IRC Logs for #crux Sunday, 2017-06-25

brian|lfsmore info on stack clash02:24
brian|lfsI have no clue if we are patched for this or not
darfoif a NIC flips back and forth between enp3s8 and enp4s8 after power interruptions is it flaky hardware? I thought this shouldn't happen with udev.02:30
darfoI checked /etc/udev/rules.d and there is no rules in it.02:33
darfoand /lib/udev/rules.d/80-net-name-slot.rules is the default from core/eudev02:37
j_vbrian|lfs: it looks like we should be patched for the sudo vulnerability with that latest update to the sudo port. if i understand the descriptions for CVE-2017-1000364 and CVE-2017-1000365, the fix is upgrading kernel (cve document says that 4.11.5 and earlier are affected).03:06
j_vi updated to kernel 4.11.7 because since the changelog for that kernel documents for fixes for stack guard stuff. looks to have been backported to the 4.9 branch with 4.9.34, ifaict03:15
j_vs/because since/because/03:16
brian|lfsok so I should upgrade my kernel03:24
j_vi would recommend it03:26
j_vlooking at the release dates for recent kernels, it looks like the 4.11 and 4.9 are the only branches (other than 'next') that have been patched. just an observation that i can't prove03:30
brian|lfsok I"m patched03:52
brian|lfswonder if we need an e-mail announcement or an announcement ont he CRUX home page03:57
brian|lfseven announcement added to the welcome message people will see whent hey come in here04:03
j_vyou could send in a heads up to the CRUX ml. can't hurt04:05
frinnstdont you read the [notify] emails?04:07
j_vfrinnst: was there one about CVE-2017-100036{4,5} ?04:08
j_vi noticed the one about sudo for CVE-2017-100036704:09
frinnstsudo is patched, but there wasnt any public disclosure when it got patched04:10
frinnstso no notification was sent out04:10
j_vhmmm, you had something about it in the commit message, didn't you?04:10
frinnstI dont think so04:11
frinnstah, when p1 was updated yes04:11
j_vahh, looking at it now, i see that there wasn't. ok, thought i remembered it from somewhere04:12
Romsteri've compiled almost all of opt xorg and contrib and i have error logs and over 1000 built packages;O=D04:12
frinnstthats what we knew at the time04:13
brian|lfsif your running less then 4.11.5 update your kernl romster04:13
brian|lfsbad security vulnerability discovered04:14
frinnstnot really remote exploitable so no big worry04:14
Romsteri'm on 4.9 3304:14
Romsteri've been reading04:14
brian|lfsI think 4.9 may be patched04:14
frinnstdo you follow oss-sec brian|lfs ?04:15
*** tsaop has joined #crux06:32
cruxbot[contrib.git/3.3]: virtualbox: fix footprint08:25
cruxbot[contrib.git/3.3]: ffmpeg-compat: 2.8.8 -> 2.8.1208:25
cruxbot[contrib.git/3.3]: vlc: 2.2.1 -> 2.2.608:25
cruxbot[contrib.git/3.3]: slock: fix dependency08:25
cruxbot[contrib.git/3.3]: qiv: fix dependency09:09
cruxbot[contrib.git/3.3]: p5-berkeleydb: 0.43 -> 0.5509:09
cruxbot[contrib.git/3.3]: p5-asterisk: 1.03 -> 1.0809:09
cruxbot[contrib.git/3.3]: p5-class-std: 0.011 -> 0.01309:09
cruxbot[contrib.git/3.3]: p5-gd: 2.53 -> 2.6609:09
cruxbot[contrib.git/3.3]: p5-sdl1-perl: fix footprint09:09
just_funRomster, any chance to sign your CRUX-Store ? :D09:19
Romsterat some point09:20
Romsterso much stuff is broken -_-09:21
Romsteri haven't figured what key or make a new key or best way yet09:22
just_funWhy not ?09:22
Romsteri was thinking of using my one09:23
Romsteryou could pretty much install an entire deptree of ports from that collection in binary09:24
Romsterbut you will miss out on soft dependencies09:24
Romsterunless you rebuild those.09:24
just_funI know you have a huge collection, this is why I'm asking about sigs. I can't wait to enable the signature check in my pkgmk.conf patches for your "store". I already found two bugs there.09:27
Romsterwhat 2 bugs are that?09:27
just_funone was: after the pkg was downloaded, the signature was tried on all mirrors, including the source ones09:28
just_funthe other one is in by container-build-script: wrong signature name09:31
just_fun (function make_pkg_signature)09:32
Romstermake_signature() function and make it work for built packages09:32
Romstercrikey the complexity of that09:36
just_funThe ports are signed by the port's maintainer (make_signature), and the builds are signed by the "builder" (signing everything).09:39
just_funDo you say I should change make_signature to sign binaries too?09:39
Romsteri dunno, i have my own scripts for building and stuff09:44
just_funWell, signing your builds is one signify line away :)09:45
Romsteryeah true09:46
just_funI was thinking if using prebuilt packages when the build fails will be useful, as an option.09:46
Romsteri've done that a few times when something on my system is putting it off09:47
Romstersometimes libtool can be a pain with old references to a library version that's been updated.09:47
Romsterbut i've fixed those with sed09:48
just_funI do have my pkgmk.conf patches enabled, and one time I was suprised that I've downloaded a prebuild package from you :))09:48
just_funforgot about that09:49
just_funI was trying to build firefox on a 2GB mem machine09:49
just_funand it was fast :))09:49
just_funThis is why I was thinking to "improve" those patches to download only when fails :)09:50
Romsterwell i was only building the big slow ports at first.09:50
Romsteri just throw them at my distcc+ccache cluster09:51
just_funIt was good to hear you've build them all.09:52
Romsterwell most of them, there is still about 138 broken ports09:52
just_funYou've already done a huge work. 138 is nothing :)09:53
*** tsaop has joined #crux09:55
*** tsaop has quit IRC10:11
*** tsaop has joined #crux10:20
cruxbot[opt.git/3.3]: nano: update to 2.8.511:31
cruxbot[opt.git/3.3]: dar: update to 2.5.1111:31
cruxbot[contrib.git/3.3]: libva-intel: add missing dependency libva12:19
cruxbot[contrib.git/3.3]: keepassx2: 2.0.2 -> 2.0.312:19
Romster132 now just_fun12:21
Romstersome will be held back from a dependency being broken12:21
just_funRomster, do you count contrib too?12:22
just_funI'm thinking that there are 2 psychological levels: 128 and 64 :))12:23
cruxbot[contrib.git/3.3]: keepassx2: forgot to update signature after footprint12:24
Romsteri'm counting contrib compat-32 xorg and opt12:25
Romstersome of these errors are just missing dependencies12:26
*** tsaop has joined #crux12:27
cruxbot[contrib.git/3.3]: keepassx: add missing dependency xorg-libxtst12:28
just_funRomster, we are already in your debt. After that, some will go broke.12:33
Romsteri'm just sick of brokenness so i am doing something about it.12:34
Romsterneed to keep the quality of crux up not the quantity12:34
tsaopI should also polish my ports12:35
cruxbot[opt.git/3.3]: libunique: depends on gtk version 2 not 312:37
Romsteri have yet to get to romster collection12:42
cruxbot[contrib.git/3.3]: mpd: 0.20.6 -> 0.20.9 add boost at a dependency, move man pages to /usr/share12:45
Romsterwow that is old in xorg... wonder how that got missed.12:52
cruxbot[xorg.git/3.3]: xorg-xf86-video-openchrome: 0.3.3 -> 0.6.013:05
cruxbot[xorg.git/3.3]: xorg-xf86-video-xgixp: dropped last update in 201213:05
cruxbot[xorg.git/3.3]: xorg-xf86-video-newport: dropped last update in 201213:05
cruxbot[xorg.git/3.3]: xorg-xf86-video-v4l: dropped last update in 200813:05
cruxbot[contrib.git/3.3]: wyrd: move man pages to share, remove redundant dependency13:21
cruxbot[contrib.git/3.3]: camlp depends on ocamlbuild and removed redundant dependency ocaml13:21
*** xeirrr has joined #crux13:55
xeirrrRomster: I know sepen is the maintainer of virtualbox, but how about you update it to 5.1.22 since there are several fixes there?13:56
xeirrrI saw you updated its footprint.13:57
*** ubuuu has joined #crux14:04
Romsteryeah i did just do that.14:06
Romsteri'll look into it14:06
*** ubuuu has joined #crux14:08
*** xeirrr has quit IRC14:08
*** ubuuu has joined #crux16:29
*** tsaop has joined #crux16:30
*** Guest1705 has joined #crux16:46
*** tsaop has quit IRC18:31
darfo<darfo> ah, one of my two NIC's drivers is loaded as a module. Modules are loaded asynchronously.18:39
darfo<darfo> I'll see if changing it to built-in makes udev generate the same name after all power cycles.18:40
darfoput the above on the wrong channel18:40
darfoafter rebuilding the kernel and then a power cycle it flipped to enp3s8. Now to power cycle again and see what gives.18:42
darfo[    3.803708] 8139too 0000:04:08.0 enp4s8: renamed from eth118:50
darfohrm. making it built-in didn't help18:51
onoderahow dangerous is this?18:51
darfo"system misbehavior, data corruption, and data loss" sound pretty serious to me18:54
darfoso 80-net-name-slot.rules is renaming my interface for me but is using supplied info for the name18:59
darfoand that info is toggling on every power cycle.18:59
darfoi guess there some things I don't understand about PCI slots and the discovery the kernel does19:00
darfothe NIC built on to the motherboard never changes but the one in the expansion slot does19:01
darfoi keep hearing Inago Montoya saying "I don' theenk you know the meening of this word"19:02
jaegerchances are the chipset/bios enumerates differently when the expansion slots change19:02
darfobut I move nothing19:02
jaegerthat would indeed be strange, then. :)19:03
darfothis is just one power cycle to the next19:03
jaegerdoes lspci always show the same numbers/ids?19:03
darfoI haven't been checking but will going forward19:03
darfoi think the mobo is flaky19:03
*** onodera has joined #crux19:10
*** darfo has joined #crux19:20
darfodidn't change this time :(19:23
darfolooking at the old logs the pci numbers correspond to the the move and it changes the FireWire too19:34
jaegerthat sounds like a hardware/bios issue to me, though I'm no expert19:35
darfothe firewire is built-in19:35
darfoyeah, me too. might be time to start shopping for a mobo19:36
darfothis one is 2005 vintage so maybe I got my moneys worth out of it19:36
jaegeryeah :)19:45
*** tsaop has quit IRC20:46
vsteveis anyone here using the radeon driver?23:55

