Capsicum Beyond the Basics: Building Capability-Mode Services From Scratch
How to design a FreeBSD service around Capsicum descriptor rights, capability mode, process descriptors, and delegated Casper services.
The ports tree, ZFS, jails, pf, and the internals of a Unix built for correctness.
How to design a FreeBSD service around Capsicum descriptor rights, capability mode, process descriptors, and delegated Casper services.
A layered bhyve UEFI diagnostic for firmware paths, VNC output, NVRAM state, EFI partitions, virtual disks, drivers, and stale VMs.
How to distinguish damaged GPT metadata from missing BIOS or EFI boot code, recover safely from the backup table, and verify every write.
How to correlate FreeBSD link events, counters, negotiated media, switch logs, optics, driver messages, and EEE before changing anything.
How to verify FreeBSD dump capture, preserve vmcore evidence, match kernel symbols, read crashinfo and kgdb traces, and report a panic.
How to diagnose FreeBSD ntpd source selection, reachability, offset thresholds, drift, virtual clocks, and safe one-time clock steps.
How to confirm PF state exhaustion, identify the responsible rules and sources, size memory safely, apply limits, and validate a ruleset reload.
How to measure FreeBSD boot delays with boottrace, inspect rcorder dependencies, isolate blocking services, and repair ordering safely.
How to distinguish healthy ZFS ARC caching from real FreeBSD memory pressure, measure reclamation, and set a tested ARC ceiling safely.
How to preserve and classify a FreeBSD ZFS assertion panic, protect the pool, test hardware, recover data, and report a reproducible bug.