-
s2r
I fixed it temporarily by adding an entry in hosts to pkg0.nyi.freeebsd.org IP for pkg.freebsd.org
-
spork_css_
Just wanted to check, it's not possible to ktrace from a host to a jail with jexec, right? Especially if the jail is a much older release...
-
kerneldove
so i pkg install squid, no problem. but pkg -r <jail root> install squid and it errors "install: nknown group squid" for /var/squid, /var/squid/cache, etc
-
kerneldove
does pkg -r have bug or? 14.4
-
spork_css_
what about "pkg -j yourjail install squid"
-
spork_css_
I don't think just changing the root is going to make it aware of in-jail users.
-
spork_css_
see the "pkg" manpage and the "-j" option.
-
kerneldove
lemme try
-
kerneldove
fuck
-
kerneldove
spork_css_ did you not see me say 14.4?
-
kerneldove
-j is 15 only
-
spork_css_
yeah, I just feel like it's been in there forever. I tested on an old 13.x host, so.... no idea.
-
spork_css_
all I know is from my reading of the manpage,
-
spork_css_
-r would not work
-
kerneldove
-
kerneldove
-j isn't in there
-
yakubin
pkg supports -j since forever.
-
spork_css_
again, can't comment on that
-
spork_css_
WFM
-
spork_css_
just type "man pkg" and then "/" and then "-j".
-
spork_css_
-
mason
kerneldove: Run "pkg" and see what it offers for options.
-
kerneldove
hm from command line pkg shows -j is an option. dunno what's up with man page site then
-
mason
Man page on an installed 14.4 system will also show the option.
-
mason
kerneldove: Oh, you selected section... 0? It's in section 8.
-
kerneldove
when i run sudo pkg install cowsay, works. when i run sudo pkg -j myjail install cowsay, it gives permission denied and fails with error updating repositories. why?
-
kerneldove
i just used whatever was default selected
-
mason
kerneldove: I tend to chroot in instead, as jails can have some funny limitations. I've never dug in. I just pivot to something fairly simple that works.
-
kerneldove
it must be trying to run the pkg from within the jail, and it's hitting the firewall
-
kerneldove
that's a dumb way of running because not all jails have public network
-
kerneldove
that's why i was using pkg -r
-
kerneldove
but so then pkg -r fails with other reasons, ffs what a cluster
-
mason
Yeah, everything's a bunch of tradeoffs. :/
-
kerneldove
well how the f have jails not matured to where you can properly install packages in them from the host system?
-
kerneldove
20 year old tech that has these basic gaps in lifecycle? embarassing tbh
-
mason
kerneldove: Dunno. I chroot in. Works reliably.
-
kerneldove
what's that look like?
-
mason
Shut the jail down, chroot in, install packages.
-
mason
It's probably inelegant, but I'll take inelegant if it's boring and incident-free.
-
mason
As I've noted previously, I'm sliding towards ever-simpler lately.
-
kerneldove
ya especially with so much sht half baked here
-
mason
Oh, I wouldn't say that. FreeBSD is very reliable in a number of ways that other systems can't touch.
-
kerneldove
no offense but don't care what you'd say or not. the issue i just ran into proves what i said
-
spork_css_
OK, well for starters, if you want the manpage for the system you're currently on, you run "man" on that system and you will have the correct manpage.
-
spork_css_
It's much less work to type "man pkg" than to go to a browser and google it.
-
spork_css_
and many commands will just spit out a bunch of options if run with no options. This isn't poor OS design, this is just how unix is.
-
spork_css_
maybe the "-c" option will work for your setup, not sure. But trying to use a system (pkg) that relies on the internet to fetch packages on something without internet is a choice and an edge case, IMO.
-
kerneldove
spork_css_ cool so how to install pkgs into a jail that doesn't have networking? because -r and -j ain't it
-
kerneldove
should be able to install pkg into a jail from host system
-
spork_css_
no idea, I've never had a need to do it.
-
kerneldove
so every jail you use has inet?
-
mason
kerneldove: Setting up NAT for them so they can reach out isn't a terrible idea.
-
spork_css_
yes
-
kerneldove
lol nice security model bro
-
spork_css_
do you want help or do you want to yell at people that aren't getting paid to do this?
-
kerneldove
yell? emotional much?
-
mason
It's a reasonable characterization.
-
spork_css_
OK, insult people, how's that?
-
spork_css_
(and insulting people because you can't figure something out is kind of... emotional?)
-
kerneldove
stop obsessing
-
spork_css_
?
-
mason
kerneldove: It sounds like a reasonable time to take a break. You're not making yourself happier. Maybe write up a bug with details of the failures you see with pkg -j and/or pkg -r when you come back, so something productive comes out of it.
-
Reinhilde
`less` has a poorly-discoverable interface
-
mason
Reinhilde: If you try --help it's pretty good, but -h could be more helpful.
-
spork_css_
decent manpage as well (and thankfully unlike most linux distros, typing "more" doesn't give you an ancient "more")
-
spork_css_
sad state of affairs here, one of my old junker PCs just freezes midway through the BIOS device iteration when a bootable USB key is in there that it doesn't like (which includes all FreeBSD memstick images)...
-
spork_css_
no BIOS updates, some hints in old forums that maybe gparted can whack it into shape, but it does have an optical drive...
-
spork_css_
-
mason
I have one of those, that needs two plugs to get enough power to burn.
-
spork_css_
yeah, honestly kind of shocked that current macos a) recognized it as a burner b) still has code to burn discs
-
kerneldove
-c and -j both fail trying to install pkg to a jail that doesn't have inet
-
kerneldove
and -r leaks shit across the jail boundary into the host and installs fail (squid)
-
kerneldove
junk
-
mason
kerneldove: Wait, if these don't have Internet access, how are you supplying packages?
-
kerneldove
host has inet, jails don't
-
mason
Mm. All the tools assume you have internet access. I'd probably set up an on-disk repository, maybe one that you nullmount in, and set up your repo config as needed to accomodate that.
-
mason
Like, set up the config per-jail, so the jail expects packages in a particular directory.
-
mason
That can be a read-only mount from the host.
-
mason
The pkg tools expect networking.
-
mason
That shot past me in the earlier discussion.
-
mason
Use pkg fetch on the host to get the things. I haven't done this particular variation, so I'm not sure what pkg wants on the repo side.
-
mason
You're going to need to treat these as being air-gapped in various ways.
-
mason
Frankly I'd set up NAT so they can reach out. There's not a ton you can do on a system with no networking nowadays, so it's unusual to have something with no network.
-
mns
kerneldove: how have you setup your jails? I have jails but do not have pkg setup inside of the jails. I use 'pkg -r' every day on a 14.4R system everyday, no issues.
-
nesta
:o
-
mns
kerneldove: for j in /usr/local/jails/containers/*; do printf "\nUpgrading jail: ${j##*/}\n=========================\n"; pkg -r ${j} update && pkg -r ${j} upgrade; done
-
mns
I run that every day
-
mns
no issues.
-
spork_css_
depends on what you're installing - in kerneldove's case, he's installing squid, and that needs to add a user.
-
kerneldove
mns try installing squid to a jail with pkg -r and tell me if it gives error "install: unknown group squid"?
-
kerneldove
ya
-
spork_css_
I suspect that fails because it's not chrooted into the jail
-
mns
spork_css_: I install lighttpd, and that needs a user as well, as I recall.
-
mns
kerneldove: let me try that and see what happens
-
spork_css_
mns: "-r" just sets an alternate root, "-j" and "-c" both chroot into the jail.
-
spork_css_
If your jail had the lighty user in there before doing the upgrades, I'd guess that might work? I don't know.
-
spork_css_
I don't have a single jail that doesn't at least have internet access via NAT
-
spork_css_
anyhow, off to walk a dog, good luck, all
-
mason
o/
-
mns
spork_css_, kerneldove: I was able to install squid using the command that kerneldove provided, no issue. It went ahead and created the squid user inside my jail.
-
kerneldove
wtf
-
kerneldove
does jail have internet? using pkg -r from host?
-
kerneldove
what freebsd version?
-
mns
kerneldove: doing it from host: sudo pkg -r /usr/local/jails/containers/lighty install squid
-
mns
kerneldove: 14.4
-
kerneldove
hm same as me
-
kerneldove
and your extracting squid line wasn't followed by any install: unknown group squid stuff?
-
mns
nope
-
kerneldove
host running zfs?
-
mns
yup
-
kerneldove
not sure if it'd matter but is it a thick jail with its own base?
-
mns
kerneldove: I am running a thinjail but I don't think that should matter in this scenario
-
mns
how do you have your jail setup? which directory are you pointing to?
-
kerneldove
i'm running the pkg -r /jail/jails/myjail/ install squid during bsdinstall, not after the post-install reboot, not sure if that matters
-
kerneldove
jail fs was created with zfs reate -o mountpoint=/jail zroot/jail
-
kerneldove
and ln -s /mnt/jail /jail before that
-
mns
what's under /jail/jails/myjail, is it usr/, etc/, dev/, etc. ?
-
kerneldove
yep
-
mns
it might be because of bsdinstall, but I can't think of a reason why.
-
mns
I have networking in the jail, but I do not have pkg setup inside the jail. Everything in terms of package management gets done from the host.
-
mns
kerneldove: when you run your pkg command, did it also say that perl would be installed?
-
kerneldove
yep
-
mns
What's the error you get?
-
kerneldove
got a working pastie site i can use?
-
mason
bpaste.net works
-
kerneldove
-
mns
let me check mine again
-
mns
never mind, I got the same messages as you did. I was checking if the user got created inside the jail, which it did.
-
mns
I didn't look at the messages from pkg properly as it prints out a bunch of messages after the install
-
kerneldove
ok now we're getting somewhere. so don't you think freebsd should have a way to install pkgs into a jail without the jail itself needing to do the networking?
-
mns
I don't think its' the networking in this case. The package got installed, just that the post-install setup doesn't get done properly. /var/squid and the other directories get created, but when the ownership is supposed to be given, the post-install script is using the host's /etc/passwd instead of the one rooted at /jail/jails/myjail. I think a bug report would be good to fix it.
-
kerneldove
that wasn't my point. my point was that there's no way to propertly install pkgs to a jail, from host
-
kerneldove
(without the jail having internet, which is an unnecessary security hole)
-
mason
kerneldove: Did you see where I mentioned null mounting a repository in from the host?
-
mns
-
mns
Use -c instead of -r
-
kerneldove
mns tried -c, doesn't work. fails with transient dns resolution error or smth
-
kerneldove
mason no but that's a dirty hack
-
mason
kerneldove: You're talking about security, but you've evidently never run airgapped systems.
-
mns
kerneldove: look at my output, I got no such errors, the directories all have the right permissions and ownership, the user gets created, all inside the jail, but done from the host.
-
kerneldove
i'll try again but i know it didn't work for me
-
mns
kerneldove: I deleted the previous install of the package in the jail, removed both squid and perl, and then did a fresh install from the host.
-
mns
As you can see in my paste above, no messages. If you do a 'ls -l /jail/jails/myjail/var/' squid should have owner:group of 100:100 (because you're looking at it from the host, which doesn't know about squid user as that is inside the jail)
-
mns
which I wonder what the difference between -r and -c is supposed to be.
-
kerneldove
ya so it says transient resolver failure
-
kerneldove
error updating repositories
-
mns
that means you're inside the jail not on the host
-
mns
is my guess.
-
kevans
presumably you didn't drop a resolv.conf inside?
-
kerneldove
kevans no didn't put resolv.conf in jail since it doesn't have inet
-
mns
I do have a resolv.conf in there. hmmm I'll have to find the documentation on my setup.
-
kerneldove
with an ip or?
-
kerneldove
i'm guessing you're not running a full unbound instance in a jail without inet?
-
kerneldove
mns
-
mns
no kerneldove, I do have networking in the thinjail
-
kerneldove
thought you said no inet in jail
-
mns
I started using -r because I used to have issues with the networking when I was first setting up jails. I never stopped even after switching to basic jails based on the handbook instructions
-
mns
I said I don't have pkg working inside the jail
-
kerneldove
kevans that worked, but why?
-
kerneldove
i appreciate the tip but nowi
-
kerneldove
m even more confused about freebsd
-
mns
what was the tip kerneldove, to put a resolve.conf inside the jail?
-
kerneldove
ya
-
mns
-
kerneldove
?
-
mns
from inside the jail my pkg doesn't have network connections.
-
mns
and I get the same transient error you get, when inside the jail.
-
hernan604
So, i got 2 geli disks, with "configure -b" so the passphrase is requested during boot. However, during boot the follwing error shows for the 2 disks: "cannot import no such pool or dataset destroy and re-create the pool from a backup source"
-
hernan604
however, after the boot, i am able to manually "geli attach" the disks, then import the pools
-
hernan604
what could be the problem ?
-
laidback01
hey, not like it matters much... I used Gnome on FreeBSD as a desktop and have had a problem for a while since I switched to an Nvidia Card. It no longer blanks my monitors when I go to sleep. I don't like that. so I worked with Claude to get a simple script that I could tie to a key combo - so I can just use DPMS to power off the monitors before sleeping.
-
laidback01
-
kerneldove
is the pkg provides update site down?
-
kerneldove
sudo pkg provides -u is stalling for me
-
laidback01
pkg provides -u is failing for me as well.
-
laidback01
timing out
-
kerneldove
hm might need to remove it as a standard system install
-
kerneldove
it's handy but can't have system deploys held up on downtime
-
laidback01
osorio.me is up, but
pkg-provides.osorio.me is down.
-
kerneldove
should be hosted on pkg's infra
-
laidback01
i've never used it, I typically use locate db but that's not quite an analog to that setup.
-
Wyler
So I have an old laptop with Atom processor and 2Gb ram that is stuck at FreeBSD v14.4 (i386) so is there a method to bring it up to latest now that all i386 has been removed from distro ?? Or am I just stuck at FreeBSD v14.4 ???
-
Reinhilde
quite honestly, you're gonna want to switch OSes at this point
-
kerneldove
Wyler i think 14.5 is coming out so you could stay with fbsd through that, then ya i'd get rid of laptop and get something newer
-
kerneldove
i have an old white macbook core 2 duo and i tried linux but at a certain point hardware is just too old
-
nsoci
/help w
-
nsoci
/part #freebsd
-
nsoci
/part #freebsd