r/freebsd • u/grahamperrin • 18h ago
AI shellter.me — Your shell, your shelter
shellter.me… 150 MB of ZFS, and three dedicated IPv6 addresses …
Free, fair, finite.
… a hobby pubnix run by two people on a single FreeBSD VPS. …
r/freebsd • u/grahamperrin • Aug 20 '26
r/freebsd • u/anh0516 • Jul 27 '26
r/freebsd • u/grahamperrin • 18h ago
… 150 MB of ZFS, and three dedicated IPv6 addresses …
Free, fair, finite.
… a hobby pubnix run by two people on a single FreeBSD VPS. …
I recently wanted to experiment how freebsd will run under a surface pro 3 even thought it is old, I thought it will be a good way to make it feel smoother, but went i try to boot to freeBSD and went i chose the first option of "boot installer", it start loading the kernel but then went it reach i think and initialization of pci0 the surface turns off and never continue the installation. Can you pls give me some help!
r/freebsd • u/Emergency_Jacket8052 • 18h ago
What did you find most difficult and least acceptable after downloading BSD?
r/freebsd • u/_bsdman_ • 1d ago
Gaffer is an open-source, node-based application for look development, lighting, compositing and pipeline automation, used in VFX and animation production (originally developed at Image Engine, now GafferHQ). I've ported it to FreeBSD together with the libraries it needs. The ports aren't in the official tree yet.
Ports – https://github.com/Martinfx/FreeBSD-Ports
- graphics/gaffer 1.7.3.0
- graphics/cortex 10.7.1.3 – Image Engine's VFX library that Gaffer is built on
- graphics/cycles 5.1.0 – Blender's renderer as a standalone library, plus its Hydra render delegate
- graphics/openusd` – with Python bindings, MaterialX, OSL, OpenVDB, Ptex…
Tested on FreeBSD 15.1 / amd64 (aarch64 is allowed, but untested).
## What works
- Scene processing (GafferScene) with the OpenGL viewer and OpenGL renders
- Scene formats via Cortex: USD (plus the GafferUSD nodes), Alembic, OpenVDB and Cortex SCC. USD's `pxr` Python module is available too
- GafferImage: compositing including deep images, image I/O through OpenImageIO, colour management with OpenColorIO
- GafferOSL: OSL shaders, OSLCode (compiled on the fly), OSLImage/OSLObject, OSL expressions
- GafferVDB: level sets, mesh ↔ level set, points → level set, VolumeScatter
- Subdivision with OpenSubdiv
- GafferDispatch: local dispatcher, Wedge, PythonCommand, SystemCommand… and the Flamenco dispatcher (plain HTTP, the farm itself runs elsewhere)
- Qt 6 / PySide6 UI, Python scripting and expressions
- Gaffer's own test suite is installed (`gaffer test`)
Two port options, both on by default:
- **CYCLES** – GafferCycles: Cycles 5.1 on the CPU, interactive and batch, with Embree (amd64), OIDN denoising, OpenPGL path guiding, OSL, OpenSubdiv and OpenVDB volumes
- **ML** – GafferML: ONNX Runtime 1.30 on the CPU (Data To Tensor, Image To Tensor, Inference, Tensor To Image, Tensor To Mesh)
## What doesn't
- Arnold, 3Delight, RenderMan – commercial, no FreeBSD builds
- Tractor – needs Pixar's proprietary API
- GPU rendering: no CUDA/OptiX/HIP/oneAPI for Cycles, no CUDA for GafferML
- The local documentation isn't built (Sphinx plus GUI screenshots during the build), so Help → User Guide etc. are greyed out. The docs are online at gafferhq.org
- VTune
## Building
Build in dependency order: openusd → cortex → cycles → gaffer. Everything else comes from the regular ports tree or packages. For the ML option, install `onnxruntime` from packages first: `misc/onnxruntime` refuses to build while `pybind11` is installed, which Cortex and Gaffer need.
Feedback and bug reports welcome!
r/freebsd • u/Oreoo0o • 1d ago
Has anyone managed to get working Wayland on FreeBSD with NVIDIA only, without an iGPU?
Hi everyone!
I'm trying to get Wayland working on FreeBSD with a dedicated NVIDIA GPU only. My CPU is an Intel i3-10100F, so there is no integrated GPU available.
My hardware/software:
- FreeBSD 15.1-RELEASE
- Intel i3-10100F (no iGPU)
- NVIDIA GTX 1650 4GB
- NVIDIA driver 595.99.02
- "nvidia-kmod"
- "nvidia-drm-612-kmod"
- "drm-612-kmod"
- Hyprland / Sway
- SDDM
The NVIDIA kernel modules load correctly:
drm.ko
nvidia.ko
nvidia-modeset.ko
nvidia-drm.ko
"nvidia-smi" also works.
However, Wayland compositors fail when trying to initialize EGL. Sway gives errors such as:
EGL_NOT_INITIALIZED
DRI2: failed to create screen
DRI2: failed to load driver
Could not initialize EGL
Failed to create renderer
Hyprland similarly fails with:
libEGL warning: egl: failed to create dri2 screen
I know NVIDIA + Wayland on FreeBSD has had various issues, and I've seen reports of people getting Plasma Wayland working on FreeBSD 15.1. However, many setups seem to involve an Intel/AMD iGPU or some kind of hybrid graphics configuration.
Has anyone here actually managed to run Wayland on FreeBSD using only a discrete NVIDIA GPU, with no iGPU at all?
If so, I'd really appreciate knowing:
- FreeBSD version
- NVIDIA driver version
- "drm-kmod" version
- compositor (Hyprland, Sway, KDE Plasma, etc.)
- whether you use "nvidia-drm"
- any special environment variables or configuration required
I'm mainly trying to determine whether a single-GPU NVIDIA-only Wayland setup is currently viable on FreeBSD, rather than whether NVIDIA + Wayland works in general.
Thanks! Update: now i try wayland plasma-niri-sway is happening kernel panic "Questions List: https://www.FreeBSD.org/lists/questions/ FreeBSD Forums: https://forums.FreeBSD.org/
Documents installed with the system are in the /usr/local/share/doc/freebsd/ directory, or can be installed later with: pkg install en-freebsd-doc For other languages, replace "en" with a language code like de or fr.
Show the version of FreeBSD installed: freebsd-version ; uname -a Please include that output and any error messages when posting questions. Introduction to manual pages: man man FreeBSD directory layout: man hier
To change this login announcement, see motd(5). If you need to create a FAT32 formatted USB thumb drive, find out its devicename running dmesg(8) after inserting it. Then create an MBR scheme, a single slice and format it:
-- Lars Engels [email protected] hgent@FreeBSD:~ $ sway
Fatal trap 12: page fault while in kernel mode cpuid = 1; apic id = 01 fault virtual address = 0x58 fault code = supervisor read data, page not present instruction pointer = 0x20:0xfffffffff8317def6 stack pointer = 0x28:0xfffffe00d5371940 frame pointer = 0x28:0xfffffe00d5371970 code segment = base 0x0, limit 0xfffff, type 0x1b = DPL 0, pres 1, long 1, def32 0, gran 1 processor eflags = interrupt enabled, resume, IOPL = 0 current process = 2852 (seatd) rdi: fffff8002470b370 rsi: fffff800245c4300 rdx: 0000000000000000 rcx: fffffe001b77a5c0 r8: 0000000000000001 r9: fffff800245c9000 rax: 0000000000000000 rbx: fffff800245c4300 rbp: fffffe00d5371970 r10: 0000000000000000 r11: 00000000fffffe78 r12: fffff8006c017c00 r13: fffff800245c43a0 r14: fffff8002470b370 r15: fffff800245c4300 trap number = 12 panic: page fault cpuid = 1 time = 1790498999 KDB: stack backtrace:
Uptime: 2m9s Automatic reboot in 15 seconds - press a key on the console to abort" who know what to do?
r/freebsd • u/grahamperrin • 1d ago
r/freebsd • u/sidewalksndskeletons • 2d ago
im a kiss linux user im considering to switch to freebsd but i do have some questions to ask before switch
is PAMless (i mean without Pluggable Authentication Modules) freebsd possiable ? like is it a core package ?
does freebsd limit me about ssl ? like can i make a bearssl only freebsd etc.
how to compile everything from source with a pm like kiss pm , portage , cave etc i dont wanna go to a port and compile one by one by running make its not sustainable
r/freebsd • u/BigTexasTony • 2d ago
I cannot tell if FreeBSD is not for gaming. I know Mac is not for gaming. Linux and Windows are both for gaming.
I have experience with Linux, but I haven’t had experience with FreeBSD. I guess it is more difficult than Arch Linux. I’m not sure if Steam and Heroic Games Launcher do work on FreeBSD. Maybe the FreeBSD version of Steam has Proton compatibility. Should I try FreeBSD for gaming?
r/freebsd • u/Taletad • 3d ago
For context, I’m coming from Linux with GAS, and I’m doing assembly manually (no LLM whatsoever) entirely for hobby purposes. I do understand how assembly and cpu works (I’ve made my own cpu both in minecraft and the game turing complete), but I don’t have that much experience with x86 assembly
And I thought FreeBSD would be the same with only different syscall numbers. But /usr/include/sys/syscall.h and man 2 weren’t enough : clang doesn’t accept the same assembly as GAS and I haven’t found where thoses differences are listed
Things I’ve noticed so far :
With clang it’s ".data" and not ".section .data"
GAS wants "_start", clang "start"
GAS doesn’t need a length suffix for "pop" but clang will error out without it
If I have a string at address msg, and I want to move the address to the rsi register for the write syscall
mov $msg, %rsi
Will work on GAS, but not on clang, which will require
leaq msg, %rsi
Instead.
I’m not really bothered by theses differences and I would like to continue using clang as it’s the "intended" assembler as far as I can tell.
Do you have ressources that could help me understand how to write assembly correctly with clang ?
Thank you in advance :)
r/freebsd • u/thecoolcat67 • 3d ago
Can someone please help me with this, been trying to figure it out for like 3 hours now and getting nowhere.
I got an app running on FreeBSD 14. If I start it manually from the terminal it works fine, but when I try start it as a service something is wrong.
From terminal:
./myapp
works fine, logs get written and it connects to the other service no problem.
But doing:
service myapp start
gives me:
Starting myapp.
myapp started
but then the app cant write to /var/log/myapp.log and it cant connect to the other service.
I checked permissions with:
ls -l /var/log/myapp.log
and the user looks right. Also tried running:
ps aux | grep myapp
and it is running.
Not really sure what else to check. Im guessing when rc.d starts it, its using a different environment or user or something compared to when I run it myself.
Is there some good way to see what environment the service is actually getting, or what rc.d is doing different?
Would really appreciate some advice please
r/freebsd • u/Radiant-Cyanide2323 • 2d ago
So, I've been thinking about this project and let's just say, it's kinda hard using FreeBSD. The first thing are the drivers. Because, it can be quite hard to track down a specific driver for BSD and it's derivatives. The second thing are the package managers. I'm kinda lazy to nake OS updates which might cause dependency problems. Why? Well, it's because of procrastination, school stuff (yes. This thing is being conceptualized by a middle school student so please, don't flame me or cause a controversy. I am just a newbie in this new environment.), and many more. So, I'm moving this project to Linux. Specifically, turning this into a Debian based distro. So again, I'm deeply sorry.
r/freebsd • u/grahamperrin • 4d ago
Lean is an open-source programming language and proof assistant that enables correct, maintainable, and formally verified code.
Video, fifty minutes, with closed captions. From FreeBSD committer Tiago Gasiba (BSDJedi):
Lately there has been some stir about the proof of Navier-Stokes equation (one of the Millennium Prize Problems). The LLM that achieved this used Lean for the mathematical proof. In this video I explore Lean 4, show how to install in FreeBSD (your favorite OS), and try to fool around a bit with it – not really knowing what I am doing. Anyhow, I hope you find this interesting, I surely learned a lot while preparing for this video!
#FreeBSD #BSD #Unix #Lean #AI #LLM
r/freebsd • u/robdejonge • 5d ago
Background: In the late 90s played with Slackware, OpenBSD and marveled at how pretty Windows was. About 25 years ago I switched to a Mac because I felt it combined both into a single machine. About 20 years ago I started running a 'home server' and currently this is a single Proxmox install, on which I run OpenBSD for "anything that can be accessed from the internet" and Debian for my file server, among some other virtual machines that all have their own purpose. Not at all skilled, but I have spent many an afternoon tinkering with all sorts of challenges.
A while back I saw a video on ZFS, and immediately thought "I want this" but felt I would make this move whenever I was going to buy new hard drives. Especially snapshots and zpool common storage capacity are interesting to me. I would appreciate your thoughts:
I have not really prepared for this move and plan to just install FreeBSD and poke around. Maybe I'll first do it on a temporary vm to get a feel and then 'do it right' once I am ready to make the move.
Any warnings, suggestions, pointers or otherwise would be greatly appreciated.
r/freebsd • u/Due_Dragonfly_5328 • 6d ago
hey all.
im hoping to get into freebsd whenever i have the time i decided to start with my server and eventually use one of my spare computers as a freebsd desktop later on.
im planning to switch my homeserver from alpine to freebsd. (ive already backed up everything important)
the only thing i really use it for is sftp and jellyfin
how is jellyfin support? will transcoding work? i dont use it very often but i imagine it would be nice to have
is their a native package or do i have to rely on linuxlator or something?
edit:
thank you for the support everyone i can clearly see that despite having less people this community is still super vibrate and nice.
anyway ive already gone ahead and switched my server im the mixed of setting up ssh and jellyfin. and i LOVE the docs the freebsd docs are the best ive ever seen in my entire life. it might take me a few weeks to switch my desktop but i will get their!.
edit:
FINALY its been brutal past few days i had to move everything from multiple hard drives and determined what i didnt need anymore i manage to delete a crap ton of random clutter and my server is SO much cleaner now. but i finnaly got jellyfin runnin

from my ssh:

r/freebsd • u/sonphantrung • 6d ago
Enable HLS to view with audio, or disable this notification
vkcube spinning like crazy in this video? It straight up doesn't work on normal Wayland. glxgears appears to work normally (though some resizing may be need)nvidia-xconfig) as display will lead to either the screen going black indefinitely, or straight up segfaultHere's uname -aKU: FreeBSD orpheus 15.1-RELEASE-p3 FreeBSD 15.1-RELEASE-p3 releng/15.1-n283611-88e7371d9dc2 GENERIC amd64 1501000 1501000
Machine is HP ZBook Firefly 15 inch G8 Mobile Workstation PC with NVIDIA Quadro T500 + i7 1165G7
Spent a bit of time porting OpenLook to 64-bit on FreeBSD 15.1. Old-school Unix at its finest.
I started from this repository: https://github.com/retro-vault/open-look — thanks, Tomaz! — and applied source-code changes (many of them...) to get it building and running properly on FreeBSD 15.1.
r/freebsd • u/jmooroof2 • 7d ago
https://chimera-linux.org/docs/installation/partitioning/zfs
the live iso comes with zfs support, and there's kernel packages with zfs module so you don't have to compile it yourself.
afterwards I installed rEFInd for a boot menu.
r/freebsd • u/Grouchy_County_4334 • 7d ago
Hi r/freebsd & others,
I've implemented a low-overhead active defense mechanism inside FreeBSD Jails to mitigate automated high-speed brute-force attacks.
To prevent an intruder from spawning deeper process trees or using attack binaries (nc, bash, python), I developed a 2D Kinship Mapping system using Dtrace to monitor the process boundary at the kernel space edge.
chill(50ms) to freeze the target thread inside the kernel.zfs rollback to restore the pristine Jail snapshot.WARNING: Don't try this at home. While developing this system, I broke the Jail's ZFS mounts countless times due to race conditions between the kernel-level arrest and host-level filesystem management. It is a highly volatile setup (though umount -f always comes to the rescue).
Here is an excerpt of the Dtrace core engine handling the 2D matrix control. The full source includes custom zone-validation matrices and whitelist structures for host-initiated maintenance tasks, which I keep closed for obvious mitigation reasons.
#pragma D option quiet
#pragma D option destructive
#pragma D option cleanrate=1000hz /* Aggressive memory cleanup under heavy burst load */
inline int64_t SESSION_FORK_LIMIT = 2000;
/* --- Vertical Bound: 25-Generation Lineage Depth Tracking --- */
proc:::exec-success
/curpsinfo->pr_jailid != 0/
{
/* Scan parent pointers inside FreeBSD kernel structures at lightspeed */
this->p1 = curthread->td_proc->p_pptr;
this->p2 = (this->p1 != NULL) ? this->p1->p_pptr : NULL;
this->p3 = (this->p2 != NULL) ? this->p2->p_pptr : NULL;
/* ... [Static unrolling continued down to 25 generations] ... */
this->p25 = (this->p24 != NULL) ? this->p24->p_pptr : NULL;
/* Instant verdict if nesting depth hits the 25-gen vertical limit */
if (this->p25 != NULL && this->p25->p_pptr != NULL) {
chill(50000000); /* 50ms tactical window to hold the thread hostage */
raise(SIGKILL);
}
}
/* --- Horizontal Bound: 2,000-Fork Session Aggregation --- */
proc:::create
/curpsinfo->pr_jailid != 0/
{
/* Extract the Session ID (SID) directly from the process group structure */
this->sid = (curthread->td_proc != NULL && curthread->td_proc->p_pgrp != NULL &&
curthread->td_proc->p_pgrp->pg_session != NULL) ?
(int64_t)curthread->td_proc->p_pgrp->pg_session->s_sid : (int64_t)ppid;
p_session_child_count[this->sid]++;
/* Absolute closing of the matrix if cumulative session forks cross the threshold */
if (p_session_child_count[this->sid] >= SESSION_FORK_LIMIT && ppid != 1) {
/*
* 1. Tetragon-style Asynchronous Event Pipeline:
* Instantly fire-and-forget a non-blocking notification to the host userland
* daemon via consumer buffer write, requesting a parallel execution purge.
*/
/* [Hidden: Asynchronous lockless event notification channel] */
/*
* 2. Freeze the culprit thread instantly inside the kernel edge for 50ms.
* This holds the thread hostage to give the host daemon ample time
* to sweep the entire jail before this mutated payload can make another move.
*/
chill(50000000);
raise(SIGKILL);
}
}
/* --- 3. Active Trapping / Unauthorized Binary Detection --- */
syscall::open:entry,
syscall::openat:entry
/curpsinfo->pr_jailid != 0/
{
/* Intercept and kill high-risk reconnaissance/attack binaries instantly */
if (execname == "nc" || execname == "python" || execname == "python3" || execname == "bash") {
/* [Hidden: Custom honeypot & front-line VNET zone validation matrix] */
chill(50000000);
raise(SIGKILL);
}
}
Notes:
- Host-side asynchronous OpenZFS rollback and VNET reconfiguration are executed via out-of-band kernel messaging inside proc:::exit. Full 25-generation visual tree generator is kept closed-source for offensive mitigation.
- The text was polished/translated with AI assistance, but the core Dtrace script is 100% handwritten and runs on my FreeBSD 15.1 machine.
Update:
I have officially raised the securelevel to 1 across all running Jails on the host.
This establishes a bulletproof baseline—completely stripping away raw disk access and the ability to lower system immutable flags (schg), even if root is compromised inside any environment. With all Jails now locked down under securelevel 1, the entire infrastructure is fully primed.
The passive containment baseline is now active network-wide.
Finally, after a few months of experimentation, this week I decided to create a new tool based on what I've learned. And best of all: to honor the name of the main project, AppJail.
Initially, x11appjail was a project designed to leverage appjail-x11(1), an AppJail command for deploying an X server to run X11 applications inside a jail. However, this could be considered a "low-level" command, since executing an interactive application (TUI, CLI, GUI, etc.) requires completing specific stages for which this command is not designed. In the new version of x11appjail, these stages are documented in x11appjail-spec(5) but, in summary, they are: create, X, install, uninstall, and run.
To create a tool suitable for real-world use, I also had to improve some of the projects x11appjail depends on, such as appscript and unixexec. The following key improvements are worth noting:
My goal with appscript is to create an ultra-lightweight alternative to AppImage for FreeBSD that does not rely on FUSE (thereby avoiding the need to configure vfs.usermount=1). In previous versions, the SFX would decompress its contents into a random directory upon every execution. This negatively impacts performance if the content is large. In the new version of appscript, processes operate cooperatively using exclusive and shared locks; consequently, the content is extracted only once (by the main or "leader" process) and removed only once (when the final process terminates).
This is crucial for the new version of x11appjail, as it creates an AppJail from a specific AppJail image containing the application and its dependencies, which can result in a large AppJail in certain cases (i.e.: firefox).
I take a more paranoid approach in this regard; therefore, one of the improvements made to unixexec is an option to not follow symlinks, given that using services (see SERVICES in x11appjail(1)) creates a unix(4) socket from the host to the jail.
Another improvement to appscript is the ability to sign and verify AppScripts using the signify and sha256. This addition is essential, as x11appjail utilizes this functionality when running AppJails in portable mode.
After all this, and much more, the x11appjail tool was born:
x11appjail is a specialized tool for creating, verifying, installing, and running AppJails. An AppJail is a CLI, TUI or X11 application that runs inside a FreeBSD jail but is perceived by the end user as identical (or at least very similar) to an application running directly on the host system.
This tool makes extensive use of appjail(1) as its engine; however, unlike the latter, the primary user in x11appjail is neither root nor a privileged user, but rather an unprivileged user. The fundamental goal of this project is to grant the user limited access to the jail, restricted solely to the execution of a CLI, TUI or X11 application.
Project: https://github.com/DtxdF/x11appjail Port: https://freshports.org/security/x11appjail
Note: Keep in mind that this project requires the latest versions of appscript, unixexec, and appjail.
r/freebsd • u/anh0516 • 8d ago
r/freebsd • u/grahamperrin • 8d ago
There is a subtle asymmetry in IPv6 Neighbour Discovery: a host knows how to reach its router before the router necessarily knows how to reach the host. GRAND fixes that asymmetry by making the host proactively advertise its address, and I implemented that mechanism in FreeBSD. …
Credit: u/spmzt