/srv/irclogs.ubuntu.com/2017/12/12/#ubuntu-server.txt

danrikis it possible to use ssh to simulate vpn? as in - bridge 2 networks?01:19
sarnolddanrik: I've done one of these before, it feels plausible that it could do network bridging http://www.tldp.org/HOWTO/ppp-ssh/01:50
danriksarnold: thanks. im seeing that apparently these days ssh-vpn comes standard in fedora 27.02:20
danrikpackage called NetworkManager-ssh, testing that02:21
sarnolddanrik: ha! :) that's awesome02:22
danrikwhich group should I add myself to so I have access to tun|tap devices in ubuntu 12.04 ?02:44
jlacroixI'm having a strange issue with passing an external USB hard disk to a KVM guest. Long story short, USB-passthrough works fine to this guest if I plug in a flash drive. However, my USB hard disk doesn't register on the guest at all whatsoever (the host does see it)02:59
cpaelzergood morning06:39
cpaelzerjlacroix: I remember I have seen another issue similar to yours06:39
cpaelzerjlacroix: in the case a device didn't show up in the guest because the real device controller messed up usb1/2/306:39
cpaelzerjlacroix: the solution was to force it onto an (virtual) usb 2.0 controller06:39
cpaelzerjlacroix: if you want to try - I think virt-manager adds 4 types of ich9 usb controllers06:40
cpaelzerjlacroix: reduce that to one of them, then start a loop06:40
cpaelzerjlacroix: shutdown the guest via virsh, start it and test06:40
cpaelzerjlacroix: in that loop try all the different usb controllers that https://libvirt.org/formatdomain.html#elementsControllers lists06:41
cpaelzerjlacroix: but you said you will try different devices as well, that should be just as good to find if it is that06:41
=== _ruben_ is now known as _ruben
lordievaderGood morning08:59
tobascojamespage: coreycb has ubuntu changed static path for openstack-dashboard horizon package recently? had to change from /usr/share/openstack-dashboard/static to /var/lib/openstack-dashboard/static09:03
tobascois this change consistent for all ubuntu packages for openstack-dashboard (and not just cloud-archive for xenial/ocata)09:04
tobascoif so, i'll push changes to the puppet modules09:04
tobascosince they write their own apache2 config, it seems like that was a breaking change09:04
jamespagetobasco: yes we switched static asset collection to use a guaranteed writeable location (/var/lib/openstackd-dashboard)11:32
jamespagethat was a while back tho11:32
tobascojamespage: ok, saw ut was changed now must have been in a hurry11:50
boxrickHello! I am installing /var to a ZFS volume in the pre-seed right at the end. However when I do /sbin/start-stop-daemon is not present on the install.12:32
boxrickAny ideas why this may be?12:32
boxrickOr perhaps someone could tell me when  start-stop-daemon  is installed during a typical install?12:39
rbasakahasenack: I think bug 1735744 should be fixed in beta. Just not stable. Did you find that it isn't?13:27
ubottubug 1735744 in usd-importer "lint won't run: "Multiple candidate branches found and they do not target the same series:"" [Undecided,Fix committed] https://launchpad.net/bugs/173574413:27
ahasenackrbasak: it's not in my snap13:27
rbasakhttps://git.launchpad.net/usd-importer/log/ - tagged snap/beta13:27
ahasenackI have 0.6.2+git49.967f05013:27
rbasakMaybe the snap didn't build.13:27
ahasenackdoes it build automatically on commit?13:28
rbasak967f050 is where snap/beta is at the moment13:28
rbasakYes13:28
rbasakAnd it has the lint fix as a parent13:28
ahasenackrbasak: oh, you are right13:28
ahasenackI was confused because it still required --target-branch13:28
ahasenackbut once I provide that, the snap one works too13:29
coreycbjamespage: hey i'm going to bump openstacksdk13:37
jamespagecoreycb: ack14:36
rbasakahasenack: I ran update-maintainer and committed and pushed that for the MySQL merge MP. But I just realised that I accidentally pushed it to alioth's ubuntu/devel (my real target branch) instead of rbasak/ubuntu/devel (my staging area).14:37
rbasakahasenack: just FYI. I'll leave things as they are, and sort them out once you've concluded the MP.14:38
HackeMatehi15:03
HackeMatei have 2 ethernet and i want to make route from one to the other one, when i try to use route add default gw <gateway> i get this: SIOCADDRT: Network is unreachable15:04
coreycbjamespage: i'm fixing up openstack-dashboard for b2. the install is broken with the move of openstack_auth in tree.15:09
jamespagecoreycb: ack15:09
jamespagecoreycb: doing a fixup on glance - duped rootwrap.conf with glance-store15:10
coreycbjamespage: ok15:10
jamespagecoreycb: I've uploaded updates for glance, cinder and nova to fix uid/gid to reservations as detailed in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=88417815:33
ubottuDebian bug 884178 in base-passwd "base-passwd: uid/gid reservations for OpenStack users/groups (nova,glance,cinder)" [Normal,Open]15:33
jamespagecoreycb: also mailed openstack-devel@debian with details on why15:33
coreycbjamespage: ack15:33
jamespagecoreycb: zigo is going todo the same in openstack-pkg-tools for the debian variants15:33
coreycbjamespage: ok great15:34
jamespagecoreycb: that should sort out the GPFS permissions consistency issues that the IBM team had; but I don't think we can retro that change into older releases15:34
jamespagemight be wrong but that's my perspective15:34
cpaelzerHowdy all!  office hours is officially starting.  Please bring all questions16:08
cpaelzerrbasak: ahasenack and myself are around, dpb1 might be busy16:09
cpaelzerslashd: smb: anything from you this week to bring up?16:09
ahasenacko/16:09
cpaelzerteward: I wanted to ask you one thing - http2 in nginx16:10
cpaelzerteward: I did apache2 in regard to https://bugs.launchpad.net/ubuntu/+source/nghttp2/+bug/168745416:10
ubottuLaunchpad bug 1687454 in curl (Ubuntu) "[MIR] nghttp2" [Undecided,Triaged]16:10
cpaelzernot sure but you might want to do so next time you touch nginx16:11
cpaelzerso I wanted to ask what you think about that16:11
dpb1thanks cpaelzer16:15
slashdcpaelzer, nothing in particular, everything under control sorry for the late answer.16:17
cpaelzerfine16:18
cpaelzerthere is no being late in our new less formal process16:18
slashdcpaelzer, do you know if there is any SRU shutdown during the holidays ?16:20
cpaelzerquestion for rbasak as he is member of the SRU team16:20
rbasakI don't think we have a formal answer. IIRC generally people try to be extra cautious about releasing SRUs in case of regression.16:21
rbasakI will be reluctant to release an SRU if I'm not around for the next few days.16:22
rbasakAccepting into proposed shouldn't be problem as long as people are around to review them as normal.16:22
slashdrbasak, sound good to me thanks16:22
fstoltzHi, I'm slightly confused as to why there are articles like this (first link) that talk about how to setup a normal user account with sudo priviliges. And then I read thomasrutters' answers on this (second link). Why does the first link explain in-depth of how to set this up when the default way seems to be the way the article tries to explain how to do yourself? Am I missing something or isn't Ubuntu-Server default way by16:24
fstoltzdoing it that way(that the first link explains)?16:24
fstoltzfirst -> https://www.digitalocean.com/community/tutorials/initial-server-setup-with-ubuntu-16-0416:25
fstoltzsecond -> https://askubuntu.com/questions/189907/what-is-the-default-root-password16:25
rbasakRegarding the first link, Ubuntu cloud images set all of that up by default automatically.16:28
rbasakYou get a user called 'ubuntu' (by default) which can already sudo.16:28
cpaelzeron an ISO install your initial user also can do that16:28
rbasakI'm not sure why Digital Ocean aren't just using that. It sounds like they're just making things more complicated for their customers.16:28
cpaelzerbecause that is the way to administrate16:28
cpaelzermy mesg was not in reply to the last of rbasak but to the one before16:28
cpaelzerI also think link #1 is makeing things complex that shouldn't be that way16:29
rbasakfstoltz: does that answer your question?16:30
cpaelzerin general I think sudo also provides a nice level of extra auditability16:30
cpaelzerif (any)one can log in as root you have much less traction what happened why16:31
sdezielbut then people use "sudo -i" and your audit track vanishes16:33
cpaelzertrue16:34
sdezielstill slightly better than a direct SSH to root though16:34
cpaelzerbut it is better than handing all admins the key to root@16:34
cpaelzerthat is what I meant16:34
cpaelzerI didn't want to say it is all needed for good tracking16:34
sdezielgood tracking is hard16:35
fstoltzYes, it does, thank you. Since I'm still new to Ubuntu and the whole GNU/Linux world and I'm fiddling around with Ubuntu-Server for the first time I was unsure whether that step was necessary (firstlink) since it seemed to me that it was already setup like that(without me doing anything in particular). And like cpaelzer said it seems like they're just making it more complex, and that's what I just wanted to confirm, that I16:35
fstoltzwasn't missing some detail. When I try typing "su" i get asked for a password that I do not know, and I'm assuming there is no password since I haven't touched 'root' user. I appreciate you talking about it, makes it clearer for me.16:35
sdezielfstoltz: with su, you are trying to change to another user so you have to know the other user's password16:36
sdezielfstoltz: unless you invoke su as the super user (sudo su) in which case you won't be require to provide the other user's password16:36
fstoltzsdeziel: But when I type solely "su" I get asked for a password16:37
fstoltzsdeziel: I don't specify a user, nor does the password prompt specify anything16:37
sdezielfstoltz: I think it asks for your own password then16:37
sdezielfstoltz: but invoking su alone is probably not very useful16:38
fstoltzsdeziel: Doesn't accept my password16:38
sdezielfstoltz: sorry, I was wrong, su will by default try to auth as root16:38
sdezielfstoltz: could you share a little more context around what you want to achieve?16:39
fstoltzsdeziel: Nothing in particular, it was more just to ease my confusement. I was looking around on this guide regarding ufw, and saw that their prerequisites was following the first link in my first message. And so I was pondering whether I actually needed to do that because it seems that's the way my setup already looks, so I just wanted to confirm that I wasn't missing anything. And seems like I wasn't, so I'll go ahead and16:43
fstoltzstart configuring ufw now :)16:43
fstoltzhttps://www.digitalocean.com/community/tutorials/how-to-set-up-a-firewall-with-ufw-on-ubuntu-16-0416:44
sdezielfstoltz: alright then :)16:45
tewardcpaelzer: http2 is already good to go in NGINX in Ubuntu16:57
tewardcpaelzer: nginx rolls its own implementation, not nghttp216:57
tewardthis is one reason it was ACK'd by the Security team back in one of the earlier cycles16:57
tewardcpaelzer: so, in short, NGINX has been ahead of Apache2 wrt HTTP/2 for well over a year now.16:58
tewardi forget when we actually enabled it, I'd ahve to dig into the histories.16:58
sdezielI know I'm happily using http2 on Xenial so thanks teward :)16:58
tewardyep16:59
tewardcpaelzer: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1565043 i think is the relevant one16:59
ubottuLaunchpad bug 1565043 in nginx (Ubuntu) "Please enable HTTP/2 in NGINX for Xenial" [Wishlist,Fix released]17:00
tewardback in the 16.04 cycle we enabled it17:00
tewardcpaelzer: so, wrt nginx, there's nothing to do wrt HTTP/2 - it's been available since 1.9.14 in Xenial17:01
ahasenackteward: nice17:14
albechany tools similar to imapsync on ubuntu? I have looked at imapsync but it appears that it will require git source and compilation, which i dont want on a production system.17:15
albechor possible imapsync on a repo17:15
albechnever mind seems like larch is what i was looking for17:17
teward...17:25
tewardrbasak: cpaelzer: either of you know how to fix an issue where dpkg doesn't realize changes are actually applied via a quilt patch but it sees them as 'unusual' changes?17:26
tewardand new non-upstream changes?17:26
teward... nevermind.17:26
tewardit's a Merge-o-Matic problem17:27
rbasakteward: you might find http://people.canonical.com/~cjwatson/dpkg-quilt-setup helpful17:27
tewardrbasak: actually, it was a MoM issue17:28
tewardi fixed it by applying the same set of debian/* to a pristine upstream tarball17:28
rbasakIndeed. That script works around the MoM issue :)17:28
tewardand it stopped complaining17:28
tewardrbasak: well, I use MoM as a 'base', then test against pristine17:29
tewardso meh17:29
teward*Yawns*17:29
tewardI need more coffee17:29
tewardrbasak: i got it to build - https://launchpad.net/~teward/+archive/ubuntu/nginx-merge-bionic/+packages - could use some help testing, so I'll put a call for tests out on the ML because I'm busy the next couple days (final exams).17:41
tewardgood news though: if I do well on these finals, GRADUATION GUARANTEED17:41
tewardno more school :p17:41
powersjwoohoo :)17:45
dpb1teward: :)17:45
Laneyhey, is the server team responsible for cloud images?17:48
Laneyif so, wondering if anyone has investigated systemd-networkd-wait-online.service hanging on boot?17:48
Laneyhappens with uvt-kvm17:48
Laney(bug link would be ok)17:48
ahasenackI heard something about that today17:49
ahasenackLaney: https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1737704 perhaps?17:51
Laneyyes someone mentioned it in #ubuntu-release17:51
ubottuLaunchpad bug 1737704 in cloud-init (Ubuntu) "Cloud-init fails if iso9660 filesystem on non-cdrom path in 20171211 image." [High,In progress]17:51
ahasenackLaney: http://paste.ubuntu.com/26169046/ output (bad)17:52
ahasenack(from the bug)17:52
Laneyyes sounds right17:52
Laneythanks!17:52
ahasenack  E: Failed to fetch http://br.archive.ubuntu.com/ubuntu/dists/bionic/main/i18n/Translation-en.xz  File has unexpected size (517768 != 517816). Mirror sync in progress?18:09
ahasenackI was hoping these errors were behind us18:09
tewardrbasak: powersj: sdeziel: cpaelzer: dpb1: and anyone else who cares, just pushed an nginx merge up, assuming nothing explodes from it we're tracking Mainline now.  SRUs will behave as normal once Freeze hits, until then we're in sync with Debian except for upstream nginx version changes.19:33
sdezielteward: great, will give it a try soon-ish and report back any problems19:39
tewardsdeziel: well patience19:39
tewardit's been uploaded but *not* yet done building/syncing19:39
sdezielack19:40
rbasakteward: thanks!20:34
lucidguySetting up openldap with ppolicy and I was password complexity.  What pwdCheckModule do people recommend. pqchecker seems to be popular.  Recommendations?20:55
ktechmidasAnyone know if it's possible to do something like this with a one-liner? lxc config set sf-dc-{seafile,mysql,ex} boot.autostart true23:44
ktechmidasI thought that would generate three seperate commands...23:44
ktechmidasbut it doesn't23:44
ScottEfor i in seafile mysql ex; do echo lxc config set sf-dc-${i} boot.autostart true;done23:47
ScottENote "echo" - remove that to actually run the commands23:47

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!