=== markthomas is now known as markthomas|away === markthomas|away is now known as markthomas === ideopathic_ is now known as ideopathic === markthomas is now known as markthomas|away [01:45] say I have a brand new instance of ubuntu ... and I want to install git ... TYPICALLY I need to $ apt-get update .. before doing this ... however that installs a ton of other stuff ... is there a way to ONLY get the packages I need to install git ? [01:46] ok, what is the REAL issue? [01:46] apt-get update, installs NOTHING, EVER [01:46] NEVER EVER [01:47] where is the logs of it INSTALLING TONS of crap? [01:48] Patrickdk, apt-get update + apt-get upgrade [01:48] now your changing your statement [01:48] WHY would you run apt-get upgrade? === semiosis_ is now known as semiosis [01:48] what does that have to do with installing git? [01:48] Patrickdk, let me fire up an instance and get the failing message [01:51] Patrickdk, preferrred paste service? [01:52] https://gist.github.com/carlcrott/da81282980a8f8cdbe7a [01:52] " has no installation candidate " [01:52] did you do a apt-get update [01:53] Patrickdk, I know that will solve it but Im looking to run fewer operations [01:54] you ALWAYS must run apt-get update [01:54] it's REQUIRED [01:55] if you don't run it, you have your issue [01:55] you want to *install* packages that NO LONGER EXIST === markthomas|away is now known as markthomas === markthomas is now known as markthomas|away === arrrghhh is now known as arrrghhhAWAY === thumper is now known as thumper-afk === TDog_ is now known as TDog [06:12] Hi I am trying to setup an ubuntu server (to serve as an LTSP server) .. and I have 2 NICs .. one for the WAN where I get an IP thru DHCP, and one for the LAN which the server will manage [06:12] during install I'm being asked "Choose the primary network interface" which will be used during the setup, listing the 2 nics I have [06:12] which should I pick? WAN? [06:15] guess it shud be WAN, it's doing dhcp [06:16] Guys, could you tell me, why i dont see ä,ö,ü in my ssh client? my locales are all de_DE and i'm on UTF-8 [06:19] Thumpxr: check out locale-gen on the server, perhaps de_DE.utf8 doesn't exist on the server? [06:19] Thumpxr: also check outputof 'locale', perhaps a shell script is setting stupid variables [06:21] sarnold: output of locale is everywhere the same "UTF8-de_DE" or sth like that. did the locale-gen.. must i relogin afterwards ? [06:22] Thumpxr: hmm, maybe... [06:24] sarnold: it worked. Thank you :) [06:24] sweet :) [07:26] Good morning. [07:57] zul, jdstrand: lp:~james-page/horizon/juno-b3-fixes [08:57] zul, jdstrand: there is a build of that in https://launchpad.net/~james-page/+archive/ubuntu/junk [08:57] it appears to work OK [10:13] jamespage: o/ [10:13] hey lynxman [10:13] jamespage: ello ello :) [10:49] rbasak, ping re websocket clietn [10:49] rbasak, looking through hazmats requested jujuclient and deployer updates (which I've ignored for to long) [10:49] needs > 0.18 for websocket client and we only have 0.13 now - any thoughts? === thumper-afk is now known as thumper [10:57] * rbasak looks to remind himself [11:00] rbasak, merging with debian looks good as we can drop your patches tests [11:01] rbasak, 0.18 unit tests OK and is fixes only over 1.16 as in debian [11:02] jamespage: looks OK to sync. Do need an FFe for this? I see only Juju, python-socketio-client and python-docker as reverse deps. [11:03] jamespage: for 0.18, Debian doesn't have it yet, but it is DPMT so maybe update Debian and sync? [11:03] rbasak, I'm not DPMT - maybe barry can [11:04] rbasak, yeah we can sync tho - the breaks/replaces is no longer required [11:06] rbasak, your reverse deps are correct [11:06] jamespage: agreed we can sync - b/r was in Trusty, so all supported upgrade paths should be fine. [11:07] rbasak, it probably does need a FFe I think [11:08] jamespage: there is a testsuite, so that should mitigate any regression. [11:08] rbasak, yah [11:09] rbasak, I pinged barry in #ubuntu-devel [11:09] hallyn: fyi, I've uploaded your fix for bug 1372368 as a workaround for now at least. I think there's a much deeper libvirt bug though. I'm still looking into it. [11:09] Launchpad bug 1372368 in uvtool "VM creation fails on Utopic" [High,Triaged] https://launchpad.net/bugs/1372368 [11:26] jamespage: +1 for horizon, although I think the README.Debian should be updated to reflect how you generated the xstatic tarball === Lcawte|Away is now known as Lcawte [12:43] zul, ok - ack === Lcawte is now known as Lcawte|Away [12:47] jamespage: looked at the debian/changelog. that seems fine to me. it is more like what we have now. you can make sure the right xstatic packages are available. nothing else will start using them [12:49] jamespage: thanks for working on that! [12:53] jdstrand, np - I just added a README.source to explain why and how to use all that stuff [13:10] nice [13:22] jamespage: while you're working on horizon, have you seen https://code.launchpad.net/~cjohnston/ubuntu/utopic/horizon/1308651/+merge/235741 ? [13:27] hey guys] [13:27] looking at unattended-upgrades [13:27] what does "sudo dpkg-reconfigure -plow unattended-upgrades" do exactly? [13:30] is the only thing the creation of 20auto-upgrades, 50unattended-upgrades [13:30] ? === Lcawte|Away is now known as Lcawte === arrrghhhAWAY is now known as arrrghhh === edwardly is now known as D === D is now known as edwardly [14:29] Hello, I am looking for assistance with nfs userid mapping [14:29] Can somebody explain Ubuntu's support policy for PHP 5.2. PHP 5.2 is discontinued upstream, but included in editions of Ubuntu server that are still supported. Did Canonical force users to upgrade to PHP 5.3 to continue receiving security updates? or what is the story with it? how does it differ from debian-lts as it is 'limited support' in debian-lts. [14:30] juice23: do you mean PHP 5.3? [14:30] juice23: we don't have 5.2 in any supported versions of Ubun [14:30] Ubuntu [14:31] mdslaur: i thought 5.2 was in ubuntu 12.04 lts, or was. no? [14:31] juice23: no, 12.04 lts shipped with 5.3.10 to which we've been backporting all the security fixes [14:32] mdslaur: and what about ubuntu 10.04 lts for server? even if it isn't 5.2 it would have been an earlier version that was discontinued. [14:32] 10.04 lts has 5.3.2 to which we backport security fixes [14:32] basically, we backport security fixes to whatever php version we shipped, whether or not the versions are discontinued upstream [14:32] mdselaur: ok, so in other words i'll probably run into this problem again. [14:33] juice23: into what problem? [14:33] mdeslaur: 10.04 lts wouldn't have shipped with 5.3.x though back in 2010. right? [14:33] juice23: yes, it originally shipped with 5.3.2, and we've backported all the security fixes to it since then [14:34] zul, just got enought of a +1 on #ubuntu release for that horizon upload [14:34] can you +1 my mp - https://code.launchpad.net/~james-page/horizon/juno-b3-fixes/+merge/235959 [14:34] and I'll upload for release [14:34] mdslaur: the problem is content management systems dependent on specific versions of php that are then discontinued by ubuntu and other distributions. [14:34] juice23: whatever version we ship a release with is supported for the lifetime of the release [14:34] mdeslaur: OK, thanks for the info. i guess my choice of distribution was poor (well, maybe not, back when we setup the server in 2008, but currently). [14:35] mdselaur: thanks, i think i might move to ubuntu then [14:35] juice23: np === Lcawte is now known as Lcawte|Away [14:35] jamespage: +1ed [15:22] are there firewall rules to allow security updates through? [15:22] ie [15:22] whats the server ip i should allow? [15:23] most firewalls will block inbound traffic but are permissive for outbound... are you blocking outbound as well? [15:23] most firewalls by default I should say ^^ [15:27] hi, i'm trying to get postfix installed and configured as a gmail smtp relay, and i'm running into some weird problems [15:27] http://paste.ubuntu.com/8426161/ [15:27] i've tried to purge sendmail, and install --reinstall postfix, and for some reason, i can't get the postfix service to start [15:28] service postfix start *says* it's starting, but status says it's not running and the mail.err log says that port 25 is already bound [15:28] ses1984, have you checked what is hogging port 25 with netstat? [15:29] yes, it's in my paste, it says, 20604/sendmail: MTA, which i dont understand because i purged sendmail [15:30] but then i read that postfix includes a drop in sendmail binary so i dont know what i'm seeing...is *part* of postfix running but the postfix service is not? === Lcawte|Away is now known as Lcawte [15:38] Anybody have any pointers on how to slipstream a driver into Ubuntu PXE server? My server need a RAID driver to see the volumes [15:47] arrrghhh: we are blocking outbound as well [15:47] Azaril, well then you need to determine how to allow that out I spose ;) [15:47] look at your apt source list, see which mirror you chose... and allow that host [15:47] choose* [15:48] maybe it's chose. blah. [15:48] sure, but if i run an nslookup on security.ubuntu.com i get 7 ips [15:49] Azaril, might want to pick a specific mirror [16:02] HI I am using ubuntu 14.04, where could I get the patch for ubuntu bash security issue? thanks [16:03] sudo apt-get update && sudo apt-get upgrade [16:04] bazzzb, thanks === markthomas|away is now known as markthomas [16:06] ANy help to preload a driver into ubuntu installation? [16:12] Any ETA on the proposed patch to bash for it to merge to stable ? [16:12] rostam: the main issue is fixed in http://www.ubuntu.com/usn/usn-2362-1/ . all you need to do is apply your regular security updates. a followup fix is forthcoming [16:22] jdstrand, we have a few new MIR's that are pending security team review - specifically pysnmp and kazoo - http://people.canonical.com/~ubuntu-archive/component-mismatches-proposed.svg [16:22] jdstrand, just checking these are on your list ;-) [16:25] I'm not sure they are [16:25] * jdstrand looks [16:35] jdstrand, thanks [16:43] why would bash upgrade stuck at kernel dependecy? [16:44] http://pastebin.com/RjFQ2gHd [16:45] where do you see bash in there ? [16:45] coreycb, can you unsubscribe ubuntu-release from the xstatic sync requests pls; we've agreed a different way forward for this cycle [16:46] your package system is messed up and it wants to fix itself ... even "apt-get install foo" would have triggered that [16:46] axisys: nothing to do with bash, your apt is messed up to begin with. apt-get remove linux-headers-server && apt-get install bash [16:46] jamespage, ok will do [16:46] ogra_: I only have unattended upgrade running nightly for security patches [16:46] coreycb, fyi the approach was to embed the xstatic bits within horizon; using a multi orig.tar.gz approach [16:46] jrwren: apt-get remove linux-headers-server won't hurt my server? [16:47] jrwren, ogra_ : may be unattended upgrade broke it? [16:47] coreycb, https://launchpad.net/ubuntu/utopic/+queue/?queue_state=1&queue_text=horizon [16:48] axisys: they are header files, you only need them if you are compiling kernel modules. [16:48] axisys, no idea how it happened, but it isnt realted to bash [16:48] axisys: i don't know much about unattended upgrade. [16:49] jrwren: did not let me remove the header [16:49] jrwren: http://pastebin.com/CLP0rfg2 [16:49] jrwren: how do you address zero day exploit? I am using unattended for security to address just that [16:50] axisys: I don't sufficiently understand the vulnerability to do a risk assessment. [16:51] axisys, i dont get that, why dont you just let "apt-get -f install" do its job ? [16:53] because it will try to remove a newer kernel than what I have [16:53] ogra_: ^ [16:53] ogra_: My guess some upgrade is pending a reboot [16:53] ogra_: and it will apply the newer kernel.. so I dont want to prematurely remove it [16:54] axisys, oh, you dont have 3.2.0-69 installed ? [16:54] I am on [16:54] 3.2.0-59-generic [16:54] well, it wont "just remove" kernels [16:54] so those might be in the queue and pending to be applied [16:55] (it even tells you that you have to do that yourself) [16:55] your first paste: http://pastebin.com/RjFQ2gHd [16:56] $ sudo apt-get install bash [16:56] .... [16:56] E: Unmet dependencies. Try 'apt-get -f install' with no packages (or specify a solution). [16:56] ... thats what i read in the first paragraph [16:56] sudo apt-get -f install [16:56] ... [16:56] Use 'apt-get autoremove' to remove them. (your old kernels ... and only if you want to) [16:56] ... [16:57] and then it just wants to fix package conflicts for you [16:57] i donrt see anything related to your 3.2.0-59-generic [16:58] ogra_: to answer your question - i don't have CGI enabled. I'm the only user of my servers or all my server users are trusted. I haven't figured out where else I'd be vulnerable. [16:58] (if you are worried you can even hardcode the kernel in your grub config) [16:58] ogra_: I am few kernel version behind.. so I would reboot first to make the change.. [16:58] but you guys already answered my question [16:58] it is not bash dependcy .. it is apt related [16:59] yes, your local setup is a little out of sync [17:01] ogra_: unattended upgrade might have a security update which forced the new kernel.. [17:01] could be [17:01] that stil doesnt mean you need to run it :) [17:01] http://www.ubuntu.com/usn/usn-2359-1/ [17:01] it just wants to install it [17:02] to solve the packaging issues [17:03] there are few linux kernel vulnerability from 23rd [17:03] even APT vulnerability from 23rd [17:36] [offtopic] http://techreport.com/review/27062/the-ssd-endurance-experiment-only-two-remain-after-1-5pb/4 <-- interesting [17:39] RoyK: don't need the [offtopic] posts please, as you know [17:39] Need to order me a new 1U SuperMicro server to run Ubuntu 12.04.. finding it difficult to determine what hardware 12.04 will support. Tips? [17:40] research the hardware [17:41] ikonia, thats what I'm doing. Is there a simple way to list supported hardware? [17:41] no [17:41] the HCL is poorly maintained [17:45] for example where do these kernel modules come from /lib/modules/3.11.0xxxx/kernal/drivers ? [17:46] Did my distribution bundle these in and create these during the install .. or some how from the kernel itself? [17:46] LucidGuy: why 12.04? 14.04 has been stable for a while [17:46] RoyK, we sit on an LTS for quite some time, no need to upgrade [17:47] 14.04.1 is LTS [17:47] I know [17:48] LucidGuy: I've used a lot of supermicro systems, and haven't had issues with drivers [17:48] last thing was setup with debian wheezy - no issues [17:49] I have lots of supermicros running ubuntu server [17:49] no issue either [17:49] I even have systems with ssd [17:49] with only SSDs [17:49] axisys, version of Ubuntu? [17:49] Ubuntu 12.04.3 LTS [17:50] LucidGuy: I've used 10.04 and 12.04 and debian with those systems - no issues [17:50] 64bit [17:50] (and obviously, 64bit) === keithzg_ is now known as keithzg [18:32] jamespage: do you know why slapd in utopic is still at 2.4.31 while debian unstable is at 2.4.39 ? [19:09] ubuntu 14.04 stuck booting after nonblocking pool is initialized [19:17] * patdk-wk feels dirty === Ursinha is now known as Ursinha-afk === Ursinha-afk is now known as Ursinha [19:32] pmatulis, because no-one has noticed and merged it [19:32] jamespage: so too late? [19:33] pmatulis, without looking at the upstream changelog I could not say - it would need a FFe from the release team and we are in final freeze now [19:33] jamespage: ah well. i thought these things were automatic [19:54] anyone know how I can upgrade bash on saucy? it doesn't seem to want to, it is showing latest version as 4.2-5ubuntu3 which is vulnerable to "shell shock" [19:55] Lapadine: Saucy is EOL and won't receive updates. === markthomas is now known as markthomas|away [19:55] Lapadine: You should upgrade to Trusty. [19:55] Lapadine: grab the sources from trusty/utopic and rebuild on saucy. Then do it again when the final fix is out :) [20:10] Man, that was far more harrowing than it should have been, updating bash on the old server we use as a router at work. [20:11] It was still running Bash 2.05b! [20:15] do-release-upgrade == not fun over ssh... [20:15] Lapadine: Never had any trouble with it, it opens a screen anyhow. [20:16] am running it in screen so should be ok, just dont like it [20:21] ehh, I've never had it fail. It opens a second ssh session you can connect to in case of failure, too. [20:24] pmatulis, not merges - sorry [20:37] does anyone here know why snmpd wants to install mysql in 14.04? [20:41] claude2: It depends on "libmysqlclient18" [20:42] but why is that and mysql-common necessary? that seems odd [20:55] server unreachable :/ reboot seems to have failed.... [21:03] My friends, how to use cloud-init to create ISOs? I do need to generate a bunch of images for a dark hypervisor. [21:05] what's a dark hypervisor ? [21:08] ikonia: A hypervisor with thousands of instances without openstack support. [21:08] I've never heard of a dark hypervisor before. === markthomas|away is now known as markthomas === Lcawte is now known as Lcawte|Away [22:28] Has the second bash patch hit the repos outside proposed yet ? [22:30] dmsimard: which one? [22:30] in stable releases? [22:30] mdeslaur: The one you made :) [22:30] I pushed out the one for CVE-2014-6271 about 10 minutes ago [22:30] mdeslaur: GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environmen [22:31] sorry, not that one [22:31] mdeslaur: Looking to get the proposed patch in the stable branches for precise and trusty [22:31] I pushed out CVE-2014-7169 about 10 minutes ago [22:31] mdeslaur: GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP cl [22:31] Right [22:31] uvirtbot: will you shut up [22:31] mdeslaur: Error: "will" is not a valid command. [22:31] lol [22:31] uvirtbot: die [22:31] So an apt-get update should get it ? [22:31] mdeslaur: Error: "die" is not a valid command. [22:31] dmsimard: yes, it'll take a few minutes for the mirrors to catch up [22:31] and the USN should be going out in about 5 minutes [22:31] mdeslaur: Thanks for your work. [22:32] you're welcome [22:43] http://www.ubuntu.com/usn/usn-2363-1/ [22:45] :) [22:45] my cache servers have it :) [22:45] now to repatch lenny and fc9 systems :( [22:45] why did they have to dump those onto me last month [22:46] fc9.. [22:46] yes! [22:47] I'm suppost to migrate them [22:47] we where still in phase one, figuring out what they did, cause no one knew [22:48] did anyone propose "turn them off one at a time and see who screams"? .. cause fc9. wow. [22:48] :) [22:49] yes, they where all confirmed working and production [22:49] they had another cluster too [22:49] those where running ubuntu 13.10 [22:50] those are halfway migrated [22:50] I just patched bash in it [22:50] and for fc9 :( [22:50] and lenny, and squeeze [22:52] ovious what my day was spent doing :) === dmsimard is now known as dmsimard_away [23:06] hello, sorry, i'm just a newbie looking for some help about how i should configure my apache2 in the purpose to get my vhost working, i'm trying to do so since 2 hours and 3 tutorials and i still can't figure out what's going on [23:07] hurin_: this guide is well-suited to the ubuntu / debian configuration style: https://help.ubuntu.com/14.04/serverguide/httpd.html [23:08] whatever i'm doing i still see only my default virtual host, even if i write my virtual hosts name,... [23:08] sarnold: i'm going to look at it, thank you [23:08] hurin_: is there anything interesting in the apache logs? [23:09] sarnold: no, all i see are http 200, as if all was working perfectly [23:10] but i keep see only my default website, and never any of my vhosts === dmsimard_away is now known as dmsimard [23:48] any of you folks know off-hand if there's a regex to grep for checking to see if any "shell shock" exploits have been attempted? === dmsimard is now known as dmsimard_away [23:52] MrPPS: pals were grepping for :; in their apache logs earlier, finding all kinds of fun things [23:54] sarnold: I'll take a look, thanks kindly :)