-
Reinhilde
garrulous mode, in /usr/src/bin/ed/main.c, seems unreachable
-
izder456
today's pkg update && pkg upgrade on my arm64 host resulted in a segfaulting pkg tool, when update or upgrade are passed. i tried force reinstalling pkg with pkg-static but the problem didn't go away. what can i do?
-
izder456
i don't have x86 machines running freebsd
-
izder456
i'll try building the latest from ports. seems the binary package is one version old
-
SponiX
izder456: you still around ?
-
SponiX
At times like these, I hope the person is on ZFS root, and has a boot image snapshot created prior with bectl that they can roll back to
-
kona
Reinhilde: what is garrulous mode, i have never heard of this and it seems maybe undocumented?
-
kona
Reinhilde: I see, it is reachable with
-
kona
Reinhilde: garrulous mode is toggled with H
-
dacav
Hi. I was wondering how to access a service that is running in another jail. I realized that two jails sharing the same ip address will not see each other service via `sockstat -P tcp -l`, but I can connect anyway to localhost:port even from the jail that is not exposing it. Bug or feature?
-
Xinayder
is there a rss feed or something I can subscribe to, to know when a new patch release is available?
-
Reinhilde
so it is
-
lts
Xinayder: on the front page
freebsd.org
-
izder456
SponiX: the image i used is UFS. building the latest pkg from ports fixed my issue.
-
dch
wow, wordpress, unauthenticated WordPress REST batch route-confusion SQL injection
-
dch
-
dch
if you have a wordpress its time to patch it
-
dch
dacav: definitely feature, I assume you're using host networking for the jail.
-
dch
dacav: I would typically segment these, and use either unix domain sockets, pf rules, or (HA)proxy to allow acces
-
dch
*access
-
dch
but mostly haproxy because its so awesome
-
dch
izder456: I have a patch for this
-
dch
-
dch
izder456: and one for ports tree also
git.sr.ht/~dch/ports/commit/0ab82e4
-
dch
and if you need a pre-built one for arm64 I have that too
-
izder456
its already fixed. compiling from ports fixed my issue.
-
polarian
ForeverNoob[m]: I would need to check the src to see what the defaults are, to my knowledge the defaults.
-
polarian
looking at what the installation media used 2-3 years ago, I have a keylen of 256 which matches the current most secure, but the checksum I can't seem to see within the geli list command.
-
polarian
AES-XTS-256 is used by default though
-
polarian
I do wonder if HMAC/SHA512 is dramatically more secure than HMAC/SHA256 anyways
-
rtprio
dramatically? no
-
polarian
considering sha256 is still the standard for cryptographic verification of packages on most Linux distros
-
polarian
(the sha256sum gets signed, so if the sha256sum can be forged, it would eminate the point of a sha256sum)
-
scoobybejesus
dacav yeah, this is intended. There are other ways get to the more basic sources, but I would point you to the BastilleBSD abstraction. Their setup starts with cloning lo0 into lo1 and giving it the bastille0 name (IIRC). The default bastille create command uses bastille0. When I wanted to create a NAT/loopback jail with an unshared loopback, I
-
scoobybejesus
did a sysrc cloned_interfaces+=lo2 and a sysrc ifconfig_lo2_name="bastille1" and then in my bastille create command I put a bastille1 on the end so the jail was associated with that network, thus leaving that jail without a loopback connection to the others all on bastille0
-
dacav
scoobybejesus: thanks for the info. In my case I should have probably started directly with bastille, but now I'm not inclined to move, as I'm afraid to disrupt my (few) services
-
polarian
kevans: was reading the source code for the efi loader
-
polarian
-
polarian
I see this, maybe this is the issue?
-
polarian
wait no because it should still parse the config?
-
polarian
kerneldove: reading the sourc ecode this is already the case, on line 1315 in main.c we have the setenv in the bpa paste, and then the line after we have the parser.
-
polarian
this parser seems like it is meant to detect serial interfaces exposed via acpi
-
kerneldove
polarian eh?
-
polarian
however kevans also said unless the firmware redirects the output to serial, this will not work
-
polarian
that is why loader.env is useful
-
polarian
(to my knowledge)
-
polarian
then cons_probe is called, then some low level init, then the devinit()
-
polarian
so I am not quite sure what im looking for
-
polarian
ahhh I was meant to move devinit() down
-
polarian
-
polarian
I bet it is something in here
-
polarian
I dont know what the variables mean so the logic doesnt make sense, but this comes AFTER reading the config, and it would make sense if this overrides the loader.env config
-
polarian
alright I have moved devinit below that, and jsut before the boot_howto
-
kerneldove
for jails that don't have a public ip i guess that means you need privileged access to the jail host so you can run pkg and target the jail to install software?
-
dvl
Commit processing has resumed on all FreshPorts hosts. It will take a while for prod to catch up. Probably by 22:00 UTC today.
FreshPorts/freshports #668
-
polarian
ugh I havent a clew what the fuck I am doing
-
polarian
kerneldove: no you install it through the host by setting the basedir to the jail directory?
-
polarian
it seems to work according to the man page, in practice? dunno
-
polarian
happy testing!!!
-
polarian
meanwhile I haven't the faintest clue what to do
-
kerneldove
i'm setting up squid inside a jail and i read i gotta do something so it doesn't conflict with other squid instances in other jails? doesn't that mean jails aren't isolating/securing their domain?
-
kerneldove
i thought anything ran in a jail is segregated from anything else
-
polarian
kerneldove: it is
-
polarian
its a more powerful chrootr
-
polarian
chroot*
-
kerneldove
-
kerneldove
that basically says jail doesn't work to segregate?
-
kerneldove
"Obviously, while a bit out-of-scope here, the fact that Squid's SHM objects can be freely accessed from any jail can constitute a security issue in its own right and must not be ignored..."
-
polarian
-
polarian
I cant even f*cking build the loader, how tf is string.h not found!!
-
kerneldove
oh maybe it's been fixed
-
polarian
I have no clue how string.h cant be found
-
polarian
hmmm, can I only compile the entire src tree? I am so confused.
-
rtprio
why
-
rtprio
and also why aren't you in /usr/src