schmonz.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Search results for tag #NetBSD

Jay 🚩 :runbsd: boosted

[?]R.L. Dane :Debian: :FreeBSD: :OpenBSD: :NetBSD:🍵 :MiraLovesYou: [he/him/my good fellow] » 🌐
@rl_dane@polymaths.social

@moses_izumi @hikari @AnachronistJohn

#NetBSD definitely deserves some love for being one of the very few, and perhaps the most featureful Operating Systems that has a strong #NOAi stance.❤️‍🔥

I definitely want to start supporting them. I need to get on that.

    Jay 🚩 :runbsd: boosted

    [?]Dragon of BSDCafe :freebsd: [he/him] » 🌐
    @evgandr@mastodon.bsd.cafe

    Kinda postmortem:

    1) The maximal log size before rotation and count of gzipped logs to store should be increased in the newsyslogd configuration. This should be applied to any service, which is looking into the void^WInternet. So, I will not loss log records, related to the start of attack…

    2) Also, Asterisk log should be added to newsyslogd configuration first. It weren't added here, so *.log files became too big (> 1 Gb) and of course fail2ban ate a lot of memory while parsing these big logs. If they were rotated properly, then fail2ban will not eat so much memory, parsing small enough files.

    3) Since start of attack in logs were lost, then I could only imagine possible root cause of an attack. By default, any IP, which once failed to provide the proper credentials to login somewhere in my kitchen server, is banned immediately and forever.
    But somehow those attackers managed to use just 2 IPs to make an attack and they weren't banned before manual intervention :drgn_confused:

    According to fail2ban logs they were banned, but they were obviously not banned by npf. So, I think, they started attack right in time when my blacklists were successfully updated and npf was reloading — as a result their IPs appeared as "banned" in the fail2ban, but the fail2ban failed to ban them via npf, so "IRL" their IPs still weren't banned. Time to revisit my script to update blacklists :drgn_wrench:

    4) Looks like I need to install some Intrusion Detection System (possibly snort :drgn_think: since it is mature enough). It isn't good to rely only on one mechanism (fail2ban + blacklists + npf) to protect my precious machine.

      #netbsd boosted

      [?]Dragon of BSDCafe :freebsd: [he/him] » 🌐
      @evgandr@mastodon.bsd.cafe

      Kinda postmortem:

      1) The maximal log size before rotation and count of gzipped logs to store should be increased in the newsyslogd configuration. This should be applied to any service, which is looking into the void^WInternet. So, I will not loss log records, related to the start of attack…

      2) Also, Asterisk log should be added to newsyslogd configuration first. It weren't added here, so *.log files became too big (> 1 Gb) and of course fail2ban ate a lot of memory while parsing these big logs. If they were rotated properly, then fail2ban will not eat so much memory, parsing small enough files.

      3) Since start of attack in logs were lost, then I could only imagine possible root cause of an attack. By default, any IP, which once failed to provide the proper credentials to login somewhere in my kitchen server, is banned immediately and forever.
      But somehow those attackers managed to use just 2 IPs to make an attack and they weren't banned before manual intervention :drgn_confused:

      According to fail2ban logs they were banned, but they were obviously not banned by npf. So, I think, they started attack right in time when my blacklists were successfully updated and npf was reloading — as a result their IPs appeared as "banned" in the fail2ban, but the fail2ban failed to ban them via npf, so "IRL" their IPs still weren't banned. Time to revisit my script to update blacklists :drgn_wrench:

      4) Looks like I need to install some Intrusion Detection System (possibly snort :drgn_think: since it is mature enough). It isn't good to rely only on one mechanism (fail2ban + blacklists + npf) to protect my precious machine.

        #netbsd boosted

        [?]Dr. Brian Callahan [He/Him] » 🌐
        @bcallah@bsd.network

        By the way, our first two publications on evaluating mitigations are out. Both of these papers evaluate some amd64 anti-ROP mitigations: specifically changing the register selection order and semantically equivalent rewriting of instructions that may produce a potential polymorphic gadget instruction. This tracks a paper by mortimer@ back in 2019 at AsiaBSDCon.

        The TL;DR is "OpenBSD can shrink binaries a little and gain a little performance without any security loss simply by reverting these mitigations." The mitigations did not hold up to independent evaluation.

        The first paper did an exact 1:1 port of these mitigations to FreeBSD and found that register reallocation eliminates only about 0.3% of unique gadgets, for a 0.5% increase in binary size (mortimer@ claimed 6% reduction and "entirely free"). It is useless at best but more likely actively detrimental, as it produces a false sense of security. It also found the instruction rewriting reduces unique gadgets by about 3.5% with a binary size increase of about 1.8% (mortimer@ claimed 5% reduction with 0.15% binary size increase).

        We then did a separate implementation of the instruction rewriting mitigation to GCC in the second paper. Our GCC implementation does the older <xchg; op; xchg> dance, as that's what mortimer@'s paper described. This is way worse; producing about a 3% performance hit for no security benefit at all.

        The only part of both mitigations worth saving is for basic arithmetic, OpenBSD LLVM now takes advantage of the fact that basic arithmetic has two forms. For example, the newer instruction rewriting mitigation turns
        addq %rax, %rbx (48 01 c3)
        into
        {load} addq %rax, %rbx (48 03 d8)

        The new instruction rewriting mitigation is genuinely free in terms of binary size and execution speed, but doesn't move the security needle, so this one can stay as it is harmless. Other rewritings still have the flaw of increasing binary size and reducing performance for no security benefit.

        Anyhow feel free to read the papers:
        ieeexplore.ieee.org/abstract/d
        researchgate.net/publication/4

          #netbsd boosted

          [?]R.L. Dane :Debian: :FreeBSD: :OpenBSD: :NetBSD:🍵 :MiraLovesYou: [he/him/my good fellow] » 🌐
          @rl_dane@polymaths.social

          New #blog #post: Package Manager Tier List

          https://rldane.space/package-manager-tier-list.html

          1521 words

          Note: this is a very off-the-cuff tier list, using speed as the main qualifier, but the article explains exceptions to that as it goes on.

          cc: my wonderful #chorus: @joel @dm @sotolf @thedoctor @pixx @orbitalmartian @adamsdesk @krafter @roguefoam @clayton @giantspacesquid @Twizzay @stfn

          (I will happily add/remove you from the chorus upon request! :)

          #rlDaneWriting #blost #Linux #BSD #RunBSD #FreeBSD #OpenBSD #NetBSD #Debian #Arch #pacman #AUR #Fedora #homebrew #flatpak #snap #OpenSuSE #RPM

          (Edit 2026-07-17: removed stray "DeadLikeMe" hashtag that had been left over from the previous post. Oops! ;)

            [?]Jay 🚩 :runbsd: » 🌐
            @jaypatelani@bsd.network

            NetBSD turns 33 this Sunday! 🚩

            To celebrate 33 years of clean code, portability, and zero bloat, Challenging the rest of the fediverse to help hit this year's funding goals.

            Also do drop a screenshot of your uptime, uname -a, or a pic of the weirdest hardware you've got running NetBSD right now. (RockPro64 NPF routers or Pi's hooked up to retro CRTs highly encouraged).

            Throw some money at the developers keeping the real UNIX alive:

            netbsd.org/donations/

              7 ★ 1 ↺
              Jay 🚩 :runbsd: boosted

              [?]Amitai Schleier [he/they] » 🌐
              @schmonz@schmonz.com

              Macmini6,2

              fastfetch output

              Alt...fastfetch output

                6 ★ 0 ↺

                [?]Amitai Schleier [he/they] » 🌐
                @schmonz@schmonz.com

                2018 Mac mini was already being weird. Then macOS Tahoe dropped support. Usually I'd want NetBSD. But the only option was Linux, and it's pretty darn okay.

                Here's my setup: https://schmonz.com/2025/11/12/small-macs/

                (Writing... muscles... loosening.)


                  [?]Bitslingers-R-Us » 🌐
                  @AnachronistJohn@zia.io

                  #NetBSD #pkgsrc 2025Q3 is here!

                  Here are the final pkgsrc-2025Q2 package counts:

                  9.0: earmv4 4230 (still working on gcc 13)
                  9.0: m68k 3418 (+46)

                  10.0: aarch64eb 24677 (finished)
                  10.0: alpha 18926 (+564 - finished)
                  10.0: earmv4 12678 (+573)
                  10.0: m68k 9929 (+127)
                  10.0: sh3el 10669 (+3)
                  10.0: sparc64 15637 (+53)
                  10.0: vax 9298 (+54)

                  current: riscv64 11615 (+672)

                    benz boosted

                    [?]Parade du Grotesque 💀 » 🌐
                    @ParadeGrotesque@mastodon.sdf.org

                    4 ★ 0 ↺

                    [?]Amitai Schleier [he/they] » 🌐
                    @schmonz@schmonz.com

                    Ancient serving home stereo AirPlay.

                    I'd prefer : https://schmonz.com/2024/06/07/small-arms/

                    Staged latest shairport-sync for . Builds on NetBSD, . Normally I'd commit, wait for evbearmv6hf-el binary package, forget.

                    Trying something new today: https://cdn.netbsd.org/pub/pkgsrc/current/pkgsrc/doc/HOWTO-use-crosscompile

                      #netbsd boosted

                      [?]Dr. Brian Callahan [He/Him] » 🌐
                      @bcallah@bsd.network

                      Jay 🚩 :runbsd: boosted

                      [?]Parade du Grotesque 💀 » 🌐
                      @ParadeGrotesque@mastodon.sdf.org

                      All right, pkgsrc 2025Q1 has just been announced on the mailing lists.

                      It's not even on pkgsrc.org yet! 😉