libera/#devuan/ Wednesday, 2019-01-23

BeerbelottI remember having wondered why packages were not delivered over HTTPS ans at the time I got replied the GPG signature of the packages themselves was sufficient00:01
Beerbelottpackages chain-links pwned :)00:02
KatolaZBeerbelott: even if they were delivered via https, youwould have been vulnerable anyway00:02
KatolaZ'cause the bug is in the way "Location" headers are handled by apt00:03
KatolaZand this has nothing to do with https, or lack thereof00:03
KatolaZmore details in the CVE00:03
BeerbelottKatolaZ: It is said HTTPS would have helped as to forge the redirect the attacked would also need to have his hands on the server's certificate, not merely intercept/tamper with packets on a network (never trust it)00:28
BeerbelottThere is a dedicated part of the blog post about it: https://justi.cz/security/2019/01/22/apt-rce.html00:28
Beerbelottattacker*00:32
Beerbelotttl; dr does not solve the core problem, correct, but greatly reduces attack surface00:33
Beerbelottit's the same plain old debate HTTP vs HTTPs to me, uness I missed sth?00:33
drwhiteHi folks, I'm having serious issues with LibVirt and it having access to things. Even XEN can't do things that is has to.00:36
drwhiteIs this just an issue because of the security on Devuan?00:38
drwhiteIt's run as root00:38
rwpHello drwhite. I am just another user but what specifically are you having problems with? What issues are you having?00:39
drwhiteLibvirt can't access the certificate that is there.00:40
drwhitevirtualbricks can't detect qemu version00:40
drwhiteqemu can't run with XEN.00:40
drwhiteWehter admin or not.00:40
rwpThose are pretty vague descriptions.00:40
drwhiteThey are just t he first things.00:41
drwhiteand they aren't vague00:41
drwhitethey are specific.00:41
drwhitethey are 3 issues00:41
drwhiteis there anyone that can assist with those issues or any one of them please?00:42
drwhiteI have no idea what is going on, it should work, but isn't.00:42
BeerbelottCorrect me if I'm wrong, but I guess rwp would like to know commands and the associated errors? Mb a paste is in order?00:43
drwhiteFirst issue, not one that I listed.. This one is related to SPICE using LibVirt...00:48
drwhitenable to complete install: 'internal error: unable to execute QEMU command 'set_password': Could not set password'00:48
drwhiteTraceback (most recent call last):00:48
drwhite  File "/usr/share/virt-manager/virtManager/asyncjob.py", line 88, in cb_wrapper00:48
drwhite    callback(asyncjob, *args, **kwargs)00:48
drwhite  File "/usr/share/virt-manager/virtManager/create.py", line 2288, in _do_async_install00:48
drwhite    guest.start_install(meter=meter)00:48
* Jjp137 sighs00:48
BeerbelottI guess he is not coming back ^^00:49
Criggiedrwhite: do consider using http://pastebin.com/ or similar, rather than dumping a load of stuff in channel.   One line paste is fine, two is marginal, any more than 2 lines absolutely use a pastebin-like service.00:50
CriggieOh he hasn't rejoined yet..... *waits*00:50
Jjp137you should probably say that again when he comes back :p00:50
Criggie-grin-  I remember the days of auto-rejoin.....00:50
Criggiebugger me its 34 degrees outside.   *melt*00:51
rwpIt's -8C here.  And windy today.00:52
KatolaZ34 in which scale?00:52
Criggierwp: every wind can be a tail-wind.00:52
CriggieKatolaZ: celcius AND centigrade.  Not that impressive, but hot for here.00:53
rwpIt was quite a headwind driving home from playing in the snow in the mountains.  AWOS reporting 19kts gusting 29kts on the nose.00:53
KatolaZCriggie: you must be in NZ or AUS then00:53
CriggieI had to go home last night straight into a 30 km/h headwind at ~30 degrees C.  It was hard yakka.00:54
Criggienormal commute is 60 minutes - yesterday took 9000:54
Criggieground speed barely passed 20 km/h and not for long.00:54
CriggieI should put an airspeed gauge on my bike.00:54
golinuxIt was over nearly 70 F here today.  That's about to change01:17
golinuxWrong channel for that discussion though.01:18
watchcat"I wouldn’t have been able to exploit the Dockerfile at the top of this post if the default package servers had been using https." -- the guy who found CVE-2019-3462, https://justi.cz/security/2019/01/22/apt-rce.html02:40
buZzhttps://deb.devuan.org/ gives interesting results ;)02:45
g4570n!ping03:46
infobot1 packet transmitted, 1 packet received, 0.0% packet loss03:46
Xenguy!pong03:47
infobotping, or also https://en.wikipedia.org/wiki/First_video_game03:47
redrickCriggie:  Celsius AND Centigrade?  How very trans-temporal of you.  ;->09:12
redrickI'm officially-not-really awarding you credit for 50 kph pedalling.  Wear it proudly.09:17
watchcatis there any way to fix the broken apt without using the broken apt?10:14
gnarfacewget the package manually then install it with dpkg10:15
watchcatthat would be perfect. what's the url?10:19
gnarfacei didn't memorize it10:20
gnarfacepkgmaster.devuan.org something10:20
Jjp137here's the e-mail sent to DNG: https://lists.dyne.org/lurker/message/20190122.152406.07b05a4c.en.html10:21
redrickJjp137: Beat me to that by a few secs.10:23
redrickWell, maybe a minute or so.  ;->10:23
furrymcgeeare redirections of http://deb.devuan.org/merged logged?10:46
Wonka*sigh* Failed to fetch http://deb.devuan.org/merged/pool/DEBIAN/main/c/ca-certificates/ca-certificates_20190110_all.deb: 404  Not Found [IP: 131.188.12.211 80]10:46
iatrogenicHello. I've posted this issue before here but I'll restate. Some fonts were aliased, I installed microsoft fonts and it fixed most but the issue remains for websites that use Helvetica. Is there any missing fonts I have to install or is it just something related to this particular font?12:34
iatrogenichttps://unix.stackexchange.com/questions/145701/how-do-i-diagnose-a-font-rendering-problem12:35
iatrogenicIn this link they tell me to just replace it. But if possible, I would rather not alter the intended look of the websites I visit12:36
iatrogenicVerdana also seems aliased12:36
iatrogenichttps://i.imgur.com/mQNIjr3.png12:39
iatrogenicWell the first 5 do look the same to me12:40
Leanderdo you want to remove aliasing (and have your fonts look ugly), or do you need to adjust it because they look blurry on your monitor?12:51
iatrogenicLeander: They do not look blurry. They (now just Helvetica) look aliased, pixelated. I want them to look smooth15:20
jonadabSo what you want is to turn anti-aliasing on.15:41
caioauHello, I have devuan on my raspberry pi , and I installed in jully and never updated the kernel, Am I using a outdated kernel version? It's running Linux rpi 4.14.44+ #1 Tue Jun 5 20:32:40 CEST 2018 armv6l GNU/Linux Thanks16:09
_stephen_Anyone know off the top of their head how much space is needed to create a mirror?  I'm using rsync per https://files.devuan.org/MIRRORS.txt17:02
KatolaZ_stephen_: ISO mirror or package mirror?17:02
_stephen_Package mirror17:02
djphsome 2TB, IIRC for a package mirror.17:02
_stephen_Maybe I should just grab the packages for ascii, then...17:03
KatolaZ_stephen_: you are reading the wrong howto if you want to setup a package mirror then17:03
KatolaZthat's the howto for ISO mirrors17:03
_stephen_I just noticed that...17:03
KatolaZ_stephen_: https://pkgmaster.devuan.org/devuan_mirror_walkthrough.txt17:04
_stephen_THanks!17:04
KatolaZ_stephen_: the package mirror is currently around 20GB17:04
KatolaZthe reason is that packages that have not been forked by Devuan come directly from Debian17:05
KatolaZthrough an appropriate set of rewrites17:05
_stephen_So will I need a debian and a devuan mirror to use it offline?17:05
KatolaZ_stephen_: more information in the document I linked17:05
KatolaZif you want to use it offline, then yes17:05
r3bootI used to manage some debian package repo's (for debian squeeze). Repo size for amd64 was around 70GB back then17:06
KatolaZa full repo with all archs is far larger than that, tbh17:06
r3boot(main+contrib+non-free)17:06
r3bootoh, yes, indeed17:07
r3bootimho, a safe assumption is to allocate some 100GB per arch/release17:07
KatolaZhttps://www.debian.org/mirror/size17:07
KatolaZr3boot: it's not enough for i386 or amd6417:07
r3bootoh wow, things grew :O17:07
KatolaZthe whole thing is around 3TB for all arch and ports, apparently17:08
_stephen_Damn, this looks kind of involved, I was hoping I could just kick of rsync, serve the directory up via http, and have an offline mirror.17:08
KatolaZno _stephen_17:08
KatolaZyou can't17:08
KatolaZas I explained above17:08
KatolaZyou can crate a local mirror with debmirror or apt-mirror though17:09
r3bootwhat is iyt17:09
_stephen_Yes, as I'm reading.17:09
r3boot*what is it you're trying to achieve _stephen_?17:09
KatolaZI guess I posted some HOWTO on dev1galaxy a few months ago17:09
_stephen_To have packages available on an offline network.17:09
KatolaZ(maybe more than that, actually)17:09
KatolaZ_stephen_: use debmirror then17:09
r3boot.. one setup I used to run had squid in front of the repo's, with caching rules that picked up everything17:10
r3bootworked pretty well, but you will need special rules for various special files underneath the repo17:11
KatolaZ_stephen_: https://dev1galaxy.org/viewtopic.php?id=157117:11
KatolaZbut you don't actually need devuan-debmirror17:11
KatolaZjust plain debmirror17:11
KatolaZwith host=pkgmaster.devuan.org17:12
KatolaZand the appropriate keyring17:12
KatolaZ(it's at /usr/share/keyrings/devuan-archive-keyring.gpg)17:12
KatolaZ_stephen_: https://dev1galaxy.org/viewtopic.php?pid=7712#p771217:14
KatolaZthis is actually the most relevant reply I guess17:14
KatolaZ_stephen_: but please use $remoteroot="merged"17:15
_stephen_Hm.  Apparently you have to spell the config file name correctly.17:21
work25040Hello, I have devuan on my raspberry pi , and I installed in jully and never updated the kernel, Am I using a outdated kernel version? It's running Linux rpi 4.14.44+ #1 Tue Jun 5 20:32:40 CEST 2018 armv6l GNU/Linux Thanks17:22
KatolaZwork25040: do you have any issue in particular?17:24
work25040Katolaz I dont have any issue, I just find this as strange17:42
KatolaZwork25040: that do you find strange?17:43
work25040KatolaZ I been using it for mouths and the kernel havent been updated once17:44
KatolaZwork25040: the kernel will never be updated automatically, unless you have installed the package linux-image-$ARCH17:44
KatolaZand issued an apt-get upgrade17:44
KatolaZI would be surprised of the opposite, i.e., if the kernel was actually changed without me noticing it... :)17:45
fsmithred4.14 sounds like an old backports or testing kernel17:45
KatolaZI think 4.14 is the kernel available in the standard arm images17:46
fsmithredoh, maybe17:46
KatolaZbut parazyd might remember better17:46
fsmithredI'm only seeing amd64 here, but there's 4.17, 4.18 and 4.19 backports kernels showing up17:46
work25040KatolaZ thanks, I will do a apt search linux-image, I found this strange because I used to use raspbian and the kernel updated normaly17:47
parazydI have this on my todo17:47
parazydThe kernels don't update automatically.17:47
KatolaZwork25040: if you want to update the kernel, you should install linux-image-${ARCH}17:47
parazydWe'll need a separate repo section for all of the boards so we can build kernels on the CI.17:47
KatolaZe.g., linux-image-armhf17:47
parazydKatolaZ: I'm not sure it'll work out.17:48
KatolaZparazyd: if they have the raspberrypi repo, it should17:48
KatolaZ(but I might be wrong)17:48
parazydIn theory it should conflict with the existing files.17:48
KatolaZok17:49
parazydIn any case it's something to talk over with you. These days even.17:49
KatolaZok17:49
KatolaZanytime :)17:49
parazyd*nod*17:49
* KatolaZ nods17:49
work25040KatolaZ, parazyd Thanks17:50
* enyc meows17:54
DocScrutinizer05haha nice!  >>How many ad blocks could an ad slinger block if an ad slinger could block blocks?<<19:37
DocScrutinizer05wood pecker would peck wood...19:37
sixwheeledbeastcould block ads surely?20:15
DocScrutinizer05https://www.theregister.co.uk/2019/01/22/google_chrome_browser_ad_content_block_change/20:23
DocScrutinizer05aaand20:23
DocScrutinizer05https://securityboulevard.com/2019/01/wi-fi-chip-firmware-flaws-enable-over-the-air-hacking/20:23
* DocScrutinizer05 cringes20:25
furrywolfthere's a reason I don't use chrome.20:25
DocScrutinizer056 billion(!) WiFi chips using this ThreadX firmware20:26
DocScrutinizer056E920:27
furrywolfthis is also a good argument for why any project with a major corporate backer should be frowned upon.20:28
gnarfacedid something bring back the nice font rendering?  i'm looking at rendered fonts in firefox-esr today on ceres and something seems to have improved subtly... it seems like there's been a fix to the font rendering quality regression i mentioned some months back21:35
gnarfacei can't think of anything that might have changed other than basic package updates though21:36
gnarfacehas anyone else noticed this, or am i hallucinating?21:37
Criggieredrick: chur :)21:47
redrickIt's a balmy 17 degrees chez redrick.21:48
redrickGood weather for being balmy.21:48
HumanG33kand an other upgrade for libsystemd0 ^^23:23

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!