#freebsd

382 posts · Last used 27m

TIL you can nullfs mount a #ZFS snapshot. This could be particularly useful for making sure jail root filesystems are absolutely 100% immutable: hbsd-current-02[shawn]:/home/shawn $ uname -a FreeBSD hbsd-current-02 16.0-CURRENT FreeBSD 16.0-CURRENT #0 hardened/current/master-n196551-d4411c7c9cc3-dirty: Wed Sep 16 19:42:46 UTC 2026 shawn@hbsd-current-02:/usr/obj/usr/src/amd64.amd64/sys/HARDENEDBSD amd64 hbsd-current-02[shawn]:/home/shawn $ sudo mount -t nullfs /usr/ports/.zfs/snapshot/2026-07-24_before /mnt $ ls -l /usr/ports | head -n 5 total 3215 -rw-r--r-- 1 shawn shawn 149175 Oct 7 00:59 CHANGES -rw-r--r-- 1 shawn shawn 727 Apr 26 18:13 CONTRIBUTING.md -rw-r--r-- 1 shawn shawn 1412 Apr 26 18:13 COPYRIGHT -rw-r--r-- 1 shawn shawn 13370 Oct 1 18:46 GIDs hbsd-current-02[shawn]:/home/shawn $ mount | grep nullfs /usr/ports/.zfs/snapshot/2026-07-24_before on /mnt (nullfs, local) hbsd-current-02[shawn]:/home/shawn $ touch /mnt/blah touch: /mnt/blah: Read-only file system hbsd-current-02[shawn]:/home/shawn (1) $ echo ohai > /mnt/README zsh: read-only file system: /mnt/README #FreeBSD #HardenedBSD #infosec #OpenZFS
1
0
0
0
@FreeBSDFoundation@mastodon.social I wrote something. Consider #FreeBSD for your next big project in the cloud. https://freebsdfoundation.org/our-work/journal/browser-based-edition/production-deployments/cloud-operations-using-freebsd-compute/ RE: https://mastodon.social/@FreeBSDFoundation/117394092954747546
Quoting
The Q3 2026 issue of the FreeBSD Journal is now available. This edition explores Production Deployments, with articles covering home lab consolidation, cloud operations using FreeBSD Compute, USB in user space, auditable credential-exposure checks, and more. Inside, you'll also find the Foundation Letter, a EuroBSDCon trip report, and the latest 2026 events calendar. 🔗 Read it here: https://freebsdfoundation.org/our-work/journal/browser-based-edition/production-deployments/ #FreeBSD #FreeBSDJournal #OpenSource #SysAdmin
Open quoted post
0
0
1
0
The Q3 2026 issue of the FreeBSD Journal is now available. This edition explores Production Deployments, with articles covering home lab consolidation, cloud operations using FreeBSD Compute, USB in user space, auditable credential-exposure checks, and more. Inside, you'll also find the Foundation Letter, a EuroBSDCon trip report, and the latest 2026 events calendar. 🔗 Read it here: https://freebsdfoundation.org/our-work/journal/browser-based-edition/production-deployments/ #FreeBSD #FreeBSDJournal #OpenSource #SysAdmin
9
0
5
1
Boosted by @fedicat@pc.cafe
Thank you, @dch@bsd.network One of the peculiarities of littleFedi is that it was developed and tested first on the BSDs, then on illumos, and only later on Linux. The first public instance, my own @stefano@rpi0w.stefanomarinelli.it account, runs on a Raspberry Pi Zero W with NetBSD. I don’t think many social platforms have started out on NetBSD in recent years. #NetBSD #FreeBSD #littleFedi #Fediverse
Quoting
I want to publicly thank @dch@bsd.network The FreeBSD port of littleFedi was already ready at release time, and it’s really well done. One of the peculiarities of littleFedi is that it was developed and tested first on the BSDs, then on illumos, and only later on Linux. The first public instance, my own @stefano@rpi0w.stefanomarinelli.it account, runs on a Raspberry Pi Zero W with NetBSD. I don’t think many social platforms have started out on NetBSD in recent years. #ThankYou #RunBSD #NetBSD #FreeBSD #OpenBSD #illumos #OwnYourData #Fediverse #littleFedi
Open quoted post
0
0
1
0
I want to publicly thank @dch@bsd.network The FreeBSD port of littleFedi was already ready at release time, and it’s really well done. One of the peculiarities of littleFedi is that it was developed and tested first on the BSDs, then on illumos, and only later on Linux. The first public instance, my own @stefano@rpi0w.stefanomarinelli.it account, runs on a Raspberry Pi Zero W with NetBSD. I don’t think many social platforms have started out on NetBSD in recent years. #ThankYou #RunBSD #NetBSD #FreeBSD #OpenBSD #illumos #OwnYourData #Fediverse #littleFedi
58
0
31
1
Replying to
@jaypatelani@bsd.network I don't want to spoil the #retrocomputing fun, but for those new to the BSDs who do not have the context and might come away thinking that they should move from GUID partitioning, or even MBR-style partitioning with LBAs, to disk labels: The "BSD disklabel" is a partitioning scheme from 1988 that can destroy your GUID partitioning or boot loader if accidentally mis-used. #NetBSD, #OpenBSD, and #FreeBSD haven't agreed on disklabel partition types since IBM's JFS2. They don't agree on what the types for ZFS or HAMMER2 partitions are, for example. It is 32-bit, occasionally 16-bit, in some fields, and mostly has the old 2TiB size limits that the GUID system overcame with 64-bit addressing at the turn of this century. And the on-disk data structures are no longer even compatible as of OpenBSD discontinuing 'v0' in 2025 (with a somewhat optimistic note in the version control history that no-one has written that to disc since 2007). #disklabel #bsdlabel
4
3
1
0
Replying to
@phlash@mastodon.me.uk I just gave the world a re-write of the boot chapter of the #FreeBSD Handbook that does away with bsdlabel and (finally!) uses gpart. https://mastodonapp.uk/@JdeBP/117326574782531292 I wonder whether we can get the FreeBSD Handbook people to embrace this. GEOM was a big new thing in FreeBSD in 2003. I see that the #NetBSD Guide suffers from the same disklabel-centrism, when it is closing in on 2 decades of having the gpt command. @jaypatelani@bsd.network#geom
Quoting
I actually read the #FreeBSD Handbook's chapter on how FreeBSD bootstraps. It's stuck in 2010. I'm not kidding. There's stuff in there that changed in the FreeBSD 7.3 release notes. FreeBSD can boot on UEFI firmware nowadays, and directly from ZFS datasets. There's a gpart bootstrap command, and syscons does not use bright white for kernel messages any more. In the meantime, the Handbook is telling people how to accidentally destroy their MBR or GUID partition tables with bsdlabel. Do you think that we can get the Handbook people to catch up with the actual operating system, that is 16 years ahead? (-: https://github.com/jdebp/freebsd-doc/blob/main/documentation/content/en/books/handbook/boot/_index.adoc #UEFI #ZFS
Open quoted post
8
3
6
0
I actually read the #FreeBSD Handbook's chapter on how FreeBSD bootstraps. It's stuck in 2010. I'm not kidding. There's stuff in there that changed in the FreeBSD 7.3 release notes. FreeBSD can boot on UEFI firmware nowadays, and directly from ZFS datasets. There's a gpart bootstrap command, and syscons does not use bright white for kernel messages any more. In the meantime, the Handbook is telling people how to accidentally destroy their MBR or GUID partition tables with bsdlabel. Do you think that we can get the Handbook people to catch up with the actual operating system, that is 16 years ahead? (-: https://github.com/jdebp/freebsd-doc/blob/main/documentation/content/en/books/handbook/boot/_index.adoc #UEFI #ZFS
6
1
2
1
Replying to
@vmcall@infosec.exchange @hweissi@infosec.exchange @notbobbytables@infosec.exchange @lavados@infosec.exchange @isec_tugraz@infosec.exchange Unless someone beats me to it, I'm hoping to test on #FreeBSD now that it, too, has a native inotify implementation (only recently implemented). It'll take me a couple weeks to get to this, though, as I have a few other higher-priority tasks to clear off my plate.
0
1
0
0
Replying to

With host-side SEV support, multi-core virtualization, and networking now functional in bhyve, the team is working on upstreaming the code to the main FreeBSD repository.

Future milestones include upgrading to newer SEV generations like SEV-ES for encrypted CPU register states and SEV-SNP for hardware memory integrity protection as well as updating the FreeBSD kernel to run seamlessly as an encrypted guest OS using memory C-bit handling and bounce buffers.

And for you, mere mortal, what does all of this actually mean? It means true cloud privacy without having to blindly trust anyone. Whether you're hosting sensitive customer data, financial workloads, or proprietary algorithms, confidential computing ensures that not even your cloud provider or a rogue admin with full root access can peek into your running memory.

By bringing AMD SEV to FreeBSD, top-tier, silicon-enforced protection stops being an exclusive enterprise luxury and becomes part of the open-source toolkit.

Bottom line: your data is finally locked down in transit, at rest, and right down to the hardware while in use.

#freebsd #openbsd #netbsd #bsd #EuroBSDCon2026

0
1
0
0
OpenJDK 27 released to FreeBSD ports tree I just pushed a port for OpenJDK 27 to the main branch of the FreeBSD ports tree. In additions to the upstream changes, the following BSD specific improvements are included: Fix os::naked_short_nanosleep on OpenBSD when < 20 miliseconds.Only return symbols that match the requested address for dladdr(3) on BSD. The latter also reverts the default visibility of symbols in libjvm.so to hidden, which should make loading the library faster, and reduce the memory consumption slightly. As always thanks to @FreeBSDFoundation@mastodon.social for sponsoring my work on the OpenJDK for FreeBSD, and also to Kurt Miller for digging into the details for the BSD specific fixes for this release. #FreeBSD #OpenJDK #mywork #java #jvm #FLOSS
0
0
0
0