IRC Logs for #crux-devel Sunday, 2015-07-26

Romsteri need to get onto updates.04:53
Romstergod damn it... why are we using mkdir instead of install -d04:55
Romsterthe former messes up on umask04:56
Romsteron footprints.04:56
teK__I dont speak awk but checking the Pkgfile for mkdir calls in prtverify should be easy09:12
teK__for starters09:12
juefrinnst: ok, will do09:14
juebtw, I'm still using jfs on two very old boxes09:16
jueif we continue to ship reiserfsprogs and jfsutils on our ISO we should keep it in core, otherweise someone else has to take over maintenance09:18
juefrinnst: we build ncurses two times, one time with widec the other one without; it's easier to keep both builds in sync with that variable09:21
jueRomster: good call, we should change that for 3.209:30
Romsterthat'll be nice. :)09:30
juethe team is defined here ->
Romsterjaeger, we need to make sure we get the right docs in the iso this time. last time they pointed to the previous release.09:47
teK__jue: I know that page. All of them/us?09:53
teK__alan actually commited something this month :)09:54
teK__so the list is _not_ outdated.09:54
jueyes, the page is up-to-date now, I just removed the retired contributors09:58
teK__hehe, I thought so09:58
frinnstteK___: lighttpd 1.4.36 was just released13:07
frinnst <- quick ssd initscript for lighttpd13:16
frinnstalso, installing an empty pid-file is probably a bad idea :-)13:31
frinnstncurses moved and lilo fixed14:49
teK___escape all strings for logging15:57
teK___RedHat is bitching about their brain dead userhelper vuln :D15:59
teK___fun starts at
teK___do we have a templade ssd-based rc script somewhere in our wiki?16:01
teK___and I think I touched the pid file for a reason.16:02
teK___done (
frinnstheh yeah I was reading that yesterday16:37
frinnstIm all for full disclosure but this was a bit stupid I think, actually16:37
frinnstsince there were no patches availabe for centos when i started my weekend16:37
teK___as stupid as the fact that libuser exists? :\16:38
frinnstyeah, stupid all around16:38
teK___but yeah, disclosure has to happen responsibly if done by a company16:38
frinnstI should probably patch our centos machines..16:39
teK___what's the usage profile of these?16:40
frinnstno ssh/login customerfacing16:42
frinnstjust some dns and smtp relays16:43
teK___well if there's a non-privileged daemon that's compromised you get your box popped as root16:43
teK___so yeah you should update but not on a Sunday :)16:43
frinnstno patches available so I guess its not installed?16:45
frinnst<3 ansible for patching16:45
teK___I didnt look at the code but from the description, the fix should be simple?16:45
teK___hehe, I guess. How many machines are there?16:46
frinnstnot many centos. most are debian16:46
frinnstjust 5 centos or something16:46
frinnstthe guy complaining about the exploit works here:
frinnsthe has a few nodes to patch :)16:57
teK___then he hopefully has some patching machinery in place :]16:58
teK___we earned a certain reputation <317:01
teK___btw.. my iwlwifi firmware issues went away (I had to wait 60 seconds for wlan0 to appear) with *some* kernel update17:02
frinnstmy kvm/spice issue with keyboard lag went away in a kernel update too17:02
frinnstnow my yubikey works again - no need to paste between host and guest17:03
teK___sounds a lot nicer17:03
teK___I added google authenticator + an android app to serverop17:03
teK___not bad either but a bit messy because the workflow looks like this:17:03
teK___unlock phone with pin17:03
teK___start gauth app17:03
teK___ssh serverop17:03
teK___Enter Keyphrase17:04
teK___enter password17:04
teK___enter 6 digit pin code17:04
teK___the mobile pin and keyphrase are optional but necessary imho, according to the howto I need local password auth to have this work (???)17:05
frinnstwe use yubikeys + authlite for windows ad integration for our management network. no dependency on a working wan (if shit really hits the fan)17:05
teK___I only need connectivity to serverop for this work, too17:06
frinnstoh? I thought you were dependent on a 3rd party server17:07
teK___the PIN generation is time based17:07
teK___i.e. the pin generator works offline too ;-)17:08
jaegerwatching while I work on the ISO updates some more17:15
jaegerHrmm, I think I need to go ahead and build a 3.2 ISO building VM to make this all smooth17:40
teK___we are going to have fun with the Dr20:12
frinnstfredrik@nibbler:/usr/man$ du -sh21:19
frinnstnot that much to go :)21:19
