/srv/irclogs.ubuntu.com/2012/03/29/#ubuntu-server.txt

=== nonotza_ is now known as nonotza
=== nonotza_ is now known as nonotza
hallyntjaalton: just tested debian sid xserver-xorg-video-qxl in precise guest, worked fine for me.03:04
hallyntjaalton: i can't say whether it fixes the standing bugs i pointed to, but quick test didn't show up any new bugs for me03:05
tjaaltonhallyn: nice to hear, thanks04:11
uvirtbotNew bug: #957003 in sssd (main) "sssd_be crashed with SIGABRT" [Undecided,New] https://launchpad.net/bugs/95700307:31
=== bigjools-afk is now known as jtvs-evil-twin
=== jtvs-evil-twin is now known as bigjools_
jamespageDaviey: around? wanted to check something euca related with you for precise?08:01
Davieyjamespage: hola08:11
jamespageDaviey: there are a number of packages which won't install anymore due to euca being removed from precise08:13
jamespageDaviey: python-image-store-proxy being one of them - should I go ahead and request they are dropped as well?08:14
Davieyjamespage: yes please08:21
jamespageDaviey, ack08:22
Davieyjamespage: utlemming was removing the UEC branding i understood.08:22
Davieyjamespage: We want to be as close to upstream Euca as we can.08:22
lynxmanmorning o/08:30
huatsmorning08:38
uvirtbotNew bug: #914469 in bind9 (main) "dig crashed with SIGABRT in isc_assertion_failed()" [Medium,Confirmed] https://launchpad.net/bugs/91446908:47
uvirtbotNew bug: #915870 in bind9 (main) "dig crashed with SIGABRT in raise() when using +trace +sigchase" [Medium,New] https://launchpad.net/bugs/91587009:01
uvirtbotNew bug: #923754 in ocfs2-tools (main) "ocfs2console crashed with DeprecationWarning in /usr/lib/python2.7/popen2.py: The popen2 module is deprecated.  Use the subprocess module." [Medium,Confirmed] https://launchpad.net/bugs/92375409:12
brontosaurusrexhi, how would i go updating karmic server to 10.04 or something?09:24
rbasakDaviey: I've filed bug 968124. What's the right way for it to be tracked appropriately? Milestone for 12.04? Or subscribe someone appropriate? Or a tag? Or something else?10:21
uvirtbotLaunchpad bug 968124 in rabbitmq-server "Restarting rabbitmq-server from another package's postinst hangs the init script" [High,Triaged] https://launchpad.net/bugs/96812410:21
jamespagerbasak, ah - I think I just hit that - bah10:22
rbasakjamespage: there's a workaround. I'll post in the bug10:22
jamespagerbasak, ta - I'll target that for you as well if that helps10:23
jamespageis this for beta-2?10:23
rbasakbeta-2 is today, isn't it?10:23
rbasakI was wondering what the appropriate mechanism for targeting is really10:23
jamespagerbasak, not beta-2 then10:23
jamespage:-)10:23
jamespagerbasak, I normally nomiate for release and target to a milestone10:23
jamespagerbasak, I think you can nominate but it won't be automatically accepted10:24
rbasakjamespage: does that make it show up in http://status.qa.ubuntu.com/reports/ubuntu-server/release-bugs.html? What does that report filter on?10:24
Davieyrbasak: it's fixed in trunk10:25
Davieyrbasak: roaksoax will be uploading a fix today, so it's in the archive for beta-2 release time10:25
jamespagerbasak, ah - subscribe ubuntu-server-release-tracking10:25
rbasakDaviey: ah cool, thanks10:25
uvirtbotNew bug: #968124 in rabbitmq-server (main) "Restarting rabbitmq-server from another package's postinst hangs the init script" [High,Triaged] https://launchpad.net/bugs/96812410:26
Davieyi literally just tested his package :)10:26
rbasakDaviey: I literally just reproduced on amd64 :)10:27
Davieyrbasak: from the PPA?10:27
rbasakDaviey: no from the archive10:27
Davieywell then.10:27
Daviey:)10:27
PedroGomesHi, I have dozens of machines on my lab, all equal among themselves. When I try to install the ubuntu 12.04 some machines, but not all report an error when mounting the ram disck11:10
PedroGomesthere is a kernel panic because it can't find the /dev/rd/0 partition11:11
PedroGomesbut If I install the stable version with the same pxe file11:11
PedroGomesit works11:11
PedroGomesany idea?11:11
andygraybealhold up, so pgadmin isn't a web interface?11:27
andygraybeal*pgadmin3 ? it's asking for gtk.11:27
andygraybealgrrrrr!11:27
=== acidflash__ is now known as acidflash
andygraybealhmm i guess i can install it on my workstation.. and then connect to the server.. doh11:31
zulbeta is out yet?11:35
dorkits been out for weeks11:42
piquadratHi! Is there a packed version of solr 3.x available  somewhere? 1.4 from the repos is quite ancient12:34
zulgood morning12:51
jamespagepiquadrat, not in either the debian or ubuntu archives at the moment12:56
jamespagesorry - on my list for next release...12:56
jamespage(your are not the first to ask :-))12:57
piquadratjamespage: it's simple enough to set it up manually, so no worries :)12:57
jamespage1.4 is not quite that ancient - its only one major release behind12:57
jamespagesolr skipped 2.x12:57
=== acidflash_ is now known as acidflash
=== bladernr_afk is now known as bladernr_
piquadratyeah, but Solr 3 has all these shiny new things like spatial support :)13:04
=== PedroGomes_ is now known as PedroGomes
koolhead11anyone around!! :P13:23
=== PedroGomes_ is now known as PedroGomes
=== bladernr_ is now known as bladernr_afk
=== bladernr_afk is now known as bladernr_
AmougWhat is the use of nosuid mount option if one is already mounting with noexec ? From a security perspective14:30
xranbyAmoug: there do pop up bugs that enable execution of binarys on noexec filesystems14:37
xranbylike the  /lib/ld*.so /mnt/binary  trick14:37
xranbythat plauged some kernels14:37
xranbynosuid of course makes sure the suid bit are not set14:37
Amougxranby, so it is more of a defense in depth14:39
Amougbecause modern kernels fixed that trick14:40
xranbyAmoug: all i am saying, it looks hard to execute a binary and misuse the suid bit,  people belived it to be impossible before that trick got discovered14:40
xranbynet tricks can get discovered14:40
xranbyif you are security paranoid,, be paranoid :)14:41
xranbyand try secure your system before someone finds out how to get you14:41
xranbyits a cat and mouse race after all14:41
Amougxranby, I am more of a pentester than a sysadmin... But you have to learn how to secure, in order to know how to find flaws14:42
Amougand vice versa :)14:43
=== Arc_ is now known as a5m0
stgraberhallyn: ping15:25
hallynstgraber: hey15:25
stgraberhallyn: lxc-execute is mounting the mqueue filesystem on /dev/mqueue/ showing a failure with arkose (though still working fine afterwards)15:26
hallynstgraber: yes, lxc-init always does that.15:26
stgraberhallyn: so I was wondering if mqueue is considered safe and if so if we should add a "mount fstype=mqueue," to the profile15:26
stgraberstgraber@castiana:~/data/code/ubuntu-archive-tools$ sudo arkose -h15:26
stgraberlxc-init: failed to mount /dev/mqueue : Permission denied15:26
stgraberstgraber@arkose-tmpTkI6d7:~/data/code/ubuntu-archive-tools$15:26
stgraberat least lxc-init is kind enough to ignore the failure and continue so that didn't break arkose ;)15:27
hallynstgraber: yeah, it didn't used to ignore that :)  hold on, i'm checking whether that is definately namespace-safe15:28
hallynyeah, no reason not to imo15:29
hallyn('mount -t mqueue /dev/mqueue /mnt' after lxc-unshare -s IPC /bin/bash does not show the contents from the host's equivalent mount)15:30
stgrabergood, I'll upload the change as soon as the freeze is lifted then15:30
stgraberhallyn: isn't bug 948447 fixed with the apparmor profile?15:32
uvirtbotLaunchpad bug 948447 in lxc "Starting an LXC changes the volume (sound!) of the host" [Medium,Confirmed] https://launchpad.net/bugs/94844715:32
hallynstgraber: no15:34
hallynstgraber: that's fixed with precise guests bc udevadm trigger doesn't run15:34
hallynstgraber: apparmor can't stop that15:34
hallynthat's the one we coudl do if we coudl write a BPF filter to reject the uevent netlink msgs from container15:34
hallynheck, with seccomp2 now in our kernel, maybe we could do something with that.  if it wasn't too late15:35
stgraberhallyn: ok, good, so we can probably mark it fixed for good next cycle then15:35
hallynhopefully.  i'm not 100% clear on how it'll work in practice15:38
uvirtbotNew bug: #968326 in lxc (universe) "lxc-execute tries to mount /dev/mqueue and is rejected by apparmor" [Medium,Fix committed] https://launchpad.net/bugs/96832615:40
=== Ursinha_ is now known as Guest92471
hallynstgraber: is that the only bug you're getting from lxc-execute?15:44
stgraberhallyn: yep15:48
gary_posterhallyn, hey.  -b in current lxc-create sets up an fstab that has "$homedir $homedir none bind 0 0" instead of "$homedir /var/lib/lxc/$container/rootfs/$homedir none bind 0 0".  This doesn't seem to work.  I'm about to file a bug, unless you stop me along the way. :-)16:07
Davieyroaksoax: Hey, are you planning that rabbit upload?16:08
Davieyroaksoax: we are now in thaw btw16:09
hallyngary_poster: why does it not work?  that shoudl work16:11
hallynbug is good16:11
gary_postercool hallyn, will give details16:12
roaksoaxDaviey: already uploaded16:12
Davieyroaksoax: awesome16:12
roaksoaxhggdh: I need free machines to work on the fence_cdu issue you were seeing16:13
hggdhroaksoax: we are upgrading aldebaran to the jenkins precise backport right now. When we are done, you can test it there (as long as you do not destroy the system ;-))16:15
roaksoaxhggdh: hehe I just need a couple of machines to 1. see what's going on. 2. work on a fix16:15
roaksoaxhggdh: so, the cobbler server and 2 free machines not being used16:16
roaksoaxto try to reproduce what you are seeing16:16
hggdhroaksoax: deal16:16
hggdhroaksoax: it will be aldebaran as the cobbler server, and alkaid and phact as the cannon fodder16:16
roaksoaxhggdh: cool, just let me know when they are free16:17
roaksoaxi'll work on it this afternoon16:17
gary_posterhallyn, a bot will announce it soon I'm sure, but I filed bug 968371.  Running to lunch.16:18
uvirtbotLaunchpad bug 968371 in lxc "lxc-create -b is broken" [Undecided,New] https://launchpad.net/bugs/96837116:18
hggdhroaksoax: ack16:20
uvirtbotNew bug: #968371 in lxc (universe) "lxc-create -b is broken" [Undecided,New] https://launchpad.net/bugs/96837116:26
smoserha.16:37
smoserthis is pretty awesome16:37
smoserhttp://www.erikyyy.de/invaders/16:37
smoserdownload, extract, run:16:37
smoser kvm -kernel invaders16:37
=== marrusl_ is now known as marrusl
=== koolhead17 is now known as bootlepy
=== bootlepy is now known as koolhead17
koolhead17Daviey, please let me know when you around, something important17:19
koolhead17to talk17:19
koolhead17help needed17:19
gary_posterhallyn, we are trying to decide whether to manually fix a one-off instance of our machinery and run some tests, or wait for the fixes (ubuntu template and lxc-start-ephemeral, I'm guessing) to bug 968371.  (Note that we're also willing to help with that bug, but it sounded like you were working on it already.)  Is this something we can hope to have fixed by, say, tomorrow; or will it be later?17:50
uvirtbotLaunchpad bug 968371 in lxc "lxc-create -b is broken" [High,Confirmed] https://launchpad.net/bugs/96837117:50
hallynstgraber: ^ when is freeze to be lifted?17:52
stgraberhallyn: it's17:52
stgraberhallyn: I already uploaded lxc a few minutes ago with the lxc-execute fix17:52
hallynok17:53
hallyngary_poster: i'd really like to finish digging into this libvirt bug, but i didn't realize you had a deadline.  I can pusha fix by tomorrow morning at leatest17:53
gary_posterhallyn, thank you; like I said, I'm happy to help, and also, if you want to dig into libvirt and then do this, that's fine, but it will change our plans a bit.  No biggie.  Would Monday be a better goal for 968371?17:55
axisysdo I make change in logrotate.d/rsyslog or some other file to make sure mail.log in always 644 ?17:56
hallyngary_poster: no let's plan on tomorrow.  LIke I say i'ts just a matter of removing the leading '/' from the second field in fstab, so if you want to post a debdiff that'd be great;  but i'll do it.  (once i decide how best to do it in bash :)17:56
hallyngary_poster: really, I feel like I should re-write the lxc-start-ephemeral to be cleaner script (local vars, exit early if first part of pipline fails, etc).17:57
gary_posterheh, cool, thanks hallyn.  And then we might need an ephemeral change too, right, for the lines that parse fstab?  re-write: yeah, that sounds nice.  If it fits in your schedule, and we still have some time to test and debug it before final freeze, sounds good17:58
hallyngary_poster: actually,17:59
hallyngary_poster: originall someone wanted lxc-start-ephemeral to work for non-root,17:59
hallyngary_poster, but some of the parsing being done now should make that fail.  Do you care?17:59
hallyn(i.e. 'while read line do < fstab.orig > fstab' type of stuff)17:59
gary_posteryeah, we talked about that17:59
hallyni hope you don't mean you and i18:00
hallyn(just bc i have no recollection, and worry about my memory)18:01
gary_poster(no sorry, talked about it on our team.) I suspect it was me caring.  I'm into it just working now. :-)  We (our team) actually talked about proposing to rip all of the support for non-root for simplicity18:01
gary_posterWe didn't do it, but would be fine with it now.18:01
hallynright, we should either fix it somehow, or do a check early on for id == 0 and fail cleanly if not18:02
gary_poster+118:02
gary_posterhallyn, so having the fix in tomorrow is plenty early for us, and much appreciated.  Please ask us if you want us to work on it, and we'll be happy to, but by default we won't, and will leave it to you.18:04
gary_posterCan also do testing if that would be helpful18:04
uvirtbotNew bug: #968411 in nova (main) "[Precise] nova is vulnerable to CVE-2012-1585" [Medium,Confirmed] https://launchpad.net/bugs/96841118:38
zuladam_g: im looking to upload a newish keystone tomorrow18:39
=== che3ver_ is now known as tcivyr
adam_gzul: with what?18:43
zuladam_g: the one with the git clone stuff removed from the testusite18:44
adam_gzul: please push to -proposed first, im going to be squashing some packaging bugs later today too18:44
adam_gnova has a few, and id really like to get the quantum package installabel18:44
zuladam_g: its already in there18:44
adam_gk18:44
uvirtbotNew bug: #914164 in horizon (universe) "[MIR] horizon" [High,Incomplete] https://launchpad.net/bugs/91416419:02
melterdoes anyone know if the 12.04 focus on new hardware applies to ubuntu server?19:12
dorkabsolutely19:13
jamespageSpamapS, m_3: any opinion on whether I should spend some time FFe'ing/merging nodejs 0.6.x from debian for precise?19:15
melterdork: was that a reply to me?19:17
dorkmelter: yes19:20
smoserutlemming, need your help.19:21
m_3jamespage: don't really know what depends on the new version19:27
jamespagem_3: nothing in the archive19:28
m_3jamespage: as a general rule, sure... but19:28
jamespagebut node seems to move along at a fair pace19:28
m_3jamespage: yup, I'm for it if you have tim19:30
m_3e19:30
jamespagem_3: I'll push it all somewhere to see if it works19:30
jamespagesure it will but...19:30
smoserutlemming, when you see this, please look at https://code.launchpad.net/~smoser/cloud-init/precise-locale-warning19:32
smoserit seems to function as designed, but then when i tried to get french error messages i failed.19:32
smoserie, i set LC_ALL=fr_FR.UTF-8, and ssh'd in.19:33
smoserit gave me a friendly error message19:33
smoseri ran sudo localegen.... set LANG and LANGUAGE to fr_FR but then when i do somethin glike: ls asdf19:34
smoserthe error message is english19:34
Davieywfm19:34
smoserutlemming, i assigned bug 859814 to you.19:53
uvirtbotLaunchpad bug 859814 in cloud-init "Locale issues with beta-1/2 cloud-images" [Medium,In progress] https://launchpad.net/bugs/85981419:53
smoseri'd suggest starting from my branch and making sure that when you foloow the given directions it works.19:53
adam_gzul: were you able to successfully run all keystone tests lately?19:55
zulnot since friday19:56
zulare they broken again?19:56
adam_goh i see19:58
adam_gzul: the ksc test cases target (and git checkout) 3 different keystoneclient branches19:59
zullovely..20:00
adam_gzul: we can just get rid of KcMasterTestCase + KcEssex3TestCase i think20:01
adam_gill look into after luch. bb in a few20:01
zuladam_g: agreed20:01
utlemmingsmoser: ack20:04
SpamapSjamespage: what is our delta for node where we can't just sync it?20:05
smoseri can' tseem to make it give me french error messages20:05
utlemmingsmoser: do you have a paste of what your doing?20:06
smoserutlemming, well, not really.20:07
smoser:)20:07
smoserbut the goal is to just launch instance20:08
smoserinstall new deb20:08
smoserexit20:08
smoserLC_ALL=some_other_lang ssh instance20:08
smosersee message, follow instructions20:08
utlemmingso this is interesting20:08
smoserexit20:08
smoserLC_ALL=some_other_lang ssh instance20:08
smoserls asdf20:08
utlemmingif you have a proper locale generated and defined in the settings, then you get localized messages20:08
smosersee failed message in some othe rlanguage20:08
utlemmingif, however, any of your locales defined in LANG=? or LC_*=?, are bad, then you get english20:09
smoseri'm completley locale iillterate.20:09
utlemminghttp://paste.ubuntu.com/906193/20:09
_rubenwhat determines the resolution of the console nowadays? (or on O actually)20:18
_rubengot two boxes, installed in the same way, but they ended up with different resolutions20:18
_rubenone of 'em might've had a monitor attached and the other not, during install20:19
=== bladernr_ is now known as bladernr_afk
jamespageSpamapS, mainly tests - we get some different test failures/timeouts20:35
SpamapSjamespage: ugh20:35
=== rickspencer3_ is now known as rickspencer3
jseutteranyone here running maas from trunk?20:50
jacobwmaas?20:53
jacobwassume that i want to learn juju, how could i do that?20:54
jseutterjacobw: do you want to use juju, or write charms?20:59
jseutterjacobw: if you want to simply use it, juju.ubuntu.com is pretty much the only spot for docs.21:00
jseutterjacobw: the tutorial there is pretty good at explaining how things work.  The other place you can look for stuff is on youtube.21:02
smoserutlemming, ok. you and i need to figure out how to do basic locale stuff21:04
utlemmingsmoser: like?21:04
smoserie, i want to see an error message that i dont undretsand.21:04
smoserhow do you do that21:04
* utlemming works on it21:05
smoseri was using 'ls' because i'm almost certain its "no such file or directory" is translated.21:10
utlemmingtry apt21:11
utlemmingso it depends on the language. But I've exported "LC_ALL=fr_FR21:12
utlemmingand I get:21:12
utlemming$ apt-get --fail-miserably-you-stupid-machine21:12
utlemmingE: L'option --fail-miserably-you-stupid-machine de la ligne de commande n'est pas reconnue21:12
utlemmingand the language pack is not installed.21:14
utlemmingAfter installing "language-pack-fr-base":21:15
utlemming$ ls foo21:15
utlemmingls: impossible d'acc�der � foo: Aucun fichier ou dossier de ce type21:15
utlemmingsmoser: ^21:15
utlemmingsmoser: so the conclusion that we can draw here is 1) unless the appropriate language pack is installed, then errors messages are in english and 2) the default error language is english21:18
jetoleHey guys. Don't know if this is the best spot to ask but does anyone know how I can add a user to sudo-ldap who can execute all commands except certain ones, for example if I wanted to set a rule that allowed a user to execute all commands except /usr/bin/perl and /usr/bin/python, does anyone know how I would do that?21:41
lifelessman sudoers21:42
jetolelifeless: you know sudo? Can you take a look at my questions and see if you have any suggestions related to my problem?21:44
SpamapSjetole: if they can execute "all commands except perl" , they can execute /bin/bash .. or /usr/bin/top .. and run other commands21:46
SpamapSjetole: consider defining the exact commands they can execute, and just let them do that21:47
jetoleSpamapS: actually I can set these rules on normal sudo so they can execute all commands except the ones I specify and I can make it so they cannot execute other command from the command called by sudo. On normal sudo I can say define a command alias SHELLS and have it contain all the shells on the system and then I say the user rule is """user ALL=ALL, !SHELLS""" (without the quotes) and then I use the option noexec which makes it so if I try ...21:51
jetole... to run anything from say top, or vim, etc that it will fail. Now I know how I can easily implement noexec with sudo-ldap but, it doesn't have aliases and there are some weird limitions with the order it processes rules so not sure how to do the first part21:51
=== Jasonn is now known as juicy
SpamapSjetole: heh.. sounds like complexity to me.. I'm like frankenstein with complexity.. COMPLEXITY BAD!!!22:09
* SpamapS goes on a rampage22:09
zulSpamapS: braaains....braiiins22:21
EvilResistancezul, stop being a zombie, or i'll have to get my zombie-buster out22:23
=== Jasonn is now known as juicy
mcloy wget -r is not showing sometimes layout and  the links are always not working22:25
=== jvdz_ is now known as jvdz
SpamapSEvilResistance: do you call it 'Waitpid The Destroyer'? ;)22:34
jetoleSpamapS: yeah it's actually pretty easy and basic sudo stuff typically but something is different in sudo-ldap and while I can't put my finger on it, someone will come by and say "oh you just do it like this"22:47
jetole...and I will scream "why didn't I think of that?"22:47
jetoleon that not I'm going home for the day. Later22:47
Aethorhi all :) any network guru available for help/advice?23:12
SpamapSAethor: best to just ask your question, and if somebody is around who can answer, they will23:12
Aethorok - ubuntu 11.10, trying to bond 2 NICs, and at the end of my wits - /etc/network/interfaces looks ok and yet it doesn't work23:13
Aethoron network restart, I get a "RTNETLINK answers: File exist" error23:13
Aethorand then "Failed to bring up bond0"23:13
Juv1228hello, im trying to configure a server here. it has a single IP and needs to run several lxc containers23:14
Juv1228so it needs to use a nat and internal bridge correct?23:14
SpamapSJuv1228: lxc containers can use nat, or bridged networking23:15
Juv1228SpamapS, but with a bridged networking they each have to have their own public ip right?23:16
SpamapSJuv1228: right, so you probably want NAT23:18
Juv1228to avoid that i am trying to setup a nat and use shorewall to firewall/forward things23:18
Juv1228the problem is none of my containers can reach the outside world23:19
uvirtbotNew bug: #968722 in rabbitmq-server (main) "/usr/sbin missing some wrappers for plugins/env" [Undecided,New] https://launchpad.net/bugs/96872223:41
taipresThat bug report is confusing23:50
taipresoh missing files, nevermind23:51

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!