Recent posts

#1
26.7 Series / Re: 26.7.3 boot loop on Hyper-...
Last post by Monviech (Cedrik) - Today at 12:33:46 PM
Run the command and if the thing happens you have the same issue, if not then most likely not. Ensure you have more than one vcpu configured.

You dont need to test it if you don't want to. It would just be interesting I guess.

But if unbound already runs the nullfs kernel module is already loaded anyway so I wouldnt expect anything to happen.

If you wanne be totally sure try the 26.7 installer in a new VM with 2vCPUs to see if it kernel crashes when it boots.

In my experience it boots around 10% of the time and crashes 90%, so it might be a race and not 100%.
#2
26.7 Series / Re: Are ports currently broken...
Last post by thingy - Today at 12:16:17 PM
Quote from: franco on Today at 08:45:58 AMI'd try to run opnsense-code again, because it will bootstrap the correct /etc/make.conf for you, which is why that message was emitted in the first place (it could not).

I ran "opnsense-code ports" and since /usr/tools + /etc/make.conf was not updated, I tried running "opnsense-code -f ports". This reported /usr/ports: Device busy after it had git cloned the ports repo from github. I couldn't find out what files were open in /usr/ports as fopen /usr/ports reported nothing.

I then searched the forum for anyone else mentioning /usr/tools and came across this post: https://forum.opnsense.org/index.php?topic=34566.msg167559#msg167559

Running "rm -rf /usr/tools" and then "opnsense-code ports" resolved the issue. It updated /etc/make.conf and /usr/tools.

I was then able to successfully install the s-nail port.

Thanks for your input.
#3
26.7 Series / Re: 26.7.3 boot loop on Hyper-...
Last post by iorx - Today at 12:08:10 PM
Thanks guys for followup.

You want me to test anything out here?

DNS setup:

Unbound: enabled, port 8053, active on LAN and WG interfaces, forwards to Quad9 via DoT.
AdGuard Home (os-adguardhome-maxit): port 53, uses Unbound on 127.0.0.1:8053 as upstream for internal zones.
Dnsmasq: port 53053, DHCP hostname resolution only.

So Unbound is active and running at boot, which fits Franco's description of the nullfs trigger.

Would it add any value if I run the test (mount -r -t nullfs /usr/local/lib/python3.13 /mnt) on the running 26.7.3_8 system? I still have the 26.7.2 snapshot available if a confirmed reproduction on a clean upgrade attempt would be more useful.
#4
26.7 Series / Re: 26.7.3 boot loop on Hyper-...
Last post by franco - Today at 12:00:35 PM
The crash happens in file systems unionfs and nullfs from what we have seen.  If you turn off Unbound it should boot always (using nullfs).  We also saw this with the installer media (using unionfs).  Perhaps it's also not a 100% guaranteed crash.


Cheers,
Franco
#5
26.7 Series / Re: 26.7.3 boot loop on Hyper-...
Last post by Monviech (Cedrik) - Today at 11:59:50 AM
If your guest has 8 vCPUs, and you issue this command and the kernel panic occurs, it's the same issue as in the ticket:

mount -r -t nullfs /usr/local/lib/python3.13 /mnt
This command should kernel panic /instantly/ so have a snapshot.

if not, then probably not
#6
26.7 Series / Re: Can anyone at OPNsense cre...
Last post by sopex - Today at 11:45:39 AM
I am almost sure AI can do this for you. Try it out.
#7
26.7 Series / Re: 26.7.3 boot loop on Hyper-...
Last post by iorx - Today at 11:43:46 AM
Hi again!

Think we maybe have to file this under strange

I set only one vCPU on the VM and ran the upgrade. It booted and works. Changed it back to 8 vCPU. And booted as it should into 26.7.3_8...

Still got a snapshot of 26.7.2 if we should investigate this further. I'm willing to revert and see if the problem can be reproduced.
I tried two times from 26.7.2 without success.

But, I did something different (without thinking about it...). The successful upgrade when I had set it to 1 vCPU was from the console, option 12. The previous two attempts when vCPU was set to 8 was done from UI. That shouldn't make any difference how the upgrade process is done, or?
 
#8
General Discussion / Re: nfSensei ( fork pfsense )
Last post by sopex - Today at 11:31:39 AM
Quote from: Netlearn on August 30, 2026, 08:30:18 PMBut anyway, it's being developed since 2004.

Hahaha, no it isn't... If he actually started on January, I would be surprised.

The only reason we know of the project is that Ullrich is one of the pfsense cofounders. Other than that, this is a very unserious situation in my humble opinion.
#9
German - Deutsch / Re: SSD Killer gesucht
Last post by grefabu - Today at 11:24:08 AM
Musste erst mal nachschauen, was Netflow ist.Das ist ja ein zusätzliches Plugin? -> Nein.

Ich habe mir auch gerade mal die Überwachung des SMART Werts ins zabbix eingebaut und werde das beobachten.
Evtl. tausche ich mal am nächsten Wochenende eine der SSDs aus, die haben beide nämlich einen ähnlichen ssd_life_left Wert, nicht das mir beide SSDs gelichzeitig das Zeitliche segnen.
#10
General Discussion / Re: Block Gambling/Betting Sit...
Last post by sopex - Today at 11:16:56 AM
OPNsense includes the Hagezi Gambling blocklist under the unbound blocklists. Start there, and you can also use any other provider you prefer.