm?
-
wez
I would say gaol would be more accurate than jail :)
-
wez
hardware virtualisation gives more segregation than kernel based gaols
-
sambala
and jails in the kvm?
-
sambala
is more secure than just jail?
-
sambala
..so much work
-
moviuro
I don't understand install(1). I have: /usr/local/jails/media/defaults/usr/local/etc/prometheus/web.yml (file) and I want to copy it to /usr/local/jails/containers/ub/usr/local/etc/prometheus/web.yml . There is ~no garantee that the destination folders/directories exist, but /usr/local/jails/containers/ub/ does exist. Can install(1) just handle everything and put my file in the right place?
-
jbo
dnp1
-
dnp1
Morning
-
joemie
3:54 pm here, good morning :)
-
sambala
4:54 pm
-
dch
moviuro: no. but you can try this yourself: `install /etc/motd /tmp/118/motd` -> install: /tmp/118: No such file or directory
-
dch
in this case moviuro I typically use rsync ... -d , or do a mkdir -p prior.
-
moviuro
dch: I fell back to using tar(1) which ships by default and also supports proper permission management for all files on the path
-
dch
moviuro: nice. also if you're doping lots of these things, mtree is another choice.
-
dch
s/doping/doing/
-
angry_vincent
ok, so i tried make packages in /usr/src and it made the repo with packages and sets and i was able to make and run test jail that has only FreeBSD-sets-minimal-jail ( and whatever this meta pkg installs ) there. Nice
-
angry_vincent
however, repo is generated in /usr/obj/usr/src/repo/... so i had to null mount it for the jail to use the repo. which is sub-optimal. it could that i do make clean in /usr/obj and this repo is then gone.
-
angry_vincent
can i have generated repo somewhere else somehow?
-
angry_vincent
copy it over to /var/db/repos?
-
moviuro
-
kevans
angry_vincent: there'ss a knob for that
-
kevans
build(7) documents this, fwiw. You set REPODIR, ideally
-
angry_vincent
oh
-
angry_vincent
i remember REPODIR, yes. didn't know pkgbase also respects it.
-
bsdrobert
spork_css: no, you can use that ssh command exactly as-is (ssh robert⊙4) then ask your question. It is connected to the FreeBSD handbook and man pages. The answer you want is in official sources.
-
rsjw
where can I find documentation on what interface cloning is?
-
bsdrobert
ifconfig(8) mainly
-
rsjw
ifconfig(8) talks about cloned interfaces but doesn't really say what the phrase means
-
rwp
AFAIK it is a misnamed term that is now historical on context and the rationale for it is not well known. I don't know it.
-
rwp
The rc.conf file has a variable cloned_interfaces. This is documented in the "man 5 rc.conf" man page.
-
rwp
I don't really understand why they use the word "cloned" as that to me implies that an existing interface is being copied creating a clone of it. AFAIK that is not what is happening. What is happening is that ifconfig is being called to create additional interfaces on the system.
-
bsdrobert
Yes, im not sure such an intro exists, it is scattered across many diff man pages, so you have to piece it together.
-
rwp
So basically if you want to create a new ifconfig interface automatically at boot time then put the name of the interface to create in cloned_interfaces in rc.conf and then it will call ifconfig at boot time and create it.
-
rwp
The ifconfig command does different things depending upon the naming convention of the device. For example cloned_interfaces="bridge37" would create a bridge device (numbered 37) at boot time because that's what "ifconfig bridge37" will do.
-
rwp
To start setting up something (such as for a jail or bhyve or whatever) it is good to be able to run through all of the ifconfig commands manually on the command line first. Understand what the commands are and what is needed. Then map those back to the rc variable names. It starts with cloned_interfaces to create the device. But then in another /something/ devices will be associated.
-
rwp
For example I create a bridge on a system like above. Then what I do is in the jail.conf prestart for the jail I create an epair, rename the epair, add the named epair to the bridge. In the jail poststop I destroy the epair for the teardown side of things.
-
rsjw
so it sounds like you're saying that cloned interfaces are just interfaces that are dynamically created after startup
-
ketas
it's cloned because it clones an if
-
bsdrobert
Physical interfaces (like em0, igb0) are tied to hardware. Cloned interfaces are software-only virtual interfaces
-
rwp
So my interpretation of cloned_interfaces is that it is a list of devices that ifconfig is told to create at rc boot time. (It probably started out for some specific purpose, hence the name, but was there, so got pressed into service to do other things, basically every other thing, and the name was already in place and never updated to reflect the new more expanded role.)
-
bsdrobert
that you create on-demand with ifconfig <name> create. The kernel provides "cloner" modules (listed by ifconfig
-
bsdrobert
-C) — things like bridge, vlan, gif, tap, epair, lagg — and you instantiate them as needed. They work just li
-
bsdrobert
ke real interfaces once created: they can have IP addresses, be added to bridges, moved into jails, etc. You list
-
bsdrobert
them in /etc/rc.conf under cloned_interfaces to make them persist across reboots.
-
rsjw
I thought cloned interfaces had something to do with a device in /dev with a name that doesn't have a trailing number, and then when you clone it, it creates another device in /dev with an unused number
-
bsdrobert
woops, that paste was wonky, but explains the conceptual level.
-
ketas
could view as create
-
ketas
which is what clone is
-
ketas
but it doesn't copy the real if
-
ketas
:p
-
rwp
If it were s/clone/create/ then personally I think that would make more sense. (shrug)
-
ketas
it clones an interface from kernel virtual interface driver
-
ketas
original doens't "work"
-
ketas
like there's no "vlan"
-
rwp
So the naming comes from the low-level kernel system calls which are used? I guess that is defendable.
-
ketas
maybe if you rename it
-
ketas
if it's allowed
-
ketas
no idea what kernel actually does
-
ketas
but i bet i copies virt if structs
-
ketas
it
-
rwp
(now me wants to run it through truss and see what is actually called, but no time at the moment)
-
ketas
no idea wtf is syscall to clone vlan
-
ketas
i tried
-
ketas
oh now i remember
-
ketas
somehow
-
ketas
38507 ifconfig CALL ioctl(0x4,SIOCIFCREATE2,0x56f5c7e8a60)
-
zip
I'm having the weirdest time
-
zip
47% consistent packet loss on lo0
-
rwp
Packet loss on a loopback device? That is unexpected! What release kernel are you running "freebsd-version -r"?
-
zip
should be 15.1, lemme finish booting it back up...
-
zip
though perhaps that's a hint to try the boot-env from before I updated it
-
rwp
Meanwhile... I don't know how that could happen. So I won't be any help regardless. I would start with a fresh reboot.
-
zip
it's had a few
-
zip
15-1-RELEASE-P1
-
rwp
That is the current one. That is the same as I am running on all of my (now) upgraded systems.
-
zip
I can probably rule out RAM, it does it with either stick as well as both
-
zip
I guess my next move is to boot 'er up off a usb stick
-
zip
or even better, a usb ssd drive. save myself 20 minutes of waiting for a dinky USB stick to finish flashing
-
rwp
But the loopback device lo0 is a purely virtual in kernel memory device. It is independent of hardware. If it is failing then I don't see how it can be anything other than a kernel bug.
-
zip
it's not independent of memroy hardware
-
dnp1
Sounds like reasource
-
zip
then again I suppose if it was fucked enough to lose that many packets it wouldn't run at all
-
zip
well, here comes the installation media
-
zip
so, that's an improvement. it's 28% now
-
zip
oh, hold up, that's because ipv4
-
zip
choosing to use a spare SSD for this instead of a USB stick is a major QOL improvement
-
zip
still happens with 15.0
-
zip
right, time to grab the old mini PC I guess
-
sloane
hey i'm having an issue with pf and bastille. i have a (nearly) fresh freebsd 15.0-release VPS. i ran bastille setup, configured a single jail, and now i cannot make outbound requests from the host but i **can** make them from the jail.
-
sloane
does this ring a bell for anyone? how might i go about troubleshooting this? my guess is it has something to do with the default bastille pf rules
-
sloane
-
zip
update: so I tried on an entire 'nother computer with 15.1-RELEASE memory stick boot, and it's still happening. for reference, I was doing a `ping -c 1000 -f ::1`and my point of reference here was that my linux machine does not lose packets doing this
-
zip
either way I guess I'm popping that off the debugging stack and assumign my nfs issues are somewhere else
-
zip
even more interestingly, it's not bidirectional: if I ping _to_ the freebsd box it loses packets, if I ping _from_ it it'll lose none
-
zip
fucksake, sussed it
-
zip
`net.inet.icmp.icmplim`
-
LapsangS
hello
-
LapsangS
my uname -a says my kernel is dirty, does it stink?
-
LapsangS
system is running fine though
-
LapsangS
this after updating from 15.0 to 15.1
-
sig`
LapsangS: it's a known issue in the build-process. was mentioned in the mailing list on July 1.
-
sig`
-
sig`
only the metadata is affected and they'll likely just leaeve it until the next set of advisories.
-
sig`
laiz: freebsd-version -kru
-
sig`
you're all bood
-
LapsangS
yeah
-
sig`
bood = good
-
dvl
Only my gateway and production FreshPorts are not yet on #FreeBSD 15.1 - soon. Perhaps tomorrow.
-
dnp1
Nice progress dvl
-
Macer
guess i'll roll up my sleeves now and see if i can swap from freebsd-update to pkg :/
-
dnp1
zip: max number of icmp responses per second. You're exceeding the default cap?