-
polarian
kerneldove: ssh forward on the host then?
-
polarian
wait nvm hmmm
-
kerneldove
polarian that won't work?
-
kerneldove
that's what i'd hope to do i think
-
polarian
honestly if the vnet jail is limited to the host network, then there is not going to be some elegate way which doesn't involve the host, if the jails are available on the local network, but not got a public IPv4 (IE: not WAN reachable) then you can simply transfer the file locally?
-
polarian
kerneldove: you could use git (or friends), push the asset there, and have the asset pulled back down
-
polarian
or push the asset to some webserver and pull it back down from the jail
-
kerneldove
well with docker type containers, the container host can do port forwarding to the container. i just assumed jails would have something similar
-
polarian
yeah you can, with pf!
-
kerneldove
the jails do have a private ip so that jails can be on the same private lan, if that helps?
-
kerneldove
would i connect to ip of jail host and it forwards to jail using its private lan ip?
-
polarian
match in proto tcp from any to $hostip nat-to $jailip
-
polarian
sorry no
-
polarian
match in proto tcp from any to $hostip port $someport rdr-to $jailip
-
polarian
there you go
-
polarian
thats what you want
-
polarian
actually
-
polarian
you want to do
-
kerneldove
and hostip is like 10.1.1.5 (my home lan) or 1.2.3.4 (public ipv4 at a colo) and the jailip would be like 192.168.15.20? (192.168.15/24 being the private lan for the project, so its various jails can all talk to each other on that private lan)
-
polarian
match in on $hostif proto tcp from any to $hostip port $someport rdr-to $jailip
-
polarian
the hostip is the ip of your jail host, and then the jailip is the ip address of the vnet jail
-
polarian
and you want this to be only matching against packets coming in on the host interface
-
kerneldove
but you get my point about the vnet jail's ip being in a private lan subnet?
-
polarian
aka the interface which connects it to the local network
-
polarian
kerneldove: yes but the host can reach said subnet
-
kerneldove
ok so that's supported, nice!
-
polarian
so you can just do packet redirection
-
polarian
rdr-to is pf's way to redirect packets, aka "port forwarding"
-
polarian
the port(s) you specify are redirected to the IP you specify
-
kerneldove
ok that's great, seems this is a solution. i had no idea the public ip of the host could be used to 'bridge' onto the private lan subnet of a set of jails
-
kerneldove
that's really great
-
kerneldove
tyvm
-
polarian
this relies on the host being able to access the internal networks
-
polarian
I assume its configured with an epair right>
-
polarian
?
-
kerneldove
polarian can i forward the port to a different port on the jail? that way each jail can have normal ports
-
kerneldove
ya epair
-
kerneldove
like 5522 forwards to 22
-
kerneldove
5622 forwards to 22 of a different jail's private ip
-
kerneldove
etc
-
polarian
kerneldove: yes iirc you just specify the jail port after
-
polarian
so
-
kerneldove
ok nice thought so
-
polarian
match in on $hostif proto tcp from any to $hostip port $someport rdr-to $jailip port $someotherport
-
polarian
I think...
-
polarian
:)
-
polarian
I mainly know pf from OpenBSD, it differs slightly, but afaik that is the correct syntax
-
kerneldove
man i've been so stressed wondering how tf i'm gonna allow network access to select services (ssh/rsync/sftp) in jails without giving them public ips
-
kerneldove
i guess this scheme makes pinging jails impossible unless i created host forwards for that too?
-
kerneldove
(not a deal killer jc)
-
polarian
kevans: any docs to debug loader stages?
-
kerneldove
polarian do you know about ping forwarding too?
-
spork_css
some of MWL's footnotes are just good life advice: "If you don’t like your vendor’s answer, ask more loudly and with malice aforethought."
-
kerneldove
how do you install pkgs into a jail that doesn't have public internet access?
-
wez
You can setup separate routing in a gaol?
-
kerneldove
gaol?
-
kerneldove
i assume i can't use pkg -j since that runs from within the jail
-
wez
kerneldove: yeah?
-
kerneldove
so freebsd-update -j operates ON the jail, but pkg -j operates IN the jail? seems weird inconsistent
-
kevans
freebsd-update -j is more like pkg -r
-
kevans
but with the path resolved from `jls`
-
kerneldove
would be nice if pkg had that too :/ seem slike a gap
-
wez
You can give it a VNET to work with and then use ipfw or whatever to block traffic
-
wez
Is that what you are refering to?
-
kerneldove
wut
-
kerneldove21
got d/c
-
kerneldove21
wut?
-
dkeav
dumb question, but is there any efforts to bring the openbsd pledge/unveil stuff into the FreeBSD kernel?
-
dkeav
capsicum seems to be well nobody gives a shit about it and doesn't want to mess with it, and pledge/unveil stuff seem readily adopted
-
dkeav
i mean at this point its okay to say maybe we were wrong and this is a better option etc
-
dkeav
I just worry because of the AI find exploits thing and its going to be predominately 3rd party stuff and we have zero way to protect ourselves from it
-
kerneldove21
does actually noone give shit about capsicum?
-
kevans
no
-
kevans
it hasn't seen widespread adoption, but we still deploy it in base utilities
-
spork_css
nobody ever evangelized it that I'm aware of, couldn't even give you a one sentence summary of what it is but I guess SE-Linux-like?
-
kerneldove21
hopefully it keeps being spread into base
-
kerneldove21
like ucl and other freebsd tech, constantly spreading slowly but surely
-
kerneldove21
like jails spreading to now have service jails
-
dkeav
well it just seems like capsicum is very difficult to implement
-
dkeav
so, it doesn't get implemented
-
dkeav
i dunno, maybe there are options here
-
kevans
spork_css: selinux is more like MAC
-
kevans
except gross
-
dkeav
lol
-
kevans
you boot a linux system and see that selinux is enabled, your first thought is "ah shit"
-
kevans
MAC? nah, it's helpful. it removed root from ntpd like a good guy
-
spork_css
IIRC it's like someone's thesis originally or something? some relation to oxford? I only have vague vibes on it.
-
dkeav
granted in SELinux they're trying to tackle the userland security at the kernel level but they don't have a userland
-
dkeav
FreeBSD does
-
spork_css
the last thing FreeBSD introduced where I just jumped in really, really early was ZFS. Prior to that a 2.2.7-stable snapshot where CAM was brought in (we had a fancy RAID controller that in some way required something that CAM introduced - I think something really silly like addressing multiple LUNs or something.
-
kerneldove21
if you install a pkg with pkg mypkg, then you install the same pkg again with a jail root like pkg -r ... mypkg, will it download mypkg again or is there a cache that'll be used?
-
dkeav
yea i remember when some jerkass mentioned about boot environments with zfs being a killer feature in solaris
-
kevans
kerneldove21: iirc pkg -r sandboxes itself to the root these days, it wouldn't have access to system cache
-
kevans
don't quote me on that
-
spork_css
We ran some stats to compare running just a pair of (very expensive at that time) SSDs for postgresql servers to a pair of "enterprise" 7200 RPM SATA drives, but backed with a pair of small Intel 320 SSDs as ZIL/L2ARC and that's when we bought in fully.
-
spork_css
The ZIL basically let us *safely* cache atomic writes at SSD speed instead of HD speed is the most basic way to explain it.
-
kerneldove21
swap && zfs is a hairy thing to me but aside from that zfs is gold
-
spork_css
So a filesystem saved us a shitload of money.
-
spork_css
I still don't put swap on zfs, I imagine it works now, but I still partition the same - gpt w/boot - swap - zfs (or add in EFI if you're doing that)
-
kerneldove21
ya i don't use swap unless i'm running single disk zfs
-
spork_css
I think part of what swayed us was that lots of people with influence in the PostgreSQL community were banging on it immediately, and there were also people running PG on Solaris back then, so they came in with knowledge.
-
spork_css
since it's late night, some #social-ish material:
imgur.com/a/Il89ch4
-
spork_css
unpacking and finding 90's things...
-
dnp1
Walnut Creek, nastolgia
-
kerneldove21
so instead of running pkg within a jail, and running pkg ON a jail, i change pkg bootstrap -f to pkg -r /zroot/jails/myjail bootstrap -f?
-
polarian
kenichi: you cant ping something which you do not have access to.
-
polarian
it would eliminate the point of ICMP
-
polarian
kenichi: as for pkg installation on airgapped containers, you can proxy the pkg repository using nginx on the host, and then you use the nginx on the host to install ports
-
polarian
someone spoke about this recently on XMPP
-
polarian
sorry I meant to ping kerneldove not kenichi I am so sorry...
-
polarian
oh wait kerneldove isn't even in the channel
-
» polarian facepalms
-
polarian
question, how many people here would refuse to attend an event if it was branded under FSF(E)? Would you attend an event if it was simply sponsored/supported by FSF(E)?
-
polarian
I am finding it difficult to mix FOSS circles (FSF(E) endorsed) with BSD, because well... BSD folks tend to hate FSF(E)
-
polarian
intentionally keeping this out of the ML, as I dont want drama around it, I just want an honest response from the community without archives
-
wavefunction
polarian: There's a huge difference between hating the FSF as an entity (which I kinda do because they're so busy protecting Stallman), and FSF-endorsed stuff.
-
wavefunction
Free Software is great, happy to take your money and tell you as an entity to go pound sand. (If grants require FSF influence, that's money with ropes, not strings)
-
polarian
wavefunction: tl;dr I have an offer from FSFE I am turning down
-
polarian
they want the branding for a series of meetups I am planning in London
-
polarian
however its targetted at FOSS entirely, incl BSD
-
polarian
last time I helped organise a FOSS meetup it was sponsored by FSF and BSD people got a little... yk...
-
polarian
I know FSFE is a lot more mild than the FSF so probably wouldnt be as controversial, but still
-
polarian
I will be running a meetup on 8th and I will let them take the branding for it
-
polarian
but in the future I ideally want my own branding and for it to be across many groups (BSD, XMPP, FOSS)
-
polarian
im not even looking for funding, all I wanted from the FSFE was advertisement, which they can do for free. Plus I donated to them :)
-
polarian
I was originally looking to make a BUG (BSD User Group) but FOSS in the UK is in a bad place right now (little to no functional linux user groups, hackerspaces are actually makerspaces and are pretty hostile to free software in some cases), so I have pivoting to combine and run a joint effort for FOSS+BSD+XMPP
-
polarian
but I cant combine 3 different interests together if I then brand it as a FSFE event, can I?
-
polarian
I want it to be flexible, I dont want to be locked into a name or into a organisation which is advertising (or potentially funding) it
-
polarian
anyways, I need to get the whole FDE stuff sorted because one of the servers which I want to use for it needs it done :)
-
kerneldove
so instead of running pkg within a jail, i'm switching to running pkg ON a jail, and that means i change jexec -l myjail /bin/sh -c "pkg bootstrap -f | cat" to pkg -r /zroot/jails/myjail bootstrap -f | cat right?
-
polarian
kerneldove: yes that *could* work
-
polarian
but you wont be able to bootstrap pkg without network access in the first place
-
polarian
you can copy /usr/ports into the jail (or mount it as a nullfs)
-
polarian
and then make install the port
-
kerneldove
network access where? the jail host has network access, the jail shouldn't
-
polarian
yes
-
kerneldove
WHERE
-
polarian
to bootstrap the jail you need network access, your command is jexec the boostrap inside the jail
-
polarian
"pkg boostrap -f | cat" is ran within the jail
-
polarian
pkg bootstrap requires network access
-
kerneldove
uh ya
-
kerneldove
i didn't ask that
-
polarian
then I am not sure what you are asking/
-
kerneldove
i said that's the current command. i want to change it to run pkg -r
-
kerneldove
so instead of running pkg within a jail, i'm switching to running pkg ON a jail, and that means i change jexec -l myjail /bin/sh -c "pkg bootstrap -f | cat" to pkg -r /zroot/jails/myjail bootstrap -f | cat right?
-
kerneldove
read the whole question pls
-
polarian
oh right
-
polarian
no you dont need to boostrap the jail then
-
polarian
afaik you can just use the -r flag with pkg on the host, and it will install the files into the directory
-
polarian
I think!
-
polarian
you will need to test it
-
polarian
eg try
-
polarian
pkg -r /zroot/jails/myjail install cowsay
-
polarian
then run cowsay within the jail
-
polarian
if it works as expected, it should work!
-
polarian
so is there a freebsd dev willing to help me with debugging stage 1 loader to find out why its either ignoring loader.env or there is some bug in it?
-
polarian
im not giving up on this :)
-
kevans
sorry, dealing with ports tree things
-
polarian
ah yes that fuck up, one of 3 in 48 hours xD
-
polarian
seems like hell quite frankly, someone should buy ya'll a coffee (or a beer to drown out the suffering)
-
jmnbtslsQE
polarian: i'm not a dev, but i read part of the previous conversation about this. my question is, would it solve your problem if you use gptboot instead of gptzfsboot? or does this also present the same hard-coded value?
-
polarian
jmnbtslsQE: gptboot is for ufs afaik
-
polarian
but no
-
polarian
this is stage 1, and the issue lies with potentially either the parsing of the loader.env, or a bug within the stage 1 loader
-
polarian
that is what I need to debug, but I dont know how to do this, and I will have to wait for a dev to become available to help mentor :p
-
jmnbtslsQE
OK, i just thought that if gptboot had the value you wanted, you could put your kernel in a ufs partition then mountroot from a separate zfs-on-root partition
-
kevans
polarian: i think you can move the devinit() call in loader's main() down a little bit to after we've adjusted `howto`, but i suspect this will not be enough
-
kevans
polarian: i think the bits that read loader env would also need to move above cons_probe()
-
kevans
i think both are safe to make, but it'd be worth confirming if you have the time. just don't install either as loader.efi / bootx64.efi, install as a new one and create an `efibootmgr` entry for the test loader
-
kevans
actually, maybe leave the ordering of loader.env w.r.t. `cons_probe()` alone fr the moment, it installs hooks that may just do the right thing
-
black_mambet
how to patch kde2 for freebsd?
-
black_mambet
как пропатчить кде2 под фрибсд?
-
wavefunction
:/
-
black_mambet
how to patch kde2 for freebsd?
-
boru
I think you might have a network problem. Your ping is 26 years.
-
sig`
lol or just lagged and now you're in the future
-
black_mambet
is nvidia-driver-470 still supported on freebsd? if yes, which version of freebsd is recommended?
-
black_mambet
if not, are there any out-of-tree patches or ports to make it work on the latest release?
-
sig`
black_mambet: yes it is still supported and it works on the current release and no patches needed
-
sig`
x11/nvidia-driver-470
-
mary751
I run FreeBSD 15.1 in different machines as both a host (bhyve/Sylve) and as a virtual machine. I noticed there was a new warning about issues in ports repository freeze, also I noticed that if I run pkg update and pkg upgrade I see a ton of things being reinstalled/upgraded. I hope this is normal if anyone has any insight let me know! FreeBSD's announcement:
lists.freebsd.org/archives/freebsd-announce/2026-July/000294.html
-
sig`
markmcb: did you update your pkg package?
-
sig`
sorry mary751
-
mary751
I thought pkg package updates in pkg update && pkg upgrade
-
sig`
those are unrelated, the freeze is just a git-side cleanup.
-
sig`
looks like someone commited a 150mb blob, that must have broke the github mirrror and it doesn't touch the pkg at all
-
sig`
prabably the big reinstall list is just the pkgbase
-
sig`
what does, pkg which /usr/bin/uname
-
sig`
it say FreeBSD-runtime ?
-
kerneldove
i need to set up port forwarding through the public ip to the private ip of a jail, using pf. can i just enable gateway_enable or do i need to set net.inet.ip.forwarding = 1? or both?
-
isley
that's all gateway_enable does iirc
-
kerneldove
ok i'll go through that
-
kerneldove
tyvm and nice scotch