Netlink Added to FreeBSD – Unmodified Linux IP(8) Correctly Works
cgit.freebsd.org
cgit.freebsd.org
This is something other BSD systems don't get. OpenBSD developers pretend Linux doesn't even exist, while FreeBSD is doing a great job catching up with Linux and doing all the Linux stuff so you can Linuxy Linux your Linux stuff in your Linux FreeBSD Linux. Linux.
I don't think that's quite right. OpenZFS is a thing that is consumed (and pushed forward) by both FreeBSD and Linux; FreeBSD isn't following Linux, they just both use the same thing. (Which is why it isn't named ZoL anymore; it isn't supposed to be Linux-centric)
>brings together developers from the Linux, FreeBSD, illumos, MacOS, and Windows platforms. OpenZFS is supported by a wide range of companies.
But if you work with Illumos or *BSD's for a extended time, Linux feels dirty and bloated..just not right anymore, if you like linux good...i am happy for you but i try to avoid linux if i can (obviously not always the case...OracleDB, DB2, k8s and so on).
>ZFS case though where they were the pioneers
No that was OpenSolaris...and i am still sad about it.
But Jails? I would say that was a real pioneering, whereas Solaris came a bit later with Zones and then a decade later Linux, you probably call that containers "a pure linux invention" today ;)
Containers are a pure Linux invention: BSD jails/Solaris zones are a different creature to Linux namespaces and cgroups - the lack of isolation is what enables composibility of containers
>the lack of isolation is what enables composibility of containers
Oh really? So containers are not isolated to each other...that's some news...bad ones ;)
BTW are you from a marketing department? ....composibility....stop with that stinking shit please.
Containers are considerably more than virtualization[1], which is why jails/zones/kvm never took off, but Docker did.
> Oh really? So containers are not isolated to each other...that's some news...bad ones
Indeed, containers make for very poor security boundaries. But there are upsides to sharing the same kernel.
> composibility....stop with that stinking shit please.
Are you unfamiliar with "composition" as a software design/architecture term? One can create and bundle (Docker) containers that work together and have a shared network interface in a way that jails can't. As an example, a reverse proxy + service backend + db working in concert.
1. Disk storage format, standardized packaging descriptor, repository.
Then giving a example that is a piece of cake for jails/zones...even in a concert.
Please educate yourself about zones, brandedzones and lxzones (for the solaris/illumos) or jails (for the bsd side) it's really interesting i can tell you, and additionally you don't sound like marketing blabla after that.
NetBSD has linux emulation, it is just OpenBSD that ignores Linux.
What is the point of this statement? OpenBSD devs are focused on OpenBSD. Importing Linux is not their goal. That is their choice. If you don't like it, then don't use it. People are allowed to do as they please.
Edit: If you need Linux use Linux. Stop demanding other OS's bloat their code base so you can run foreign code.
That's a virtual machine and not a compat layer.
So Wine is bad for Linux? Just asking....
BSD in general seems like a potential pivot into embedded space too, there's a lot of interesting electronics out there that run it
But I wouldn’t deliberately specialize: get a job working with BSD or Linux, and learn by doing; but keep an eye on the other kernels to see how they do it, and to get a broader basis for your skills.
I see it used by more and more very special cases (this one from Meta employee who did networking at Yandex before), but out of general usage.
Just over this year:
https://redd.it/x3ewxf - IBM Cloud ditches FreeBSD
https://redd.it/wf7h34 - Hetzner drops FreeBSD support
https://redd.it/ui9z0m - Digital Ocean doing the sameNot true, i send them an email about it, the Answer was kind of:
They had problem's with the Boot process on some machines, however you can send them the image and they will put i on a USB-Stick then open a web-terminal for you..for free, they still support FreeBSD but not in the Rescue-Media-Way.
BTW thanks for the great Answer from Robin...Hetzner is still great ;)
Or see it other way around - will require more efforts as before. I see no value in extra efforts.
Another solution you can live boot linux and write the image onto your hardware, like you do it on oraclecloud, when you want..for example archlinux or a bsd.
The ip manpage is much better. It is broken up into sections which is a bummer for searching but does make it a little less daunting for reading.
The nice thing about it is that since it has been around for many years now you can google search most any question and find the answer. All in all the ip command is fairly straightforward and orthogonal which is nice.
Some starting commands
"ip addr show" lists interfaces and their stats. It's harder to read than ifconfig -a but gives you the same information in a similar format.
"ip route show" replaces netstat -rn to show the routing table but is also not as well formatted as the old command.
"ip neigh show" replaces arp -a and is about the same level of legibility.
"ip route add ..." replaces "route ..." command and is about the same to use.
So basically it combines a bunch of commands (including ifconfig) into one and gives them all a unified interface.
$ip a
$ip a a 10.99.0.111/24 dev re0
$ip r
$ip r a default via 10.99.0.1 dev re0
The second command is: ip address add. The third is show me the routing table - ip4 is the default add -6 for ipv6. The fourth is add a default route. $ip n s
That is neigh(bour) show - the arp table.On Linux, ipconfig and co are destined to quietly go away. Use ip and co instead - so much more powerful.
If you feel you are personally a bit random then use the try/commit mode that most decent gear allows. You package up a set of changes and try them out. You then commit them within an agreed time or the changes revert.
Things might have improved since I was last managing Cisco gear. try/commit wasn’t available back then and maybe those stupid commands (like “administrator-full-port-shutdown”) have been since removed to prevent ambiguous shortenings. But I did quickly learn that it’s better to be explicit rather than implicit. And frankly, I still think that’s good advice given the IaC methodologies that are now commonly practiced. If nothing else, you should be writing your config so that others can read it, and storing that config in version control.
It's worth noting that `-br` gives you a brief version of the output, and `-c` colors it, so that it's possible to do something like this:
ip -br -c addr
to get a very readable and colorful table-like output.There's also `-j` for JSON, and `-j -p` for pretty JSON.
ifconfig can't express the idea that an interface can have IPv4 address, and is inconsistent with itself because it does show all of the IPv6 addresses.
netstat (and route because you can't manipulate the main RIB with netstat, so now you have two problems-- er-- tools) completely elides things like source address selection as a function of the RIB, and the fact that the kernel can have more than one routing table.
[1] https://www.cyberciti.biz/faq/linux-ip-command-examples-usag...
Hence my username :)
brew install iproute2mac
https://github.com/brona/iproute2macI only have limited knowledge about netlink, all coming from a devsummit presentation by Alexander, but it seems like an actually good generic kernel interface to have.
NB: my experience specifically relates to C. Protobuf's bindings to other languages are better.
> "ip addr show" lists interfaces and their stats. It's harder to read than ifconfig -a but gives you the same information in a similar format.
> "ip route show" replaces netstat -rn to show the routing table but is also not as well formatted as the old command.
> So basically it combines a bunch of commands (including ifconfig) into one and gives them all a unified interface.
To me sounds like same but worse, and combining 10 commands into 1 seems to be totally against the unix philosophy "it should do one thing, and do it properly"
The "one thing" ip essentially does is working with NETLINK_ROUTE protocol; it is relatively thin wrapper exposing that to shell.
v6 works like v4, arp and ndp work the same (down to subcommand to invoke them: they're under "neighbor") everything uses the same verbiage: add/delete/change/set.
none of this sillyness where you need one command to show the routing table 'netstat -rn' and another to manipulate the routing table 'route add/delete/change' (and then v4 uses -mask and v6 uses -prefixlen, etc etc)
Flattening everything and then making it available through the 'verb' syntax is an absolute joy to work with, especially if you're doing time sensitive work or trying to debug a test setup.
The CLI flows like a language, and you find yourself guessing at new "phrases" that very often _don't_ summon demons and actually do what you expected. I like it so much, I emulate it whenever it makes sense to do so for my own CLI tools.
`ip` is ugly (especially it's help system or more like lack of it) but works and pretty consistent.
As a network engineer pre-ip linux was a disaster, while ip is a joy to work with.
To me, the main advantage of netlink is the multicast mode, where you can subscribe to certain class of events. e.g. route add, neighbor add, etc.
Also, a lot of linux software for the networking domain interfaces with netlink, so they gain freebsd compatibility for, well, free. For example, you get FRR compat now.
Permissive licenses work so well they'd still be stuck in the 90s if not for Linux ports
You know saving files is kind of important, but since not even Linus understands COW-Filesystem's i have not much hope for Linux, and what about the kernel-queue NIH-Syndrom?
Oh and when do you get a real Scheduler who's not start to hiccup on a load over 85%...yes i know you have 20 of them, and maybe in the future ULE (you know the FreeBSD one).
That Jails vs Docker insight event will happen on the date, not older than 10 years after `Year Of Linux On Desktop` finally comes :)