
cpaelzergood morning04:25
lordievaderGood morning06:39
_rubenCheckmate: if /home isn't a separate filesystem from /, how is moving /opt to /home gonna help anything?08:47
k_szeI think I messed up my /boot or something.09:44
k_szeDuring `apt full-upgrade`, dpkg complained that there's not enough space (though I didn't check exactly which volume ran out of space).09:44
k_szeNow the machine can't boot into Ubuntu09:44
k_szeIt just shows the boot menu where I can choose ubuntu or advanced options.09:45
k_szeAnd if I choose ubuntu, the screen goes black for a moment, and loops right back to the boot menu.09:45
k_szeIs there any easy way to fix that? Given that I have a live USB as well.09:45
k_szeBy "boot menu", I mean GRUB09:49
TJ-k_sze: choose Advanced, then pick an older kernel version from the menu. The problem will be the /boot/ ran out of space whilst writing the new /boot/initrd.img09:52
k_sze(I didn't realise that I should regularly purge old kernels from /boot until today)09:53
k_szeI just kept installing updates without purging.09:54
k_szeI hope I still have a bootable old kernel. XD09:54
k_szeBut what do I do once I get it booting?09:54
k_sze`apt autoremove` shall do the right thing? And then I can `apt full-upgrade` again?09:55
k_szeHmm, and now I can't start a GNOME session.10:00
k_szeI get the "Failed to start session" message when I attempt to log into GNOME.10:01
TJ-k_sze: once it's booted, you manually delete the /boot/initrd.img-XXX files for the versions of linux-image-* that "apt autoremove" says it wants to remove10:02
k_szeI kept thinking this is a ubuntu server. I guess I'll ask in the normal #ubuntu channel.10:02
TJ-k_sze: I wrote a script to do it automatically if you want to try it10:03
k_szeSeems like everything works now.10:25
k_szeThanks for the help.10:25
=== downtime is now known as uptime
Neo4hi, Who know what means "musti-server"? http://pix.toile-libre.org/?img=1523620041.png11:48
Neo4Can I install on VM DNS server, VPS and other apps for test?11:50
Neo4I want to install a 10 times all and get a skill :)11:50
Neo4so muscle training )11:51
=== miguel is now known as Guest50751
rbasakahasenack: good morning!12:38
rbasakahasenack: I'm looking at some server-next bugs.12:38
rbasakahasenack: any opinion on my comment in bug 1659223 please?12:38
ubottubug 1659223 in clamav (Ubuntu Xenial) "apparmor regression blocking freshclam process info" [Undecided,New] https://launchpad.net/bugs/165922312:38
ahasenackhello rbasak12:38
ahasenackrbasak: agreede, fixed in bionic12:40
ahasenackregarding xenial, it would need the change from https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1658239 fixed in xenial12:41
ubottuLaunchpad bug 1658239 in apparmor (Ubuntu) "base abstraction missing glibc /proc/$pid/ things" [Undecided,Fix released]12:41
rbasakahasenack: do you think we should do it?12:41
ahasenackor just include that change in clamav's profile12:42
ahasenackI don't know if it's just a warning, I can't remember12:43
rbasakahasenack: yeah. But is it worth it? If it doesn't actually impact anything apart from the log message.12:43
rbasakahasenack: how about I Won't Fix for Xenial for now, but invite people to reopen if there's a functional problem?12:43
ahasenackI would test it to see if freshclam works or not, I think that's the crux of the issue12:43
ahasenackalso, the bug says "regression", I would check if that's true12:44
rbasakI'm not too worried about that, because the bug itself seems unimportant and is resolved in the development release.12:44
rbasakSo I see no need to dig further - but if someone does and finds something worthy of attention, that's still fine.12:45
rbasakcpaelzer, ahasenack: as I'm going through the server-next bugs, there are a number I want to drop from that queue because I don't think they're important enough. Would it be worth us running through the list together in a HO perhaps?13:08
ahasenackI don't have the spare cycles :/13:14
rbasakWe can defer it.13:30
Neo4Guys, how easy manage your server?13:59
Neo4is it way for speed up?14:01
Neo4I have this book14:01
Neo4for effective manage your system we need set up control panel, doesn't it?14:02
Neo4don't it*14:02
Neo4I'm a newbie, Who know how I can rapidly learn web hosting?14:03
Neo4I am interestiong everything that relate to VPS14:03
dpb1rbasak: tag them as "should-drop" or something.14:03
rbasakGood idea, thanks.14:05
Neo4dpb1: What control panel do you use?14:05
Neo4see this https://www.virtualmin.com/14:05
Neo4I don't know what chose14:05
Neo4wirtualmin or webmin14:05
Neo4the best ISPmanager14:06
Neo4dpb1: ???14:06
Neo4dpb1: what is bash4life ?14:07
Neo4dpb1: what contral panel do you sugest to use?14:08
m1dnight_what dpb1 is telling you is that you don't need a control panel. You just do stuff in the commandline.14:08
m1dnight_What will you do when your controlpanel says "ERROR" ;p14:08
m1dnight_webhosting is fairly easy, given you have enough experience with the shell.14:09
Neo4it's difficult, I do, but for install VPS I spend 4 hours and more14:09
m1dnight_you want to host vps's?14:09
Neo4I want to learn this theme14:09
m1dnight_and you have no experience with the commandline?14:09
Neo4have, and not good impressions14:09
Neo4I used ISPmanager, it's very nice , here I would able to change php versions easy14:10
m1dnight_the best you can use I guess is virt-manager whic is a GUI on top of virtlibd14:10
Neo4set up database user, create db, create FTP account14:10
m1dnight_is anyone else confused here?14:10
m1dnight_vps or website hosting.14:10
m1dnight_php version, dbs and ftp accounts seem to relate to webhosting, not vps hosting.14:11
Neo4for vPS too14:11
Neo4m1dnight_: of course I can use SSH, but if I want to give access somebody, suppose for some folder for test something, I couldn't give SSH access14:12
m1dnight_sure you can14:12
m1dnight_you can chroot a user into his home directory14:12
Neo4yes, all of this I can doing manyally and spend much time14:13
m1dnight_ftp is an ancient protocol and should not be used.14:13
Neo4I think to try some panes, sudenly there all will faster?14:13
m1dnight_i have no idea about admin panels that allow you to do all this.14:13
m1dnight_So I can't help you, sorry14:13
Neo4m1dnight_: read this, they have very attractive features, haven't they?14:15
Neo4I didn't use them, but it looks like if you will use it will much better that do all manually14:15
Neo4I'm interesting what people use here?14:16
Neo4anyone use control panel for desctop?14:16
Neo4it is said it's frequently unix linux users use it14:16
ogra_home users prehaps ...14:17
ogra_most professionals will simply use the shell14:17
Neo4ogra_: why? maybe opposite? Home use shall and professional control panel?14:18
ogra_(and specifically webmin being a pile of security holes is likely something nobody will use in a professional environment .... it was removed from the debian and ubuntu archives for a reason)14:18
Neo4professionals don't want to spend type type comands, they will rather use interface14:19
Neo4ogra_: what has ubuntu in archive ?14:19
ogra_most professionals i know want control and not abstraction14:19
Neo4what panels has ubuntu in archive?14:19
ogra_no idea, i never used any14:20
m1dnight_you have the paid ubuntu landscape thing, no? I actually have no idea what that does, though..14:20
Neo4ogra_: you didn't use any, is it now time to try some? :)14:21
ogra_not really :)14:21
Neo4m1dnight_: noither am I14:21
Neo4ogra_: neither  am I)14:22
Neo4no I will use, better tried and then say it's bad14:22
Neo4ogra_: see what I found https://www.rosehosting.com/blog/best-open-source-hosting-control-panels/14:23
Neo4this things are thrived, it means they are actively used, perhaps14:23
Neo4are thriving*14:24
Neo4we don't have to be a command line guru in order to manage simple web site14:25
m1dnight_no, you can do it with simple commands.14:25
m1dnight_Instead of forcing your way around the commandline, bite the bullet :p14:25
m1dnight_it's all just files anyway..14:26
Neo4yes, I can do, but my future clients won't, They will require CP14:27
Neo4for to be expert I must learn at least a few of theme14:28
m1dnight_I've only used one.com and they rolled their own I think.14:28
Neo4Cpanel and ISPmanager, it's obligate, and one opensource14:29
Neo4m1dnight_: I used ISPmanager, Used and skill to install and customzie  are different things14:29
Neo4m1dnight_: by the way do you know what could mean 'multi-server'?14:30
ogra_well, if you want to sell services using these tools,i'd suggest to do a security audit and usablility research and then pick the best ... after all you are giving your business into the hands of the developers of that panel software14:32
Neo4who know what means "multi-server"?14:32
Neo4ogra_: I'm going to build site using wordpress, 'online stores' and for this I need VPS, What I will say my client, use command line?14:33
ogra_... if their tool does a minor mis-configuration of a database or website and all credit card data of all users of your customers are exposed online all of a sudden your business will quickly be broke :)14:33
Neo4ogra_: oh, no, there not credit cards in database nor other data14:34
ogra_if i'd use any of such panels i'd hire a security specialist and have her review the tools from the ground up (including the source) before giving my business in the hands of the devs of these tools14:35
m1dnight_the databases will be empty *magic*14:35
Neo4ogra_: TLS14:35
Neo4ogra_: force user to use TLS14:35
ogra_see, i cn trhow around acronyms too :)14:36
RoyKm1dnight_: https://xkcd.com/327/ ?14:36
Neo4ogra_: web interface, there all security it's TLS and use strong password14:36
ogra_Neo4, and that helps how ?14:36
m1dnight_ABC :D14:36
ogra_if the interface code has a bug and breaks security of your webserver, it doesnt matter if your users interact securely with it14:37
m1dnight_Neo4: the point here is that its very easy for a bug in the webpanel to execute a command that has unwanted side effects14:37
Neo4ogra_: TLS, encrypt all data and adversary can't access site14:37
m1dnight_Neo4: but it's not adversaries you're worried about14:37
m1dnight_endusers are just as dangerous...14:37
Neo4ogra_: man in the middle, this is the main problem, if client strong care about security you must install valid certificate and force him use strong password14:38
blackflowthat's not really true. the CA model for TLS certificates is fundamentally broken and shouldn't be considered "secure" for most intents and purposes.14:38
ogra_man in the middle is a possible attack vector, but surely not "the main problem"14:39
Neo4m1dnight_: do  you sink client can harm site using CP?14:39
RoyKand don't do something as silly as for instance zabbix, which indeed is a nice system, but all passwords are stored as non-salted md5 hashes14:39
m1dnight_assume so, unles you had the aforementioned security audit...14:39
Neo4blackflow: who will care out attack on simple online store? You don't need somebody.14:39
blackflowRoyK: still? in 2018?14:39
RoyKblackflow: yes14:40
m1dnight_such security.14:40
blackflowNeo4: just saying that using TLS does not make it magically "secure". the whole model relies on trusted CAs, which have repeatedly proven untrusted.14:40
Neo4ogra_: for WEB it's main, what could be other problems? As it said broken CPanel itself. I think many users are using it and they would long ago niticced it and corrected14:41
ogra_m1dnight_, well, how else would the callcenter support verify you are you if they couldnt see your cleartext password on their screen ;)14:41
m1dnight_Youre kidding right?14:41
Neo4blackflow: users don't know what is certificate, Do you know many people who know what is TLS?14:41
Neo4blackflow: they will accept easy invalid certificate if attacker will send it, I think for little store it's not problem14:42
m1dnight_oh, didn't pick up on the sarcasm there, ogra_  :p sorry14:42
blackflowNeo4: what does that have to do? you mentioned MITM. TLS does not absolutely protect against MITM with the current CA model.14:42
ogra_m1dnight_, i'm never kiddng ... ;)14:42
Neo4not exists person who has motive to broken that shity store14:42
blackflowNeo4: do customers input credit card data in that store?14:43
Neo4blackflow: in 99% cases its protect14:43
ogra_m1dnight_, there is actually a current case where telekom.at stores passwords in clear text only and callcenter employees can see the first 4 chars in theit UI14:43
m1dnight_jezus :p that's horrible14:44
ogra_one would think such a big company would know better :)14:44
Neo4blackflow: who indentionaly want kill you something like USA gavernment of course they decrypted it, bride VPS host and get privet key or will use other ways14:44
Neo4Who want you they find ways hit you14:44
Neo4but you don't need those people, TLS enough secure for our aims14:45
blackflowNeo4: do you intend to operate in EU?14:45
Neo4blackflow: they want, they will leave their phones and data where deliver product, then manager will call them and will give bank number where they will pay and then they will send product14:46
blackflowand, will customers input credit card data through that connection to the webstore, even if you don't store the CC data locally?14:46
Neo4blackflow: or send product and then user pay on the postofice,14:47
blackflowso, no CC payments?14:47
Neo4its for Ukraine clients, I haven't learned schemes how it works yet14:47
Neo4blackflow: no, in Ukraine exists 'private bank' they has his own pay and when you order something little manger call you and then send SMS with account number14:48
Neo4you send there money and recall manager, then he send product,14:48
Neo4but he offer you pay in time getting in the post office, you can pay immidiately or when it arrived14:49
Neo4blackflow: they also afraid whether you pay or not14:49
Neo4blackflow: Here not like in Amazon or Ebay, you must pay instantly14:49
Neo4but I'm going to do online stores on WP for English people as well, for other client, need to learn their pay systems14:51
Neo4we deviated from theme... :)14:51
Neo4well, as we see this domain not popular here, all users prefer use command line, and even barely heard about them...14:55
Neo4I always though in ubuntu server must sitting users who work with web hosting14:55
m1dnight_Neo4: i think we can conclude that most people will either use the commandline, or roll their own CMS for webhosting.14:56
Neo4it's like "who don't know they are speak and who know they are silence"14:56
m1dnight_It has been mentioned *numerous* times at this point, that most of the free webpanels out there are unsecure heaps of crap. If you want to use one, make sure you use a secure one, but my guess is you won't find one.14:56
Neo4m1dnight_: yes, more easier command use command line14:56
blackflowthe webhosting standard is cPanel, but that doesn't run on Ubuntu.14:57
Neo4m1dnight_: ok, I will be know14:57
Neo4blackflow: why?14:57
blackflowwhy what?14:57
Neo4Cpanel could be run on any Unix like OS?14:57
blackflowno, only CentOS14:58
Neo4Ok, I didn't know that14:58
blackflowIt used to run on Debian iirc, but for several years now it's CentOS only.14:58
Neo4I used ISPmanager on ubuntu14:58
blackflowwell... like m1dnight_ said, the free ones are unsecure heaps of...14:59
Neo4it was when I first time install my VPS I bought it with ISP, there had to pay for license14:59
blackflowThere is also VestaCP but I know little about it. Supposedly runs on Ubuntu.14:59
blackflowthing is, if you want to get into webhosting industry, you really have just one choice - cPanel or Plesk. The users will require it, especially for one-click migrations, even if you had something else.15:00
blackflow(one choice = I meant one set of choices, between the two)15:00
blackflowThe VPS industry is a bit different. There's Proxmox, and of course VMWare proprietary stuff, as well as OpenStack.15:01
Neo4blackflow: see, ISP manager is secure? We can for not serious client use not secure opensource panel cause we won't have motivated serious adversaries, and for good client that I think I won't have we could use Cpanel15:01
blackflowNeo4: however, definitely not something you should be getting into WITHOUT years of experience administering servers WITHOUT panels.15:02
Neo4blackflow: yes, it's broad domain15:02
Neo4blackflow: do you know people who has lack of knowledge for them it's difficult even use Cpanel15:03
Neo4ordinary people know only how to turn on computer and sing in in social network15:03
blackflowordinary people do not buy hosting services. webmasters do.15:03
Neo4it's majority, you need to orient on this sort of person15:04
tomreynthe only way you should start a shared web hosting business in 2018, if at all, is with a deployment framewórk aat its core, with a light user self service web panel as a frontend to queue tasks.15:04
blackflowbtw, I'm in the hosting industry since early 2000s.15:04
Neo4blackflow: if person has some little busness he can order online store for 200 - 300$ and have hostingtoo15:04
Neo4they buy15:04
blackflowyes, that's software as a service, SaaS. you can buy turnkey Magento solutions for that, for example, and iirc it can even get cheaper than that, to start with.15:05
Neo4it's not true, not everybody has money to hire personal, even average bussnes, Who has money they will appeale to real good firms for do shop, not for you15:05
blackflowNeo4: yeah but what are we talking about here? What do you want to offer? What kind of service? shared hosting with a panel for webmasters? managed online store SaaS? what?15:06
Neo4tomreyn: I watched on youtube there you can resell prapeared hosting15:06
blackflowyes, cPanel resellers. Cheapest and most numerous.15:06
tomreynNeo4: so you're business will be based on watching youtube videos?15:07
tomreynok i guess that's off topic here, i won't push this further.15:08
Neo4blackflow: yes, online store on wordpress, registered domain, and VPS with cpanel, + TLS certificate, Client pay me for example 300$ and I did these all and in the end give him all access to site and instruction how to use it15:08
blackflowwordpress is a blog platform. you should not be basing an online store business on it. There are far better tools, specialized, and far more secure, than WP.15:08
Neo4blackflow: it could be not bad bissness, I watch firms that do sites from 1000$, but for start we can take 200 - 300 untill will well work scheme15:08
Neo4blackflow: no, it has woocomerce, that is the moust popular online store platform for a while15:09
blackflowall based on wordpress?15:09
Neo4tomreyn: yes, buy prapered theme on themforest, put to wordpreess, install woocomerce and all needed plugins, write config and site is done15:10
blackflowNeo4: see, that's the problem, you lack experience. all those WP modules are hacks atop of a blogging platform. Take a look at their code internally and you'll see why that is. Encoding fields as [tags] in the main "body" of a "post" to simulate data....15:10
blackflowWP is a blogging platform. If you want to get serious about online shops, there's specialized tools designed for that.15:11
Neo4blackflow: there don't need programming nothing, only customization, of course you need know CSS and HTML15:11
blackflowjust because everyone and their dog rush to WP (and most of them regret installing random plugins), that's another story.15:11
Neo4blackflow: no, you understand nothing, I see you dont know anything about wordpress15:12
blackflowif you say so.15:13
Neo4blackflow: https://wordpress.org/plugins/woocommerce/15:14
Neo4blackflow: the most popular shot in the world for a while15:14
blackflowmost popular based on what audit?15:15
Neo4the bigest number of shotps use woocomerce as well as the biggest number of sites use wordpress15:15
Neo4blackflow: I forgot, I read about that in some blog, or in book, It's not precise data15:16
blackflowyou mean it's random, unverified and you don't even have the source of it. Got it ;)15:19
blackflowNeo4: but okay. you seem to know all what you need and want to use. Good luck in your business.15:19
Neo4blackflow: Thank, I know what I need, but I stupid to implement it...15:20
blackflowthen start playing with it. after a while you'll gain knowledge and experience.15:24
Neo4I'll try15:25
boxrickI would like to pull a package and all associated dependencies, but rather than install them throw the debs on my package mirror15:51
boxrickIs there a simple way, other than finding each dependency and manually getting each one15:51
rbasakboxrick: I would use chdist and --download-only for that.15:52
boxrickAny example commands, or shall I just look through the man pages?15:53
Neo4boxrick: what do you want to do? Remove dependencies?15:54
boxrickIn this case, I want to download a package, all its dependencies and throw it into an aptly repo15:54
boxrickaptly ( package mirror )15:54
Neo4what read about DNS? I badly know how it works16:29
Neo4want to improve knowledge16:29
Neo4I've got this book16:31
Neo4is it good one? Worth to read it?16:31
Neo4that book looks like not my level16:32
ProCycleIs there a way to find out what or who deleted a folder? After rebooting my server /var/run/mysqld/ went poof. I checked my bash history and didn't delete it myself18:25
sarnoldare you sure you're looking in the right place? /var/run is a symlink to /run on my system, and /run is a tmpfs18:26
sarnoldit goes away *every* reboot18:26
ProCycleHmm good point. The problem is mysqld couldn't create a socket or pid file18:26
ProCycleHad to manually create the directory with the right perms18:27
sarnoldstrictly speaking, yes, you can install auditd rules to watch for unlink, rmdir, and rename syscalls, but you have to install the rules beforehand18:27
ProCycleI'll try rebooting and see if it does it again18:27
ProCycleHmm yep it's gone again. So I guess the question is why can't it create the file it needs?18:28
=== devil is now known as Guest61956
sarnoldanything in dmesg? mysql logs?18:29
ProCycleDidn't see anything in dmesg, checking elsewhere18:33
ProCycleThis seems to be a problem for two different machines with similar configurations18:35
ProCycleI think it narrowed it down to the fact that the default service creates that folder, but the mariadb@ services don't18:38
ProCycleProbably a bug I get to report... yay18:41
sarnoldif nothing else, the logs collected by the bug report tool may help point out the problem :)18:44
ProCycleI'm comparing /lib/systemd/system/mariadb.service and mariadb@.service and it is missing the step where it creates that directory18:45
ProCycleAmong other things18:45
ProCycleMissing this line18:48
ProCycleExecStartPre=/usr/bin/install -m 755 -o mysql -g root -d /var/run/mysqld18:48
ProCycleThanks for your help once again :) I'll take this up with the mariadb people18:50
sdezielProCycle: RuntimeDirectory=mysqld is probably better18:52
ProCycleI figure that's a holdover from init.d18:54
sdezielMySQL's service unit has:18:54
ProCycleOracle mysql?18:56
=== iarp_ is now known as iarp
ProCycleI'm going to add an override... once I can remember how to do it18:58
sdezielsystemctl edit $foo18:59
sdezielProCycle: yes, mysql as provided by the mysql-server package in Ubuntu18:59
ProCycleDoes it have a mysqld@.service file? Do they do the same in that one?19:03
ProCycleIt seems that RuntimeDirectory= gets deleted when the service stops so it wouldn't be appropriate for multiple services all using the same runtime directory19:04
ProCycleThough maybe a better way is to simply create a /var/run/mariadb%I directory for each19:05
sdezielProCycle: with MySQL on Xenial, there is only 1 unit: https://paste.ubuntu.com/p/ktv9Np5GPF/19:07
ProCycleAh so to run multiple instances you need to use mysqldmulti or whatever it was called19:07
sdezielI guess so19:08
ProCycleI like mariadb's way, it's so much easier to manage through systemd instead of yet another manager19:08
ProCyclesans this one bug19:09
=== devil is now known as Guest55708
ahasenacknacc: do you have a moment to review https://code.launchpad.net/~ahasenack/ubuntu/+source/autofs/+git/autofs/+merge/343237 ? It's a simple revert of the immediate previous change and fixes a segfault. Test included in the mp19:51
ahasenacknacc: I can then start reviewing g-u again19:51
naccahasenack: looking19:52
naccahasenack: you've already tested this, i assume? do you need me to upload?19:53
ahasenackyes and yes19:53
naccahasenack: ok one moment19:53
ahasenackbug reporter confirmed that not linking with tirpc fixes it for him, and I confirmed as well19:54
ahasenackand you can try the test case, it's quick19:54
ahasenackthe ppa built the debs already, they are just not published yet19:54
ahasenackI used wget https://launchpad.net/~ahasenack/+archive/ubuntu/autofs-no-tirpc-1745817/+build/14756265/+files/autofs_5.1.2-1ubuntu3~ppa1_amd64.deb19:55
naccahasenack: looks good20:01
ahasenacknacc: did you try it?20:01
naccahasenack: yeah20:02
ahasenackif I had more time, that would make an excellent dep8 test20:02
ahasenacknacc: I'm starting with https://code.launchpad.net/~nacc/usd-importer/+git/usd-importer/+merge/34314320:13
ahasenacknacc: I have to run to an appt in a few, but I'll continue when I'm back20:13
naccahasenack: sure, thanks21:57

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!