1. sidetone

    Bastille jail: to build and test builds

    Install sysutils/bastille, net/gitup and x11-servers/xorg-nestserver on host through either ports or packages. Bastille jail in the example or instruction will be named "myjail". I'll use an alias IP and network card as an example. doas or sudo can be used from your host system, depending on...
  2. B

    Solved Package installation in jail, pkg -j or pkg -r?

    Hi all, I recently came across the `-j` and `-r` options for pkg, and start wondering if there is any reason to prefer one over the other. Specifically, do pkg -j jid install pkg_name and pkg -r path_to_jail install pkg_name essentially achieve the same thing, or are there any subtle...
  3. O

    Solved OpenSSL version appears differently from inside and outside of jail

    After updating freebsd and jails to 13.0 release patch 4 I tried to verify everthing was up to date. However when checking the openssl version in my jail I noticed something strange. Inside the jail openssl version produced the output: OpenSSL 1.1.1k-freebsd 25 Mar 2021 But invoking version...
  4. B

    MESA Loader Fails to Open amdgpu, Doesn't Detect /dev/dri/card0

    Specs: Ryzen 3960x, Radeon RX 5700, 13.0-RELEASE-p3 Problem is occuring inside jails. When I try to launch a GUI app (Falkon, Blender, etc), the app launches, but with significant lag for moving objects with mouse, videoplayback, and consuming large CPU resources even at idle...
  5. Thomas.

    Vnet jail with IPFW NAT outbound traffic no longer works after upgrade from 12.2-RELEASE to 13.0-RELEASE

    Hi, I'm new to FreeBSD (only started tinkering about with it last week), and after lots of digging through the documentation, handbook, and many other online resources I managed to have my vnet enabled jail working in conjunction with ipfw in-kernel NAT. Both inbound and outbound traffic was...
  6. D

    Network interface alias used by jail disappears until server restart

    I have a network interface alias which I declared in /etc/rc.conf, as follows: ifconfig_alc0="DHCP" ifconfig_alc0_alias0="inet" ifconfig_alc0_alias1="inet" ifconfig_alc0_alias2="inet" The jail is configured to use (and two other jails...
  7. M

    Solved BastilleBSD Jail can not run package update or install with pf configured on host

    Hi all, DiscIaimer: I only partially understand what I am doing. I set up a FreeBSD 13.0 Host with. BastilleBSD. Everything working fine but I struggle with the configuration of the pf packet filter, which is new to me (only used ipfw since). My goal is to be as restrictive as possible without...
  8. G

    Services whithin jails no longer accessible after upgrade to version 13.0

    After upgrading a virtual FreeBSD 12.2 system to 13.0-p3, traffic to services within jails (through Apache 2.4 reverse proxy) was blocked. This is a Hyper-V virtual server and the second one that shows the same problem (the other one being a commercial VPS, hypervisor type unknown). At first, I...
  9. S

    Protect process from OOM killer in Jail

    Hi, Does anybody know how to protect daemon in jail from OOM Killer? I tried to set mysql_oomprotect to YES in rc.conf in Jail but it doesn't work. Thaks
  10. F

    Solved bsdinstall FTP Permission Denied Error

    When I run bsdinstall jail <jailpath> and select a mirror I get: Could not download ftp://ftp.freebsd.org/pub/FreeBSD/releases/amd64/amd64/13.0-RELEASE/MANIFEST I click <restart> and and get: Error while fetching ftp://ftp.freebsd.org/pub/FreeBSD/releases/amd64/amd64/13.0-RELEASE/base.txt...
  11. I

    jails Strange behavior with "devfs_ruleset"

    I've noticed a strange problem with setting"devfs_ruleset" in jail.conf. In jail.conf: testjail { host.hostname = testjail; devfs_ruleset = 27; #note: with no other configuration for this jail } Note: ruleset 27 does NOT exist - I've checked in /etc/defaults/devfs.rules and...
  12. I

    jails Using mdconfig inside jail

    I need to use mdconfig inside a jail, but I'm hit with "Error mdconfig: open(/dev/mdctl): No such file or directory". I think I need to "allow" it in the jail.conf but couldnt figure out what it is. Please help.
  13. keldonin

    jails files and directories invisible from jail

    Hello, I'm encountering an issue that I can't explain, so looking for SME advice here :) I run a linux (debian) inside a jail. I'm using iocage for jail management. deboostrap was used to deploy the guest system. Everything seems to work well except that many files from /etc directory are not...
  14. I

    jails How to install "pkg" inside a jail for a machine without Internet connection?

    I have a FreeBSD box with no Internet connection. Somehow I had installed "pkg" into the host system previously (if I remember correctly, it was from the mounted dvd1.iso). I created a jail and tried to install some packages. The "pkg" is not available in the jail. I tried to mount the same...
  15. I

    jails How to configure routing for jail?

    I'm having some problem setting routing inside a jail. I added to rc.conf (inside jail) and it did not work. I then tried "route add" and it responded "route: writing to routing socket: Operation not permitted" I think it is not possible to set routing from inside. So, how do I...
  16. M

    PF Nat is not forwarding to jail

    I am using PF and cannot get packets forwarded to a particular jail. I want data that comes into my base machine on port 4243 to be forwarded to my jail that has a service that is listening on port 4243. I have verified with telnet that the jail can receive data on that port. Here is my...
  17. jbodenmann

    Solved Unexpected behavior mounting NFS share to jail data

    The following scenario is happening on two freshly installed FreeBSD 13.0-RELEASE hosts. Host A acts as an NFSv4 server. It provides the following share: Host B can successfully mount and browse the share using mount -t nfs -o nfsv4,rw /mnt. Host B...
  18. poorandunlucky

    Problem upgrading jails (pkg, freebsd-update)

    So I have these jails now, and I want to install Samba on my www jail. I've upgraded to 12.2-p6, pkg -vv shows kernel 120200. I've upgraded my jail with freebsd-update -b /jails/www There was an error, some directories for the certificates under /usr/share/[certs]/[trusted/blacklisted] didn't...
  19. sidetone

    Solved jails - Accessing devices from Bastille

    How do I make devices in /dev/ accessible inside a Bastille jail? When I have two sets of rules, how do I set this in rc.conf.local, from within the host system? devfs_system_ruleset="localrules" How would bastille also get referenced with this? In devfs.rules of the host (not within the...
  20. G

    PF pf - does not block traffic to jail

    I have remote FreeBSD server with name server inside jail. My rules are: ext_if="em0" ext_ip="X.X.X.X" jail_net="" ns_ip="" icmp_types = "echoreq" table <blacklist> persist file "/etc/pf/blacklist" table <trusted> persist file "/etc/pf/trusted" set block-policy drop set...