00:54:19 garrulous mode, in /usr/src/bin/ed/main.c, seems unreachable 02:37:42 today's pkg update && pkg upgrade on my arm64 host resulted in a segfaulting pkg tool, when update or upgrade are passed. i tried force reinstalling pkg with pkg-static but the problem didn't go away. what can i do? 02:37:53 i don't have x86 machines running freebsd 02:48:03 i'll try building the latest from ports. seems the binary package is one version old 04:47:11 izder456: you still around ? 04:48:02 At times like these, I hope the person is on ZFS root, and has a boot image snapshot created prior with bectl that they can roll back to 08:22:45 Reinhilde: what is garrulous mode, i have never heard of this and it seems maybe undocumented? 08:25:00 Reinhilde: I see, it is reachable with 08:25:15 Reinhilde: garrulous mode is toggled with H 12:49:59 Hi. I was wondering how to access a service that is running in another jail. I realized that two jails sharing the same ip address will not see each other service via `sockstat -P tcp -l`, but I can connect anyway to localhost:port even from the jail that is not exposing it. Bug or feature? 12:50:04 is there a rss feed or something I can subscribe to, to know when a new patch release is available? 13:23:38 so it is 14:01:43 Xinayder: on the front page https://www.freebsd.org/ 14:16:06 SponiX: the image i used is UFS. building the latest pkg from ports fixed my issue. 14:47:05 wow, wordpress, unauthenticated WordPress REST batch route-confusion SQL injection 14:47:15 https://github.com/Icex0/wp2shell-poc 14:47:25 if you have a wordpress its time to patch it 14:48:06 dacav: definitely feature, I assume you're using host networking for the jail. 14:48:51 dacav: I would typically segment these, and use either unix domain sockets, pf rules, or (HA)proxy to allow acces 14:48:55 *access 14:49:03 but mostly haproxy because its so awesome 15:12:48 izder456: I have a patch for this 15:13:10 izder456: https://github.com/freebsd/pkg/pull/2727 15:13:57 izder456: and one for ports tree also https://git.sr.ht/~dch/ports/commit/0ab82e4 15:14:21 and if you need a pre-built one for arm64 I have that too 15:42:11 its already fixed. compiling from ports fixed my issue. 16:06:01 ForeverNoob[m]: I would need to check the src to see what the defaults are, to my knowledge the defaults. 16:06:39 looking at what the installation media used 2-3 years ago, I have a keylen of 256 which matches the current most secure, but the checksum I can't seem to see within the geli list command. 16:06:49 AES-XTS-256 is used by default though 16:07:13 I do wonder if HMAC/SHA512 is dramatically more secure than HMAC/SHA256 anyways 16:07:33 dramatically? no 16:07:35 considering sha256 is still the standard for cryptographic verification of packages on most Linux distros 16:07:54 (the sha256sum gets signed, so if the sha256sum can be forged, it would eminate the point of a sha256sum) 19:34:05 dacav yeah, this is intended. There are other ways get to the more basic sources, but I would point you to the BastilleBSD abstraction. Their setup starts with cloning lo0 into lo1 and giving it the bastille0 name (IIRC). The default bastille create command uses bastille0. When I wanted to create a NAT/loopback jail with an unshared loopback, I 19:34:05 did a sysrc cloned_interfaces+=lo2 and a sysrc ifconfig_lo2_name="bastille1" and then in my bastille create command I put a bastille1 on the end so the jail was associated with that network, thus leaving that jail without a loopback connection to the others all on bastille0 19:48:48 scoobybejesus: thanks for the info. In my case I should have probably started directly with bastille, but now I'm not inclined to move, as I'm afraid to disrupt my (few) services 19:59:22 kevans: was reading the source code for the efi loader 19:59:24 https://bpa.st/VGIA 19:59:28 I see this, maybe this is the issue? 19:59:38 wait no because it should still parse the config? 20:01:31 kerneldove: reading the sourc ecode this is already the case, on line 1315 in main.c we have the setenv in the bpa paste, and then the line after we have the parser. 20:01:50 this parser seems like it is meant to detect serial interfaces exposed via acpi 20:02:04 polarian eh? 20:03:12 however kevans also said unless the firmware redirects the output to serial, this will not work 20:03:18 that is why loader.env is useful 20:03:20 (to my knowledge) 20:04:12 then cons_probe is called, then some low level init, then the devinit() 20:04:17 so I am not quite sure what im looking for 20:06:10 ahhh I was meant to move devinit() down 20:07:56 https://bpa.st/6RRQ 20:08:00 I bet it is something in here 20:08:21 I dont know what the variables mean so the logic doesnt make sense, but this comes AFTER reading the config, and it would make sense if this overrides the loader.env config 20:10:38 alright I have moved devinit below that, and jsut before the boot_howto 20:30:24 for jails that don't have a public ip i guess that means you need privileged access to the jail host so you can run pkg and target the jail to install software? 20:30:26 Commit processing has resumed on all FreshPorts hosts. It will take a while for prod to catch up. Probably by 22:00 UTC today. https://github.com/FreshPorts/freshports/issues/668 20:36:26 ugh I havent a clew what the fuck I am doing 20:36:42 kerneldove: no you install it through the host by setting the basedir to the jail directory? 20:36:49 it seems to work according to the man page, in practice? dunno 20:36:55 happy testing!!! 20:46:33 meanwhile I haven't the faintest clue what to do 20:48:33 i'm setting up squid inside a jail and i read i gotta do something so it doesn't conflict with other squid instances in other jails? doesn't that mean jails aren't isolating/securing their domain? 20:48:45 i thought anything ran in a jail is segregated from anything else 20:49:04 kerneldove: it is 20:49:24 its a more powerful chrootr 20:49:26 chroot* 20:51:28 https://unix.stackexchange.com/a/269269 20:51:45 that basically says jail doesn't work to segregate? 20:52:08 "Obviously, while a bit out-of-scope here, the fact that Squid's SHM objects can be freely accessed from any jail can constitute a security issue in its own right and must not be ignored..." 20:53:32 https://bpa.st/R26A 20:53:41 I cant even f*cking build the loader, how tf is string.h not found!! 20:53:50 oh maybe it's been fixed 21:05:37 I have no clue how string.h cant be found 21:07:58 hmmm, can I only compile the entire src tree? I am so confused. 21:25:43 why 21:26:29 and also why aren't you in /usr/src