/srv/irclogs.ubuntu.com/2012/04/03/#ubuntu-server.txt

=== fakhir_ is now known as fakhir
uvirtbotNew bug: #971981 in quantum (universe) "usptart and missing bin files" [Undecided,Fix released] https://launchpad.net/bugs/97198100:50
uvirtbotNew bug: #972019 in quantum (universe) "quantum-common missing /etc/quantum" [Undecided,Fix released] https://launchpad.net/bugs/97201900:50
uvirtbotNew bug: #960731 in quantum (universe) "Missing: quantum, quantum-server, python-quantum" [High,Fix released] https://launchpad.net/bugs/96073100:52
adrien2Hello01:17
adrien2I have reason to believe 5 or so people are attempting to hack my computer01:17
adrien2is there any recent security flaws in ubuntu 11.10?01:17
twbYes.01:17
adrien2I'm scared01:17
adrien2I logedd off from there though01:17
twbThen unplug all your computers and leave them off forever01:17
adrien2Why? I did nothing wrong01:18
twbThat's the only way to be safe01:18
adrien2You guys sure are helpful01:18
twbAlso run an angle-grinder through your hard disks01:18
adrien2what is your problem?01:18
twbMan, he was uptight.01:18
fyrfaktrylol01:18
twbI was just trying to give him some perspective.01:19
twbhttps://en.wikipedia.org/wiki/Computer_security offers some background theory01:27
twbAlso http://cwe.mitre.org/top25/01:33
CyberAlejo17Hello, someone speaks Spanish?01:47
virusuyCyberAlejo17: si01:59
CyberAlejo17Hola :) que gusto01:59
virusuy:-D01:59
CyberAlejo17será que puedes ayudarme con un pequeño problema que tengo en un server openvpn?01:59
CyberAlejo17mas precisamente en la configuracion de iptables con politica por defecto drop02:00
virusuyuy.. conozco poco de iptables02:00
CyberAlejo17mira mas info: http://www.ubuntu-es.org/node/16670002:00
twbCyberAlejo17: are you using ucf, or iptables directly?02:00
uvirtbotNew bug: #972043 in samba (main) "smbd crashed with SIGABRT in rep_strlcpy()" [Undecided,New] https://launchpad.net/bugs/97204302:00
CyberAlejo17ucf?02:01
twbucf is Ubuntu's wrapper around iptables02:02
twbhttp://cyber.com.au/~twb/doc/iptab is an example using iptables directly02:02
CyberAlejo17Estoy aplicando iptables directamente.02:03
CyberAlejo17Mediante un script.sh02:03
twbCyberAlejo17: please pastebin your script.sh02:04
twbAlso please read http://jengelh.medozas.de/documents/Perfect_Ruleset.pdf, and consider joining #netfilter (which is English only)02:05
=== dduffey_afk is now known as dduffey
CyberAlejo17ohhh, no tengo ahora acceso al servidor. No puedo hacer conexión mediante SSH, creo que quedó confgurado con DROP cuando salí.02:06
CyberAlejo17De esta forma no es mucho lo que se pueda hacer :(02:06
twbCyberAlejo17: I'm sorry to hear that.02:16
twbCyberAlejo17: ask me again, when you have access to your server.02:17
CyberAlejo17ok. Eso haré. Muchas gracias. Disculpa la molestia.02:20
stgraberhallyn: I pushed a very minor fix to ubuntu:lxc (won't upload just for that), just adds a missing space before the = sign of "lxc.network.hwaddr"02:22
stgraberhallyn: http://paste.ubuntu.com/912396/02:23
psusibug #919281 appears to be an iso spin error for the server iso... kernel modules are missing... what is the correct package that should be assigned to?02:43
uvirtbotLaunchpad bug 919281 in ubuntu "devmapper kernel modules missing from precise server cd" [Critical,Triaged] https://launchpad.net/bugs/91928102:43
=== tnachen_ is now known as tnachen
=== Jare_ is now known as Jare
=== bladernr_ is now known as bladernr_afk
HodgyI just installed Ubuntu Server 11.10 and I am accessing it from SSH, is there anything neat I could try out with it?04:58
FrozenFireFor some reason, on my gateway/router server running Ubuntu Server, the internal interface which is supposed to always be set to 192.168.0.1, dhclient is reconfiguring that interface with a DHCP address.05:06
FrozenFireThe interface is set to static in /etc/network/interfaces05:06
FrozenFireAnd I've even set supersede fixed-address 192.168.0.1 in dhclient.conf05:06
FrozenFireBut it keeps happening05:06
FrozenFireIt's getting frustrating as heck, because something's causing dhclient to reconfigure the interfaces on a regular basis05:07
FrozenFireAny ideas as to why?05:08
FrozenFirehttps://bugzilla.redhat.com/show_bug.cgi?id=556001 Essentially equivalent to this05:12
uvirtbotbugzilla.redhat.com bug 556001 in dhcp "dhclient sets wrong interface when the correct one is disconnected" [High,Closed: worksforme]05:12
RoyKhi all. I have two kvm nodes setup with ssh auth between them, both running oneiric. When I try to migrate this vm, it tells me http://paste.ubuntu.com/912552/ - source kvm host has been running for some weeks, dst host has just been rebooted for good measure06:06
RoyKoh, and after that attempt, the vm loses contact with its root device06:07
RoyKanyone awake?06:15
* RoyK += 0xc0ffee07:34
lynxmanmorning o/07:59
twbRoyK: surely you should XOR that08:01
RoyKtwb: heh08:06
jamespagemorning all08:10
twbWhat's nomodeset called in lucid?08:32
twbpost-install I want it to fuck off and stop loading a fuzzy, larger font than the 80x25 it starts with08:33
twbThat is, vga16fb08:33
twbFuck it, blacklisting it in modprobe.d works08:36
twbgrub-common has an update in lucid/updates, but grub-efi-amd64 doesn't -- WHY?  They're from the same source package.08:39
* smb chants iscsitarget into Daviey 's generic direction...08:46
Tm_Tlanguage ...08:50
_rubeniscsitarget as in iet? yuck :P08:52
twb_ruben: it's OK provided you remember to use a non-terminated BLACK goat08:53
_rubentwb: hehe09:02
twbOK, this is confusing.  lucid's grub-efi-amd64 says that it needs an EFI partition, and doesn't take a device.  The same program in precise, DOES take a device, and if you just do "grub-install /dev/sda" without an EFI partition on that device, it succeeds without output.  Looking at the partition table afterwards shows there is still no EFI partition.  WTF?09:09
* twb reboots to see if anything has changed09:09
twbrebooting makes it boot from the MBR still09:09
kokyuis anyone here (kind of) experienced with Ubuntu plus OpenStack?09:38
uksysadminkokyu: what do you need to know? dev support or end user help/09:39
kokyuI just installed 12.04 (daily build) and despite the fact, that OpenStack enabled during installation process, it did not succeed without telling me why, so I excluded it again, and did continue install09:39
kokyu(still writing my issue :-) )09:39
kokyunow, after install reboot, I see, that it actually has installed OpenStack, but SWIFT failed to start up, Compute (nova) seems to be running, at least when checking the process list.09:39
kokyuI am kind of new to both, Ubuntu (not Linux et al) and OpenStack, so I am a little confused on how to fix things now. is OpenStack now half or fully installed, or am I missing just some db configuration bits?09:40
kokyumaybe choosing 12.04 wasn't that a great idea, but this is going to be the next LTS and to be released in a few weeks, so I chose this one (also due to the recent kernel and userland :)09:41
kokyuuksysadmin: I kind of need someone to give me hints to get OpenStack initially running :)09:42
kokyuwe're currently using Proxmox 1.9 with OpenVZ, with LTS 8.04 and would like to switch to OpenStack for the new hardware with 12.04 LTS ideally09:42
kokyuand since OpenStack seems to be core part of Ubuntu now, it just seems ideal.09:43
uksysadminkokyu: check this out: http://uksysadmin.wordpress.com/2012/03/28/screencast-video-of-an-install-of-openstack-essex-on-ubuntu-12-04-under-virtualbox/09:45
kokyuoha, interesting. I'll watch that. many thanks so far ;)09:45
uvirtbotNew bug: #972268 in clamav (main) "clamscan crashed with SIGSEGV in pthread_cond_timedwait@@GLIBC_2.3.2()" [Undecided,New] https://launchpad.net/bugs/97226809:51
kokyuuksysadmin: thanks :)09:51
uksysadminnp kokyu - check out #openstack too - other guys can help you in there with OpenStack issues09:52
=== leonel2 is now known as leonel
kokyuuksysadmin: is your vimeo video guide really without sound, or is it my audio messing up right now?10:04
uksysadminah - sorry - I should put a message up - it is without sound10:05
* uksysadmin went for the 1900s silent movie genre ;-)10:05
kokyulol damn it, and I was searching for the issue locally :D10:05
uksysadminI'll update my blog. sorry! :S10:06
kokyunever mind, now that I now, I really apreciate ppl doing screencats, however, I can just encourage you to actually speak with it, it is really much more helpful with audio text :)10:07
kokyuuksysadmin: I also found this one, btw: http://www.hastexo.com/resources/docs/installing-openstack-essex-4-ubuntu-1204-precise-pangolin10:08
koolhead17uksysadmin: ^^10:09
uksysadminthat's a great tutorial too10:10
uksysadminand don't encourage koolhead17 to make me do a voice over10:10
uksysadmin;-)10:10
uksysadminThere are some great guides coming out now that accompany the documentation10:10
kokyuhehe10:10
koolhead17lol. you should definately do that man10:10
uksysadminok ok, I'll try and find some time to add some audio10:11
=== andol_ is now known as andol
sergevnhi10:25
uvirtbotNew bug: #972299 in ntp (main) "package ntp 1:4.2.6.p3+dfsg-1ubuntu3 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1" [Undecided,New] https://launchpad.net/bugs/97229910:31
ironm!daily10:45
ubottuDaily builds of the CD images of the current development version of Ubuntu are available at http://cdimage.ubuntu.com/daily/current/ and http://cdimage.ubuntu.com/daily-live/current/10:45
sergevnhi11:07
ironm!ubuntu-server+111:08
ironm!ubuntu-server11:08
ubottuUbuntu Server Edition is a release of Ubuntu designed especially for server environments, including a server specific !kernel and no !GUI. The install CD contains many server applications. Current !LTS version is !Lucid (Lucid Lynx 10.04) - More info: http://www.ubuntu.com/products/whatisubuntu/serveredition - Guide: https://help.ubuntu.com/10.04/serverguide/C/ - Support in #ubuntu-server11:08
hlanhello, I'm using the ppa ondrej/php5 because I need php 5.4 but php segfaults so I also need the debug symbols so I can do a gdb backtrace... how do I proceed?11:24
=== Brumle__ is now known as Brumle
ironmhello. Please allow me one question. I use XCP 1.5 (xen) as host and I can successfully install ubuntu-server 11.10 as VM but I am running in "CD-ROM mount" issue with ubuntu-server 12.04. Mor detals are in: xcp1.5-ubuntu-server12.04.error.txt11:58
ironmhttp://paste.debian.net/161870/11:58
ironmcan anyone confirm this issue? Thank you in advance for any hints.11:59
ironmwould be #ubuntu+1 channel better for the question above?12:02
aleinHi can I ask in the channel?12:18
uksysadminalein: I can't speak for everyone, but I'll let you. :p12:18
aleinOk thanks, I have one big problem with one of my servers. The problem is that some bad person make a huge ddos syn flood on port 80. That overload my server, http stop working and other services become slow and useless.12:20
ahxcjbyour front end firewalls should mitigate against syn floods12:21
aleinI don't talk about webserver flood - I mean tcp syn flood on port 8012:21
aleinI talk about 200Mbps syn flood traffic12:21
uksysadmin+1 on ahxcjb.12:22
aleinahxcjb what you mean? my ISP should stop the flood?12:22
rbasakalein: what's your question?12:22
uksysadminok, few solutions - set up your systems to not allow the creation of many syn connections without the full ack etc... firewall, ips.12:22
aleinhow to deffend myself12:22
uksysadminif its to port 80... another quick win - check out www.cloudflare.com and have your site live behind that12:23
ahxcjbset your front end firewall to mitigatge against the attack12:23
ahxcjbwhat is your front-end firewall?12:23
ahxcjbis it Ubuntu?12:23
rbasakEnabling syn cookies should protect against a plain syn flood12:23
aleinahxcjb iptables doesn't help at all12:23
ahxcjbhttp://www.lainoox.com/tag/syn-flood-iptables/12:23
ahxcjbalein: of course it does!12:24
aleinI can drop all the traffic and the server gets overloaded12:24
ahxcjbthen you're not doing it correctly12:24
aleinlol12:24
ahxcjbif you're getting a 200Mbps syn flood, you should involve your ISP12:24
aleiniptables -I INPUT -i eth0 -s 0.0.0.0/0 -j DROP12:24
patdk-wkhttp://www.symantec.com/connect/articles/hardening-tcpip-stack-syn-attacks12:24
ahxcjbwell that's just silly12:24
aleinthat doesn't help12:24
ahxcjbit doesn't help because you clearly haven't got clue12:25
* patdk-wk has never been syn flooded12:25
alein;)12:25
patdk-wkatleast not more than my server could handly by itself12:25
patdk-wkwithout adjustments12:25
patdk-wkpeople do love to do POST floods for some reason12:26
ahxcjbif you're suffering a major DoS you need to involve your ISP12:26
ahxcjbas they can mitigate against the flood far better than a home user can.12:26
aleinahxcjb I call them, wtite them a letter nad the answer was "We can't handle it"12:27
ahxcjbalein: then change ISPs12:27
aleinwrite*12:27
aleinits not that easy12:27
aleinso  http://www.lainoox.com/tag/syn-flood-iptables/ should help?12:27
ahxcjbI think if you are being hit by the size of DoS  that you state, then you have to involve your ISP12:28
ahxcjband if your ISP doesn't act, then MOVE ISP12:28
aleinI have 1gbps connection so they hardly can owerload my bandwith12:28
aleinbut that last flood was ugly12:28
ahxcjbif you have a 1gbps connection, then you're a fixed line user12:29
ahxcjband should have budget for proper firewalls12:29
ahxcjbwhich i suggest you purchase12:29
ahxcjbto allow you to mitigate against such attacks12:29
aleinNope, I don't have it12:29
ahxcjbthen how and why do you have a 1gbps connection? Are you a business?12:30
aleinNope, I'm not a business, I have little game server12:30
ahxcjbon 1gbps? pull the other one12:30
aleinjust have friends in that ISP and I have 1 Gbps12:30
ahxcjbso are you paying for this co-lo12:31
ahxcjb?12:31
aleinYes with 9 years work in that company12:31
patdk-wksound like a, I'll put it under my desk, deal12:31
aleinpossible SYN flooding on port 80. Sending cookies I sick of this12:32
dorkhow distributed is it12:36
=== scubes13 is now known as BEZ|Kevin
dorkare the bots leaving any sort of fingerprint in the access log?12:38
dorktry tarpit'ing the string of their client12:38
dorkhttp://www.spinics.net/lists/netfilter/msg17583.html12:38
dorkbut bottom line is anyone who runs a box and gets dos'd only mitigates and eventually contacts upstream carrier to filter12:39
dorkso do it the right way12:39
dorkand stop making excuses :)12:39
rbasakjamespage: I apt-get installed jenkins on oneiric, but it failed to start because /etc/init/jenkins.conf uses JAVA_HOME=/usr/lib/jvm/default-java which doesn't exist. Changing it to /usr/lib/jvm/java-6-openjdk fixed it. Is this a bug? Any idea why I don't have a /usr/lib/jvm/default-java?12:39
jamespagerbasak, bug 97195212:39
uvirtbotLaunchpad bug 971952 in jenkins "Java home not correct causes jenkins to crash at start" [Undecided,New] https://launchpad.net/bugs/97195212:39
rbasakthanks :)12:40
jamespagejenkins depends of default-jre-headless | java6-runtime-headless...12:40
jamespagerbasak, you can fix it bey installing default-jre-headless12:40
jamespageit works differently in precise so its an oneiric specific issue12:41
* jamespage wishes for good JAVA_HOME detection12:41
jamespagevirtually every server type package has this problem12:41
jamespagerbasak, hence things like bigtop-utils....12:42
ironmhello. Does anyone run ubuntu-server 12.04 on XCP 1.5 host? (free xen-server)12:42
rbasakjamespage: that worked - thanks!12:43
jamespagerbasak, its a PITA12:45
jamespagerbasak, BTW I've been backporting precise jenkins to ppa:hudson-ubuntu/backports if you want something a bit more up-to-date for the next few weeks12:46
rbasakjamespage: thanks, I'll use that if I find something I need that's missing12:47
=== bladernr_afk is now known as bladernr_
=== sergevn is now known as zz_sergevn
=== zz_sergevn is now known as sergevn
ironmhello. Anyone around running a kvm  based host on ubuntu-server 11.10 or 12.04? I am looking for some documentation about configuring and running kvm VMs14:08
SpamapSlynxman: pong, was out yesterday.14:10
SpamapSironm: https://help.ubuntu.com/8.04/serverguide/C/libvirt.html14:11
ironmthanks a lot SpamapS :)14:11
lynxmanSpamapS: hey I'm having some problems with the splice command, wanted to pick your brain for a bit :)14:12
SpamapShrm.. why does google insist on giving me the hardy docs? We need to setup a sitemap for help.ubuntu.com14:12
lynxmanSpamapS: http://pastebin.ubuntu.com/913051/ <-- already converted all the soft links to regular files, still errors14:12
SpamapSironm: https://help.ubuntu.com/11.10/serverguide/C/libvirt.html probably more current :)14:12
ironmSpamapS,  I will check this one too. Merci :)14:13
=== Gallomimia_ is now known as Gallomimia
SpamapSlynxman: hmm14:16
lynxmanSpamapS: easily reproducible, negronjl suggested me that soft links wouldn't work so I ran a small script to convert them14:18
lynxmanSpamapS: the error message is kinda confusing, that's why I wanted to ask you :)14:18
SpamapSlynxman: the logic looks a bit out of order14:18
lynxmanSpamapS: what would you suggest?14:19
lynxmanSpamapS: do the charms need to be in any special order?14:19
lynxmanSpamapS: even if I try to do one it's failing I'm afraid14:19
SpamapSlynxman: yeah I think the lack of tests for splice is showing. ;)14:20
lynxmanSpamapS: hah yeah :)14:20
koolhead17Daviey: around?14:20
SpamapSlynxman: I believe the simple fix is to add an os.mkdir before the proxy_relation calls14:20
lynxmanSpamapS: just create a silently failing os.mkdir before the proxy_relation call to create the dir if it doesn't exist?14:22
SpamapSlynxman: yeah, or perhaps move the make_hook calls before the proxy relation calls.14:24
SpamapS(they do a mkdir)14:25
lynxmanSpamapS: could you pass me a small diff so I know where to look at quickly? :)14:27
lynxmanSpamapS: ah neverminds scripts/splice14:28
lynxmanSpamapS: I've been too long doing ruby, almost forgot python now ;)14:29
lynxmanSpamapS: yeah that worked \o/14:31
SpamapSlynxman: I think its probably time that we merge splice into charm-tools14:32
lynxmanSpamapS: would be good, it's extremely useful14:32
SpamapSlynxman: still feels very experimental though.. hrm14:33
ironmSpamapS, I am wondering a bit, why virtinst has not been installed even I have chosen the host tasksel option (for kvm)14:35
SpamapSironm: dunno, I have to admit, my libvirt knowledge is pitiful, I usually just use virt-manager14:38
ironmSpamapS, wirt-manager hasn't been installed too14:40
SpamapSironm: its a GUI so thats no surprise14:40
ironmoh .. I see :)14:41
=== bladernr_ is now known as bladernr_afk
=== arthur__ is now known as Snowdog
=== BEZ|Kevin is now known as scubes13
hlanI'm trying to automate apt and I'm copying sources.list however that makes apt hang on /var/lib/dpkg/info/base-passwd.postinst15:01
hlanI guess some trust/security files must also be copied...  what more files do I need to copy except /etc/apt/sources.list15:02
hlan?15:02
SpamapShlan: what exactly are you trying to automate?15:02
SpamapShlan: sources.list would have nothing to do with /var/lib/dpkg/info/base-passwd.postinst ..15:03
SpamapShlan: if you want to create a new, tiny ubuntu, you want debootstrap, not apt15:03
hlanSpamapS: apt-get spawns that process and it waits for some kind of user prompt15:03
SpamapShlan: that process is the post install script for a package. dpkg is spawning it, not apt15:04
hlanSpamapS: what kind of information is it asking for?15:04
hlanit's trying to read from stdin15:04
hlanunfortunately I can't see stdout15:04
SpamapShlan: no idea, but if you want to not be prompted you can use export DEBIAN_FRONTEND=noninteractive15:05
SpamapShlan: it wil then choose defaults for all questions15:06
konradbhi, is it possible to make dist-upgrade without rebooting?15:09
=== lool- is now known as lool
NGNTNThi everybody15:24
konradbeverypony*15:24
NGNTNTcan anyone help me with my stucked-at-the-boot ubuntu server ?15:25
=== tobin is now known as Guest31547
NGNTNTnoone ?15:29
SpamapSNGNTNT: can you be more specific than "stuck at the boot" ?15:33
SpamapSkonradb: yes you can upgrade almost anything without rebooting.. notable exceptions are upstart and the kernel (though there is 'ksplice' for kernels, I don't know how stable it is)15:33
NGNTNTat the boot sequence the server goes to busybox prompt. The previouse lines said mounting /dev to /root/dev failed15:42
NGNTNTI tried to launch fsck booting from a live cd but nothing worked yet15:42
=== sergevn is now known as zz_sergevn
=== zz_sergevn is now known as sergevn
jamespageUrsinha,  http://reports.qa.ubuntu.com/reports/ubuntu-server/triage-report.html is looking better (if a little scary)15:44
Ursinhajamespage, is the data correct? I removed one constraint that was making that miss some bugs15:45
jamespageUrsinha, well I could see bugs moving through the queue so I think so15:45
jamespageUrsinha, ~260 New bugs was the scary bit (was 275 this morning :-))15:46
raubvogelDoes ubuntu now do disk alignment when partitioning hard drives?15:54
SpamapSUrsinha: thanks for fixing that15:55
SpamapSjamespage: and well done noticing it was wrong ;)15:55
Ursinhathanks guys for using it15:55
Ursinha:)15:55
jamespageUrsinha, makes my life easier (well it does now)15:55
* jamespage thinks we need to have a blitz on New bugs15:56
jamespageubuntu-server team meeting in #ubuntu-meeting about to start...16:01
ironmSpamapS, I used the following line to create VM. I am not sure if it is correct syntax. How can I connect to the install console?16:14
ironmvirt-install -n web70 -r 2048 --disk path=/dev/sdd -c /var/lib/libvirt/ubuntu-11.10-server-amd64.iso  --network network=default --connect=qemu:///system --graphics none -v16:14
ironm 10 web70                running16:15
uvirtbotNew bug: #972578 in rabbitmq-server (main) "rabbitmq-server 2.7.1-0ubuntu4 failed to start due to wrong directory owner" [Undecided,Invalid] https://launchpad.net/bugs/97257816:15
ironmhmm... : ironm@dev10:~$ virt-viewer --connect qemu:///system 1016:17
SpamapSironm: you're asking the wrong person. ;)16:20
SpamapShallyn: ^^ perhaps you can help ironm ?16:20
ironmok .. thanks a lot anyway SpamapS :)16:21
ironmit looks like the VM is running. I don't know how to connect to console using virt-viewer16:21
ironmconsole of this VM ...16:22
hallyni don't use virt-install.  but perhaps 'virsh console 10', if you have a serial console hooked up inthe guest16:23
ironmthank you hallyn  .. i will check it16:23
ironmhmm ... I am gettint the following output but nothing happen anymore and I am not able to type in  ...16:24
ironmConnected to domain web7016:24
ironmEscape character is ^]16:24
ironmhallyn, has the following line a correct syntax? virt-install -n web70 -r 2048 --disk path=/dev/sdd -c /var/lib/libvirt/ubuntu-11.10-server-amd64.iso  --network network=default --connect=qemu:///system --graphics none -v16:28
hallynironm: as I say I don't use virt-install.  looks fine based on what i know16:29
hallyni wonder if mdeslaur uses it...16:30
hallyni'll give it a whirl though16:30
ironmthanks a lot hallyn16:30
hallynlooks fine especiallly per https://help.ubuntu.com/11.10/serverguide/C/libvirt.html16:33
mdeslaurironm: I don't think you can connect to a virt-install console16:34
hallynironm: why exactly did you say --graphics=none?  if you do vnc, you'll get the console over vnc16:34
hallynwhich i think is what you need right now16:34
hallynit won't cause x to be installed16:34
mdeslaurironm: ah, I take it back, hallyn is right16:34
ironmhallyn, I am on console of the host (ssh)16:35
ironmit looks like I need a client with vnc ...16:36
hallynironm: i'm afraid we have terminology confusion.  'ssh' gives you a pty, fwiw.  'console' usually means a getty running on /dev/ttyX16:36
hallynright.  once it's all set up you can then ssh into the guest16:37
hallynvirsh console itself "works", but I dont' knwo if virtinst is setting /dev/ttyS0 up, nor do i think ubuntu server is setting it up16:37
hallynso virsh console gives nothing bc there is no getty running16:37
utlemmingkirkland: ping16:37
ironmhallyn, yes .. I thought it is possible to use an install console also from the KVM host16:37
hallyni don't know what you mean16:38
smoserkirkland, you see https://bugs.launchpad.net/ubuntu/+source/byobu/+bug/96668616:38
uvirtbotLaunchpad bug 966686 in byobu "byobu clears screen on login" [High,New]16:38
ironmhallyn, I try to follow you16:38
smoserRoyK, you were asserting somewhere that a cd install in a vm results in an empty console on server install, is that right?16:38
smosergah16:39
smosers/RoyK/RoakSoax/16:39
roaksoaxsmoser: i'm here16:39
smoserroaksoax, then look above. stupid caps change.16:40
smoseranyway16:40
roaksoaxlol16:40
roaksoaxsmoser: yeah, I've seen that issue16:40
smosercan you open a bug.16:40
smoserhallyn, ^16:40
roaksoaxsmoser: sure, let me test it again to confirm and will open a bug16:40
smoserand we should determine if thats vm only.16:40
roaksoaxk ;)16:41
hallynsmoser: eh what?16:42
hallynif you install a non-server iso without x, grub.conf still redirects you to vt7, which is empty.  is that what you're referring to?16:43
hallynit's not only in vms16:43
hallynyou can edit /etc/default/grub, or jsut hit alt-left to get a console16:43
smoserthis was server iso install16:43
smoserbut admittedly possibly via preseed and cobbler/maas16:43
hallynand what does /proc/cmdline show16:44
roaksoaxhallyn: yes16:44
roaksoaxhallyn: that's it, it shows a black screen with cursor, but changing ttys gives you the login prompt16:44
hallynI assume there is vt.handoff=7 in /proc/cmdline16:45
roaksoaxlet me check, doing a new install16:45
kirklandutlemming: howdy16:47
utlemmingkirkland: have you perchance seen my bug on byobu clearing the screen on login?16:48
utlemmingbug 96668616:48
uvirtbotLaunchpad bug 966686 in byobu "byobu clears screen on login" [High,New] https://launchpad.net/bugs/96668616:48
kirklandutlemming: yeah, haven't had time to look into that16:48
kirklandutlemming: is that a difference between tmux and screen, perhaps?16:48
kirklandutlemming: I think that's because the older byobu used the /usr/bin/byobu-shell to launch a shell16:49
kirklandutlemming: which cats the motd16:49
=== bladernr_afk is now known as bladernr_
utlemmingkirkland: yeah, the tmux version is the one that clears the screen16:50
kirklandutlemming: do you think this is release critical?16:54
kirklandutlemming: I reckon it is, since it removes the landscape commercial, huh?16:54
utlemmingkirkland: yes...we are putting some logic in to warn people of invalid or uninstalled locales. There is a problem with some packages where if LC_* variable are exported, the package may not installed.16:55
utlemmingkirkland: and it removes the blatant commerical advertising too16:55
kirklandutlemming: well, byobu is off by default now, so meh :-)16:55
utlemmingkirkland: hence the reason I filed it as "high" instead of critical. Although, the tmux version of byobu is pretty slick. I'm using it a whole lot more myself.16:56
kirklandutlemming: okay, I'll get that one fixed, please assign it to me, mark it triaged/high and milestone it appropriately16:56
kirklandutlemming: i *love* it ;-)16:56
kirklandutlemming: 1920x1080 with about ~6 splits usually16:56
kirklandutlemming: and rarely more than 1 window16:56
kirklandutlemming: okay, i'll get on that today16:56
utlemmingkirkland: thanks :) Marked triaged, assigned and targeted16:57
hallynroaksoax: i really don't know what's to be done about htat :)  unless we have the core x package do the appending of vthandoff line17:35
bobweaverDoes anyone know where to get this how much it costs . Is it real ? does it work on deb systems or only rpm ? ect   http://www.hepsia.com/ .Talk about bad advertising, All I can find is demo lol18:01
jamespageadam_g, around? want to discuss squid3?18:01
uvirtbotNew bug: #967887 in glance "Glance's auto-recovery of db connections is incompatible with newer sqlalchemy" [High,Fix released] https://launchpad.net/bugs/96788718:01
dexter76hello, on a fresh ubuntu 11.10 server virt-install raise "Could not find an installable distribution at" error whatever iso/http/ftp i give to the --location18:16
dexter76any ideas what to check?18:16
adam_gjamespage: sorry, lost in an email. yea18:20
adam_gjamespage: still around or did i miss you?18:21
kklimondahuh, it seems like idmapd doesn't start early enough on precise when used with autofs..18:40
kklimondaah, it's a different issue - my network doesn't start early enough so idmapd can't figure out the domain..18:42
kklimondabut that makes no sense18:42
imjustmatthewI'm having some trouble getting an upstart job to work right, is there an even fires when a DHCP lease is accepted?18:54
smoserhallyn, ping19:05
hallyn.19:05
KM0201!ping19:05
ubottuanother contentless ping... sigh...19:05
KM0201lol19:05
smoserhow would you boot a kvm instance with networking other than guest net19:06
smoserie, i'd like to use kvm without libvirt, but the only time i ever do something other than guest net is with libvirt19:06
hallynsmoser: hold on lemme pastebin what i do19:07
hallynsmoser: http://paste.ubuntu.com/913492/19:08
hallynor are you asking for libvirt xml to do that?19:09
smoserhallyn, thats what i wanted19:09
smoserminus...19:09
smoserhow do you get a network interface there19:09
hallynyou mean br0?19:09
smoserin the guest19:10
smoserstatic?19:10
hallyni dno't understand.  the cmds above will give you an eth0 in the guest19:10
smoserright.19:11
smoserbut how does it get an IP19:11
hallyndepends on how br0 is set up19:13
smoserah19:13
smoseri see19:13
smoserbr0 from libvirt ?19:13
hallynit should ping the same dhcp sever as your host does19:13
hallynor br0 that eth0 is slaved to19:14
smoserah.19:14
smoseryeah.19:14
smoseri need to provide it one then.19:14
smoserk.19:14
hallynor,19:14
hallynyou can set one in the guest by hadn i suppose, but it probably won't talk to the network right19:14
smoserhallyn, thanks.19:18
hallynnp19:20
hlanwill the log rotator process any log directly stored in /var/log ?19:34
hlanor just "syslogs"19:34
uvirtbotNew bug: #972786 in ipsec-tools (main) "racoon does not bind to interfaces brought up afterwards" [Undecided,New] https://launchpad.net/bugs/97278620:06
zuladam_g:  so novnc doesnt have tarballs per say, like release tarballs, so i think we should be doing another snapshot with the horizon patches applied20:29
aleinhi all20:30
aleinI would like to ask, is there any way to catch NULL TCP packets with tcpdump?20:30
=== ajmitch_ is now known as ajmitch
RoyKalein: "Null Packets are neither sent nor acknowledged when not received."21:02
RoyK2.1. Formal Definition21:04
RoyK[This section is intentionally left blank, see also Section 0 of [NULL].]21:04
* RoyK loves april fool RFCs :D21:05
aleinRoyK I'm trying to catch the true ip address of spoofed syn flood attack.21:05
aleinCan I do this with tcpdump and wireshark21:05
RoyKhow do you want to catch the real IP when it's spoofed?21:06
RoyKspoofed means it's overwritten21:06
uvirtbotNew bug: #972845 in tftp-hpa (main) "after upgrade to precise, service did not start" [Undecided,New] https://launchpad.net/bugs/97284521:06
RoyKand the routers don't track what they do21:07
aleinThe only way to detect default ip is to looking for NULL TCP packets (meaning no TCP flags set) with destination ports of 0.21:07
aleinbut I'm not sure that I can do this with tcpdump or only with an intrusion-detection system21:09
RoyKalein: what should generate that null packet, then?21:21
aleinmeaning no TCP flags set21:21
zuladam_g: we 600 the keystone config files dont we?21:21
adam_gzul: keystone.conf, yeah, we should21:23
adam_gzul: also, /var/lib/keystone/keystone.db if it exists21:24
zulk21:24
=== Jasonn is now known as juicy
rmkAlright so the Ubuntu dhcp client seems to just give up and die if the dhcp server is down during the time a request is bad..22:09
rmks/bad/made22:09
=== sergevn is now known as zz_sergevn
=== zz_sergevn is now known as sergevn
uvirtbotNew bug: #950942 in glance (main) "glance-registry upstart should also include 'started' for mysql/pgsql" [Low,Invalid] https://launchpad.net/bugs/95094222:32
rmkSo, when we lose our dhcp server, our dhclient process retries for about a minute then exits rather than sleeping.  Ubuntu 11.10 64-bit server.  Is this expected behavior and is there a way to change that?23:15
rmkI can obviously script aorund it but I figure there has to be a cleaner way.23:15
jiboumans_hi smoser, just tried to launch a new ami (ami-37af765e) in us-east-1a and cloud-init exited with code 1. Using the slightly older ami-3e9b4957 everythings works just dandy. figured you'd want to know.23:16
dorkit is expected behavior because it's assuming you chose the wrong interface, meant to provision a static ip, etc23:20
dorkjust hit go back and do it again23:20
smoserjiboumans_, i suspect mirror issues. but will give a quick check.23:22
smoserhm.. i dont know of ami-37af765e23:22
jiboumans_http://uec-images.ubuntu.com/query/lucid/server/released.current.txt23:22
jiboumans_smoser: it's listed there ^23:22
smoserah. k.  my cache was just out of date23:23
jiboumans_smoser: this is the last bits in the syslog: https://gist.github.com/229626223:23
smoserwell, i can't be sure why your pupet died.23:23
dorkrmk: oh nevermind thought you meant during installation23:23
smoserperhaps it could not reach the master ?23:23
rmkno I need it to retry forever23:24
dorkrmk: try dhclienf.conf23:24
jiboumans_smoser: possibly, but it left the ami in a non-good state and appeared to exit the run.23:24
dorkdhclient.conf23:24
jiboumans_am i seeing that wrong?23:24
dorklooks like the params are in there23:24
jiboumans_there was no /etc/puppet generated for example23:25
smoserjiboumans_, console output (get-console-output) is more helopful. it will have more info. i suspect it has a apt-get update failre.23:26
smoserbut there will probably be something meaningful to you there.23:26
jiboumans_smoser: i've scrapped the instance, but happy to respin one if it helps you diagnose23:26
smoser(and note, in later releases, you should set23:26
smoser output: {all: '| tee -a /var/log/cloud-init-output.log'}23:26
smoseryou have access to the instance up to 1 hour after termination23:26
smoserjiboumans_, so above, then you'll have everything that output by cloud-inti or subprocess in that log file.23:27
smoserjust easier to get at thene console23:28
jiboumans_smoser: i don't seem to be able to start it up again from the console though.. am i missing something?23:28
jiboumans_thanks, adding that to our start up script23:28
smoseryou cant start it up again23:28
smoserbut at least from the tools, you'll be able to get console output23:28
smoserits just stored for 1 hour.23:28
smoserie, euca-get-console-output <i-iabababab>23:29
jiboumans_checking23:30
jiboumans_smoser: you're right. updated the gist: https://gist.github.com/229631223:31
jiboumans_W: Failed to fetch http://us-east-1.ec2.archive.ubuntu.com/ubuntu/dists/lucid-updates/main/source/Sources.bz2  Hash Sum mismatch23:31
smoserjiboumans_, you  might be a good candidate for our s3 mirrors.23:31
jiboumans_smoser: i'm listening :)23:32
smoserwhich (given disabled apt pipelining , which is current in daily images, or anything with up to date cloud-init)23:32
smosershould be more stable.23:32
smoserwe'll have offically released amis later this week that have the optoin already disabled inside them23:32
utlemmingsmoser, jiboumans_: lucid was officially released today with the update23:33
smoserbut you can either laucnh the daily, or set the option in apt yourselfbefore update.23:33
jiboumans_sorry, you mean that new images will use the s3 mirror by default?23:33
smoserjiboumans_, so there ya go.23:33
smoserjiboumans_, no, htye use the other mirrors. but you can tell them fairly easily to use the s323:33
smoserutlemming, can tell you how23:33
utlemmingrun 'sed -i "s,ec2.archive.ubuntu.com,ec2.archive.ubuntu.com.s3.amazonaws.com,g" /etc/apt/sources.list'23:34
jiboumans_then i didn't quite follow; what's the apt-pipelining option? I see the lp repo, but not the rationale behind it23:34
utlemmingAPT uses a micro-enhancement (HTTP Pipelining) to eak out a few microseconds of performance. S3, well, it doesn't get along with pipelining. If you disable apt's pipelining, then S3 works well.23:36
jiboumans_ah, that makes sense23:36
jiboumans_utlemming/smoser: is the s3 apt repo code viewable somewhere? it's on my bucket list to do that internally for our own apt repo too23:37
utlemmingyup... lp:s3aptmirror23:38
jiboumans_thanks utlemming smoser, very helpful :)23:39
smoserutlemming, could you open an RT about the apt mirror issue23:43
smoserutlemming, oh, its the stale issue23:47

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!