Page Menu
Home
FreeBSD
Search
Configure Global Search
Log In
Files
F174115489
D59474.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Flag For Later
Award Token
Size
23 KB
Referenced Files
None
Subscribers
None
D59474.diff
View Options
diff --git a/ObsoleteFiles.inc b/ObsoleteFiles.inc
--- a/ObsoleteFiles.inc
+++ b/ObsoleteFiles.inc
@@ -51,6 +51,10 @@
# xargs -n1 | sort | uniq -d;
# done
+# 20260906: Move jib and jng from share/examples/jails to usr.sbin
+OLD_FILES+=usr/share/examples/jails/jib
+OLD_FILES+=usr/share/examples/jails/jng
+
# 20260813: lib9p.so becomes a private library
OLD_LIBS+=usr/lib/lib9p.so.1
diff --git a/share/examples/Makefile b/share/examples/Makefile
--- a/share/examples/Makefile
+++ b/share/examples/Makefile
@@ -107,8 +107,6 @@
README \
VIMAGE \
jail.xxx.conf \
- jib \
- jng \
rc.conf.jails \
rcjail.xxx.conf
diff --git a/share/examples/jails/README b/share/examples/jails/README
--- a/share/examples/jails/README
+++ b/share/examples/jails/README
@@ -17,9 +17,10 @@
# Load ng_ether at once without rebooting:
$ kldload ng_ether
+See jib(8) and jng(8). Both are installed to /usr/sbin.
+
Sample 1: jail.conf(5)
- $ cp jib jng /usr/sbin/
$ cat jail.xxx.conf >> /etc/jail.conf
$ vi /etc/jail.conf
# NB: Customize root directory and bridge interface
@@ -30,7 +31,6 @@
Sample 2: rc.conf(5)
- $ cp jib jng /usr/sbin/
$ cp rc.conf.jails /etc/
$ vi /etc/rc.conf.jails
# NB: Customize root directory and bridge interface
@@ -40,7 +40,6 @@
Sample 3: Per-jail jail.conf(5)
- $ cp jib jng /usr/sbin/
$ cp jail.xxx.conf /etc/
$ vi /etc/jail.xxx.conf
# NB: Customize root directory and bridge interface
@@ -51,7 +50,6 @@
Sample 4: Per-jail rc.conf(5)
- $ cp jib jng /usr/sbin/
$ cp rcjail.xxx.conf /etc/
$ vi /etc/rcjail.xxx.conf
# NB: Customize root directory and bridge interface
diff --git a/share/man/man4/epair.4 b/share/man/man4/epair.4
--- a/share/man/man4/epair.4
+++ b/share/man/man4/epair.4
@@ -25,7 +25,7 @@
.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
.\" SUCH DAMAGE.
.\"
-.Dd August 16, 2026
+.Dd September 6, 2026
.Dt EPAIR 4
.Os
.Sh NAME
@@ -87,16 +87,40 @@
that is only guaranteed to be unique within one network stack.
The tunable
.Va net.link.epair.ether_gen_addr Ns
-=1 will generate a stable MAC address with
+=1 will generate a stable MAC address in the
.Fx
-OUI using
+Foundation OUI
+.Dq 58:9c:fc
+using
.Xr ether_gen_addr 9 .
-This tunable defaults to 1 in
-.Fx 15.0 and might be removed in
+This tunable defaults to 0 on
+.Fx 14
+and to 1 in
+.Fx 15.0
+and later; it might be removed in
.Fx 16.0 .
-To change the default addresses one may use the SIOCSIFADDR
-.Xr ioctl 2 or
-.Xr ifconfig 8 utility.
+On
+.Fx 14
+set
+.Dl sysctl net.link.epair.ether_gen_addr=1
+to get the Foundation OUI instead of a random locally administered address.
+.Pp
+To change the default addresses one may use
+.Xr ifconfig 8
+.Cm ether .
+That moves the clone-time address to
+.Cm hwaddr
+and places the new address on the wire.
+.Xr jib 8
+does this by default so a multi-node cluster can derive unique addresses
+from the parent NIC.
+Prefixing an interface with
+.Ql \&!
+in
+.Xr jib 8
+skips that override so the
+.Xr ether_gen_addr 9
+address remains on the wire.
.Pp
The basic intent is to provide connectivity between two virtual
network stack instances.
@@ -161,7 +185,9 @@
.Xr vlan 4 ,
.Xr loader.conf 5 ,
.Xr rc.conf 5 ,
-.Xr ifconfig 8
+.Xr ifconfig 8 ,
+.Xr jib 8 ,
+.Xr ether_gen_addr 9
.Sh HISTORY
The
.Nm
diff --git a/tools/build/mk/OptionalObsoleteFiles.inc b/tools/build/mk/OptionalObsoleteFiles.inc
--- a/tools/build/mk/OptionalObsoleteFiles.inc
+++ b/tools/build/mk/OptionalObsoleteFiles.inc
@@ -1791,8 +1791,6 @@
OLD_FILES+=usr/share/examples/jails/README
OLD_FILES+=usr/share/examples/jails/VIMAGE
OLD_FILES+=usr/share/examples/jails/jail.xxx.conf
-OLD_FILES+=usr/share/examples/jails/jib
-OLD_FILES+=usr/share/examples/jails/jng
OLD_FILES+=usr/share/examples/jails/rc.conf.jails
OLD_FILES+=usr/share/examples/jails/rcjail.xxx.conf
OLD_FILES+=usr/share/examples/kld/Makefile
@@ -2711,11 +2709,15 @@
OLD_FILES+=etc/rc.d/jail
OLD_FILES+=usr/sbin/jail
OLD_FILES+=usr/sbin/jexec
+OLD_FILES+=usr/sbin/jib
OLD_FILES+=usr/sbin/jls
+OLD_FILES+=usr/sbin/jng
OLD_FILES+=usr/share/man/man5/jail.conf.5.gz
OLD_FILES+=usr/share/man/man8/jail.8.gz
OLD_FILES+=usr/share/man/man8/jexec.8.gz
+OLD_FILES+=usr/share/man/man8/jib.8.gz
OLD_FILES+=usr/share/man/man8/jls.8.gz
+OLD_FILES+=usr/share/man/man8/jng.8.gz
.endif
.if ${MK_KDUMP} == no
diff --git a/usr.sbin/Makefile b/usr.sbin/Makefile
--- a/usr.sbin/Makefile
+++ b/usr.sbin/Makefile
@@ -160,7 +160,9 @@
SUBDIR.${MK_ISCSI}+= iscsid
SUBDIR.${MK_JAIL}+= jail
SUBDIR.${MK_JAIL}+= jexec
+SUBDIR.${MK_JAIL}+= jib
SUBDIR.${MK_JAIL}+= jls
+SUBDIR.${MK_JAIL}+= jng
# XXX MK_SYSCONS
SUBDIR.${MK_LEGACY_CONSOLE}+= kbdcontrol
SUBDIR.${MK_LEGACY_CONSOLE}+= kbdmap
diff --git a/usr.sbin/jail/jail.8 b/usr.sbin/jail/jail.8
--- a/usr.sbin/jail/jail.8
+++ b/usr.sbin/jail/jail.8
@@ -26,7 +26,7 @@
.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
.\" SUCH DAMAGE.
.\"
-.Dd August 13, 2026
+.Dd September 6, 2026
.Dt JAIL 8
.Os
.Sh NAME
@@ -1596,7 +1596,9 @@
.Xr ifconfig 8 ,
.Xr inetd 8 ,
.Xr jexec 8 ,
+.Xr jib 8 ,
.Xr jls 8 ,
+.Xr jng 8 ,
.Xr mount 8 ,
.Xr mountd 8 ,
.Xr nfsd 8 ,
diff --git a/usr.sbin/jail/jail.conf.5 b/usr.sbin/jail/jail.conf.5
--- a/usr.sbin/jail/jail.conf.5
+++ b/usr.sbin/jail/jail.conf.5
@@ -25,7 +25,7 @@
.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
.\" SUCH DAMAGE.
.\"
-.Dd September 21, 2024
+.Dd September 6, 2026
.Dt JAIL.CONF 5
.Os
.Sh NAME
@@ -245,7 +245,9 @@
.Xr rc.conf 5 ,
.Xr jail 8 ,
.Xr jexec 8 ,
+.Xr jib 8 ,
.Xr jls 8 ,
+.Xr jng 8 ,
.Xr zfs-jail 8
.Pp
The
diff --git a/usr.sbin/jib/Makefile b/usr.sbin/jib/Makefile
new file mode 100644
--- /dev/null
+++ b/usr.sbin/jib/Makefile
@@ -0,0 +1,6 @@
+PACKAGE= jail
+
+SCRIPTS= jib
+MAN= jib.8
+
+.include <bsd.prog.mk>
diff --git a/share/examples/jails/jib b/usr.sbin/jib/jib
rename from share/examples/jails/jib
rename to usr.sbin/jib/jib
--- a/share/examples/jails/jib
+++ b/usr.sbin/jib/jib
@@ -205,7 +205,7 @@
#
# The formula I'm using is ``NP:SS:SS:II:II:II'' where:
# + N denotes 4 bits used as a counter to support branching
- # each parent interface up to 15 times under the same jail
+ # each parent interface up to 16 times under the same jail
# name (see S below).
# + P denotes the special nibble whose value, if one of
# 2, 6, A, or E (but usually 2) denotes a privately
@@ -342,7 +342,7 @@
jib_show_usage="show"
jib_show_descr="List possible NAME values for \`show NAME'"
jib_show1_usage="show NAME"
-jib_show1_descr="Lists e0b_NAME [e1b_NAME ...]"
+jib_show1_descr="Lists e0a_NAME [e1a_NAME ...]"
jib_show2_usage="show [NAME]"
jib_show()
{
diff --git a/usr.sbin/jib/jib.8 b/usr.sbin/jib/jib.8
new file mode 100644
--- /dev/null
+++ b/usr.sbin/jib/jib.8
@@ -0,0 +1,319 @@
+.\"
+.\" SPDX-License-Identifier: BSD-2-Clause
+.\"
+.\" Copyright (c) 2016-2026 Devin Teske
+.\"
+.Dd September 6, 2026
+.Dt JIB 8
+.Os
+.Sh NAME
+.Nm jib
+.Nd "if_bridge(4) and epair(4) management for vnet jails"
+.Sh SYNOPSIS
+.Nm
+.Op Fl hv
+.Ar action
+.Op Ar arguments
+.Nm
+.Cm addm
+.Op Fl b Ar bridge_name
+.Ar name
+.Oo Li \&! Oc Ns Ar iface ...
+.Nm
+.Cm show
+.Op Ar name
+.Nm
+.Cm destroy
+.Ar name
+.Sh DESCRIPTION
+The
+.Nm
+utility creates and destroys
+.Xr epair 4
+interfaces attached to
+.Xr if_bridge 4
+for
+.Xr jail 8
+instances that use
+.Va vnet .
+It is intended to run from
+.Va exec.prestart
+and
+.Va exec.poststop
+in
+.Xr jail.conf 5
+.Po
+or the equivalent
+.Xr rc.conf 5
+.Dq legacy
+jail variables
+.Pc .
+.Pp
+For each parent interface given to
+.Cm addm ,
+.Nm
+brings the parent up, creates a bridge by appending the suffix
+.Ql Li bridge
+to the parent name
+.Pq for example Li em0bridge
+if one does not already exist, creates an
+.Xr epair 4
+pair, adds the host side to the bridge, and renames the ends
+.Li e Ns Ar N Ns Li a_ Ns Ar name
+.Pq host
+and
+.Li e Ns Ar N Ns Li b_ Ns Ar name
+.Pq jail .
+The jail configuration should list the
+.Li b
+side in
+.Va vnet.interface
+.Pq Xr jail.conf 5
+or
+.Va jail_ Ns Ar name Ns Va _vnet_interface
+.Pq Xr rc.conf 5 .
+.Pp
+.Nm
+cannot express every topology.
+It covers the common bridged-vnet case.
+.Sh OPTIONS
+.Bl -tag -width indent
+.It Fl h
+Print usage statement and exit.
+.It Fl v
+Print version information and exit.
+.El
+.Sh ACTIONS
+.Bl -tag -width indent
+.It Xo
+.Cm addm
+.Op Fl b Ar bridge_name
+.Ar name
+.Oo Li \&! Oc Ns Ar iface ...
+.Xc
+Create
+.Li e0b_ Ns Ar name ,
+.Li e1b_ Ns Ar name ,
+\&... for each parent interface.
+Must be run as root.
+.Pp
+.Bl -tag -width indent -compact
+.It Fl b Ar bridge_name
+Suffix used to name the bridge
+.Pq default Ql Cm bridge ,
+so parent
+.Li em0
+yields
+.Li em0bridge .
+.It Li \&! Ns Ar iface
+Do not run the multi-node MAC derivation described under
+.Sx MAC ADDRESSES .
+The kernel-generated
+.Xr ether_gen_addr 9
+address stays on the wire instead of moving to
+.Cm hwaddr .
+.El
+.It Cm show
+List jail
+.Ar name
+values that currently have
+.Nm
+interfaces.
+.It Cm show Ar name
+List
+.Li e Ns Ar N Ns Li a_ Ns Ar name
+interfaces for
+.Ar name .
+.It Cm destroy Ar name
+Destroy the
+.Xr epair 4
+interfaces created for
+.Ar name .
+Must be run as root.
+.El
+.Sh MAC ADDRESSES
+By default,
+.Nm
+sets a derived link-level address on both ends of each
+.Xr epair 4
+so that the same jail name can be started on more than one host without
+producing a duplicate MAC on a shared L2 segment.
+.Pp
+The derived address has the form
+.Li NP:SS:SS:II:II:II :
+.Bl -tag -width indent
+.It N
+A 4-bit branch counter, allowing the same parent interface to be presented
+up to 16 times under one jail name.
+.It P
+The locally administered unicast nibble
+.Pq typically 2, 6, A, or E .
+.It S
+16 bits from
+.Xr sum 1
+of the jail
+.Ar name ,
+so renaming the jail
+.Pq or moving it
+yields a new address, while changing
+only the epair instance number does not.
+.It I
+The last three octets inherited from the parent interface.
+.El
+.Pp
+Keeping the
+.Fx
+Foundation OUI
+.Pq Dq 58:9c:fc
+on the wire is supported with
+.Ql \&!
+but is not the default.
+A fixed vendor OUI consumes the bits
+.Nm
+uses for the branch counter and parent inheritance.
+Without inheritance, two hosts that start a jail of the same name derive
+the same address and a switch will see a flap.
+Unlike
+.Xr bhyve 8
+orchestrators,
+.Nm
+is stateless and does not keep a MAC database.
+.Pp
+Prefix
+.Ar iface
+with
+.Ql \&!
+to skip derivation.
+The address assigned at
+.Xr epair 4
+clone time remains the on-wire address.
+With
+.Va net.link.epair.ether_gen_addr Ns =1
+that is a stable address in the Foundation OUI from
+.Xr ether_gen_addr 9 ;
+see
+.Xr epair 4 .
+On
+.Fx 14
+that tunable defaults to 0
+.Pq a random locally administered address
+and must be set to 1 for the Foundation OUI.
+.Fx 15.0
+and later default to 1.
+.Pp
+When derivation
+.Em does
+run,
+.Xr ifconfig 8 Cm ether
+moves the clone-time address to
+.Cm hwaddr
+and places the derived address on the wire.
+.Sh EXAMPLES
+A typical
+.Xr jail.conf 5
+stanza:
+.Bd -literal -offset indent
+xxx {
+ host.hostname = "xxx.yyy";
+ path = "/vm/xxx";
+
+ vnet;
+ vnet.interface = e0b_xxx, e1b_xxx;
+
+ exec.clean;
+ exec.system_user = "root";
+ exec.jail_user = "root";
+
+ exec.prestart += "jib addm xxx em0 em1";
+ exec.poststop += "jib destroy xxx";
+
+ exec.start += "/bin/sh /etc/rc";
+ exec.stop = "/bin/sh /etc/rc.shutdown jail";
+ exec.consolelog = "/var/log/jail_xxx_console.log";
+ mount.devfs;
+}
+.Ed
+.Pp
+The number of
+.Li e Ns Ar N Ns Li b_ Ns Ar name
+values in
+.Va vnet.interface
+must match the number of parent interfaces given to
+.Cm addm .
+In
+.Xr rc.conf 5
+.Dq legacy
+form
+.Po
+used when
+.Pa /etc/jail.conf
+does not exist; converted to
+.Pa /var/run/jail. Ns Ar name Ns Pa .conf
+by
+.Pa /etc/rc.d/jail
+.Pc ,
+that list is
+.Va jail_ Ns Ar name Ns Va _vnet_interface .
+See
+.Pa /usr/share/examples/jails/
+for samples.
+.Pp
+To leave the Foundation OUI on the wire:
+.Bd -literal -offset indent
+exec.prestart += "jib addm xxx !em0";
+.Ed
+.Ss DHCP inside the jail
+To allow
+.Xr dhclient 8
+to work inside a vnet jail, create
+.Pa /etc/devfs.rules
+if needed:
+.Bd -literal -offset indent
+[devfsrules_jail=11]
+add include $devfsrules_hide_all
+add include $devfsrules_unhide_basic
+add include $devfsrules_unhide_login
+add path 'bpf*' unhide
+.Ed
+.Pp
+and set
+.Va devfs_ruleset Ns = Ns Ql 11
+in
+.Xr jail.conf 5 ,
+or
+.Va jail_ Ns Ar name Ns Va _devfs_ruleset Ns = Ns Ql 11
+in
+.Xr rc.conf 5 .
+.Sh FILES
+.Bl -tag -width "/usr/share/examples/jails/" -compact
+.It Pa /usr/share/examples/jails/
+Sample
+.Xr jail.conf 5
+and
+.Xr rc.conf 5
+stanzas.
+.El
+.Sh SEE ALSO
+.Xr sum 1 ,
+.Xr epair 4 ,
+.Xr if_bridge 4 ,
+.Xr jail.conf 5 ,
+.Xr rc.conf 5 ,
+.Xr dhclient 8 ,
+.Xr ifconfig 8 ,
+.Xr jail 8 ,
+.Xr jng 8 ,
+.Xr ether_gen_addr 9
+.Sh HISTORY
+The
+.Nm
+utility first appeared in
+.Fx 11.0
+as
+.Pa /usr/share/examples/jails/jib
+and was moved to
+.Pa /usr/sbin
+in
+.Fx 16.0 .
+.Sh AUTHORS
+.An Devin Teske Aq Mt dteske@FreeBSD.org
diff --git a/usr.sbin/jng/Makefile b/usr.sbin/jng/Makefile
new file mode 100644
--- /dev/null
+++ b/usr.sbin/jng/Makefile
@@ -0,0 +1,6 @@
+PACKAGE= jail
+
+SCRIPTS= jng
+MAN= jng.8
+
+.include <bsd.prog.mk>
diff --git a/share/examples/jails/jng b/usr.sbin/jng/jng
rename from share/examples/jails/jng
rename to usr.sbin/jng/jng
--- a/share/examples/jails/jng
+++ b/usr.sbin/jng/jng
@@ -262,7 +262,7 @@
#
# The formula used is ``NP:SS:SS:II:II:II'' where:
# + N denotes 4 bits used as a counter to support branching
- # each parent interface up to 15 times under the same jail
+ # each parent interface up to 16 times under the same jail
# name (see S below).
# + P denotes the special nibble whose value, if one of
# 2, 6, A, or E (but usually 2) denotes a privately
diff --git a/usr.sbin/jng/jng.8 b/usr.sbin/jng/jng.8
new file mode 100644
--- /dev/null
+++ b/usr.sbin/jng/jng.8
@@ -0,0 +1,491 @@
+.\"
+.\" SPDX-License-Identifier: BSD-2-Clause
+.\"
+.\" Copyright (c) 2016-2026 Devin Teske
+.\"
+.Dd September 7, 2026
+.Dt JNG 8
+.Os
+.Sh NAME
+.Nm jng
+.Nd "netgraph(4) management for vnet jails"
+.Sh SYNOPSIS
+.Nm
+.Op Fl hv
+.Ar action
+.Op Ar arguments
+.Nm
+.Cm bridge
+.Op Fl b Ar bridge_name
+.Ar name
+.Oo Li \&! Ns | Ns Li = Oc Ns Ar iface ...
+.Nm
+.Cm pin
+.Brq Fl a | Ar name ...
+.Nm
+.Cm graph
+.Op Fl f
+.Op Fl T Ar type
+.Op Fl o Ar output
+.Nm
+.Cm show
+.Op Ar name ...
+.Nm
+.Cm shutdown
+.Ar name ...
+.Nm
+.Cm stats
+.Op Fl j
+.Brq Fl a | Ar name ...
+.Sh DESCRIPTION
+The
+.Nm
+utility creates and destroys
+.Xr ng_eiface 4
+interfaces attached to
+.Xr ng_bridge 4
+for
+.Xr jail 8
+instances that use
+.Va vnet .
+It is intended to run from
+.Va exec.prestart
+and
+.Va exec.poststop
+in
+.Xr jail.conf 5
+.Po
+or the equivalent
+.Xr rc.conf 5
+.Dq legacy
+jail variables
+.Pc .
+.Pp
+Unlike
+.Xr jib 8 ,
+which uses
+.Xr if_bridge 4
+and
+.Xr epair 4 ,
+.Nm
+uses netgraph as the virtual networking fabric.
+The
+.Xr ng_ether 4
+module must be loaded
+.Pq it is not loaded on demand .
+.Xr ng_bridge 4
+and
+.Xr ng_eiface 4
+load with it as needed.
+.Bd -literal -offset indent
+sysrc kld_list+=ng_ether
+kldload ng_ether
+.Ed
+.Pp
+For each parent interface given to
+.Cm bridge ,
+.Nm
+brings the parent up, attaches an
+.Xr ng_bridge 4
+on the
+.Xr ng_ether 4
+.Li lower
+hook as
+.Li uplink
+if one does not already exist, creates an
+.Xr ng_eiface 4 ,
+and renames it
+.Li ng Ns Ar N Ns Li _ Ns Ar name .
+The jail configuration should list that name in
+.Va vnet.interface
+.Pq Xr jail.conf 5
+or
+.Va jail_ Ns Ar name Ns Va _vnet_interface
+.Pq Xr rc.conf 5 .
+.Pp
+Return each interface to the host in
+.Va exec.prestop
+with
+.Xr ifconfig 8
+.Cm -vnet
+so the kernel does not move it during jail removal
+.Pq a BPF race
+and destroy it in
+.Va exec.poststop
+with
+.Cm shutdown .
+.Pp
+Uplink on
+.Xr ng_ether 4
+.Li lower
+keeps the WAN MAC table small:
+.Xr ng_bridge 4
+does not learn on uplink hooks.
+The first connected hook being uplink also selects restrictive unknown-unicast:
+frames for an unknown destination go only to uplink, not to jail links.
+Inbound unicast to a jail therefore requires that jail's MAC to live in the
+forwarding database
+.Pq FDB
+on the jail's link.
+.Nm
+pins each eiface MAC with
+.Xr ngctl 8
+.Cm movehost
+and sets
+.Va maxStaleness
+so
+.Li host->staleness
+cannot age it out.
+.Cm pin
+replants after an accidental move.
+.Pp
+.Nm
+cannot express every topology.
+It covers the common bridged-vnet case.
+.Sh OPTIONS
+.Bl -tag -width indent
+.It Fl h
+Print usage statement and exit.
+.It Fl v
+Print version information and exit.
+.El
+.Sh ACTIONS
+All actions must be run as root.
+.Bl -tag -width indent
+.It Xo
+.Cm bridge
+.Op Fl b Ar bridge_name
+.Ar name
+.Oo Li \&! Ns | Ns Li = Oc Ns Ar iface ...
+.Xc
+Create
+.Li ng0_ Ns Ar name ,
+.Li ng1_ Ns Ar name ,
+\&... for each parent interface.
+.Pp
+.Bl -tag -width indent -compact
+.It Fl b Ar bridge_name
+Suffix for a secondary
+.Xr ng_bridge 4
+on that parent, so
+.Li em0
+with
+.Ql Fl b Ar private
+yields
+.Li em0private .
+Eifaces attach there instead of to the default
+.Li em0bridge
+on the parent's
+.Li lower
+hook.
+That node has its own
+.Xr ng_bridge 4
+configuration, independent of the WAN bridge.
+.It Li \&! Ns Ar iface
+Do not run the multi-node MAC derivation described under
+.Sx MAC ADDRESSES .
+The kernel-generated
+.Xr ether_gen_addr 9
+address stays on the wire instead of moving to
+.Cm hwaddr .
+.It Li = Ns Ar iface
+Set the eiface MAC to a copy of the parent interface's on-wire address.
+.El
+.It Xo
+.Cm pin
+.Brq Fl a | Ar name ...
+.Xc
+Pin eiface MACs into the
+.Xr ng_bridge 4
+FDB.
+.Ql Fl a
+pins every running jail that has
+.Nm
+interfaces.
+.It Xo
+.Cm graph
+.Op Fl f
+.Op Fl T Ar type
+.Op Fl o Ar output
+.Xc
+Write a netgraph diagram via
+.Xr ngctl 8
+.Cm dot
+and the Graphviz
+.Xr dot 1
+utility.
+The default output file is
+.Pa jng.svg .
+.Ql Fl f
+overwrites an existing file.
+.It Cm show
+List jail
+.Ar name
+values that currently have
+.Nm
+interfaces.
+.It Cm show Ar name ...
+List
+.Li ng Ns Ar N Ns Li _ Ns Ar name
+interfaces for each
+.Ar name .
+.It Cm shutdown Ar name ...
+Shut down the
+.Xr ng_eiface 4
+nodes created for each
+.Ar name .
+.It Xo
+.Cm stats
+.Op Fl j
+.Brq Fl a | Ar name ...
+.Xc
+Show
+.Xr ng_bridge 4
+link statistics.
+A parent interface reports
+.Li lower
+and
+.Li upper
+on its default bridge.
+A jail name reports each eiface's link.
+.Ql Fl a
+covers every bridged
+.Xr ng_ether 4
+device and every
+.Nm
+jail name.
+.Ql Fl j
+prints JSON.
+.El
+.Sh MAC ADDRESSES
+By default,
+.Nm
+sets a derived link-level address on each
+.Xr ng_eiface 4
+so that the same jail name can be started on more than one host without
+producing a duplicate MAC on a shared L2 segment.
+.Pp
+The derived address has the form
+.Li NP:SS:SS:II:II:II :
+.Bl -tag -width indent
+.It N
+A 4-bit branch counter, allowing the same parent interface to be presented
+up to 16 times under one jail name.
+.It P
+The locally administered unicast nibble
+.Pq typically 2, 6, A, or E .
+.It S
+16 bits from
+.Xr sum 1
+of the jail
+.Ar name ,
+so renaming the jail
+.Pq or moving it
+yields a new address, while changing
+only the eiface instance number does not.
+.It I
+The last three octets inherited from the parent interface.
+.El
+.Pp
+Keeping the
+.Fx
+Foundation OUI
+.Pq Dq 58:9c:fc
+on the wire is supported with
+.Ql \&!
+but is not the default.
+A fixed vendor OUI consumes the bits
+.Nm
+uses for the branch counter and parent inheritance.
+Without inheritance, two hosts that start a jail of the same name derive
+the same address and a switch will see a flap.
+Unlike
+.Xr bhyve 8
+orchestrators,
+.Nm
+is stateless and does not keep a MAC database.
+.Pp
+Prefix
+.Ar iface
+with
+.Ql \&!
+to skip derivation.
+The address assigned when the
+.Xr ng_eiface 4
+is created remains the on-wire address: a stable address in the Foundation
+OUI from
+.Xr ether_gen_addr 9 .
+.Xr ng_eiface 4
+always uses
+.Xr ether_gen_addr 9
+.Pq there is no epair-style sysctl .
+When derivation
+.Em does
+run,
+.Xr ifconfig 8 Cm ether
+moves the create-time address to
+.Cm hwaddr
+and places the derived address on the wire.
+.Pp
+Prefix
+.Ar iface
+with
+.Ql =
+to copy the parent interface's MAC onto the eiface instead.
+.Sh EXAMPLES
+A typical
+.Xr jail.conf 5
+stanza:
+.Bd -literal -offset indent
+xxx {
+ host.hostname = "xxx.yyy";
+ path = "/vm/$name";
+
+ vnet;
+ vnet.interface = ng0_$name, ng1_$name;
+
+ exec.clean;
+ exec.system_user = "root";
+ exec.jail_user = "root";
+
+ exec.prestart += "jng bridge $name em0 em1";
+ exec.prestop += "ifconfig ng0_$name -vnet $name";
+ exec.prestop += "ifconfig ng1_$name -vnet $name";
+ exec.poststop += "jng shutdown $name";
+
+ exec.start += "/bin/sh /etc/rc";
+ exec.stop = "/bin/sh /etc/rc.shutdown jail";
+ exec.consolelog = "/var/log/jail_${name}_console.log";
+ mount.devfs;
+}
+.Ed
+.Pp
+The number of
+.Li ng Ns Ar N Ns Li _ Ns Ar name
+values in
+.Va vnet.interface
+must match the number of parent interfaces given to
+.Cm bridge ,
+and each must be returned to the host in
+.Va exec.prestop .
+In
+.Xr rc.conf 5
+.Dq legacy
+form
+.Po
+used when
+.Pa /etc/jail.conf
+does not exist; converted to
+.Pa /var/run/jail. Ns Ar name Ns Pa .conf
+by
+.Pa /etc/rc.d/jail
+.Pc ,
+that list is
+.Va jail_ Ns Ar name Ns Va _vnet_interface .
+See
+.Pa /usr/share/examples/jails/
+for samples.
+.Pp
+To leave the Foundation OUI on the wire:
+.Bd -literal -offset indent
+exec.prestart += "jng bridge $name !em0";
+.Ed
+.Pp
+To attach eifaces to a secondary
+.Xr ng_bridge 4
+that can be configured apart from the WAN node, define the
+.Cm setconfig
+fields once in
+.Xr jail.conf 5
+and reuse them:
+.Bd -literal -offset indent
+$dL = "debugLevel";
+$lT = "loopTimeout";
+$mS = "maxStaleness";
+$mSA = "minStableAge";
+$debug_cfg = "$dL=2 $lT=60 $mS=900 $mSA=1";
+.Pp
+exec.prestart += "jng bridge -b debug $name em0";
+exec.prestart += "ngctl msg em0debug: setconfig '{ $debug_cfg }'";
+.Ed
+.Pp
+Each jail that uses that suffix on the same parent shares
+.Li em0debug .
+.Xr ngctl 8
+.Cm setconfig
+is per node: the last jail to start or restart wins.
+Expanding one variable from every such stanza keeps the values from drifting.
+The
+.Va exec.prestart
+string is double-quoted so
+.Li $debug_cfg
+expands; single quotes around the
+.Cm setconfig
+argument keep it one word for the shell.
+.Cm setconfig
+replaces the whole node config; fields not named default to 0.
+The values above are
+.Xr ng_bridge 4
+defaults except
+.Ql Va debugLevel Ns = Ns 2
+.Pq log detected loops .
+This does not change
+.Li em0bridge .
+.Ss DHCP inside the jail
+To allow
+.Xr dhclient 8
+to work inside a vnet jail, create
+.Pa /etc/devfs.rules
+if needed:
+.Bd -literal -offset indent
+[devfsrules_jail=11]
+add include $devfsrules_hide_all
+add include $devfsrules_unhide_basic
+add include $devfsrules_unhide_login
+add path 'bpf*' unhide
+.Ed
+.Pp
+and set
+.Va devfs_ruleset Ns = Ns Ql 11
+in
+.Xr jail.conf 5 ,
+or
+.Va jail_ Ns Ar name Ns Va _devfs_ruleset Ns = Ns Ql 11
+in
+.Xr rc.conf 5 .
+.Sh FILES
+.Bl -tag -width "/usr/share/examples/jails/" -compact
+.It Pa /usr/share/examples/jails/
+Sample
+.Xr jail.conf 5
+and
+.Xr rc.conf 5
+stanzas.
+.El
+.Sh SEE ALSO
+.Xr sum 1 ,
+.Xr netgraph 4 ,
+.Xr ng_bridge 4 ,
+.Xr ng_eiface 4 ,
+.Xr ng_ether 4 ,
+.Xr jail.conf 5 ,
+.Xr rc.conf 5 ,
+.Xr dhclient 8 ,
+.Xr ifconfig 8 ,
+.Xr jail 8 ,
+.Xr jib 8 ,
+.Xr ngctl 8 ,
+.Xr ether_gen_addr 9
+.Sh HISTORY
+The
+.Nm
+utility first appeared in
+.Fx 11.0
+as
+.Pa /usr/share/examples/jails/jng
+and was moved to
+.Pa /usr/sbin
+in
+.Fx 16.0 .
+.Sh AUTHORS
+.An Devin Teske Aq Mt dteske@FreeBSD.org
File Metadata
Details
Attached
Mime Type
text/plain
Expires
Thu, Oct 1, 5:48 PM (12 h, 36 s)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
40029133
Default Alt Text
D59474.diff (23 KB)
Attached To
Mode
D59474: jib, jng: Move to usr.sbin and add manuals
Attached
Detach File
Event Timeline
Log In to Comment