Open post goeranh @goeranh@mastodon.online · 6mo ago Replying to @zeab@fosstodon.org <p>Started to use <a href="https://fosstodon.org/tags/SystemManager" class="mention hashtag" rel="tag">#<span>SystemManager</span></a> from <a href="https://fosstodon.org/tags/numtide" class="mention hashtag" rel="tag">#<span>numtide</span></a> and I'm SO with this. 😎</p><p>I don't run <a href="https://fosstodon.org/tags/nixos" class="mention hashtag" rel="tag">#<span>nixos</span></a>. Yes. I still prefer <a href="https://fosstodon.org/tags/ubuntu" class="mention hashtag" rel="tag">#<span>ubuntu</span></a> or <a href="https://fosstodon.org/tags/popos" class="mention hashtag" rel="tag">#<span>popos</span></a>. I like the distros and usually deviate their base to be anything anyhow. 😏</p><p>But that does not mean I like missing declaration magic. System manager lets me still do all the crazy things I normally do. Plus I get some guard on my system settings. 😅</p><p><a href="https://system-manager.net/main/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">system-manager.net/main/</span><span class="invisible"></span></a></p> @zeab how does this compare to traditional home-manager?
Open post goeranh @goeranh@mastodon.online · 7mo ago @rubenerd@bsd.network regarding your vim post^^https://lkml.org/lkml/2026/3/2/1510 lkml.org LKML: bot+bpf-ci@kernel ...: Re: [PATCH bpf-next v2 3/6] bpf: Disallow !kprobe_write_ctx progs tail-calling kprobe_write_ctx progs
Open post goeranh @goeranh@mastodon.online · 5mo ago Replying to @jana@social.jsteuernagel.de <p>I started reading about netgraph on FreeBSD.</p><p>I think I understood the basic theory of what nodes, hooks and edges are and a bit on how ngctl can be used to configure those.</p><p>I definitely still have enough questions about it, which will hopefully be able to be resolved by just playing with it. Gotta spin up a VM and break some stuff.</p><p>I wanna skip tools like ngbuddy, because at first glance they seem like they are opinionated in ways that don’t match what I want to do, but I‘m used to that. After all I had the same „problem“ with Bastille and vm-bhyve :D</p> @jana would you mind sharing some sample setups when you are up and running? I tried to look into netgraph about a year back and didnt really get anywhere, but the concepts sound really promising!
Open post goeranh @goeranh@mastodon.online · 3mo ago Replying to @domi@donotsta.re so i look into why my logs are so enormous. i shouldn’t have left them as verbose for 1.5 months but they also shouldn’t have grown to EIGHT GIGABYTES. and most of my recent log lines are something like Jul 04 13:36:22 msg="Limit of simultaneous TCP connections reached - raise max-tcp-connections" prio="Warning" this, but 15 times a second… Which usually means that we’re under attack. but it’s a very lousy attack, i can’t even see it on the graph, so they’re only really causing some disruption to TCP connections, not UDP. and most of DNS is UDP, that’s why I’m only noticing right now. anyways. ss -tulnap | grep 53 shows a lot of connections with addresses that begin with 2a03:2880. | wc -l says 273, from maybe 5-6 different hosts. and, my dear comrades, can you guess who owns 2a03:2880::/32? inet6num: 2a03:2880::/40 netname: PRN country: US admin-c: RD4299-RIPE tech-c: RD4299-RIPE status: ASSIGNED mnt-by: fb-neteng mnt-by: facebook-neteng created: 2020-03-11T00:33:38Z last-modified: 2020-03-11T00:33:38Z source: RIPE that’s right! facebook! and after a preliminary check, we’ve seen this same exact thing on at least one other #SERVFAIL nameserver in “completely unrelated news”: i “slipped” in my kitchen and executed ip6tables -I INPUT -s 2a03:2880::/32 -j DROP as root on sakamoto i’m so sorry (not sorry). and through the power of ip6tables… suddenly my TCP limits aren’t reached anymore. CURIOUS if you didn’t have enough reasons to hate meta: FUCK META :boost_ok: @domi@donotsta.re i had the same thing happen to me and built a AS blocklist service, but using nftables😅 https://codeberg.org/stura-htw-dresden/stura-infra/src/branch/master/modules/isp-block.nix Because the semrush but was alsmost worse for me😅 codeberg.org Cookie monster!
Open post goeranh @goeranh@mastodon.online · 5mo ago Replying to @tubsta@social.bsdlab.au @oxy@social.bsdlab.au Ping @tj@altelectron.org.uk had a bit to do with VPP in FreeBSD. Maybe an email to feedback@bsdnow.tv addresses to Tom on where it is at and who is using it :-) @tubsta@social.bsdlab.au @tj@altelectron.org.uk @oxy@social.bsdlab.au hey, wanna do a episode about vpp and netmap? Had to do work with linux xdp recently and would really love to know more about the freebsd side of things👉👈😅