libera/#devuan-dev/ Thursday, 2019-10-24

plasma41Notes sent to the mailing list04:45
LeePeno/10:14
LeePenThanks to jaromil for updating the build hosts.10:15
LeePenIs there somebody who has perms to retry the failed policykit-1-binary arm64 #73 build, please?10:17
LeePenOr give me the ability to trigger it? I don't think I can build for beowulf at the moment.10:18
LeePenThanks10:18
* rrq is a bit tired today .. but can do some fiddling ..10:54
rrqbtw I think I need to bump the version on util-linux.. it still got different version for i386 and amd64 (didn't update i386)11:00
rrqmight need to make it 2.33.1-0.1+devuan2~beowulf111:00
rrq(seems 2.33.1-0.1+devuan1~beowulf1 is not later than 2.33.1-0.1+devuan1 ?)11:01
fsmithredthe plus is mightier than the tilde?11:15
fsmithredis someone working on udisks2? We have an older version in beowulf/ceres that's incompatible with gparted.11:29
LeePenfsmithred: Yes, I have udisks2 in hand.11:44
LeePenrrq: thanks. amd64 policykit is fixed. :)11:45
LeePenMost of my udisks2 builds have failed with "/tmp/hooks/B20autopkgtest: 60: /tmp/hooks/B20autopkgtest: adt-run: not found"15:00
LeePenHas anybody seen this before? It is new to me.15:01
LeePenBut on a positive note, policykit-1 and consolekit2 are now built for beowulf. :)15:01
LeePenOK, this might be related to Debian #87639915:10
LeePenLooks as though the /tmp/hooks/B20autopkgtest needs updating for autopkgtest 5.0. adt-* commands are no longer available.15:22
LeePenOr pbuilder >= 0.229.15:29
masonI'm curious - checked last night, and I saw that the Apache security update finally made it in, and I haven't seen anything on the lists mentioning what happened there.16:13
JorilLeepen: YAY for Beowulf going forward! :)16:57
LeePenJoril: :)18:27
masonJjp137: Do you know what happened that addressed the issue with Apache?19:00
golinuxI'm not Joril but have seen nothing recently apache related.  Most everyone here has likely moved on to nginx19:06
xrogaangolinux: which email client do you use?19:20
golinuxRoundcube on the dyne server19:23
golinuxThat's webmail.19:24
golinuxIt's only happening on the dyne ML.  Didn't used to be that way.19:25
xrogaandyne updated their software, as pointed out by somebody on the ML?19:29
xrogaanoh, it's the same ML for both dyne and devuan?19:30
onefangI'm still using Apache, though I'll be experimenting with Lighttpd soon.19:43
Jjp137mason, someone probably gave amprolla a swift kick to make it learn about the update; beyond that, I have no idea really19:47
masonJjp137: That's a worry. Thought it was all automatic.19:47
masongolinux: The issue is that Debian has released a fix, but Amprolla wasn't showing that fix for a good week or two, which is a window of vulnerability. Knowing how it resolved would point to how likely it is to happen again in future.19:48
masongolinux: Re: nginx, it's entirely possible the same thing could happen with an nginx vulernability. That it was Apache is almost incidental, except that it's often facing the public Internet.19:52
golinuxThat defect in amprolla has been happening for a very long time and is being ignored by those capable of fixing it.20:03
golinuxIIRC a solution was offered but the hurdle of "proof" required to having it applied was not feasible to accomplish20:05
masonHrm. Do we know what it is and it just needs to be fixed, or is there some diagnostic work required?20:05
golinuxI think it self-corrects at some point.20:05
masonAnd do we know what the workaround was in this case, to help identify the problem?20:05
golinuxI'll try to find it20:06
masonI guess I want to snag the code and see what it's doing.20:06
masonCool, if you see anything I'd be happy to look. Reimplementing it was something that showed up in one of the videos I watched, so maybe I can assess the feasibility of this.20:06
golinuxHere you go: https://lists.dyne.org/lurker/message/20190914.151803.224e1f02.en.html20:08
golinuxThe final word in that thread: https://lists.dyne.org/lurker/message/20190924.203227.69fa9513.en.html20:10
masongolinux: Thank you. And I've pulled down https://github.com/parazyd/amprolla now and am digging a bit.20:11
masonOh, I remember that thread. I hadn't connected that with this.20:11
golinuxThanks for doing that.21:22
fsmithredmason, pkgmaster tends to lag behind packages.devuan.org sometimes, and when it does, it's usually just ascii-security.21:40
fsmithredBut I've seen packages.devuan lag a couple times, too.21:41
masonfsmithred: But is that all Amprolla?21:48
golinuxThere is no other thing messing with it21:49
fsmithredyeah, it's amprolla. There are two instances running.21:50
fsmithredauto.mirror mirrors packages.d.o. deb.devuan mirrors pkgmaster.21:51
masonI'm going to write up a design doc for it, and if that looks accurate to everyone maybe I can implement something new and have it be both talkative and paranoid.21:53
fsmithredtalk to rrq. I know he's looked at it and might know what the problem is.21:54
masonI really dislike Python, though. More fun to have a clean start.21:54
masonPlus, it'll be useful having a design document.21:56
golinuxYou must have seen this by now: https://dev1galaxy.org/files/amprolla.png21:59
masongolinux: Yes.22:00
golinuxThat's the general flow though I understand that it is slightly different now22:00
masonMy understanding is that it uses redirects so we don't host things that are unmodified Debian, but I'm more or less taking this on faith.22:01
masonHaven't finished a readthrough yet.22:01
golinuxThat is correct.22:02
golinuxWe only host devuan-specific packages22:02
rrqmason: if you look into the Packages file(s) you'll see that every package has their access filename as a url with ether DEVUAN or DEBIAN as path component, which the repository server(s) use as key for dispatching to either a local file or a deb.debian.org file22:32
masonrrq: kk, ty22:33

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!