/srv/irclogs.ubuntu.com/2008/05/12/#ubuntu-devel.txt

pwnguinis this an appropriate channel to discuss free/nonfree inclusion of documentation?00:46
pwnguinbug #32042 is about openGL documentation00:47
ubottuLaunchpad bug 32042 in mesa "OpenGL subroutine man pages missing" [Low,Confirmed] https://launchpad.net/bugs/3204200:47
LaserJockpwnguin: what did you want to discuss?00:49
pwnguinwell, I'd like to see the bug fixed00:50
pwnguinbut i haven't seen anything representing a decision. they're technically non free as is, because of a requirement to notify SGI if you are made aware of an IP claim by a third party00:51
pwnguindoes ubuntu regularly NOT tell copyright holders when sued?00:52
ScottKIt doesn't matter really.00:52
ScottKpwnguin: The best solution is to make a separate -doc package and put it in Multiverse.00:53
pwnguinthe only developer comment in that bug is that it cannot be distributed =/00:53
pwnguinScottK: if mesa is in main, wouldn't it be restricted?00:54
ScottKIf it can't be distributed, then it can't go in at all.00:55
ScottKRestricted has some very special things that go in it.  I'd expect it's in multiverse if at all.00:55
pwnguinas far as my lay interpretation of the troublesome clause goes, it's not a restriction per se on distribution00:56
pwnguinjust an additional burden00:56
ftastgraber, would you accept this: http://www.sofaraway.org/ubuntu/tmp/pastebinit-01-ubuntu.patch ? and this (on top) http://www.sofaraway.org/ubuntu/tmp/pastebinit-02-mozilla.patch ?01:01
awen_would it be appropriate to subscribe ubuntu-main-sponsors for a patch like bug 200750 ? ... or should i rather try contacting the last uploader of the package instead01:43
ubottuLaunchpad bug 200750 in inkscape "Add python-uniconvertor to Recommends and patch inkscape (for Corel Draw formats support)" [Medium,Confirmed] https://launchpad.net/bugs/20075001:43
ScottKawen_: Don't we still need python-uniconverter in Ubuntu first?01:52
ScottKawen_: Then generic answer though is subscribe ums.01:53
awen_ScottK: it got included a few days ago01:53
ScottKawen_: Launchpad doesn't seem to know about it that I can find.01:53
awen_ScottK: https://launchpad.net/ubuntu/+source/python-uniconvertor01:53
ScottKI see LP search functions are working as well as usual.01:54
ScottKIIRC bryce is involved in inkscape and might be good to ask too.01:55
awen_okay, thanks ... i've subscribed ums anyway though01:57
awen_bryce: if you are involved in inkscape and have a minute, please have a look at the above01:59
=== jamesh_ is now known as jamesh
=== ember_ is now known as ember
TheMuso/c/c05:41
slangasekScottK: right, well, I guess I'll roll back hal and see what that gets me for starters06:51
=== hunger_t is now known as hunger
emgentmorning09:17
tseliotemgent: morning09:25
emgentheya tseliot09:25
emgent:)09:25
Riddellpitti, doko: four MIRs needed for KDE 4 when you have time09:31
stgraberfta: Both patches look good, are those done for the current version in Ubuntu or the version we have in bzr ?09:35
emgentRiddell: heya09:43
Riddellhi emgent10:02
Riddellit's another european holiday today? they just had one!11:38
* TheMuso is wondering why -devel is so quiet.11:39
RiddellWhit Monday apparantly, guess they're all in church11:40
Ngthey?11:40
Ngare we not european now? ;)11:40
Riddellnot so you'd notice by the different numbers of bank holidays :)11:41
SpadsThe UK is in Africa, clearly.11:42
\shat least it's such a nice day for doing merges and drinking some beer at home ,-)11:44
TheMusoHrm. Is it just me, or is launchpad taking a while to respond to http requests?11:47
\shTheMuso: here too...at least launchpadlibrarian11:47
TheMuso\sh: Yeah thats what I'm trying to access as well.11:47
\shTheMuso: it's doomed ;)11:50
TheMuso\sh: heh I just managed to get the diff I wanted, so I'm fine for now.11:51
\shTheMuso: fun,..me too :)11:51
pochunot a holiday in Spain :(12:07
hwilde   Device Boot      Start         End      Blocks   Id  System12:25
hwilde/dev/sdb1               1       19458   156289848+  42  SFS12:25
hwildewhat is filesystem SFS ?  it won't mount with ntfs12:25
cjwatsonSFS is partition type (hex) 4212:29
cjwatsondoesn't necessarily correspond to the filesystem actually on that partition12:29
cjwatsonuse 'sudo vol_id --type /dev/sdb1' to find that out12:29
hwilde"/dev/sdb1: unknown volume type"12:30
hwildeI guess that's their fault for letting windows merge their partitions12:30
hwildewho knows what that did12:30
hwildecjwatson, do you know Simon12:33
hwildeTatham12:33
\shsabdfl: nice post about "The Art of Release"12:34
cjwatsonhwilde: yes, why?12:35
hwildebecause putty freakin rules12:37
hwildechiark++12:37
cjwatsonputty is indeed superb, that's why I maintain its Debian package ;-)12:38
\shsabdfl: but one thing you forgot: "How do we get other software vendors like adobe to test and release and support their enterprise software for Ubuntu LTS versions"...I do think as an example of Adobe Flash Media Server...12:38
hwildecjwatson, any way to control the display font tho?  it's too big12:40
cjwatsonhwilde: sure, -fn, or ctrl-rightclick -> Change Settings -> Window -> Fonts -> Change...12:44
hwildecjwatson, I mean in the putty window itself.  before you connect12:46
hwildeI have the profile set for the terminal windows12:46
hwildeit's like 14pt font size12:47
cjwatsonthat's just whatever GTK's defaults are - however, ability to configure this consistently with the rest of the system should improve once the GTK2 port of putty finally lands, which should be fairly soon12:48
cjwatson(assuming this is Linux putty rather than Windows putty; I don't know much about the latter)12:48
hwildeooo gtk212:49
hwildegtk-theme-switch seems to do it :)12:50
ftastgraber, against ubuntu, there was no Vcs-Bzr in debian/control12:53
ftastgraber, I have a small fix too: http://www.sofaraway.org/ubuntu/tmp/pastebinit-03-fix.patch12:54
stgraberfta: https://code.launchpad.net/~pastebinit-developers/pastebinit/trunk12:57
TheMusoc12:59
TheMusough12:59
\shTheMuso: ugh?!13:00
TheMuso\sh: Meant for my mutt window.13:01
=== davmor2 is now known as davmor2_dinner
\shTheMuso: doesn't mutt make "whee" instead of "Ugh"? ;)13:02
TheMuso\sh: heh13:02
fta_stgraber, if you prefer, i can branch that and you'll just have to merge13:04
stgraberfta_: yes, that or a patch based on the current bzr revision would rock. I don't have a lot of time to spend on pastebinit but I plan to push a new version in Ubuntu for Intrepid if David or someone else don't send it to Debian before13:06
fta_ok, i'll do that then13:07
sabdfl\sh: yes, we have some work to do in getting the ISV's to embrace our release cycle13:15
sabdflthough LTS's are a pretty obvious target for them13:15
\shsabdfl: yes...even that adobe is not playing nice with rhel in general...anyways..this is really what's missing for serious "non webserver mass rollouts of ubuntu" ;)13:16
=== fta_ is now known as fta
maswan\sh: There is alot of other enterprisy software/hardware that I'd like to see support for over anything from adobe, but then I'm not doing much consumer-related stuff. :)13:22
hwildehow about visio :)13:23
maswanhwilde: what's that?13:23
hungerCould somebody push the perl stuff that is still build against the old perl version into the build queue again, please?13:23
hwildethat's the only proprietary thing I haven't been able to hack yet.13:23
hwildelike flowcharts and stuff.  (think dia)13:23
\shhwilde: visio is just nice with the Datacenter Planning Plugin ;)13:23
hwilde\sh, gimme13:24
cjwatsonhunger: if it's already built successfully, it needs a developer to reupload (with build1 versioning, or incrementing the number after ubuntu if it's modified)13:24
cjwatsonwe don't have a way to do that automatically13:24
maswanhwilde: ok, never used it. I'd just like vendor support for ubuntu connected to tape libraries, etc13:24
=== sebner_ is now known as sebner
hwildemaswan, now that dell is offering preinstalled we will see an increase in vendor support13:24
hungerhwilde: Try kivio. It works ok, even though it does not have too many stencils.13:25
maswanhwilde: they are doing that in the server space now?13:25
\shmaswan: yes, there are more software/hardware things to support...but right now, those FLV streaming stuff is the way to go...and seeing that ISVs who are supporting their software for RHEL or SLES only it's depressing me..because most of the software runs just fine on debian/ubuntu..but you are stuck with support from the ISVs when running on non-supported OS..and OS doesn't mean "Linux in General" but "RHEL" or "SLES" and not "LTS" ;)13:26
\shhwilde: dell is not pushing ubuntu on servers...not right now, it's sad...I would like to see e.g. HP or IBM to push their hardware (especially blade stuff) with ubuntu..because it just works13:27
hwildemaswan, scheduled to announce Q1 next year  http://www.linux-watch.com/news/NS4557593896.html  http://www.theregister.co.uk/2007/11/16/dell_ubuntu_servers/13:27
maswan\sh: I know, I know.13:27
ftastgraber, done: https://code.edge.launchpad.net/~fta/pastebinit/trunk  Please review and pull :)13:27
\shmaswan: btw...did you already had hands on the new areca sata raid crack?13:28
maswan\sh: I just see a different set of software/hardware section, and adobe is very far from anything I run or want to run. :)13:28
\shmaswan: well, of course, oracle is the other needed ISV who needs to be switched to Ubuntu ;)13:29
hwildebut then ubuntu is going to be bogged down with all their overhead13:29
hwildei'm glad there is no oracle13:29
maswan\sh: nah, just get all ibm's stuff and I'll be happy, TSM, DB2, hw support, GPFS, etc. :)13:31
\shmaswan: hmmm? ibm hs20 blades are running just fine on Ubuntu ;)13:32
\shwell it's old...13:33
\shmaswan: but I can assure, that IBM is testing their HW also on ubuntu and debian...at least that is what a friend is doing here in germany13:34
=== asac_ is now known as asac
andrew___So far as I can tell, vinagre can't do IPv6, but vino requires it in order to do local VNC connections.  If this is a bug, which package should I report it in?13:46
\shandrew___: vinagre13:48
andrew___Thanks, will do.13:48
\shbut I wonder what's the difference between ipv4 and ipv6 despite the difference between 32 and 64bit addresses.13:49
andrew___The difference in what sense?13:49
cjwatsonerr, significant; there are books on the subject13:49
hwildevino does not require v6 for local connex, I do it all the time13:50
andrew___hwilde: Strange - can you confirm that `netstat --inet -lpn` includes vino in it?13:50
\shcjwatson: hmm..not in that case..I thought glibc gives you a nice compat mode for connecting to ipv4 or ipv6 addresses13:50
cjwatson\sh: to some extent, but it's not entirely trivial13:51
\shcjwatson: oh joy...at least on the application level we shouldn't make the change more difficult ;)13:52
cjwatsonit can't be made a complete drop-in replacement13:52
hwildeandrew___, wow it is using v6 !  I didn't even realize I had it enabled13:52
hwildeandrew___, tcp6       0      0 *:5900                  *:*                     LISTEN     5461/vino-server13:52
hwildetcp6       0      0 mpro:5900               mpro:38308              ESTABLISHED5461/vino-server13:52
andrew___:)13:52
andrew___You might want to look at ip6tables then - it's probably not firewalled.13:53
hwildeeh13:53
hwildei'm not scurred13:53
andrew___iptables is IPv4 only.  If you've got IPv6 enabled, you need to use ip6tables to firewall your IPv6 connections.13:54
\shcjwatson: I'm damned...not only I have to take care about the routers and kernels but also on the apps....not only damned, I'm somewhat doomed...13:54
hwildeor I could just not care13:54
andrew___More relevantly though, which VNC client are you on?13:54
andrew___Fair enough.13:54
hwildeandrew___, I just typed vncviewer13:54
cjwatson\sh: it might be a novel idea to read up on it before panicking13:55
hwildenovel idea to read up on it    lol nice pun13:55
andrew___Ah, okay.  So it's still a bug in vinagre.13:55
andrew___Thanks.13:55
cjwatsonhwilde: unintentional :)13:55
hwildeI was going to say, it's a bit early for that :)13:56
\shcjwatson: we are doing some migration tests...so I'm not panicking...but I have to extend our tests13:57
\shregarding some non standard aps13:57
\shapps even13:57
ScottK\sh: You have upstream IPv6 connectivity?13:58
\shScottK: we are playing with ipv6 connectivity...but for production stuff, no13:58
ScottKOK.13:58
ScottK\sh: Yes.  You'll need to test all the apps in an IPv6 environment.  It's not at all transparent.13:59
\shScottK: there are some other issues I have to take care about first...e.g. php crc32 implementation ;)13:59
cjwatson\sh: IPv6 has been in a chicken-and-egg situation for a long time; it hasn't been worth ISPs' time as long as OS vendors don't support it well (and as long customers aren't asking for it), and it hasn't been worth OS vendors' time to support it as long as ISPs don't14:00
cjwatsonso I'm all for the deadlock being broken14:00
cjwatsonbut yes, as ScottK says it isn't a trivial migration by any stretch of the imagination14:00
ScottKJust teaching an app I'm upstream for to do IPv6 CIDR matches was enough pain for me for a while.14:01
\shcjwatson: I know...when I started to play with ipv6 <-> ipv4 tunnel ISPs...it went bad...but tbh, it's time to get ipv6 out of the kindergarden14:01
\shScottK: oh well, just explain people ipv4 cidr..it makes them stupid again...people think only in classes :(14:01
sebner\sh: well, it's also time to get 64bit out of the kindergarden -.-14:03
maswan\sh: yes, but for some things "supported" is rather important. not just "works".14:04
\shsebner: tell MS ... that's why we have to fight with win32 on x86_64 still14:05
sebner\sh: it isn't that a big step but there will always be people that are complaining that app xy isn't working. /me ist just happy hat nexuiz is running on amd64 =)14:07
\shmaswan: when I read about the last ripe ipv6 meeting and googles attack on it, I wonder when we accomplish the change from 32 to 64...we all know changes are difficult and painful...14:08
\shsebner: regarding developers, 32bit vs. 64bit is a big step..many devs are not knowing the difference between (pointer)(int) and (pointer)(long) on 32 and 64bit archs....even today...14:10
wgrant\sh: This is why we have cluebats.14:10
cjwatson\sh: BTW, IPv6 addresses are 128-bit, not 32-bit14:10
\shcjwatson: not 6414:11
cjwatsonerr ... "not 64-bit"14:11
cjwatsonyes14:11
\shyeah.../me has a beer too much in his system ;)14:11
\shno coincidence...but "one bit too many" ;)14:11
* \sh should go and prepare the asparagus14:12
\shCan't use string ("2/8") as a HASH ref while "strict refs" in use at debian/file-actions.pl line 40, <JL> line 23. oh joy14:13
maswancjwatson: we have been doing ipv6 testing here at ACC, and as of the last 2-3 years or so base OS support has been there, and the last 1-2 years have had "most" application support working too.14:14
cjwatsonmaswan: yeah, it's just been gradual rather than a strongly-coordinated effort14:14
cjwatson(with all due respect to people like fabbione who've been pushing for it for a long time)14:15
cjwatsonand I rather suspect that network-manager doesn't have great IPv6 support ...14:15
maswancjwatson: the thing that worries me is that the 2011 date is getting closer and they aren't pushing it back to "5-10 years from now".14:15
wgrantNM works fine with stateless autoconfig, but not sure about other kinds.14:15
cjwatsonthat's the address exhaustion time?14:16
maswancjwatson: yeah14:16
* wgrant doesn't know of any consumer .au ISPs that provide native v6 :(14:16
Ng+projected14:16
cjwatsonmy ISP is still going LA LA LA NO URGENCY14:17
TheMusoa/c14:17
wgrantcjwatson: They all are.14:17
\shcjwatson: I'm more concerned about the routers (say juniper, cisco to name the big guns)...you could come over some problems with ipv4 tunnels regarding testing/fixing time .. but even our routers are not behaving with ipv614:17
maswanwgrant: last time I checked, static setup was a pain. we haven't tried it on hardy though, the hack in network/interfaces with pre-up and up-hooks to disable autoconf was working14:17
wgrantcjwatson: It's ridiculous.14:17
maswanNg: well, yeah. I'm just worried because we're getting close and the projections aren't getting (significantly) pushed back.14:17
ScottKLack of IPv6 just means they can charge more for IPv4 addresses.  I'm not sure why an ISP would invest money to avoid that.14:18
wgrantScottK: That's a good point.14:18
\shScottK: because ripe e.g. as european ip registry has a policy to not pay for ip addresses...at least when I was member of ripe14:18
ScottKSo your ISP gives you unlimited static IPs for no extra cost?14:19
maswanScottK: Well, when procurement of connectivity for organisations include "ipv6 connectivity" as a requirement14:19
\shScottK: setup fee is ok...but not for the ips14:19
Ngmaswan: there are a bunch of really huge ipv4 allocations that are extremely old and unnecessary, which could be reclaimed14:20
NgI think HP have 3 /8s, two of which are from aquisitions14:20
ScottKmaswan: As an organizatin, why would I want to raise my contract cost to get that?14:20
ScottKNg: Yes, but even reclamations don't help a huge amount in the long run.14:20
\shScottK: for my new rootserver I have 8ip network for free...and more then that, I'll have to pay a setup fee ...well, it's a different wording, but fulfills ripes rules14:20
NgScottK: the almost universal lack of adoption suggests that ipv6 doesn't either14:20
maswanNg: Technically they can be reclaimed, can they legally?14:21
\shNg: Daimler Benz has one or two /8 too... and they don't need it14:21
andrew___My concern is that this could become another Y2K media event - "experts say the Internet will crack asunder on June 2, 2011 at 8:34 GMT, releasing Shub-Internet from its 30 year sleep".14:21
Ng\sh: exactly, and there are a bunch of others14:21
maswanNg: It seems more likely to create a market where you can buy/sell adresses..14:21
cjwatsonScottK: some organisations seem pretty keen on getting Mobile IPv6 in place; the US DoD seems to be one such14:21
ScottKcjwatson: Yes.  US DoD is a major exception and they're big enough to get it done.14:22
Ngmaswan: how? I can't sell my ADSL's IP to you, it's assigned to my ISP by RIPE14:22
maswanNg: No, you can't currently. But RIPE can't revoke that assignment either, so your ISP has it forever, unless they choose to return it..14:22
ScottKcjwatson: US DoD also has a large IP multicast deployment in place.  I don't know of anyone else who's pulled that off yet either.14:23
\shmaswan: ripe can revoke14:23
\shmaswan: they did it once even for a /16 for my old company14:23
=== davmor2_dinner is now known as davmor2
ScottKmaswan: There is a reclamation process, but it's slow and painful.  We'll probably run out before a significant fraction of the theoretically doable reclamations could be done.14:24
\shmaswan: but "names do count"14:24
maswan\sh: Ah, so there is a process. Could it work if your company had said "no" and kept announcing them?14:24
cjwatsonScottK: they're also driving a certain amount of the hardware and software fixes, which is the only way the chicken-and-egg problem is going to get resolved14:24
\shmaswan: as I said, "names do count" ... so if you have a name like "Daimler"..they won't start revoking14:25
maswan\sh: or "deutsche telekom" for that matter..14:25
persiaScottK: Quite a few of the multinational financial institutions have large IP multicast, often with negotiated multi-network transfer.14:25
ScottKcjwatson: Yes.  This is true, but I think getting the hardware/software working is a necessary, but not sufficient condition for getting deployment.14:25
ScottKpersia: Oh.  I did not know that.  Thanks.14:25
cjwatsonScottK: agreed14:25
maswanScottK: The likely outcome of v4 exhaustion I think is a trading model and layer upon layer of NAT. With some growing v6 adoption over time, just because it becomse less painful.14:26
cjwatsonlayer upon layer of NAT> and stuff becoming less and less reliable as a result, but since we've all been trained to go "oh, whatever, restart connection" ...14:26
andrew___Is there any data yet on how good Vista's IPv6 is in the real world?14:26
maswanandrew___: AFAIK, it "just works" on the client at least.14:27
maswanandrew___: much like ubuntu since dapper14:27
maswan(or possibly earlier)14:27
andrew___That's good, at least.14:28
\shmaswan: yepp....but they can claim to be a ISP14:28
\shmaswan: I wonder if DTAG or DAIMLER or AS701/AS702 are paying more then just the normal ripe fee14:29
\sh(ok AS701 is ARIN)14:29
* \sh is an old fart regarding AS numbers14:30
\shhmm..AS702 is now verizon...in former times, as701 and as702 were uu.net america, uu.net europe14:33
TheMuso/c/c14:33
andrew___cjwatson: is this a good time to ask my SSH question?14:34
\shandrew___: why do you not fire away?14:35
andrew___Because... I might be wrong :s14:36
\shandrew___: we have hobbsee to tell someone who is wrong or not ,-)14:36
andrew___Hehe.14:36
cjwatsonandrew___: sure14:36
* Hobbsee loosk in14:37
andrew___If I allow an untrusted user to log in to my machine, who can't forward local, remote or X connections, and is given a specific command instead of a shell, what security problems do I need to be thinking about?14:37
Hobbsee\sh: who am i telling who's wrong?14:37
* \sh waves to LPS aeh Hobbsee 14:37
cjwatsonandrew___: make sure you've set all the no-* listed in sshd(8)14:39
cjwatsonandrew___: but otherwise that can be made secure providing that you're certain there's no way to cause the command in question to do anything unexpected given arbitrary input14:39
cjwatsonpeople have set up anonymous CVS servers that way, for instance14:39
cjwatson(who don't trust pserver)14:39
\shwho's in charge for running MoM to be up2date?14:40
andrew___The plan is that the command do some initial negotiation, then listen on port 5900 (to forward a VNC session back to the client's computer) or /var/run/screen/.../some-unix-socket (to forward a screen back)14:41
andrew___Where the unix socket in question is decided by the program, with no input from SSH.14:42
cjwatsonwhat happens if that port is already in use?14:43
andrew___VNC servers normally use 590*.  I think some use 5901 for X :1, 5902 for X :2, etc.14:43
andrew___I suppose I could do that transparently to SSH as well.14:44
cjwatsonyou'd have to return the port number then14:44
andrew___I was thinking I'd pipe it all through SSH's standard input/output, and the client would redirect it to the relevant port/socket on the client.14:45
andrew___(Which could even be IPv6, going back to the earlier discussion)14:45
andrew___I suggest that because I'm not aware of any other mechanism to only allow an SSH client to forward a specified port.14:46
tmmoyeris there any documentation on how to build udebs for the installer? I know how to build a traditional package for a running system, but I need to add a package to the installer and haven't seen anything on building udebs14:53
TheMusotmmoyer: You could have a look at how existing udebs are packaged.14:54
tmmoyerokay14:54
evandtmmoyer: This may also be of help: http://meetings-archive.debian.net/pub/debian-meetings/2006/debconf6/slides/Debian_installer_workshop-Frans_Pop/paper/index.html#id253534014:59
ScottK\sh: I think the plan is to work on it during UDS (MoM).14:59
=== danielm_ is now known as danielm
tmmoyerevand: yes I just found that when I expanded my search to include debian as well thank you for the help14:59
\shScottK: -ETOOLATE ... let's run mom as it was...and try to merge mom with dad on a different server?15:00
cjwatson\sh: MoM is running, it's just having trouble getting a consistent archive because the archive is loaded15:00
andrew___cjwatson: on the other hand, I see I'm wrong about that :).  How much information do people actually need to share in order to be reasonably confident that they've transmitted the correct RSA key?  Would the cksum/md5sum be any use?15:00
cjwatsonandrew___: err, sorry, now I'm lacking context. Why would people be transmitting RSA keys?15:01
\shcjwatson: well the last update was on the 7th...and all the syncs and merges were not recognized...if it's because of leningradskaya...ok ;)15:01
andrew___cjwatson: If you want to log in with a public key (RSA keys being shorter than DSA keys, therefore quicker to check), and want to confirm over the phone that you've got the correct key.15:02
cjwatsonandrew___: use the fingerprint; I've had people reading those out over the phone and it's fine15:02
andrew___Thanks, that's enough to keep me going for a while :)15:03
andrew___I expect I'll be back at some point with a blueprint to annoy people with.15:03
* \sh is off now.....guests are in da house....african party now ;)15:05
emgentre15:06
andrew___cjwatson: actually no, I'm not explaining myself right.  If client and server have never connected before, you need a safe way of transmitting the client's public key to the server, and I'm thinking of doing a password-based login, sending the public key, then logging out and back in again with the public key.  I'm worried about a situation where Mallory intercepts the SSH connection from the client, logs in to the serv15:12
andrew___er, and sends her own public key, allowing her to do an MITM attack on the later session.15:12
andrew___Would confirming the server's RSA fingerprint guard against that?15:13
cjwatsonthe purpose of the host key check is to guard against man-in-the-middle attacks15:13
cjwatsonso yes, it would; a middle-man attacker would be unable to forge the server's host key15:13
andrew___Okay, good.  Thanks again.15:14
cjwatsonhow are you transmitting the passwords around?15:14
andrew___Telephone.15:14
cjwatsonok15:14
cjwatsonyou have to bootstrap trust somehow :)15:14
andrew___Yeah :)15:14
=== cr3_ is now known as cr3
=== johanbr_ is now known as johanbr
=== Shely_ is now known as Shely
Dane2Hello, all.  I've been trying to cross-compile asterisk (compiling i386 binary using amd64 distro) using pbuilder/dh_make/debuild, but I keep getting the following error after the compile completes, and it's about to make a binary package: "build_tools/mkpkgconfig: 34: cannot create /usr/lib/pkgconfig/asterisk.pc: Permission denied"18:03
Dane2any ideas?18:03
Dane2I've asked on the #asterisk channel, and they said it's a distro specific thing, so I'm trying here.  :-)18:04
jdaviesDane2: I think #ubuntu-motu may be a better place :-)18:05
Dane2ok.  Thanks.18:05
=== bobbo_ is now known as bobbocanfly
=== bobbocanfly is now known as bobbo
=== asac_ is now known as asac
emgentheya people20:04
johanbrIf I wanted to get a patch into ubuntu to run various cron tasks (locate etc) less often than daily, what would be the recommended way of doing that? Debconf question at low priority?20:44
cjwatsonjohanbr: debconf isn't a very good interface for that sort of choice, really - you'd end up typing crontab entries into it as a string, which would be awful. Why not just edit /etc/crontab? It's a conffile and so your edits will be preserved - that's the supported way to change this.20:48
cjwatsonalso, mixing debconf and conffiles is bad, so in order to offer debconf configuration it would have to stop being a conffile for everyone else, which would introduce a lot of complexity - probably too much for a low-priority tweakable.20:49
johanbrcjwatson: I see, thanks. But with editing crontab, changing the interval of only a few daily tasks seems to be complicated.20:51
johanbrBut on closer inspection, none of the /etc/cron.daily jobs seem to necessarily need to be run daily, at least for me. So I may just do that. Thank you.20:55
emgentheya sabdfl20:59
emgent:)20:59
cjwatsonjohanbr: yes, if you needed that you'd need to split cron.daily up somehow. run-parts has a --regex option that might help.21:00
arekmhello, how do you separate own commits from upstream one in git://kernel.ubuntu.com/ubuntu/ubuntu-gutsy.git repo?21:07
kirklandcjwatson: I see that you were the last person to merge/upload yaboot-installer.  i merged for intrepid, in case you want to review and upload.21:41
cjwatsonkirkland: thanks - can you send me mail to remind me?21:42
cjwatsonI probably won't get to it tonight, but can certainly review21:42
kirklandcjwatson: you bet, will do.  it's no rush.  i'll leave in my home dir on chinstrap.21:43
andrew___reportbug-ng is Debian-specific - it doesn't check for bugs filed with Ubuntu.  Is that a bug or a reason to remove the package altogether?  If the latter, who do I talk to about it?21:49
beunoandrew___, maybe some ubuntu users want to check for debian bugs?21:49
geseror use it to file bugs in Debian21:50
andrew___So you reckon I should file a bug saying that it should warn more clearly about not being a useful Ubuntu tool?21:51
beunoandrew___, nope, I think it's fine as-is21:52
ScottKandrew___: Reportbug has been patched not to report to Debian by default.  Same magic should be done to reportbug-ng if it isn't already.21:53
beunoScottK, really?   what does it do then?21:53
andrew___ScottK: Either it's not, or the magic went wrong with the bug I filed :)21:53
ScottKBy default it sends mail to ubuntu-users or something reasonably useless.  You have to tell it specifically you want to report to Debian.21:54
ScottKandrew___: Then it needs to be fixed up like reportbug.21:54
beunohrm  :/21:55
ScottKUnfortunately LP doesn't expose sufficient API to actually allow reportbug to be modified to do something useful in Ubuntu.21:55
andrew___I'll have a poke about and complain that -ng is insufficiently crippled.21:56
ScottKJust make sure you complain to Ubuntu, not Debian '-)21:56
andrew___I don't suppose I can report bugs against some test package that blackholes the report?21:56
andrew___:p21:56
andrew___(So I can do a test and describe the reportbug UI)21:57
ScottKYou can control what happens to the mail via your local MTA is the best thing I can offer.21:57
andrew___Yeah, good plan.21:58
cjwatsonandrew___: (noted smiley, but) afraid not; bugs against unknown packages in bugs.debian.org typically end up in my inbox so I'd be unhappy about that plan ...21:59
cjwatsonthough there is a debbugs-test pseudopackage, but it's really more for debbugs developers to test, rather than a general-access sandbox21:59
andrew___Fair enough, I'll disable anything that looks like it could talk SMTP before I play around with it.22:00
ScottKandrew___: It wasn't you that reported a bug against skype in Debian recently is it?22:04
=== asac_ is now known as asac
andrew___No, Vinagre.22:07
ScottKOK.  At least it's a package that's in Debian.22:08
=== mweinelt__ is now known as mweinelt
pochuandrew___: that's bug 175508. No worries for the Vinagre bug :-)22:39
ubottuLaunchpad bug 175508 in reportbug-ng "reportbug-ng reports bugs to Debian instead of Ubuntu" [High,Triaged] https://launchpad.net/bugs/17550822:39
andrew___Thanks :)22:40
andrew___I was halfway through writing a thing with suggested fixes - is that still useful?22:41
pochuandrew___: I'll probably look at changing it to ubuntu-users@l.u.c unless you have a better proposal, so yes, that will be useful22:43
pochugood night22:43
=== iceman_ is now known as iceman

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!