-
ForeverNoob[m]
Uh how true is this statement? - "Modern ZFS is smart. When you give it a 512e drive, ZFS queries the drive, sees that the physical sector size is 4K, and automatically defaults to ashift=12. Therefore, ZFS treats 512e drives exactly like 4Kn drives anyway."
-
kerneldove
how granular should pf rule and translation configs be?
-
kerneldove
granular includes
-
dkeav
uyhhh how granular do you think they need to be
-
dkeav
frankly, doesn't matter if its PF or any other firewall, the default should be deny/block/drop
-
dkeav
the only granularity is on what you deem should be passed through
-
kerneldove
dkeav no for example if i make port forwards for ssh into jails through the jail host ip since the jails don't have a public ip, do i give each set of forward rules for a jail its own file, or put them all in 1 jail forwards file?
-
kerneldove
doesn't seem like there's a binary correct answer, but wanna know best practice
-
dnp1
spork_css: I've used both znc and soju, currently using soju
-
Macer
hm. not really sure if this is smb/zfs/freebsd related but using samba as a backup datastore for proxmox gives me this weirdness:
-
Macer
INFO: zstd: error 70 : Write error : cannot write block : Bad address
-
karolyi
hm, it seems to me that pkg 2.8.0 became significantly slower than versions before, on upgrade operations
-
karolyi
a single `pkg install -y pkg vim xxd fish` will churn the cpu for ~15 seconds when executing as an update
-
karolyi
reaching 1.2GB RES
-
Reinhilde
I would love to be a fly on the wall in that pkg implementation's address space.
-
karolyi
you'd probably see things previously unimaginable
-
bsdrobert
sounds like a tab of lsd, im down for it
-
rdr
when this baby hits 88Gflops... you're gonna see some serious sh!t
-
ForeverNoob[m]
polarian: Are you sure those are all defaults? According to geli(8) I see nothing about `-a HMAC/SHA512` being the default. Just HMAC/SHA256 being recommended. Also, seems like `-l` is dependent on `AES-XTS: 128, 256` and `AES-CBC, Camellia-CBC: 128, 192, 256` - None of which seem to document a default?
-
ForeverNoob[m]
Something I found a bit underdocumented is `geli backup`: "Backup metadata from the given provider to the given file." - Cool but uh... where can I find those? :D
-
ForeverNoob[m]
They don't appear at the $PWD, that I can tell you for sure. Adding a -v flag furthermore presented me with an ever descriptive "Done." - Wonderful! :P
-
ForeverNoob[m]
Zooming out a bit though, I wonder what the added benefit of GELI-level data integrity verification is if I'm going to use it in a ZFS mirror with weekly scrubs anyway.
-
mosaid
Hi
-
mosaid
I want to ask a question, I noticed any drive (hd, cd, usb, etc) plugged into my pc.. automount corrupts it after three or four times
-
mosaid
or just writing big thing on it (+1GB)
-
mosaid
my pc is hp compaq pro 6305 sff
-
Reinhilde
uname -a ?
-
Reinhilde
and how did you install automount
-
mosaid
FreeBSD 13.5-RELEASE FreeBSD 13.5-RELEASE releng/13.5-n259162-882b9f3f2218 GENERIC amd64
-
mosaid
installed it 4 years ago when I was using 13.2 using pkg install automount
-
mosaid
and upgraded it when I freebsd-update to 13.5 last year
-
mosaid
but this problem is so old, since I begin to use freebsd.. maybe it's a bug? if anyone uses compaq 6305 or any similar one please tell me.. Ethernet had a problem with my pc, and It was just uncompatible with specific feature in my pc (went to bios and disabled it.. then worked!)
-
mosaid
so maybe it's the same here?
-
Reinhilde
If your disk is getting corrupted, that's not normal.
-
boru
I would advise running memtest to check if your RAM is okay, just to rule it out.
-
boru
I've had bad/failing RAM cause all sorts of weird corruption over the years.
-
Reinhilde
yeah. Memtest86+ several times over.
-
ForeverNoob[m]
Seems like `geli init -B <file>` is only painless if you specify a disk without its path.
-
mosaid
memtest? I will see
-
mosaid
first time to know this, maybe my ram is bad .. I didn't change it since I installed freebsd 4 years ago
-
jmnbtslsQE
ForeverNoob[m]: the geli backups should be in /var/backups. the geli integrity is intended to be for cryptograpic integrity, to defend against malicious alteration of the on-disk encrypted data. also, the default key length has always been 128 (at least for AES-XTS), not sure if that's still true, but probably.
-
jmnbtslsQE
so the added benefit would be that you would be authenticating the disk contents even against malicious alterations of data at the zfs level (but i think this is not worth it in most cases unless you have a reason). also, i don't know what happens to reads when geli detects an integrity issue, i think reading might just fail in that area, which might be a problem for zfs (not sure)
-
ForeverNoob[m]
jmnbtslsQE: Thanks. So if I'm understanding correctly, if for some reason the GELI checksums don't match (after tampering for example), `geli attach` will warn about this and subsequently fail to decrypt drives?
-
jmnbtslsQE
i think it will report the errors in the console for geli blocks where the failures happen (and not until they happen), but i'm not sure what happens when you actually try to read data in those blocks - probably a failure, but i haven't tried. geli attach will only report this if it encounters these inconsistencies during its attach. if the errors are elsewhere, they will be encountered when you try
-
jmnbtslsQE
to read there
-
jmnbtslsQE
(read or write actually)
-
jmnbtslsQE
well, hmm, i'm not sure if it happens on a write
-
ForeverNoob[m]
Hmm I see, so I guess it can happen during attach but most likely during runtime.
-
jmnbtslsQE
yeah i think so, because attaching only touches part of the disk. honestly, i think the only time it ever happened to me was when i thought a drive had geli auth but it didn't, so geli reported errors on everything and couldn't attach. but today, i also don't use geli auth for anything
-
jmnbtslsQE
if you feel adventurous, you could create a small, 128MB empty file with `truncate`, attach it as a memory disk (mdconfig -f), set up geli encryption/auth on the md device, then `dd` a small amount of random data somewhere on the disk and see what happens, either trying to attach or after it's attached.
-
jmnbtslsQE
bottom line though, i feel like it will be safer to not use geli auth with zfs. i would be concerned about how they might interact if zfs doesn't have a chance to look at the on disk data upon authentication error. i think it's unlikely to ever happen, but if it does, maybe the interaction will make the problem worse (right when you don't need that). maybe someone who knows more about it can advise
-
jmnbtslsQE
you on it or better yet, ask one of the mailing list
-
ForeverNoob[m]
Interesting idea to test it out using (empty) files. I might try that later on in my VM.
-
ForeverNoob[m]
Apparently the ashift value is also not hardcoded at pool creation time?
man.freebsd.org/cgi/man.cgi?query=zpoolprops - "The following properties can be set at creation time and import time, and later changed with the zpool set command"
-
ForeverNoob[m]
Seems like I've been reading old docs? Wasn't this always an unmodifiable property after pool creation?
-
jmnbtslsQE
oh, interesting, didn't know that. it looks like it "is" unmodifiable but it allows it to be set for new vdevs
-
jmnbtslsQE
hen set, this property is used as the default hint value in subsequent vdev operations (add, attach and replace). Changing this value will not modify any existing vdev, not even on disk replacement; however it can be used, for instance, to replace a dying 512B sectors disk with a newer 4KiB sectors device: this will probably result in bad performance but at the same time could prevent loss of data.
-
jmnbtslsQE
(from the man)
-
ForeverNoob[m]
Huh.
-
jmnbtslsQE
i guess there are some restrictions sometimes regarding sector size when trying to add/remove disks on a pool, so maybe this helps to workaround those..can't really remember though.
-
jmnbtslsQE
s/disks/vdevs/ (maybe)
-
ForeverNoob[m]
Toshiba N300 (4TB) apparently only support 512n while my WDs (16TB) support both 512e as well as 4Kn. The bigger one will be used for stuff like my music collection and movies, while the smaller ones will be used for more "serious" stuff.
-
ForeverNoob[m]
If I should believe some of the FreeBSD forum posts, then if the stack is set to 4Kn (on physical disk, GELI sector size and ZFS pool ashift), it would result in significant performance benefit compared to 512. Since resilvering a 16TB drive can take a bit longer than a 4TB one, I'm thinking ashift=9 for the smaller pool and ashift=12 for the larger one.
-
ForeverNoob[m]
man.freebsd.org/cgi/man.cgi?query=zpool-features - "The native 64-bit arithmetic of SHA-512 provides an approximate 50% per- formance boost over SHA-256 on 64-bit hardware..."
-
ForeverNoob[m]
First time ever reading that sha512sum is faster than sha256sum.
-
kerneldove
ya me too
-
ForeverNoob[m]
Ugh, apparently zpool create can't target devices in /dev/label/ ?
-
llua
yeah it can
-
ForeverNoob[m]
llua: Then what on earth am I doing wrong?
-
ForeverNoob[m]
$ zpool create mirpool mirror /dev/label/zfs_ddisk_*.eli
-
ForeverNoob[m]
cannot use '/dev/label/zfs_ddisk_1.eli': must be a block device or regular file
-
llua
ForeverNoob[m]:
paste.rs/KmWUd
-
hernan604
ForeverNoob[m]: chek which is the device related to that label and use the device instead
-
hernan604
use gpart show -l to see labels and devices
-
hernan604
So i have this laptop with 1 disk using geli. Looks like 2 partitions are mounted using geli.
-
hernan604
nda1% nda1p1% nda1p2% nda1p3% nda1p3.eli% nda1p4% nda1p4.eli%
-
hernan604
To define a new geli passphrase, the passphrase must be set for both partitions in this case? nda1p3 and nda1p4 ?
-
ForeverNoob[m]
hernan604: I mean... if I'd wanted to use raw devices I'd just do that, but that obviously comes with its downsides.
-
ForeverNoob[m]
If you enter 1 passphrase for that disk, then I'd assume you also have to only set 1 passphrase. But as always, backup backup backup etc.
-
ForeverNoob[m]
-
ForeverNoob[m]
-
ForeverNoob[m]
> must be a full path or shorthand device name
-
ForeverNoob[m]
lolnope
-
ForeverNoob[m]
Thing is, I could have sworn this just worked not even a few years ago.
-
ForeverNoob[m]
(Even have it documented to do it in such a way)
-
llua
the second example definitely didn't work before
-
llua
i showed the shorthand device name, geoms in freebsd.
-
llua
disks in freebsd are character files, you can see that via ls's -l option, which isn't new.
-
hernan604
ForeverNoob[m]: geli init -l 256 -s 4096 /dev/gpt/${HDD_1_LABEL} /dev/gpt/${HDD_2_LABEL}
-
hernan604
geli configure -b /dev/gpt/${HDD_1_LABEL}
-
hernan604
geli configure -b /dev/gpt/${HDD_2_LABEL}
-
hernan604
geli attach /dev/gpt/${HDD_1_LABEL} /dev/gpt/${HDD_2_LABEL}
-
hernan604
zpool create $ZPOOL_NAME mirror /dev/gpt/${HDD_1_LABEL}.eli /dev/gpt/${HDD_2_LABEL}.eli
-
hernan604
zfs set mountpoint=/mnt/$ZPOOL_NAME $ZPOOL_NAME
-
hernan604
zfs list
-
ForeverNoob[m]
hernan604: GPT labels need at least 1 GPT partition present on the drive. I am intending to used entire drive instead. The glabel labels don't have this requirement.
-
ForeverNoob[m]
btw you can set mountpoint during creation time.
-
ForeverNoob[m]
llua: Apparently zpool needed elevated privileges. Whatever the case, "cannot use '/dev/label/bar0': must be a block device or regular file" as an error message for such a situation is dumb as hell.