=== nonotza_ is now known as nonotza === nonotza_ is now known as nonotza [03:04] tjaalton: just tested debian sid xserver-xorg-video-qxl in precise guest, worked fine for me. [03:05] tjaalton: i can't say whether it fixes the standing bugs i pointed to, but quick test didn't show up any new bugs for me [04:11] hallyn: nice to hear, thanks [07:31] New bug: #957003 in sssd (main) "sssd_be crashed with SIGABRT" [Undecided,New] https://launchpad.net/bugs/957003 === bigjools-afk is now known as jtvs-evil-twin === jtvs-evil-twin is now known as bigjools_ [08:01] Daviey: around? wanted to check something euca related with you for precise? [08:11] jamespage: hola [08:13] Daviey: there are a number of packages which won't install anymore due to euca being removed from precise [08:14] Daviey: python-image-store-proxy being one of them - should I go ahead and request they are dropped as well? [08:21] jamespage: yes please [08:22] Daviey, ack [08:22] jamespage: utlemming was removing the UEC branding i understood. [08:22] jamespage: We want to be as close to upstream Euca as we can. [08:30] morning o/ [08:38] morning [08:47] New bug: #914469 in bind9 (main) "dig crashed with SIGABRT in isc_assertion_failed()" [Medium,Confirmed] https://launchpad.net/bugs/914469 [09:01] New bug: #915870 in bind9 (main) "dig crashed with SIGABRT in raise() when using +trace +sigchase" [Medium,New] https://launchpad.net/bugs/915870 [09:12] New bug: #923754 in ocfs2-tools (main) "ocfs2console crashed with DeprecationWarning in /usr/lib/python2.7/popen2.py: The popen2 module is deprecated. Use the subprocess module." [Medium,Confirmed] https://launchpad.net/bugs/923754 [09:24] hi, how would i go updating karmic server to 10.04 or something? [10:21] Daviey: I've filed bug 968124. What's the right way for it to be tracked appropriately? Milestone for 12.04? Or subscribe someone appropriate? Or a tag? Or something else? [10:21] Launchpad bug 968124 in rabbitmq-server "Restarting rabbitmq-server from another package's postinst hangs the init script" [High,Triaged] https://launchpad.net/bugs/968124 [10:22] rbasak, ah - I think I just hit that - bah [10:22] jamespage: there's a workaround. I'll post in the bug [10:23] rbasak, ta - I'll target that for you as well if that helps [10:23] is this for beta-2? [10:23] beta-2 is today, isn't it? [10:23] I was wondering what the appropriate mechanism for targeting is really [10:23] rbasak, not beta-2 then [10:23] :-) [10:23] rbasak, I normally nomiate for release and target to a milestone [10:24] rbasak, I think you can nominate but it won't be automatically accepted [10:24] jamespage: does that make it show up in http://status.qa.ubuntu.com/reports/ubuntu-server/release-bugs.html? What does that report filter on? [10:25] rbasak: it's fixed in trunk [10:25] rbasak: roaksoax will be uploading a fix today, so it's in the archive for beta-2 release time [10:25] rbasak, ah - subscribe ubuntu-server-release-tracking [10:25] Daviey: ah cool, thanks [10:26] New bug: #968124 in rabbitmq-server (main) "Restarting rabbitmq-server from another package's postinst hangs the init script" [High,Triaged] https://launchpad.net/bugs/968124 [10:26] i literally just tested his package :) [10:27] Daviey: I literally just reproduced on amd64 :) [10:27] rbasak: from the PPA? [10:27] Daviey: no from the archive [10:27] well then. [10:27] :) [11:10] Hi, I have dozens of machines on my lab, all equal among themselves. When I try to install the ubuntu 12.04 some machines, but not all report an error when mounting the ram disck [11:11] there is a kernel panic because it can't find the /dev/rd/0 partition [11:11] but If I install the stable version with the same pxe file [11:11] it works [11:11] any idea? [11:27] hold up, so pgadmin isn't a web interface? [11:27] *pgadmin3 ? it's asking for gtk. [11:27] grrrrr! === acidflash__ is now known as acidflash [11:31] hmm i guess i can install it on my workstation.. and then connect to the server.. doh [11:35] beta is out yet? [11:42] its been out for weeks [12:34] Hi! Is there a packed version of solr 3.x available somewhere? 1.4 from the repos is quite ancient [12:51] good morning [12:56] piquadrat, not in either the debian or ubuntu archives at the moment [12:56] sorry - on my list for next release... [12:57] (your are not the first to ask :-)) [12:57] jamespage: it's simple enough to set it up manually, so no worries :) [12:57] 1.4 is not quite that ancient - its only one major release behind [12:57] solr skipped 2.x === acidflash_ is now known as acidflash === bladernr_afk is now known as bladernr_ [13:04] yeah, but Solr 3 has all these shiny new things like spatial support :) === PedroGomes_ is now known as PedroGomes [13:23] anyone around!! :P === PedroGomes_ is now known as PedroGomes === bladernr_ is now known as bladernr_afk === bladernr_afk is now known as bladernr_ [14:30] What is the use of nosuid mount option if one is already mounting with noexec ? From a security perspective [14:37] Amoug: there do pop up bugs that enable execution of binarys on noexec filesystems [14:37] like the /lib/ld*.so /mnt/binary trick [14:37] that plauged some kernels [14:37] nosuid of course makes sure the suid bit are not set [14:39] xranby, so it is more of a defense in depth [14:40] because modern kernels fixed that trick [14:40] Amoug: all i am saying, it looks hard to execute a binary and misuse the suid bit, people belived it to be impossible before that trick got discovered [14:40] net tricks can get discovered [14:41] if you are security paranoid,, be paranoid :) [14:41] and try secure your system before someone finds out how to get you [14:41] its a cat and mouse race after all [14:42] xranby, I am more of a pentester than a sysadmin... But you have to learn how to secure, in order to know how to find flaws [14:43] and vice versa :) === Arc_ is now known as a5m0 [15:25] hallyn: ping [15:25] stgraber: hey [15:26] hallyn: lxc-execute is mounting the mqueue filesystem on /dev/mqueue/ showing a failure with arkose (though still working fine afterwards) [15:26] stgraber: yes, lxc-init always does that. [15:26] hallyn: so I was wondering if mqueue is considered safe and if so if we should add a "mount fstype=mqueue," to the profile [15:26] stgraber@castiana:~/data/code/ubuntu-archive-tools$ sudo arkose -h [15:26] lxc-init: failed to mount /dev/mqueue : Permission denied [15:26] stgraber@arkose-tmpTkI6d7:~/data/code/ubuntu-archive-tools$ [15:27] at least lxc-init is kind enough to ignore the failure and continue so that didn't break arkose ;) [15:28] stgraber: yeah, it didn't used to ignore that :) hold on, i'm checking whether that is definately namespace-safe [15:29] yeah, no reason not to imo [15:30] ('mount -t mqueue /dev/mqueue /mnt' after lxc-unshare -s IPC /bin/bash does not show the contents from the host's equivalent mount) [15:30] good, I'll upload the change as soon as the freeze is lifted then [15:32] hallyn: isn't bug 948447 fixed with the apparmor profile? [15:32] Launchpad bug 948447 in lxc "Starting an LXC changes the volume (sound!) of the host" [Medium,Confirmed] https://launchpad.net/bugs/948447 [15:34] stgraber: no [15:34] stgraber: that's fixed with precise guests bc udevadm trigger doesn't run [15:34] stgraber: apparmor can't stop that [15:34] that's the one we coudl do if we coudl write a BPF filter to reject the uevent netlink msgs from container [15:35] heck, with seccomp2 now in our kernel, maybe we could do something with that. if it wasn't too late [15:35] hallyn: ok, good, so we can probably mark it fixed for good next cycle then [15:38] hopefully. i'm not 100% clear on how it'll work in practice [15:40] New bug: #968326 in lxc (universe) "lxc-execute tries to mount /dev/mqueue and is rejected by apparmor" [Medium,Fix committed] https://launchpad.net/bugs/968326 === Ursinha_ is now known as Guest92471 [15:44] stgraber: is that the only bug you're getting from lxc-execute? [15:48] hallyn: yep [16:07] hallyn, hey. -b in current lxc-create sets up an fstab that has "$homedir $homedir none bind 0 0" instead of "$homedir /var/lib/lxc/$container/rootfs/$homedir none bind 0 0". This doesn't seem to work. I'm about to file a bug, unless you stop me along the way. :-) [16:08] roaksoax: Hey, are you planning that rabbit upload? [16:09] roaksoax: we are now in thaw btw [16:11] gary_poster: why does it not work? that shoudl work [16:11] bug is good [16:12] cool hallyn, will give details [16:12] Daviey: already uploaded [16:12] roaksoax: awesome [16:13] hggdh: I need free machines to work on the fence_cdu issue you were seeing [16:15] roaksoax: we are upgrading aldebaran to the jenkins precise backport right now. When we are done, you can test it there (as long as you do not destroy the system ;-)) [16:15] hggdh: hehe I just need a couple of machines to 1. see what's going on. 2. work on a fix [16:16] hggdh: so, the cobbler server and 2 free machines not being used [16:16] to try to reproduce what you are seeing [16:16] roaksoax: deal [16:16] roaksoax: it will be aldebaran as the cobbler server, and alkaid and phact as the cannon fodder [16:17] hggdh: cool, just let me know when they are free [16:17] i'll work on it this afternoon [16:18] hallyn, a bot will announce it soon I'm sure, but I filed bug 968371. Running to lunch. [16:18] Launchpad bug 968371 in lxc "lxc-create -b is broken" [Undecided,New] https://launchpad.net/bugs/968371 [16:20] roaksoax: ack [16:26] New bug: #968371 in lxc (universe) "lxc-create -b is broken" [Undecided,New] https://launchpad.net/bugs/968371 [16:37] ha. [16:37] this is pretty awesome [16:37] http://www.erikyyy.de/invaders/ [16:37] download, extract, run: [16:37] kvm -kernel invaders === marrusl_ is now known as marrusl === koolhead17 is now known as bootlepy === bootlepy is now known as koolhead17 [17:19] Daviey, please let me know when you around, something important [17:19] to talk [17:19] help needed [17:50] hallyn, we are trying to decide whether to manually fix a one-off instance of our machinery and run some tests, or wait for the fixes (ubuntu template and lxc-start-ephemeral, I'm guessing) to bug 968371. (Note that we're also willing to help with that bug, but it sounded like you were working on it already.) Is this something we can hope to have fixed by, say, tomorrow; or will it be later? [17:50] Launchpad bug 968371 in lxc "lxc-create -b is broken" [High,Confirmed] https://launchpad.net/bugs/968371 [17:52] stgraber: ^ when is freeze to be lifted? [17:52] hallyn: it's [17:52] hallyn: I already uploaded lxc a few minutes ago with the lxc-execute fix [17:53] ok [17:53] gary_poster: i'd really like to finish digging into this libvirt bug, but i didn't realize you had a deadline. I can pusha fix by tomorrow morning at leatest [17:55] hallyn, thank you; like I said, I'm happy to help, and also, if you want to dig into libvirt and then do this, that's fine, but it will change our plans a bit. No biggie. Would Monday be a better goal for 968371? [17:56] do I make change in logrotate.d/rsyslog or some other file to make sure mail.log in always 644 ? [17:56] gary_poster: no let's plan on tomorrow. LIke I say i'ts just a matter of removing the leading '/' from the second field in fstab, so if you want to post a debdiff that'd be great; but i'll do it. (once i decide how best to do it in bash :) [17:57] gary_poster: really, I feel like I should re-write the lxc-start-ephemeral to be cleaner script (local vars, exit early if first part of pipline fails, etc). [17:58] heh, cool, thanks hallyn. And then we might need an ephemeral change too, right, for the lines that parse fstab? re-write: yeah, that sounds nice. If it fits in your schedule, and we still have some time to test and debug it before final freeze, sounds good [17:59] gary_poster: actually, [17:59] gary_poster: originall someone wanted lxc-start-ephemeral to work for non-root, [17:59] gary_poster, but some of the parsing being done now should make that fail. Do you care? [17:59] (i.e. 'while read line do < fstab.orig > fstab' type of stuff) [17:59] yeah, we talked about that [18:00] i hope you don't mean you and i [18:01] (just bc i have no recollection, and worry about my memory) [18:01] (no sorry, talked about it on our team.) I suspect it was me caring. I'm into it just working now. :-) We (our team) actually talked about proposing to rip all of the support for non-root for simplicity [18:01] We didn't do it, but would be fine with it now. [18:02] right, we should either fix it somehow, or do a check early on for id == 0 and fail cleanly if not [18:02] +1 [18:04] hallyn, so having the fix in tomorrow is plenty early for us, and much appreciated. Please ask us if you want us to work on it, and we'll be happy to, but by default we won't, and will leave it to you. [18:04] Can also do testing if that would be helpful [18:38] New bug: #968411 in nova (main) "[Precise] nova is vulnerable to CVE-2012-1585" [Medium,Confirmed] https://launchpad.net/bugs/968411 [18:39] adam_g: im looking to upload a newish keystone tomorrow === che3ver_ is now known as tcivyr [18:43] zul: with what? [18:44] adam_g: the one with the git clone stuff removed from the testusite [18:44] zul: please push to -proposed first, im going to be squashing some packaging bugs later today too [18:44] nova has a few, and id really like to get the quantum package installabel [18:44] adam_g: its already in there [18:44] k [19:02] New bug: #914164 in horizon (universe) "[MIR] horizon" [High,Incomplete] https://launchpad.net/bugs/914164 [19:12] does anyone know if the 12.04 focus on new hardware applies to ubuntu server? [19:13] absolutely [19:15] SpamapS, m_3: any opinion on whether I should spend some time FFe'ing/merging nodejs 0.6.x from debian for precise? [19:17] dork: was that a reply to me? [19:20] melter: yes [19:21] utlemming, need your help. [19:27] jamespage: don't really know what depends on the new version [19:28] m_3: nothing in the archive [19:28] jamespage: as a general rule, sure... but [19:28] but node seems to move along at a fair pace [19:30] jamespage: yup, I'm for it if you have tim [19:30] e [19:30] m_3: I'll push it all somewhere to see if it works [19:30] sure it will but... [19:32] utlemming, when you see this, please look at https://code.launchpad.net/~smoser/cloud-init/precise-locale-warning [19:32] it seems to function as designed, but then when i tried to get french error messages i failed. [19:33] ie, i set LC_ALL=fr_FR.UTF-8, and ssh'd in. [19:33] it gave me a friendly error message [19:34] i ran sudo localegen.... set LANG and LANGUAGE to fr_FR but then when i do somethin glike: ls asdf [19:34] the error message is english [19:34] wfm [19:53] utlemming, i assigned bug 859814 to you. [19:53] Launchpad bug 859814 in cloud-init "Locale issues with beta-1/2 cloud-images" [Medium,In progress] https://launchpad.net/bugs/859814 [19:53] i'd suggest starting from my branch and making sure that when you foloow the given directions it works. [19:55] zul: were you able to successfully run all keystone tests lately? [19:56] not since friday [19:56] are they broken again? [19:58] oh i see [19:59] zul: the ksc test cases target (and git checkout) 3 different keystoneclient branches [20:00] lovely.. [20:01] zul: we can just get rid of KcMasterTestCase + KcEssex3TestCase i think [20:01] ill look into after luch. bb in a few [20:01] adam_g: agreed [20:04] smoser: ack [20:05] jamespage: what is our delta for node where we can't just sync it? [20:05] i can' tseem to make it give me french error messages [20:06] smoser: do you have a paste of what your doing? [20:07] utlemming, well, not really. [20:07] :) [20:08] but the goal is to just launch instance [20:08] install new deb [20:08] exit [20:08] LC_ALL=some_other_lang ssh instance [20:08] see message, follow instructions [20:08] so this is interesting [20:08] exit [20:08] LC_ALL=some_other_lang ssh instance [20:08] ls asdf [20:08] if you have a proper locale generated and defined in the settings, then you get localized messages [20:08] see failed message in some othe rlanguage [20:09] if, however, any of your locales defined in LANG=? or LC_*=?, are bad, then you get english [20:09] i'm completley locale iillterate. [20:09] http://paste.ubuntu.com/906193/ [20:18] <_ruben> what determines the resolution of the console nowadays? (or on O actually) [20:18] <_ruben> got two boxes, installed in the same way, but they ended up with different resolutions [20:19] <_ruben> one of 'em might've had a monitor attached and the other not, during install === bladernr_ is now known as bladernr_afk [20:35] SpamapS, mainly tests - we get some different test failures/timeouts [20:35] jamespage: ugh === rickspencer3_ is now known as rickspencer3 [20:50] anyone here running maas from trunk? [20:53] maas? [20:54] assume that i want to learn juju, how could i do that? [20:59] jacobw: do you want to use juju, or write charms? [21:00] jacobw: if you want to simply use it, juju.ubuntu.com is pretty much the only spot for docs. [21:02] jacobw: the tutorial there is pretty good at explaining how things work. The other place you can look for stuff is on youtube. [21:04] utlemming, ok. you and i need to figure out how to do basic locale stuff [21:04] smoser: like? [21:04] ie, i want to see an error message that i dont undretsand. [21:04] how do you do that [21:05] * utlemming works on it [21:10] i was using 'ls' because i'm almost certain its "no such file or directory" is translated. [21:11] try apt [21:12] so it depends on the language. But I've exported "LC_ALL=fr_FR [21:12] and I get: [21:12] $ apt-get --fail-miserably-you-stupid-machine [21:12] E: L'option --fail-miserably-you-stupid-machine de la ligne de commande n'est pas reconnue [21:14] and the language pack is not installed. [21:15] After installing "language-pack-fr-base": [21:15] $ ls foo [21:15] ls: impossible d'acc�der � foo: Aucun fichier ou dossier de ce type [21:15] smoser: ^ [21:18] smoser: so the conclusion that we can draw here is 1) unless the appropriate language pack is installed, then errors messages are in english and 2) the default error language is english [21:41] Hey guys. Don't know if this is the best spot to ask but does anyone know how I can add a user to sudo-ldap who can execute all commands except certain ones, for example if I wanted to set a rule that allowed a user to execute all commands except /usr/bin/perl and /usr/bin/python, does anyone know how I would do that? [21:42] man sudoers [21:44] lifeless: you know sudo? Can you take a look at my questions and see if you have any suggestions related to my problem? [21:46] jetole: if they can execute "all commands except perl" , they can execute /bin/bash .. or /usr/bin/top .. and run other commands [21:47] jetole: consider defining the exact commands they can execute, and just let them do that [21:51] SpamapS: actually I can set these rules on normal sudo so they can execute all commands except the ones I specify and I can make it so they cannot execute other command from the command called by sudo. On normal sudo I can say define a command alias SHELLS and have it contain all the shells on the system and then I say the user rule is """user ALL=ALL, !SHELLS""" (without the quotes) and then I use the option noexec which makes it so if I try ... [21:51] ... to run anything from say top, or vim, etc that it will fail. Now I know how I can easily implement noexec with sudo-ldap but, it doesn't have aliases and there are some weird limitions with the order it processes rules so not sure how to do the first part === Jasonn is now known as juicy [22:09] jetole: heh.. sounds like complexity to me.. I'm like frankenstein with complexity.. COMPLEXITY BAD!!! [22:09] * SpamapS goes on a rampage [22:21] SpamapS: braaains....braiiins [22:23] zul, stop being a zombie, or i'll have to get my zombie-buster out === Jasonn is now known as juicy [22:25] wget -r is not showing sometimes layout and the links are always not working === jvdz_ is now known as jvdz [22:34] EvilResistance: do you call it 'Waitpid The Destroyer'? ;) [22:47] SpamapS: yeah it's actually pretty easy and basic sudo stuff typically but something is different in sudo-ldap and while I can't put my finger on it, someone will come by and say "oh you just do it like this" [22:47] ...and I will scream "why didn't I think of that?" [22:47] on that not I'm going home for the day. Later [23:12] hi all :) any network guru available for help/advice? [23:12] Aethor: best to just ask your question, and if somebody is around who can answer, they will [23:13] ok - ubuntu 11.10, trying to bond 2 NICs, and at the end of my wits - /etc/network/interfaces looks ok and yet it doesn't work [23:13] on network restart, I get a "RTNETLINK answers: File exist" error [23:13] and then "Failed to bring up bond0" [23:14] hello, im trying to configure a server here. it has a single IP and needs to run several lxc containers [23:14] so it needs to use a nat and internal bridge correct? [23:15] Juv1228: lxc containers can use nat, or bridged networking [23:16] SpamapS, but with a bridged networking they each have to have their own public ip right? [23:18] Juv1228: right, so you probably want NAT [23:18] to avoid that i am trying to setup a nat and use shorewall to firewall/forward things [23:19] the problem is none of my containers can reach the outside world [23:41] New bug: #968722 in rabbitmq-server (main) "/usr/sbin missing some wrappers for plugins/env" [Undecided,New] https://launchpad.net/bugs/968722 [23:50] That bug report is confusing [23:51] oh missing files, nevermind