libera/#devuan/ Tuesday, 2024-08-27

Elw3So i installed with disc encryption, now i have to enter the password before and after grub, any way to get this down to one entering?11:40
fsmithredElw3, you can set auto-login in /etc/inittab and your display manager config11:43
Elw3I mean disk encryption, not login11:44
Elw3With login i have even 3 passwords, but ohwell i aint there yet.11:44
fsmithredyou have more than one encrypted partition without lvm?11:47
fsmithredoh, sorry, I'm not fully awake11:47
fsmithredI get it now - grub password, cryptsetup password...11:47
fsmithredNot sure, but maybe you can put a keyfile in the initramfs and also make an entry for it in the /etc/crypttab of the initramfs11:49
Elw3well grub asks for the disk password, then it asks for the same password again, i dunno what it is that asks the second time, but THEN i get the login.11:49
fsmithredYeah, I remember that. It's the reason I don't encrypt my /boot partition.11:51
CueXXIIIgrub is probably not passing the password down to linux. no idea how to do that, though11:51
Elw3:/ so i hit a blind spot in configuration11:52
rktakeyfiles should work or using lvm, but that should have been done during install.11:52
rktaI know I used keyfiles before I switched to lvm.11:53
Elw3Was the installer supposed to do this automatically?11:53
fsmithredhttps://wiki.archlinux.org/title/Dm-crypt/Encrypting_an_entire_system#Creating_the_keyfiles11:54
rktaNo, it's all manual.11:54
fsmithredarch wiki knows all11:54
Elw3bummer11:54
Elw3So if i just encrypt the home, would that just work?11:54
fsmithredyeah or you could do what the Archies say to do. Read my link.11:55
fsmithredbtw, something between full disk and just home is to encrypt the root (with home) and leave /boot unencrypted.11:56
rktaOr use lvm. Everything encrypted and only one passphrase prompt.11:56
onefangArchies?  I wonder if there's a distro for Jugheads?  B-)11:56
fsmithredusually /boot is unencrypted with lvm11:56
fsmithredlol11:56
fsmithredI want to install Betty.11:56
rktamy mount says something different though11:57
rkta/dev/mapper/boot_crypt on /boot type ext2 (rw,relatime)11:57
fsmithreddoes /etc/default/grub have a line for CRYPTODISK?11:58
Elw3I dont see what there is to gain by splitting boot from root really11:58
CueXXIIIi guess grub can't boot from a partition on an encrypted lvm device11:59
fsmithredsplitting boot off makes it so you don't need to enter a password for grub11:59
Elw3Yea but why would i not just leave the entire root unencrypted?11:59
fsmithred stuff in /var and /tmp might be private12:00
fsmithredmaybe other stuff too.12:00
Elw3Hm, sounds rare enough.12:02
Elw3This is just so messy, theer is also this stupid efi partition and then adding boot, root and a home, and eventually a swap and there we have a full pokemon set of partitions.12:03
fsmithredanother option for security is to put the /boot partition on a usb stick. Then you can't boot without that stick.12:03
fsmithredyeah, swap should be encrypted too.12:04
Elw3Pretty sure people who steal my box wont bother checking if it boots or not.12:04
fsmithredWhy not? You might have saved your banking login in the web browser.12:05
fsmithredThe point of using lvm with encryption is that there's just one encrypted container with logical partitions inside it.12:06
onefangInstall swapspace, then you wont need a swap partition.12:10
Elw3Ill see later what i decide to end up with, just wanted to know if the installer should have taken care of it or if its normal12:10
onefangswapspace will automatically create and delete swapfiles as needed.12:11
Elw3I meant in regards to crypt, i dont actually want to use swap12:12
Elw3That actually is annoying, the installer had no checkbox to disable it.12:13
onefangWell if it's creating those swap files on an encrypted root...12:13
fsmithredto disable what?12:14
fsmithredDid you install from the live-iso?12:14
onefangAnd if you don't actually need swap, then swapspace is still good.  A backup plan.12:14
Elw3yep12:15
Elw3Ive installed from one usb to the other.12:15
Elw3Swapping via usb will just stall your system.12:15
fsmithredif you choose to encrypt the root partition, normally you would make a separate /boot partition which would not be encrypted.12:15
fsmithredIf you don't separate /boot then you get full disk encryption.12:16
fsmithredand the live installer doesn't do lvm, so if you make a separate /home partiton and encrypted it, you'd have to enter the password one more time or else make a keyfile for /home12:16
masonIf LVM exists, swap as a volume > swap as a file, IMHO.17:30
CueXXIIIalso i don't know if you can resume from a swap file without issues17:36
CueXXIIIbecause the filesystem it is located on is probably in an unclean state17:37
rwpFully encrypted systems usually use LVM2 with one unencrypted /boot partition and the rest in an encrypted LVM PV.  The system boots from the unencrypted /boot, prompts for a passphrase for the encrypted PV, then uses an LVM LV for swap and for root and everything is normal at that point.17:38
rwpLVM is what provides for exactly one LUKS prompt for the encrypted PV but then allows multiple partitions out for root and for swap using LVs.17:39
rwpEspecially on a mobile device one almost always wants to hibernate the system powered off at some point.  Swap facilitates this hibernation.17:40
masonrwp: Easy enough to get just one LUKS prompt for a variety of devices.17:40
masonkeyscript=decrypt_keyctl provides the magic17:40
masonfwiw17:40
rwpI am unfamiliar with the strategy and technique you just mention.17:41
masonrwp: man 5 crypttab and search for "keyscript" - there are a couple useful mentions, and then a section labelled "keyscript=<path>"17:41
rwpWill do!  Thanks.17:42
masonI love it. Makes booting with four LUKS devices (no LVM) quite a bit less painful.17:42
mason(No LVM because it's all ZFS.)17:42
rwpWell ZFS is the superior way for certain.  It's just not shipped by default in Debian/Devuan.17:43
rwpI also think people generally misunderstand that having a little swap space available does NOT mean that their system will be thrashing swap all of the time.  People seem to think that but that's false.17:46
rwpBut not having swap space means that the Out Of Memory Killer is invoked.  And I really, really hate the OOM Killer.  Avoiding the OOM Killer is worth dedicating an insignificant amount of disk to swap.17:46
CueXXIIIbut i do notice that linux tends to use a bit of swap, especially during high io-loads, and those pages stay swapped17:47
CueXXIIIso they are really used rarely17:47
masonrwp: https://bpa.st/PQVQ17:49
masonfor kicks17:49
CueXXIIIhm, archlinux wiki suggests a plain keyfile without keyutils package: https://wiki.archlinux.org/title/Dm-crypt/Device_encryption#With_a_keyfile_embedded_in_the_initramfs17:52
masonCueXXIII: Note their warning.18:26
masonCueXXIII: The keys we provide to LUKS are not the keys that are used for encryption. They simply unlock those keys, which are embedded in the actual storage.18:26
masonI feel safer having something I must provide manually.18:27
CueXXIIImason: sure, the same with passwords19:01
masonYeah, that's what I mean - passphrases.19:02
CueXXIIIyou can have both in luks, you can have up to 4 either passphrases or keyfiles that can unlock the volume key19:06
CueXXIII(in any combination)19:06
masonLUKS2 it goes up to like 2019:07
masonBut I think you only ever need one of them.19:08
golinuxParanoid much?19:19
fsmithredyou might want to give different people access to the same encrypted volume and be able to easily disable access to only their key (file or passphrase)19:21
fsmithredone19:21
masonThat's what we do here. My kids' computers have an unlock they know, but I also have a default I use everywhere here.,19:22
Hurgotrondoes there happen to be some Linux project  for  ***reliable*** printing? No cups, foomatic, bonjour, Avahi, zeroconf, whatever drek. I want to configure a printer, if necessary by chiseling the configuration in rock, but it ***needs*** to still work when I reboot the computer or the printer. The printer of my 83 yo mom and 78 yo neighbor basically never works,  no matter how often I configure it, and it drives me nuts.21:03
masonHurgotron: Noting how it fails in each case might be good. Printers are funny things nowadays, and while you might be able to set up a simple lpd, using it for more than monospaced text might be tricky without CUPS.21:10
masonProbably better to debug what's going wrong.21:10
masonAnd picking free-software-friendly printers can help.21:10
fluffywolfis the printer causing problems a hp, by any chance?21:16
fluffywolfcups 3 is supposed to be very, very different...  I think it'll be a lot worse, but it might work better in some situations, dunno.21:18
HurgotronOne of them is connected via USB (Epson? don't remember), the one connected via WLAN is HP indeed.21:32
plasma41Hurgotron: Do the printers in question speak either of the PCL or PostScript languages?21:37
HurgotronProbably not. multifunction devices, scanner/printer21:38
HurgotronWith the USB printer the issue is basically that it is not there anymore the next time you try to print. The job just sits there because the printer is not available, or something. Delete printer, configure again, works. Until next time.21:38
plasma41If neither of those page description languages are supported and if you want a simple printing setup, then you not going to have a fun time.21:39
HurgotronIs it really too much to ask that some USB POS can still be found the next time you power on stuff? Works with my mouse.21:40
plasma41For the HP connected via the network, assuming it supports JetDirect network printing, you should be able to netcat a print job to it on port 9100.21:43
plasma41Given that HP created PCL, I'd be surprised if the HP printer doesn't support it.21:45
Hurgotronplasma41: Well if your print dialog thinks your printer is not there, what do you do?21:55
onefangHurgotron: Get a pen is what you do.22:10
Hurgotron?22:25
djphonefang: heh22:26
Elw3So what is the usual process here when one needs programs which are not in the repo? I mean with the lack of ppas and such, do i have to make it myself or are there packagers taking suggestions?22:47
rkta./configure && make && make install22:51
Elw3I wish, but i am a bit lost with some depends here.22:53
djphrkta: debuild ? :D22:54
djphElw3: does the project's github not detail the dependencies?22:55
rktadjph: Debuild: Build web apps lightning fast with AI-powered code generation - This? :D22:56
djphrkta: uh... no.  This https://wiki.debian.org/Packaging/Intro?action=show&redirect=IntroDebianPackaging22:57
djphhuh, weird on the showredirect there; meh whatever22:57
fsmithredwhat package is it?22:58
Elw3Its moksha, an enlightenment fork.22:58
fsmithredsounds familiar22:59
Elw3First glance several build depends are not there, but i havnt actually tried building it yet.23:00
Elw3Another thing i basically miss every time on any distro is deadbeef. The best of music players.23:01
fsmithredIn general it's best to go with the debian packaging instructions. Then the package manager knows it's there.23:02
Elw3But i gather that should be doable to install23:02
fsmithredyou can install deadbeef on devuan. I use it on some builds.23:02
Elw3But it aint in the repo23:02
fsmithrednope23:02
fsmithredI don't recall where I got the .deb package.23:02
Elw3I mean isnst that a clear oversight to not have it?23:03
fsmithredI have no idea why they removed it from debian.23:03
fsmithredI got it from sourceforge.23:04
Elw3not only there, its in no other repo at all.23:04
fsmithredIf you do some research you could probably find a note as to why it got removed.23:04
onefangI'm still wondering why Debian purged jpeg2000 support.  That's basically the only texture format supported by OpenSim.  SO now I have millions of textures I can't view.23:05
Elw3I would not know where to search for such notes.23:05
fsmithredmailing lists, maybe the changelog for the package.23:05
fsmithredmaybe nobody was maintaining it in debian23:06
Elw3*shrug*23:07
onefangYou can use PPA's in Devuan.  People will tell you that it might break your system, but if you know what you are doing, it's fine.  I have no problem with half a dozen PPAs.  Including deb-multimedia, which DOES include deadbeef.23:08
Elw3Good to know, but i already tried using a ppa for moksha yesterday and the amount of missing stuff was really something.23:11
Elw3I practically would need to load the ubuntu repo for it to work, i wonder if the system will survive that.23:12
onefangAh, that'll be one of those "some PPAs can break your system".23:13
Elw3Now i itch to try it, but at some point it prolly tries to pull in systemd and the whole thing gets kaboom.23:14
onefangUp until shortly after Samsung basically bought Enlightenment window manager, I was a developer for it.  At the time Enlightenment had systemd included, but was optional.  I got a thrill the other day seeing a huge Tizen based TV in a shop, knowing it runs software I wrote.  lol23:16
onefangI gave up on Enlightenment long ago.23:16
Elw3From a codepoint or from usage?23:17
onefangFrom the horrid things that started happening after Samsung took over.23:17
Elw3:P23:18
Elw3E 0.1699999999 is best E, right?23:18
Elw3I was pretty shocked yesterday seeing its now 450mb, thats over 10 times of what it used to be, and i dont get why23:19
Elw3Usage wise nobody can use it since repos always update to the latest versions and this always lack any modules or themes making this ugly and unusable.23:22
Elw3This is why i need moksha, it actually has themes and the one module i want.23:22
Elw3While real E just breaks everything like clockwork.23:23
onefangThe biggest thing is that Samsung had some skunkworks group adding 3D rendering support, the code was turning up in Enlightenment.  GREAT I thought, this'll be wonderful for my OpenSIm virtual world / metaverse stuff.  I even had a basic viewer half written using it.  But the skunkworks group wouldn't talk to anyone, so I couldn't help out.  And then it vanished.23:23
onefangMoksha forked before Samsung.23:23
Elw3I think its after.23:23
Elw3Its a shame really, it can be so powerful.23:26
Elw3even this 10 times sized bloated version is still faster than xfce.23:27
onefangI switched to Awesome, and I'm still looking for a decent C based 3D rendering system.23:29
Elw3Ive had the exact same desktop without changes since 15 years, aint open for changes.23:32
onefangFair enough.23:33
Elw3Say if something works on debian, how high are the changes it works here? Cause seems there is a debian repo for moksha23:36
golinuxhttps://pkginfo.devuan.org/cgi-bin/policy-query.html?c=package&q=moksha*&x=submit23:45
Elw3What are you trying to say here?23:46
golinuxThat there are moksha-related files available in Devuan for the listed releases23:47
Elw3moksha is a common word in some language, its likely unrelated.23:48
golinuxI am not seeing any moksha on the banned packages list.23:48
* golinux retreats . . .23:49
Elw3I actually got confused trying to install chromium-browser yesterday because other distros have the package named like that and _chromium_ is a game. Now here we have it reversed.23:52
golinuxThis may help clear things up for you https://git.devuan.org/devuan/amprolla323:53
golinuxIt is how our repos are created;.23:53
golinuxExplained with images here: https://dev1galaxy.org/viewtopic.php?id=319223:54

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!