/srv/irclogs.ubuntu.com/2013/01/12/#ubuntu-server.txt

xnoxdebian dropped clustered lvm2 support *sigh*00:03
xnoxdo you want it?00:03
xnoxstill00:03
patdk-lapclustered lvm2?00:03
xnoxclvm00:04
xnoxpatdk-lap: yeah, where lvm vg is spread across multiple machines.00:04
xnoxwell pvs reside on nodes.00:04
patdk-lapoh, kind of interesting00:06
patdk-lapin a way, it's like a stripped down vmfs00:07
=== slank is now known as slank_away
=== Guest53868 is now known as cpg
hallynroaksoax: ivoks: ppetraki: did y'all see the email about clvm being dropped in debian?00:20
adam_gjust read about it ~15 lines above.00:22
adam_gwheres the mail?00:22
hallynadam_g: heh, sorry00:22
adam_g:)00:22
hallynadam_g: oh, it wasn't email per se, it was in bug 107595000:23
uvirtbotLaunchpad bug 1075950 in libvirt "Starting clustered lvm vg pool fails with status 5" [Medium,Confirmed] https://launchpad.net/bugs/107595000:23
* xnox waves to hallyn00:23
adam_gyikes00:23
xnoxadam_g: hallyn: do we need/want/rely on clvm? and should I be fixing it or dropping it in ubuntu?!00:24
* xnox doesn't want to cause havoc.00:24
hallynxnox: I'm not sure.  In the past we've used it/relied on it...  but we wouldn't be dropping it for old LTSes, so not sure it's as big a deal00:24
hallynbut I'd like to hear from ppetraki and ivoks first, they probably rely on it more than I :)00:25
adam_gxnox: AFAIK its certainly a requirement of some clustered filesystem deployments00:25
xnoxi mean if cloud / customers rely on it, we should keep it.00:26
* xnox thinks debian is dropping it to just get wheezy out the door.00:27
hallynoops.  uh, please do disregard comment # 5 in that bug...  :)00:28
hallynxnox: let's discuss on monday with whoever cares;  i don't want to waste anyone's time, but yeah i do suspect we want to keep it.00:29
hallynxnox: is that particular bug one you'd want to work on?  (if not, i should put my time where my mouth is and look at it next week...  if we're not dropping it)00:30
hallynnow to go figure out why my setuid bits aren't being maintained00:30
xnoxhallyn: i maintain lvm2, but I never setup clustered lvm2 myself. But I did want to play around with clvm. So I can do it, that's fine.00:31
xnoxhallyn: any particular list public or private where I can kick this a thread on? or are we just gonna do it on irc? (server team meeting?!)00:32
hallynxnox: I think it's fine to start right here00:33
xnoxhallyn: fair enough. =)00:34
xnoxI guess everyone was highlighted already =))) Daviey ^^^ =) do we want clvm or not, debian dropped it.00:34
ppetrakihallyn, roaksoax: regarding clvm, that's news. Do we have many users? The last use case we did commercially was kinda old school.00:58
roaksoaxhallyn: i didn't see it, but i was expecting it would01:08
hallynppetraki: roaksoax: ok, interesting.  if it doesn't rattle you folks, then i'm fine with it01:32
hallynvictim of chown vs lchown02:45
adam_gzul: Daviey http://people.canonical.com/~agandelman/g2_deps/ is the full set of no-change rebuild dependencies needed for grizzly-2.02:45
sarnoldhallyn: isn't lchown just on *BSDs?02:47
sarnold.. or am I thikning of lchmod?02:48
adam_gzul: Daviey a +1 on those and ill put them in the staging repo. some of he test* packages will fail to build if not built in correct order.02:51
hallynsarnold: actually, *i* meant lchmod, not lchown :)02:54
hallynikeep typing one when i mean the other today02:54
sarnoldhallyn: hah, I never expected that. :)02:55
hallynmainly when looking for man pages, luckily, not int he code itself :)02:55
hallynstgraber: holy cow i've never seen patch mess up this many chunks, and so subtly, as my userns lxc patch today.  Apparently we've been moving code around in extra-sneaky ways lately!03:08
stgraberhallyn: hehe ;)03:08
hallynstgraber: userns update.  mostly works, but (unlike a month or two ago) if I don't comment out /sys/fs/fuse/connections, /sys/kernel/debug and /sys/kernel/security from /lib/init/fstab, I hang at mountall from the failures (-EPERM) to mount those03:34
hallynI'll ignore that and send hte patch out to the m-l anyway.  now that at least uid mapping is in 3.8.03:35
stgraberhallyn: yeah, I guess we can figure those out later03:43
hallynstgraber: it seems like there must be ar ecent change in raring's mountall to make it not handle failure as gracefully as it used to03:48
stgraberhallyn: there might have been a bugfix causing that change in behavior. Would have to look at the upstream bzr.03:49
stgraberhallyn: But yeah, mountall hanging isn't really optimal, I'll have to take a look.03:50
stgraberthe generic rule is that it won't attempt a mount of an fs that's not supported by the kernel (which doesn't apply to our case) and will ignore failures if nobootwait is set (which AFAIK it's not for those fs)03:50
stgraberbut there's a clear difference between being unable to find the source of a mount and having mount fail, the latter shouldn't prevent mountall from exitting as there's no change that the mount call will ever succeed (not that mountall actually retries anyway)03:51
hallynstgraber: the filesystems are all marked 'optional', but not 'nobootwait'.  i could try that one...03:56
hallynstgraber: haha, yeah, that works03:58
hallynstgraber: btw, if you look at /proc/$$/fd for the getty's, we are leaking fds03:59
hallyn(rootfs.hold)03:59
hallynrecon i can count that one my bad03:59
=== aarcane_ is now known as aarcane
=== lickalott_ is now known as lickalott
decci I have installed Ubuntu without RAID partitioning system. I have just one /dev/sda1,2,3 partiton I can see through fdisk. I added 3 more disk. How shall I create RAID out of my four disk06:35
decciIs it possible to include /dev/sda too for RAID06:35
decciI am looking for RAID 10 out of 4 HDD of 3TB each06:35
=== megha is now known as security
=== security is now known as firewall
sergey_099357Народ, привет. Русские есть??08:13
sergey_099357Помощь нужна срочно08:14
sergey_099357!!!08:14
sarnoldprivet, english? :)08:14
sarnoldsergey_099357: #ubuntu-ru  :)08:15
sergey_099357russin?08:15
sergey_099357Russian&08:15
sergey_099357anybody speak russian08:15
sarnoldsorry, I didn't see "Русские" very quickly :)08:15
=== megha is now known as firewall
wernersHow does one install dkms when one performs a clean install of Ubuntu Server on a server without internet access? I can't find the package.09:23
=== freedomrun is now known as Guest97005
NaGeLhello. i Got a problem with Ubuntu with samba. samba sharing works perfectly with Windows XP and it worked fine with Window 7 yestrday. Today it doesnt work anymoreyet XP  still works10:48
RoyKNaGeL: I guess we'll need a few more details - does \\ip.add.re.ss work? what is the error message? what does the samba logs say?11:07
NaGeLRoyK, ijust tried the Ip adressand it works!11:07
NaGeLand the rrors message last time i checked said nothing about even connection attempt11:07
RoyKthen something is fishy in the windows resolver, which is quite normal ;)11:08
NaGeLand how can i resolve that shit?11:08
RoyKNaGeL: well, I guess use dns or perhaps just fix windows <(11:20
RoyK:)11:20
NaGeLI'm trying to fix windows but i dont even know why the problem is here11:20
RoyKdunno, but doubt it's an ubuntu question11:21
RoyKor, have you set netbios name in smb.conf?11:21
NaGeLRoyK, no i haventtouched that file.. thought i do stuff throught webmin11:28
NaGeLRoyK, found the problem. windows only allows 1 connection to the server and it wasalready connected yet i could not use it11:38
RoyKhuh?11:44
=== motmot is now known as liva
RoyK!webmin11:44
ubottuwebmin is no longer supported in Debian and Ubuntu. It is not compatible with the way that Ubuntu packages handle configuration files, and is likely to cause unexpected issues with your system.11:44
TheBronxhi!11:50
RoyK!ih11:51
NaGeL...yet i use webmin.. is there an alternative to that?11:52
NaGeLanyway i just installed xrdp for remote connections. andit immeadtly said that logn failed. do i need to reatea special user or the basic ubuntu user should be enough?11:53
RoyKNaGeL: well, learning linux is a rather good alternative ;)11:56
NaGeLRoyk, i will in due time forst comes apache server11:57
=== cpg is now known as cpg|away
sk1pperhi all!12:39
sk1pperi installed bind9 on 12.04 and i am trying to configure it from a ubuntu documentation that i have. the thing is that bind is resolving without me having set up a dns forwarder. why is that happening? can i somehow disable that? i would like bind to resolv just the addresses in my network12:39
jabba_hello13:37
jabba_just tried to prevent my system from loading ohci_hcd, ehci_hcd and xhcd_hcd at boot. so i added these modules to /etc/modprobe.d/blacklist.conf, did a update-initramfs -u and rebootet. but: modules where still loaded.13:37
Free99hey everyone. If I'm trying to compile some source for a package from launchpad, and there is also a diff file included, how do I apply the diff?14:07
jabba_i follwed this howto: http://wiki.debian.org/KernelModuleBlacklisting for blacklisting ohci_hcd, ehci_hcd, uhci_hcd and xhci_hcd. But they still seem to work, as the usb-stick plugged in is still visible under /dev after boot...14:09
jabba_lspci -k shows the modules as used kernel drivers for the usb-hardware, but they are not visible by lsmod14:10
jabba_wtf?14:10
jabba_Free99: man patch14:12
Free99jabba_: looking at that right now, but when I less the diff file, it looks like it applies to several different files.. I'll try to figure it out, thanks for the pointer14:13
Free99jabba_ so I copy the file into the source's directory, then just run patch < blabla.diff ?14:16
Free99*copy the diff file14:18
jabba_i guess14:18
Free99sweet! patch -p1 to get rid of that first component. Learned something new, thanks jabba_14:22
jabba_you're welcome... any suuggestions to my "problem"?14:24
RoyKjabba_: does lsmod list them?14:27
samba35RoyK, hi ,how r u14:28
jabba_RoyK: no14:29
jabba_but they are usable14:29
jabba_the usb-stick is visible under /dev/sdb14:30
jabba_on the bootscreen i can even see that it's attached by usb-storage14:30
RoyKwhat does lsusb have to say?14:34
RoyKsamba35: fine, thanks14:34
TheBronxhi all!14:46
TheBronxiptables question: http://askubuntu.com/questions/240360/is-there-a-rule-for-iptables-to-limit-the-amount-of-syn-packets-a-24-range-of-i14:46
TheBronxit is probably not very difficult but I'm new to iptables and I it seems the problem is a bit weird14:47
RoyKTheBronx: I guess something like iptables -I INPUT -s 192.132.209.0/24 -p tcp --syn -m limit (something)15:01
qman__TheBronx, the answer is right there, just change the address to the ones yo uwant to block15:05
=== a|way is now known as alein
TheBronxyeah, but I want the blocks to be detected automatically hehe15:08
TheBronxthere are a lot of blocks during the attacks15:08
TheBronxI can't block them manually15:08
qman__then apply a broader limit, something like this15:09
qman__now, this won't apply directly to you, but the setup does15:10
qman__I use this to block SSH brute forcing15:10
RoyKsomething like what?15:10
qman__http://paste.ubuntu.com/1523916/15:10
qman__basically, there are four levels of measurement and block time15:11
qman__if you exceed the shorter threshold, you're blocked for a short time15:11
qman__if you exceed the larger thresholds, you're blocked for longer periods of time15:11
qman__you'd clearly want different numbers for syn packets, much more tolerant15:13
qman__but you could configure it to say if you got flooded for three minutes flat, block for an hour15:14
RoyKqman__: dropping all of ipv6?15:14
qman__yeah, I'm not using it and that's my shell server15:14
=== alein is now known as a|way
qman__reduce the attack surface15:14
qman__really I should have an input drop rule too, but I used to run more software and was lazy15:15
RoyKlooks like an iptables version of denyhosts/fail2ban15:15
qman__pretty much15:16
RoyKbut good, though15:16
RoyKqman__++15:16
mika__Testing15:48
=== a|way is now known as alein
=== Err404NotFound is now known as Error404NotFound
lifelesszul: testrepository 0.0.12 is out with a .testr.conf in the MANIFEST.in19:33
=== sw__ is now known as sw
=== jnix is now known as jnix-work
=== aarcane_ is now known as aarcane
=== cpg|away is now known as cpg
=== alein is now known as a|way
scalability-junkhey I looked into that issue twice in the last 6 weeks and still haven't found a real answer for the problem. I started out with kickstart files, but tried ubuntu autostart files after kickstartfiles seem to have issues on ubuntu.21:18
scalability-junkI want to great a raid1 with encryption on top of it with lvm inside the encrypted volume.21:19
=== cpg is now known as cpg|away
scalability-junkany good way to do that?21:19
scalability-junkI really have no idea to to it in an automated fashion. or is this something Maas is better suited for than using a config file?21:35
scalability-junkmaas seems to overkill for a 2-10 server setup especially maas needs another server etc...21:36
scalability-junkany help would be appreciated I really don't want to switch to another os because of this21:40
freesbieif its not that many servers what is the problem in doing disk setup manually ?21:41
freesbieive never tried crypt with kickstart, so I have no clue about it :)21:42
scalability-junkfreesbie, not as convenient when setting up a new server, not as automated as I would love to (love to learn new stuff) and setting up encryption lvm etc. is taking 30+ mins per server that seems fairly much even on 10 servers.21:42
freesbie30 mins ?? wow .. i did it in 5 on my laptop install ..21:43
scalability-junkfreesbie, crypt with kickstart is fine, but not on ubuntu it isn't supported :(21:43
scalability-junkfreesbie, clicking through raid1 + encryption + 4 partitions is a lot to click21:44
scalability-junkcould be 20 mins but more than 5 all together21:44
freesbieclicking ? something is wrong here .. text installer doesnt support clicks :)21:44
scalability-junkfreesbie, true, but I still thought of it as clicking :D21:45
=== cpg|away is now known as cpg
freesbiebut yeah, with more partitions it will take a while. on the laptop I only have boot, swap and / .. and only 2 of them crypted21:46
scalability-junkyeah and with raid it is double the time ;)21:47
scalability-junkor it feels like it :)21:47
=== cpg is now known as cpg|away
scalability-junkmhh seems like I really have to go the manual approach or use another distro with decent support of kickstart files :(21:51
scalability-junkfreesbie, I even tried to use the auto generated preseed file after manually setting up an installation, but that preeseed file is just horrible. non readable gibberish listing enter steps, which seems like breaking any minimal update :D21:53
freesbieI will agree that the kickstart system needs some love in ubuntu21:53
freesbiei did a fast setup without lvm, grub failed to install on the device. manual worked perfectly21:54
freesbieso ive opted for kickstarting with manual disk setup, as it works best for different hardware platforms21:56
freesbiewhen I get half a day of freetime I will look into it again .. but since were only doing 1-2 new installs every month its not that big a deal21:58
scalability-junkyeah still fedora is much better in this sense, and I wonder how something like this is done via maas, probably not possible all together :D21:59
addicatDoes anyone have several minutes to help me mount an ubuntu-server NFS share from OS X 10.8? I'm pretty far along in the process and got stuck when google stopped offering help. I can view the export from my client terminal with show mount -e ser.ver.i.p22:10
addicatMy server's hosts files are set up to enable all connections (until I get it working)22:12
freesbieaddicat: how do you export it on the server ?22:27
addicatfreesbie, in /etc/exports: /export/music 192.168.1.*(rw,sync,no_subtree_check)22:29
freesbieaddicat: check the logs on the server and client, try to mount it on the client in a terminal that might give you a better message22:32
addicatshould I be looking at /proc/mounts?22:38
freesbieaddicat: logs is in /var/log, something should be written there when trying to mount .. I know nothing about OS X, but the export looks ok .. you could test it by mounting on the server itself in a different dir22:42
addicatfreesbie: I'm getting a little closer, thanks. It looks like it might not be mounted properly22:43
Super_DogI know this is server channel.  But since it's probably a Samba issue - thought I'd ask here.  Just upgraded my Ubuntu 10.04LTS to 12.04LTS.  Worked pretty well.  However, the share to my home directory on this system doesn't seem to work now... Any obvious fix I'm overlooking?23:57
Super_DogI hear horror stories about Samba 4 which I believe 12.04 LTS is running now.23:58
freesbiesamba 4 is too new for 12.04 .. so no its not running that23:59
Super_DogI thought I saw "Samba Alpha" when I was running through the install.  Maybe I'm wrong.  Let me check.23:59

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!