/srv/irclogs.ubuntu.com/2016/04/05/#ubuntu-server.txt

sdezielhallyn: are you there?00:05
=== prince is now known as King
=== King is now known as prince
=== prince is now known as prince[1]
=== prince[1] is now known as prince
=== Bray90820_ is now known as bray90820_
=== ochoroch1 is now known as ochoroch
sarnoldman, for a bad time, undefine the uvtool storage pool in libvirt then try to make it work again. sheeeeesh.06:46
sarnoldI ought to be familiar with this cycle by now; ignore libvirt, think it's probably fine, try it again, hate it again. repeat.06:47
=== athairus is now known as afkthairus
lifelessnevyn: you factoring07:22
lifelessbah07:22
trippehdnsmaster named[15571]: ../../../lib/isc/ratelimiter.c:185: INSIST((rl->pending).tail == (event)) failed, back trace08:43
trippehhrms ;)08:43
CelphishElo09:16
CelphishI'm in the need of some advice, I'll describe my problem, hold on09:17
CelphishI'm trying to install ubuntu server 12.04 on a hp-server through ILO, during the setup it states that it's missing firmware for the hardware, and it asks for the file q12500_fw.bin and asks if I want to insert a removable disk or media with it.. I then go on to create a .img with the file on it (also tried a version where the file was on the img at the path /lib/firmware/) but it doesn't seem to find it..09:18
Celphishproblem is that I need that firmware to be loaded for me to be able to access the first disks and so on09:18
jamespagecpaelzer, any opinion on a sane default for allocating cpu cores for dpdk/ovs ?10:30
jamespagetrying to capture some sort of best-practice for the neutron/ovs/dpdk integration10:31
cpaelzerjamespage: dpeends on the system size11:03
cpaelzerjamespage: how complex can the rules become ?11:03
cpaelzerjamespage: as input vars you surely have the overall #cpus11:03
jamespagecpaelzer, my current thinking was to allocate a core on each numa node along with some ram11:03
cpaelzerjamespage: do you also have #network cards and maybe even #queues on these cards?11:03
cpaelzerjamespage: not a bad thinking - I'd consider that a good lower boundary11:04
cpaelzerjamespage: but it depends a lot if this system primary purpose is passing dpdk traffic11:04
cpaelzerjamespage: if this is doing a lot of dpdk traffic like via many cards and/or 40G/100G cards I'd go higher than that11:05
jamespagecpaelzer, I have memory per numa node as a config option, might add cores per numa node as well11:05
cpaelzerjamespage: htat I like very much11:06
cpaelzercores-per-node starting with 1 as a working but not high-intensity default and up to X as requested would be a good match11:06
cpaelzerjamespage: will that end up in dpdk's -c option?11:06
jamespagecpaelzer, yes11:07
cpaelzerjamespage: while you are at it please consider setting rx queues11:07
cpaelzerjamespage: after you started openvswitch-dpdk11:07
jamespagecpaelzer, on what formula?11:07
cpaelzerjamespage: you can set it via "ovs-vsctl set Open_vSwitch . other_config:n-dpdk-rxqs=2"11:07
cpaelzerthat example uses two queues11:08
cpaelzerjamespage: formular would IMHO be "up to the number of combined queues, but not more than CPUs assigned"11:09
cpaelzerjamespage: I'd guess that is a sane start11:09
cpaelzerjamespage: a manual tuning would include locating on which socket a network card is and then make way more complex masks11:09
cpaelzerjamespage: number of queues can be read with "ethtool -l"11:10
cpaelzerand - btw - is by default limited to #cpus11:10
cpaelzerso on my 12 core the card has 64 queues but uses 12 by default11:10
cpaelzerah and I wrote it wrong, has to be BEFORE ovs-dpdk restart11:11
cpaelzerso that on device init it picks it up11:11
caribourbasak: remember my query on apache2 backport from Xenial to trusty : looks like it's not going to be as simple :12:11
caribourbasak: there is a Pre-Depends: dpkg (>= 1.17.14) after the Utopic version12:12
rbasak"  * Bump dpkg Pre-Depends to version that supports relative symlinks in12:13
rbasak    dpkg-maintscript-helper's symlink_to_dir. Closes: #769821"12:13
rbasakI remember that now.12:13
rbasakYeah that one might be a little messy to fix.12:13
caribourbasak: the simpler solution is to backport the Utopic version that is the one right before the addition of this pre-depends12:26
caribourbasak: and is still what the original bug asked for12:27
rbasakcaribou: I think the pre-depends was to fix a bug.12:27
caribourbasak: I'm looking at the xenial source;looks like what it was fixing is no longer used12:28
caribousymlink_to_file12:28
rbasakPerhaps I'm thinking of a different bug.12:28
caribousymlink_to_dir rather12:28
rbasakbug 1393832 is what I have in mind.12:30
ubottubug 1393832 in apache2 (Ubuntu) "Modules fail to enable when configured after apache2 is configured" [High,Fix released] https://launchpad.net/bugs/139383212:30
rbasakI think that's completely unrelated now. Sorry.12:30
fricklerjamespage: does https://bugs.launchpad.net/ubuntu/+source/python-keystoneauth1/+bug/1566296 look plausible to you? will it be possible to get a FFE or could you only do an update after the initial release is done?13:08
ubottuLaunchpad bug 1566296 in python-keystoneauth1 (Ubuntu) "Please upgrade python-keystoneauth1 for xenial" [Undecided,New]13:08
=== Sprockt is now known as Sprocks
=== xnox_ is now known as xnox
=== not_phunyguy is now known as phunyguy
=== akaWolf1 is now known as akaWolf
=== inaddy_ is now known as inaddy
=== andol_ is now known as andol
=== fidothe_ is now known as fidothe
=== TJ_Remix is now known as TJ-
Slashmanhello, do you think the beta version of xenial is fine to use on a server without any graphical interface in production (without net access)? I'm looking at the bug list and doesn't see any show stopper... I want to avoid if possible the update from 15.10 to 16.04 and use latest ZFS and LXD13:49
jamespagefrickler, we have a standing ffe for mitaka/xenial13:49
jamespagecoreycb, ^^ can you take a look please13:49
jamespagecoreycb, I'm +1 on a resync with Debian if that looks good with you.13:50
tewardSlashman: #ubuntu+1 for 16.04 questions.  And I would not use 16.04 unless you have no choice as it is still not released as 'stable' yet.13:51
DirtyCajunim about to bond 2 nic. i dont have a special switch so im going to use balance-alb, do i need to state bond-lacp-rate or no?13:52
Slashmanteward: thanks for the chan. I understand your point of view, but from the bug tracker I don't see any critical bug for a container/virtualization server13:53
coreycbjamespage, frickler, yes sounds good I'll take a look today.13:53
jrwrenSlashman: its fine, but the update is not a problem either. Jumping through hoops do avoid running an update does nothing but waste your time, IMO.13:54
tewardSlashman: that isn't why I said that.  It's up to you if you use software that is not yet released as stable - there's still quite a lot of other bugs in the system.  I would suggest waiting anyways, before updating production systems.  Or, stage a testing environment to test things13:54
tewardor both :)13:54
SlashmanI'm already testing it, it's working so far13:55
jrwrenOr... use it in production, its excellent real world testing for the rest of us ;]13:55
Slashmanjrwren: ^^13:56
jamespagefrickler, fyi just testing a revised 32 bit compat patch and will get 10.1.0 uploaded to xenial13:57
SlashmanI may stay reasonable and use wily with lxc and zfs ppa then13:58
fricklerjamespage: any change to tackle some of my issues with that, too?14:00
fricklerjamespage: also I just found an old one: https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/1488962 this is still present in xenial, too, it seems14:01
ubottuLaunchpad bug 1488962 in apache2 (Ubuntu) "systemd does not notice when apache2 service fails" [Medium,Confirmed]14:01
jrwrenSlashman: that is no fun. the built in zfs and lxd instead of ppa-zfs and lxc is like upgrading to cadillac from a chevy :p14:02
=== BlackDex_ is now known as BlackDex
jamespagefrickler, on my list for this week...14:04
jamespagenot apache214:04
jamespagefrickler, I see rbasak did some triage - is that bug ^^ a target for xenial?14:05
jamespagefrickler, urgh - that's a systemd fix in suse...14:05
rbasakYeah, that needs attention.14:06
rbasaksmoser was going to look at systemd-boot tagged bugs but I think he's occupied on something else.14:06
rbasakjgrimm: ^^14:06
smoser:-(14:07
Slashmanthere is on issue with zfs between ppa wily and xenial: ppa version is 0.6.5.6 and xenial version is 0.6.5.414:07
Slashmans/on/one/14:07
jgrimmrbasak,  i'm going to suggest cpaelzer for that task14:07
jrwrenSlashman: how is that an issue?14:07
Slashmannot sure how the update will handle that, and I prefer the latest stable version :p14:08
cpaelzerjgrimm: dpdk crumbles between my fingers atm, so I unsugegst myself :-) but lets talk in 20 minutes and define priorities14:10
jgrimmcpaelzer, ok, i can do1x1 now if you'd like14:10
cpaelzerjgrimm: let me just adapt and start the next iteration of the testsuite - approx 3 min14:11
jgrimmcpaelzer, k14:11
tewardjgrimm: ohai, PM?15:02
jgrimmteward, hi there15:03
=== kickinz1|eod is now known as kickinz1
=== jgrimm is now known as jgrimm-afk
ddellavjamespage when you get a chance, can you look at my fix for this and push it if possible? https://bugs.launchpad.net/ubuntu/+source/manila/+bug/154611615:33
ubottuLaunchpad bug 1546116 in manila (Ubuntu) "manila share process init script is missing" [Medium,Fix committed]15:33
ddellavI put the fix up awhile ago but no one has had the chance to review/push15:33
jamespageddellav, we need to get that into xenial first - manila is one of the git repo's under ~ubuntu-server-dev15:35
ddellavjamespage should I create the MIR?15:37
jamespageddellav, MIR ?15:37
ddellavjamespage it's in xenial/universe currently15:37
jamespageddellav, I think we're talking cross purposes15:38
jamespagethere is no manila-share package in xenial yet15:38
ddellavjamespage ooooh, that's what you meant.15:38
jamespageddellav, yes15:38
ddellavjamespage so a requestsync then?15:39
jamespageddellav, no15:39
jamespageddellav, we're divergent from debian here - infact it was in Ubuntu first, but members of the openstack-pkg team did their own thing15:41
ddellavjamespage so what is the next step?15:41
jamespageddellav, how would you make a packaging change to any of the other core openstack packages?15:41
ddellavjamespage normally what i do is package updates, so i debcheckout, import updated package, fix depends and any other issues then push for review. If making an upstream change i use git-review to push changes for CI and manual review.15:44
jamespageddellav, git+ssh://git.launchpad.net/~ubuntu-server-dev/ubuntu/+source/manila is the source for manila15:45
jamespagecan you propose the fix for this bug against that please?15:45
ddellavjamespage yep15:46
jamespageddellav, thanks!15:46
jamespageddellav, the delta in your bzr branch looks fine btw - just needs targetting to the right location!15:46
ddellavjamespage gotcha, thanks15:46
tewardserver team still meeting today?15:46
rharperteward: yeah, scheduled to start in 10 minutes15:49
tewardcool15:49
tewardjust making sure, I can't ever keep track of whomever is chair :)15:49
rharperhttps://wiki.ubuntu.com/ServerTeam/Meeting has chair15:50
rharperbut as you say, not always 100% accurate15:50
tewardyep15:50
=== kickinz1 is now known as kickinz1|eod
jamespagefrickler, any thoughts on what we should set the TasksMax attribute to for ceph-osd/mds/mon ?16:17
jamespage512 is way to low16:17
jamespagefrickler, looking at the juju charms, we currently set kernel.pid_max to 2097152 as a sane default16:18
jamespagefrickler, but this is really just applied at the process level - so I'm tempted to set it to infinity and allow the server admin to deal with it at the kernel sysctl level16:23
=== twoface89 is now known as twoface88
=== wendar_ is now known as wendar
jamespagefrickler, I've uploaded another set of updates for 10.1.0 to the ceph-sru PPA - they will take a while to build16:56
jamespagebut they include fixes for most of your reported problems...16:57
BluekingTJ- hello again :)17:19
=== twoface89 is now known as twoface88
=== twoface89 is now known as twoface88
=== afkthairus is now known as athairus
=== jgrimm-afk is now known as jgrimm
axisyshow do I know if my openssh server is vulnerable to CVE-2016-3115 ? I am using 12.04 lts and I have the latest openssh server already..18:45
sdezielaxisys: you can track the patch status in Ubuntu here: http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-3115.html18:47
sdezielaxisys: in the meantime there are some mitigation you can apply as mentioned in http://www.openssh.com/txt/x11fwd.adv18:47
axisyssdeziel: forgot to mention, I was there already... but let me check the mitigations18:49
tewardaxisys: disable X11Forwarding and it'll help mitigate18:49
sdezielyup18:50
teward"Set X11Forwarding=no in sshd_config. This is the default."18:50
tewardnot sure the defaults in Ubuntu's openssh-server, but it's that simple to help mitigate18:50
sdezielDebian/Ubuntu changed that default18:50
axisyshow do I check the default values? is there a switch ?18:51
tewardaxisys: /etc/ssh/sshd_config18:51
tewardgo poke there, which is on your system.18:51
tewardedit those configuration items, so that X11Forwarding has 'no' instead of 'yes'18:51
tewardunless you need X forwarding18:51
axisysI know I can manually modify the config.. but is there a switch to get the default value, like postconf and mutt has?18:51
tewardin which case you're stuck between a rock and a hard-place18:51
sdezielaxisys: sed -i 's/^X11Forwarding.*/X11Forwarding no/' /etc/ssh/sshd_config18:53
axisyssdeziel: and no-x11-forwarding on those keys18:58
sdezielaxisys: that would work too but the global param also covers password authentication18:59
axisyssdeziel: right.. would you know if ubuntu will have a upgrade available soon?19:27
sarnoldunlikely19:28
sarnoldwe've rated it low, so it'll only get handled alongside something else19:28
axisysalso, might a be question for #openssh, but anyway find out if anyone used x11 .. if not I could modify it without notifying over 2000 users :-)19:28
tewardaxisys: for the record, sarnold is on the security team - he speaks from knowledge therein ;)19:29
tewardso if it's an "Unlikely, unless we handle it alongside something else", well... :P19:29
axisysteward: appreciate that..19:29
sarnoldwe're currently running a pretty steep backlog of issues at the moment, so it's behind a looong queue of other things19:29
axisyssarnold: I know how that is ;-)19:29
axisyssarnold: thank you19:30
axisysso any trick you guys know of x11 has been used recently would help decide how I go about making change with or without change management19:30
sdezielaxisys: maybe you could create a thin wrapper around xauth that logs something prior to calling the real xauth19:30
sarnoldaxisys: another potential mitigation (one I haven't researched at all) is using apparmor policies on the server; that can also confine what authenticated users can do. there's lots of ways of doing that, from giving users a login shell that is confinde with apparmor, or confining sshd with apparmor and using pam_apparmor to change users into a hat ..19:31
axisyssdeziel: so no log today of xauth use?19:32
sdezielconfining sshd with apparmor isn't exactly trivial though :)19:32
sdezielaxisys: maybe sshd logs something specific when calling to xauth. I don't know since I don't use that19:33
axisyssdeziel: on that token since it is enabled today.. let me use it and see how the log looks like.. thanks19:34
sarnoldback when I was a kid we used to confine sshd with apparmor just for something fun to do on a saturday afternoon! of course back then movies were a quarter and a candy bar a nickel so you couldn't just buy your way to happiness let me tell you19:34
* axisys wonders how old is sarnold19:35
sdezielhttps://code.launchpad.net/~sdeziel/apparmor/usr.sbin.sshd-refresh19:36
sdeziel^^ it was fun indeed :)19:36
sarnoldcap_sys_ptrace???19:37
sarnoldoh. right.19:38
sarnold#insert <rant/kernel_devs/ptrace>19:38
sdezielyeah19:38
* axisys struggling to follow 19:39
sdezielactually the up to date version of the profile is here: https://github.com/simondeziel/aa-profiles/blob/master/16.04/usr.sbin.sshd19:40
sarnoldit might be nice to clean out all the commented-out stuff.. I can't imagine that we'll bring back the privsep sshd any time soon19:40
sdezielaxisys: I also have a version for 14.04 but nothing for 12.0419:40
sarnoldaxisys: if you care about this specific flaw enough to use apparmor to confine your sshd, these patches would be a good starting point19:41
axisyssdeziel: might need to enable Log DEBUG .. cuz I do not see anything about xauth on remote's /var/log/auth.log when I login with ssh -X remote19:41
sdezielsarnold: hmm, let me update that bzr merge proposal with the commented-out stuff removed19:41
sdezielI wish apparmor's was tracked in git19:42
sarnoldyeah :/19:46
sarnoldsee afore-mentioned backlog :(19:46
sdezielyeah, at least the conversion is in the pipeline19:51
=== twoface89 is now known as twoface88
=== twoface89 is now known as twoface88
axisyssdeziel: yep atleast DEBUG1 is necessary to catch20:44
axisysx11-req20:44
sdezielgood to know20:45
axisysi have x11forwarding disabled.. what is the best way to test it? ssh -X remotehost and xterm fails ?21:42
sarnoldyeah that shld suffice21:45
tewardsarnold: oh, that brings a question, i'll poke in -hardened since it's a question about the openssl defaults :P21:46
tewardopenssh*21:46
=== alexisb is now known as alexisb-afk

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!