| fsmithred | sensys, wireless-tools is a package, not a command. It contains commands like iwconfig and iwlist | 00:10 |
|---|---|---|
| sensys | :DD | 00:16 |
| ibanja | I can't export or unmount a zfs pool. 'zfs umount -a -f' returns: cannot unmount '/mnt/chroot/usr': pool or dataset is busy | 00:22 |
| ibanja | I get the same message with 'zpool export zroot' | 00:23 |
| ibanja | I am trying to unmount from a chroot. | 00:25 |
| rrq | ibanja: you need to make sure the mount is not in use | 00:31 |
| rrq | check: lsof | grep chrootusr | 00:32 |
| rrq | check: lsof | grep chroot/usr | 00:32 |
| ibanja | I'm not showing anything. | 00:38 |
| rrq | check# mount | grep chroot | 00:38 |
| ibanja | there are mounts under /chroot but only /mnt/chroot/usr which is a zpool dataset lists the user directory. | 00:40 |
| rrq | yes that's ok; next is to "sync", to flush kernel buffers | 00:42 |
| ibanja | lsof |grep chroot lists a lot of lines with zed as process owner | 00:42 |
| ibanja | synced... still busy | 00:43 |
| ibanja | what would happen if I kill the zed process? | 00:43 |
| rrq | is this with zfs-fuse? then that's possible bu deosn't change its status | 00:44 |
| rrq | as I rememebr you can kill zfs-fuse and then export | 00:44 |
| ibanja | ps aux shows /usr/sbin/zed is in use. | 00:44 |
| rrq | by what | 00:45 |
| rrq | zfs-fuse maybe? | 00:45 |
| ibanja | I don't use zfs-fuse | 00:45 |
| ibanja | it says usr/sbin/zed -p /run/zed.pid | 00:45 |
| rrq | hmm but those paths are not within the chroot are they? | 00:46 |
| ibanja | no, I exited the chroot | 00:46 |
| ibanja | good point | 00:46 |
| ibanja | I could reboot, but I'd rather not go that route. | 00:47 |
| rrq | ok; you'll need to wait for a zfs whiz ... I don't know enough | 00:48 |
| ibanja | OK, thanks for trying. | 00:48 |
| ibanja | I think I'll reboot and figure it out later. | 00:49 |
| spine-o-saurus | hey how do i get qemu to save the boot cfg EFI info? every time I close the vm the bios needs to be reset for the boot entry | 01:19 |
| rrq | do you use the pflash device arguments? then make vars a local file | 01:22 |
| rrq | -drive if=pflash,readonly=off,format=raw,file=pvars.bin | 01:24 |
| spine-o-saurus | how do i export the current config for the file? | 01:25 |
| rrq | I have an initial dd if=/usr/share/OVMF/OVMF_VARS_4M.fd of=pvars.bin | 01:26 |
| rrq | the emulator uses the file as its flash store so no "export" is needed | 01:28 |
| rrq | all in all I have 2 initial (code+vars) and the 2 -drive arguments (code+vars) | 01:28 |
| rrq | dd if=/usr/share/OVMF/OVMF_CODE_4M.fd of=pcode.bin | 01:29 |
| rrq | dd if=/usr/share/OVMF/OVMF_VARS_4M.fd of=pvars.bin | 01:29 |
| rrq | -drive if=pflash,readonly=on,format=raw,file=pcode.bin | 01:29 |
| rrq | -drive if=pflash,readonly=off,format=raw,file=pvars.bin | 01:29 |
| rrq | I think the latter is /sys/firmware/efi/efivars | 01:33 |
| rrq | if mounted | 01:34 |
| spine-o-saurus | added those two drive paramaters but now it doesn't even boot up | 01:48 |
| spine-o-saurus | gues has not initialized the display (yet) | 01:48 |
| rrq | those -drive arguents would be instead of other boot arguments | 01:50 |
| spine-o-saurus | ya, i used to just have -bios /usr/share/OVMF/OVMF_CODE.fd | 01:51 |
| spine-o-saurus | i replaced that for the two drives | 01:51 |
| rrq | I have ovmf=2022.11-6+deb12u1 | 01:52 |
| rrq | if the 4M files are slow, maybe try without _4M | 01:52 |
| rrq | is it 64 bit host & guest ? | 01:53 |
| spine-o-saurus | 64, ya | 01:53 |
| spine-o-saurus | oh nm i copied the non-4M one previously that was mixed up | 01:57 |
| spine-o-saurus | ok good now it works | 01:59 |
| jayware | nm...cable issue...thx! | 04:46 |
| jiefk | Hello Folks ! I have troubles installing fail2ban package. It says : | 10:00 |
| jiefk | https://paste.debian.net/1321806/ | 10:00 |
| jiefk | I'm on Devuan Excalibur, and I tried both Excalibur and Ceres packages, to no avail. | 10:00 |
| jiefk | Can anyone please guide me in where to start for "debugging" the issue? Thanks in advance. | 10:00 |
| gnarface | jiefk: so uh, just in general terms, when the package installs, it extracts some pre and post installation scripts and runs them, it specifically says it was the post-inst one that failed, so it should still be sitting there waiting for the cleanup task that never happened. you should be able to just read it and figure out what failed, or run it manually if you have to | 10:54 |
| gnarface | worst case scenario it could shred the whole system though, hopefully you kept a backup (this is testing after all) | 10:54 |
| gnarface | might be worth checking debian's bug tracker to see if someone has already reported this over there. lots of bugs will be the same for us. | 10:55 |
| gnarface | i can't tell you anything specific about this but if you stick around someone else here probably can | 10:56 |
| jiefk | gnarface: OK Thanks, I will try to fint the post-inst script and see how it goes ! | 13:21 |
| jayway | nope...still having problems with internet connection sharing with devuan | 13:25 |
| jayway | my client gets an IP but cannot connect outside to the internet | 13:26 |
| jayway | any suggestions? | 13:26 |
| rrq | "gets an IP" .. is that from the router or from the server? | 13:33 |
| rrq | i.e. does it need NAT? | 13:34 |
| rrq | also: ipv4 or ipv6? | 13:35 |
| jiefk | © | 13:38 |
| jayway | ipv4 | 13:42 |
| jayway | from the server | 13:42 |
| rrq | ok. presuably a "private" IP so the server needs to provide NAT, i.e. change packets so the outside sees them as if from the server. | 13:44 |
| jayway | i assume nat is happening? I am doing some reading the network manager should handle sharing a connection and that I don't need dnsmasq or other | 13:44 |
| jayway | is something nat missing? | 13:45 |
| rrq | I use iptables for that. possibly "network-manager" uses some other way for setting up NAT. it's a kernel networking feature | 13:46 |
| jayway | normally just changing the setting in network manager works for me...it sounds like I am missing something for nat then | 13:47 |
| jayway | i've seen iptables instructions for this, but no luck trying anything yet | 13:47 |
| jayway | do you know what exact iptables incantation I need? | 13:48 |
| rrq | with iptables it'd be: iptables -t nat -A POSTROUTING -o $IFACE -j MASQUERADE | 13:48 |
| jayway | ok...let me try that...back in a few | 13:49 |
| rrq | where $IFACE would be your outbound interface (eth0 perhaps) | 13:49 |
| jayway | OH...that is different | 13:49 |
| jayway | my outside connection is my wifi card...eth0 serves to the private network | 13:49 |
| rrq | itd be wlan0 then I suppose | 13:50 |
| jayway | right | 13:50 |
| jayway | ok...let me grab a coffee and get things running again so I can test...biab | 13:50 |
| rrq | the server also needs the flag net.ipv4.ip_forward=1 | 13:51 |
| jayway | still no connection to outside | 13:57 |
| jayway | does this normally "just work" with network manager? I wonder if I've done something weird with my network and forgot about it | 13:58 |
| rrq | and ip_forward is turned on? | 13:58 |
| rrq | I don't use network-manager so I can't say | 13:58 |
| jayway | cat /proc/sys/net/ipv4/ip_forward is set to 1, yes | 13:58 |
| rrq | .. and the client's default route is ok? | 13:59 |
| rrq | .. and server "iptables -vnL FORWARD" admits traffic? | 14:00 |
| jayway | i have my client set to automatic so it uses dhcp...this all works as expected with my laptop sharing it's connection instead of my desktop with devuan | 14:01 |
| jayway | I am not an iptables expert...let me check | 14:01 |
| jayway | iptables reports a bunch of docker0 stuff I don't really understand | 14:03 |
| rrq | firstly is POLICY set to ACCEPT? | 14:04 |
| jayway | perhaps docker is interfering with my network? | 14:04 |
| jayway | i see this line at the top: | 14:04 |
| jayway | Chain FORWARD (policy DROP 168 packets, 11064 bytes) | 14:04 |
| rrq | ok so that means there is a firewall that by default drops packets; prohibits forwarding | 14:05 |
| rrq | resumably there is an ACCEPT rule for your laptop (or its network) | 14:05 |
| jayway | ok...sounds like we are getting somewhere...is that an easy fix? | 14:06 |
| rrq | are you using some firewall tooling? (like ufw or something?) | 14:06 |
| rrq | it's easy to add a rule but that gets lost on reboot | 14:07 |
| jayway | I don't see that I have ufw installed | 14:08 |
| jayway | if i did something else firewall it was in the distant past and i've forgotten what | 14:08 |
| jayway | iptables rules must be able to go into a startup script somewhere? | 14:09 |
| rrq | maybe you just have some persistence set up | 14:10 |
| rrq | package iptables-persistent aybe? | 14:11 |
| rrq | (that'd be cosistent with "long forgotten" :)) | 14:11 |
| rrq | is there an /etc/iptables.conf or similar? | 14:12 |
| jayway | iptables-persistent not installed... | 14:12 |
| rrq | any /etc/ipt* ? | 14:12 |
| jayway | nothing at all in etc | 14:13 |
| rrq | ok... hmm anything with docker configs? | 14:13 |
| jayway | i don't usually setup a firewall...so docker would be my next suspicion | 14:14 |
| jayway | i don't need docker for anything important...let me try removing | 14:14 |
| rrq | manual iptables rules would be like: iptables -I FORWARD -i eth0 -o wlan0 -j ACCEPT | 14:15 |
| rrq | that'd punch a hole for outbound forwarding | 14:16 |
| rrq | and maybe one "opposite" is needed for the return packets | 14:17 |
| jayway | swap the eth0 and wlan0? | 14:17 |
| rrq | yes | 14:18 |
| jayway | oooooooh! that last one did it | 14:18 |
| jayway | my client starting receiving ping packets as soon as i did the return one | 14:19 |
| jayway | is there a good place to put this so it stays persistent? | 14:20 |
| jayway | i am making notes now | 14:20 |
| rrq | "good place" is an opinion question :) I tend to put adhoc things like that in /etc/rc.local | 14:21 |
| jayway | that works for me | 14:21 |
| rrq | not that the "-I FORWARD" (the -I specifically) inseets the rules first for the chain so they end up in the opposite order and before any other rules | 14:23 |
| jayway | ok | 14:23 |
| rrq | with DROP policy you might want to use -A instead, which would add them last.. after other rules | 14:24 |
| rrq | i.e. just before the policy decision | 14:24 |
| jayway | sounds like I have some iptables reading to finally get around to ;) | 14:25 |
| jayway | now i have a reason :) | 14:25 |
| rrq | cheers. | 14:25 |
| jayway | this is great...now i can download a music player onto my pi that handles all my lossless music files...happy times! thanks very much rrq | 14:26 |
| Silvia2 | Hi, | 22:18 |
| Silvia2 | I am installing Devuan Unstable with Deboostrap (in dual boot with Windows11) from the live-minimal from the terminal having partially parted the hard-disk (M2) as follows: nvmen1p2 (Boot not encrypted), nvmen1p4 (Root Luks2 encrypted), nvmen1p5 (Home Luks2 encrypted ). | 22:18 |
| Silvia2 | After installing everything you need, when (in chroot) launch grub-install --target=x86_64-efi --efi-directory=/boot/efi --bootloader-id=grub. | 22:18 |
| Silvia2 | This error gives me back: grub-install: "error: attept to install to encrypted disk without cryptdisk enabled. Set 'grub_enable_cryptisk = 1' in file '/etc/default/grub' ". | 22:18 |
| Silvia2 | When I restart the boot grub does not start but asks me for the H4 passphrase that does not work ... | 22:18 |
| Silvia2 | How can I solve? | 22:18 |
| Silvia2 | Hi, | 22:18 |
| Silvia2 | I am installing Devuan Unstable with Deboostrap (in dual boot with Windows11) from the live-minimal from the terminal having partially parted the hard-disk (M2) as follows: nvmen1p2 (Boot not encrypted), nvmen1p4 (Root Luks2 encrypted), nvmen1p5 (Home Luks2 encrypted ). | 22:18 |
| Silvia2 | After installing everything you need, when (in chroot) launch grub-install --target=x86_64-efi --efi-directory=/boot/efi --bootloader-id=grub. | 22:18 |
| Silvia2 | This error gives me back: grub-install: "error: attept to install to encrypted disk without cryptdisk enabled. Set 'grub_enable_cryptisk = 1' in file '/etc/default/grub' ". | 22:18 |
| Silvia2 | When I restart the boot grub does not start but asks me for the H4 passphrase that does not work ... | 22:18 |
| Silvia2 | How can I solve? | 22:18 |
| Silvia2 | l | 22:18 |
| joerg | hi Silvia2, please don't post twice. We can read you | 22:19 |
| joerg | please allow a few minutes for somebody to come up with a advice | 22:19 |
| Silvia2 | Hi, | 22:21 |
| Silvia2 | I am installing Devuan Unstable with Deboostrap (in dual boot with Windows11) from the live-minimal from the terminal having partially parted the hard-disk (M2) as follows: nvmen1p2 (Boot not encrypted), nvmen1p4 (Root Luks2 encrypted), nvmen1p5 (Home Luks2 encrypted ). | 22:21 |
| Silvia2 | After installing everything you need, when (in chroot) launch grub-install --target=x86_64-efi --efi-directory=/boot/efi --bootloader-id=grub. | 22:21 |
| Silvia2 | This error gives me back: grub-install: "error: attept to install to encrypted disk without cryptdisk enabled. Set 'grub_enable_cryptisk = 1' in file '/etc/default/grub' ". | 22:21 |
| Silvia2 | When I restart the boot grub does not start but asks me for the H4 passphrase that does not work ... | 22:21 |
| Silvia2 | How can I solve? | 22:21 |
| joerg | hello Silvia2 | 22:22 |
| joerg | please stay here, allow for a few minutes or even half an hour for somebody to come up with a reply | 22:24 |
| joerg | Silvia2: and please don't repost, we seen your question three times here now | 22:24 |
| joerg | fsmithred suggested <fsmithred> echo -e "\nGRUB_ENABLE_CRYPTODISK=y\n" >> /etc/default/grub | 22:26 |
| rrq | also re-run "update-initrafs -u -k all" after enabling grub decryption | 22:28 |
| joerg | rrq: typo? | 22:30 |
| joerg | initram? | 22:31 |
| rrq | yes | 22:31 |
| rrq | like did it really say grub_enable_cryptisk ? :) | 22:32 |
| rrq | and also that /etc/default/grub settings are in uppercase without spacing, or needing quotes | 22:33 |
| rrq | ... i.e., quotes, for value with spaces | 22:34 |
| joerg | rrq: I'm just trying to clarify for Silvia2 | 22:35 |
| rrq | yes; should be: update-initramfs -u -k all | 22:36 |
| rrq | after setting GRUB_ENABLE_CRYPTODISK=1 | 22:37 |
| sensys | hello, fellas, thanks for your answers, but I guess, that I don't ready for this yet. I think to try later, with other usb flash on virtual machine. See you :x. | 22:44 |
| Silvia2 | 5 | 23:17 |
| joerg | Silvia2: if you lost backscroll of the cahnnel, there's http://reisenweber.net/irclogs/libera/_devuan/ | 23:18 |
| * joerg seen several users with some strange IRC (handling) issues recently, who all used "Purple IRC" | 23:24 | |
| joerg | trying to find out what an IRC client that is, all I found was something "Minecraft" :-o | 23:25 |
| CueXXIII | seems to be an irc bridge for the minecraft in-game chat | 23:29 |
| joerg | maybe try https://web.libera.chat/#devuan alternative, to find your way in real IRC | 23:33 |
| joerg | and while recommending generically useful stuff: looking for a IRC client? See https://libera.chat/guides/clients . Searching for channels? /query alis help list | 23:39 |
| joerg | prolly "purple" is Pidgin | 23:41 |
| joerg | also useful: https://netsplit.de/networks/top100.php | 23:44 |
| joerg | https://netsplit.de/channels/?net=Libera.Chat | 23:45 |
Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!