=== fakhir_ is now known as fakhir [00:50] New bug: #971981 in quantum (universe) "usptart and missing bin files" [Undecided,Fix released] https://launchpad.net/bugs/971981 [00:50] New bug: #972019 in quantum (universe) "quantum-common missing /etc/quantum" [Undecided,Fix released] https://launchpad.net/bugs/972019 [00:52] New bug: #960731 in quantum (universe) "Missing: quantum, quantum-server, python-quantum" [High,Fix released] https://launchpad.net/bugs/960731 [01:17] Hello [01:17] I have reason to believe 5 or so people are attempting to hack my computer [01:17] is there any recent security flaws in ubuntu 11.10? [01:17] Yes. [01:17] I'm scared [01:17] I logedd off from there though [01:17] Then unplug all your computers and leave them off forever [01:18] Why? I did nothing wrong [01:18] That's the only way to be safe [01:18] You guys sure are helpful [01:18] Also run an angle-grinder through your hard disks [01:18] what is your problem? [01:18] Man, he was uptight. [01:18] lol [01:19] I was just trying to give him some perspective. [01:27] https://en.wikipedia.org/wiki/Computer_security offers some background theory [01:33] Also http://cwe.mitre.org/top25/ [01:47] Hello, someone speaks Spanish? [01:59] CyberAlejo17: si [01:59] Hola :) que gusto [01:59] :-D [01:59] será que puedes ayudarme con un pequeño problema que tengo en un server openvpn? [02:00] mas precisamente en la configuracion de iptables con politica por defecto drop [02:00] uy.. conozco poco de iptables [02:00] mira mas info: http://www.ubuntu-es.org/node/166700 [02:00] CyberAlejo17: are you using ucf, or iptables directly? [02:00] New bug: #972043 in samba (main) "smbd crashed with SIGABRT in rep_strlcpy()" [Undecided,New] https://launchpad.net/bugs/972043 [02:01] ucf? [02:02] ucf is Ubuntu's wrapper around iptables [02:02] http://cyber.com.au/~twb/doc/iptab is an example using iptables directly [02:03] Estoy aplicando iptables directamente. [02:03] Mediante un script.sh [02:04] CyberAlejo17: please pastebin your script.sh [02:05] Also please read http://jengelh.medozas.de/documents/Perfect_Ruleset.pdf, and consider joining #netfilter (which is English only) === dduffey_afk is now known as dduffey [02:06] ohhh, no tengo ahora acceso al servidor. No puedo hacer conexión mediante SSH, creo que quedó confgurado con DROP cuando salí. [02:06] De esta forma no es mucho lo que se pueda hacer :( [02:16] CyberAlejo17: I'm sorry to hear that. [02:17] CyberAlejo17: ask me again, when you have access to your server. [02:20] ok. Eso haré. Muchas gracias. Disculpa la molestia. [02:22] hallyn: I pushed a very minor fix to ubuntu:lxc (won't upload just for that), just adds a missing space before the = sign of "lxc.network.hwaddr" [02:23] hallyn: http://paste.ubuntu.com/912396/ [02:43] bug #919281 appears to be an iso spin error for the server iso... kernel modules are missing... what is the correct package that should be assigned to? [02:43] Launchpad bug 919281 in ubuntu "devmapper kernel modules missing from precise server cd" [Critical,Triaged] https://launchpad.net/bugs/919281 === tnachen_ is now known as tnachen === Jare_ is now known as Jare === bladernr_ is now known as bladernr_afk [04:58] I just installed Ubuntu Server 11.10 and I am accessing it from SSH, is there anything neat I could try out with it? [05:06] For some reason, on my gateway/router server running Ubuntu Server, the internal interface which is supposed to always be set to 192.168.0.1, dhclient is reconfiguring that interface with a DHCP address. [05:06] The interface is set to static in /etc/network/interfaces [05:06] And I've even set supersede fixed-address 192.168.0.1 in dhclient.conf [05:06] But it keeps happening [05:07] It's getting frustrating as heck, because something's causing dhclient to reconfigure the interfaces on a regular basis [05:08] Any ideas as to why? [05:12] https://bugzilla.redhat.com/show_bug.cgi?id=556001 Essentially equivalent to this [05:12] bugzilla.redhat.com bug 556001 in dhcp "dhclient sets wrong interface when the correct one is disconnected" [High,Closed: worksforme] [06:06] hi all. I have two kvm nodes setup with ssh auth between them, both running oneiric. When I try to migrate this vm, it tells me http://paste.ubuntu.com/912552/ - source kvm host has been running for some weeks, dst host has just been rebooted for good measure [06:07] oh, and after that attempt, the vm loses contact with its root device [06:15] anyone awake? [07:34] * RoyK += 0xc0ffee [07:59] morning o/ [08:01] RoyK: surely you should XOR that [08:06] twb: heh [08:10] morning all [08:32] What's nomodeset called in lucid? [08:33] post-install I want it to fuck off and stop loading a fuzzy, larger font than the 80x25 it starts with [08:33] That is, vga16fb [08:36] Fuck it, blacklisting it in modprobe.d works [08:39] grub-common has an update in lucid/updates, but grub-efi-amd64 doesn't -- WHY? They're from the same source package. [08:46] * smb chants iscsitarget into Daviey 's generic direction... [08:50] language ... [08:52] <_ruben> iscsitarget as in iet? yuck :P [08:53] _ruben: it's OK provided you remember to use a non-terminated BLACK goat [09:02] <_ruben> twb: hehe [09:09] OK, this is confusing. lucid's grub-efi-amd64 says that it needs an EFI partition, and doesn't take a device. The same program in precise, DOES take a device, and if you just do "grub-install /dev/sda" without an EFI partition on that device, it succeeds without output. Looking at the partition table afterwards shows there is still no EFI partition. WTF? [09:09] * twb reboots to see if anything has changed [09:09] rebooting makes it boot from the MBR still [09:38] is anyone here (kind of) experienced with Ubuntu plus OpenStack? [09:39] kokyu: what do you need to know? dev support or end user help/ [09:39] I just installed 12.04 (daily build) and despite the fact, that OpenStack enabled during installation process, it did not succeed without telling me why, so I excluded it again, and did continue install [09:39] (still writing my issue :-) ) [09:39] now, after install reboot, I see, that it actually has installed OpenStack, but SWIFT failed to start up, Compute (nova) seems to be running, at least when checking the process list. [09:40] I am kind of new to both, Ubuntu (not Linux et al) and OpenStack, so I am a little confused on how to fix things now. is OpenStack now half or fully installed, or am I missing just some db configuration bits? [09:41] maybe choosing 12.04 wasn't that a great idea, but this is going to be the next LTS and to be released in a few weeks, so I chose this one (also due to the recent kernel and userland :) [09:42] uksysadmin: I kind of need someone to give me hints to get OpenStack initially running :) [09:42] we're currently using Proxmox 1.9 with OpenVZ, with LTS 8.04 and would like to switch to OpenStack for the new hardware with 12.04 LTS ideally [09:43] and since OpenStack seems to be core part of Ubuntu now, it just seems ideal. [09:45] kokyu: check this out: http://uksysadmin.wordpress.com/2012/03/28/screencast-video-of-an-install-of-openstack-essex-on-ubuntu-12-04-under-virtualbox/ [09:45] oha, interesting. I'll watch that. many thanks so far ;) [09:51] New bug: #972268 in clamav (main) "clamscan crashed with SIGSEGV in pthread_cond_timedwait@@GLIBC_2.3.2()" [Undecided,New] https://launchpad.net/bugs/972268 [09:51] uksysadmin: thanks :) [09:52] np kokyu - check out #openstack too - other guys can help you in there with OpenStack issues === leonel2 is now known as leonel [10:04] uksysadmin: is your vimeo video guide really without sound, or is it my audio messing up right now? [10:05] ah - sorry - I should put a message up - it is without sound [10:05] * uksysadmin went for the 1900s silent movie genre ;-) [10:05] lol damn it, and I was searching for the issue locally :D [10:06] I'll update my blog. sorry! :S [10:07] never mind, now that I now, I really apreciate ppl doing screencats, however, I can just encourage you to actually speak with it, it is really much more helpful with audio text :) [10:08] uksysadmin: I also found this one, btw: http://www.hastexo.com/resources/docs/installing-openstack-essex-4-ubuntu-1204-precise-pangolin [10:09] uksysadmin: ^^ [10:10] that's a great tutorial too [10:10] and don't encourage koolhead17 to make me do a voice over [10:10] ;-) [10:10] There are some great guides coming out now that accompany the documentation [10:10] hehe [10:10] lol. you should definately do that man [10:11] ok ok, I'll try and find some time to add some audio === andol_ is now known as andol [10:25] hi [10:31] New bug: #972299 in ntp (main) "package ntp 1:4.2.6.p3+dfsg-1ubuntu3 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1" [Undecided,New] https://launchpad.net/bugs/972299 [10:45] !daily [10:45] Daily builds of the CD images of the current development version of Ubuntu are available at http://cdimage.ubuntu.com/daily/current/ and http://cdimage.ubuntu.com/daily-live/current/ [11:07] hi [11:08] !ubuntu-server+1 [11:08] !ubuntu-server [11:08] Ubuntu Server Edition is a release of Ubuntu designed especially for server environments, including a server specific !kernel and no !GUI. The install CD contains many server applications. Current !LTS version is !Lucid (Lucid Lynx 10.04) - More info: http://www.ubuntu.com/products/whatisubuntu/serveredition - Guide: https://help.ubuntu.com/10.04/serverguide/C/ - Support in #ubuntu-server [11:24] hello, I'm using the ppa ondrej/php5 because I need php 5.4 but php segfaults so I also need the debug symbols so I can do a gdb backtrace... how do I proceed? === Brumle__ is now known as Brumle [11:58] hello. Please allow me one question. I use XCP 1.5 (xen) as host and I can successfully install ubuntu-server 11.10 as VM but I am running in "CD-ROM mount" issue with ubuntu-server 12.04. Mor detals are in: xcp1.5-ubuntu-server12.04.error.txt [11:58] http://paste.debian.net/161870/ [11:59] can anyone confirm this issue? Thank you in advance for any hints. [12:02] would be #ubuntu+1 channel better for the question above? [12:18] Hi can I ask in the channel? [12:18] alein: I can't speak for everyone, but I'll let you. :p [12:20] Ok thanks, I have one big problem with one of my servers. The problem is that some bad person make a huge ddos syn flood on port 80. That overload my server, http stop working and other services become slow and useless. [12:21] your front end firewalls should mitigate against syn floods [12:21] I don't talk about webserver flood - I mean tcp syn flood on port 80 [12:21] I talk about 200Mbps syn flood traffic [12:22] +1 on ahxcjb. [12:22] ahxcjb what you mean? my ISP should stop the flood? [12:22] alein: what's your question? [12:22] ok, few solutions - set up your systems to not allow the creation of many syn connections without the full ack etc... firewall, ips. [12:22] how to deffend myself [12:23] if its to port 80... another quick win - check out www.cloudflare.com and have your site live behind that [12:23] set your front end firewall to mitigatge against the attack [12:23] what is your front-end firewall? [12:23] is it Ubuntu? [12:23] Enabling syn cookies should protect against a plain syn flood [12:23] ahxcjb iptables doesn't help at all [12:23] http://www.lainoox.com/tag/syn-flood-iptables/ [12:24] alein: of course it does! [12:24] I can drop all the traffic and the server gets overloaded [12:24] then you're not doing it correctly [12:24] lol [12:24] if you're getting a 200Mbps syn flood, you should involve your ISP [12:24] iptables -I INPUT -i eth0 -s 0.0.0.0/0 -j DROP [12:24] http://www.symantec.com/connect/articles/hardening-tcpip-stack-syn-attacks [12:24] well that's just silly [12:24] that doesn't help [12:25] it doesn't help because you clearly haven't got clue [12:25] * patdk-wk has never been syn flooded [12:25] ;) [12:25] atleast not more than my server could handly by itself [12:25] without adjustments [12:26] people do love to do POST floods for some reason [12:26] if you're suffering a major DoS you need to involve your ISP [12:26] as they can mitigate against the flood far better than a home user can. [12:27] ahxcjb I call them, wtite them a letter nad the answer was "We can't handle it" [12:27] alein: then change ISPs [12:27] write* [12:27] its not that easy [12:27] so http://www.lainoox.com/tag/syn-flood-iptables/ should help? [12:28] I think if you are being hit by the size of DoS that you state, then you have to involve your ISP [12:28] and if your ISP doesn't act, then MOVE ISP [12:28] I have 1gbps connection so they hardly can owerload my bandwith [12:28] but that last flood was ugly [12:29] if you have a 1gbps connection, then you're a fixed line user [12:29] and should have budget for proper firewalls [12:29] which i suggest you purchase [12:29] to allow you to mitigate against such attacks [12:29] Nope, I don't have it [12:30] then how and why do you have a 1gbps connection? Are you a business? [12:30] Nope, I'm not a business, I have little game server [12:30] on 1gbps? pull the other one [12:30] just have friends in that ISP and I have 1 Gbps [12:31] so are you paying for this co-lo [12:31] ? [12:31] Yes with 9 years work in that company [12:31] sound like a, I'll put it under my desk, deal [12:32] possible SYN flooding on port 80. Sending cookies I sick of this [12:36] how distributed is it === scubes13 is now known as BEZ|Kevin [12:38] are the bots leaving any sort of fingerprint in the access log? [12:38] try tarpit'ing the string of their client [12:38] http://www.spinics.net/lists/netfilter/msg17583.html [12:39] but bottom line is anyone who runs a box and gets dos'd only mitigates and eventually contacts upstream carrier to filter [12:39] so do it the right way [12:39] and stop making excuses :) [12:39] jamespage: I apt-get installed jenkins on oneiric, but it failed to start because /etc/init/jenkins.conf uses JAVA_HOME=/usr/lib/jvm/default-java which doesn't exist. Changing it to /usr/lib/jvm/java-6-openjdk fixed it. Is this a bug? Any idea why I don't have a /usr/lib/jvm/default-java? [12:39] rbasak, bug 971952 [12:39] Launchpad bug 971952 in jenkins "Java home not correct causes jenkins to crash at start" [Undecided,New] https://launchpad.net/bugs/971952 [12:40] thanks :) [12:40] jenkins depends of default-jre-headless | java6-runtime-headless... [12:40] rbasak, you can fix it bey installing default-jre-headless [12:41] it works differently in precise so its an oneiric specific issue [12:41] * jamespage wishes for good JAVA_HOME detection [12:41] virtually every server type package has this problem [12:42] rbasak, hence things like bigtop-utils.... [12:42] hello. Does anyone run ubuntu-server 12.04 on XCP 1.5 host? (free xen-server) [12:43] jamespage: that worked - thanks! [12:45] rbasak, its a PITA [12:46] rbasak, BTW I've been backporting precise jenkins to ppa:hudson-ubuntu/backports if you want something a bit more up-to-date for the next few weeks [12:47] jamespage: thanks, I'll use that if I find something I need that's missing === bladernr_afk is now known as bladernr_ === sergevn is now known as zz_sergevn === zz_sergevn is now known as sergevn [14:08] hello. Anyone around running a kvm based host on ubuntu-server 11.10 or 12.04? I am looking for some documentation about configuring and running kvm VMs [14:10] lynxman: pong, was out yesterday. [14:11] ironm: https://help.ubuntu.com/8.04/serverguide/C/libvirt.html [14:11] thanks a lot SpamapS :) [14:12] SpamapS: hey I'm having some problems with the splice command, wanted to pick your brain for a bit :) [14:12] hrm.. why does google insist on giving me the hardy docs? We need to setup a sitemap for help.ubuntu.com [14:12] SpamapS: http://pastebin.ubuntu.com/913051/ <-- already converted all the soft links to regular files, still errors [14:12] ironm: https://help.ubuntu.com/11.10/serverguide/C/libvirt.html probably more current :) [14:13] SpamapS, I will check this one too. Merci :) === Gallomimia_ is now known as Gallomimia [14:16] lynxman: hmm [14:18] SpamapS: easily reproducible, negronjl suggested me that soft links wouldn't work so I ran a small script to convert them [14:18] SpamapS: the error message is kinda confusing, that's why I wanted to ask you :) [14:18] lynxman: the logic looks a bit out of order [14:19] SpamapS: what would you suggest? [14:19] SpamapS: do the charms need to be in any special order? [14:19] SpamapS: even if I try to do one it's failing I'm afraid [14:20] lynxman: yeah I think the lack of tests for splice is showing. ;) [14:20] SpamapS: hah yeah :) [14:20] Daviey: around? [14:20] lynxman: I believe the simple fix is to add an os.mkdir before the proxy_relation calls [14:22] SpamapS: just create a silently failing os.mkdir before the proxy_relation call to create the dir if it doesn't exist? [14:24] lynxman: yeah, or perhaps move the make_hook calls before the proxy relation calls. [14:25] (they do a mkdir) [14:27] SpamapS: could you pass me a small diff so I know where to look at quickly? :) [14:28] SpamapS: ah neverminds scripts/splice [14:29] SpamapS: I've been too long doing ruby, almost forgot python now ;) [14:31] SpamapS: yeah that worked \o/ [14:32] lynxman: I think its probably time that we merge splice into charm-tools [14:32] SpamapS: would be good, it's extremely useful [14:33] lynxman: still feels very experimental though.. hrm [14:35] SpamapS, I am wondering a bit, why virtinst has not been installed even I have chosen the host tasksel option (for kvm) [14:38] ironm: dunno, I have to admit, my libvirt knowledge is pitiful, I usually just use virt-manager [14:40] SpamapS, wirt-manager hasn't been installed too [14:40] ironm: its a GUI so thats no surprise [14:41] oh .. I see :) === bladernr_ is now known as bladernr_afk === arthur__ is now known as Snowdog === BEZ|Kevin is now known as scubes13 [15:01] I'm trying to automate apt and I'm copying sources.list however that makes apt hang on /var/lib/dpkg/info/base-passwd.postinst [15:02] I guess some trust/security files must also be copied... what more files do I need to copy except /etc/apt/sources.list [15:02] ? [15:02] hlan: what exactly are you trying to automate? [15:03] hlan: sources.list would have nothing to do with /var/lib/dpkg/info/base-passwd.postinst .. [15:03] hlan: if you want to create a new, tiny ubuntu, you want debootstrap, not apt [15:03] SpamapS: apt-get spawns that process and it waits for some kind of user prompt [15:04] hlan: that process is the post install script for a package. dpkg is spawning it, not apt [15:04] SpamapS: what kind of information is it asking for? [15:04] it's trying to read from stdin [15:04] unfortunately I can't see stdout [15:05] hlan: no idea, but if you want to not be prompted you can use export DEBIAN_FRONTEND=noninteractive [15:06] hlan: it wil then choose defaults for all questions [15:09] hi, is it possible to make dist-upgrade without rebooting? === lool- is now known as lool [15:24] hi everybody [15:24] everypony* [15:25] can anyone help me with my stucked-at-the-boot ubuntu server ? === tobin is now known as Guest31547 [15:29] noone ? [15:33] NGNTNT: can you be more specific than "stuck at the boot" ? [15:33] konradb: yes you can upgrade almost anything without rebooting.. notable exceptions are upstart and the kernel (though there is 'ksplice' for kernels, I don't know how stable it is) [15:42] at the boot sequence the server goes to busybox prompt. The previouse lines said mounting /dev to /root/dev failed [15:42] I tried to launch fsck booting from a live cd but nothing worked yet === sergevn is now known as zz_sergevn === zz_sergevn is now known as sergevn [15:44] Ursinha, http://reports.qa.ubuntu.com/reports/ubuntu-server/triage-report.html is looking better (if a little scary) [15:45] jamespage, is the data correct? I removed one constraint that was making that miss some bugs [15:45] Ursinha, well I could see bugs moving through the queue so I think so [15:46] Ursinha, ~260 New bugs was the scary bit (was 275 this morning :-)) [15:54] Does ubuntu now do disk alignment when partitioning hard drives? [15:55] Ursinha: thanks for fixing that [15:55] jamespage: and well done noticing it was wrong ;) [15:55] thanks guys for using it [15:55] :) [15:55] Ursinha, makes my life easier (well it does now) [15:56] * jamespage thinks we need to have a blitz on New bugs [16:01] ubuntu-server team meeting in #ubuntu-meeting about to start... [16:14] SpamapS, I used the following line to create VM. I am not sure if it is correct syntax. How can I connect to the install console? [16:14] virt-install -n web70 -r 2048 --disk path=/dev/sdd -c /var/lib/libvirt/ubuntu-11.10-server-amd64.iso --network network=default --connect=qemu:///system --graphics none -v [16:15] 10 web70 running [16:15] New bug: #972578 in rabbitmq-server (main) "rabbitmq-server 2.7.1-0ubuntu4 failed to start due to wrong directory owner" [Undecided,Invalid] https://launchpad.net/bugs/972578 [16:17] hmm... : ironm@dev10:~$ virt-viewer --connect qemu:///system 10 [16:20] ironm: you're asking the wrong person. ;) [16:20] hallyn: ^^ perhaps you can help ironm ? [16:21] ok .. thanks a lot anyway SpamapS :) [16:21] it looks like the VM is running. I don't know how to connect to console using virt-viewer [16:22] console of this VM ... [16:23] i don't use virt-install. but perhaps 'virsh console 10', if you have a serial console hooked up inthe guest [16:23] thank you hallyn .. i will check it [16:24] hmm ... I am gettint the following output but nothing happen anymore and I am not able to type in ... [16:24] Connected to domain web70 [16:24] Escape character is ^] [16:28] hallyn, has the following line a correct syntax? virt-install -n web70 -r 2048 --disk path=/dev/sdd -c /var/lib/libvirt/ubuntu-11.10-server-amd64.iso --network network=default --connect=qemu:///system --graphics none -v [16:29] ironm: as I say I don't use virt-install. looks fine based on what i know [16:30] i wonder if mdeslaur uses it... [16:30] i'll give it a whirl though [16:30] thanks a lot hallyn [16:33] looks fine especiallly per https://help.ubuntu.com/11.10/serverguide/C/libvirt.html [16:34] ironm: I don't think you can connect to a virt-install console [16:34] ironm: why exactly did you say --graphics=none? if you do vnc, you'll get the console over vnc [16:34] which i think is what you need right now [16:34] it won't cause x to be installed [16:34] ironm: ah, I take it back, hallyn is right [16:35] hallyn, I am on console of the host (ssh) [16:36] it looks like I need a client with vnc ... [16:36] ironm: i'm afraid we have terminology confusion. 'ssh' gives you a pty, fwiw. 'console' usually means a getty running on /dev/ttyX [16:37] right. once it's all set up you can then ssh into the guest [16:37] virsh console itself "works", but I dont' knwo if virtinst is setting /dev/ttyS0 up, nor do i think ubuntu server is setting it up [16:37] so virsh console gives nothing bc there is no getty running [16:37] kirkland: ping [16:37] hallyn, yes .. I thought it is possible to use an install console also from the KVM host [16:38] i don't know what you mean [16:38] kirkland, you see https://bugs.launchpad.net/ubuntu/+source/byobu/+bug/966686 [16:38] Launchpad bug 966686 in byobu "byobu clears screen on login" [High,New] [16:38] hallyn, I try to follow you [16:38] RoyK, you were asserting somewhere that a cd install in a vm results in an empty console on server install, is that right? [16:39] gah [16:39] s/RoyK/RoakSoax/ [16:39] smoser: i'm here [16:40] roaksoax, then look above. stupid caps change. [16:40] anyway [16:40] lol [16:40] smoser: yeah, I've seen that issue [16:40] can you open a bug. [16:40] hallyn, ^ [16:40] smoser: sure, let me test it again to confirm and will open a bug [16:40] and we should determine if thats vm only. [16:41] k ;) [16:42] smoser: eh what? [16:43] if you install a non-server iso without x, grub.conf still redirects you to vt7, which is empty. is that what you're referring to? [16:43] it's not only in vms [16:43] you can edit /etc/default/grub, or jsut hit alt-left to get a console [16:43] this was server iso install [16:43] but admittedly possibly via preseed and cobbler/maas [16:44] and what does /proc/cmdline show [16:44] hallyn: yes [16:44] hallyn: that's it, it shows a black screen with cursor, but changing ttys gives you the login prompt [16:45] I assume there is vt.handoff=7 in /proc/cmdline [16:45] let me check, doing a new install [16:47] utlemming: howdy [16:48] kirkland: have you perchance seen my bug on byobu clearing the screen on login? [16:48] bug 966686 [16:48] Launchpad bug 966686 in byobu "byobu clears screen on login" [High,New] https://launchpad.net/bugs/966686 [16:48] utlemming: yeah, haven't had time to look into that [16:48] utlemming: is that a difference between tmux and screen, perhaps? [16:49] utlemming: I think that's because the older byobu used the /usr/bin/byobu-shell to launch a shell [16:49] utlemming: which cats the motd === bladernr_afk is now known as bladernr_ [16:50] kirkland: yeah, the tmux version is the one that clears the screen [16:54] utlemming: do you think this is release critical? [16:54] utlemming: I reckon it is, since it removes the landscape commercial, huh? [16:55] kirkland: yes...we are putting some logic in to warn people of invalid or uninstalled locales. There is a problem with some packages where if LC_* variable are exported, the package may not installed. [16:55] kirkland: and it removes the blatant commerical advertising too [16:55] utlemming: well, byobu is off by default now, so meh :-) [16:56] kirkland: hence the reason I filed it as "high" instead of critical. Although, the tmux version of byobu is pretty slick. I'm using it a whole lot more myself. [16:56] utlemming: okay, I'll get that one fixed, please assign it to me, mark it triaged/high and milestone it appropriately [16:56] utlemming: i *love* it ;-) [16:56] utlemming: 1920x1080 with about ~6 splits usually [16:56] utlemming: and rarely more than 1 window [16:56] utlemming: okay, i'll get on that today [16:57] kirkland: thanks :) Marked triaged, assigned and targeted [17:35] roaksoax: i really don't know what's to be done about htat :) unless we have the core x package do the appending of vthandoff line [18:01] Does anyone know where to get this how much it costs . Is it real ? does it work on deb systems or only rpm ? ect http://www.hepsia.com/ .Talk about bad advertising, All I can find is demo lol [18:01] adam_g, around? want to discuss squid3? [18:01] New bug: #967887 in glance "Glance's auto-recovery of db connections is incompatible with newer sqlalchemy" [High,Fix released] https://launchpad.net/bugs/967887 [18:16] hello, on a fresh ubuntu 11.10 server virt-install raise "Could not find an installable distribution at" error whatever iso/http/ftp i give to the --location [18:16] any ideas what to check? [18:20] jamespage: sorry, lost in an email. yea [18:21] jamespage: still around or did i miss you? [18:40] huh, it seems like idmapd doesn't start early enough on precise when used with autofs.. [18:42] ah, it's a different issue - my network doesn't start early enough so idmapd can't figure out the domain.. [18:42] but that makes no sense [18:54] I'm having some trouble getting an upstart job to work right, is there an even fires when a DHCP lease is accepted? [19:05] hallyn, ping [19:05] . [19:05] !ping [19:05] another contentless ping... sigh... [19:05] lol [19:06] how would you boot a kvm instance with networking other than guest net [19:06] ie, i'd like to use kvm without libvirt, but the only time i ever do something other than guest net is with libvirt [19:07] smoser: hold on lemme pastebin what i do [19:08] smoser: http://paste.ubuntu.com/913492/ [19:09] or are you asking for libvirt xml to do that? [19:09] hallyn, thats what i wanted [19:09] minus... [19:09] how do you get a network interface there [19:09] you mean br0? [19:10] in the guest [19:10] static? [19:10] i dno't understand. the cmds above will give you an eth0 in the guest [19:11] right. [19:11] but how does it get an IP [19:13] depends on how br0 is set up [19:13] ah [19:13] i see [19:13] br0 from libvirt ? [19:13] it should ping the same dhcp sever as your host does [19:14] or br0 that eth0 is slaved to [19:14] ah. [19:14] yeah. [19:14] i need to provide it one then. [19:14] k. [19:14] or, [19:14] you can set one in the guest by hadn i suppose, but it probably won't talk to the network right [19:18] hallyn, thanks. [19:20] np [19:34] will the log rotator process any log directly stored in /var/log ? [19:34] or just "syslogs" [20:06] New bug: #972786 in ipsec-tools (main) "racoon does not bind to interfaces brought up afterwards" [Undecided,New] https://launchpad.net/bugs/972786 [20:29] adam_g: so novnc doesnt have tarballs per say, like release tarballs, so i think we should be doing another snapshot with the horizon patches applied [20:30] hi all [20:30] I would like to ask, is there any way to catch NULL TCP packets with tcpdump? === ajmitch_ is now known as ajmitch [21:02] alein: "Null Packets are neither sent nor acknowledged when not received." [21:04] 2.1. Formal Definition [21:04] [This section is intentionally left blank, see also Section 0 of [NULL].] [21:05] * RoyK loves april fool RFCs :D [21:05] RoyK I'm trying to catch the true ip address of spoofed syn flood attack. [21:05] Can I do this with tcpdump and wireshark [21:06] how do you want to catch the real IP when it's spoofed? [21:06] spoofed means it's overwritten [21:06] New bug: #972845 in tftp-hpa (main) "after upgrade to precise, service did not start" [Undecided,New] https://launchpad.net/bugs/972845 [21:07] and the routers don't track what they do [21:07] The only way to detect default ip is to looking for NULL TCP packets (meaning no TCP flags set) with destination ports of 0. [21:09] but I'm not sure that I can do this with tcpdump or only with an intrusion-detection system [21:21] alein: what should generate that null packet, then? [21:21] meaning no TCP flags set [21:21] adam_g: we 600 the keystone config files dont we? [21:23] zul: keystone.conf, yeah, we should [21:24] zul: also, /var/lib/keystone/keystone.db if it exists [21:24] k === Jasonn is now known as juicy [22:09] Alright so the Ubuntu dhcp client seems to just give up and die if the dhcp server is down during the time a request is bad.. [22:09] s/bad/made === sergevn is now known as zz_sergevn === zz_sergevn is now known as sergevn [22:32] New bug: #950942 in glance (main) "glance-registry upstart should also include 'started' for mysql/pgsql" [Low,Invalid] https://launchpad.net/bugs/950942 [23:15] So, when we lose our dhcp server, our dhclient process retries for about a minute then exits rather than sleeping. Ubuntu 11.10 64-bit server. Is this expected behavior and is there a way to change that? [23:15] I can obviously script aorund it but I figure there has to be a cleaner way. [23:16] hi smoser, just tried to launch a new ami (ami-37af765e) in us-east-1a and cloud-init exited with code 1. Using the slightly older ami-3e9b4957 everythings works just dandy. figured you'd want to know. [23:20] it is expected behavior because it's assuming you chose the wrong interface, meant to provision a static ip, etc [23:20] just hit go back and do it again [23:22] jiboumans_, i suspect mirror issues. but will give a quick check. [23:22] hm.. i dont know of ami-37af765e [23:22] http://uec-images.ubuntu.com/query/lucid/server/released.current.txt [23:22] smoser: it's listed there ^ [23:23] ah. k. my cache was just out of date [23:23] smoser: this is the last bits in the syslog: https://gist.github.com/2296262 [23:23] well, i can't be sure why your pupet died. [23:23] rmk: oh nevermind thought you meant during installation [23:23] perhaps it could not reach the master ? [23:24] no I need it to retry forever [23:24] rmk: try dhclienf.conf [23:24] smoser: possibly, but it left the ami in a non-good state and appeared to exit the run. [23:24] dhclient.conf [23:24] am i seeing that wrong? [23:24] looks like the params are in there [23:25] there was no /etc/puppet generated for example [23:26] jiboumans_, console output (get-console-output) is more helopful. it will have more info. i suspect it has a apt-get update failre. [23:26] but there will probably be something meaningful to you there. [23:26] smoser: i've scrapped the instance, but happy to respin one if it helps you diagnose [23:26] (and note, in later releases, you should set [23:26] output: {all: '| tee -a /var/log/cloud-init-output.log'} [23:26] you have access to the instance up to 1 hour after termination [23:27] jiboumans_, so above, then you'll have everything that output by cloud-inti or subprocess in that log file. [23:28] just easier to get at thene console [23:28] smoser: i don't seem to be able to start it up again from the console though.. am i missing something? [23:28] thanks, adding that to our start up script [23:28] you cant start it up again [23:28] but at least from the tools, you'll be able to get console output [23:28] its just stored for 1 hour. [23:29] ie, euca-get-console-output [23:30] checking [23:31] smoser: you're right. updated the gist: https://gist.github.com/2296312 [23:31] W: Failed to fetch http://us-east-1.ec2.archive.ubuntu.com/ubuntu/dists/lucid-updates/main/source/Sources.bz2 Hash Sum mismatch [23:31] jiboumans_, you might be a good candidate for our s3 mirrors. [23:32] smoser: i'm listening :) [23:32] which (given disabled apt pipelining , which is current in daily images, or anything with up to date cloud-init) [23:32] should be more stable. [23:32] we'll have offically released amis later this week that have the optoin already disabled inside them [23:33] smoser, jiboumans_: lucid was officially released today with the update [23:33] but you can either laucnh the daily, or set the option in apt yourselfbefore update. [23:33] sorry, you mean that new images will use the s3 mirror by default? [23:33] jiboumans_, so there ya go. [23:33] jiboumans_, no, htye use the other mirrors. but you can tell them fairly easily to use the s3 [23:33] utlemming, can tell you how [23:34] run 'sed -i "s,ec2.archive.ubuntu.com,ec2.archive.ubuntu.com.s3.amazonaws.com,g" /etc/apt/sources.list' [23:34] then i didn't quite follow; what's the apt-pipelining option? I see the lp repo, but not the rationale behind it [23:36] APT uses a micro-enhancement (HTTP Pipelining) to eak out a few microseconds of performance. S3, well, it doesn't get along with pipelining. If you disable apt's pipelining, then S3 works well. [23:36] ah, that makes sense [23:37] utlemming/smoser: is the s3 apt repo code viewable somewhere? it's on my bucket list to do that internally for our own apt repo too [23:38] yup... lp:s3aptmirror [23:39] thanks utlemming smoser, very helpful :) [23:43] utlemming, could you open an RT about the apt mirror issue [23:47] utlemming, oh, its the stale issue