Re: umount raid volume before shutdown?

2024-05-31 Thread Claudio Jeker
On Thu, May 30, 2024 at 08:17:27PM +0100, 04-psyche.tot...@icloud.com wrote: > From my reading of /etc/rc, it seems that at shutdown or reboot, the OS will > automatically unmount everything. > > So that will unmount my encrypted partition. > > However, it does not run bioctl -d sd* for the

Re: OpenBSD bgpd / rad "Permission denied" messages ?

2024-05-28 Thread Claudio Jeker
On Tue, May 28, 2024 at 06:28:27PM +0200, Rachel Roch wrote: > Hi > > I'm struggling to understand what is going on here. > > I have an Openbsd 7.2 box which has been working beautifully for about 3 > years. > > Now it seemingly suddenly refuses to do anything involving the outside world, >

Re: advice debugging lockups with swap-thrashing symptoms?

2024-05-23 Thread Claudio Jeker
On Thu, May 23, 2024 at 03:37:24PM +, James Cook wrote: > On Thu, May 23, 2024 at 08:00:37AM GMT, Nick Holland wrote: > > On 5/23/24 03:18, Stuart Henderson wrote: > > > On 2024-05-22, James Cook wrote: > > > > One of my OpenBSD boxes sometimes gets in a weird locked-up or > > > >

Re: bgpd(8) not announcing IPv6 addresses from local network

2024-05-06 Thread Claudio Jeker
:ba:6000::/48fe80::9ab7:85ff:fe00:3726%mgre0 100 > 0 10261 i > I*N-? 2620:ba:6000::/48fe80::9ab7:85ff:fe00:3727%mgre0 100 > 0 10261 i > > I'm not seeing any output with the global address in question, which > is pretty weird. > > > On Mon, May 6

Re: bgpd(8) not announcing IPv6 addresses from local network

2024-05-06 Thread Claudio Jeker
On Mon, May 06, 2024 at 02:03:52PM -0400, Benjamin Raskin wrote: > As mentioned in my previous email, I'm looking to advertise global > addresses such as 2620:ba:6000:3:58d2:48ff:fee6:270a, but then > I took a look at my routing table and noticed that gateway/nexthop > for this global address is a

Re: has dump(8) changed or something? recently?

2024-04-26 Thread Claudio Jeker
On Fri, Apr 26, 2024 at 12:44:34PM +0200, Peter J. Philipp wrote: > Hi! > > I've had some problems with dump(8) lately. A 800 GB SSD partition on a > raspberry pi 4b (via USB) that is 50% filled had trouble with dump. I don't > know why this could be, but it used to work. > > Here is my backup

Re: bad first impression [ ...] Fwd: [HUNSN RJ43: USB keyboard lost at boot time]

2024-04-26 Thread Claudio Jeker
On Fri, Apr 26, 2024 at 08:31:17AM -, Stuart Henderson wrote: > On 2024-04-25, Wolfgang Pfeiffer wrote: > > - Forwarded message from Harald Dunkel - > > This morning I've got a HUNSN RJ43 network appliance with N100 and > > 4 2.5Gbit network interfaces. Problem: The keyboard is lost

Re: bad first impression of OpenBSD at install time

2024-04-25 Thread Claudio Jeker
On Thu, Apr 25, 2024 at 05:46:04PM +0200, Harald Dunkel wrote: > Hi folks, > > I posted this before, without any response from the community: > > At the boot> prompt of the installer image my USB keyboard still works, > but at the install prompt the keyboard is ignored. I cannot press "i" > to

Re: Upgraded to 7.5: vfs.ffs.dirhash_dirsize no longer exists and large directory ere veeery slow

2024-04-11 Thread Claudio Jeker
ote: > > > > > > > On 4/11/24 16:15, Claudio Jeker wrote: > > > > > On Thu, Apr 11, 2024 at 03:36:29PM +0200, Federico Giannici wrote: > > > > > > On 4/11/24 14:12, Nick Holland wrote: > > > > > > > On 4/11/24 05

Re: Upgraded to 7.5: vfs.ffs.dirhash_dirsize no longer exists and large directory ere veeery slow

2024-04-11 Thread Claudio Jeker
On Thu, Apr 11, 2024 at 03:36:29PM +0200, Federico Giannici wrote: > On 4/11/24 14:12, Nick Holland wrote: > > On 4/11/24 05:47, Federico Giannici wrote: > > > We have a server with A LOT of files in some directories (an email > > > server in maildir format). > > > > > > Since we upgraded from

Re: 7.5: Fatal errors from eigrpd

2024-04-09 Thread Claudio Jeker
This is most probably fallout from the imsg / ibuf API changes done in 7.5. I need to setup a test system to see if I can figure out what goes wrong. On Mon, Apr 08, 2024 at 08:15:52PM +0200, Mark Leonard wrote: > (Gah! Here's the post again in plaintext. Apologies.) > > Hello all, > > I'm

Re: TSO support and performance gain

2024-04-05 Thread Claudio Jeker
On Fri, Apr 05, 2024 at 05:24:27PM +, mabi wrote: > Hi, > > First thank you for another great OpenBSD release. I just updated my home > firewall today and was wondering about the performance of TSO support on bnxt > and em interfaces which have been added to the 7.5 release... > > Does

Re: crawling network with ix driver when routing trafic

2024-03-04 Thread Claudio Jeker
On Mon, Mar 04, 2024 at 11:07:37AM +1100, Aaron Mason wrote: > Hi! > > It's my understanding that the Realtek network adapters are pretty > craptacular under load since they basically defer to the OS for > everything, raising an interrupt each time. Try the fourth test again > while running top

Re: crawling network with ix driver when routing trafic

2024-03-04 Thread Claudio Jeker
On Sun, Mar 03, 2024 at 09:38:22PM +0100, Pierre Peyronnel wrote: > Hey misc, > > Note : I posted on this topic in r/openbsd and before I open a bug, I > thought I'd ask you. > > My OBSD router has a Realtek (onboard) and an intel (X540 pcie) network > card, and in one particular situation I get

Re: Programmatically add default IPv6 route

2024-02-23 Thread Claudio Jeker
On Fri, Feb 23, 2024 at 06:25:18PM +0100, Denis Fondras wrote: > Hello, > > I am trying to add IPv6 support for pppd(8) (IPv6CP) and I encounter a blocker > when adding a default IPv6 route to PPP peer. > > Feb 23 17:26:45 rt-01 pppd[64071]: Couldn't add IPv6 default route: Network > is

Re: load balancing with rdomains

2023-12-18 Thread Claudio Jeker
On Mon, Dec 18, 2023 at 01:53:50PM +0100, Marko Cupać wrote: > On Sat, 16 Dec 2023 18:53:29 +0100 > Petr Ročkai wrote: > > > Hi, > > > > On Sat, Dec 16, 2023 at 06:37:54PM +0100, Marko Cupać wrote: > > > pass in on em0 from (em0:network) to probability 50% > > > rtable 1 pass in on em0 from

Re: OpenBSD SMP - BGPd - send_rtmsg: action 1, prefix A.B.C.D/24: No buffer space available - panic: malloc: out of space in kmem_map

2023-12-14 Thread Claudio Jeker
On Tue, Nov 28, 2023 at 05:55:03PM +0100, Laurent CARON wrote: > > Le 28/11/2023 à 17:46, Claudio Jeker a écrit : > > The problem is that the symbol nkmempages moved into .bss and is therefor > > no longer modifiable by config(8). I think you can still use ukc via &g

Re: relayd https inspection certificate issue

2023-12-09 Thread Claudio Jeker
On Fri, Dec 08, 2023 at 10:04:25PM +, Philipp Benner wrote: > Dear all, > >   > I would like to use relayd as an outbound https proxy, so I configured it > like shown in the last section of the relayd.conf(5) manpage. > > This works fine for e.g. wikipedia.org. The certificate issued by my

Re: Realtek 8723BE unsupported

2023-12-04 Thread Claudio Jeker
On Mon, Dec 04, 2023 at 11:16:04AM +1000, David Gwynne wrote: > On Sun, Dec 03, 2023 at 06:02:03PM +0100, Jan Stary wrote: > > (please keep replies on the list) > > > > On Dec 03 12:08:08, kolip...@exoticsilicon.com wrote: > > > On Sun, Dec 03, 2023 at 02:35:11PM +0100, Jan Stary wrote: > > > >

Re: OpenBSD SMP - BGPd - send_rtmsg: action 1, prefix A.B.C.D/24: No buffer space available - panic: malloc: out of space in kmem_map

2023-11-28 Thread Claudio Jeker
On Tue, Nov 28, 2023 at 04:50:05PM +0100, Laurent CARON wrote: > Le 28/11/2023 à 12:12, Claudio Jeker a écrit : > > So the problem is that the malloc space is filled by > > a) 26540K of devbuf -- because of the multiqueue support in ixl > > b) 63493K of ACPI

Re: OpenBSD SMP - BGPd - send_rtmsg: action 1, prefix A.B.C.D/24: No buffer space available - panic: malloc: out of space in kmem_map

2023-11-28 Thread Claudio Jeker
t -m SMP with bgpd until crash. > > > Thanks > > Laurent > > Le 27/11/2023 à 17:10, Claudio Jeker a écrit : > > vmstat -m So the problem is that the malloc space is filled by a) 26540K of devbuf -- because of the multiqueue support in ixl b) 63493K of ACPI -- what the h

Re: OpenBSD SMP - BGPd - send_rtmsg: action 1, prefix A.B.C.D/24: No buffer space available - panic: malloc: out of space in kmem_map

2023-11-27 Thread Claudio Jeker
On Mon, Nov 27, 2023 at 04:57:35PM +0100, Laurent CARON wrote: > Hi, > > I'm currently migrating a BGPd server. > > Specs of "old" machine: > > - Dell R720 with Intel(R) Xeon(R) CPU E5-2637 v2and 16GB RAM > > - SMP Kernel (default) > > - BGPd runs fine with 5 full views > > - X710 NIC (ixl)

Re: Jumbo frame, just a little late..

2023-11-07 Thread Claudio Jeker
rio 3 > groups: egress > media: Ethernet autoselect (1000baseT > full-duplex,master,rxpause,txpause) status: active inet > 192.168.XXX.XXX netmask 0xff00 broadcast 192.168.XXX.XXX > > > == Daniele Bonini > > > Claudio Jeker wrote: > > > Sorry

Re: Jumbo frame, just a little late..

2023-11-07 Thread Claudio Jeker
On Tue, Nov 07, 2023 at 10:21:35AM +0100, Daniele B. wrote: > Hello, > > Actually i'm not sure about the real benefits of it, and for a soho > environment like mine but after 17 years I decided to take jumbo > frame seriously.. and MTU values of my network equipment to 9018. > I watched with

Re: Regression (or misconfig on my side?) after OpenOSPFd upgrade (OpenBSD 7.3 -> 7.4)

2023-11-07 Thread Claudio Jeker
On Tue, Nov 07, 2023 at 08:21:16AM +0100, Laurent CARON wrote: > Hi, > > After upgrading a 7.3 to 7.4 OpenBSD box, I noticed OSPF adjacencies using a > password are not coming up with the following in /var/log/messages: > > ospfd[55040]: recv_packet: authentication error, neighbor ID X.X.X.X >

Re: What could cause high CPU load averages (no actual CPU usage)?

2023-10-27 Thread Claudio Jeker
On Fri, Oct 27, 2023 at 01:54:28AM +0200, Justin Yates Fletcher wrote: > On Wed, 2023-10-25 at 20:25 -0400, Raul Miller wrote: > > On Wed, Oct 25, 2023 at 8:16 PM Justin Yates Fletcher > > wrote: > > > On Wed, 2023-10-25 at 21:12 +0200, Mike Fischer wrote: > > > > > > > > > Am 25.10.2023 um

Re: What could cause high CPU load averages (no actual CPU usage)?

2023-10-25 Thread Claudio Jeker
On Wed, Oct 25, 2023 at 05:24:50PM +0200, Mike Fischer wrote: > > > Am 25.10.2023 um 17:07 schrieb Theo de Raadt : > > > > Claudio Jeker wrote: > > > >> On Wed, Oct 25, 2023 at 11:57:54AM +0200, Mike Fischer wrote: > >>> I have been observing o

Re: What could cause high CPU load averages (no actual CPU usage)?

2023-10-25 Thread Claudio Jeker
On Wed, Oct 25, 2023 at 11:57:54AM +0200, Mike Fischer wrote: > I have been observing occasional bouts of high load averages on several > servers I administer and I am trying to find the cause. (I monitor these > machines so that I can implement corrective measures in case of any > malicious or

Re: Question about rdomains/rtables

2023-10-24 Thread Claudio Jeker
On Mon, Oct 23, 2023 at 06:08:37PM +0200, tetrosalame wrote: > Hello misc, > > I'm playing with rdomain/rtable on OpenBSD 7.4 and I'm a bit confused about > the relation between rdomains and rtables. > > If I got rdomain(4) right, the two facilities are designed so that a rdomain > can hold

Re: Default rdomain for CLI commands

2023-10-24 Thread Claudio Jeker
On Tue, Oct 24, 2023 at 08:39:33AM -, Stuart Henderson wrote: > On 2023-10-24, Andy Lemin wrote: > > Hi all, > > > > Just a quick question. > > > > I have multiple rdomains. My outside rdomain (rdomain 0) has a single > > default route to my ISP. And my internal rdomain 9 has multiple

Re: Default rdomain for CLI commands

2023-10-24 Thread Claudio Jeker
On Tue, Oct 24, 2023 at 06:56:33PM +1100, Andy Lemin wrote: > Hi Lyndon, > That is a good trick, I will try that. > > But it is more of an unexpected nuisance as I’m expecting the default to > be rdomain 0. No rdomains are inherited. Once a process runs in rdomain X all childs will also be in

Re: OpenBSD 7.3 found a process with PID 0

2023-09-27 Thread Claudio Jeker
On Tue, Sep 26, 2023 at 06:12:20PM +0200, Alessandro Baggi wrote: > > > Il 26/09/23 17:30, Claudio Jeker ha scritto: > > On Tue, Sep 26, 2023 at 05:13:46PM +0200, Andreas Kähäri wrote: > > > On Tue, Sep 26, 2023 at 04:59:22PM +0200, Alessandro Baggi wrote: > >

Re: OpenBSD 7.3 found a process with PID 0

2023-09-26 Thread Claudio Jeker
On Tue, Sep 26, 2023 at 05:13:46PM +0200, Andreas Kähäri wrote: > On Tue, Sep 26, 2023 at 04:59:22PM +0200, Alessandro Baggi wrote: > > Hi list, > > running this python3 script: > > > > #!/usr/bin/env python3 > > import psutil > > > > pids = psutil.pids() > > for i in pids: > > p =

Re: IPv6 link-local addresses outside of fe80::/64 are not handled correctly

2023-07-12 Thread Claudio Jeker
On Wed, Jul 12, 2023 at 10:59:13AM -0600, Zack Newman wrote: > On 7/12/23 10:20, Claudio Jeker wrote: > > You are missing something. It is called the KAME hack or embedded scope. > > The KAME IPv6 implementation hijacks the 2nd 16bit addr part to store the > > sco

Re: IPv6 link-local addresses outside of fe80::/64 are not handled correctly

2023-07-12 Thread Claudio Jeker
On Wed, Jul 12, 2023 at 08:23:36AM -0600, Zack Newman wrote: > Before I raise a bug report, I wanted to pass it by @misc in case I'm > confused. It appears there is an issue with link-local addresses at > least as far as route(8) is concerned. Since May 2, /var/log/messages > has been getting

Re: APCI on old Thinkpad

2023-07-03 Thread Claudio Jeker
Also keep in mind that laptops that old most often had bad or broken early ACPI implementations and it was better to not enable ACPI on those. Normally there was some BIOS knob to just use apm(4) which often worked much better. On Mon, Jul 03, 2023 at 08:58:45PM +0200, Daniele B. wrote: > Thanks

Re: relayd: pfe_route: failed to add gateway 22 Invalid argument

2023-06-29 Thread Claudio Jeker
On Thu, Jun 29, 2023 at 09:34:10AM +0200, Jörg Streckfuß wrote: > Hi Claudio, > > Am 29.06.23 um 09:01 schrieb Claudio Jeker: > > On Thu, Jun 29, 2023 at 08:53:05AM +0200, Jörg Streckfuß wrote: > > > > > > Hi list, > > > > > > here is a small

Re: relayd: pfe_route: failed to add gateway 22 Invalid argument

2023-06-29 Thread Claudio Jeker
On Thu, Jun 29, 2023 at 08:53:05AM +0200, Jörg Streckfuß wrote: > > Hi list, > > here is a small addition. Adding and deleting the route to and from routing > table on the command line works as expected: > > fw1 # route add 2001:::::4/128 2001:::::4 -label > geo_service

Re: mp-safe tun

2023-06-26 Thread Claudio Jeker
On Mon, Jun 26, 2023 at 03:21:26PM +, Valdrin MUJA wrote: > Hello OpenBSD, > > I've been thinking about this since OpenBSD devs do a lot of mp-safe on the > network stack: > Is it possible to make /dev/tun device mp-safe/Multi-queue? It is rather complicated to do mainly because a large

Re: latest amd64 snap hangs on "root on sd0a..."

2023-06-22 Thread Claudio Jeker
On Wed, Jun 21, 2023 at 07:27:44PM +0300, Mikhail wrote: > Just installed latest amd64 install73.img from cdn.openbsd.org > > OpenBSD 7.3-current (GENERIC.MP) #1253 Tue Jun 20 13:52:16 MDT 2023 > > and after installation it can't proceed further than > > root on sd0a (..) swap on sdb0b dump on

Re: latest amd64 snap hangs on "root on sdoa..."

2023-06-21 Thread Claudio Jeker
On Wed, Jun 21, 2023 at 01:03:03PM -0600, Chris Waddey wrote: > Sorry for breaking the thread, I wasn't subscribed to misc, but found > this in the archives. > > After some testing, it looks like the recent uvm_meter() commit is what > did this (to my machine at least). > > The git commit for

Re: [Bug (?) ld]: ld interprets % weirdly

2023-06-11 Thread Claudio Jeker
On Sun, Jun 11, 2023 at 12:01:04AM -0600, Theo de Raadt wrote: > I assume you are on an architecture where the linker is LLVM ld, > otherwise known as ld-lld in OpenBSD (some older architectures > still use ld-bfd). > > In llvm/lib/Support/Path.cpp, there is code that acts just like you describe:

Re: Multi path routing with BGPD

2023-06-01 Thread Claudio Jeker
ature is developed? I'm not sure if bird does multipath on OpenBSD. Guess you will find out. > ____ > From: Claudio Jeker > Sent: Thursday, June 1, 2023 19:34 > To: Valdrin MUJA > Cc: MISC@openbsd.org > Subject: Re: Multi path routing with BGPD >

Re: Multi path routing with BGPD

2023-06-01 Thread Claudio Jeker
On Mon, May 29, 2023 at 07:29:14PM +, Valdrin MUJA wrote: > Hello, > > I try to setup multipath routing environment with OpenBSD's bgpd. multipath != add-path. OpenBGPD currently does not do multipath routing. It only uses the best path for the FIB and the nexthops are only resolved to one

Re: Route based IPsec

2023-05-31 Thread Claudio Jeker
On Wed, May 31, 2023 at 06:39:27PM +1000, David Gwynne wrote: > > > > On 31 May 2023, at 18:33, Claudio Jeker wrote: > > > > On Wed, May 31, 2023 at 08:35:45AM +1000, David Gwynne wrote: > >> > >> > >>> On 27 May 2023, at 21:40, Stua

Re: Route based IPsec

2023-05-31 Thread Claudio Jeker
On Wed, May 31, 2023 at 08:35:45AM +1000, David Gwynne wrote: > > > > On 27 May 2023, at 21:40, Stuart Henderson > > wrote: > > > > On 2023-05-27, Valdrin MUJA wrote: > >>Does OpenBSD have routed based IPsec support? > > > > Not yet. > > while you wait, it might be possible to

Re: small issue with mpe

2023-05-23 Thread Claudio Jeker
On Wed, May 24, 2023 at 01:31:56PM +1000, David Gwynne wrote: > > > > On 23 May 2023, at 17:40, Claudio Jeker wrote: > > > > On Tue, May 23, 2023 at 07:09:51AM -, Stuart Henderson wrote: > >> On 2023-05-23, David Gwynne wrote: > >>> On Sat, Ma

Re: small issue with mpe

2023-05-23 Thread Claudio Jeker
On Tue, May 23, 2023 at 07:09:51AM -, Stuart Henderson wrote: > On 2023-05-23, David Gwynne wrote: > > On Sat, May 20, 2023 at 09:44:51AM +0200, Holger Glaess wrote: > >> hi > >> > >> > >> looks like that the patch works , but should not print "tunneldomain" > >> instead of "rdomain" ? > >

Re: 'bgpctl show rib in neighbor $peer' no longer shows unfiltered received routes

2023-05-09 Thread Claudio Jeker
On Tue, May 09, 2023 at 09:49:18AM +0200, Rogier Krieger wrote: > Thanks for the rapid response and proposal. > I'd wanted to test yesterday but had to postpone. > > On Mon, May 8, 2023 at 12:18 PM Claudio Jeker > wrote: > > Here is a possible solution where a perfect match

Re: 'bgpctl show rib in neighbor $peer' no longer shows unfiltered received routes

2023-05-08 Thread Claudio Jeker
On Mon, May 08, 2023 at 09:14:43AM +0200, Claudio Jeker wrote: > On Mon, May 08, 2023 at 12:28:58AM +0200, Rogier Krieger wrote: > > While diagnosing an unrelated matter, I find that 'bgpctl show rib' > > has difficulty with the 'in' keyword. The 'out' counterpart works as > &

Re: 'bgpctl show rib in neighbor $peer' no longer shows unfiltered received routes

2023-05-08 Thread Claudio Jeker
On Mon, May 08, 2023 at 12:28:58AM +0200, Rogier Krieger wrote: > While diagnosing an unrelated matter, I find that 'bgpctl show rib' > has difficulty with the 'in' keyword. The 'out' counterpart works as > expected. Looking at bgpctl(8), the following should work (but > doesn't): > $ bgpctl show

Re: OpenBSD and AMD EPYC/RYZEN 10gb

2023-04-12 Thread Claudio Jeker
On Wed, Apr 12, 2023 at 02:05:02PM +, Laura Smith wrote: > No worries. > > (And for anyone following on-list, I think FreeBSD might have > subsequently renamed axgbe to something else beginning on ax, I think > maybe "axa" as per the "history" note on the bottom of this page >

Re: rdomains finally working!!

2023-04-03 Thread Claudio Jeker
On Mon, Apr 03, 2023 at 10:53:26AM +0100, Kaya Saman wrote: > Hey guys, > ... > Taking an excerpt from the website I was following: > > https://www.packetmischief.ca/2011/09/20/virtualizing-the-openbsd-routing-table/ > > Citing: > > Creating a loopback interface in rdomain 2 so that Host 1

Re: Folks are there any tips to improve page load times on smokeping running on OpenBSD

2023-03-07 Thread Claudio Jeker
On Tue, Mar 07, 2023 at 08:36:24AM +, Stuart Henderson wrote: > On 2023/03/07 07:10, Tom Smyth wrote: > > I m running smokeping fcgi and rrdcached ontop of OpenbSD, to smokeping > > about 150 devces > > the page load times can take 30 seconds to 1 minute, > > is there any way to speed this up.

Re: Recommended place to store static arp entries

2023-02-28 Thread Claudio Jeker
On Tue, Feb 28, 2023 at 03:30:18PM +0200, Cristian Danila wrote: > Dear Misc, > > I would really appreciate if more experienced members of you > could suggest if there is a dedicated place or recommended > place for OpenBSD where static arp entries should be stored. > I found many answers over

Re: Performance optimizing OpenBSD 7.2

2023-02-15 Thread Claudio Jeker
On Wed, Feb 15, 2023 at 01:01:10PM -, Stuart Henderson wrote: > On 2023-02-15, Lars Bonnesen wrote: > > One says: > > > > # pfctl -s info > > Status: Enabled for 0 days 10:56:43 Debug: err > > > > State Table Total Rate > > current entries

Re: Performance optimizing OpenBSD 7.2

2023-02-15 Thread Claudio Jeker
On Wed, Feb 15, 2023 at 01:39:54PM +0100, Lars Bonnesen wrote: > One says: > > # pfctl -s info > Status: Enabled for 0 days 10:56:43 Debug: err > > State Table Total Rate > current entries91680 > half-open tcp

Re: Performance optimizing OpenBSD 7.2

2023-02-15 Thread Claudio Jeker
On Wed, Feb 15, 2023 at 10:28:57AM +0100, Gábor LENCSE wrote: > Hi Lars, > > > I downscaled from 8 to 4 vCPUs and from 8 to 4 gig RAM - and the two obsd > > now seems to hold the packages decently. > > As for performance optimization, I think the direction is good, and perhaps > you could go

Re: OpenBSD as a transparent switch filter

2023-01-24 Thread Claudio Jeker
On Tue, Jan 24, 2023 at 11:43:08AM +, Tom Smyth wrote: > Hello Cristian, > if you want to filter on layer 2 ... you would need to use Bridge > have a look at man ifconfig(8) > bridge filter rules can be added to ports in the bridge... > you can also tag traffic in bridge filter rules and

Re: OpenBGDP IPv6 ignoring set localpref parameter

2023-01-09 Thread Claudio Jeker
On Mon, Jan 09, 2023 at 11:59:22AM -0500, Matt wrote: > Hello list, > > > > I've run across an interesting issue which I think might be something I did > wrong but here goes. Below is my configuration file for bgpd.conf. I will > also give you the interface configurations for the two tunnels

Re: bgpd.conf rules changed?

2022-12-19 Thread Claudio Jeker
On Mon, Dec 19, 2022 at 12:41:26PM +0100, Toni Mueller wrote: > > Hi, > > I am trying to upgrade an OpenBSD based BGP router from an old version > to 7.2. But on OpenBSD 7.2, the config file results in several errors, > despite the man page not indicating any thing "obvious". > > Eg. I get

Re: ex/vi 100% CPU when STDIN_FILENO set to O_NONBLOCK

2022-12-12 Thread Claudio Jeker
On Sun, Dec 11, 2022 at 04:10:41PM -0800, Jeremy Mates wrote: > ... > 42136 ex RET read -1 errno 35 Resource temporarily unavailable > 42136 ex CALL read(0,0x3d94b585400,0xff) > 42136 ex RET read -1 errno 35 Resource temporarily unavailable > 42136

Re: bgp conditional advertisement

2022-11-30 Thread Claudio Jeker
On Thu, Dec 01, 2022 at 01:01:16AM +0200, Gregory Edigarov wrote: > Hello, > > Having two sites in different physical locations, siteA is connected > via uplink1 and uplink2, siteB is connected via uplink3 and uplink4. > I want to announce prefixes from siteB if ASn not found originating > from

Re: slaacd, MTUs, and pledge

2022-11-21 Thread Claudio Jeker
On Sun, Nov 20, 2022 at 05:28:06PM -0500, Stefan R. Filipek wrote: > My router advertises its MTU over ICMPv6 router advertisements. It's > somewhat large (9216), and exceeds the hardware capabilities of my > OpenBSD system's rge interface (9194). This results in a bunch of > noisy log messages

Re: bgpd VPNs broken in kroute with 7.2?

2022-11-04 Thread Claudio Jeker
On Fri, Nov 04, 2022 at 10:18:26AM +0300, Bars Bars wrote: > Hi, Claudio! > > It seems there were at least two issues: > 1. VPN routes were never installed to fib (with errno 'Network is > unreachable' > returned when send_rtmsg tried to writev them) > 2. kroute_remove brakes when prefix withdraw

Re: bgpd VPNs broken in kroute with 7.2?

2022-11-03 Thread Claudio Jeker
On Mon, Oct 31, 2022 at 09:54:12AM +0300, Bars Bars wrote: > Hi! > > Just upgraded to 7.2 and bgpd began to crash with VPNs, not immediately > but in 1 minute after daemon start (probably the issue happens > when prefix withdraw received or so, and rde goes to change the fib, not > sure). > If

Re: Triple booting Windows/Debian/OpenBSD?

2022-11-01 Thread Claudio Jeker
On Tue, Nov 01, 2022 at 02:20:38PM +, Ottavio Caruso wrote: > Op 01/11/2022 om 13:16 schreef Claudio Jeker: > > On Tue, Nov 01, 2022 at 12:42:10PM +, Maurice McCarthy wrote: > > > I think you are asking for a world of grief. > > Not really, just be careful when inst

Re: Triple booting Windows/Debian/OpenBSD?

2022-11-01 Thread Claudio Jeker
On Tue, Nov 01, 2022 at 12:42:10PM +, Maurice McCarthy wrote: > I think you are asking for a world of grief. Not really, just be careful when installing any additional OS on a multiboot system. They like to trample on each others toes. In the OpenBSD installer be careful and do not select

Re: bgpd loadbalancing feature

2022-08-13 Thread Claudio Jeker
On Sat, Aug 13, 2022 at 08:27:53AM +0200, Holger Glaess wrote: > hi > > > i need a little bit help to understand how i can check if > > the new openbgpd do the loadbalancing > > > wendehals# bgpctl sh nei 172.16.2.251 > BGP neighbor is 172.16.2.251, remote AS 65010 >   BGP version 4, remote

Re: bridge rules are evaluated different compared to pf?

2022-07-26 Thread Claudio Jeker
On Tue, Jul 26, 2022 at 11:18:06AM +0300, Cristian Danila wrote: > Good day! > I hope someone could clarify if the following behavior is > expected in a bridge configuration > I have following rules added in hostname.bridge0 > > --- > #this will

Re: RFC7432 (EVPN)

2022-07-18 Thread Claudio Jeker
On Sun, Jul 17, 2022 at 09:13:52PM +0200, Holger Glaess wrote: > hi > > > is there an plan or think about it to implement this RFC ? > There is no plan to do this work. It will requirer a good amount of work to make this proper. There is currently no way to program the LUT of veb(4) /

Re: OpenBGPD via (WG?) Tunnel Not Learning Routes

2022-07-13 Thread Claudio Jeker
On Wed, Jul 13, 2022 at 11:01:09AM -, Stuart Henderson wrote: > On 2022-07-13, Tobias Fiebig wrote: > > Heho, > > > > When doing what i described in my message, I get the below messages. > > > > When I set static routes, packet forwarding works fine, i.e.: > > > > gw02.dus01.as59645.net ~ #

Re: Cron running at 99% CPU for seemingly no reason

2022-06-27 Thread Claudio Jeker
On Sun, Jun 19, 2022 at 01:26:27PM +0200, Stephan Mending wrote: > Hi, > it crashed again. > Here is the dmesg, this time the kernel had debugging symbols enabled. > > [...] > ic0 at ichiic0 > spdmem0 at iic0 addr 0x50: 2GB DDR3 SDRAM PC3-12800 SO-DIMM > isa0 at pcib0 > isadma0 at isa0 > vga0

Re: Resizing encrypted disk

2022-06-25 Thread Claudio Jeker
On Sun, Jun 26, 2022 at 04:25:56AM +0100, Chris Narkiewicz wrote: > I have a network-attached block device that is used > as an encrypted device: > > bioctl -c C -l /dev/sd1a -p /keydisk softraid0 > > Underlying volume is about to be resized, but I can't resize > the decrypted volume. Here is

Re: tail(1) with multiple FIFOs

2022-06-09 Thread Claudio Jeker
On Thu, Jun 09, 2022 at 02:34:27PM +0200, Martijn van Duren wrote: > The "problem" is that a FIFO without data hangs on open(2), until data > is available, the same goes for the initial read of the file. > > We could work around this by adding the O_NONBLOCK flag to a separate > open(2) call, but

Re: Cron running at 99% CPU for seemingly no reason

2022-05-15 Thread Claudio Jeker
On Sun, May 15, 2022 at 12:06:33PM +0200, Stephan Mending wrote: > Hi *, > I've got a system running -current that keeps crashing on me every couple of > days. > Output of ddb: > > Connected to /dev/cuaU0 (speed 115200) > > ddb{0}> show panic > the kernel did not panic > ddb{0}> show uvm >

Re: Cron running at 99% CPU for seemingly no reason

2022-05-15 Thread Claudio Jeker
On Sun, May 15, 2022 at 12:06:33PM +0200, Stephan Mending wrote: > Hi *, > I've got a system running -current that keeps crashing on me every couple of > days. > Output of ddb: > > Connected to /dev/cuaU0 (speed 115200) > > ddb{0}> show panic > the kernel did not panic > ddb{0}> show uvm >

Re: OpenBGPd: fatal in RDE: aspath_get: Cannot allocate memory

2022-04-04 Thread Claudio Jeker
On Tue, Mar 29, 2022 at 09:53:56AM +0200, Laurent CARON wrote: > Hi, > > I'm happily running several OpenBGPd routers (Openbsd 7.0). > > After having applied the folloxing filters (to blackhole traffic from > certain countries): > > include "/etc/bgpd/deny-asn.ru.bgpd" > include

Re: OpenBGPd: fatal in RDE: aspath_get: Cannot allocate memory

2022-04-04 Thread Claudio Jeker
On Mon, Apr 04, 2022 at 03:14:35PM +0200, Laurent CARON wrote: > > Le 01/04/2022 à 14:38, Claudio Jeker a écrit : > > > > The numbers look reasonable with maybe the exception of prefix and BGP > > path attrs. Unless this system is pushing or pulling lots of full fe

Re: OpenBGPd: fatal in RDE: aspath_get: Cannot allocate memory

2022-04-01 Thread Claudio Jeker
On Thu, Mar 31, 2022 at 09:06:05PM +0200, Laurent CARON wrote: > Le 29/03/2022 à 12:10, Claudio Jeker a écrit : > > I doubt it is the filters. You run into some sort of memory leak. Please > > monitor 'bgpctl show rib mem' output. Also check ps aux | grep bgpd output > >

Re: OpenBGPd: fatal in RDE: aspath_get: Cannot allocate memory

2022-03-29 Thread Claudio Jeker
On Tue, Mar 29, 2022 at 09:53:56AM +0200, Laurent CARON wrote: > Hi, > > I'm happily running several OpenBGPd routers (Openbsd 7.0). > > After having applied the folloxing filters (to blackhole traffic from > certain countries): > > include "/etc/bgpd/deny-asn.ru.bgpd" > include

Re: httpd HTTP/2 and HTTP/3 support

2022-01-03 Thread Claudio Jeker
On Fri, Dec 31, 2021 at 09:36:54AM -, Stuart Henderson wrote: > On 2021-12-31, Georg Pfuetzenreuter wrote: > > Hi, > > I searched but couldn't find any recent threads. > > Does httpd support HTTP/2? > > No. > > > Is support for the upcoming HTTP/3 planned? > > guessing but I think this

Re: Profiling ifconfig

2021-12-16 Thread Claudio Jeker
On Thu, Dec 16, 2021 at 03:55:43PM +0800, Vladimir Nikishkin wrote: > Hello, everyone > > Recently I had a problem: my system is losing network connectivity, > although the interface (vio0 on KVM) seemed up. Restarting the > connection with `ifconfig vio0 down` and `ifconfig vio0 up` restores the

Re: bgpd, announce to ibgp from 2 routers, prefixes only show up from 1

2021-11-30 Thread Claudio Jeker
On Mon, Nov 29, 2021 at 10:38:21PM +0100, Sebastian Benoit wrote: > Stuart Henderson(s...@spacehopper.org) on 2021.11.13 00:11:08 +: > > I have a pair of -current routers running bgpd (let's call them rtr-a > > and rtr-b) on a subnet which also has some vpn gateways and firewalls. > > > >

Re: Put non-NULL pledge abort in the man page

2021-11-25 Thread Claudio Jeker
On Thu, Nov 25, 2021 at 04:55:23AM -0600, Luke Small wrote: > I ran ktrace. Kdump said the last thing it did was try to load > /usr/libexec/ld.so > > To main(), before the unveil pledge is dropped, I added: > > if (unveil("/usr/libexec/", "rx") == -1) > err(1, "unveil,

Re: Dynamic routing and REJECT,LLINFO,CLONED routes

2021-11-07 Thread Claudio Jeker
On Sun, Nov 07, 2021 at 12:46:43PM +0100, Denis Fondras wrote: > I came up with this diff to overcome my problem. > > Index: rtable.c > === > RCS file: /cvs/src/sys/net/rtable.c,v > retrieving revision 1.75 > diff -u -p -r1.75

Re: Asyncronous IO

2021-11-04 Thread Claudio Jeker
On Wed, Nov 03, 2021 at 03:37:01PM +, cho...@jtan.com wrote: > I program on OpenBSD and am writing a library which presents an API > for IO. POSIX defines an API[*] for asyncronous IO and I would like > my code to support it but this API is unavailable in OpenBSD. > > Is the lack intentional

Re: httpd(8) - Internal Server error (500) on invalid request

2021-10-21 Thread Claudio Jeker
On Thu, Oct 21, 2021 at 04:38:43PM +0200, Sebastian Benoit wrote: > J. K.(openbsd.l...@krottmayer.com) on 2021.10.21 14:10:16 +0200: > > Another question, to httpd(8). Tried the following query. > > Used an invalid HTTP Version number (typo). > > > > $ telnet 10.42.42.183 80 > > [Shortened] > >

Re: httpd(8) - Internal Server error (500) on invalid request

2021-10-21 Thread Claudio Jeker
On Thu, Oct 21, 2021 at 01:21:33PM +0200, Sebastian Benoit wrote: > J. K.(openbsd.l...@krottmayer.com) on 2021.10.21 11:55:47 +0200: > > Hi, > > > > I don't know if this is a real issue from OpenBSD's httpd(8). > > Tried some requests to httpd(8) for the purpose of education. > > > > Simple

Re: problems with outbound load-balancing (PF sticky-address for destination IPs)

2021-09-29 Thread Claudio Jeker
e and 25% of your traffic will be dropped. This is another advantage of multipath routing. Cheers -- :wq Claudio > Thanks for your time, Andy. > > On Wed, Sep 29, 2021 at 5:21 PM Claudio Jeker > wrote: > > > On Wed, Sep 29, 2021 at 02:17:59PM +1000, Andrew Lemin wrote: > &g

Re: problems with outbound load-balancing (PF sticky-address for destination IPs)

2021-09-29 Thread Claudio Jeker
On Wed, Sep 29, 2021 at 02:17:59PM +1000, Andrew Lemin wrote: > I see this question died on its arse! :) > > This is still an issue for outbound load-balancing over multiple internet > links. > > PF's 'sticky-address' parameter only works on source IPs (because it was > originally designed for

Re: Blog comparing open source BGP stacks

2021-08-25 Thread Claudio Jeker
On Wed, Aug 25, 2021 at 02:01:26PM +0200, Kristjan Komlosi wrote: > On 24. 08. 21 21:59, Laura Smith wrote: > > Would be interesting to hear comments from the community on this comparison > > : https://elegantnetwork.github.io/posts/followup-measuring-BGP-stacks/ > > > > N.B. For the record,

Re: WireGuard host crashes roughly every week

2021-08-04 Thread Claudio Jeker
On Wed, Aug 04, 2021 at 08:36:07PM +1000, Matt Dunwoodie wrote: > On Tue, 3 Aug 2021 13:02:15 -0500 > "Matt P." wrote: > > > Hi Stuart! > > > > Your advice lead me to discover, the issue happens only with the > > "PersistantKeepalive = 25" option I had enabled on each wg-quick > > peer. Looks

Re: iked choosing the wrong policy?

2021-07-27 Thread Claudio Jeker
On Tue, Jul 27, 2021 at 07:32:09AM -, Stuart Henderson wrote: > On 2021-07-27, Vladimir Nikishkin wrote: > > Hello, everyone. > > > > This is my iked.conf: > > > > ``` > > ikev2 "for-phone" passive esp \ > > from any to 10.0.3.2/32 \ > > local egress peer any \ > ... > >

Re: DHCP non-issues

2021-07-20 Thread Claudio Jeker
On Tue, Jul 20, 2021 at 08:53:03AM -, Stuart Henderson wrote: > On 2021-07-19, jungle Boogie wrote: > > On Mon, 19 Jul 2021 at 04:48, Christian Weisgerber > > wrote: > >> > >> Look guys, it's simple. > >> > >> If you want IPv6 (SLAAC) autoconfiguration, you set "inet6 autoconf" > >> for

Re: VLANs isolation

2021-07-13 Thread Claudio Jeker
On Tue, Jul 13, 2021 at 11:34:28AM +0200, Radek wrote: > Hello, > I'm going to build a router with +40 vlans. > I need to block access from every vlan to each other (and then enable traffic > between certain vlans as needed). > > How can I do this? Is there any one liner pf block rule to do

Re: rpki-client and BLACKHOLE routes

2021-06-23 Thread Claudio Jeker
On Wed, Jun 23, 2021 at 11:40:25AM +0200, Hrvoje Popovski wrote: > Hi all, > > fist of all, thank you for rpki-client, it's so easy to use it and to > get the job done. > I'm playing with rpki-client and denying ovs invalid statement and I've > seen that with default ovs config statement (deny

Re: EACCES of UDP packet

2021-06-22 Thread Claudio Jeker
On Tue, Jun 22, 2021 at 04:48:26PM +0800, Siegfried Levin wrote: > > Why have you chosen to hide information that may be useful in debugging > > your problem? > > I’m truly sorry for the inconvenience but I do have some concerns of security > and privacy. I confirm it is not a broadcast address

Re: Prometheus on OpenBSD - does it work?

2021-06-15 Thread Claudio Jeker
On Tue, Jun 15, 2021 at 04:24:08PM +0200, Julien Pivotto wrote: > Hello, > > I am a Prometheus maintainer and we have received a bug regarding > Prometheus - prometheus would no longer work on OpenBSD since we > introduced MMAP: > > https://github.com/prometheus/prometheus/issues/8877 >

Re: Howto measure pps at forwarding plane

2021-06-10 Thread Claudio Jeker
On Thu, Jun 10, 2021 at 09:23:03AM -, Stuart Henderson wrote: > On 2021-06-10, Valdrin MUJA wrote: > > Hello, > > > > I'm trying to figure out how much packets are being forwarded on my OpenBSD > > firewall. > > Here a small script i wrote. > > > > > > #!/bin/sh > > > > > > VAL1=`netstat -s

  1   2   3   4   5   6   7   8   9   10   >