/srv/irclogs.ubuntu.com/2018/11/05/#ubuntu-server.txt

=== cpaelzer__ is now known as cpaelzer
lordievaderGood morning09:20
rbasakkstenerud: if you're still looking for bugs, bug 1581864 might be an interesting one to tackle.10:18
ubottubug 1581864 in nginx (Ubuntu) "nginx.service: Failed to read PID from file /run/nginx.pid: Invalid argument" [Low,Confirmed] https://launchpad.net/bugs/158186410:18
rbasakUnless teward is already working on it?10:18
rbasakahasenack: see bug 1677755. Maybe worth updating the bug with Disco inclusion staus (I know it's still closed, but is a branch pending somewhere?)10:21
ubottubug 1677755 in backuppc (Ubuntu) "Missing dep8 tests" [Wishlist,New] https://launchpad.net/bugs/167775510:21
rbasakcpaelzer__, kstenerud: I think bug 1800040 can be low prio as it's armhf only. Shall I communicate that with the repoerter and then leave it ("patches welcome")?10:24
ubottubug 1800040 in bacula (Ubuntu) "bacula-fd segfault on status client from Bat" [Undecided,New] https://launchpad.net/bugs/180004010:24
cpaelzer__rbasak:  hiho10:29
cpaelzer__rbasak: you can do so (downpedal the bug to low)10:29
cpaelzer__rbasak: there were too much tests for me to get a good overview what exactly was affected eventually10:29
=== cpaelzer__ is now known as cpaelzer
cpaelzerI would have needed the time to really read into it10:30
cpaelzerand that is what I asked karl to take a look10:30
cpaelzerif it really is only armhf that is affected I agree it is not too important then10:31
rbasakcpaelzer: done, thanks10:33
rbasak(every failure report has armhf in it, AFAICT)10:33
rbasakIf I'm wrong, I'm sure he'll get back to us.10:33
ahasenackkantlivelong: I got it working on plain ubuntu, btw10:34
cpaelzerrbasak: thanks10:34
ahasenackthere is a search order for the host's keytab10:34
ahasenackkantlivelong: did you check the rpc.gssd manpage? It lists the principals it looks for10:35
ahasenackI had a host/<fqdn>@ key for the nfs client10:35
ahasenackkantlivelong: check /etc/hosts and /etc/hostname on both machines, I think what is different is the output of "hostname -f" and those files could be setting that10:36
ahasenackkantlivelong: I found #1616123 while experimenting, btw. triplicate-filed bug, since xenial (aka, introduction of systemd) :(10:37
* ahasenack wonders who owns nfs server packages10:37
cpaelzerahasenack: you know how that works, now it is you :-)10:50
ahasenackhehe10:51
ahasenackthree bugs in nfsv4 server with kerberos, I'm a bit surprised, more people use that than I expected10:51
kstenerudrbasak: I've posted a summary on the bug page for what's tested and what failed. It looks like the critical element is bacula-fd on armhf.10:55
TJ-ahasenack: if you find out who owns nfs, please ask them to deal with Bug #1697339 too10:56
ubottubug 1697339 in nfs-utils (Ubuntu) "rpc.gssd performs reverse DNS by default (regardless of -D flag)" [Undecided,Confirmed] https://launchpad.net/bugs/169733910:56
cpaelzerahasenack: your acpi MP could also contain the adding of comments for dirmngr10:59
cpaelzerthe updates on the task read as if it is resolved (would be auto-installed but we want to keep it explicit)10:59
cpaelzerif that is correct we'd want to add that as a comment I think10:59
ahasenackcpaelzer: I was planing on doing one MP per package11:02
ahasenackTJ-: thanks, I'll take a look11:06
TJ-ahasenack: had a few users report that on 16.04; I helped one such last week rebuild the packages locally with the patch because they had 10s of systems affected11:07
DenBeirenis anyone around to help out with a transmission-daemon issue?11:32
lordievaderDenBeiren: What is the issue?11:55
=== cpaelzer__ is now known as cpaelzer
ahasenackcpaelzer: have you seen this before? https://pastebin.ubuntu.com/p/Hf34BhDnN4/12:14
ahasenackcpaelzer: it's my first multipass launch12:14
ahasenackbut the files it complained about are in qemu12:14
ahasenackmight be another case of a classic snap not working in an ubuntu release different from where it was built12:14
cpaelzerahasenack: these are .so's that break out certain functions of qemu12:19
cpaelzerahasenack: you can that way reduce your attack surface from guests, or put only some of them in main12:19
cpaelzerahasenack: seems to be an incompatibility of your systems .so's with what is in the snap ?12:20
cpaelzerI thought LD magic should avoid that12:20
DenBeirenlordievader: i had a working system that borked,.. so i removed it, purged all packets, removed the dir and tried a reinstall.12:22
DenBeirennow it seems if i stop, edit the settings, start and check, none of the settings are changed12:23
DenBeirenaltough the settingsfile is correct afaik12:23
DenBeirenchange of port for example,.12:23
lordievaderAre you editing the correct settings file? It might be that in an update the path changed.12:23
lordievaderI had at one time three possible paths...12:24
DenBeiren/etc/transmission-daemon/settings.json12:24
ahasenackcpaelzer: I pinged #multipass12:24
ahasenackmight open a bug12:24
ahasenackkstenerud: where are multipass bugs opened again?12:25
lordievaderDenBeiren: What is the output of `systemctl cat transmission-daemon.service`?12:25
DenBeirenhttps://pastebin.com/Fv9MS3x712:26
kstenerudahasenack: On their github issues page12:27
ahasenackthx, got it12:27
lordievaderDenBeiren: Does `/var/lib/transmission/config` exist?12:28
DenBeirenhttps://pastebin.com/aya2CbJ812:29
kantlivelongahasenack: hmm il have to check again. i had host/ and nfs/12:33
ahasenackI have nfs/ for the server12:33
ahasenackand the client has host/<fqdn>12:33
ahasenackbut check the output of hostname -f12:33
ahasenackon both sytems12:33
ahasenacknormally just "hostname" should be a name without dots, and "hostname -f" should be the fqdn12:33
kantlivelongright12:34
ahasenackfreeipa has a different opinion, fwiw12:34
kantlivelongyou used the variable mentioned in that ticket?12:35
kantlivelongdidnt see any opts that applied12:37
ahasenackwhat variable?12:38
ahasenackyou mean bug #1616123 ?12:38
ubottubug 1616123 in nfs-utils (Ubuntu) "rpc-svcgssd.service uses incorrrect variable SVCGSSDARGS" [High,Confirmed] https://launchpad.net/bugs/161612312:38
kantlivelongyeah.sorry im mobile12:41
ahasenackkantlivelong: that bug is embarassing, it's been out there since xenial12:42
ahasenackkantlivelong: I will fix it12:42
kantlivelonghappens12:42
kantlivelongim going to check everything again tonight when i get home12:43
kantlivelongoh and duh thats for nfs-server. shouldnt be affecting me anyway12:44
ahasenackit's for that svcgssd service in particular12:45
ahasenackbut yeah12:45
ahasenackthe client runs rpc.gssd12:45
ahasenackboth do12:46
ahasenackanyway12:46
ahasenackfound some other bugs about nfsv4 in the nfs-utils package, while looking at that one12:46
kantlivelongright. but it wouldnt use the options from nfs-kernel-server on a client would it?12:46
ahasenacknope12:47
ahasenackkantlivelong: have you tried storing the kerberos tickets in the kernel keyring? I found a bug about that, looks like rpc.gssd can't read it12:48
ahasenackI flagged it for further investigation, see what's going on upstream, what alternatives there are, check fedora, etc12:48
kantlivelongahasenack: is that available in 16.04? i thought that was something new in later veraions12:48
ahasenackoh, I didn't check that12:49
ahasenackI mean, the bug is against 16.04, so kerberos itself can probably store it12:49
ahasenackbug #173357112:49
ubottubug 1733571 in nfs-utils (Ubuntu) "unable to access kerberized nfs4 shares with keyring ccache" [Undecided,Confirmed] https://launchpad.net/bugs/173357112:49
kantlivelongi did notice in my logs that it looks for machine ticket using the fqdn12:49
kantlivelongor maybe you noticed that. cant remember haha12:50
ahasenackjust check what hostname -f returns, it's the most likely source for the <hostname> bit in the ticket. I didn't see anything in the manpage about it being the shortname once, and later versions wanting the fqdn12:50
kantlivelongbut from what i can tell there isnt a way for me to to generate an entry with that many characters12:50
ahasenack(the keyring question I brought up is about something else entirely, sorry for crossing the streams)12:51
ahasenackit was just one of those bugs I saw while looking at the state of the package12:51
kantlivelongim just grateful that your taking a look. i was going insane12:52
lordievaderDenBeiren: Does that .config also exist when transmission is not runnign?12:54
DenBeirenlordievader: i believe it is13:09
DenBeirenhttps://pastebin.com/AW168bxj13:09
GekkoHow could I configure netplan / systemd-resolved to prefer any DHCP based DNS servers, but fallback to hardcoded DNS IPs if none are found working via DHCP? I've tried adding DNS=x.x.x.x into /etc/systemd/resolved.conf, but that seems to override any DHCP based DNS13:14
GekkoI'm trying to make this system manage DNS configuration in any network it's plugged into, regardless of if the local LAN offers DNS or not13:15
GekkoUbuntu server 18.0413:15
GekkoSo far the cases I've had involved all public DNS IPs being blocked in the network, and configured LAN DNS not working13:17
GekkoBut never both13:18
kstenerudDoes anyone know how to build debian packages using git-buildpackage? I'm using https://wikitech.wikimedia.org/wiki/Git-buildpackage as a guide, but it errors out right at the start :/13:18
TJ-Gekko: maybe you can use netplan's "optional" and "optional-addresses" ?13:21
GekkoI'll read about them, thanks13:22
TJ-Gekko: I suspect those only apply to the IP address allocation itself though13:22
kantlivelongahasenack: hostname -f returns the right fqdn, hostname shows fqdn, hostname -s shows shortname13:24
kantlivelonglooks right13:25
ahasenackin both machines?13:25
kantlivelongboth clients or server and affected client?13:25
kantlivelongits right on the server13:26
ahasenackthe client that can't mount13:26
kantlivelongyeah its valid13:26
ahasenackok13:27
TJ-Gekko: I think you're better off doing it directly in systemd-networkd config; using "UseDNS=True" (the default) DHCP addresses take precendence over manually set addresses13:27
ahasenackkantlivelong: so the complaint on that client was that the principal it selected from /etc/krb5.keytab wasn't found on the server datbase13:27
kantlivelongahasenack: server meaning krb5 server?13:27
ahasenackyes13:27
kantlivelongits certainly there13:27
kantlivelongmatches the working client13:28
kantlivelong(minus the shortname of course)13:28
kantlivelonghttps://i.imgur.com/BiHL3Bf.png13:30
ahasenackfrom your earlier pastebin,13:30
ahasenackit's looking for these in /etc/krb5.keytab, in this order:13:30
ahasenack1) ADTESTUBUNT.XXX.YYY.ZZZ$@XXX.YYY.ZZZ13:30
ahasenack2) root/adtestubunt.xxx.yyy.com@XXX.YYY.ZZZ13:30
ahasenack3) nfs/adtestubunt.xxx.yyy.com@ <--13:30
ahasenackit found the 3rd13:30
kantlivelong#1 is where i have concern13:31
ahasenackand then says13:31
ahasenackWARNING: Client 'nfs/adtestubunt.xxx.yyy.com@XXX.YYY.ZZZ' not found in Kerberos database while getting initial ticket for principal 'nfs/adtestubunt.xxx.yyy.com@XXX.YYY.ZZZ' using keytab 'FILE:/etc/krb5.keytab'13:31
kantlivelongshouldn't it be looking for ATESTUBUNT$@XXX.YYY.ZZZ?13:31
ahasenackthe manpage just says "<hostname>", without detailing if it's the fqdn or not13:31
kantlivelongthe shortname is certainly there13:32
kantlivelong:/13:33
kantlivelonghave to head to work now tho13:33
ahasenackon my ubuntu client, it does look for the short name as well13:34
ahasenackI mena, ubuntu 18.0413:34
ahasenackkantlivelong: https://pastebin.ubuntu.com/p/6pb4GCRWjm/ it stopped when it found the host/ key13:34
ahasenackit's what I'm using13:34
ahasenackgssd_get_single_krb5_cred: principal 'host/nsnx.lowtech@LOWTECH' ccache:'FILE:/tmp/krb5ccmachine_LOWTECH'13:35
ahasenackand I actually have the key with the fqdn in the keytab13:35
kantlivelongodd.13:36
ahasenackso how come you have nfs/adtestubunt.xxx.yyy.com@XXX.YYY.ZZZ in the keytab, but no such principal exists in the kdc?13:36
kantlivelongim not asking you to or anything but i wouldnt object if you had interest in hopping on the boxes13:36
kantlivelongthe nfs/fqdn is definitely there13:37
ahasenackcan you kinit that principal?13:38
ahasenacklike13:38
ahasenackkinit -V -t /etc/krb5.keytab -k <principal>13:38
ahasenackfor example, here:13:38
kantlivelongon the client or ad?13:38
ahasenackkantlivelong: https://pastebin.ubuntu.com/p/ZhgVs5cw7B/13:38
ahasenackclient13:38
ahasenackon that machine where rpc.gssd failed13:38
ahasenackusing nfs/adtestubunt.xxx.yyy.com@XXX.YYY.ZZZ as the principal13:39
ahasenackbecause that's what rpc.gssd tried to do, after finding nfs/adtestubunt.xxx.yyy.com@XXX.YYY.ZZZ in the keytab13:39
kantlivelongill give it a shot13:39
GekkoTJ-: thanks, I'll see if that does it. I had to remove some entries from /etc/systemd/resolved.conf as apparently there can be too many, says systemd13:40
GekkoRight now I'm getting nameserver 8.8.8.8 followed by nameserver local_ip_here in /run/systemd/resolve/resolv.conf, so maybe it's good enough13:41
TJ-ahasenack: this might be useful for you, a patch that landed for 1.2.9. The commit messsage is insightful: http://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=bdc50fc12a621545feaf9925999723d45171c34d13:43
TJ-ahasenack: bearing in mind the issue is on 16.04 with 1.2.8, and 18.04 has 1.3.413:43
ahasenackand upstream is past 2.x13:43
TJ-ahasenack: 1.2.8 was 2013 :)13:44
TJ-there is a 2nd commit immediately before ^^ that one with the same commit message:  http://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=a6ab6f63de618180127daadc070d696f6268000f13:45
TJ-ahasenack: I'm looking at the commits pre 1.2.9, listed at http://git.linux-nfs.org/?p=steved/nfs-utils.git;a=shortlog;pg=513:45
ahasenackTJ-: the order in which it looks up the principals (line 126+ in https://paste.ubuntu.com/p/GZqqcGgsvk/) matches the rpc.gssd manpage13:46
TJ-here's another one, talking specifically about the fqdn/hostname http://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=05e6d39a988e76d5803f79018a9e40d435f6d2f713:47
ahasenackI don't know what the target= field is that he mentions13:47
ahasenackkantlivelong: all that being said, let me try on xenial, I've been trying with bionic as the client13:48
ahasenackkantlivelong: worked with a xenial client as well: https://pastebin.ubuntu.com/p/Htpvgq6fy4/14:10
TJ-ahasenack: "target=" refers to the part to the right of the @, the realm, I thinik, from looking at the code (where service is to the right of the @)14:17
ahasenackit's @REALM, yep14:17
ahasenackit's something like <name/someoptionalqualifier@REALM>14:17
=== lotuspsychje__ is now known as lotus|NUC
rbasakahasenack: https://code.launchpad.net/~racb/usd-importer/+git/usd-importer/+merge/358334 please, to put the git-ubuntu fire out.17:08
ahasenacksaw it17:08
ahasenackrbasak: you are using the +build path from launchpad because this package is not in discoyet?17:08
rbasakahasenack: it is actually in Cosmic. But that will end up in oldreleases. Launchpad will last longer.17:09
ahasenackrbasak: I think you can use http://archive.ubuntu.com/ubuntu/pool/main/u/ubuntu-keyring/ubuntu-keyring_2018.09.18.1_all.deb, is that better?17:10
ahasenackor not, for the reason you just mentioned17:10
ahasenackkstenerud: did you get your debian mysql build issue sorted out after standup?17:11
ahasenackrbasak: my master (and I updated, I think?) doesn't have test_gpg_public_key_list() in gitubuntu/integration_test.py, do you know what's going on?17:16
ahasenackhttps://git.launchpad.net/usd-importer/tree/gitubuntu/integration_test.py also doesn't17:17
ahasenackoh, wait17:18
ahasenackok, n/m17:18
ahasenackwas confused by a commit message17:18
rbasakBTW CI is still running.17:22
rbasakBut I've tested a full build/CI run locally, etc. I will wait for the official one before merging.17:23
rbasakahasenack: thanks!17:47
granjerohi, ubuntu server 18.04 fstab looks quite empty. is still working for mounting windows shares at startup?20:18
cryptodan_mobilegranjero: https://www.hiroom2.com/2018/05/04/ubuntu-1804-cifs-utils-en/20:19
kantlivelongahasenack: hmm. cant kinit on either the working or non-working box. have to do it from ad22:41
kantlivelongi might have found hte issue.. will check23:03

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!