00:30:03 sambala: had a heck of a time finding out, closest I got was a bug report that notes a change in the rc.d/ipsec script to change "nojail" to "nojailvnet", but nothing in the vnet or jail handbook sections. 01:26:31 ssh robert⊙4 - IPSEC in a VNET jail, possible? 01:26:45 there's a complee answer there, just tried. 02:15:18 c ear 03:34:01 bsdrobert: I don't really follow, there's an answer where? or is this a mis-paste (noting the ssh command)? 08:27:02 spork_css: i recommend strongswan 08:28:40 it looks like the ipsec rc script is a wrapper around manualy specifying your ipsec state which would not be recommended for a normal installation 08:29:52 in theory, there is no difference to running outside a jail 08:36:43 can you create apple-compatible .dmg disk images on freebsd? 11:44:39 is a jail more secure than a kvm? 11:48:27 I would say gaol would be more accurate than jail :) 11:49:09 hardware virtualisation gives more segregation than kernel based gaols 11:51:52 and jails in the kvm? 11:52:33 is more secure than just jail? 12:13:35 ..so much work 12:14:49 I don't understand install(1). I have: /usr/local/jails/media/defaults/usr/local/etc/prometheus/web.yml (file) and I want to copy it to /usr/local/jails/containers/ub/usr/local/etc/prometheus/web.yml . There is ~no garantee that the destination folders/directories exist, but /usr/local/jails/containers/ub/ does exist. Can install(1) just handle everything and put my file in the right place? 13:41:17 dnp1 13:53:49 Morning 13:54:12 3:54 pm here, good morning :) 13:54:47 4:54 pm 13:58:46 moviuro: no. but you can try this yourself: `install /etc/motd /tmp/118/motd` -> install: /tmp/118: No such file or directory 13:59:06 in this case moviuro I typically use rsync ... -d , or do a mkdir -p prior. 13:59:34 dch: I fell back to using tar(1) which ships by default and also supports proper permission management for all files on the path 13:59:57 moviuro: nice. also if you're doping lots of these things, mtree is another choice. 14:00:36 s/doping/doing/ 14:30:58 ok, so i tried make packages in /usr/src and it made the repo with packages and sets and i was able to make and run test jail that has only FreeBSD-sets-minimal-jail ( and whatever this meta pkg installs ) there. Nice 14:32:04 however, repo is generated in /usr/obj/usr/src/repo/... so i had to null mount it for the jail to use the repo. which is sub-optimal. it could that i do make clean in /usr/obj and this repo is then gone. 14:32:23 can i have generated repo somewhere else somehow? 14:32:43 copy it over to /var/db/repos? 14:36:47 dch: glad I found https://forums.freebsd.org/threads/small-guide-on-using-mtree.61113/ because the manpage is... lackluster 14:46:08 angry_vincent: there'ss a knob for that 14:46:50 build(7) documents this, fwiw. You set REPODIR, ideally 14:46:52 oh 14:47:57 i remember REPODIR, yes. didn't know pkgbase also respects it. 15:19:39 spork_css: no, you can use that ssh command exactly as-is (ssh robert⊙4) then ask your question. It is connected to the FreeBSD handbook and man pages. The answer you want is in official sources. 16:42:18 where can I find documentation on what interface cloning is? 16:48:38 ifconfig(8) mainly 16:55:31 ifconfig(8) talks about cloned interfaces but doesn't really say what the phrase means 16:59:50 AFAIK it is a misnamed term that is now historical on context and the rationale for it is not well known. I don't know it. 16:59:56 The rc.conf file has a variable cloned_interfaces. This is documented in the "man 5 rc.conf" man page. 17:00:01 I don't really understand why they use the word "cloned" as that to me implies that an existing interface is being copied creating a clone of it. AFAIK that is not what is happening. What is happening is that ifconfig is being called to create additional interfaces on the system. 17:00:31 Yes, im not sure such an intro exists, it is scattered across many diff man pages, so you have to piece it together. 17:01:01 So basically if you want to create a new ifconfig interface automatically at boot time then put the name of the interface to create in cloned_interfaces in rc.conf and then it will call ifconfig at boot time and create it. 17:01:58 The ifconfig command does different things depending upon the naming convention of the device. For example cloned_interfaces="bridge37" would create a bridge device (numbered 37) at boot time because that's what "ifconfig bridge37" will do. 17:03:25 To start setting up something (such as for a jail or bhyve or whatever) it is good to be able to run through all of the ifconfig commands manually on the command line first. Understand what the commands are and what is needed. Then map those back to the rc variable names. It starts with cloned_interfaces to create the device. But then in another /something/ devices will be associated. 17:05:08 For example I create a bridge on a system like above. Then what I do is in the jail.conf prestart for the jail I create an epair, rename the epair, add the named epair to the bridge. In the jail poststop I destroy the epair for the teardown side of things. 17:07:14 so it sounds like you're saying that cloned interfaces are just interfaces that are dynamically created after startup 17:07:42 it's cloned because it clones an if 17:08:07 Physical interfaces (like em0, igb0) are tied to hardware. Cloned interfaces are software-only virtual interfaces 17:08:09 So my interpretation of cloned_interfaces is that it is a list of devices that ifconfig is told to create at rc boot time. (It probably started out for some specific purpose, hence the name, but was there, so got pressed into service to do other things, basically every other thing, and the name was already in place and never updated to reflect the new more expanded role.) 17:08:10 that you create on-demand with ifconfig create. The kernel provides "cloner" modules (listed by ifconfig 17:08:14 -C) — things like bridge, vlan, gif, tap, epair, lagg — and you instantiate them as needed. They work just li 17:08:17 ke real interfaces once created: they can have IP addresses, be added to bridges, moved into jails, etc. You list 17:08:20 them in /etc/rc.conf under cloned_interfaces to make them persist across reboots. 17:08:25 I thought cloned interfaces had something to do with a device in /dev with a name that doesn't have a trailing number, and then when you clone it, it creates another device in /dev with an unused number 17:08:34 woops, that paste was wonky, but explains the conceptual level. 17:09:08 could view as create 17:09:24 which is what clone is 17:09:44 but it doesn't copy the real if 17:09:51 :p 17:09:55 If it were s/clone/create/ then personally I think that would make more sense. (shrug) 17:10:29 it clones an interface from kernel virtual interface driver 17:10:43 original doens't "work" 17:11:00 like there's no "vlan" 17:11:04 So the naming comes from the low-level kernel system calls which are used? I guess that is defendable. 17:11:08 maybe if you rename it 17:11:24 if it's allowed 17:11:42 no idea what kernel actually does 17:12:05 but i bet i copies virt if structs 17:12:08 it 17:12:16 (now me wants to run it through truss and see what is actually called, but no time at the moment) 17:13:23 no idea wtf is syscall to clone vlan 17:16:13 i tried 17:19:31 oh now i remember 17:19:33 somehow 17:19:35 38507 ifconfig CALL ioctl(0x4,SIOCIFCREATE2,0x56f5c7e8a60) 18:16:07 I'm having the weirdest time 18:16:20 47% consistent packet loss on lo0 18:19:50 Packet loss on a loopback device? That is unexpected! What release kernel are you running "freebsd-version -r"? 18:20:13 should be 15.1, lemme finish booting it back up... 18:20:26 though perhaps that's a hint to try the boot-env from before I updated it 18:20:26 Meanwhile... I don't know how that could happen. So I won't be any help regardless. I would start with a fresh reboot. 18:20:34 it's had a few 18:21:33 15-1-RELEASE-P1 18:22:09 That is the current one. That is the same as I am running on all of my (now) upgraded systems. 18:22:10 I can probably rule out RAM, it does it with either stick as well as both 18:22:52 I guess my next move is to boot 'er up off a usb stick 18:26:09 or even better, a usb ssd drive. save myself 20 minutes of waiting for a dinky USB stick to finish flashing 18:27:21 But the loopback device lo0 is a purely virtual in kernel memory device. It is independent of hardware. If it is failing then I don't see how it can be anything other than a kernel bug. 18:28:35 it's not independent of memroy hardware 18:29:52 Sounds like reasource 18:30:09 then again I suppose if it was fucked enough to lose that many packets it wouldn't run at all 18:30:17 well, here comes the installation media 18:31:10 so, that's an improvement. it's 28% now 18:31:30 oh, hold up, that's because ipv4 18:36:30 choosing to use a spare SSD for this instead of a USB stick is a major QOL improvement 18:39:06 still happens with 15.0 18:39:18 right, time to grab the old mini PC I guess 18:49:19 hey i'm having an issue with pf and bastille. i have a (nearly) fresh freebsd 15.0-release VPS. i ran bastille setup, configured a single jail, and now i cannot make outbound requests from the host but i **can** make them from the jail. 18:50:25 does this ring a bell for anyone? how might i go about troubleshooting this? my guess is it has something to do with the default bastille pf rules 18:56:22 aha! enabling icmp6 functions here fixed it: https://oneuptime.com/blog/post/2026-03-20-configure-ipv6-firewall-pf-freebsd/view 19:00:26 update: so I tried on an entire 'nother computer with 15.1-RELEASE memory stick boot, and it's still happening. for reference, I was doing a `ping -c 1000 -f ::1`and my point of reference here was that my linux machine does not lose packets doing this 19:00:43 either way I guess I'm popping that off the debugging stack and assumign my nfs issues are somewhere else 19:17:02 even more interestingly, it's not bidirectional: if I ping _to_ the freebsd box it loses packets, if I ping _from_ it it'll lose none 19:20:22 fucksake, sussed it 19:20:25 `net.inet.icmp.icmplim` 20:23:41 hello 20:24:16 my uname -a says my kernel is dirty, does it stink? 20:24:51 system is running fine though 20:26:09 this after updating from 15.0 to 15.1 20:31:25 LapsangS: it's a known issue in the build-process. was mentioned in the mailing list on July 1. 20:31:58 LapsangS: https://forums.freebsd.org/threads/freebsd-15-1-p1-dirty.103140/page-2 20:32:45 only the metadata is affected and they'll likely just leaeve it until the next set of advisories. 20:33:23 laiz: freebsd-version -kru 20:33:26 you're all bood 20:35:57 yeah 20:36:04 bood = good 21:58:22 Only my gateway and production FreshPorts are not yet on #FreeBSD 15.1 - soon. Perhaps tomorrow. 22:18:46 Nice progress dvl 23:46:55 guess i'll roll up my sleeves now and see if i can swap from freebsd-update to pkg :/ 23:51:37 zip: max number of icmp responses per second. You're exceeding the default cap?