00:03:33 kerneldove: ssh forward on the host then? 00:03:55 wait nvm hmmm 00:04:09 polarian that won't work? 00:04:20 that's what i'd hope to do i think 00:05:52 honestly if the vnet jail is limited to the host network, then there is not going to be some elegate way which doesn't involve the host, if the jails are available on the local network, but not got a public IPv4 (IE: not WAN reachable) then you can simply transfer the file locally? 00:06:24 kerneldove: you could use git (or friends), push the asset there, and have the asset pulled back down 00:06:30 or push the asset to some webserver and pull it back down from the jail 00:06:43 well with docker type containers, the container host can do port forwarding to the container. i just assumed jails would have something similar 00:06:55 yeah you can, with pf! 00:07:02 the jails do have a private ip so that jails can be on the same private lan, if that helps? 00:07:47 would i connect to ip of jail host and it forwards to jail using its private lan ip? 00:07:49 match in proto tcp from any to $hostip nat-to $jailip 00:08:03 sorry no 00:08:20 match in proto tcp from any to $hostip port $someport rdr-to $jailip 00:08:22 there you go 00:08:25 thats what you want 00:09:25 actually 00:09:27 you want to do 00:09:30 and hostip is like 10.1.1.5 (my home lan) or 1.2.3.4 (public ipv4 at a colo) and the jailip would be like 192.168.15.20? (192.168.15/24 being the private lan for the project, so its various jails can all talk to each other on that private lan) 00:09:42 match in on $hostif proto tcp from any to $hostip port $someport rdr-to $jailip 00:10:28 the hostip is the ip of your jail host, and then the jailip is the ip address of the vnet jail 00:10:49 and you want this to be only matching against packets coming in on the host interface 00:10:51 but you get my point about the vnet jail's ip being in a private lan subnet? 00:10:56 aka the interface which connects it to the local network 00:11:08 kerneldove: yes but the host can reach said subnet 00:11:18 ok so that's supported, nice! 00:11:20 so you can just do packet redirection 00:11:33 rdr-to is pf's way to redirect packets, aka "port forwarding" 00:11:46 the port(s) you specify are redirected to the IP you specify 00:13:20 ok that's great, seems this is a solution. i had no idea the public ip of the host could be used to 'bridge' onto the private lan subnet of a set of jails 00:13:25 that's really great 00:13:53 tyvm 00:15:55 this relies on the host being able to access the internal networks 00:16:01 I assume its configured with an epair right> 00:16:03 ? 00:16:03 polarian can i forward the port to a different port on the jail? that way each jail can have normal ports 00:16:06 ya epair 00:16:25 like 5522 forwards to 22 00:16:45 5622 forwards to 22 of a different jail's private ip 00:16:50 etc 00:16:53 kerneldove: yes iirc you just specify the jail port after 00:16:55 so 00:17:01 ok nice thought so 00:17:05 match in on $hostif proto tcp from any to $hostip port $someport rdr-to $jailip port $someotherport 00:17:08 I think... 00:17:16 :) 00:17:30 I mainly know pf from OpenBSD, it differs slightly, but afaik that is the correct syntax 00:23:44 man i've been so stressed wondering how tf i'm gonna allow network access to select services (ssh/rsync/sftp) in jails without giving them public ips 00:24:35 i guess this scheme makes pinging jails impossible unless i created host forwards for that too? 00:24:50 (not a deal killer jc) 00:25:53 kevans: any docs to debug loader stages? 00:30:24 polarian do you know about ping forwarding too? 01:54:10 some of MWL's footnotes are just good life advice: "If you don’t like your vendor’s answer, ask more loudly and with malice aforethought." 03:49:12 how do you install pkgs into a jail that doesn't have public internet access? 03:50:39 You can setup separate routing in a gaol? 03:53:03 gaol? 03:53:15 i assume i can't use pkg -j since that runs from within the jail 03:53:42 kerneldove: yeah? 03:53:48 so freebsd-update -j operates ON the jail, but pkg -j operates IN the jail? seems weird inconsistent 03:54:50 freebsd-update -j is more like pkg -r 03:54:58 but with the path resolved from `jls` 03:55:36 would be nice if pkg had that too :/ seem slike a gap 03:55:43 You can give it a VNET to work with and then use ipfw or whatever to block traffic 03:55:58 Is that what you are refering to? 03:56:04 wut 03:58:47 got d/c 03:58:49 wut? 04:59:24 dumb question, but is there any efforts to bring the openbsd pledge/unveil stuff into the FreeBSD kernel? 05:00:11 capsicum seems to be well nobody gives a shit about it and doesn't want to mess with it, and pledge/unveil stuff seem readily adopted 05:01:43 i mean at this point its okay to say maybe we were wrong and this is a better option etc 05:02:48 I just worry because of the AI find exploits thing and its going to be predominately 3rd party stuff and we have zero way to protect ourselves from it 05:06:11 does actually noone give  shit about capsicum? 05:10:13 no 05:10:51 it hasn't seen widespread adoption, but we still deploy it in base utilities 05:11:18 nobody ever evangelized it that I'm aware of, couldn't even give you a one sentence summary of what it is but I guess SE-Linux-like? 05:11:34 hopefully it keeps being spread into base 05:11:47 like ucl and other freebsd tech, constantly spreading slowly but surely 05:11:58 like jails spreading to now have service jails 05:14:11 well it just seems like capsicum is very difficult to implement 05:14:22 so, it doesn't get implemented 05:14:38 i dunno, maybe there are options here 05:16:10 spork_css: selinux is more like MAC 05:16:21 except gross 05:16:30 lol 05:17:03 you boot a linux system and see that selinux is enabled, your first thought is "ah shit" 05:17:27 MAC? nah, it's helpful. it removed root from ntpd like a good guy 05:17:35 IIRC it's like someone's thesis originally or something? some relation to oxford? I only have vague vibes on it. 05:18:31 granted in SELinux they're trying to tackle the userland security at the kernel level but they don't have a userland 05:18:37 FreeBSD does 05:19:29 the last thing FreeBSD introduced where I just jumped in really, really early was ZFS. Prior to that a 2.2.7-stable snapshot where CAM was brought in (we had a fancy RAID controller that in some way required something that CAM introduced - I think something really silly like addressing multiple LUNs or something. 05:20:10 if you install a pkg with pkg mypkg, then you install the same pkg again with a jail root like pkg -r ... mypkg, will it download mypkg again or is there a cache that'll be used? 05:20:11 yea i remember when some jerkass mentioned about boot environments with zfs being a killer feature in solaris 05:21:58 kerneldove21: iirc pkg -r sandboxes itself to the root these days, it wouldn't have access to system cache 05:22:28 don't quote me on that 05:25:04 We ran some stats to compare running just a pair of (very expensive at that time) SSDs for postgresql servers to a pair of "enterprise" 7200 RPM SATA drives, but backed with a pair of small Intel 320 SSDs as ZIL/L2ARC and that's when we bought in fully. 05:25:45 The ZIL basically let us *safely* cache atomic writes at SSD speed instead of HD speed is the most basic way to explain it. 05:25:50 swap && zfs is a hairy thing to me but aside from that zfs is gold 05:25:59 So a filesystem saved us a shitload of money. 05:26:55 I still don't put swap on zfs, I imagine it works now, but I still partition the same - gpt w/boot - swap - zfs (or add in EFI if you're doing that) 05:27:40 ya i don't use swap unless i'm running single disk zfs 05:28:19 I think part of what swayed us was that lots of people with influence in the PostgreSQL community were banging on it immediately, and there were also people running PG on Solaris back then, so they came in with knowledge. 05:28:57 since it's late night, some #social-ish material: https://imgur.com/a/Il89ch4 05:29:20 unpacking and finding 90's things... 05:30:31 Walnut Creek, nastolgia 05:47:40 so instead of running pkg within a jail, and running pkg ON a jail, i change pkg bootstrap -f to pkg -r /zroot/jails/myjail bootstrap -f? 12:05:38 kenichi: you cant ping something which you do not have access to. 12:05:43 it would eliminate the point of ICMP 12:06:39 kenichi: as for pkg installation on airgapped containers, you can proxy the pkg repository using nginx on the host, and then you use the nginx on the host to install ports 12:06:53 someone spoke about this recently on XMPP 12:07:14 sorry I meant to ping kerneldove not kenichi I am so sorry... 12:07:21 oh wait kerneldove isn't even in the channel 12:07:26 * polarian facepalms 15:35:37 question, how many people here would refuse to attend an event if it was branded under FSF(E)? Would you attend an event if it was simply sponsored/supported by FSF(E)? 15:36:19 I am finding it difficult to mix FOSS circles (FSF(E) endorsed) with BSD, because well... BSD folks tend to hate FSF(E) 15:37:03 intentionally keeping this out of the ML, as I dont want drama around it, I just want an honest response from the community without archives 16:10:02 polarian: There's a huge difference between hating the FSF as an entity (which I kinda do because they're so busy protecting Stallman), and FSF-endorsed stuff. 16:10:53 Free Software is great, happy to take your money and tell you as an entity to go pound sand. (If grants require FSF influence, that's money with ropes, not strings) 16:38:37 wavefunction: tl;dr I have an offer from FSFE I am turning down 16:38:54 they want the branding for a series of meetups I am planning in London 16:39:22 however its targetted at FOSS entirely, incl BSD 16:39:50 last time I helped organise a FOSS meetup it was sponsored by FSF and BSD people got a little... yk... 16:40:05 I know FSFE is a lot more mild than the FSF so probably wouldnt be as controversial, but still 16:40:25 I will be running a meetup on 8th and I will let them take the branding for it 16:40:45 but in the future I ideally want my own branding and for it to be across many groups (BSD, XMPP, FOSS) 16:41:14 im not even looking for funding, all I wanted from the FSFE was advertisement, which they can do for free. Plus I donated to them :) 16:42:19 I was originally looking to make a BUG (BSD User Group) but FOSS in the UK is in a bad place right now (little to no functional linux user groups, hackerspaces are actually makerspaces and are pretty hostile to free software in some cases), so I have pivoting to combine and run a joint effort for FOSS+BSD+XMPP 16:42:42 but I cant combine 3 different interests together if I then brand it as a FSFE event, can I? 16:43:24 I want it to be flexible, I dont want to be locked into a name or into a organisation which is advertising (or potentially funding) it 16:43:46 anyways, I need to get the whole FDE stuff sorted because one of the servers which I want to use for it needs it done :) 16:43:47 so instead of running pkg within a jail, i'm switching to running pkg ON a jail, and that means i change jexec -l myjail /bin/sh -c "pkg bootstrap -f | cat" to pkg -r /zroot/jails/myjail bootstrap -f | cat right? 16:44:24 kerneldove: yes that *could* work 16:44:43 but you wont be able to bootstrap pkg without network access in the first place 16:44:53 you can copy /usr/ports into the jail (or mount it as a nullfs) 16:44:59 and then make install the port 16:45:06 network access where? the jail host has network access, the jail shouldn't 16:45:12 yes 16:45:20 WHERE 16:45:27 to bootstrap the jail you need network access, your command is jexec the boostrap inside the jail 16:45:41 "pkg boostrap -f | cat" is ran within the jail 16:45:49 pkg bootstrap requires network access 16:45:49 uh ya 16:45:53 i didn't ask that 16:46:01 then I am not sure what you are asking/ 16:46:10 i said that's the current command. i want to change it to run pkg -r 16:46:12 so instead of running pkg within a jail, i'm switching to running pkg ON a jail, and that means i change jexec -l myjail /bin/sh -c "pkg bootstrap -f | cat" to pkg -r /zroot/jails/myjail bootstrap -f | cat right? 16:46:16 read the whole question pls 16:46:33 oh right 16:46:54 no you dont need to boostrap the jail then 16:47:06 afaik you can just use the -r flag with pkg on the host, and it will install the files into the directory 16:47:10 I think! 16:47:20 you will need to test it 16:47:50 eg try 16:48:04 pkg -r /zroot/jails/myjail install cowsay 16:49:12 then run cowsay within the jail 16:49:16 if it works as expected, it should work! 17:05:12 so is there a freebsd dev willing to help me with debugging stage 1 loader to find out why its either ignoring loader.env or there is some bug in it? 17:05:30 im not giving up on this :) 17:07:29 sorry, dealing with ports tree things 17:24:57 ah yes that fuck up, one of 3 in 48 hours xD 17:25:31 seems like hell quite frankly, someone should buy ya'll a coffee (or a beer to drown out the suffering) 17:33:58 polarian: i'm not a dev, but i read part of the previous conversation about this. my question is, would it solve your problem if you use gptboot instead of gptzfsboot? or does this also present the same hard-coded value? 17:35:36 jmnbtslsQE: gptboot is for ufs afaik 17:35:38 but no 17:36:13 this is stage 1, and the issue lies with potentially either the parsing of the loader.env, or a bug within the stage 1 loader 17:36:28 that is what I need to debug, but I dont know how to do this, and I will have to wait for a dev to become available to help mentor :p 17:37:22 OK, i just thought that if gptboot had the value you wanted, you could put your kernel in a ufs partition then mountroot from a separate zfs-on-root partition 17:37:32 polarian: i think you can move the devinit() call in loader's main() down a little bit to after we've adjusted `howto`, but i suspect this will not be enough 17:38:28 polarian: i think the bits that read loader env would also need to move above cons_probe() 17:39:08 i think both are safe to make, but it'd be worth confirming if you have the time. just don't install either as loader.efi / bootx64.efi, install as a new one and create an `efibootmgr` entry for the test loader 17:40:07 actually, maybe leave the ordering of loader.env w.r.t. `cons_probe()` alone fr the moment, it installs hooks that may just do the right thing 19:44:57 how to patch kde2 for freebsd? 19:46:35 как пропатчить кде2 под фрибсд? 19:50:20 :/ 19:50:29 how to patch kde2 for freebsd? 19:52:43 I think you might have a network problem. Your ping is 26 years. 19:56:59 lol or just lagged and now you're in the future 20:10:49 is nvidia-driver-470 still supported on freebsd? if yes, which version of freebsd is recommended? 20:11:24 if not, are there any out-of-tree patches or ports to make it work on the latest release? 20:15:53 black_mambet: yes it is still supported and it works on the current release and no patches needed 20:16:12 x11/nvidia-driver-470 20:20:50 I run FreeBSD 15.1 in different machines as both a host (bhyve/Sylve) and as a virtual machine. I noticed there was a new warning about issues in ports repository freeze, also I noticed that if I run pkg update and pkg upgrade I see a ton of things being reinstalled/upgraded. I hope this is normal if anyone has any insight let me know! FreeBSD's announcement: https://lists.freebsd.org/archives/freebsd-announce/2026-July/000294.html 20:22:36 markmcb: did you update your pkg package? 20:23:07 sorry mary751 20:31:10 I thought pkg package updates in pkg update && pkg upgrade 20:34:54 those are unrelated, the freeze is just a git-side cleanup. 20:35:31 looks like someone commited a 150mb blob, that must have broke the github mirrror and it doesn't touch the pkg at all 20:35:56 prabably the big reinstall list is just the pkgbase 20:36:17 what does, pkg which /usr/bin/uname 20:36:34 it say FreeBSD-runtime ? 22:06:49 i need to set up port forwarding through the public ip to the private ip of a jail, using pf. can i just enable gateway_enable or do i need to set net.inet.ip.forwarding = 1? or both? 22:12:39 that's all gateway_enable does iirc 22:15:40 ok i'll go through that 22:15:46 tyvm and nice scotch