/srv/irclogs.ubuntu.com/2016/01/05/#ubuntu-server.txt

EmilienMjamespage, coreycb: would it be possible to have Rally ( https://launchpad.net/ubuntu/+source/rally ) into Trusty?00:05
sarnoldlost1nfound: investigate kexec/kdump, that might work in aws..00:16
[Mew2]is it possible to forward incoming connections on port 80 to another port?01:21
[Mew2]or i must open port 80 to do this01:21
lost1nfoundsarnold: thanks! i configured kdump per https://help.ubuntu.com/stable/serverguide/kernel-crash-dump.html on 4/10 machines so hopefully i can get some good debugging info sometime later today when one crashes01:22
lost1nfoundand then i guess i should file a bug report with that data?01:23
sarnoldlost1nfound: sweet! yeah, that's probably the next step01:23
sarnold[Mew2]: you could probably achieve the same thing using iptables NAT portfowarding, but that's not exactly trivial01:24
lost1nfoundawesome, thanks for the help, will do01:25
sarnoldgood luck lost1nfound :)01:25
lost1nfoundthanks :)01:25
sarnold[Mew2]: (note that's a guess on my part that iptables NAT can do it -- iptables can be made to do nearly anything, and I do know that you can do port forwarding / manipulating as part of NAT processing.. doing it onthe same IP might be different though.)01:26
[Mew2]ok thanks sarnold01:31
=== rbanffy_ is now known as rbanffy
=== Guest62646 is now known as IdleOne
=== Lcawte|Away is now known as Lcawte
=== Lcawte is now known as Lcawte|Away
imincikHi all, does anybody knows when we can expect Vagrant images for Xenial on https://cloud-images.ubuntu.com/vagrant/ ?08:48
xmjmoin!10:10
xmjI just saw one of our engineers reporting that machines were 'stuck' on “Stopping System V runlevel compatibility”, when connecting a terminal to them10:11
xmjwhere 'stuck' means that they perform as expected, but to get to a login prompt you'd have to CTRL ALT F1.10:11
xmjAnyone else seen this on 12.04.1?10:11
=== kickinz1_ is now known as kickinz1
[Mew2]sudo iptables -A PREROUTING -t nat -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 6000 <-- is this the correct command to forward all traffic from port 80 to 6000?11:11
jamespagesmb, got to the bottom of that jdb process issue i had prior to xmas - looks like the cgmanager backport to trusty is causing problems when the mount happens prior to cgmanager starting11:15
jamespageindeed I'm running with the one in updates, not backports...11:18
* jamespage sighs11:18
halvors1Hi. Ubuntu 16.04 Beta 1 ships with Apache 2.4.17. Isn't it supposed to include the mod_http2 module?11:21
halvors1Or is it in a separate package?11:21
rbasakhalvors1: on advice from the security team, we are not building http2 support deliberately since 2.4.17-1ubuntu111:24
rbasakmdeslaur, sarnold: do we have a release note bug for the http2 drop, OOI? Shall I create one?11:24
halvors1rbask: Is there a security risk?11:24
rbasakhalvors1: that's a question for the security team that I can't really answer, sorry. All I know is that they don't want it for security reasons. Could be LTS-length supportability rather than an immediate risk.11:26
rbasakI accept that we need to communicate their real reason, so I'll try and make sure that there is something in the release notes with an explanation at release time.11:26
=== m1dnight1 is now known as m1dnight_
halvors1You say the LTS release of ubuntu won't include mod_http2 when it is released?11:41
mdeslaurrbasak: I don't think it was a security concern, it's the fact that it's marked "experimental", and libnghttp2 needs a MIR security audit12:03
mdeslaurrbasak: if you want to support the code, including possibly doing a substantial backport if it changes, I don't have an issue12:04
rbasakmdeslaur: ah, my misunderstanding, thanks. Is that the same reason as nginx? I don't see a libnghttp2-dev build-dep in nginx in Debian.12:18
mdeslaurrbasak: I have no idea why it was disabled in nginx, I wasn't part of that discussion, sorry12:23
mdeslaurwe definitely do need to ship http2 in the lts release at some point, whether that's shipping "experimental" code right away, or releasing an SRU of a backport of whatever is considered stable at some time in the future is up to the server team to decide, IMHO12:24
mdeslaurrbasak: libnghttp2 is all new code, and even got a CVE this week, so if we need it in main, now would be the time to do the MIR paperwork12:25
rbasakteward: ^ who were you working with on that, please?12:25
rbasakmdeslaur: noted, thanks.12:26
tewardmdeslaur: rbasak: sarnold12:57
tewardmdeslaur: I asked sarnold whether the Security team had any concerns with the 1.9.6 merge, sarnold said to disable HTTP/212:57
tewardboooo, evil IRC client double post >.<12:57
* teward kicks hexchat out the window12:57
mdeslaurteward: and nginx doesn't require libnghttp2? it has its own implementation?12:57
tewardmdeslaur: AFAIK yes, I've not had to pull that in as a build dep to make HTTP/2 work12:58
tewardtested with 1.9.6 in a Xenial VM too just to make sure, with three SSL / HTTPS checker scripts to confirm h2 was a valid proto offering12:58
mdeslaurok, perhaps it's worth discussing all 4 of us once sarnold is online12:58
tewardok12:59
tewardhttps://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1510096/comments/2 may be relevant12:59
ubottuLaunchpad bug 1510096 in nginx (Ubuntu) "Please merge 1.9.6-2 (main) from Debian Unstable (main)" [Wishlist,Fix released]12:59
tewardas I asked sarnold to post to the merge bug so there's at least a paper trail12:59
tewardperfect timing for the pings, too, I was about to put a 1.9.9 update into Xenial since Debian's dragging their heels13:00
tewardso i'll put that on hold13:00
mdeslaurok, lets discuss this again with sarnold13:01
rbasakacvk13:01
rbasakack13:01
tewardack13:01
tewardmdeslaur: what's missing here is that sarnold and I discussed this as well, i think the idea was that once the Sec team was OK'd with the 'real world exposure' to turn it back on13:02
tewardeither as SRU or before release date13:02
tewardthough, i will say that with SPDY now *gone* in 1.9.5+, HTTP/2's the only thing that would replace it13:03
mdeslaurhaving spdy gone is a big plus13:03
teward+1 there13:03
tewardmdeslaur: may want to wait for the reply to my question to the nginx-devel mailing list13:09
tewardi've pushed the question on HTTP/2 up there to be *certain*13:09
tewardwhen anyone from @nginx.org replies then that's pretty much an authoritative answer, but AFAIK it's their own implementation that has built and worked without libnghttp213:09
tewardhttp://mailman.nginx.org/pipermail/nginx-devel/2016-January/007751.html is the base message, please let me know if I missed anything13:10
tewardactually13:19
tewardmdeslaur: rbasak: confirmed authoritative answer: what I thought I knew is correct - NGINX's HTTP/2 implementation is their own, and only has a dependency on OpenSSL 1.0.2+ with ALPN TLS extensions.   http://mailman.nginx.org/pipermail/nginx-devel/2016-January/007752.html13:21
tewardmdeslaur: rbasak: so nginx won't need to require libnghttp213:21
tewardperhaps this is why sarnold wanted http/2 disabled for now, to let the nginx implementation get some 'real world' exposure for a while to rule out security risks?13:22
tewardstupid question, but when's the next server team meeting15:46
argesteward: isn't it in 8 minutes?15:52
argesjgrimm: ^^^15:52
jgrimmarges, correct15:53
geniiAccording to the fridge, 4pm ( I assume GMT)15:54
tewardarges: unfortunately phone calls are evil16:18
tewardrbanffy: ^16:18
tewarderm16:18
tewardrbasak: ^16:18
rbasakteward: ?16:20
argesteward: its an IRC meeting in #ubuntu-meeting going on right now16:22
argesrather it just eneddd16:23
jgeHey all, my server is notifing that it has 7 updates which are security updates but when I do apt-get update && apt-get upgrade, I only see 3 upgrades which have been held back16:39
jgewhere are the remaining 4?16:39
jgeonly main and security repos enabled16:39
Slingjge: and dist-upgrade ?16:49
jgeSling: that did it, but it installed regular updates too.. was that because the security updates needed them?16:56
Slingdist-upgrade installs all available upgrades16:56
Slingincluding kernel updates16:56
jgeahh, even if I only have main/security repos available?16:57
jgeenabled*16:57
yoinkjge usually it's because the packages listed with security updates also require new packages which aren't installed17:07
yoinkjge if you enable the "mail" option in the unattended-upgrades config, you'll get a detailed email about which packages were listed as security-updates were held back.17:08
yoinkI usually mannual 'apt-get install' those packages and will be prompted for the extra dependencies that aren't installed.17:09
yoinkfor example this recently happened with the mariadb security updates on 14.0417:10
=== njalk_ is now known as njalk
naccrbasak: quick q on logwatch ... I noticed that one of the remaining changes was moving libsys-cpu-perl from Recommends to Suggests (your change in vivid/7.4.1-2ubuntu2). Debian added libsys-meminfo-perl to Recommends in the meanwhile. The change is trivial to move libsys-meminfo-perl also to Suggests in control, but can i just put that in the same line in the remaining changes section as the libsys-cpu19:02
nacc-perl in teh changelog?19:02
rbasaknacc: if it's a new change, then it isn't a remaining change, so it should be in a separate top-level bullet point below rather than as a subitem of the "remaining changes" bullet.19:09
rbasaknacc: note that we usually move things from recommends to suggests in an Ubuntu delta because the package is in main and the recommend is not, which isn't allowed. A suggests is allowed in that case though. So libsys-meminfo-perl does need to be moved if it is universe, but not if it is main.19:10
naccrbasak: ok, i'll verify that, thanks19:13
naccrbasak: yeah, i understand the point about remaining vs. not; but was just wondering as logically it's the "same" change. So in a future merge, we could combine them to one line?19:14
=== Lcawte|Away is now known as Lcawte
=== jdstrand_ is now known as jdstrand
rbasaknacc: that's right. In a future merge we'd combine them to the same line, but for the first merge that includes it, we call it out.19:43
naccrbasak: ok, and for tracking this, should I open a new LP bug? similar to LP 138781719:44
ubottuLaunchpad bug 1387817 in logwatch (Ubuntu) "New Upstream Version 7.4.1" [Undecided,Fix released] https://launchpad.net/bugs/138781719:44
rbasaknacc: if we want a bug to track this, we usually have one that is entitled "Please merge logwatch 7.4.1+svn20150731rev294-1 from Debian" or similar with a tag "upgrade-software-version". And the changelog should auto-close that merge bug.19:51
rbasaknacc: assign yourself to the bug too please. That helps avoid someone else working on it concurrently.19:52
rbasak(though that sort of thing still does happen)19:52
naccrbasak: ok, will do20:03
naccrbasak: still working through the steps from the wiki, etc, but working on it20:03
naccrbasak: ok, does this look reasonable? still want to test, etc, but: https://launchpad.net/~nacc/+archive/ubuntu/logwatch/+packages20:42
jak2000how to check if port 80 is opened?21:19
jak2000and wich service use port 8021:20
tarpmannc -v 1.2.3.4 8021:20
tarpmannetstat -ltpn | grep 8021:20
jak20001.2.3.4 is the local ip?21:20
tarpmanis whatever ip you're wondering about port 80 on21:21
jak2000http://pastie.org/1067212221:23
tarpman-p only works if you run it as root21:27
jak2000ahh21:28
jak20001050/nginx21:28
tarpmansounds right21:28
jak2000tcp        0      0 0.0.0.0:80              0.0.0.0:*               LISTEN      1050/nginx21:30
jak2000how to disable ?21:30
jak2000killing?21:30
tarpmanif it's nginx from apt -> service nginx stop21:30
sarnoldprobably service nginx stop or something similar21:30
tarpmanto disable it permanently -> systemctl disable nginx21:31
* tarpman wonders whether update-rc.d ever ended up learning about systemd21:31
tarpmanoh, it did! :)21:32
jak2000systemctl: command not found21:32
jak2000cant disable permanently21:32
tarpmanoh, are you running a pre-systemd release?21:32
tarpmanthen echo manual > /etc/init/nginx.override21:33
tarpman(IIRC)21:33
tarpmanbeen a while since I touched upstart, someone had better confirm that :)21:33
jak2000sudo echo manual > /etc/init/nginx.override21:33
jak2000-bash: /etc/init/nginx.override: Permission denied21:33
tarpmanwell, yeah21:33
tarpmanecho manual | sudo tee /etc/init/nginx.override21:34
tarpmanwould work21:34
bearfaceupdate-rc.d nginx disable21:34
sarnoldsudo and echo .. >  don't combine :)21:34
tarpmanbearface: does that handle upstart?21:34
jak2000echo manual | sudo tee /etc/init/nginx.override21:35
jak2000say manual21:35
tarpmanyes, that's what tee does.21:35
jak2000done21:35
jak2000update-rc.d nginx disable21:35
tarpmanjak2000: please read manpages of commands if you don't know what they do.21:35
jak2000tarpman tahnks21:38
jak2000and yes21:38
jak2000reading21:38
bearfacetarpman: err, fair point, not sure21:39
jrwrenpretty sure it does.21:40
jrwrenerr, nope.21:41
=== Lcawte is now known as Lcawte|Away

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!