/srv/irclogs.ubuntu.com/2012/01/30/#ubuntu-server.txt

=== Lcawte is now known as Lcawte|Away
gmr-Hey there, having a hard time trying to clean up an old ldap install on a box and perform a new, clean one. I've done the apt-get remove slapd (and related things) did an rm -rf /etc/ldap & /var/lib/ldap.  Now when I install slapd none of the schema files get created in /etc/ldap/schema.00:16
gmr-Any suggestions?00:16
pmatulisgmr-: may require 'purge' with apt00:25
gmr-pmatulis: thanks, will try00:29
itguruI'm getting an unable to write to temporary file error 13 on a linux box, and I googled around, and it suppose to be permssions issue, but other mysql databases on the same instance are running fine - this seems like a red herring error, any ideas?01:09
itguruhttp://pastebin.com/ZjgBFxwX - Usually, when I've faced this error in the past it's been permissions, but other databases are running okay, and it's got me confused. This is being thown up by a php based website01:09
=== micahg_ is now known as micahg
ilovemesomeubuntIf I set up 2 factor Auth on SSHd should I also still set up something like fail2ban?02:01
qman__brute force attempts will happen regardless of the authentication you use02:03
qman__so, setting up some method of limiting it (fail2ban or -m recent) is a good idea02:03
qman__if nothing else, to stop log cluttert02:03
ilovemesomeubuntqman__, Oh, ok.  Figured it might.  I will setup fial2band02:03
qman__in my case, my shell server was disk thrashing from all the hits and it was annoying, so I set up iptables -m recent02:05
=== fenris is now known as Guest45833
=== Guest45833 is now known as ejat
_godhelpmefrom a shell how do i see what user accounts are on my system04:28
twbgetent passwd04:29
_godhelpme thanks04:31
pehdenWhats up05:11
pehdenis there ever going to be a time where ubuntu would have repos for ispconfig?05:12
qman__that's more a question for the ispconfig people05:13
qman__whether or not they're going to package and maintain it, and submit it05:13
twbPackaging is not normally done by upstream (because upstream is usually incompetent)05:14
twbHowever, it's apparently a "hosting control panel", so the same caveats as webmin probably apply05:14
pehdeni would have considered it something like webmin05:14
pehdenor packed like phpmyadmin really05:15
twbWe encourage sysadmins to learn how to manage the system properly, via the CLI05:15
pehdeni know that but it would have been of interest05:15
pehden know webmin was left behind and no longer supported05:16
twbispconfig is not currently packaged for ubuntu or debian.  You could file a Request for Package (RFP) to Debian's bug tracker, where it will probably be ignored for years because no one likes it.05:16
pehdenbut ispconfig has been very well maintained.05:16
twbpehden: that is your opinion.05:16
pehdenits a php based install system05:17
twbIMO PHP is an automatic fail.05:17
twbhttp://wiki.debian.org/HostingControlPanels is a summary of FOSS WHCPs.05:17
pehdenthe top ones on there are non-freware05:20
pehden*freeware05:20
qman__it's alphabetical05:23
twbqman__: I think he's referring to the opening paragraph which mentions cpanel and plesk05:23
qman__ah05:24
qman__I use plesk at work, it's meh05:24
twbpehden: as I said, I do not endose any WHCP -- I discourage their use.05:24
qman__a bunch of random software precariously stitched together05:24
twb<stupid customer> I started babysitting today, is running cpanel05:28
twbAnd they refuse to give out ssh access, but they want kerberized SSO in their apache, which is not using TLS *at all*05:28
qman__of course we do run it on a windows VPS, so maybe it's better on linux, but I honestly don't think it would be05:28
twbStupid bloody monkeys05:28
=== fenris is now known as Guest67783
heraldI've got a question about Iptables and routing, could someone give me a hand?06:23
twbDon't ask to ask unless you're prepared to ask to ask to ask.06:24
heraldI am so prepared06:24
heraldOK so I'm using comcast and they don't allow you to bridge their cable modem.  Essentially, I have to use one of the IPs in my static IP block to give to my router, and then the public DMZ has the rest of the IPs.  My question is, how to I handle routing and set gateways for that?  I'd have like 4 different gateways or something06:26
heraldThe cable modem and the public DMZ are the same logical network, but are split between two different NICs06:27
heraldDo I set up a static route for the single IP on the one NIC and let the routing tables take care of the rest?06:27
twbherald: replace the cable modem with one you control06:29
=== smb` is now known as smb
Davieyjamespage: around?09:12
jamespageDaviey, yep09:12
Davieyjamespage: Great :)09:12
Davieyjamespage: One adam_g has polished being able to run preicse and oneiric on the ci lab, fast... Are you ready to be able to suck in stable/diablo on oneiric proposed branches?09:13
DavieyThat should read "Once adam_g"09:18
* Daviey wonders if jamespage is still there?09:23
jamespageDaviey: yes - sorry - just helping someone with something else09:24
jamespagegive me 5 mins09:24
Davieyjamespage: ok, sure09:25
koolhead11hi all09:30
jamespageDaviey: I've not tested it for a while but it should not be to much effort.09:39
Davieyjamespage: yeah, there seems to be a jenkins plugin for gerrit proposed changes.09:52
* jamespage re-reads09:52
Davieyjamespage: was it you that setup the reprepro part?09:52
jamespagecan you clarify "suck in stable/diablo on oneiric proposed branches"?09:52
jamespageDaviey: I did setup reprepro09:53
Davieyjamespage: sorry, someone proposes an 'upstream SRU' if you like, i'd like to pre-validate it before review via jenkins09:53
Davieyso, a pre-commit test09:53
Davieyor pre-merge test09:53
jamespagemerge in bzr or git upstream?09:54
Davieyjamespage: git upstream09:54
jamespageDaviey: well in that case I change "I've not tested it for a while but it should not be to much effort."09:54
Davieyheh, thanks09:55
jamespageto "I need to catchup with mtaylor as they do some of this alread"09:55
jamespageto "I need to catchup with mtaylor as they do some of this already"09:55
jamespageI expect that will need some infrastructure changes as well09:55
jamespageas I suspect we ONLY have access to github.com09:55
Davieyjamespage: no, we have ssh09:56
Davieyjamespage: we'll talk iab about it09:56
jamespageDaviey: OK09:56
Davieyjamespage: sorry, i was supposed to have a call starting now, but cannot find the other person..10:03
Davieyso, $ ssh davewalker@review.openstack.org -p29418  gerrit query --format=JSON status:open status:open project:openstack/nova branch:stable/diablo10:03
Daviey{"type":"stats","rowCount":0,"runTimeMilliseconds":6}10:03
DavieyIt seems to be handled already with, https://wiki.jenkins-ci.org/display/JENKINS/Gerrit+Plugin10:04
WomkesI use Jenkins + Gerrit10:07
Womkesworks well10:07
jamespageDaviey: OK so you want to pickup proposed merges from gerrit; pull them into the lab with the current packaging for stable?10:29
jamespagebuild; deploy and test?10:29
lynxmanmorning o/10:42
jamespagemorning lynxman10:43
MezOk, I'm in a bit of a pickle here.  Ubuntu Lucid.  It supports sslv2.  However, I need to disable this for PCI.  However, doing so means that external servers that are attempting to use an ssl23 socket to open a connection to us fail...10:47
greppyHow many external servers are you talking about?10:50
greppyMez: are they using sslv2 because that's all they can use, or because it is available.10:51
Davieyjamespage: yep10:53
Mezgreppy - I'm not sure.  I basically changed the code to use SSlv3 instead of sslv23 ..10:53
Mezthis caused wget to fail aswell.10:53
DavieyMez: this is on pound?10:54
greppyMez: what if you specify for wget to use v3?10:54
MezDaviey: yes.10:55
DavieyMez: do you have the patch you used handy?10:55
Mezgreppy: I don't know (didn't know I could do that).10:55
MezDaviey ... er... yes.10:55
greppyhttp://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html10:55
greppythat may help10:55
Mezgreppy: not really.10:55
Davieygreppy: he's using a whizzy load balancer, not apache10:55
MezI tried connecting via openssl s_client and that wouldnt connect unless I specified -ssl310:56
DavieyI hear the debian maintainer for pound is a real ass BTW :)10:56
Mezhowever, the problem is that Paypal IPN notifications were failing.10:56
DavieyMez: whee is the patch?10:56
Mezwheee!10:56
greppyDaviey: yeah, but it has commands for testing what is going on.10:56
Mezjust finding it.10:56
Mez(as it's hiding in LP)10:56
Mezhttps://launchpad.net/~mez/+archive/mez-mf/+files/pound_2.5-1.1~lucid2.debian.tar.gz10:56
Davieygreppy: right, i think i threw them to mez last week.10:57
MezDaviey: yeah.10:57
greppyah10:57
MezDaviey: see debian/patches/disable_sslv2_server.patch10:57
Mezor I can pastebin it if need be.10:57
greppyI do good to remember what I read in here from day to day, much less a week ago :)  I mean, hopefully, I have slept since then, which means /tmp got cleared :)10:58
MezIt was somewhere else.10:58
uvirtbotNew bug: #923676 in dovecot (main) "/usr/lib/dovecot/deliver: invalid option -- 'n'" [Undecided,Triaged] https://launchpad.net/bugs/92367611:01
DavieyMez: crikey, https://launchpadlibrarian.net/91198061/pound_2.5-1~lucid1_2.5-1.1~lucid1.diff.gz ?11:01
Davieygreppy: yes, sorry - it was even on a different irc network :)11:01
greppyha!11:01
MezDaviey:  ?? ?11:03
Mezthat's also a patch from debian.11:04
Davieyah11:05
* Mez sighs11:08
DavieyMez: found it?11:09
Meznope.11:11
Mez(found what?)11:11
DavieyMez: right, what is happening?11:12
Davieywhat is openssl reporting, with the patch applied?11:12
Mezhandshake failed.11:12
Mez(I don't have a specific test environment for that at the moment, as I had to roll back the change)11:13
DavieyMez: I haven't grokked the code, but what does http://pb.daviey.com/napC/ do ?11:14
MezThat was never actually applied.11:15
Davieyug?11:15
Davieyuh?11:15
Mez~lucid1 - I forgot to add it to series XD11:15
Mezbut that code *would* if it had been applied, change from using anb SSLv23 (version 2 and 3) socket to just use a v3 socket11:16
DavieyMez: neat, but there are two other references to SSLv23 config.c .. which the pastebin i just pushed includes11:16
MezDaviey: ok.  the 2 _client_method() are for outgoing connections (when it connects to the backend) Not for incoming.11:17
therveMez, iirc, v23 also supports TLSv1, but v3 only support SSL311:19
therveMez, you should use SSL options instead to disable SSLv211:19
Meztherve: yeah, am starting to think that myself.11:19
therveand http://www.openssl.org/docs/ssl/SSL_CTX_new.html agrees11:20
therveSSL_CTX_set_options(res->ctx, SSL_OP_NO_SSLv2) should do the trick11:21
* Mez puts new version of pound to ftp-master11:24
DavieyMez: erm, why not test it first? :)11:24
smbDaviey, stgraber fyi, I thought I file bug 923685 to document this. Maybe more of an observation but probably this is not so uncommon as a setup.11:24
uvirtbotLaunchpad bug 923685 in resolvconf "New resolver package overwrites manually created resolv.conf on server" [Undecided,New] https://launchpad.net/bugs/92368511:24
MezDaviey: simultaneous development.11:24
MezThe new version of pound is without the SSL changes.11:25
Mezthe ssl changes are for a local copy.11:25
DavieyMez: You've just uploaded something, to Debian?11:25
Mezyes.11:25
DavieyMez: Was this something, pound?11:25
Mezwhile we've been talking, I've been doing a build of a point update for debian.11:25
Mezyes.11:26
Davieysmb: Stop finding problems, find solutions :P11:26
Davieyoh11:26
smbDaviey, Hey I need to find the problems first. :)11:26
MezDaviey: why'd you ask?11:27
Davieysmb: You are looking at this wrong, lets find the solutions - then the problems. :)11:27
DavieyMez: Just wondered.11:27
MezDaviey: there's a new point release of pound, thought I'd update unstable while I'm there fiddling wtih pound anyways (and yes, I tested it!)11:28
Davieysmb: confirming you are using static ip, not dhcp?11:28
Davieysmb: and the nameservers where just /dropped/ not replaced?11:29
smbDaviey, I do use a static IP, yes11:29
DavieyMez: heh11:29
smbDaviey, And not, resolv.conf was _empty_11:29
MezNow the question is...11:29
Davieysmb: That is less than ideal11:29
MezDo I make this change regarding sslv2 into a config option ... or do I just keep it in our local copy ?11:29
DavieyMez: speak with upstream?11:30
smbDaviey, Could be a tat annoying. Though ssh connections probably still work. Just nothing looking for a dns name from withing the server.11:30
smb*tad11:30
MezDaviey: upstream are very... weird...11:31
MezSometimes they'll be happy to do anything and everything to help11:31
Mezsometimes they just ... go silent... and you never get a response.11:31
Davieysmb: Hmm, ssh fails if it couldn't resolve itself... but i guess it can through /etc/hosts11:31
smbRight, there is the hostname defined mapped to loopback11:32
DavieyMez: .. and you choose to use this software? :)11:32
MezDaviey: I sorta got forced into it.11:33
Mez$random_manager stuck a pin in the internet and chose to use pound.11:34
MezTherefore I became debian maintainer.11:34
Davieyahh11:36
Mez(had to fix a couple of bugs we needed fixing, so I MIA'd the old maintainer, and hijacked.11:37
MezOh, by the way... I noticed a bit of a problem the other day regarding the TCP stack in Linux with use of reverse proxies.11:42
MezWhat's the HZ of the kernel set to for Ubuntu server?11:42
andolMez: Well, not sure if there are different values for different version, but "grep CONFIG_HZ /boot/config-*" should tell you.11:50
sattu94Hi, does the 64-bit server cd load a 32bit kernel or a 64 bit one to carry out the installation?12:13
henkjan_sattu94: 64bit12:14
sattu94Okay, thank you.12:15
uvirtbotNew bug: #923699 in php5 (main) "Compiling PHP 5 fails due to missing suhosin_patch.c" [Undecided,New] https://launchpad.net/bugs/92369912:26
MezDaviey: thoughts?12:48
Mezhttp://pb.daviey.com/v8So/12:48
Mezffs, somehow some of it's got caught in the anti_beast patch12:51
Mezhttp://pb.daviey.com/MRJt/12:54
DavieyMez: if it compiles, ship it/.13:10
Mezlol.13:10
MezDaviey: unfortunately, it doesn't compile for Lucid (due to another patch)13:10
Mezquilt pop -a13:12
MezSo I'm just poking that into the old pound manually13:13
Davieyoh13:14
VivekHi13:17
VivekI am getting Dropbox LAN sync Discovery  Protocol messages in my tcpdump output.13:19
VivekIs there Dropbox inbuilt into Orchestra/13:19
Vivek?13:19
VivekAlso In the directory /var/log/orchestra/ryslog I am getting dhcp requests from my eth0 when during orchestra configuration, I had configured it to only serve dhcp I.P Addresses via eth113:22
=== Ursinha` is now known as Ursinha
=== fjlacoste is now known as flacoste
Davieytherve: Hey, can i ask what testing you have done against your proposed fix for bug 913464?13:57
uvirtbotLaunchpad bug 913464 in rabbitmq-server "rabbit creates new PAM session" [Medium,New] https://launchpad.net/bugs/91346413:57
therveDaviey, I used the changed init on my oneiric and precise machines13:58
Mezbtw, thanks for the info earlier therve13:58
therveMez, you're welcome13:58
therveDaviey, rabbit is not reported in the list of connected users anymore, and my machines shutdown properly13:58
Davieytherve: nice, but do we lose the ability to log? shutdown_log ?13:59
therveDaviey, yeah I don't know about those13:59
Davieytherve: /me ponders.14:01
therveDaviey, shutdown_log seems to be filled as usual14:01
therveafter some local testing14:01
Davieytherve: cool14:02
roaksoaxDaviey: some peer review please>? https://launchpad.net/~andreserl/+archive/ppa14:05
Davieyroaksoax: looking14:05
Davieytherve: uploaded14:05
thervesweet! thanks14:06
Davieytherve: no, thanks to you!14:06
Davieybigjools: Are you in a psotion to test oops-*, txaws packages?14:07
Davieyposition*14:07
stgrabersmb: thanks for the bug report. So that was a regular d-i install and you didn't get the dns- fields in /etc/network/interfaces? that'd be the actual bug as netcfg is supposed to add them and we confirmed last week that it did14:09
smbstgraber, Well some d-i install for oneiric and then the install does succeed in dhcp usage. which I change later14:10
smbThen upgraded14:10
smb(so completely "normal" usecase :-P)14:11
smoserhallyn, 2 things14:11
smosera.) -root.tar.gz now available at https://cloud-images.ubuntu.com/server/precise/current/14:11
Davieyroaksoax: We normally try to put the debian/* under the same licence as upstream right?14:11
Davieyhere we have LGPL-3 and GPL-2+14:11
stgrabersmb: ah right, so that was a dhcp install that you then turned into static when we didn't have resolvconf14:11
smoserb.) i use lxc-is-container at http://bazaar.launchpad.net/~cloud-init-dev/cloud-init/trunk/view/head:/cloudinit/util.py (islxc method)14:11
Davieyroaksoax: Also, isn't * under Canonical Ltd copyright?14:12
hallynsmoser: ok, so if i rename that, how hard is that for you to handle?14:12
smbstgraber, Right. As I updated the report, I am not sure I ignored some warning in the file. But it used to work that way.14:13
stgrabersmb: not exactly sure what we can do in that case. We might be able to show a debconf prompt if we detect that case and ask the user to configured /etc/network/interfaces with the DNS based on /etc/resolvconf/resolv.conf.d/original14:13
stgrabersmb: not converting to a symlink based on /etc/network/interfaces and /etc/resolv.conf content is a bit tricky as we also have to deal with Network Manager and some other ways of configuring networking (like thin clients/netboot system doing dhcp from the initrd)14:14
stgrabersmb: I'll update the bug with these thoughts14:14
hallynsmoser: great, i'll hopefully work on the ubucloud template today  (though nuking lxcguest takes precedence)14:14
smbstgraber, Hm yeah. Yes, best have things in there.14:15
=== bladernr_afk is now known as bladernr_
smoserhallyn, i can easily re-name, why, i wonder?14:15
hallynsmoser: anyway, https://code.launchpad.net/~serge-hallyn/ubuntu/precise/upstart/upstart-containers is where i was renaming lxc-is-container14:15
hallynbc "running-in-container" sounded nicer than "lxc-is-container"14:16
hallynesp if it ships in upstart14:16
Davieyroaksoax: I thought we were supposed to be using Format: http://www.debian.org/doc/packaging-manuals/copyright-format/1.0/ , in debian/copyright now ?14:18
uvirtbotNew bug: #923744 in samba (main) "smbclient messaging not responding to control-D" [Undecided,New] https://launchpad.net/bugs/92374414:25
hallynstgraber: so for lxccontainer.conf in upstart, you were suggesting making it "start on container and stopped rc RUNLEVEL=[2345]" ?14:29
stgraberhallyn: yep14:32
hallynok, refreshing my tree and will test a bit14:32
stgraberhallyn: so we don't end up copy/pasting the pre-start bit that checks the environment14:32
stgraberhallyn: did you have a chance to talk about these changes with jodh?14:33
hallynright.  thanks.14:33
hallynno, i mentioned them at the rally,14:33
roaksoaxDaviey: looking14:33
hallynbut he hasn't really taken a look yet that i know of14:33
hallyni'll ping him once i've tested extensively (esp on non-container014:33
roaksoaxDaviey: webside does not exist14:34
stgraberhallyn: ok. I'm guessing getting the console job and container job in the package should be fine, I'm mostly interested in his opinion about the is-container command (mostly whether we should have it in debian/, as part of the upstream code (which you did last I checked the branch) or in some other package)14:35
Davieyroaksoax: right, and currently the one in there doesn't... http://pb.daviey.com/Vb72/14:35
Davieyroaksoax: http://lists.debian.org/debian-mentors/2012/01/msg00191.html14:36
roaksoaxDaviey: E: python-oops-datedir-repo: copyright-contains-dh_make-todo-boilerplate14:37
roaksoaxDaviey: that one is because I didn't uplad the last version fixing that14:37
roaksoax:P14:37
Davieyroaksoax: it does14:37
hallynstgraber: yeah, if it all works i'll send him a merge request, so he can comment there for posterity and i'll update to whatever he prefers :)14:37
Davieyroaksoax: dave@voodoo:/tmp/review/oops-datedir-repo-0.0.15$ tail -n2 debian/copyright14:37
Daviey# Please also look if there are files or directories which have a14:37
Daviey# different copyright/license attached and list them here.14:37
Davieyahh14:37
hallyn(i like the public record showing what a dumbass i am :)14:38
hallyn(that's why i'm on lkml)14:38
roaksoaxDaviey: yeah didn't strip that part in the PPA but its stripped on the actual package to upload to the archives14:38
Davieyhallyn: lol14:39
roaksoaxlynxman: you mean using something likie githubredir?14:45
roaksoaxlynxman: http://githubredir.debian.net/14:45
lynxmanroaksoax: yeah, but it's a repo not in github :)14:45
lynxmanroaksoax: that's why14:45
roaksoaxlynxman: ah well if you can't get it then nevermind... is not that we *have* to have it, but it's rather desirable14:46
lynxmanroaksoax: just wanted to make sure I didn't miss anything :)14:46
roaksoaxlynxman: ;)14:46
tgardnerso, my precise orchestra server is borken this morning after weekend updates. none of the clients can parse the mirror bits correctly. anyone seen something like this yet ?14:48
hallynstgraber: mountall has the support we need for containers, right?14:51
roaksoaxtgardner: could you please pastebinit?14:51
tgardnerroaksoax, this is a real bare metal machine, so I don't think I'll be able to get a log. lemme mess with it.14:52
tgardnerroaksoax, this was in the server log: http://pastebin.com/CiT6naSK14:57
stgraberhallyn: yes14:57
tgardnerroaksoax, I've gotta bolt. appt cross town in 30 minutes.14:57
tgardnerroaksoax, p.s. - I've verified that the mirror is behaving correctly.14:58
roaksoaxtgardner: so make sure squid is running correctly on the orchestra server14:58
tgardnerroaksoax, how does one do that? This orchestra server was updated and rebooted just this morning.14:59
roaksoaxtgardner: your orchestra server is in oneiric or in precise?14:59
tgardnerroaksoax, precise14:59
tgardnerdogfooding, you know14:59
roaksoaxtgardner: to my knowledge there haswn15:00
roaksoaxt been any updates to orchestra itseellf15:00
roaksoaxtgardner: but maybe something got broken in the squid cache due to being using precise as the problems we were experiencing with it15:00
tgardnerroaksoax, ok, I'll deal with it when I get back from my appt.15:01
roaksoaxtgardner: just check if squid is running in the orchestra server and if not, start it manually15:01
smbroaksoax, actually I see similar things after upgrading the mini-isos on a oneiric cobbler and after removing the orchestra proxy line15:01
=== tgardner is now known as tgardner-afk
roaksoaxsmb: do you have any accesible machine I can get my hands on?15:02
roaksoaxls15:02
smbroaksoax, Err accessible for me but that is not open to public as its in my home office. :)15:03
smbroaksoax, Just from the the history of things, installations used to work but had a message coming up telling be modules could not be loaded because kernel and module versions were out of sync. Then smoser pointed me at the tip for cobbler-ubuntu-import and after fixing the problem of having an import of ubuntu-alternates (possibly pointlessly because a different seedfile would have helped) the latest version worked. And since then installatio15:10
smbns of precise fail15:10
smbEven when disabling the proxy line in the snippet15:10
smoserhm...15:11
smoserwhy do installations fail now?15:11
smbMy guess was that something in the mini-iso is wrong. Basically as for tgardner-afk it told me archive.ubuntu.com does not support precise15:12
=== eagles0513875_ is now known as eagles0513875
zulany objections for me to merge the new squid3 from debian?15:23
mtaylorjamespage: what's up?15:26
jamespagehey mtaylor15:27
jamespageso....15:27
jamespagemtaylor: now that we have regular testing of OpenStack trunk on Ubuntu precise on hardware....15:27
=== Lcawte|Away is now known as Lcawte
mtaylor(these are things that make me happy)15:28
jamespageDaviey wants us to start looking at testing proposed merges for stable/diablo from gerrit on the same infrastructure15:28
mtaylorjamespage: SO... there's two different ways we can go about this15:29
mtaylorjamespage: one is that we could move your jenkins jobs to the openstack jenkins (giving you access to edit them of course) and trigger them when we trigger everything else15:30
mtaylorjamespage: the other is that you could work how smokestack is working right now - in that anyone is free to read the gerrit event stream, do things and to vote on code reviews15:31
mtaylorjamespage: so you could just install the gerrit trigger plugin (you'll want our version for now until our changes get upstreamed)15:32
mtayloron your jenkins, and configure your jobs to trigger on gerrit events from the openstack gerrit15:32
Davieyjamespage: isn't that what i said? :)15:37
mtaylorjamespage: https://github.com/jeblair/gerrit-trigger-plugin/tree/trigger-on-comment-added15:37
jamespageDaviey: maybe :-)15:37
mtaylorjamespage: if you go the gerrit trigger plugin route, you want to grab that branch of that repo and use it15:38
jamespagemtaylor: so that adds feature to trigger on certain comments being added to gerrit15:38
Davieymtaylor: Does that plugin support - NOT commenting on the upstream gerrit, just sending a mail for now..15:38
mtaylorjamespage: yeah- those changes are going to be upstreamed, we've just been working on getting approval to submit them15:38
jamespagemtaylor, ack15:39
Davieymtaylor: don't want to add whitenoise until it's stable15:39
mtaylorDaviey: yes15:39
mtaylorDaviey: there's a flag in the job config to run in "silent mode"15:39
jamespagemtaylor, so are you triggering smokestack for proposals against stable as well?15:39
Davieymtaylor: nice.15:39
mtaylorjamespage: I actually don't do anything with smokestack - smokestack simply reads the ssh events stream from gerrit and runs jobs when it sees patchset uploaded events15:40
Davieyjamespage: does the openstack lp bot user have an ssh key on lp?15:40
Davieywhich seems to be what the gettit plugin wraps15:40
jamespageDaviey: yes its does15:40
mtayloryup15:40
Davieyjamespage: $ ssh davewalker@review.openstack.org -p29418  gerrit query --format=JSON status:open status:open project:openstack/openstack-manuals branch:stable/diablo15:41
Daviey{"project":"openstack/openstack-manuals","branch":"stable/diablo","topic":"bug/904792","id":"Ied4d4507dff95ec076e4d358b3751b70cf7713dc","number":"3139","subject":"Fix bug #904792","owner":{"name":"Razique Mahroua","email":"razique.mahroua@gmail.com","username":"razique"},"url":"https://review.openstack.org/3139","lastUpdated":1327759482,"sortKey":"001ab00c00000c43","open":true,"status":"NEW"}15:41
uvirtbotLaunchpad bug 904792 in openstack-manuals "Cleanup on nova-manage commands" [Medium,In progress] https://launchpad.net/bugs/90479215:41
Daviey{"type":"stats","rowCount":1,"runTimeMilliseconds":9}15:41
Davieyoops15:41
jamespageDaviey: nice15:42
mtaylorhttps://review.openstack.org/Documentation/cmd-stream-events.html15:42
mtayloris actually the interface that gerrit-trigger-plugin and smokestack consume15:42
* Daviey winders why review.openstack.org http(s) always sucks for me15:43
mtaylorhrm - does it?15:43
mtaylorI'd love to know more about that15:43
zuljamespage: the only problem with smokestack is we can get it to use the packaging15:43
zulrather than pip15:43
Davieymtaylor: constantly times out for me, i often have to refresh15:44
mtaylorDaviey: weird! that's no good15:44
DavieyBrowser reported, Error 15 (net::ERR_SOCKET_NOT_CONNECTED): Unknown error.15:44
Davieymtaylor: I assume we can request permisson to mark 'Verified' field in the future?15:46
mtaylorDaviey: we'll have to figure out what that looks like - certainly voting is an easy thing15:47
mtaylorDaviey: the implications of having a second jenkins involved directly in gating rather than consolidating gating-level jobs into the openstack jenkins is something I think we'll have to discuss more15:48
Davieymtaylor: it's just words i suppose, but i see the Verify field as 'Does not break', 'voting' as the branch has been looked at and 'Approved' as the final push"15:49
Davieymtaylor: Is Verified used as gating currently?15:49
mtaylorDaviey: yes. kind of15:50
mtaylorDaviey: the gating jobs are the ones that respond back with Verified, and then they also send the submit signal to tell gerrit to do the merge15:51
Davieyahhhh15:51
Davieyi see15:51
Davieyin which case +-1 does make more sense.15:52
mtaylorDaviey: I'm not sure what having a second system vote Verified or not Verified would do from a UI perspective (in terms of it being clear what state something should be in)15:52
Davieythanks15:52
mtaylorsure thing!15:52
mtaylorit's certainly an interested question to think about though - I hadn't really thought about having a potential second jenkins involved before now15:52
mtaylorsince we'd mainly been thinking in terms of vendor-supplied testing infrastructure being done via the openstack jenkins15:53
mtaylorso it's something I'm enjoying thinking about  :)15:53
Davieymtaylor: I'm not comfortable at gating on our development focus, but for stable/ on a stable Ubuntu release - is a concept i'd like to explore.16:00
DavieyBut first, we need to just comment i think - to see how we are doing, Infra stability wise.16:00
mtaylorDaviey: ++16:04
jamespageDaviey: sounds sensible to me16:05
=== bladernr_ is now known as bladernr_afk
lynxmanhallyn: ping16:11
hallynlynxman: .16:11
lynxmanhallyn: hey, I'm building a new ipxe package, but there's a small issue with the roms that we separate for qemu, we're now building "most" roms instead of all so some of the ones you chose don't build16:12
lynxmanhallyn: before I go into a crusade to manually build them in an override, wanted to know which ones did you really need :)16:12
lynxmanhallyn: missing ones ne2k_isa.rom and virtio-net.rom16:13
hallynlynxman: certainly virtio-net is needed16:13
lynxmanhallyn: kinda imagined so *darn*16:13
lynxmanhallyn: alright then :)16:13
hallynlynxman: is it broken upstream?16:14
lynxmanhallyn: doing allbaseroms was neither desired nor recommended by upstream16:14
lynxmanhallyn: I'll find a way, no worries16:14
=== bladernr_afk is now known as bladernr_
hallynlynxman: great, thanks16:15
uvirtbotNew bug: #923817 in nova (main) "nova-network fails due to absence of policy.json" [Undecided,New] https://launchpad.net/bugs/92381717:13
endzYmeHi all, is there a specific channel for orchestra/juju?17:21
=== tgardner-afk is now known as tgardner
SpamapSendzYme: #juju17:46
JanCanybody here ever heard about CUBRID: http://www.cubrid.org/ ?17:47
onrenope17:48
onreapparently it's quite popular in south korea17:48
onreinteresting!17:48
JanCseems like they have Ubuntu PPAs & such17:49
JanCand a GUI DBMS manager17:50
endzYmeSpamapS: Thanks!17:55
onreJanC, yes, and apparently it's not yet another mysql fork17:57
Davieyzul: + changelog_detail='No change rebuild.'17:58
Daviey+ mv dist/horizon-2012.1.tar.gz ../tarball/horizon_2012.1+git201201301257.orig.tar.gz17:58
Davieymv: cannot stat `dist/horizon-2012.1.tar.gz': No such file or directory17:58
DavieySending e-mails to: james.page@ubuntu.com17:58
zulDaviey: errrgh17:59
smoseradam_g, ping18:05
JanConre: http://www.cubrid.org/cubrid_click_counter --> quite interesting feature (although I prefer the alternative "WITH INCREMENT FOR" syntax)18:10
adam_gsmoser: pong18:10
smoserhttps://code.launchpad.net/~smoser/+junk/juju-deployer-concurrent/18:10
smoseradam_g, ^ for merge to juju-deployer18:10
adam_gsmoser: oh, nice.18:11
onreJanC, indeed. also, looking at "architecture" section of docs, looks like cubrid actually HAS an architecture. someone DESIGNED it. :)18:11
onreJanC, thank you once again, this is probably the most interesting software news in a year or so :p18:11
JanCthe funny thing is that I rather accidentally ended up on that project18:12
JanCwow: http://www.cubrid.org/concat_different_row_columns18:14
smoseradam_g, i was poking at 'jstack' again, and thought i'd get over to your code as much as possible, just to reduce my own invention and or bugs18:15
adam_gsmoser: cool, thanks. id like to rewrite that deployer at some point.. actually, i want to add more concurrency when deploying services.. which is what i thought you were proposing, by that name :)18:22
ilovemesomeubuntI'm setting up a game server and wanted to know if I should add the user that is gonna run the game to admin group or use a seperate user for that?18:25
ilovemesomeubuntShould I add the account to the admin group or visudo them?18:26
smoseradam_g, more concurrency?18:26
JanConre: apparently the company behind this DBMS operates the most popular search engine, most popular internet portal & most popular gaming portal in South Korea -- I guess they know how to stress test a database  ;)18:27
adam_gsmoser: using threads during the 'juju deploy' stage. juju commands against ec2 take a loong time18:28
onreJanC, yes, i already installed it... now testing whether my hobby project agrees to run on top of it18:30
smoseradam_g, ah.18:30
onreJanC, because this pretty much addresses the problem i'm having, especially if join performance with indexes is better than mysql 5.518:30
JanConre: I don't really have performance issues right now, but still good to know alternatives exist18:31
ilovemesomeubuntAnyone good with security questions?18:32
onreJanC, indeed. it's been "mysql or postgres" for so long :p18:32
JanConre: there are several other DBMS actually  ;)18:32
JanCeven open source18:32
smoseradam_g, yeah, this gets me to being able to use your code without just destroying the local provider18:32
smoser(or at least doing so more definitively)18:33
onreJanC, indeed, but i haven't really seen many that would have made it even so far that i actually bothered to install and see whether they work. also i have some sort of problem with mysql forks18:33
adam_gsmoser: so have you gotten any further than all services reaching started?18:34
onreJanC, whereas looking at cubrid, the way they've handled things like HA and backups looks very appealing if it manages to do even half of the stuff it promises. :p18:34
JanCilovemesomeubunt: you can create a special group and change sudoers to let users in that group run only the exact commands to start the game servers18:34
JanConre: I'm not sure drizzle is really a MySQL fork, and there is also FirebirdSQL18:35
JanCand there are some SQL servers written in Java, Python, etc.  ;)18:35
onreJanC, drizzle was forked in 200818:36
SpamapSDrizzle is *absolutely* a mysql fork18:36
SpamapS<-- drizzle dev18:36
ilovemesomeubuntJanC, so it is a bad idea to add that user to admin group?18:36
JanCSpamapS: but it doesn't look like mysql right now?  ;)18:36
SpamapSIt speaks the mysql protocol18:37
SpamapSand uses InnoDB as its core storage engine18:37
SpamapSits SQL dialect is 99.9% compatible.. except where MySQL's SQL was broken headed18:37
JanCand it's split up into something more modular?18:37
SpamapSJanC: the ones that aren't forks, that people call forks, are percona and mariadb. Those are derivative branches.. they share code back and forth... so the're not really forks.18:38
SpamapSJanC: the only real reason to use drizzle is its very powerful plugin system.. feels more like Apache that way18:38
JanCwell, they are much more close forks indeed18:38
ilovemesomeubuntJanC, should that user be able to SSH in?18:38
SpamapSJanC: with Oracle not maintaining the community version as closely, they're probably going to become true forks soon.18:39
ilovemesomeubuntor run sudo?18:39
SpamapSMy only problem with CUBRID is it sounds like its more efficient than MYSQL.. but since it works differently, you won't be able to tap the massive amount of wisdom and knowledge available around running large mysql installations.18:41
JanCSpamapS: this CUBRID DBMS promises to have a MySQL compatibility interface too, might be interesting  ☺18:41
JanCtrue18:41
JanCSpamapS: unless you know Korean  ;)18:41
JanCseems like it is very popular there18:41
onreSpamapS, and additionally, no irc channel :(18:47
JanConre: yeah, guess that isn't so popular over there or something18:48
onremost likely.18:48
onrei think i'll try it out anyway. looks like it has quite comprehensive documentation.18:48
JanCseems like their migration toolkit has lots of tools to move from MySQL18:50
freifahrthi, i'm trying to set up a virtual machine on 11.10 and it seems to have problems to find cacert.pem. any suggestions?#18:50
JanCI also wonder how they compare to Postgres (which they don't really mention)18:51
stgraberhallyn: wow, I think I just spent 5 minutes looking at containers shutting down and rebooting properly (the utmp stuff was broken for me somehow) ;)18:54
hallynstgraber: meaning 5 mins of debugging, or 5 mins of it working?18:55
hallyn(i dont' seem to have the new kernel yet)18:55
stgraberhallyn: just 5 minutes of enjoying it working ;)18:58
stgraberhallyn: the -meta was uploaded over the weekend, so if you do your updates + reboot you should have it now18:58
hallynyay18:58
koolhead17hi all19:01
alketHi, i just installed Ubuntu Server 11.10 but when I rebooted after install it doesnt start, just a black screen ? I reinstalled twice19:01
kirklandalket: try hitting ctrl-alt-f219:02
kirklandalket: when you're at that black screen19:02
alketwow, thank you kirkland19:03
alketwhat was wrong though, technicaly ?19:03
hallynkirkland: say, why is my lucid server always wanting to update for byobu?  i haven't been checking the changelogs - security fixes, or features?19:03
kirklandalket: hmm, not sure;  something wrong with your tty or switching19:03
alketok, thank you19:03
kirklandhallyn: you're probably following the ppa:byobu/ppa19:04
kirklandhallyn: which is trunk, and it's a combination of bug fixes and features19:04
hallynyeah i think that was the only way to get byobu-tmux.  i guess i need a byobu-stable/ppa  :-)19:04
kirklandhallyn: you're essentially tracking head, which is nice of you :-)19:04
hallyni forgot i was doing that actually :)19:04
kirklandhallyn: there haven't been any major or security fixes in a long time19:04
kirklandhallyn: is it more or less stable for you?19:05
hallynoh yeah19:05
kirklandhallyn: if so, keep following trunk and keep getting the goodnesses :-)19:05
hallyni have long-running byobu-tmux session for irc19:05
kirklandhallyn: and tell me as soon as I do something wrong19:05
hallynwill do :)19:05
hallynhey, you should wait for the light before crossing the street19:05
hallyn(big brother, just trying to help)19:05
smoseradam_g, ping19:16
smoserhttp://paste.ubuntu.com/822936/ <--- thats a keystone charm fail19:17
SpamapSsmoser: http://i22.photobucket.com/albums/b317/bwftex/keystone-cops-prop-hupmobile.jpg <-- thats a keystone cops fail19:22
smoserthanks, SpamapS http://youtu.be/5atPYaxX0lM19:23
adam_gsmoser: on a call atm19:24
bobweaverHas anyone installed magneto on there servers ? I can not seem to get it to install It will not connect to the database19:28
FaintHow can I prevent DDoS attacks against my Ubuntu server?19:46
PiciNothing.19:46
Picier, You can't.19:46
FaintHow can I slow them down? I've seen people do it before19:47
PiciWhat sort of 'attacks' do you mean exactly? Just requesting pages? or login attempts?19:48
FaintRequesting pages19:48
FaintPinging port 80 mainly.19:49
PiciSnort might help you to protect yourself against that.19:52
patdk-wka real ddos? or just a dos from a few ip's?19:59
Faintpatdk-wk: Anything, I want to be prepared.20:01
patdk-wkit's impossible to prepare for anything20:01
Faintpatdk-wk: Fine, then from a few IPs20:01
patdk-wkexcept to have more resources than the other20:01
patdk-wkhttp://pastebin.com/D6urZggy20:01
patdk-wksomething like that20:02
adam_gsmoser: update the keystone charm to the latest rev and you should be good20:03
adam_gsmoser: that should have gotten updated when e3 went out, my bad.20:04
smoseryeeah. i just was seeing tha tnow.20:06
smoseradam_g, so, isn't the jenkins testing using this/20:06
smoser?20:06
smoserand i dont think you pushed your changes20:07
adam_gsmoser: its using forked charms in https://code.launchpad.net/~openstack-ubuntu-testing that are customized to the lab, and also kept up to date with changes in trunk that affect deployment20:08
adam_gsec20:08
adam_gsmoser: lp:~charmers/charms/precise/keystone/trunk20:08
adam_gsmoser: ill give you a new deployments.cfg, one sec20:09
smoseryeah.20:09
adam_gsmoser: http://paste.ubuntu.com/822988/20:10
adam_gsmoser: those have the correct charm branches now. dashboard + volume are still in my branch pending merge into the charm store. the openstack-precise-ec2 deploymen is what i use to get it going on ec2 using whats in the ubuntu archive.  openstack-ubuntu-testing will deploy the same with packages from the CI PPA, which lag behind trunk by some hours depending on how backed up the builders are20:12
smoseradam_g, k. so you want to commit that example cfg to your junk branch?20:12
jhobbsHow closely will current precise package versions match what ends up in the precise release?20:20
smoserjhobbs, it depends on the package20:22
smoserover the entire archive "probably pretty close"20:22
smoserbut...20:23
jhobbsok20:23
jhobbsi guess you could always bump a package to pick up a high priority bug fix, even late in the release schedule20:23
adam_gsmoser: done20:23
mp_hello all. what's the thing with client/server keys. i'm trying to install a virtual machine on 11.10 and it asks for a cacert.pem. can't find anything about it in the serverguide for libvirtd. help appreciated.20:25
ChmEarlapt-get install ca-certificates20:28
mgwI'm working with puppet (puppet apply) and need to read files relative to $confdir — e.g., something like puppet:////files/foo/bar to read /etc/puppet/files/foo/bar20:29
mp_>"can't access client key in /etc/pki/CA/cacert.pem.... file not found"20:30
mp_ca-certificates has been installed20:30
mp_*was installed20:31
mp_i made my own cert now and put it in /usr/share/ca-certificates, didn't work. made that pki directory and put my cert in there, now he wants a client certificate20:32
mp_which ubuntu documentation explains setting up a vm?20:34
mgwmp_: this might get you started — http://linux.die.net/man/1/virsh20:35
mp_mgw: thanks a lot20:36
mgwmp_: np20:36
mp_that's the manpage20:37
mgwmp_: this too20:37
mgwhttp://libvirt.org/20:37
elfurbeAnyone have any experience debugging dkms builds? I'm having an issue building a module, it's telling me that it failed to build, but when I issue the make command myself, the .ko is definitely right where I told it to look in the dkms.conf20:37
mp_mgw: are you kidding me?20:38
mgwmp_: what do you mean?20:38
mp_the ubuntu documentation does not work as is20:38
mgwhttps://help.ubuntu.com/8.04/serverguide/C/virtualization.html doesn't work? What in particular?20:39
mp_it's a 11.10 server20:40
mp_let me look into that20:40
mgwhttps://help.ubuntu.com/11.10/serverguide/C/libvirt.html20:40
mp_that's the one20:40
mgwit doesn't work?20:41
mp_where are certificates mentioned?20:41
mgwAre you wanting to set up certs on the host machine or on a vm you already have running?20:42
elfurbeHa, comedy overlook-the-obvious update, I used "BUILD_MODULE_LOCATION" instead of BUILT_MODULE_LOCATION in the dkms,conf20:43
mp_i have the server as a host and tried to set up vms20:43
elfurbeClever lad, me20:43
mp_which did not work out as expected20:43
hallynsmoser: so checkign one more time, are you ok with switching from 'lxc-is-container' to 'running-in-container'?20:43
hallynstgraber: ^ have an opinion/preference?20:44
smoseri can adjust, hallyn, but i don't relaly understand why20:44
smoserand i think nomrally when people did somethign like that they'd use a symlink for comnpatibility20:44
smoserbut i leave it up to you20:44
hallynmaybe i should leave it20:45
hallynok i'll leave it :)20:50
stgraberhallyn: I'd love to see something a bit generic like running-in-container that'd return the container type (lxc, libvirt-lxc, openvz-ve, vserver) and return 0 if it's a container or 1 if it's not20:52
stgraber(I can contribute the logic for the other container types as I already have it in some configuration management probes here)20:52
hallynstgraber: instead of lxc-is-container, or in addition?20:52
stgraberhallyn: I'd prefer to have one is-container that'd return 0 or 1 depending if it's a container or not and return the name of the technology if it's a container20:53
hallynstgraber: https://code.launchpad.net/~serge-hallyn/ubuntu/precise/upstart/upstart-containers/ is what i have now.  it works both on hosts and containers.  do you want to update (and rename if you like) lxc-is-container, then propose merge?20:53
stgraberhallyn: so that'd be instead of lxc-is-container20:53
hallynstgraber: btw, container with lxcguest removed booted with that upstart :)20:53
stgraberhallyn: ok, I'm rushing some LTSP changes now that I want in for alpha2. I'll have a look at the branch once I'm done and propose something that'd work for me (then we can check that I won't break some other use cases in the process ;))20:54
hallynstgraber: great20:55
smoserstgraber, if you're testing general boot of lxc without lxcguest20:56
smosertry removing it from cloud-images and testin20:56
smoser(also may want dpkg-reconfigure cloud-init)20:56
smoseri guess i can test easily enough, thogh.20:57
smoserSpamapS, ping20:58
smosernever mind.20:58
SpamapSsmoser: pong, never matter20:59
smoserSpamapS, the query was regarding archive.buntu.com entry in /etc/hosts20:59
smoserwhich at first i thought would not affect 'apt-get install' from inside a juju container21:00
smoserbut now i'm thinking it will becaues those apt-gets will reference an outside-the-container apt-cacher-ng21:00
SpamapSsmoser: yep21:03
hallynstgraber: (oops, i mungled the rename of running-in-container, so just re-renamed it and pushed so it will build)21:04
hallynbiab21:04
smoseradam_g, ping21:42
=== bladernr_ is now known as bladernr_afk
adam_gsmoser: pong22:02
SpamapSLISA '12 CFP is open.. San Diego is nice in December.... :)22:05
SpamapSjcastro: **22:05
SpamapSrobbiew: ^^22:06
robbiewyep...got the email22:06
nOStahlhey guys, I left home without my ubuntu server cd22:06
nOStahland the tower cant boot off usb-zip or usb-fdd hrmm22:07
nOStahlthe tower has ubuntu 10.10 on it right now desktop22:07
nOStahlwhat options do I have to re-install ubuntu 11.10 server over it22:07
JanCnOStahl: upgrade and remove all desktop packages?  ;)22:10
JanCnOStahl: also, does it support USB-MS ?22:11
nOStahlno option for usb-ms22:11
nOStahlif it has usb-zip or fdd It may be a flag problem on the flash drive?22:11
JanCnOStahl: you can also use debootstrap to bootstrap any Debian/Ubuntu distro22:13
nOStahlwhats that?22:14
nOStahlgot a link22:14
adam_gDaviey: https://bugs.launchpad.net/nova/+bug/900925, so that kind of validation must have gotten lost since diablo22:19
uvirtbotLaunchpad bug 900925 in nova "create key pair gets a name which is longer than 256" [Medium,Fix committed]22:19
Davieyadam_g: ffs, is just on ec2 api aswell?22:23
adam_gDaviey: no, i believe it was in the common key pair controller, but its fixed now..22:25
nOStahlheh figured out easy way.22:27
nOStahlmake small 1 gig partition on the hd22:27
nOStahlfrom recovery mode22:27
nOStahland then boot into ubuntu on the machine and use unetbootin to setup that partition with the installer iso :)22:27
nOStahlthen when all done merge the partition back into the main partition etc.22:28
Davieyadam_g: yeah, i had an ec2 unit test against that...22:28
Davieybut just tested the api functions.22:28
Davieyadam_g: is https://blueprints.launchpad.net/ubuntu/+spec/servercloud-p-openstack-charms accurate?22:52
adam_gDaviey: in terms of my WI? yeah, just submitted nova-volume to the charm store today.  it seems the ceph+glance WI needs to be postponed22:54
adam_gDaviey: "nova-cloud-controller - Split into charms after Juju supports multiple units on a machine (or colocation)" maybe BLOCKED until that support lands in juju22:55
uvirtbotNew bug: #924002 in autofs5 (main) "[Lucid] dbg package symbols are not provided for latest autofs packages" [Undecided,New] https://launchpad.net/bugs/92400222:56
Davieyadam_g: can you update that please?22:58
Daviey(thanks)22:58
=== koolhead17 is now known as koolhead17|zzZZ
starscreamhi! people23:59
starscreamI need to help23:59

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!