/srv/irclogs.ubuntu.com/2008/05/06/#ubuntu-devel.txt

LaserJockPupeno: you should be able to use the package copy UI in PPA00:01
=== edson_ is now known as edson
bryceogasawara: for linux bugs, should they now be filed against just 'linux' or 'linux-source-2.6.24' or ...?00:14
ogasawarabryce: against "linux" now00:14
bryceok00:15
bryceogasawara: bug #223870 looks like it may be a kernel issue rather than an "ordinary" x crash, but needs some additional kernel-oriented triaging work.  Mind taking a look?00:16
ubottuLaunchpad bug 223870 in linux "x-server crashes on startup with intel GMA3000" [Undecided,Incomplete] https://launchpad.net/bugs/22387000:16
ogasawarabryce: np, looking right now00:16
bryceogasawara: that also might be one to have Intel test00:32
Hobbseedamn compiz02:40
RAOFTo a lifetime of driver bugs?02:40
Hobbseeit crashed.  again.02:42
Hobbseescreen froze.02:42
RAOF:(02:43
RAOFApparently there was a cycle in the animation plugin that could do that, but I think it's fixed in -updates.02:44
HobbseeRAOF: it's still in proposed, i have it installed, and i ithink it's hanging more than usual02:45
* Hobbsee had been testing it from mvo's ppa for a while though02:46
RAOFSucks.02:46
Hobbseehmm, there's some more updates, including an intel driver02:47
pranithhello04:54
pranithhello... when i do an objectdump of a binary, what are those addresses i get?04:54
pranithare they relative addresses of some kind??04:54
giggidyyI have a general question concering the USB Architecture as it exists on a PC: can a USB Host emulate a USB device?05:10
jscinozugh, where on launchpad was the intrepid new queue again?06:01
StevenKjscinoz: https://edge.launchpad.net/ubuntu/intrepid/+queue06:03
jscinozah thanks06:03
jscinozhow long of a delay is there normally between a package being uploaded to Debian Unstable, and it being imported to Ubuntu's new queue?06:04
StevenKDepends on when -archive runs the autosyncer06:05
jscinozIf i remember correctly, the freeze for importing packages from unstable is considerably earlier than the other freezes? Some time in june i believe?06:08
jdongjscinoz: yes, the auto-sync stops at an earlier point06:10
jdongjscinoz: but until the actual upstream version freeze it's very simple to request a sync anyway06:10
jscinozalright06:10
jdongDear Compiz Overlords:06:11
jdongI suggest that for Intrepid we include some Compiz games.06:11
jscinozShould i give it a bit longer for the auto-sync to do it, or file a syncrequest now?06:11
jscinozcompiz games?06:11
jdongyes.06:11
jdongI've invented a few good ones while I've been bored in lectures.06:11
jdongopen up 20 or so windows...06:11
jdonghit super-M to invert the entire screen's colors06:12
jdongthen randomly hit alt-tab and super-n to de-invert individual windows.06:12
jdongNow, uninvert the whole screen and start a stopwatch06:12
jdongtime how long it takes to get all windows back to the correct color.06:12
jscinoz>_<06:12
jdong(yes, I was really bored during lecture)06:12
jscinozspeaking of lectures and education, i really should get back to studying for my preliminaries tomorrow >_<06:13
jdongor, a random desktop plugin that shuffles your windows across all your desktops06:13
jscinozthanks for the clarification on the autosync thing06:13
jscinoz*away*06:13
jdongsure thing06:13
pittiGood morning06:16
tjaaltonCaesar: seems that the patch worked, you can find the package here https://edge.launchpad.net/~tjaalton/+archive06:16
Caesartjaalton: thanks06:33
CaesarSo is it in dapper-proposed now?06:34
dholbachgood morning06:55
tjaaltonCaesar: not yet, it would be nice to test that the patch does what it's supposed to do first :)07:15
=== hunger_t is now known as hunger
=== ikonia_ is now known as ikonia
seb128soren: hello08:32
seb128soren: do you care about gtk-vnc?08:32
sorenseb128: I do.08:35
seb128soren: do you know about bug #206227? I think that's something we should try to get fixed for 8.04.108:35
ubottuLaunchpad bug 206227 in gtk-vnc "vinagre fails to connect" [High,Fix committed] https://launchpad.net/bugs/20622708:35
seb128soren: http://gtk-vnc.codemonkey.ws/hg/outgoing.hg/rev/e1b964facd65 seems to be the upstream fix for the issue08:36
seb128soren: also bug #20720508:36
ubottuLaunchpad bug 207205 in gtk-vnc "vinagre crashed with SIGSEGV in memcpy()" [Medium,Fix committed] https://launchpad.net/bugs/20720508:36
sorenYou seem to have done all the work already? :) What do you need me for?08:37
seb128soren: no, I'm just reading bug mail, I don't want to do the actual testing and update ;-)08:37
seb128soren: you are better placed than me to make sure it doesn't create issues for the virt stack08:37
sorenseb128: The problem is that the virt-stack is very well behaved (in this context at least). I have very little clue about all the quirks of commercial vnc servers and all that jazz.08:39
sorenseb128: pochu has been very interested in this in the past. Maybe we can get him to drive it.08:39
seb128soren: well, the idea is basically to backport the change, verify it fixes the issue (trying to connect to a dapper box should be enough to test apparently) and that virt things are still working correctly and upload08:39
seb128soren: ok, will talk to him, thanks08:40
seb128soren: he commented on the bugs already08:40
seb128soren: bug #218667 mentions that the new version creates virt-manager issues that's why I want somebody to test it after patching08:41
ubottuLaunchpad bug 218667 in gtk-vnc "Please allow gtk-vnc 0.3.5 into Hardy" [Undecided,Invalid] https://launchpad.net/bugs/21866708:41
seb128pochu: ^ do you think you could try to prepare a gtk-vnc sru fixing those issues?08:42
sorenpochu: In particular, it seems that Jonh knows exactly which commits would fix this, so if we could just cherry-pick those (instead of importing new gtk-vnc and vinagre versions wholesale), that would be great.08:46
fokaHi!  I have a question: Is there a concerted effort to translate package descriptions into local languages?  :-)08:48
Ademanhey this might be a little out of place, but does apt/can apt download multiple packages concurrently? if apt-torrent or something similar were to ever mature, that might be a desirable feature09:25
=== jpinto is now known as joaopinto
CompanyAdeman: if you use multiple mirrors in your sources.list, it already downloads multiple packages at once09:30
AdemanCompany: ah, cool09:31
cjwatsonAdeman: we don't want it to hammer our mirrors like that, as a general rule ...09:36
cjwatsonwhen you multiply that sort of thing up by millions of users it starts to turn into serious server abuse09:36
Ademancjwatson: well, i'm curious more in terms of apt-p2p and debtorrent, as i'm really big on the idea of RELIEVING repository stress, and I think peer to peer apt would certainly go a long way to doing that.  But since it's rather unlikely that you will max out your connections download speed downloading from a handful of peers, it would be useful to concurrently download multiple packages via a peer to peer system09:38
Ademandownload multiple packages concurrently*09:39
cjwatsonjust saying that's why it doesn't do that at the moment09:40
\shAdeman, how does the trust model work for apt-p2p? actually, who can someone achieve, that peer X doesn't inject malicous packages?09:41
Ademancjwatson: ah, so is the functionality there though? just disabled?09:41
cjwatsonAdeman: I doubt it09:41
\shs/who/how/09:41
cjwatsonAdeman: (but I'm not an apt developer)09:41
cjwatson\sh: AFAIK it still checks against (signed) archive checksums afterwards09:42
Ademan\sh: the way i envision it existing packages.gz files would provide hashes for the files in question, plus packages are signed, correct?09:42
cjwatsonindividual packages are NOT signed09:42
Ademanah09:42
KlessouIs it normal when edit the gnome-terminal LAUNCHER (in the panel) and I add "sudo" (or "gksudo") before "gnome-terminal" command. I'm using directly the root user without password ... ??09:42
cjwatsoneach package's checksum is in Packages.gz, Packages.gz's checksum is in Release, and Release is signed09:42
Klessou ... in a terminal when I do "sudo gnome-terminal", at the same time I hate to put my password ...09:42
cjwatsonso you don't need to go around separately verifying signatures from however many developers are involved09:43
Klessou ... in a terminal when I do "sudo gnome-terminal", at the same time I have to put my password ...09:43
Ademanthat makes sense09:43
pochuseb128, soren: I prepared gtk-vnc, although it was 0.3.5, but a user reported quite a few regressions so I'm afraid of breaking the virt stuff09:43
pochuseb128: soren: bug 21866709:44
ubottuLaunchpad bug 218667 in gtk-vnc "Please allow gtk-vnc 0.3.5 into Hardy" [Undecided,Invalid] https://launchpad.net/bugs/21866709:44
Ademananyways, it certainly feels less secure, but i don't believe it should be a problem09:44
seb128pochu: I've nominated 3 bugs for hardy, do you want to backport the corresponding changes?09:44
* \sh is just afraid about the chain of trust...I trust the *.ubuntu.com infrastructure more then I trust any temp source of download for packages ;)09:44
Ademanlol09:45
Mithrandir\sh: uh, the Packages file is signed so that doesn't matter.09:45
seb128pochu: the crash on closing, the compatibility mode and the powperpc color issue09:45
seb128pochu: those have no reason to break keyboard, etc, and hardy-proposed is there to test changes before pushing to updates09:45
cjwatsonthe only thing that apt-torrent would change is that it would become much easier to attack checksums09:45
Ademanplus i like the idea of using /var/cache/apt for 'seeding' packages, since that means the most popular packages will theoretically be fastest09:45
cjwatsonat the moment you have to take over a full-scale mirror to try that kind of attack09:46
cjwatsonwith apt-torrent, you'd be able to attempt collision attacks on individual packages09:46
cjwatsonwhich does scare me a bit (not as much as \sh's description, but a bit)09:46
Ademanwouldn't adding another simple metric like file size make a hash collision nearly impossible? (with malicious code anyways)09:46
\shcjwatson, which is quite easy with a small ammount of criminal energy09:46
cjwatsonAdeman: not in the slightest (anyway, size is already checked)09:46
cjwatsonAdeman: if you read the literature on collisions they're normally if anything easier to construct with the same file size09:47
Ademancjwatson: interesting, i would have assumed that adding a second constraint of any sort would make it tougher to do09:47
cjwatsonnot that one09:47
Ademanlol09:47
cjwatsonthe biggest constraint that makes a difference is that the result still has to be a valid .deb09:48
cjwatsonwhich I think means we probably aren't in serious danger right now09:48
Ademancjwatson: ah, true09:48
cjwatsonbut I would not bet money on that continuing to be the case09:48
cjwatsonAdeman: the thing is that you have to add an *independent* constraint, and it turns out that size and checksum are not as independent as you might think; as a rough unmathematical demonstration, think of the structure of the hash algorithm - the number of iterations of the hash you perform is very much related to the file size09:49
cjwatsonAdeman: similarly, other hash algorithms with a "sort of similar" structure aren't independent either; it turns out that MD5 + SHA1 gives you about 6 extra bits of security over SHA1 alone, which is much less than many people expect09:50
Ademancjwatson: ah true, this may fall into the same category, but would having two independent hash algorithms help?  say SHA-1 and MD5 work?09:50
Ademanahah09:50
cjwatsonno :-)09:50
cjwatsonyou're much better picking a single good one09:51
cjwatsonconcatenating hashes is a waste of time09:51
Ademanhrm09:51
cjwatsonunfortunately, right now, there are no good hashes09:51
pittiargh argh argh intltool09:51
cjwatsonin the sense that there are none that cryptanalysts aren't on a path towards breaking09:52
Ademando *.debs preserve file attributes like creation and modification dates?09:52
cjwatson.debs contain a tarball for the actual filesystem data, so yes09:52
Ademanwell that might be effective, even if it's not included in Packages.gz, a file manifest with creation and modification dates sounds effective09:53
cjwatsonnot really; bear in mind that metadata is a minority of the content09:53
cjwatsonI suggest not worrying about it for now; armchair cryptography is usually a lot harder than it looks. :-)09:54
Ademanlol09:54
Ademanwell i really am interested in working on apt-p2p, but the last thing i want to do is create a gaping security hole lol09:54
cjwatsonI don't think you really are - it's a concern but not a gaping one09:54
cjwatsonas in, it lowers the bar to attacks that aren't yet feasible, but maybe will be some day - but if they are then we'll have to address that *anyway*09:55
cjwatsonand this sort of thing has been improved lately by switching to SHA256 in Packages09:56
Ademanhrm, well i suppose i'll heap apt-p2p on my giant list of crap i want to contribute to09:58
Ademanlol09:58
jeromegScottK: hello10:02
jeromegI tested with glest-data, everything works fine10:02
pittidoko: did you see slangasek's questions on bug 222876?10:07
ubottuLaunchpad bug 222876 in gcc-3.3 "package gcc-3.3-doc 1:3.3.6-15ubuntu4 failed to install/upgrade: " [High,Confirmed] https://launchpad.net/bugs/22287610:07
jeromegScottK or jdong: could one of you ack bug 227225 please ?10:09
ubottuLaunchpad bug 227225 in gutsy-backports "Please backport glest-data from Hardy" [Undecided,New] https://launchpad.net/bugs/22722510:09
emgentsomeone can add tmp execption in fiordland.ubuntu.com?10:35
cjwatsonemgent: why not use the --lp option?10:38
cjwatsonas I suggested last night, but you didn't respond10:38
emgenti used it, but dont work10:39
\shemgent, did you install this lp-support  python package?10:40
emgentyes10:40
cjwatsonthen you need to talk to #canonical-sysadmin if you want changes to fiordland10:40
emgent\sh: python-launchpad-bugs ?10:41
\shemgent, yes...10:41
emgentyes is in10:41
\shor python-launchpad-integration something like this10:41
emgenti use p-l-b for anteater (u-whitehat) and work fine10:42
emgentonly requestsync dont work to me..10:42
\shhmm....but I thought the public smtp server is open to everyone, even without having an ubuntu.com address?!10:42
emgentDktrKranz2: say to me that fiordland accept only @ubuntu.com address10:42
\shemgent, nope...I don't use my @ubuntu.com address, it's at least attached to my lp account....but first used email is my sourcecode.de address...10:43
emgentoh ok10:44
\shemgent, it even works when you use a local smtp server which sends the email from your local system10:44
\shemgent, important is only the gpg sig to the mail, your key needs to be known to lp...anyways...going back to work :)10:45
emgentyes i know10:46
emgentanyway i'm talking with canonical-sysadmin10:49
emgentthanks for all now :)10:49
dokopitti: replied and fixed, please reject the package, to be honest ... I think fixing this was a waste of time10:51
emgentcjwatson \sh10:59
emgent(11:57) ( Ng) emgent: well from our MTA logs it looks like your mail was delivered fine, so we'll need  to check with the launchpad guys for what their code did with it10:59
pittidoko: ok; nothing to reject, though, it's not in the queue11:17
pittidoko: ah, now it's there, uploaded 33 seconds ago :)11:21
victory747ArneGoetje, asac I should ask you about font substutition in gnome/firefox/etc regarding Chinese fonts11:23
victory747I have long had problems when using simplified chinese that first a traditional chinese font is chosen and if the glyph fails in there it falls back to a simplified chinese font11:24
victory747but the two fonts used have different typefaces and sometimes the simplified font is hard to read.  This often happens to me in thunderbird.11:24
ArneGoetjevictory747: which font settings do you use?11:24
victory747in thunderbird, or in gnome, or in what?11:26
ArneGoetjevictory747: in Hardy WQY ZenHei is the default font for sans-serif and monospace and therefor the default on the desktop. And this one is a Simplified Chinese font which is fairly complete in the CJK Basic area. For Serif, AR PL UMing CN is used in the zh_CN locale, which does not follow any shape standard yet and therefor you will see mixed HK and CN style glyphs. This is work in progress. Otherwise we don't have any free purely simplified 11:28
ArneGoetjevictory747: ok, other question: did you do a fresh hardy install or did you upgrade from a previous version? Also, which locale setting do you use?11:29
victory747ArneGoetje, this was on a fresh gutsy install11:32
ArneGoetjevictory747: try upgrade to hardy11:32
victory747ArneGoetje, my hardy machine was upgraded, but I'm not sure if it has that problem or not11:32
ArneGoetjevictory747: which locale do you use?11:32
victory747ArneGoetje, The menus don't have problems, it's more things like web pages or text messages in thunderbird.  using zh_CN11:33
victory747zh_CN.UTF-811:33
ArneGoetjefor firefox and thunderbird you may need to tweak the font settings yourself in the Preferences dialog.11:34
ArneGoetjevictory747: although, on my hardy machine the fonts are chosen correctly for Chinese.11:34
victory747ArneGoetje, I'll look at it more in hardy and see if I can't find problems there.  I just remember being disapointed that it still was not working as expected but I don't have any specifics.11:36
victory747Where is the order of font substitution set?11:36
ArneGoetjevictory747: what does fontconfig-voodoo -l show ?11:36
victory747zh_TW11:36
victory747ja_JP11:36
victory747ko_KR11:36
victory747zh_HK11:36
victory747zh_SG11:36
victory747zh_CN11:36
victory747zh_MO11:36
victory747ka_GE11:36
victory747I wish we could change that for zh_CN locale.11:37
ArneGoetjevictory747: change what for zh_CN locale?11:37
victory747ArneGoetje, where is the list of fonts used.11:37
victory747change the order of font substituion11:37
victory747I mean where is the order of font substitution specified.11:38
ArneGoetjevictory747: the order of font substitution is correct for zh_CN. the question is just if your system picks it up or not11:38
ArneGoetjevictory747: /etc/fonts/conf.d/11:38
victory747oh?  But I would want to use a simplified font before a traditional font in ALL situations11:38
ArneGoetjevictory747: that;s the default setting11:39
victory747oh, even in gutsy?  maybe it's just my thunderbird that's messed up11:39
ArneGoetjevictory747: we just don't have any purely simplified Song style font available.11:39
victory747right, you said that11:40
ArneGoetjevictory747: in gutsy we don't have any purely simplified font available.11:40
victory747ArneGoetje, mabye I should do a clean install in vmware to test because my systems are always such a mess anyway11:41
ArneGoetjevictory747: that';s why I suggest to upgrade to hardy11:41
victory747ArneGoetje, I'll try to find some good cases - I have nothing specific right now that I can give to you11:41
ArneGoetjevictory747: as I said, on gutsy there is no purely simpplified font available. Therefore you can't change it.11:42
victory747ArneGoetje, ok, i'll upgrade my other computer to hardy soon and see how it works11:42
ArneGoetjevictory747: ok11:42
victory747ArneGoetje, do you suggest a fresh install instead?  I would probably do that anyway.11:43
ArneGoetjevictory747: depends on if you've messed around with fontconfig or not...11:43
victory747ArneGoetje, I'll try a fresh install I think - mostly i'm interested in the experience of chinese nationals11:44
ArneGoetjevictory747: ok11:45
* ArneGoetje gotta go now...11:45
=== azeem_ is now known as azeem
ograasac, my FF cashes if i use and close gmail (i rarely use the web interface so i didnt notice yet)11:59
asacogra: start ffox in -safe-mode11:59
asacand see if you still get that12:00
ograone sec12:00
ograwoah, a million password popups12:01
ograasac, http://paste.ubuntu.com/10491/12:02
ograsilent segfault12:02
asacogra: i think its -safe-mode not --safe-mode12:07
ograoh12:07
ograwell, it looked quite different and opened the granparadiso startpage12:07
ogra(didnt use the stored window size etc)12:08
ograbut i can try again12:08
asacogra: how can you reproduce? for me it doesn't crash12:09
creAtionany idea when the intrepid web forum will open up?12:09
ograasac, open gmail, go to the spam folder let it sit there for some seconds, close the tab and see ff vanishing with it12:10
=== cprov is now known as cprov-lunch
asacogra: running -proposed? or intrepid?12:10
ograare you crazy ? i wouldnt run intrepid :)12:11
ograrunning -proposed12:12
ograhttp://paste.ubuntu.com/10494/12:12
ograone dash gives a bit more output :)12:12
ograwonders if anyone is really mad enough to run intrepid before UDS :)12:12
asacmozillateam folks are all on intrepid already ;)12:13
asacnot my idea :)12:13
dholbachasac: does X run for them? :)12:13
ograwow, thats what i call couraged12:13
asachaven't asked that much in depth ... but i think so ;)12:13
dholbachit doesn't run in my kvm session12:13
* ogra wouldnt run intrepid for money12:14
jussi01just FYI, we now have intrepid supported by the bot package lookup ;)12:14
pittiogra: why not, it's certainly fun?12:14
ograpitti, i have work to do :)12:14
emgentcjwatson: i saw now, if i use requestsync with --lp script give a little output with "Could not find Firefox cookie file12:15
persiaogra: Not even enough to purchase a test box?12:15
emgent"12:15
pittiogra: in a way, you *do* get money for it :-P12:15
* pitti hugs ogra12:15
ograpitti, lol, indeed :)12:15
* ogra hugs pitti 12:15
emgentbut seems strange, anteater use l-p-b and work fine.12:15
emgent(with firefox cookies)12:15
pittiactually it's the first release where I did *not* upgrade to the new dev release immediately12:15
seb128same for me12:15
asacogra: are you in the SRU team? otherwise you must upgrade now ;)12:15
ograyeah, there is crazy breakage ahead12:15
sorenogra: I distinctly remember back in the Edgy days when your machine was broken in so many ways and all you had to say was "Edgy is so much fun". :)12:15
* pitti hugs seb128, the fix-hardy-harder companion12:15
seb128I'm pondering installing it somewhere though12:15
* seb128 hugs pitti12:16
sorenogra: Oh, google remembers, too: http://irclogs.ubuntu.com/2006/07/07/%23ubuntu-devel.txt12:16
soren:)12:16
ograasac, oh, u-m didnt tell me yet12:16
seb128I think I'll get a vm running it to upload GNOME srus to intreprid too at least12:16
cjwatsonemgent: ah, right, well that should be easy to fix I guess12:16
asacogra: can you install -dbgsym for xulrunner-1.9 and firefox-3.0 and get a backtrace please?12:17
cjwatson    try:12:17
cjwatson        cookiefile = glob.glob(os.path.expanduser('~/.mozilla/*/*/cookies.txt'))[0]12:17
emgenti will try to paste path ?12:17
cjwatson    except IndexError:12:17
cjwatson        print >> sys.stderr, 'Could not find Firefox cookie file'12:17
cjwatson        return False12:17
sorenogra: But of course you were younger back then. Slightly. :)12:17
cjwatsonaha12:17
asacogra: and try with a fresh profile (keep a backup of the old one in case its that)12:17
cjwatsonit's cookies.sqlite in firefox 312:17
ograsoren, haha, yeah the old times :)12:17
cjwatsonemgent: the version of requestsync in ubuntu-dev-tools trunk fixes this12:17
emgentok thanks cjwatson  i will take a look12:18
cjwatsonbug 20880812:18
ubottuLaunchpad bug 208808 in ubuntu-dev-tools "requestsync crashed with LPUrlError in _safe_urlopen()" [Medium,Fix committed] https://launchpad.net/bugs/20880812:18
ograasac, btw, nothing ff related in proposed for me ... sadly i cant compare before and after the xulrunner update i got yesterday, i didnt open gmail in this ff at all since the machine was installed until today12:19
asacogra: in -proposed there is a xulrunner-1.9 upgrade12:20
ograasac, yes, got that yesterday12:20
emgenttrue12:20
cjwatsonasac: FWIW (and it's highly subjective) the I/O problems seem a lot better now12:20
cjwatsonwith that xulrunner-1.912:20
asaccjwatson: comment on bug :)12:21
cjwatsonwill do at some point :)12:21
asaccjwatson: bug 21572812:21
ubottuLaunchpad bug 215728 in xulrunner-1.9 "[MASTER] Committing to urlclassifier3.sqlite causes excessive CPU usage and disk I/O" [High,Fix committed] https://launchpad.net/bugs/21572812:21
asacok, ill try to remember to remember you in a few days.12:21
cjwatsonah, never mind, I'll do it now12:22
asacthanks12:22
emgentcjwatson: http://bazaar.launchpad.net/~ubuntu-whitehat/ubuntu-whitehat-project/uwht.dev/revision/emgent%40emanuele-gentili.com-20080408225722-t2k7o6n8z4ztz43l?start_revid=emgent%40emanuele-gentili.com-20080409012057-5lmtoh9tc6cim8wu#anteater/anteater.py-s12:23
emgenti will try to fix with: glob.glob(os.path.expanduser("~/.mozilla/firefox/*/cookies.sqlite")).pop()12:23
siretartpitti: if you happen to be working on NEW, I'm happy to answer questions on the ffmpeg-free package if necessary. it replaces the current 'ffmpeg' source package which is in main.12:24
pittisiretart: Riddell's archive day today, I'll get to it on Friday12:24
dholbachasac: it's bug 22615612:24
ubottuLaunchpad bug 226156 in xorg "After update in intrepid branch Xorg " [High,Confirmed] https://launchpad.net/bugs/22615612:24
siretartpitti: Ah, never mind then12:25
emgentcjwatson: solved, now work fine.12:25
siretartRiddel: if you happen to be working on NEW, I'm happy to answer questions on the ffmpeg-free package if necessary. it replaces the current 'ffmpeg' source package which is in main. :)12:25
cjwatsonemgent: excellent12:25
cjwatsonpitti,evand: does encrypted-filesystems need another session at UDS (for ubiquity support)? it's on my roadmap, but I'm inclined to think it probably doesn't need a session12:26
asacdholbach: "branch" == crash?12:26
ograasac, same issue with a fresh profile, installing dbgsym now12:26
asacogra: what kind of spam do you have ;)12:27
pitticjwatson: I agree; the discussion bits are done, it's a "simple" matter of programming now IMHO12:27
cjwatsonpitti: ok12:27
cjwatsonI generally try to keep things that didn't get done on the roadmap so that they don't get forgotten about12:27
dholbachasac: Xorg does not find fonts with the new libxfont - that's why it bombs out12:28
ograasac, well, there seems to be about over 20000 msgs (as i said i never use the web interface, i only pop my mail into evo from there so i only clean thatup once every decade :) )12:28
asacogra: all on one page?12:28
ogranope12:28
ogradefault setting (100 per page i think)12:29
cjwatsonogra: you added "stripped-down lightweight kernel flavour" to the platform roadmap. Extra kernel flavours generally give me the willies because they increase build time a lot - is this just removing unnecessary modules, or is there more to it?12:29
ogracjwatson, its more about the core image, i was thinking about handling the modules in the initrmfs profiling spec (they somewhat belong together)12:30
cjwatsonwhat is in the core image that could be stripped down to improve performance?12:31
cjwatsonbearing in mind that simply removing features generally only improves size, not performance12:31
cjwatsonor is performance not what you meant?12:31
ograthats what i want to determine in the process of that spec :)12:31
cjwatsonI have indeed put modules in the initramfs profiling spec12:32
ograwell, ram hunger rather12:32
cjwatsonogra: could you discuss this one with BenC? I don't feel it really belongs in platform, but perhaps he has room for it12:32
ograarchlinux uses our ltsp implementation using a 2.6.24 kernel as we do, but their kernel manages to boot in 16M12:32
cjwatsonand can stick you in <person/> on his agenda so that you can be pulled in12:32
hungerogra: Who? me?12:33
ograthats my main pointer here, i'd like to compare our default setup to theirs and whatever else i find booting in such a setup12:33
ograhunger, do you have ram for breakfast usually ? else no, not you ;)12:33
hungerogra: Nope I usually have cornflakes, so not me, great:-)12:34
ogra:)12:34
ogracjwatson, that spec would also go hand in hand with the compcache one12:34
BenCogra: Any way you can use MODULES=dep for initramfs on the clients?12:34
BenCogra: or am I missing what you want to do?12:34
ograBenC, my core kernel (before using the intramfs) already needs more than 24M (32M if it should even be able to uncompress the initramfs)12:35
ograBenC, and thats with netboot (i.e. only NIC drivers in the initramfs)12:35
ograBenC, modules=dep is already a good way, but i think that can be improved as well12:36
ograBenC, my focus in that spec is on the kernl image itself and the space it needs to load, independently of the initramfs12:37
BenCogra: Then you are suggesting a custom flavor kernel for ltsp to use?12:37
ograBenC, generally for low ram systems12:37
BenCor maybe that we can improve our current -generic config12:37
ogranot tsp specific12:37
ograright, either12:37
BenCgotcha12:37
BenCogra: sounds like a good spec...can you email me a reminder?12:38
ograit will also be relevant for subnotebooks etc12:38
ograBenC, will do12:38
* ogra would love to get back to the sizes bootfloppies used to need ...12:39
pittiRiddell: https://bugs.edge.launchpad.net/ubuntu/+source/kaffeine/+bug/226475/comments/6 ??12:51
ubottuLaunchpad bug 226475 in kaffeine "remove dvd code install" [Undecided,Fix released]12:51
Riddellpitti: just a jest for the chap who closed the bug12:52
sivangmneptok: ping13:08
Hobbseesivang!13:12
lagapitti: thanks for your mail regarding the mythbuntu-control-centre SRU. IMHO it's not necessary that the first upload is promoted to -updates, i'd rather see the second one there. or is that against policy?13:26
mok0Does anyone here know something about the mesa package?13:29
mok0I'd like to know why glw was removed13:29
mok0... which annoys me a great deal since I am looking at source code that needs it13:30
ogramok0, check the changelog, it should tell you13:34
mok0ogra: it tells me that it has been removed, not why13:34
ografor sure it does13:34
mok0ogra: lesstif?13:34
ogralook closer13:34
mok0to remove lesstif deps?13:35
ograif it says so13:35
mok0ogra: is lesstif deprecated?13:35
* ogra doesnt do anything with mesa, but knows we write proper changelogs usually .-)13:36
mok0I still don't understand the reason for removing a software component that is needed by several programs13:37
mok0Unless there's a working replacement, which there isn't in this case13:38
ogravery likely because it would pull lesstif into main if it did build dep on it13:38
mok0ogra: well, then it should move to universe13:38
ograso you that would lose 3D support all over in ubuntu ?13:39
StevenKmesa needs to be in main -- other things in main require it.13:39
mok0... or another source package could build the missing bits13:40
ograStevenK, well, i guess it would be possible to drop it and go back to fvwm2 as default desktop :P13:40
mok0Sorry to sound uptight, but I just a wee bit annoyed to get stuck at this point13:40
ogramok0, the optimal solution would be to convince upstream to release it in a separate tarball, then it could build on its own in universe13:41
StevenKTo be completly honest, this is like the first time I've seen someone actually miss GLw.13:41
mok0StevenK: I just googled for it, and there are many people wanting it13:42
StevenKI meant on IRC13:42
pittilaga: no, it's not against policy, it just makes testing increasingly more difficult13:43
mok0Perhaps I am looking at old code, but I don't have a whole lot of motivation to spend days with it13:43
mok0I just need to compile this code and get on with it13:43
azeemmok0: use Debian?13:43
azeemor just locally rebuild the Debian mesa package against Ubuntu13:43
mok0azeem: yeah13:44
mok0azeem: will be interesting to see what then breaks13:44
azeemStevenK: I think I complained once, when one of my packages got stripped of its OpenGL features in Ubuntu13:44
azeemnever realized this was because of the main/universe split, I assumed some technical/maintainance issues13:44
mok0azeem: probably because only very few packages deal with 3D graphics13:45
StevenKGL isn't the problem, GLw is.13:46
mok0azeem: ... and Ubuntu aims to be a 2D graphics distribution.~13:46
StevenKmok0: Sigh.13:46
mok0StevenK: Sorry :-)13:46
StevenKAnd I think GLw affects like what, five packages.13:46
azeemmok0: eh yes, that was some pretty stupid reasoning here13:46
azeemStevenK: there might be tons of legacy code, dunno13:46
mok0StevenK: plus an unknown number of tarballs and locally developed software13:47
ScottKWhat it would need is some interested MOTU who would make an appropriate package ...13:47
* ScottK looks around at who that might be ....13:47
* mok0 hides13:47
mok0:)13:47
* mok0 sighs13:47
mok0This is not the digression I am looking for at the moment13:48
StevenKSo, you'd like us to demote mesa and re-enable GLw in Hardy?13:50
StevenK(Or something)13:50
Hobbseehe actually wants to start developing for breezy13:51
StevenKBwahaa.13:51
* Hobbsee is surprised that this is the first time it's clearly come up where it might get changed in intrepid, since breezy.13:51
* StevenK still has a breezy chroot around somewhere.13:51
* Amaranth doesn't even know what GLw is :P14:00
ograAmaranth, it involves brick like button shapes .... (lesstif)14:01
Amaranthso an old crappy toolkit using GL14:02
azeemit's to embed OpenGL into Motif apps14:03
azeemAFAICT14:03
infinityOr, rather, allows you to draw Motif widgets on a GL canvas.14:03
infinityIt's dead code.  Very dead code.14:03
ograprobably not on irix :)14:04
ogra(which might be dead code itself though :) )14:04
infinityIRIX is also dead code at this point.14:04
mok0StevenK: No14:04
mok0But perhaps create another source package the will build the missing glw  bits14:05
azeemmok0: just a warning - the mesa packaging isn't one of the friendliest14:06
azeemat least the Debian one, dunno if Ubuntu repackaged it14:06
StevenKIt's liable to bite limbs off14:06
Amaranthmesa is not friendly14:06
ScottKFrom what I've seen, a lot of science packaging is pulling stuff from the mists of time into the modern age.14:06
azeem<vorlon> also, is there anyone alive who understands && doesn't hate mesa's debian/rules? * ejka . o O ( you can write fortran program in any language... )14:06
mok0azeem: Ubuntu just disabled a few packages AFAICT14:06
azeembah, line break14:06
ScottKmok0: You might want to look at how I split amavisd-new into amavisd-new and amavisd-new-milter for an example then.14:07
mok0ScottK: ok, thanks for the tip14:08
mok0ScottK: yeah, I can see that the orig.tar.gz are identical14:10
ScottKThe packages are virtually identical.  I just don't build all the .debs in the two packages.14:11
ScottKThe idea is each is a minimal diff from Debian to build stuff for Universe or Main.14:11
ScottKMy alternative was to get Sendmail in Main, so split the package I did.14:12
mok0ScottK: very smart14:12
ScottKslangasek: You touched pinentry last.  I'd be glad to take the merge off your hands unless you want it for some reason?14:17
asactjaalton: if i get something like http://paste.ubuntu.com/10516/ ... what could be the reason? are those codes in the error message meaningful?14:24
mok0ScottK: How do you define the inheritance of both amavisd-new and amavisd-new-milter on the same Debian package?14:25
tjaaltonasac: was that all you got?14:25
asactjaalton: no i also get something about using --sync14:25
asactjaalton: http://paste.ubuntu.com/10517/14:26
ScottKmok0: My plan is to remember to to the second when I merge the first.  I've filed a bug against MoM to have it special cased to have MoM look to the one common parent for both.14:26
asactjaalton: funny thing is that its when starting midbrowser ... it works on my desktop though14:26
mok0ScottK: In fact, it is a problem that could arise often: splitting a debian multi package into several14:27
asactjaalton: can you install midbrowser package (should be quite small) and see if you get the same when starting it?14:27
tjaaltonasac: ok I'll try14:28
ScottKmok0: Historically stuff has just been dropped, but I wasn't comfortable with that since we'd provided the package for a long time.14:28
tjaaltonI think the serial* stuff varies14:28
ScottKmok0: I agree though.14:28
mok0ScottK: It's a bad idea to drop stuff without a working replacement14:29
asactjaalton: for me the serial stuff is always the same (at least in the same X session)14:29
tjaaltonasac: fails here too.. serial is different, rest is the same14:30
ScottKmok0: I agree, but sometimes with limited resources it's the best you can do.14:30
tjaaltonand to reply the original question, no I don't know where those come from ;)14:30
mok0ScottK: that's always a restriction, of course. But if distributions only want to be "self-contained", and forget that people have their own software that also has dependencies, it is a problem14:31
ScottKmok0: Fortunately motivated volunteers show up to solve the problem. ;-)14:32
mok0:-)14:32
asactjaalton: ok thanks for testing ... intel chip?14:34
tjaaltonasac: yes. here's another with the same codes: http://fixunix.com/xwindows/90854-received-x-window-system-error.html14:34
asactjaalton: wierd. i guess its compiz then14:36
asaci have metacity on the other system14:36
asac  gdk_window_set_events (gdk_get_default_root_window (),14:39
asac                        (GdkEventMask) (gdk_window_get_events (gdk_get_default_root_window ())14:39
asac                                        | GDK_ALL_EVENTS_MASK));14:39
asactjaalton: i dont understand why i cant listen for all events :(14:39
tjaaltonasac: that's from compiz?14:40
asactjaalton: no from midbrowser14:40
tjaaltonah14:40
asacwe listen mainly for Matchbox Events ... and key events14:40
asactjaalton: maybe if WM doesn't support an event i am listeing for it makes X choke?14:41
asacbut metacity doesn't have the events either14:41
kirklandpitti: hey, i had a few questions about some filesystem encryption work you've done previously, according to kees14:42
pittihi kirkland14:42
kirklandpitti: howdy ;-)14:42
pittikirkland: well, personally I did very little, but what's your question?14:42
tjaaltonasac: hm, mystery14:42
asactjaalton: anyway, thanks for the inof ... at least i have a new pointer now ;)14:43
tjaaltonasac: cool :)14:43
kirklandpitti: we're kicking around intrepid ideas in the server team, and i threw out a suggestion for creating an encrypted mountpoint in each user's home directory, say ~/Confidential using ecryptfs + PAM14:43
kirklandpitti: see http://ecryptfs.sourceforge.net/ecryptfs-pam-doc.txt for more detailed instructions14:43
pittikirkland: ah, I think I read about it14:43
pittikirkland: is this per-file or a block device?14:44
kirklandpitti: ecryptfs is built in Ubuntu kernels, ecryptfs-utils is presently in universe as of hardy14:44
kirklandpitti: per-file/per-mount14:44
hungerkirkland: Does that reencrypt on PW-changes?14:44
kirklandpitti: it's a vfs14:44
pittiah, cool14:44
pittihunger: well, I hope it has a long random key, and the password just decrypts the key14:44
pitti(what LUKS does)14:45
hungerpitti: Yes, looks like it does.14:45
kirklandpitti: right14:45
hungerpitti: Key is stored in a file... not as good as luks does it.14:45
pittikirkland: I'm not too convinced about per-file encryption, but it might be handy in some situation, yes14:46
lucentfolder-level encryption would be interesting14:46
kirklandpitti: ecryptfs was just a suggestion.  i'm open to other encryption technologies14:46
Caesartjaalton: okay, we'll do some testing internally14:46
kirklandrather than encrypt everything, i was thinking a per user folder to put your important stuff14:46
hungerkirkland: LUKS is better, but I don't see how to include that properly as a per-user setup.14:46
lucentkirkland: what I'm really missing in Ubuntu (Desktop really though) is support for file-based luks14:46
lucentwhen I pop in my encrypted USB partition thumbdrive, it works like a champ14:46
pittikirkland: oh, I wasn't criticizing the actual implementation of ecryptfs14:47
kirklandpitti: k14:47
pittikirkland: I just prefer to encrypt the entire fs, since it gives away less information and, more importantly, data does not leak to /tmp, swap, backup files, etc.14:47
lucentwhy must it only work for partitions?   is loop in a file too hard?14:47
tjaaltonCaesar: thanks, I haven't been able to reproduce it here14:47
pittilucent: loop files are a pain to setup by default, since you need to know the size in advance, etc.14:47
kirklandpitti: encrypted swap is essential, IMHO, if we start doing encryption by default at all14:47
lucentuhm,  swap is not encrypted?14:48
lucentmy laptop system I use here was installed with alternate CD, and I put LVM-on-luks14:48
hungerlucent: I think that is because udev does the luks magic... and having udev check each file as it becomes visible might be a bit expensive.14:48
pittikirkland: I have used an entirely encrypted LVM for half a year on my laptop without problems14:48
ograpitti, nbd loopmounts might help ;)14:48
kirklandpitti: but encrypt everything approach wastes a lot of cpu cycles on stuff like /lib, /usr,14:48
lucenthunger: ah14:48
kirklandpitti: soren said earlier, try doing a massive compilation on an encrypted filesystem14:48
ograpitti, makes every file you like a blockdevice14:48
hungerkirkland: Swap and tmp, too. /var/tmp as well.14:48
pittikirkland: true, but in practice it doesn't matter so much IMHO14:49
sorenpitti: Your laptop must be beefier than mine was.14:49
pittikirkland: I guess it really depends on what your aims are14:49
Robot101you have to have swap encrypted if you want encrypted files to be meaningful at all14:49
tjaaltonhow to summon ubotu on a channel?14:49
lucentLVM-on-luks works better than I expected14:49
tjaalton(ubuntu-x14:49
tjaalton)14:49
pittiif you just want to protect your office documents and encrypt swap, ecryptfs might be good14:49
Hobbseetjaalton: ask in #ubuntu-ops)14:49
hungerkirkland: If you want to do it right, then every user-writeable FS needs to be encrypted.14:49
Robot101or you'll just leak data onto your other partitions14:50
Robot101including /tmp14:50
sorenpitti: Most of the time, I got by by logging into my machine at home and compiling kernels on that, but when I was stuck on the outskirts of the internet (i.e. in the US), either option *sucked*.14:50
pittikirkland: but if you are concerned about a lot of differnet things (email, swap files, gpg keys, log files, everything that leaves trails), you quickly loose with that approach14:50
kirklandpitti: I use LVM encryption of my whole FS too...  but I don't think the run-of-the-mill Ubuntu user is ready for that.  I'd think a /home/user/Confidential directory might be more palatable14:50
hungerRobot101: Right. Every user-writeable FS needs to be encrypted if you want to do it right.14:50
lucentkirkland: "LVM encryption"  are you referring to a feature of LVM, or LVM-on-luks PV ?14:51
* Robot101 LVM's his entire HDD just because in practice, separating system data from mutable data is quite hard, particularly when you upgrade often too14:51
pittikirkland: the problem I see with that is that people might feel protected by that and stop being careful14:51
sorenlucent: The latter.14:51
Robot101LVM on LUKS, rather14:51
hungerRobot101: do you have one of those encrypting HDD drives?14:51
pittikirkland: TBH I'd rather do it the other way around: encrypt the entire /home, /, etc., and just put /usr and some other explicit stuff on an unencrypted partition14:51
lucentLVM on LUKS works but the PVs must all be encrypted, it's a flawed concept for server space14:52
pittilucent: how do you mean?14:52
* hunger would like to get one, but unfortunately his laptop is still using PATA for the drives (even though the control itself is SATA already).14:52
Robot101hunger: no its software, using LUKS14:52
lucentI mean that if you want to expand storage, you'd have to set up another partition with LUKS, and make that a PV14:52
Robot101(and dm-crypt)14:52
lucentso it means more passwords14:52
pittilucent: you can of course also encrypt the LVs, but by encrypting the PVs you might need fewer passwords14:52
Robot101you could stack them... :P14:53
pittilucent: right, if you have 50 PVs and 3 LVs, you'd rather use an unencrypted LVM and encrypted LVs, I guess14:53
lucentpitti: it's kind of unclear how to grow encrypted LVs14:53
hungerRobot101: Had that setup for a while, too. But LUKS kept on losing the key. Dunno why... got a new drive after the first time.14:53
kirklandpitti: so i like the idea of encrypting /root, /etc, /tmp ...  but for /home, I'd think on a per-user basis, and tied to PAM would be preferable14:53
pittilucent: but I do see that this is a problem, yes14:53
Robot101hunger: ... ouch!14:53
pittikirkland: libpam-mount and per-user encryption of ~ is great indeed14:53
hungerRobot101: I do have backups:-)14:54
pittikirkland: however, you still need a global password for the swap partition (or live without suspend-to-disk)14:54
kirklandpitti: ecryptfs has one other nice benefit for homedirs, that you can do incremental backups of the underlying encrypted files14:54
pittiyeah14:55
realistI only do encrypted swap and home14:55
kirklandpitti: i use that for securely storing sensitive data on my co-lo's14:55
pittikirkland: I think the biggest problem with all that is that the requirements of users are all differnet, and thus it is hard to come up with a default schema that suits most people14:55
realistNot sure of the benefit in crypting the system files?14:55
kirklandpitti: true dat14:55
pittirealist: encrypting /usr etc. is indeed a waste14:55
pittirealist: but encrypting log files and other stuff in /var isn't14:56
* realist nods14:56
pittiand /etc as well, for obvious reasons14:56
* wgrant installs a trojan on pitti's machine.14:56
pitti(secret SSL and SSH keys, shadow, etc.)14:56
hungerpitti: Depends... with encrypted /usr you can make sure nobody messes with those files.14:56
wgrantYep.14:56
pittinot really14:56
lucentthere's two motivations to encryption:  A)  Making it unclear what your data is  B)  preventing read access to unauthorized users14:56
pittiencryption is solely an offline protection14:56
pittiit does not protect you *at all* from Trojans14:57
realistIf they crack the live boxes, they still get an unencrypted view of all your filesystems14:57
pittiencryption is defence against stealing your (switched off) laptop14:57
hungerpitti: Well, when I am online /usr is mounted ro anyway:-)14:57
pittiif it's still in suspend-to-ram, or running, you lose14:57
lucentpitti: there's legal ramifications to this too14:57
pittilucent: yes, unfortunately14:57
lucentI mean to the point where you cannot be pursued because your data is indistinguishable from random data14:58
wgrantpitti: Right, but if I grab your laptop while you're away for a bit, I can boot into a live CD and alter some binary in /usr to grab your keys or similar.14:58
* StevenK is reminded of a netgod quote.14:58
realistpitti: suspend to disk also14:58
pittilucent: for people who are concerned about those, you need complete encryption of the entire hard disk, without metadata like LUKS14:58
lucentah yeah14:58
pittithen you can plausibly deny the existence of anything; 'just unpartitioned HD space'14:58
realistOr a recently powered down laptop (frozen memory hack)14:58
lucentI think my point is, which use case are we going for?14:58
lucentpeople encrypting financial saved data14:58
pittilucent: right, my point also14:58
lucentor people who are running stuff that's illegal under law14:58
pittii. e. hard to find a default setup which suits everyone14:58
kirklandoffline protection + protection of remotely stored/backed-up data (see incremental backups to co-lo's)14:59
pittisince the encryption goals vs. the price you're willing to pay (convenience, performance) vary14:59
realistI only encrypt /home for my gnucash data14:59
realistSome keyrings too, but keys can still be revoked14:59
pittikirkland: what would really be great is to offer setups for different use cases (complete encryption, /home encrypted, per-user ~/Confidential, etc.) and the installer would ask you15:00
pittikirkland: then we need to support all of those, of course15:00
kirklandpitti: ;-)15:00
lucentuh15:00
pittiwith the alternate installer, you have some flexibility at least15:01
lucentif I'm root uid, can I not just su into people's homes and read their Confidential?15:01
pittiand per-user ~/Confidential can be set up at post-install time15:01
pittilucent: not if those people aren't logged in15:01
wgrantlucent: If they're mounted, yes.15:01
kirklandlucent: yes, as pitti said, this is about offline protection of the data15:01
pittilucent: if you use libpam-mount, and ~/Confidential is unlocked at login time (with your password), that's reasonably ok15:02
kirklandand by offline, that can mean "if the user isn't online, logged in"15:02
pittilucent: of course root can just install a daemon which just waits15:02
lucentroot will...  oh okay  it will have normal root rights15:02
pittiand as soon as he logs in, copies it over to somewhere else15:02
lucentbut it won't be able to unlock the store15:02
pittilucent: eventually root will15:02
pittiroot controls the hardware, user's don't, so there is nothing that users can do to defend against root powers when they are online15:03
pittis/user's/users/15:03
Caesartjaalton: it's very difficult to reproduce15:03
wgrantOur root can lie in wait and catch the user's passphrase, and unlock the volume at their leisure.15:03
lucentIMO "encryption" should be handled much the same way "root uid" access via sudo is15:03
lucentyou'd do like, ideally,  crypdo15:04
kirklandpitti: however, i don't have root on my remote backup system...  i rsync the encrypted underlying fs, and I have no concern about that root reading anything of mine15:04
lucententer password,15:04
lucentnow have access15:04
lucentand it times out15:04
kirklandit's as secure as a few thousand gpg files15:04
pittikirkland: right, on the backup server your stuff is safe15:04
tjaaltonCaesar: ah, ok.. I remember there was someone who said he could reproduce it always15:04
kirklandpitti: right, just emphasizing that use case15:04
pittikirkland: right, my co-lo server provider also offers 10 GB on a central FTP backup server; I just pipe the backup tarball through gpg -e and ftp that15:05
kirklandpitti: whole tarball everytime, or are you able to do it somewhat incrementally?15:05
pittikirkland: I have a pretty simple system (weekly complete plus daily incremental)15:05
pittikirkland: it's not actually a tarball, it's an afio archive15:06
pittikirkland: that's still my ancient backup solution15:06
kirklandpitti: heh, if it works :-)15:06
pittiat home I am now using rsnapshot, that works less conveniently with gpg15:06
pittikirkland: it does, that's why I don't bother to change it :)15:06
pitti(it's just the /etc/.bzr, the psql dump, and some wiki data, a mere 25 MB compressed)15:07
kirklandpitti: hmm, so that's more "system" type data, than "user" type data...  which leads us back to your suggestion that defining particular use scenarios in the installer15:08
lucentHardy ships AFAIK with a pretty useless combination of Server choice for encryption15:09
pittikirkland: maybe we should do that step by step15:09
kirklandpitti: okay, well thanks for the feedback.  sounds like this is a bigger beast than i might have initially thought15:09
lucentno encrypted swap I think15:09
kirklandpitti: i'm all for doing this incrementally15:09
pittikirkland: we have supported by-block-device with LUKS for two releases, so we can additionally support one technology for per-file (such as ecryptfs)15:09
kirklandpitti: encrypted swap is a great start15:09
pittikirkland: so we should provide some integration bits to setup such a thing post-install (ecryptfs)15:09
kirklandpitti: good to hear you're open to this then....  ;-)15:10
pittilike a GUI to do it, and think about sane key handling, as well as getting the pam-mount bits right15:10
ograencrypted swap would become difficult with hibernating i think15:10
pittikirkland: oh, I am (I love encryption)15:10
pittikirkland: my pain starts when we'd want to set it up by default15:10
wgrantogra: Works fine as long as you don't use a random key.15:10
ogra(at least it forces twp PW prompts)15:10
ogra*two15:10
wgrantNot if all volumes are on one encrypted PV.15:10
kirklandpitti: so, like i said, the kernel part is already built into Ubuntu kernels (have been for some time)15:10
pittiour default LUKS setup doesn't require two keys15:11
kirklandpitti: ecryptfs-utils would need to be promoted from universe -> main15:11
lucentI think, that pain is avoided when having LVM on LUKS15:11
kirklandpitti: and the pam-mount bits, as you said15:11
ograpitti, well, you would have to give a pw for resume to read from swap, no ?15:11
pittikirkland: MIR doesn't scare me15:11
ograplus the pw we ask for anyway from gnome-screensaver15:11
lucentLVM on LUKS hibernate works for me here15:12
realistencrypted swap (using random key) should be the default15:12
pittiogra: right, you just need one password to decrypt the entire LVM (which includes swap)15:12
pittirealist: no, that breaks suspend-to-ram15:12
pittirealist: erm, to-disk15:12
realistpitti: make the two mutually exclusive?15:12
pittirealist: it might not be a concern on servers, but it sucks on laptops, and many desktops, too15:12
pittirealist: then you'd suspend to disk in an unencrypted way, there goes your data security15:13
lucentrealist: what sucks on laptops?15:13
cjwatsonkees: just to check, you guys are aware of bug 227322 (or at any rate the CVE behind it), aren't you?15:13
ubottuLaunchpad bug 227322 in openssh "[openssh] [CVE-2008-1657] possibility to bypass global "ForceCommand" directive" [Undecided,Fix released] https://launchpad.net/bugs/22732215:13
* kirkland points cjwatson to jdstrand (kees doesn't appear online yet)15:13
jdstrandcjwatson: yes15:13
cjwatsonjdstrand: ^--15:13
cjwatsonaha15:14
lucentoh I goofed the nickname hilight15:14
lucentpitti: what sucks on laptops?15:14
lucentI'm using LVM on LUKS for a laptop, it's been fine, I think?15:14
jdstrandcjwatson: it's funny, I *just* looked at it a couple minutes ago :)15:14
kirklandpitti: you have anything regarding encryption on tap at UDS?15:14
cjwatsonjdstrand: I get desktop notifications of new bugs coming in now, so if I happen to be online at the time, I notice pretty quickly15:15
pittikirkland: not ATM, no15:15
kirklandpitti: we've discussed it a little on the Server team, but realize that we probably need to involve the platform and desktop folks too...15:15
pittikirkland: incidentally, cjwatson just asked me this morning whether there was anything further to discuss15:15
pittikirkland: I said no for the ubiquity bits15:15
jdstrandcjwatson: oh yeah, that irssi thingy I saw you posted-- is it working out well? (I use irssi too)15:15
cjwatsonjdstrand: yeah, it's really good15:16
pittikirkland: and frankly I think that "encrypted LVM" and "manual partitioning" are the only sane fs encryption bits that we can put into the installer15:16
jdstrandI need to check it out15:16
azeemwhat irssi thing?15:16
pittikirkland: but I'd like to discuss the ecryptfs stuff further if you want15:16
StevenKazeem: I was about to say that15:16
cjwatsonazeem: http://people.ubuntu.com/~cjwatson/notifications/15:16
kirklandpitti: you bet ;-)15:16
cjwatsonno instructions on that page (I'll put them up at some point) - you need the fnotify irssi script as well15:16
cjwatsonbut with that you can have desktop notifications of people addressing you on IRC, even if you use irssi on a different machine via ssh and screen15:17
pittikirkland: can we combine it with thinkfinger? my left index finger is my real system, my right index finger unlocks a virgin and dull standard Ubuntu instlalation, for presenting at the customs? :-P15:17
Hobbseecjwatson: irssinotifier is good, too15:17
cjwatson(it's not original, I modified stuff I found on the web to make it work better)15:17
azeemoh that's awesome15:17
jdstrandcjwatson: oh excellent-- that is my configuration15:17
kirklandpitti: :-D15:17
Robot101cjwatson: *rad* :)15:18
azeemnow I just wished it worked on oldstable - I'm trapped with sarge at the uni15:18
realistpitti: they actually ask you to boot up your laptop?15:18
StevenKrealist: I've had Singapore customs ask me to15:18
cjwatsonHobbsee: cool, though I haven't quite figured it out from that page - how does that get the notifications back to your desktop?15:18
pittirealist: not so far15:18
StevenKAll that did was annoy me, and presumably, everyone behind me.15:19
ograpitti, ++ for thinkfinger support (my new lappie has that too, sadly the yet unsupported device)15:19
realistwow, next they'll be asking you to take your shoes off!?15:19
StevenKrealist: The US already does15:19
cjwatsonHobbsee: I quite like mine since I can really easily piggyback other things on top of it, like notification of new LP bugs via procmail15:19
pittiogra: Keybuk hacked that in for hardy15:19
Hobbseerealist: i had that.  in every airport i went through.15:19
realistI've never been asked to boot mine.15:19
Hobbseeand was frisked in almost all of them.15:19
azeemcjwatson: hrm, that only works if you can directly ssh to your desktop, right?15:19
Hobbsee(the shoes, not the laptop)15:19
ScottKUS customs explicitly claims a right to take an image of any digital media moving through customs.15:19
ograpitti, he wrote a driver ?15:19
kirklandpitti: what about a package, that requires ecryptfs-utils, pam-mount, etc. and does the setup for you?15:20
* ScottK doesn't plan to bring his secret key to UDS.15:20
cjwatsonazeem: no, mine is the other way round, you initiate the ssh connection *from* your desktop and it pulls notifications15:20
ograpitti, my device ID is yet unsupported by the driver15:20
lucentrealist: United States plane goers walk shoeless through the security checkpoints15:20
pittiogra: no, thinkfinger has been there for a long time; I have used it for a while, too15:20
azeemcjwatson: ah, didn't get that bit, that's gold15:20
realistScottK: they can take a copy of my encrypted partition then.15:20
pittiogra: he just fixed some integration bits15:20
StevenKrealist: Last time I flew to the States, it was. "Laptop out. pockets empty" for Australia, and it's "Jacket off, shoes off, laptop out, pockets empty, belt off" for the States15:20
cjwatsonazeem: I'll htmlify my instructions for it in a bit15:20
lucentyeah15:20
lucentStevenK: but you can have 7 inch knitting needles15:21
Hobbseecjwatson: ssh tunnel and the notify stuff, i think.15:21
lucentgo figure15:21
StevenKI didn't try that.15:21
Hobbseecjwatson: i didn't check it out too much, as i then switched across to bip.15:21
Hobbsee(meaning that i rarely used irssi)15:21
StevenKI didn't want to be in prison for UDS.15:21
StevenK:-P15:21
cjwatsonthe only slightly irritating bit is that you get notifications even if you're watching the channel15:21
lucentStevenK: my auntie likes to knit on the plane15:21
Caesartjaalton: yeah we've got users internally who can reproduce it reasonably reliably, but it's never affected me personally for example15:21
lucentthey made her throw out a paperback book because it was not "appropriate"15:22
StevenKlucent: I've heard about US Customs snapping knitting needles.15:22
ograpitti, well, according to upstream "its being worked on to get that devies into the driver as well" last time i looked15:22
lucentbut she was cleared to bring her knitting needles15:22
lucentha, no customs for her15:22
lucentthat's a different kind of personal abuse15:22
kirklandyeah, my wife brought knitting needles on the plane, and they seized my 3" screwdriver15:22
* lucent laughs15:22
lucentthat's exactly true15:23
lucentsome stupid country I live in15:23
lucentsorry to herd this off-topic15:23
lucentI just wanted to confirm the shoe thing is true15:23
lucentI was waved through with a 5lb snowboard iron15:24
lucentof all the things that could be a lethal weapon, my shoes definitely are not15:24
lucentthat iron was.15:24
lucentit sounds silly but that is how it goes, I checked my laptop through a few times and the worst that's happened is some fat woman or man sprinkles dust on the top and pretends to look concerned about your safety15:25
hungerWhen I went to the UK last they even took the time to vacuum clean my laptop at the custom area. That is service!15:27
lucenthunger: vacuum it...with drug-snorting dogs?15:27
wgrantThey have these great bomb-detecting vacuum cleanerish things.15:28
hungerwgrant: Whatever the reason... it did clean my keyboard pretty nicely.15:28
wgrantHeh.15:28
hungerwgrant: The guy didn't like being asked to vacuum around the screen once more though:-(15:29
wgrantNot surprising.15:29
jcwinnieHelp! Ubuntu. Help! Wubi has fallen down the well again.15:37
StevenKOkay then15:38
=== Shely_ is now known as Shely
sorenpitti: xgettext seriously doesn't scan for _("foo")? Only _('foo')?15:40
pittisoren: the quotes don't matter, of course15:41
pittisoren: but not _(var)15:41
* soren exhales, relieved.15:42
* pitti apologizes for his inconsistent quote style in the bug reply15:42
pittisoren: in python I generally prefer ', since it doesn't need shift15:43
ograpitti, depends on your keymap, really15:43
* ogra needs shift here on a german keymap15:44
ograoh, sorry i just noticed i have the ' key twice ....15:44
* ogra shuts up15:44
sorenpitti: So, how does this work, then? print _("foo %s") % bar ?  print _("foo %s" % bar) ? Something else?15:44
cjwatson_("foo %s") % bar15:45
sorencjwatson: Thanks.15:45
cjwatsonthe translatable thing needs to be (roughly) a constant string and translators are expected to do sensible things with format string markup inside15:45
tjaaltonis archive.u.c having some issues? I get hash sum mismatches15:46
ograits slow at least15:46
tjaaltonit is that15:46
tjaaltonis there a place to sync a mirror from15:46
ograi just switched to the de mirror here for chroot building, that helps15:46
lucent_("foo") + bar15:46
lucentheh15:47
sorentjaalton: It's horribly slow, and I keep getting checksum errors and shit, too.15:47
tjaaltonsoren: ok, I'll change to another mirror then15:47
sorentjaalton: apt-cacher was acting up at the same time, so I blamed that.15:47
azeemcjwatson: it shouldn't fire for highlights in the current chan/window, IMO15:54
pittisoren: btw, if you fix the _() thing, please reupload with the same version number15:57
pittisoren: otherwise -changes@ and my SRU watch pages will just get the _() update changelog, and not the original one15:57
cjwatsonazeem: yeah, I'm sure that's fixable in irssi/fnotify, just haven't spent time figuring it out15:57
sorenpitti: Already done.15:58
sorenpitti: ~5 minutes ago, so it should be in your queue now.15:58
pittisoren: great, thanks15:59
ogracould https://wiki.ubuntu.com/SecurityUpdateProcedures be linked from the development wikipages ? it took me quite a while to find it by searchig16:03
=== ubottu changed the topic of #ubuntu-devel to: 06 May 21:00 UTC: Community Council | 07 May 21:00 UTC: Server Team | 08 May 13:00 UTC: Desktop Team | 09 May 04:00 UTC: MOTU | 14 May 21:00 UTC: Server Team | 15 May 13:00 UTC: Desktop Team
tjaaltonwhoops? :)16:15
=== Hobbsee changed the topic of #ubuntu-devel to: Archive: Intrepid open, go wild! | Ubuntu 8.04 LTS released! | Development of Ubuntu (not support, not application development on Ubuntu) | #ubuntu for support and general discussion for dapper/feisty/gutsy/hardy, #ubuntu+1 for intrepid | #ubuntu-motu for getting involved in development | http://wiki.ubuntu.com/UbuntuDevelopment | See #ubuntu-bugs for http://wiki.ubuntu.com/HelpingWithBugs
Hobbseenice work.  that would have changed all channel topics that weren't locked16:16
Hobbseeuntil it crashed, anyway16:17
realistcjwatson: is there anything special I need in order for fnotify to work?16:22
cjwatsonrealist: I have proper instructions on http://www.chiark.greenend.org.uk/~cjwatson/code/notifications/ now16:22
tjaaltonhmh, apt-mirror refuses to work with !a.u.c16:22
psusibdmurray: my ubuntu-bugcontrol membership is about to expire, could you renew it please?16:24
tjaaltonHobbsee: changed the topic on #u-x again16:24
realistcjwatson: it doesn't appear to be writing out to ~/.irssi/fnotify for some reason16:25
Hobbseetjaalton: i don't have control, i'm just watching -ops16:25
tjaaltondarn16:25
cjwatsonrealist: dunno about that, sorry, it just worked for me16:25
cjwatsonrealist: you may need to explicitly /hilight things you care about16:25
Hobbseetjaalton: i've been staying quite deliberately away from it16:25
tjaaltonHobbsee: :)16:26
realistcjwatson: not even working for privmsg :-(16:27
ograseb128, do you think david will put any more time into gnome bug 526320 ? he doesnt sound like he would16:30
seb128ogra: no, you want the change backported right?16:31
ubottuGnome bug 526320 in gio "should not list mounts that the user doesn't have permission to use" [Normal,Unconfirmed] http://bugzilla.gnome.org/show_bug.cgi?id=52632016:31
seb128ogra: it's on my todolist16:31
ograi have lots of ltsp users complaining, yes16:31
ograwow, ubottu is slooow :)16:31
ograseb128, ok, thanks, but he doesnt seem to really care which is really sad imho16:32
seb128ogra: not really true, he's usually responsive but I think he has lot of other issues on his plates already and there is no obvious way to get that one work better easily16:33
ograyeah, fedora is nearing the release, i understand he's busy16:34
emgentdholbach: thanks for ACKs, sympa fixed and ready when you have time. :)16:35
Hobbseeogra: they're trying to fix the meeting stuff16:37
ogrameeting stuff ?16:38
jdaviesogra: the automatic topic update in #u-meeting16:39
dholbachemgent: I guess I'll get to it tomorrow if nobody else does before - thanks16:40
emgentthanks to you dholbach16:40
ograHobbsee, ah, youre referring to my bot comment ... took a while to make click :)16:41
Hobbseeogra: yes :)16:41
=== cprov-lunch is now known as cprov
azeemcjwatson: ok, took me one irssi segfault, but here it is: http://paste.debian.net/2301/16:51
azeemdoesn't notify for current chan anymore16:51
* cjwatson applies the same to priv_msg16:53
azeemgood point16:56
cjwatsonazeem: looks good, I think16:56
=== asac_ is now known as asac
=== effie is now known as effie_jayx
cjwatsonazeem: updated http://www.chiark.greenend.org.uk/~cjwatson/code/notifications/fnotify, thanks16:58
LaserJockazeem: is there a reason you're going nuts in #debichem? :-)17:15
Savago@all: it seems that Hardy has some problems with Bluetooth services (# 148712 and others).17:15
SavagoIs anyone actively working on this?17:15
* Savago wants to help if possible.17:16
azeemLaserJock: euh17:17
azeemLaserJock: well, see above, I was testing cjwatson's fnotify script17:17
azeemI totally thought I was alone with CIA in there17:17
LaserJockazeem: no problem, just wondered if you were having mental problems and started talking to yourself ;-)17:19
azeemcjwatson: I've now modified it further to only notify if I'm away (which means screen detached when using screen_away), but this is probably not everybody's facourite17:19
cjwatsonyeah, I don't use that ...17:19
cjwatsonthough I sort of like the idea, not sure17:19
realistcjwatson: I found the bug in fnotify17:23
slangasekScottK: I have no attachment to pinentry, feel free to take the merge18:02
ScottKslangasek: OK.  Will do.18:02
Keybukasac: is network-manager-applet supposed to be missing a build-dep on libnotify-dev?18:08
ScottKIs CDBS generally broken right now or is my upload special?18:34
ScottKhttp://launchpadlibrarian.net/14261790/buildlog_ubuntu-intrepid-i386.pinentry_0.7.5-2ubuntu1_FAILEDTOBUILD.txt.gz18:35
norsettoscottk: is that inttool?18:35
ScottKYes18:36
norsettoscottk: its broken right now18:36
ScottKnorsetto: Thanks.18:37
norsettoScottK: np18:37
=== bigon` is now known as bigon
mario_limonciellmvo_, ping19:55
mvo_hello mario_limonciell19:58
mario_limonciellhi mvo_ .  i was speaking to Amaranth about a fix for bug 16026419:59
ubottuLaunchpad bug 160264 in dell "[nvidia] compiz displays white screen when locked" [High,Confirmed] https://launchpad.net/bugs/16026419:59
mario_limoncielland he had said to bring it up to you so it can get into intrepid before going the SRU route on it19:59
=== gnomefre1k is now known as gnomefreak
mvo_mario_limonciell: intrepid is in a bit too much flux20:09
mvo_mario_limonciell: if it needs testing I think the compiz ppa is a good candidate20:09
mvo_mario_limonciell: but we can sru it directly if the patch is reasonable small (let me check)20:09
mario_limonciellyeah its very small20:09
mario_limoncielli've attached a debdiff to the bug20:09
mvo_mario_limonciell: hm, it just drops 30_fix_screensaver ? is that 100% sure that the xserver is now fixed ? otherwise we open a huge security hole20:11
mario_limonciellmvo_, yes20:11
mario_limoncielli linked the rationale20:11
mario_limonciellin my comment20:11
mvo_mario_limonciell: yeah, I have seen the changelog - I will give it a test run tomorrow morning, ok?20:12
mario_limonciellbut widespread testing will of course be necessary per the SRU20:12
mario_limonciellmvo_, sure20:12
mario_limoncielli've also built it on my PPA if you want to save yourself a test build20:12
mvo_mario_limonciell: nice, thanks20:12
mario_limonciellno prob20:13
=== devfil is now known as dfiloni
=== gnomefre1k is now known as gnomefreak
=== mathiaz_ is now known as mathiaz
stgraberWho's ubottu's owner ? We would like it on #ubuntu-testing, we are really missing ubotu there :)21:55
dsasstgraber:  You need to speak to seveas21:56
_MMA_stgraber: #ubuntu-ops might be able to help.21:59
stgraber_MMA_: right22:00
=== fta_ is now known as fta
=== tkamppeter_ is now known as tkamppeter
hmullerI'm looking for a pointer to information that explains the purpose of "build-stamp" in a makefile.  I've searched both the manpage and manual, and googled.23:48
LaserJockhmuller: I believe it is to make sure that the build only happens once23:56

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!