/srv/irclogs.ubuntu.com/2008/06/27/#ubuntu-server.txt

mathiazzul: were you able to link openldap upstream bugs in LP ?00:02
zulmathiaz: no I havent tried00:41
=== chmac7 is now known as chmac
=== folke_ is now known as folke
=== chmac7 is now known as chmac
krautmoin08:28
=== mindframe is now known as Guest62006
=== chmac7 is now known as chmac
=== eht is now known as Weasel[DK]
=== nop is now known as nop_
=== nop_ is now known as nop__
jdstrandzul: I have a little time to play with samba bug #24144813:28
uvirtbotLaunchpad bug 241448 in totem "Playing from Samba SMB shared folder now is not possible (it could be done until last upgrade)." [Undecided,Confirmed] https://launchpad.net/bugs/24144813:28
zuljdstrand: and?13:28
jdstrandzul: I was wondering what your findings were13:29
zulinconclusive for me13:29
jdstrandok13:29
zulwhat are your findings? ;)13:29
jdstrandmaybe I'll get lucky13:29
jdstrandnothing yet-- I only just now found the time :)13:29
zulheh13:29
jdstrandzul: ruby update was pretty time consuming13:30
zuljdstrand: I bet, another mysql like?13:30
jdstrandzul: no, the patches were straightforward enough. upstream was not forthcoming publically on the disclosure, and there was a regression in their updates, so it was trying to make heads or tails of all that, and then all the testing13:31
jdstrand*loads* of testing13:32
zuljdstrand: sounds like fun :)13:32
zulim in the middle of iso testing, I can do this without looking now13:32
jdstrandzul: in the end, upstream was quite helpful and things turned out well13:32
zuljdstrand: good to hear13:32
jdstrandre iso testing> yeah, I hear you13:33
jdstrandzul: did you get host's nautilus Network/Windows Networking to see your samba server that was in a vm?13:58
zuljdstrand: no it was with real hardware14:00
jdstrandok14:00
jdstrandvms can see each other fine...14:01
jdstrandoh well, I'll just use vms for now14:01
jdstrandwild stuff- watching a flash video in a vm (no sound mind you, but still)14:03
jdstrandsoren: ^14:03
nijabajdstrand: you should cut on isolation.  I know flash is bad, but to use a vm to watch a video.... ;)14:04
jdstrandnijaba: I'm *very* careful14:05
jdstrand;)14:05
zuljdstrand: for what its worth I still havent been able to reproduce that bug from hardy server to hardy client15:17
melterdoes anyone know why dhclient wouldn't be setting the hostname provided by the dhcp server?15:32
uvirtbotNew bug: #243525 in openldap2.3 (main) "slapd needs apparmor changes for cn=config" [Undecided,New] https://launchpad.net/bugs/24352515:41
zulmathiaz: im going to get jcastro to add openldap its to the list as well15:46
zuljdstrand: ping15:51
lukehasnonamezul: pong15:53
lukehasnoname:(15:53
jdstrandzul: pong15:56
jdstrandzul: ack apparmor-- I'll fix it15:56
mathiazjdstrand: are you refering to bug 243525 ?16:00
uvirtbotLaunchpad bug 243525 in openldap2.3 "slapd needs apparmor changes for cn=config" [Medium,Triaged] https://launchpad.net/bugs/24352516:00
jdstrandmathiaz: I was-- but if you are working on, feel free to take it :)16:04
mathiazjdstrand: well - I'm working on the cnconfig migration spec for intrepid16:04
mathiazjdstrand: so I'll fix it while doing it16:05
mathiazjdstrand: however, it may be worth for an SRU16:05
jdstrandmathiaz: SRU for hardy? we have cnconfig in there?16:05
jdstrandmathiaz: cool on you fixing it in intrepid though ;)16:06
mathiazjdstrand: yes - you can setup cnconfig in hardy - but it's done by default16:07
jdstrandreading the forum does suggest people are using it there as well16:07
mathiazjdstrand: cnconfig has been available since 2.316:07
jdstrandmathiaz: ok16:07
mathiazjdstrand: there is just nothing in the debian scripts to support cnconfig16:07
jdstrandare you saying you'd like me to process the SRU?16:07
mathiazjdstrand: well - I don't know if it would qualify for an SRU16:08
jdstrand(I can, though it won't probably be today)16:08
mathiazjdstrand: oh - I don't think it has to be done so quickly16:08
jdstrandmathiaz: oh it is a totally minimal change with virtually no regression potential-- I think it might be16:08
mathiazjdstrand: for hardy, I'd like to get 2.4.10 as an sru16:08
mathiazjdstrand: and then we can add support for slapd.d in the apparmor profile at the same time16:08
jdstrandmathiaz: ah right. we can fix it in there then, with a little line saying 'cnconfig now works'16:09
* jdstrand nods16:09
mathiazjdstrand: I aggree that the potential for regression is minimal16:09
* delcoyote hi17:11
Fenix|workGreetings17:26
Fenix|workI need a hand with postfix17:27
Fenix|workI don't want to have local mailboxes... I want all usermail for *@localhost to be redirected to *@domain.com17:27
Fenix|work... without having to enter in an alias for each and every user17:27
uvirtbotNew bug: #239184 in openldap2.3 (main) "evolution-exchange-storage crash in e2k_global_catalog_lookup and ber_flush2" [Undecided,New] https://launchpad.net/bugs/23918417:46
zuljdstrand: ping18:04
jdstrandzul: pong18:05
zuljdstrand: i setup a samba under dapper with one of the configuration files found in the bug and I wasnt able to copy a file over18:05
zulthis is with a hardy client18:06
jdstrandzul: well, that sounds like a different bug entirely, or possiobly misconfiguration?18:08
jdstrandzul: I haven't played with dapper yet, though seb128 was able to definitively show it was the -security update18:09
zulcould be misconfiguration but running it through testparm says it ok18:09
jdstrandCVE-2008-110518:09
uvirtbotjdstrand: Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response. (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1105)18:09
jdstrandzul: the question is, is the update wrong or is it right with clients misbehaving18:10
jdstrandzul: I have some leads though18:10
zuljdstrand: coolio18:10
ScottKFenix|work ought to have more patience.19:03
lukehasnonametrue19:06
ScottKsommer: I was working with a DD on getting your php-clamavlib fix uploaded to Debian yesterday and he pointed out that even with the patch, there is still clamav.maxratio in the package.  I know it builds with your change, but do you know if it will actually successfully scan files.19:06
sommerScottK: yep, it did... but I think there was another bug about php-clamavlib, and when I was checking for a new upstream version the project was unavailable19:12
sommerScottK: I guess my question was is there still an upstream?19:12
ScottKDunno.  It seems pretty dead.19:16
ScottKMaybe removal is the best option then.  There's a pending removal bug in Debian.19:17
sommerScottK: I agree with that.  I don't think a PHP virus scanner is all that useful, but then again someone went through the trouble to write it... for a time19:20
sommerScottK: here's that bug I was thikning of Bug #23492719:20
uvirtbotLaunchpad bug 234927 in php5 "delay php script execution on cli" [Low,Triaged] https://launchpad.net/bugs/23492719:20
ScottKAh.  OTOH it obviously has users.19:22
ScottKsommer: Since you've already invested effort in fixing it up, how would you feel about finishing the work to get it in shape and then we leave it for the next time it's broken to remove it?19:22
=== leonel_ is now known as leonel
sommerScottK: sure, what all needs to be done?19:40
sommerScottK: oh ya, the max ratio thing... I'll whip something up this weekend probably19:46
jdstrandzul: at what loglevel and which logs are most interesting for samba19:49
jdstrandzul: I haven't been able to reproduce it (still)19:49
* jdstrand goes to try on real hardware19:51
ScottKsommer: Great.19:55
zuljdstrand: debug level 9 and /varr/log/log.smbd19:58
zulor log.workstation19:58
jdstrandzul: that is what I thought (though wasn't sure if 10 is useful)19:58
jdstrandzul: thanks19:58
zuljdstrand: np19:59
uvirtbotNew bug: #243610 in samba (main) "Can't connect to Windows Servers in Ubuntu 8" [Undecided,New] https://launchpad.net/bugs/24361020:06
FuRomhttp://pastie.org/223607 This is the end of my apache access.log. The 85.190.0.3, port 80 is open, and I checked it out, and it said "If you see portscans/abuse from 85.190.0.3 Please read http://freenode.net/policy.shtml#proxies"20:36
FuRomMy entire system has frozen at the times in my logs.20:36
jpdsFuRom: isn't ::1 the loopback for ipv6?20:38
FuRomhmm20:38
FuRomjpds, I have no idea what ipv6 is, I was completely confused by this stuff in my log =/20:39
jpdsFuRom: And if your question is a Freenode question I suggest trying #freenode20:39
Deeps"Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.1 with Suhosin-Patch mod_ruby/1.2.6 Ruby/1.8.6(2007-09-24) (internal dummy connection)"20:39
Deepsbeing the useragent20:39
* jpds points FuRom to http://en.wikipedia.org/wiki/IPv6 .20:40
Deepsthe bit in brackets suggests you have something running locally thats doing that20:40
FuRomo_o20:40
FuRomOh, really?!20:40
Deeps::1 is the ipv6 equivilant of 127.0.0.120:40
Deepsgiven that ubuntu supports ipv6 out of the box now, as do many packages, chances are something's just connecting to localhost, and hitting ::1 instead of 127.0.0.120:40
FuRomOh20:41
Deepsbut you have something running locally that's doing that20:42
FuRomAny idea what 85.190.0.3 - - [27/Jun/2008:14:55:51 -0400] "CONNECT 213.92.8.7:31204 HTTP/1.0" 405 391 "-" "-" is? I've never seen "CONNECT" there before. I'mma read about ipv6 in a min20:43
Deepssomeone trying to use your webserver as a proxy20:45
FuRomThe internal dummy connection doesn't seem to be the issue, because it's accured before with no problem.20:45
Deepsand failing20:45
FuRomOh20:45
FuRomCould that cause problems? O_o20:45
Deepsnot really20:45
FuRomLike, being iced?20:45
Deepsunless you get a massive storm of them20:45
FuRomI only got a couple.20:45
FuRomHmm20:46
Deepsthe occasional one here and there isn't anything to worry about though, it's similar to portscans20:46
FuRomAh, I see.20:46
FuRomIt only bothered me, because I can only assume 85.190.0.3 is the IP of a proxy server.20:46
Deepscould be, if the person trying to find new proxies is using an existing one,20:47
FuRomAh20:51
FuRomThanks guys, I appreciate the info. Hopefully, it'll all go well.20:57

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!