Mastodon

Welcome to Larvitz Blog! I’m Christian, a Senior Consultant by day and FreeBSD enthusiast by night, with over 20 years in enterprise IT. Here I write about FreeBSD jails, PF firewalling, self-hosting, Linux system administration, and anything that’s cleanly engineered. Most articles are hands-on guides born from running my own infrastructure, from dual-stack networking and Ansible automation to hosting a Mastodon instance on FreeBSD.

Have a question or want to discuss something? Find me on the Fediverse at @Larvitz@burningboard.net. I’m always happy to chat!

Articles


FreeBSD Foundationals: rc.d - The Service Framework That Fits in Your Head

The fourth in the FreeBSD Foundationals series. This one picks up where the boot article stopped, at the moment init runs /etc/rc. It covers how rc finds and orders scripts with rcorder, how rc.conf and its layers are really just shell, what rc.subr gives you for free, how to drive it all with service and sysrc (including inside jails), how to write a correct rc.d script for your own daemon using daemon(8) supervision, and the pidfile trap that makes “service stop” restart your process instead of stopping it. Then an honest audit of the rc.d scripts running my own Mastodon, Zigbee2MQTT and NetBox jails. Plus service jails, debugging, and an honest comparison with systemd units.

  • Sat 03 October 2026
  • Linux

Self-Hosted AI: Qwen 3.8 on a Rented Blackwell at 150 Tokens per Second

An open-weight Qwen 3.8 27B model, an RTX PRO 6000 Blackwell rented by the hour, and one shell command to start it. For most of my everyday coding it is good enough, it answers at roughly 150 tokens per second, and my prompts stay on infrastructure I chose. Some honest caveats about what “self-hosted” means on someone else’s GPU are included, along with the workflow that has worked best for me: a frontier model for architecture, and a fast open-weight model for the token-heavy implementation loop.

My Ansible Plugin Had a Jail Escape: CVE-2026-55074

For almost a year, my jailexec connection plugin let a compromised FreeBSD jail redirect a root-owned write onto the jail host. The input validation was fine. The problem was on which side of the jail boundary the paths were resolved. This is the story of the bug, the fix in 2.0.0, and the CVE that came with it.

  • Thu 17 September 2026
  • Linux

No Proxmox Backup Client for RHEL? Hold My Container Runtime

RHEL 10 on ARM64, a Proxmox Backup Server, and no convenient native client package. I borrowed the client from an old server container, mounted the host root filesystem read-only, and gave SELinux a very specific explanation. Five minutes later, I had an encrypted, incremental backup. There are caveats.


Bespoke: A Programming Language for People Who Say Please

Modern programming languages are full of violence, vulgar abbreviations, and naked imperatives. Bespoke is a statically typed alternative in which exceptions are regrettable circumstances, mutexes grant private audiences, and every request to the compiler ends with a proper thank-you.

  • Thu 03 September 2026
  • Linux

Running Citrix Workspace on Fedora with Rootless Podman

Citrix Workspace is an application I need but do not want woven into my workstation. I put its official Debian package in a disposable rootless Podman container, then pass through just enough X11, PipeWire, GPU, and webcam plumbing to open downloaded ICA files from Fedora’s file manager.

I Wanted an IPv4 Toast and Accidentally Built an IP Service

At 10:15 this morning I added a gently condescending toast for IPv4-only visitors to hofstede.it. It called ipify, which felt increasingly inappropriate for somebody operating an ASN. Three hours later I had written a Rust IP-information service, put it behind Caddy, given it three DNS names, and deployed it in its own dual-stack FreeBSD VNET jail. This is how a two-line dependency became infrastructure.

bhyve Inside a Jail: The FreeBSD Feature Nobody Uses

A jail shares the host kernel, so sooner or later you need a real virtual machine. bhyve has been able to run inside a jail since FreeBSD 12.0, and almost nobody does it. This is the full build from my production hypervisor: the devfs ruleset, the four things that have to line up, the two-tier bridge topology, and an honest account of what allow.vmm does and does not buy you.

  • Sun 16 August 2026
  • Linux

Crawlfest: Building a Terminal Roguelike in Rust

For a few months now I have been building a terminal roguelike in Rust in the spirit of ADOM and NetHack. This article is about the technical groundwork: why ratatui and legion instead of a game engine, how the four map generators work (rooms, cellular-automata caverns, hand-drawn prefabs, and a hybrid of the last two), how field of view and A* pathfinding hook into my own map type through two traits, how content lives in RON files instead of code, and how save games avoid serialising the ECS at all.