Bug#1060162: sssd_ad: Dynamic DNS updates fail with NOTZONE for PTR records if interface has multiple IPv6 adresses

2024-01-06 Thread Dirk Heinrichs
Package: sssd-ad
Version: 2.8.2-4
Severity: normal
Tags: upstream ipv6
X-Debbugs-Cc: dirk.heinri...@altum.de



If a network interface has multiple IPv6 addresses (here: a public one and one
on the fd00 network), dynamic DNS updates fail with a NOTZONE error when
updating the PTR records, although there's a zone for each of the networks
configured in the DNS (Samba AD) server. The reason is that the commands to
update the records are sent at the same time, like this (according to the log
file):

update delete .in-addr.arpa. in PTR
update add .in-addr.arpa. 3600 in PTR .
send
update delete .ip6.arpa. in PTR
update add .ip6.arpa. 3600 in PTR .
update delete .ip6.arpa. in PTR
update add .ip6.arpa. 3600 in PTR .
send

which I can also reproduce by copy/pasting the same commands into an nsupdate
session.

The problem can easily be solved by adding another send command, like so:

update delete .in-addr.arpa. in PTR
update add .in-addr.arpa. 3600 in PTR .
send
update delete .ip6.arpa. in PTR
update add .ip6.arpa. 3600 in PTR .
send
update delete .ip6.arpa. in PTR
update add .ip6.arpa. 3600 in PTR .
send

The problem has been solved upstream already (see
https://github.com/SSSD/sssd/issues/7110) and released with version 2.9.3.
Please backport the fix to 2.8.2 included in Bookworm.


-- System Information:
Debian Release: 12.4
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 6.1.0-17-amd64 (SMP w/16 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages sssd-ad depends on:
ii  libc6 2.36-9+deb12u3
ii  libdhash1 0.6.2-1
ii  libini-config50.6.2-1
ii  libldap-2.5-0 2.5.13+dfsg-5
ii  libldb2   2:2.6.2+samba4.17.12+dfsg-0+deb12u1
ii  libpopt0  1.19+dfsg-1
ii  libsasl2-22.1.28+dfsg-10
ii  libsmbclient  2:4.17.12+dfsg-0+deb12u1
ii  libsss-idmap0 2.8.2-4
ii  libtalloc22.4.0-f2
ii  libtevent00.14.1-1
ii  samba-libs2:4.17.12+dfsg-0+deb12u1
ii  sssd-ad-common2.8.2-4
ii  sssd-common   2.8.2-4
ii  sssd-krb5-common  2.8.2-4

sssd-ad recommends no packages.

Versions of packages sssd-ad suggests:
ii  adcli  0.9.1-2

-- no debconf information



Bug#1041212: Acknowledgement (When ausweisapp2 is running, clicking on notifications for other apps always opens the ausweisapp2 window)

2023-07-16 Thread Dirk Heinrichs

Debian Bug Tracking System:

Thank you for filing a new Bug report with Debian. 


Sorry, forgot to add a description:

Every time Ausweisapp2 runs, clicking on incoming notifications from 
(for example) Element or Thunderbird, results in the Ausweisapp2 window 
being openend. If Ausweisapp2 doesn't run, the correct application 
window is opened instead.


Bye...

    Dirk

--
Dirk Heinrichs 
Matrix-Adresse: @heini:chat.altum.de
GPG Public Key: 80F1540E03A3968F3D79C382853C32C427B48049
Privacy Handbuch: https://www.privacy-handbuch.de



OpenPGP_signature
Description: OpenPGP digital signature


Bug#1041212: When ausweisapp2 is running, clicking on notifications for other apps always opens the ausweisapp2 window

2023-07-15 Thread Dirk Heinrichs
Package: ausweisapp2
Version: 1.26.4-1
Severity: normal



-- System Information:
Debian Release: 12.0
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 6.1.0-10-amd64 (SMP w/4 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, 
TAINT_UNSIGNED_MODULE
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages ausweisapp2 depends on:
ii  libc6   2.36-9
ii  libhttp-parser2.9   2.9.4-5
ii  libpcsclite11.9.9-2
ii  libqt6core6 6.4.2+dfsg-10
ii  libqt6gui6  6.4.2+dfsg-10
ii  libqt6network6  6.4.2+dfsg-10
ii  libqt6qml6  6.4.2+dfsg-1
ii  libqt6quick66.4.2+dfsg-1
ii  libqt6quickcontrols2-6  6.4.2+dfsg-1
ii  libqt6statemachine6 6.4.2-2
ii  libqt6svg6  6.4.2-2
ii  libqt6websockets6 [qt6-websockets-abi]  6.4.2-1
ii  libqt6widgets6  6.4.2+dfsg-10
ii  libssl3 3.0.9-1
ii  libstdc++6  12.2.0-14
ii  libudev1252.6-1
ii  qml6-module-qt-labs-platform6.4.2+dfsg-1
ii  qml6-module-qtqml   6.4.2+dfsg-1
ii  qml6-module-qtqml-models6.4.2+dfsg-1
ii  qml6-module-qtqml-statemachine  6.4.2-2
ii  qml6-module-qtqml-workerscript  6.4.2+dfsg-1
ii  qml6-module-qtquick-controls6.4.2+dfsg-1
ii  qml6-module-qtquick-layouts 6.4.2+dfsg-1
ii  qml6-module-qtquick-templates   6.4.2+dfsg-1
ii  qml6-module-qtquick-window  6.4.2+dfsg-1

Versions of packages ausweisapp2 recommends:
ii  pcsc-tools  1.6.2-1
ii  pcscd   1.9.9-2

ausweisapp2 suggests no packages.

-- no debconf information



Bug#1033867: cloud.debian.org: Please add Amazon hibernation agent to EC2 AMIs

2023-04-03 Thread Dirk Heinrichs
Package: cloud.debian.org
Severity: wishlist

Dear Maintainer,

we're providing customized Debian and Ubuntu development servers to our
software developers. While the Ubuntu AMIs ship with the Amazon EC2
hibernation agent and are thus able to be hibernated via the AWS
console, the Debian AMIs lack that functionality.

So the request is to also ship the agent preinstalled in the Debian AMIs. See
https://packages.ubuntu.com/search?keywords=ec2-hibinit-agent=names
for Ubuntu (source) packages or https://github.com/aws/amazon-ec2-hibinit-agent
for latest sources.

I've already verified that it works on Debian with a local rebuild of
the latest Ubuntu source deb.

Thanks in advance...

Dirk



Bug#951831: Groovy is at 4.0.3 now

2022-06-12 Thread Dirk Heinrichs
Hi,

current Groovy version is 4.0.3, while even Sid still has 2.4.21. Please...

Bye...

    Dirk

-- 
Dirk Heinrichs 
Matrix-Adresse: @heini:chat.altum.de
GPG Public Key: 80F1540E03A3968F3D79C382853C32C427B48049
Privacy Handbuch: https://www.privacy-handbuch.de



OpenPGP_signature
Description: OpenPGP digital signature


Bug#927056: It's 4.0.0 now

2022-02-03 Thread Dirk Heinrichs
Hi,

Groovy 4.0.0 has been released last week. See also:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=951831

Bye...

    Dirk

-- 
Dirk Heinrichs 
Matrix-Adresse: @heini:chat.altum.de
GPG Public Key: 80F1540E03A3968F3D79C382853C32C427B48049
Privacy Handbuch: https://www.privacy-handbuch.de




OpenPGP_signature
Description: OpenPGP digital signature


Bug#951831: It's 4.0.0 now

2022-02-03 Thread Dirk Heinrichs
Hi,

Groovy 4.0.0 has been released last week. Please provide updated
packages (incl. backports to bullseye).

Thanks a lot...

    Dirk

-- 
Dirk Heinrichs 
Matrix-Adresse: @heini:chat.altum.de
GPG Public Key: 80F1540E03A3968F3D79C382853C32C427B48049
Privacy Handbuch: https://www.privacy-handbuch.de



OpenPGP_signature
Description: OpenPGP digital signature


Bug#986709: rsnapshot is stable, not dead

2021-10-01 Thread Dirk Heinrichs
John Brooks wrote:

> I don't know precisely what criteria of stability and quality are used
> to judge whether a package is suitable for inclusion; my outside view
> is that this package is no more broken or unmaintained than the
> average Debian package.

Esp. when compared to dirvish (see my previous mail), which is
unmaintained for 16+ years, but still available in bullseye. What's the
point in keeping that one while at the same time removing rsnapshot,
which is unmaintained for just a handful of months now?

Bye...

    Dirk

-- 
Dirk Heinrichs 
Matrix-Adresse: @heini:chat.altum.de
GPG Public Key: 80F1540E03A3968F3D79C382853C32C427B48049
Privacy Handbuch: https://www.privacy-handbuch.de




OpenPGP_signature
Description: OpenPGP digital signature


Bug#947688: systemd-networkd: Python socket.getfqdn() not working properly when resolv.conf lacks "domain" key

2021-08-01 Thread Dirk Heinrichs
Michael Biebl:

> On Wed, 25 Nov 2020 03:27:20 +0100 Michael Biebl 
> wrote:
>> If it's still reproducible, can you raise this upstream please at
>> https://github.com/systemd/systemd/issues 
> Any updates here?

Sorry for the delay, I always forgot to do it. It's finally there now:
https://github.com/systemd/systemd/issues/20358

Bye...

    Dirk

-- 
Dirk Heinrichs 
Matrix-Adresse: @heini:chat.altum.de
GPG Public Key: 80F1540E03A3968F3D79C382853C32C427B48049
Privacy Handbuch: https://www.privacy-handbuch.de




OpenPGP_signature
Description: OpenPGP digital signature


Bug#986709: dirvish is unmaintained since 2005, but still available in bullseye

2021-06-28 Thread Dirk Heinrichs
Hi,

given that dirvish is still available in bullseye, although it's
unmaintained for more than 16(!) years now, it really makes me wonder
why rsnapshot has been removed. Please add it back, it's removal doesn't
make any sense.

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




OpenPGP_signature
Description: OpenPGP digital signature


Bug#792894: Why are 826011 and 826012 considered blockers?

2020-05-10 Thread Dirk Heinrichs
Hi,

I wonder why these two bugs are considered blockers for this one? From
the 3 scenarios below

  * DHCPv4 only
  * DHCPv6 only
  * DHCPv4 and DHCPv6

only the last one would need to have both started, so only this _might_
have a use for compound target units. But even if they are not
available, one can still enable/start each service separately via its
own service file. This means that 826011 and 826012 are, at most, nice
to have, but in no way are they blocking systemd service files for
isc-dhcp-server, right?

In addition, the current init script based mechanism for running both is
also buggy: When one service got killed, its PID file is still around,
which results in the init script refusing to start ANY of them unless
that PID file is removed.

So, please, replace the current init script with proper, independent
systemd service files for both dhcpdv4 and dhcpdv6 for bullseye. A
compound target unit can still be added later.

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



signature.asc
Description: OpenPGP digital signature


Bug#927056: Really fixed in 2.4.17?

2020-04-25 Thread Dirk Heinrichs
Hi,

did a quick check, and there's no fix for this in neither 2.4.19 not
2.5.11. So the only fixed versions are those >=3.0.0.

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#927056: Really fixed in 2.4.17?

2020-04-25 Thread Dirk Heinrichs
Hi,

the Groovy issue only lists 3.0.0-beta1 as "Fix Version". Has it really
been fixed in 2.4.17? Even if it was, Groovy should be updated to at
least 2.5.x, better to 3.x in testing, shouldn't it?

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#951831: Yes, please

2020-04-25 Thread Dirk Heinrichs
Hi,

+1 for this wish, plus backport to buster.

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#947688: systemd-networkd: Python socket.getfqdn() not working properly when resolv.conf lacks "domain" key

2020-03-15 Thread Dirk Heinrichs
Am 01.02.20 um 07:28 schrieb Michael Biebl:

> Did you find time to reproduce the issue with v244?
Yes, finally. Sorry for the long delay.

> does it work for you? It seems to work for me at least using 244.1
Unfortunately not. I still see the same behavior in Python.
socket.getfqdn() still returns the short hostname only if resolv.conf is
a symlink to stub-resolv.conf (with or without libnss-resolve, doesn't
matter).

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#947688: systemd-networkd: Python socket.getfqdn() not working properly when resolv.conf lacks "domain" key

2020-02-01 Thread Dirk Heinrichs

Am 01.02.20 um 07:28 schrieb Michael Biebl:

Did you find time to reproduce the issue with v244? 


No, sorry. And I won't for at least another week.

Bye...

    Dirk

--
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#947688: systemd-networkd: Python socket.getfqdn() not working properly when resolv.conf lacks "domain" key

2019-12-30 Thread Dirk Heinrichs

Michael Biebl:


I've uploaded v244 to buster-backports so you should be able to test if
you can still reproduce the problem there.


Great, thanks a lot, will do. I've also meanwhile tested this in an Arch 
Linux Container and it shows the same behaviour. However, it seems I was 
somehow wrong reg. the need for the "domain" keyword in resolv.conf. The 
"search" keyword seems to be enough, but this is missing unless I add a 
proper "Domains=..." line to resolved.conf and restart it, although it 
should get the domain from the DHCP server.


Bye...

Dirk
--
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#947688: systemd-networkd: Python socket.getfqdn() not working properly when resolv.conf lacks "domain" key

2019-12-29 Thread Dirk Heinrichs
Oh, btw: I've meanwhile also tried with libnss-resolve, but that didn't 
help either. It's also not used on the working system (with 
Network-Manager).


Bye...

Dirk
--
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#947688: systemd-networkd: Python socket.getfqdn() not working properly when resolv.conf lacks "domain" key

2019-12-29 Thread Dirk Heinrichs

Michael Biebl:


How would I create that (the former)?

https://www.cyberciti.biz/faq/linux-unix-dhcpdump-monitor-dhcp-traffic/


Ah, OK. That's nice and clean. I guess it needs to be done on the 
client, right? So here we go (attached).



It probably makes sense to involve upstream at this point and file a
corresponding bug report at
https://github.com/systemd/systemd/issues


Wanted to do that first, but it stated: "Bother your distribution if 
your systemd version is more than 2 behind latest upstream.", so I went 
here.


Bye...

    Dirk
--
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de
# dhcpdump -i host0 
  TIME: 2019-12-29 15:27:29.476
IP: 0.0.0.0 (8e:5c:b0:99:be:da) > 255.255.255.255 (ff:ff:ff:ff:ff:ff)
OP: 1 (BOOTPREQUEST)
 HTYPE: 1 (Ethernet)
  HLEN: 6
  HOPS: 0
   XID: d7fa1228
  SECS: 1
 FLAGS: 0
CIADDR: 0.0.0.0
YIADDR: 0.0.0.0
SIADDR: 0.0.0.0
GIADDR: 0.0.0.0
CHADDR: 8e:5c:b0:99:be:da:00:00:00:00:00:00:00:00:00:00
 SNAME: .
 FNAME: .
OPTION:  53 (  1) DHCP message type 1 (DHCPDISCOVER)
OPTION:  61 ( 19) Client-identifier 
ff:0b:89:5b:12:00:02:00:00:ab:11:0a:f3:70:6c:f2:6d:80:1c
OPTION:  55 (  9) Parameter Request List  1 (Subnet mask)
  3 (Routers)
 12 (Host name)
 15 (Domainname)
  6 (DNS server)
 26 (Interface MTU)
 33 (Static route)
121 (Classless Static Route)
 42 (NTP servers)

OPTION:  57 (  2) Maximum DHCP message size 576
OPTION:  12 (  3) Host name testhost
---

  TIME: 2019-12-29 15:27:29.495
IP: 192.168.1.102 (be:fa:b7:4:ca:34) > 192.168.1.7 (8e:5c:b0:99:be:da)
OP: 2 (BOOTPREPLY)
 HTYPE: 1 (Ethernet)
  HLEN: 6
  HOPS: 0
   XID: d7fa1228
  SECS: 1
 FLAGS: 0
CIADDR: 0.0.0.0
YIADDR: 192.168.1.7
SIADDR: 0.0.0.0
GIADDR: 0.0.0.0
CHADDR: 8e:5c:b0:99:be:da:00:00:00:00:00:00:00:00:00:00
 SNAME: .
 FNAME: .
OPTION:  53 (  1) DHCP message type 2 (DHCPOFFER)
OPTION:  54 (  4) Server identifier 192.168.1.102
OPTION:  51 (  4) IP address leasetime  7200 (2h)
OPTION:   1 (  4) Subnet mask   255.255.255.0
OPTION:   3 (  4) Routers   192.168.1.250
OPTION:  15 (  8) Domainnamealtum.de
OPTION:   6 (  8) DNS server192.168.1.102,192.168.1.103
---

  TIME: 2019-12-29 15:27:29.495
IP: 192.168.1.103 (6:e3:54:3f:e6:27) > 192.168.1.7 (8e:5c:b0:99:be:da)
OP: 2 (BOOTPREPLY)
 HTYPE: 1 (Ethernet)
  HLEN: 6
  HOPS: 0
   XID: d7fa1228
  SECS: 1
 FLAGS: 0
CIADDR: 0.0.0.0
YIADDR: 192.168.1.7
SIADDR: 0.0.0.0
GIADDR: 0.0.0.0
CHADDR: 8e:5c:b0:99:be:da:00:00:00:00:00:00:00:00:00:00
 SNAME: .
 FNAME: .
OPTION:  53 (  1) DHCP message type 2 (DHCPOFFER)
OPTION:  54 (  4) Server identifier 192.168.1.103
OPTION:  51 (  4) IP address leasetime  7200 (2h)
OPTION:   1 (  4) Subnet mask   255.255.255.0
OPTION:   3 (  4) Routers   192.168.1.250
OPTION:  15 (  8) Domainnamealtum.de
OPTION:   6 (  8) DNS server192.168.1.102,192.168.1.103
---

  TIME: 2019-12-29 15:27:29.496
IP: 0.0.0.0 (8e:5c:b0:99:be:da) > 255.255.255.255 (ff:ff:ff:ff:ff:ff)
OP: 1 (BOOTPREQUEST)
 HTYPE: 1 (Ethernet)
  HLEN: 6
  HOPS: 0
   XID: d7fa1228
  SECS: 1
 FLAGS: 0
CIADDR: 0.0.0.0
YIADDR: 0.0.0.0
SIADDR: 0.0.0.0
GIADDR: 0.0.0.0
CHADDR: 8e:5c:b0:99:be:da:00:00:00:00:00:00:00:00:00:00
 SNAME: .
 FNAME: .
OPTION:  53 (  1) DHCP message type 3 (DHCPREQUEST)
OPTION:  61 ( 19) Client-identifier 
ff:0b:89:5b:12:00:02:00:00:ab:11:0a:f3:70:6c:f2:6d:80:1c
OPTION:  55 (  9) Parameter Request List  1 (Subnet mask)
  3 (Routers)
 12 (Host name)
 15 (Domainname)
  6 (DNS server)
 26 (Interface MTU)
 33 (Static route)
121 (Classless Static Route)
 42 (NTP servers)

OPTION:  57 (  2) Maximum DHCP message size 576
OPTION:  54 (  4) Server identifier 192.168.1.102
OPTION

Bug#947688: systemd-networkd: Python socket.getfqdn() not working properly when resolv.conf lacks "domain" key

2019-12-29 Thread Dirk Heinrichs

Michael Biebl:


Are you aware of the "UseDomain=" option (see man systemd.network)?


Yes, tried it already.


Does it help if you set that option?


No, unfortunately not.


If not, we probably need a dump of the DHCP requests and a verbose debug
log of systemd-networkd.


How would I create that (the former)?

Bye...

    Dirk
--
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#947688: systemd-networkd: Python socket.getfqdn() not working properly when resolv.conf lacks "domain" key

2019-12-29 Thread Dirk Heinrichs

Michael Biebl:


not quite sure what you mean by "domain" entry.


"domain example.com"


Can you post a (full copy of a) working/non-working /etc/resolv.conf?


Working:

nameserver 
search 
domain 

Non-Working (as created automatically by systemd-resolved):

nameserver 127.0.0.53
options edns0
search 

But as said: It works when Network-Manager is used.


Is Python reading /etc/resolv.conf directly or does it use NSS?


Don't know what Python does internally.


Is libnss-resolve installed (and enabled)?


No. Never heard of it before.

Bye...

    Dirk
--
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#947688: systemd-networkd: Python socket.getfqdn() not working properly when resolv.conf lacks "domain" key

2019-12-29 Thread Dirk Heinrichs
This might be related/similar to #859092, but I'm not sure, so I opened 
this one.


Bye...

Dirk
--
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#947688: systemd-networkd: Python socket.getfqdn() not working properly when resolv.conf lacks "domain" key

2019-12-29 Thread Dirk Heinrichs
Package: systemd
Version: 241-7~deb10u2
Severity: normal
Tags: upstream

Hi,

first, a short description of the overall setup: A private (aka home) network
using Samba AD with ISC DHCP for network management and setup. All machines run
up-to-date Debian 10 (buster). I mainly run two types of machines (reg. their
network setup mechanism): Laptops, which use Network-Manager + systemd-
resolved, and others, which use systemd-networkd + systemd-resolved (or better:
should use). I also use Salt for overall systems management.

The problem with the latter setup is that it breaks Python's socket.getfqdn()
function when

1) systemd-resolved is running
2) /etc/resolv.conf is a symlink to /run/systemd/resolve/stub-
resolv.conf
3) /etc/resolv.conf lacks a "domain" entry

On a Laptop, which uses Network-Manager, Python's socket.getfqdn() function
correctly returns the fully qualified domain name with above setup. On all
other systems, which use systemd-networkd, the function only returns the short
hostname. This, for example, breaks the Salt Minion's ability to correctly set
the "fqdn" and "domain" grains (where the latter is calculated from the
former).

The only workaround I found so far for resolving the situation (other than
switching all systems from systemd-networkd to Network-Manager) is to

1) Stop and disable systemd-resolved
2) Replace the symlink with a static /etc/resolv.conf file
3) Add a "domain" entry (in addition to "search") to the file

>From my understanding, there should be no difference in behaviour of Python's
socket.getfqdn() regardless of whether Network-Manager or systemd-networkd is
used for network setup.

Bye...

Dirk



-- Package-specific info:

-- System Information:
Debian Release: 10.2
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.19.0-6-amd64 (SMP w/4 CPU cores)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_WARN, TAINT_OOT_MODULE, 
TAINT_UNSIGNED_MODULE
Locale: LANG=de_DE.utf8, LC_CTYPE=de_DE.utf8 (charmap=UTF-8), LANGUAGE= 
(charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages systemd depends on:
ii  adduser  3.118
ii  libacl1  2.2.53-4
ii  libapparmor1 2.13.2-10
ii  libaudit11:2.8.4-3
ii  libblkid12.34-0.1
ii  libc62.28-10
ii  libcap2  1:2.25-2
ii  libcryptsetup12  2:2.1.0-5+deb10u2
ii  libgcrypt20  1.8.4-5
ii  libgnutls30  3.6.7-4
ii  libgpg-error01.35-1
ii  libidn11 1.33-2.2
ii  libip4tc01.8.2-4
ii  libkmod2 26-1
ii  liblz4-1 1.8.3-1
ii  liblzma5 5.2.4-1
ii  libmount12.34-0.1
ii  libpam0g 1.3.1-5
ii  libseccomp2  2.3.3-4
ii  libselinux1  3.0-1
ii  libsystemd0  241-7~deb10u2
ii  mount2.33.1-0.1
ii  util-linux   2.33.1-0.1

Versions of packages systemd recommends:
ii  dbus1.12.16-1
ii  libpam-systemd  241-7~deb10u2

Versions of packages systemd suggests:
ii  policykit-10.105-25
ii  systemd-container  241-7~deb10u2

Versions of packages systemd is related to:
pn  dracut   
ii  initramfs-tools  0.133+deb10u1
ii  udev 241-7~deb10u2

-- no debconf information



Bug#946748: [zfsutils-linux] /etc/cron.d/zfsutils-linux leads to false error mails with systemd-cron

2019-12-15 Thread Dirk Heinrichs
Package: zfsutils-linux
Version: 0.7.12-2+deb10u1
Severity: normal

--- Please enter the report below this line. ---
Shortly after replacing cron with systemd-cron, I received error mails
about failing zfsutils-linux cron jobs. After some debugging I found
that i only get these mails on days where the scrub should not run.
This is because of the day-of-week test in the command found in
/etc/cron.d/zfsutils-linux, which reads

[ $(date +\%w) -eq 0 ] && [ -x /usr/lib/zfs-linux/scrub ] &&
/usr/lib/zfs-linux/scrub

This first test of course always fails except on Sundays, leading to a
non-zero exit code, which triggers systemd-cron's (correct) behaviour
to send an error mail.

This doesn't happen if the entire command is rewritten as

if [ $(date +\%w) -eq 0 ] && [ -x /usr/lib/zfs-linux/scrub ]; then
/usr/lib/zfs-linux/scrub; fi

or

if [ $(date +\%w) -eq 0 ]; then [ -x /usr/lib/zfs-linux/scrub ] &&
/usr/lib/zfs-linux/scrub; fi

Bye...

Dirk

--- System information. ---
Architecture: 
Kernel:   Linux 4.19.0-6-amd64

Debian Release: 10.2
  500 stable-updates  vwakviie2ienjx6t.onion 
  500 stable  vwakviie2ienjx6t.onion 
  500 stable  sgvtcaew4bxjd7ln.onion 

--- Package information. ---
Depends(Version) | Installed
-+-=
python3  | 3.7.3-1
python3:any  | 
libblkid1  (>= 2.16) | 
libc6  (>= 2.17) | 
libnvpair1linux  (>= 0.7.12) | 
libuuid1   (>= 2.16) | 
libuutil1linux   (>= 0.7.12) | 
libzfs2linux (>= 0.7.12) | 
libzpool2linux   (>= 0.7.12) | 
zlib1g  (>= 1:1.1.4) | 


Recommends   (Version) | Installed
==-+-===
lsb-base   | 10.2019051400
zfs-modules| 
 OR zfs-dkms   | 0.7.12-2+deb10u1
zfs-zed| 0.7.12-2+deb10u1


Suggests(Version) | Installed
=-+-
nfs-kernel-server | 
samba-common-bin  (>= 3.0.23) | 2:4.9.5+dfsg-5+deb10u1
zfs-initramfs | 0.7.12-2+deb10u1
 OR zfs-dracut| 

-- 
Dirk Heinrichs
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de 


signature.asc
Description: This is a digitally signed message part


Bug#929516: [project] Please provide onion services using next-gen (v3) onion addresses

2019-05-25 Thread Dirk Heinrichs
Package: project
Version: current
adresses
Severity: normal

--- Please enter the report below this line. ---
Some time ago the tor project introduced 56 character long, next-gen
(v3) onion addresses, which also utilize stronger cryptography.
However, Debian is still using v2 onion addresses for its onion
services.

Please (also) provide the onion services using v3 addresses.

--- System information. ---
Architecture: 
Kernel:   Linux 4.19.0-4-amd64

Debian Release: 10.0
  500 testing vwakviie2ienjx6t.onion 
  500 testing sgvtcaew4bxjd7ln.onion 

--- Package information. ---
Package's Depends field is empty.

Package's Recommends field is empty.

Package's Suggests field is empty.




-- 
Dirk Heinrichs
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de 


signature.asc
Description: This is a digitally signed message part


Bug#924763: [salt-common] Wrong dependency: Installs python3-tornado4 instead of python3-tornado

2019-03-17 Thread Dirk Heinrichs
Package: salt-common
Version: 2018.3.4~git20180207+dfsg1-1
Severity: normal

--- Please enter the report below this line. ---
Without python3-tornado, the following warning is printed to stdout on
each salt command and into the minion log on startup:

[WARNING ] /usr/lib/python3/dist-packages/salt/transport/zeromq.py:40:
VisibleDeprecationWarning: zmq.eventloop.minitornado is deprecated in
pyzmq 14.0 and will be removed.
Install tornado itself to use zmq with the tornado IOLoop.

  import zmq.eventloop.ioloop

The warning goes away immediately after installing python3-tornado.

--- System information. ---
Architecture: 
Kernel:   Linux 4.19.0-2-amd64

Debian Release: buster/sid
  500 testing vwakviie2ienjx6t.onion

--- Package information. ---
Depends(Version) | Installed
-+-===
python3-apt  | 1.8.3
python3-dateutil | 2.7.3-3
python3-jinja2   | 2.10-1
python3-msgpack  | 0.5.6-1+b1
python3-pkg-resources| 40.8.0-1
python3-psutil   | 5.5.1-1
python3-requests  (>= 1.0.0) | 2.21.0-1
python3-tornado4   (>= 4.2)  | 4.5.3-3
 OR python3-tornado   (<< 5) | 
python3-tornado4   (>= 4.2)  | 4.5.3-3
 OR python3-tornado (>= 4.2) | 
python3-yaml | 3.13-2
python3:any  | 


Recommends(Version) | Installed
===-+-===
lsb-release | 10.2018112800
python3-croniter| 0.3.24-2


Suggests(Version) | Installed
=-+-
=
python3-mako  | 
salt-doc (= 2018.3.4~git20180207+dfsg1-1) | 



Bye...

    Dirk
-- 
Dirk Heinrichs
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de 


signature.asc
Description: This is a digitally signed message part


Bug#922064: [Pkg-salt-team] Bug#922064: Please restore previous version

2019-03-17 Thread Dirk Heinrichs
Am 14.03.19 um 10:51 schrieb Benjamin Drung:

> Can you try this:

Due to a severe problem with LXC containers running under libvirtd (they
can't be properly stopped anymore, see #922506), I've meanwhile migrated
my containers to systemd-nspawn which has also solved this problem for
me. So I'm afraid the output would also be quite different now.

Thanks a lot for your time and effort.

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#922064: [Pkg-salt-team] Bug#922064: Please restore previous version

2019-03-13 Thread Dirk Heinrichs
alt-master[20006]:   File
"/usr/lib/python3/dist-packages/salt/config/__init__.py", line 101, in

Mär 13 17:36:28 salt salt-master[20006]: _DFLT_IPC_WBUFFER =
_gather_buffer_space() * .5
Mär 13 17:36:28 salt salt-master[20006]:   File
"/usr/lib/python3/dist-packages/salt/config/__init__.py", line 86, in
_gather_buffer_space
Mär 13 17:36:28 salt salt-master[20006]: total_mem =
psutil.virtual_memory().total
Mär 13 17:36:28 salt salt-master[20006]:   File
"/usr/lib/python3/dist-packages/psutil/__init__.py", line 2051, in
virtual_memory
Mär 13 17:36:28 salt salt-master[20006]: ret =
_psplatform.virtual_memory()
Mär 13 17:36:28 salt salt-master[20006]:   File
"/usr/lib/python3/dist-packages/psutil/_pslinux.py", line 406, in
virtual_memory
Mär 13 17:36:28 salt salt-master[20006]: mems[fields[0]] =
int(fields[1]) * 1024
Mär 13 17:36:28 salt salt-master[20006]: IndexError: list index out of range

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



signature.asc
Description: OpenPGP digital signature


Bug#922506: Acknowledgement ([libvirt0] lxc: internal error: child reported (status=125): Kernel does not provide mount namespace: No such file or directory)

2019-03-03 Thread Dirk Heinrichs
Hi,

is there any news on this? It's not possible anymore to stop LXC
containers running under libvirtd because of this.

Thanks...

    Dirk
-- 

Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#922064: Please restore previous version

2019-03-02 Thread Dirk Heinrichs
Hi,

since the Salt master is still not starting, could the Salt packages at
least be rolled back to the previous version until the problem is solved?

Thanks...

    Dirk
-- 

Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#922506: [libvirt0] lxc: internal error: child reported (status=125): Kernel does not provide mount namespace: No such file or directory

2019-02-17 Thread Dirk Heinrichs
Package: libvirt0
Version: 5.0.0-1
Severity: normal

--- Please enter the report below this line. ---
I currently see above error when I try to stop an LXC container running
under libvirtd using

   # virsh --connect lxc:///system shutdown myContainer
   error: Failed to shutdown domain myContainer
   error: internal error: child reported (status=125): Kernel does not
   provide mount namespace: Datei oder Verzeichnis nicht gefunden

   --- System information. ---
   Architecture: 
   Kernel:   Linux 4.19.0-2-amd64

   Debian Release: buster/sid
 500 testing vwakviie2ienjx6t.onion

   --- Package information. ---
   Depends (Version) | Installed
   =-+-===
   libacl1 (>= 2.2.51-8) | 2.2.52-3+b1
   libapparmor1   (>= 2.6~devel) | 2.13.2-7
   libaudit1(>= 1:2.2.1) | 1:2.8.4-2
   libavahi-client3  (>= 0.6.16) | 0.7-4+b1
   libavahi-common3  (>= 0.6.16) | 0.7-4+b1
   libc6   (>= 2.17) | 
   libcap-ng0 (>= 0.7.9) | 
   libcurl3-gnutls   (>= 7.28.0) | 
   libdbus-1-3   (>= 1.9.14) | 
   libdevmapper1.02.1 (>= 2:1.02.97) | 
   libgcc1  (>= 1:3.3.1) | 
   libgnutls30(>= 3.6.5) | 
   libnl-3-200(>= 3.2.7) | 
   libnl-route-3-200  (>= 3.2.7) | 
   libnuma1  (>= 2.0.11) | 
   libsasl2-2| 
   libselinux1   (>= 2.1.12) | 
   libssh2-1  (>= 1.2.8) | 
   libxml2(>= 2.7.4) | 
   libyajl2   (>= 2.0.4) | 


   Recommends  (Version) | Installed
   =-+-===
   lvm2  | 


   Package's Suggests field is empty.

   Bye...

Dirk
   -- 
   Dirk Heinrichs
   GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
   Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de 


signature.asc
Description: This is a digitally signed message part


Bug#922064: [salt-master] Salt master doesn't start anymore after update

2019-02-13 Thread Dirk Heinrichs
Am 12.02.19 um 18:45 schrieb Benjamin Drung:

> Very likely. Can you send me the output of /proc/meminfo from inside
> the container?

That was it already.

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#922064: [salt-master] Salt master doesn't start anymore after update

2019-02-12 Thread Dirk Heinrichs
Am 12.02.19 um 17:37 schrieb Benjamin Drung:

> So then it is a bug in psutil. Can you attach the content of
> /proc/meminfo?

Here you are:
# cat /proc/meminfo
MemTotal:   16350148 kB
MemFree: 3822056 kB
MemAvailable:    9057676 kB
Buffers:    1356 kB
Cached:  4943992 kB
SwapCached:    0 kB
Active:  7324360 kB
Inactive: 948080 kB
Active(anon):    3682896 kB
Inactive(anon):   326888 kB
Active(file):    3641464 kB
Inactive(file):   621192 kB
Unevictable:   0 kB
Mlocked:   0 kB
SwapTotal: 0 kB
SwapFree:  0 kB
Dirty:    28 kB
Writeback: 0 kB
AnonPages:   3327100 kB
Mapped:   450524 kB
Shmem:    682688 kB
Slab:    2764932 kB
SReclaimable:    1286500 kB
SUnreclaim:  1478432 kB
KernelStack:   11024 kB
PageTables:    30728 kB
NFS_Unstable:  0 kB
Bounce:    0 kB
WritebackTmp:  0 kB
CommitLimit: 8175072 kB
Committed_AS:    8113820 kB
VmallocTotal:   34359738367 kB
VmallocUsed:   0 kB
VmallocChunk:  0 kB
Percpu: 8272 kB
HardwareCorrupted: 0 kB
AnonHugePages:   1359872 kB
ShmemHugePages:    0 kB
ShmemPmdMapped:    0 kB
HugePages_Total:   0
HugePages_Free:    0
HugePages_Rsvd:    0
HugePages_Surp:    0
Hugepagesize:   2048 kB
Hugetlb:   0 kB
DirectMap4k: 8894708 kB
DirectMap2M: 7806976 kB
DirectMap1G:   0 kB

> psutil failed to parse it on your machine.

Hmm, is this new in 2018.3.4? Didn't have this problem with 2018.3.3.
And could it be because it's an LXC Container?

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



signature.asc
Description: OpenPGP digital signature


Bug#922064: [salt-master] Salt master doesn't start anymore after update

2019-02-12 Thread Dirk Heinrichs
Am 12.02.19 um 17:28 schrieb Benjamin Drung:

> What version of psutil do you have installed? I cannot reproduce this
> crash.

# dpkg --list|grep psutil
ii  python3-psutil    5.5.0-1 
amd64    module providing convenience functions for managing
processes (Python3)

> What is the output of python3 -c "import psutil;
> print(psutil.virtual_memory())"

# python3 -c "import psutil; print(psutil.virtual_memory())"
Traceback (most recent call last):
  File "", line 1, in 
  File "/usr/lib/python3/dist-packages/psutil/__init__.py", line 1952,
in virtual_memory
    ret = _psplatform.virtual_memory()
  File "/usr/lib/python3/dist-packages/psutil/_pslinux.py", line 400, in
virtual_memory
    mems[fields[0]] = int(fields[1]) * 1024
IndexError: list index out of range

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



signature.asc
Description: OpenPGP digital signature


Bug#922064: [salt-master] Salt master doesn't start anymore after update

2019-02-11 Thread Dirk Heinrichs
Package: salt-master
Version: 2018.3.4~git20180207+dfsg1-1
Severity: normal

--- Please enter the report below this line. ---
After updating to above version, salt-master doesn't start anymore, but
prints out the following traceback instead:

Feb 11 17:45:41 salt salt-master[17426]: Traceback (most recent call
last):
Feb 11 17:45:41 salt salt-master[17426]:   File "/usr/bin/salt-master", 
line 22, in 
Feb 11 17:45:41 salt salt-master[17426]: salt_master()
Feb 11 17:45:41 salt salt-master[17426]:   File "/usr/lib/python3/dist-
packages/salt/scripts.py", line 95, in salt_master
Feb 11 17:45:41 salt salt-master[17426]: import salt.cli.daemons
Feb 11 17:45:41 salt salt-master[17426]:   File "/usr/lib/python3/dist-
packages/salt/cli/daemons.py", line 48, in 
Feb 11 17:45:41 salt salt-master[17426]: import salt.utils.parsers
Feb 11 17:45:41 salt salt-master[17426]:   File "/usr/lib/python3/dist-
packages/salt/utils/parsers.py", line 27, in 
Feb 11 17:45:41 salt salt-master[17426]: import salt.config as
config
Feb 11 17:45:41 salt salt-master[17426]:   File "/usr/lib/python3/dist-
packages/salt/config/__init__.py", line 101, in 
Feb 11 17:45:41 salt salt-master[17426]: _DFLT_IPC_WBUFFER =
_gather_buffer_space() * .5
Feb 11 17:45:41 salt salt-master[17426]:   File "/usr/lib/python3/dist-
packages/salt/config/__init__.py", line 86, in _gather_buffer_space
Feb 11 17:45:41 salt salt-master[17426]: total_mem =
psutil.virtual_memory().total
Feb 11 17:45:41 salt salt-master[17426]:   File "/usr/lib/python3/dist-
packages/psutil/__init__.py", line 1952, in virtual_memory
Feb 11 17:45:41 salt salt-master[17426]: ret =
_psplatform.virtual_memory()
Feb 11 17:45:41 salt salt-master[17426]:   File "/usr/lib/python3/dist-
packages/psutil/_pslinux.py", line 400, in virtual_memory
Feb 11 17:45:41 salt salt-master[17426]: mems[fields[0]] =
int(fields[1]) * 1024
Feb 11 17:45:41 salt salt-master[17426]: IndexError: list index out of
range
Feb 11 17:45:41 salt systemd[1]: salt-master.service: Main process
exited, code=exited, status=1/FAILURE

--- System information. ---
Architecture: 
Kernel:   Linux 4.19.0-2-amd64

Debian Release: buster/sid
  500 testing vwakviie2ienjx6t.onion

--- Package information. ---
Package's Depends field is empty.

Package's Recommends field is empty.

Package's Suggests field is empty.




-- 
Dirk Heinrichs
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de 


signature.asc
Description: This is a digitally signed message part


Bug#879892: [groovy] No menu entry for groovyConsole

2018-10-14 Thread Dirk Heinrichs
Am 01.01.2018 um 09:23 schrieb Dirk Heinrichs:
> Am 26.10.2017 um 22:09 schrieb Debian Bug Tracking System:
>
>> Thank you for filing a new Bug report with Debian.
> Any news here? Anybody taking care?

This is approaching its first aniversary, so could you please add the
following to the package as "/usr/share/applications/groovyConsole.desktop"?

[Desktop Entry]
Name=Groovy Console
Type=Application
Exec=/usr/bin/groovyConsole
Terminal=false
Comment=Groovy Script Console
NoDisplay=false
Categories=Development;IDE
Name[en]=Groovy Script Console

Thanks a lot...

    Dirk

BTW: The latest release is 2.5.3. Would be nice to have it in Buster soon.
-- 

Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



signature.asc
Description: OpenPGP digital signature


Bug#896921: [Pkg-salt-team] Bug#896921: Salt 2018.3.2 has been released

2018-07-01 Thread Dirk Heinrichs
Am 18.05.2018 um 10:27 schrieb Benjamin Drung:

> 2018.3 unless there is a blocking reason.

There's 2018.3.2 meanwhile. Can we get this one, then?

Bye...

    Dirk

-- 
Dirk Heinrichs 
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#896921: [Pkg-salt-team] Bug#896921: Salt 2017.7.5 has been released

2018-05-17 Thread Dirk Heinrichs
Am 15.05.2018 um 17:51 schrieb Dirk Heinrichs:
> Am 15.05.2018 um 10:23 schrieb Benjamin Drung:
>> It could, but fix was merged after the release of 2017.7.5. So I am
>> waiting for the release of of 2017.7.6/2018.3.1 that include the fix. 
> Ah, OK.

BTW: Which version are you planning to use, then? 2017 or 2018?

Bye...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#896921: [Pkg-salt-team] Bug#896921: Salt 2017.7.5 has been released

2018-05-15 Thread Dirk Heinrichs
Am 15.05.2018 um 10:23 schrieb Benjamin Drung:

> Am Sonntag, den 13.05.2018, 07:20 + schrieb Dirk Heinrichs:
>> Hi, could the version be bumped, then? 
> It could, but fix was merged after the release of 2017.7.5. So I am
> waiting for the release of of 2017.7.6/2018.3.1 that include the fix. 

Ah, OK.

Bye...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de






signature.asc
Description: OpenPGP digital signature


Bug#896921: Salt 2017.7.5 has been released

2018-05-13 Thread Dirk Heinrichs
Hi,

could the version be bumped, then?

Thanks...

Dirk
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



signature.asc
Description: OpenPGP digital signature


Bug#894602: [dpkg] Strange cron error mails from executing /etc/cron.daily/dpkg

2018-04-12 Thread Dirk Heinrichs
Am 12.04.2018 um 14:16 schrieb Guillem Jover:

> Do you perhaps have something like unattended-ugrades or something
> similar enabled on all those hosts?

No, I don't. That's one of the packages I uninstall immediately ;-)

Bye...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#894602: [dpkg] Strange cron error mails from executing /etc/cron.daily/dpkg

2018-04-02 Thread Dirk Heinrichs
Package: dpkg
Version: 1.18.24
Severity: normal

--- Please enter the report below this line. ---
Hi,

since a couple of days, I'm getting strange error mails from cron
daemon with subject

"Cron <root@mail> test -x /usr/sbin/anacron || ( cd / && run-
parts --report /etc/cron.daily )"

from some hosts. They're all related to executing /etc/cron.daily/dpkg
but with slightly different content. One host even sends 2(!) mails.

Here's the content:

Host1:

/etc/cron.daily/dpkg:
cp: cannot create regular file 'dpkg.status': File exists
mv: cannot move './/dpkg.status.5.gz' to './/dpkg.status.6.gz': No such
file or directory
mv: cannot move './/dpkg.status.4.gz' to './/dpkg.status.5.gz': No such
file or directory
mv: cannot move './/dpkg.status.3.gz' to './/dpkg.status.4.gz': No such
file or directory
mv: cannot move './/dpkg.status.2.gz' to './/dpkg.status.3.gz': No such
file or directory
mv: cannot move './/dpkg.status.1.gz' to './/dpkg.status.2.gz': No such
file or directory
cp: cannot create regular file 'dpkg.diversions': File exists
gzip: .//dpkg.diversions.0: No such file or directory
mv: cannot move './/dpkg.diversions.0.gz' to './/dpkg.diversions.1.gz':
No such file or directory
mv: cannot move 'dpkg.diversions' to './/dpkg.diversions.0': No such
file or directory
/etc/cron.daily/logrotate:
error: error renaming temp state file /var/lib/logrotate/status.tmp
run-parts: /etc/cron.daily/logrotate exited with return code 1

Host2:

/etc/cron.daily/dpkg:
mv: cannot move './/dpkg.status.5.gz' to './/dpkg.status.6.gz': No such
file or directory
mv: cannot stat './/dpkg.status.4.gz': No such file or directory
mv: cannot stat './/dpkg.status.2.gz': No such file or directory
gzip: .//dpkg.diversions.0: No such file or directory
cp: cannot create regular file 'dpkg.statoverride': File exists

Host3 (mail1):

/etc/cron.daily/dpkg:
mv: cannot move './/dpkg.status.2.gz' to './/dpkg.status.3.gz': No such
file or directory
cp: cannot create regular file 'dpkg.diversions': File exists
gzip: .//dpkg.diversions.0: No such file or directory
mv: cannot stat './/dpkg.statoverride.4.gz': No such file or directory
mv: cannot stat './/dpkg.statoverride.2.gz': No such file or directory
mv: cannot stat './/dpkg.statoverride.1.gz': No such file or directory
gzip: .//dpkg.statoverride.0: No such file or directory
mv: cannot stat './/dpkg.statoverride.0.gz': No such file or directory

Host3 (mail2):

/etc/cron.daily/dpkg:
cp: cannot create regular file 'dpkg.status': File exists
mv: cannot move './/dpkg.status.5.gz' to './/dpkg.status.6.gz': No such
file or directory
mv: cannot stat './/dpkg.status.4.gz': No such file or directory
mv: cannot stat './/dpkg.status.3.gz': No such file or directory
mv: cannot move './/dpkg.status.1.gz' to './/dpkg.status.2.gz': No such
file or directory
gzip: .//dpkg.status.0: No such file or directory
mv: cannot stat './/dpkg.status.0.gz': No such file or directory
mv: cannot stat 'dpkg.status': No such file or directory
mv: cannot stat './/dpkg.diversions.0.gz': No such file or directory
mv: cannot stat 'dpkg.diversions': No such file or directory
mv: cannot stat './/dpkg.statoverride.5.gz': No such file or directory
mv: cannot stat './/dpkg.statoverride.3.gz': No such file or directory
/etc/cron.daily/logrotate:
error: destination /var/lib/logrotate/status.tmp already exists,
renaming to /var/lib/logrotate/status.tmp-2018040206.backup
error: error renaming temp state file /var/lib/logrotate/status.tmp
run-parts: /etc/cron.daily/logrotate exited with return code 1

If I execute /etc/cron.daily/dpkg manually, it always finishes without
error.

In case it matters, these hosts are setup as LXC-based OS containers
running on libvirt. But I think I've seen these mails from physical
hosts in the past as well.


--- System information. ---
Architecture: 
Kernel:   Linux 4.14.0-0.bpo.3-amd64

Debian Release: 9.4
  600 stretch-backports vwakviie2ienjx6t.onion 
  500 syncthing   apt.syncthing.net 
  500 stable  www.deb-multimedia.org 
  500 stable  vwakviie2ienjx6t.onion 
  500 stable  sgvtcaew4bxjd7ln.onion 
  500 stable  repo.saltstack.com 
  500 stable  dl.google.com 
  500 stable  archive.grahamedgecombe.com 

--- Package information. ---
Depends   (Version) | Installed
===-+-
tar (>= 1.28-1) | 1.29b-1.1


Package's Recommends field is empty.

Suggests   (Version) | Installed
-+-===
apt  | 1.4.8
debsig-verify| 




Bye...

Dirk
-- 
Dirk Heinrichs
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de 

signature.asc
Description: This is a digitally signed message part


Bug#846377: discovered likely cause of this issue

2018-03-08 Thread Dirk Heinrichs
Am 08.03.2018 um 12:11 schrieb Michael Biebl:

> Dirk, can you confirm that adding pam_keyinit.so to
> /etc/pam.d/systemd-user solves the problem for you as well? 

No, it doesn't. After adding it and logging out and back in I still get
this:

% keyctl show @s
Keyring
 918482795 ---lswrv  0 0  keyring: _ses.20321
  92578899 s--v  0 0   \_ afs_pag: _pag

and, for example:

% systemctl --user enable syncthing
Failed to enable unit: Access denied

However, I got the hint in the related systemd issue
<https://github.com/systemd/systemd/issues/7261#issuecomment-370509405>,
that it might be possible to solve this in AFS, by using the user
keyring instead of the session keyring. Will start a discussion on this
on openafs-info soon...

Bye...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



signature.asc
Description: OpenPGP digital signature


Bug#885851: Seems to be related to AppArmor

2018-01-01 Thread Dirk Heinrichs
Hi,

> your snippets are a bit short to see if there was no active AppArmor
> profile for Thunderbird, if so you would have seen this one extra line
> from AppArmor.
>> Skipping profile in /etc/apparmor.d/disable: usr.bin.thunderbird <- 

Yes, I indeed have this line the log, but only when downgrading back to
52.5.0-1~deb9u1:

Entpacken von thunderbird (1:52.5.0-1~deb9u1) über (1:52.5.2-2~deb9u1) ...
Trigger für mime-support (3.60) werden verarbeitet ...
Trigger für desktop-file-utils (0.23-1) werden verarbeitet ...
thunderbird (1:52.5.0-1~deb9u1) wird eingerichtet ...
Neue Version der Konfigurationsdatei /etc/apparmor.d/usr.bin.thunderbird
wird installiert ...
Skipping profile in /etc/apparmor.d/disable: usr.bin.thunderbird

It didn't show up when upgrading.

> If you don't need or want AppArmor this is fine if you just remove this
> package.

This is indeed the case. I usually uninstall it right away. Must have
been kept or reinstalled without me noticing ;-). So at first it didn't
come to my mind that it could be related. I only noticed after
submitting the report.

> I guess this bug report is no clear and can be closed, at least in my
> eyes. 

Sure. Things are working for me again.

Bye...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#879892: Acknowledgement ([groovy] No menu entry for groovyConsole)

2018-01-01 Thread Dirk Heinrichs
Am 26.10.2017 um 22:09 schrieb Debian Bug Tracking System:

> Thank you for filing a new Bug report with Debian.

Any news here? Anybody taking care?

Bye...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#885851: Seems to be related to AppArmor

2017-12-31 Thread Dirk Heinrichs
Am 31.12.2017 um 12:05 schrieb Carsten Schoenert:

> You don't provide any information about the state of your machine before
> you startetd the update nor after the update. You also don't have
> appended any logging information, so how can I unpuzzle that and see
> what was going maybe wrong?

What kind of logging information? It's a desktop program. There is no log.

> Did you update from 1:52.5.0-1~deb9u1?

Yes.

> Did you had enabled AppArmor in the old version and was running before you
> started the update?

How does one enable AppArmor _IN_ TB? At least the package was
installed, but there was no process running.

> What messages was coming along the update?

Really? The usual messages from apt-get update telling me that TB
related packages have been updated.

> Please take a look into /var/log/apt/history.log and
> /var/log/apt/term.log.
What should I find there, except:

(term.log)
Vorbereitung zum Entpacken von
.../08-thunderbird_1%3a52.5.2-2~deb9u1_amd64.deb ...
Entpacken von thunderbird (1:52.5.2-2~deb9u1) über (1:52.5.0-1~deb9u1) ...
...
thunderbird (1:52.5.2-2~deb9u1) wird eingerichtet ...
Neue Version der Konfigurationsdatei /etc/apparmor.d/usr.bin.thunderbird
wird installiert ...

and

(history.log)
... thunderbird:amd64 (1:52.5.0-1~deb9u1, 1:52.5.2-2~deb9u1) ...

> Do you use a "normal" profile path /home/$USER/.{icedove,thunderbird}?

Yes.

So, from the beginning:

1) I had TB 52.5.0-1~deb9u1 installed, and it was working for all users
2) I got an update to 52.5.2-2~deb9u1, restarted TB but instead got the
message "Your Thunderbird profile cannot
be loaded. It may be missing or inaccessible.", same for other users on
the same machine.
3) Downgraded back to 52.5.0-1~deb9u1, rebooted and TB was working fine
again (wasn't working before the reboot).
4) Repeated step 2), same result, so downgraded and rebooted again.
5) Remembered that I saw the message about the new version of the
apparmor file while upgrading, so I
6) Uninstalled apparmor, retried the upgrade, message about inaccessible
profile was gone and new version was working fine.

So I guess something with "Neue Version der Konfigurationsdatei
/etc/apparmor.d/usr.bin.thunderbird" is wrong.

Happy new year...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#885851: Seems to be related to AppArmor

2017-12-30 Thread Dirk Heinrichs
Am 30.12.2017 um 17:28 schrieb Carsten Schoenert:

> Hello Dirk, Am 30.12.2017 um 13:34 schrieb Dirk Heinrichs:
>> Hi, after removing apparmor and retrying the update, it worked just
>> fine. So the problem might be somehow related to apparmor. 
> unfortunately you give no detailed information what did not work for
> you and also no logs. It's quite impossible to get any useful
> information from your bug report. So we can close this report?

I don't understand the question. What exactly is missing in

"After update of thunderbird to above version, it doesn't start anymore.
I only get a popup window, telling me "Your Thunderbird profile cannot
be loaded. It may be missing or inaccessible.". Downgrading the package
AND rebooting the machine solves the problem (yes, downgrade alone is
NOT sufficient)."

and "it worked after removing apparmor"?

Bye...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#885851: Seems to be related to AppArmor

2017-12-30 Thread Dirk Heinrichs
Hi,

after removing apparmor and retrying the update, it worked just fine. So
the problem might be somehow related to apparmor.

HTH...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#885851: [thunderbird] Security update breaks thunderbird

2017-12-30 Thread Dirk Heinrichs
Package: thunderbird
Version: 1:52.5.2-2~deb9u1
Severity: important

--- Please enter the report below this line. ---
After update of thunderbird to above version, it doesn't start anymore.
I only get a popup window, telling me "Your Thunderbird profile cannot
be loaded. It may be missing or inaccessible.". Downgrading the package
AND rebooting the machine solves the problem (yes, downgrade alone is
NOT sufficient).

--- System information. ---
Architecture: 
Kernel:   Linux 4.13.0-0.bpo.1-amd64

Debian Release: 9.3
  600 stretch-backports vwakviie2ienjx6t.onion 
  500 syncthing   apt.syncthing.net 
  500 stable  www.deb-multimedia.org 
  500 stable  vwakviie2ienjx6t.onion 
  500 stable  sgvtcaew4bxjd7ln.onion 
  500 stable  dl.google.com 
  500 stable  archive.grahamedgecombe.com 

--- Package information. ---
Depends   (Version) | Installed
===-+-===
debianutils   (>= 1.16) | 4.8.1.1
fontconfig  | 2.11.0-6.7+b1
psmisc  | 22.21-2.1+b2
x11-utils   | 7.7+3+b1
libatk1.0-0 (>= 1.12.4) | 2.22.0-1
libc6 (>= 2.17) | 
libcairo-gobject2   (>= 1.10.0) | 
libcairo2(>= 1.10.2-2~) | 
libdbus-1-3 (>= 1.9.14) | 
libdbus-glib-1-2  (>= 0.78) | 
libevent-2.0-5   (>= 2.0.10-stable) | 
libffi6  (>= 3.0.4) | 
libfontconfig1(>= 2.11) | 
libfreetype6 (>= 2.2.1) | 
libgcc1  (>= 1:4.0) | 
libgdk-pixbuf2.0-0  (>= 2.22.0) | 
libglib2.0-0(>= 2.30.0) | 
libgtk-3-0 (>= 3.4) | 
libhunspell-1.4-0   | 
libpango-1.0-0  (>= 1.14.0) | 
libpangocairo-1.0-0 (>= 1.14.0) | 
libpangoft2-1.0-0   (>= 1.14.0) | 
libpixman-1-0   (>= 0.19.6) | 
libstartup-notification0   (>= 0.8) | 
libstdc++6 (>= 5.2) | 
libvpx4  (>= 1.6.0) | 
libx11-6| 
libx11-xcb1 | 
libxcb-shm0 | 
libxcb1 | 
libxcomposite1 (>= 1:0.3-1) | 
libxdamage1  (>= 1:1.1) | 
libxext6| 
libxfixes3  | 
libxrender1 | 
libxt6  | 
zlib1g   (>= 1:1.2.3.4) | 


Recommends  (Version) | Installed
=-+-==
lightning   (= 1:52.5.0-1~deb9u1) | 1:52.5.0-1~deb9u1
myspell-en-us | 
 OR hunspell-dictionary   | 
 OR myspell-dictionary| 


Suggests  (Version) | Installed
===-+-===
apparmor| 2.11.0-3
fonts-lyx   | 2.2.3-2~bpo9+1
libgssapi-krb5-2| 1.15-1+deb9u1



Bye...

Dirk
-- 
Dirk Heinrichs
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de 

signature.asc
Description: This is a digitally signed message part


Bug#879892: [groovy] No menu entry for groovyConsole

2017-10-26 Thread Dirk Heinrichs
Package: groovy
Version: 2.4.8-1
Severity: normal

--- Please enter the report below this line. ---
groovy installs a graphical Groovy script console
(/usr/bin/groovyConsole), but there's no menu entry for it, so it has to
be started via shell.

--- System information. ---
Architecture: Kernel:   Linux 4.13.0-0.bpo.1-amd64

Debian Release: 9.1
  600 stretch-backports vwakviie2ienjx6t.onion   500 syncthing
apt.syncthing.net   500 stable  vwakviie2ienjx6t.onion   500
stable  sgvtcaew4bxjd7ln.onion   500 stable  dl.google.com
--- Package information. ---
Depends  (Version) | Installed
==-+-===
antlr  | 2.7.7+dfsg-7
default-jre-headless   | 2:1.8-58
 OR java6-runtime-headless | ivy | 2.4.0-3
junit4 | 4.12-4
libasm-java   (>= 5.0) | 5.2-2
libbsf-java| 1:2.4.0-5
libcommons-cli-java| 1.3.1-3
libcommons-logging-java| 1.2-1
libjansi-java  | 1.14-1
libjline2-java | 2.11-4
libqdox-java   | 1.12.1-2
libservlet3.1-java | 8.5.14-1+deb9u2
libxstream-java| 1.4.9-2


Recommends(Version) | Installed
===-+-===
ant | 1.9.9-1
ant-optional| 1.9.9-1
libgpars-groovy-java  (>= 1.0~) | 1.2.1-7
libjcommander-java  | 1.48-1
testng  | 6.9.12-1


Suggests(Version) | Installed
=-+-===
groovy-doc|
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



signature.asc
Description: OpenPGP digital signature


Bug#871841: [libpam-runtime] Dovecot PAM authentication broken when using unix + sssd (GSSAPI) authentication

2017-08-12 Thread Dirk Heinrichs
Package: libpam-runtime
Version: 1.1.8-3.6
Severity: normal

--- Please enter the report below this line. ---
To support clients which can't do GSSAPI, I've recently added plain PW
authentication (pam_unix.so) to a Dovecot server setup which otherwise
authenticates users against a Samba based AD via sssd (pam_sss.so).

In the default setup, generated by pam-auth-update, plain pw
authentication always failed during account setup with the following
message in the log:

pam_acct_mgmt() failed: Permission denied

To fix this, I needed to manually change this line in the generated
common-account file

account [success=1 new_authtok_reqd=done
default=ignore] pam_unix.so

to this

account [success=done new_authtok_reqd=done
default=ignore] pam_unix.so

("success=1" => "success=done"), which is equivalent to "account
sufficient ...", as requested by the Dovecot documentation.

--- System information. ---
Architecture: 
Kernel:   Linux 4.9.0-3-amd64

Debian Release: 9.1
  500 syncthing   apt.syncthing.net 
  500 stable  www.deb-multimedia.org 
  500 stable  vwakviie2ienjx6t.onion 
  500 stable  update.devolo.com 
  500 stable  sgvtcaew4bxjd7ln.onion 
  500 stable  dl.google.com 

--- Package information. ---
Depends   (Version) | Installed
===-+-=
debconf   (>= 0.5)  | 1.5.61
 OR debconf-2.0 | 
debconf(>= 1.5.19)  | 1.5.61
 OR cdebconf| 
libpam-modules (>= 1.0.1-6) | 1.1.8-3.6


Package's Recommends field is empty.

Package's Suggests field is empty.


Bye...

Dirk
-- 
Dirk Heinrichs
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de 

signature.asc
Description: This is a digitally signed message part


Bug#850421: patch for bug #850421 in libsqlcipher0

2017-08-05 Thread Dirk Heinrichs
Am 04.08.2017 um 23:19 schrieb Cyril Soler:

> Also affects Retroshare. The software is impossible to release on
> stretch because of this bug. Given the simplicity of the fix above, I
> dont understand why debian still ships with the crashing libsqlcipher0.

The even better "fix" would be to simply upgrade to 3.4.1, which
properly supports OpenSSL 1.1 ootb. See also: #863530
<http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863530>.

Bye...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



signature.asc
Description: OpenPGP digital signature


Bug#863530: [sqlcipher] Current version not compatible with OpenSSL 1.1

2017-05-28 Thread Dirk Heinrichs
Package: sqlcipher
Version: 3.2.0-2
Severity: important

--- Please enter the report below this line. ---
The currently shipped version of of sqlcipher is still linked with
OpenSSL 1.0, while most of Stretch has already migrated to 1.1. This
leads to problems in packages that use sqlcipher and at the same time
are linked with OpenSSL 1.1 libs (directly or indirectly). Version
3.4.1 of sqlcipher works/compiles fine against OpenSSL 1.1 (I already
use a self-compiled sqlcipher 3.4.1 package on my Stretch systems where
needed).

--- System information. ---
Architecture: 
Kernel:   Linux 4.9.0-2-amd64

Debian Release: 9.0
  500 testing www.deb-multimedia.org 
  500 testing vwakviie2ienjx6t.onion 
  500 testing sgvtcaew4bxjd7ln.onion 
  500 syncthing   apt.syncthing.net 
  500 stable  update.devolo.com 

--- Package information. ---
Package's Depends field is empty.

Package's Recommends field is empty.

Package's Suggests field is empty.



-- 
Dirk Heinrichs
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de 

signature.asc
Description: This is a digitally signed message part


Bug#858921: [firefox-esr] Firefox l10n not working

2017-03-28 Thread Dirk Heinrichs
mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9
e97384}/https-everywhere-...@eff.org
Package: xul-ext-https-everywhere
Status: user-disabled

Name: KDE Wallet password integration
Location: ${PROFILE_EXTENSIONS}/kwallet@guillermo.molina
Status: enabled

Name: KDE5 Wallet password integration
Location: /usr/lib/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e9
7384}/kde5wallet@guillermo.molina
Package: xul-ext-kwallet5
Status: user-disabled

Name: Konquefox
Location: ${PROFILE_EXTENSIONS}/konque...@free.fr.xpi
Status: enabled

Name: NoScript
Location: ${PROFILE_EXTENSIONS}/{73a6fe31-595d-460b-a920-
fcc0f8843232}.xpi
Status: user-disabled

Name: Oxygen KDE Optionen
Location: ${PROFILE_EXTENSIONS}/{c2a3f51e-2920-4eab-9008-
1bcb44d21d57}.xpi
Status: app-disabled

Name: Schaltfl??che "Auf meinen Wunschzettel" bei Amazon
Location: ${PROFILE_EXTENSIONS}/amznu...@amazon.com.xpi
Status: enabled

Name: SPDY indicator
Location: /usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9
e97384}/spdyindica...@chengsun.github.com
Package: xul-ext-spdy-indicator
Status: user-disabled

Name: Tab Mix Plus
Location: /usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-
13a3a9e97384}/{dc572301-7619-498c-a57d-39143191b318}
Package: xul-ext-tabmixplus
Status: user-disabled

Name: Tree Style Tab
Location: ${PROFILE_EXTENSIONS}/treestyle...@piro.sakura.ne.jp.xpi
Status: enabled

-- Plugins information
Name: GNOME Shell Integration
Location: /usr/lib/mozilla/plugins/libgnome-shell-browser-plugin.so
Package: gnome-shell
Status: enabled

Name: IcedTea-Web Plugin (using IcedTea-Web 1.6.2 (1.6.2-3.1))
Location: /usr/lib/jvm/java-8-openjdk-
amd64/jre/lib/amd64/IcedTeaPlugin.so
Package: icedtea-8-plugin:amd64
Status: enabled

Name: Shockwave Flash
Location: /usr/lib/flashplugin-nonfree/libflashplayer.so
Status: enabled

Name: Skype Buttons for Kopete
Location: /usr/lib/mozilla/plugins/skypebuttons.so
Package: kopete
Status: enabled


-- Addons package information
ii  firefox-esr45.8.0esr-1  amd64Mozilla Firefox web
browser - Ext
ii  firefox-esr-l1 45.8.0esr-1  all  German language package
for Firef
ii  gnome-shell3.22.3-2 amd64graphical shell for the
GNOME des
ii  icedtea-8-plug 1.6.2-3.1amd64web browser plugin based
on OpenJ
ii  kopete 4:16.08.1-3  amd64instant messaging and chat
applic
ii  xul-ext-adbloc 2.7.3+dfsg-1 all  advertisement blocking
extension 
ii  xul-ext-adbloc 1.3.8-1  all  companion for Adblock Plus
to cre
ii  xul-ext-all-in 0.7.28-2 all  sidebar extension for
Firefox
ii  xul-ext-colorf 31.1.0+dfsg- all  Color tabs differently and
make t
ii  xul-ext-debian 1.11-3   all  Buttons for querying
Debian-relat
ii  xul-ext-flashb 1.5.20-2 all  Mozilla extension to block
Adobe 
ii  xul-ext-https- 5.2.8-1  all  extension to force the use
of HTT
ii  xul-ext-kwalle 1.0-2amd64kwallet integration for
firefox
ii  xul-ext-spdy-i 2.2-1all  extension to show an SPDY
support
ii  xul-ext-tabmix 0.5.0.1-1all  add dozens of new
capabilities to

-- 
Dirk Heinrichs
GPG Public Key: D01B367761B0F7CE6E6D81AAD5A2E54246986015
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de 



Bug#846377: Solved (or worked around) the problem

2016-12-03 Thread Dirk Heinrichs
Hi,

I've meanwhile found a solution(?): After removing package
dbus-user-session and logging out and back in again the problem was
gone. However, I  don't know whether that is a real solution or just a
workaround.

Package description, for reference:
dbus-user-session - simple interprocess messaging system (systemd --user
integration)

Bye...

Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#846377: [systemd] /lib/systemd/systemd --user starts dbus-daemon without AFS token

2016-12-02 Thread Dirk Heinrichs
Am 01.12.2016 um 18:12 schrieb Benjamin Kaduk:
> I think that the KRB5CCNAME thing is only expected to help when combined
> with a change to run libpam-afs-session from common-session-noninteractive
> instead of common-session only.

On my system, configured with pam-auth-update (so no manual changes),
it's in both.

Bye...

Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#846377: [systemd] /lib/systemd/systemd --user starts dbus-daemon without AFS token

2016-12-01 Thread Dirk Heinrichs
Am 30.11.2016 um 21:42 schrieb Benjamin Kaduk:

> I have not absorbed the full report yet, but wanted to note that Dave Botsch 
> (IIRC)
> put together some notes on using AFS with systemd --user at:
> https://docs.google.com/document/d/1P27fP1uj-C8QdxDKMKtI-Qh00c5_9zJa4YHjnpB6ODM/pub

Will take a look, thanks.

Bye...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#846377: [systemd] /lib/systemd/systemd --user starts dbus-daemon without AFS token

2016-12-01 Thread Dirk Heinrichs
Am 01.12.2016 um 12:35 schrieb Michael Biebl:

> Dirk, could run
> systemctl --user import-environment KRB5CCNAME
> systemctl --user restart dbus.service dbus.socket
> then kill the running dconf-service process and see if it restarts with
> the correct context

Sure. Doesn't seem to help. Started evolution from the same shell
afterwards and got the same error as before.

Bye...

    Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#846377: [systemd] /lib/systemd/systemd --user starts dbus-daemon without AFS token

2016-11-30 Thread Dirk Heinrichs
Package: systemd
Version: 232-6
Severity: important

--- Please enter the report below this line. ---
I'm running systems with user home directories located in an OpenAFS
network filesystem. This used to work fine for years. However, since
some time now, some desktop environments/applications (KDE, Evolution,
etc.) have trouble writing their config files, while writing to the
same file from within a shell worked fine.

I did some investigation and found out that dbus-daemon is not started
be the pam-authenticated user session anymore, but
via /lib/systemd/systemd --user.

This in itself wouldn't be a problem, but /lib/systemd/systemd --user
has been started by PID 1 and thus doesn't run with an AFS token, which
means that all processes spawned from it don't have one either:

testuser 2013 1  0 18:54 ?00:00:00 /lib/systemd/systemd
--user
testuser 2015  2013  0 18:54 ?00:00:00 (sd-pam)
testuser 7783  2013  0 19:29 ?00:00:01 /usr/bin/dbus-daemon
--session --address=systemd: --nofork --nopidfile --systemd-activation

This means that any application that wants to access files through dbus
fails to do so, for example:

(evolution:9447): dconf-WARNING **: failed to commit changes to dconf:
GDBus.Error:org.gtk.GDBus.UnmappedGError.Quark._g_2dfile_2derror_2dquark.Code2:
Cannot open dconf database: Failed to open file
'/afs/altum.de/home/testuser/.config/dconf/user': Permission denied

To verify, I added an AFS ACL entry to each sub-directory of testuser's
home, which allowed write access for system:anyuser. Afterwards, the
errors were gone.

Of course, it's not a solution to grant unauthenticated
users write access to every user's home directory.

So, in it's current form, this setup makes most desktop environments
simply unusable.

--- System information. ---
Architecture: Kernel:   Linux 4.8.0-1-amd64

Debian Release: stretch/sid
  990 testing www.deb-multimedia.org   990 testing
ftp.de.debian.org   500 syncthing   apt.syncthing.net   500 stable
update.devolo.com   500 stable  repo.saltstack.com
--- Package information. ---
Depends   (Version) | Installed
===-+-=
libacl1   (>= 2.2.51-8) | 2.2.52-3
libapparmor1  (>= 2.9.0-3+exp2) | 2.10.95-6
libaudit1  (>= 1:2.2.1) | 1:2.6.7-1
libblkid1   (>= 2.19.1) | libc6
(>= 2.17) | libcap2 (>= 1:2.10) |
libcryptsetup4 (>= 2:1.4.3) | libgcrypt20
   (>= 1.7.0) | libgpg-error0 (>= 1.14) |
libidn11  (>= 1.13) | libip4tc0
  | libkmod2(>= 5~) |
liblz4-1  (>= 0.0~r127) | liblzma5   (>=
5.1.1alpha+20120614) | libmount1   (>= 2.26.2) |
libpam0g  (>= 0.99.7.1) | libseccomp2
   (>= 2.3.1) | libselinux1  (>= 2.1.9) |
libsystemd0   (= 232-6) | util-linux
  (>= 2.27.1) | mount (>= 2.26) |
adduser |

Package Status   (Version) | Installed
==-+-===
udev   | 232-6
dracut | initramfs-tools| 0.125


Recommends  (Version) | Installed
=-+-===
libpam-systemd| 232-6
dbus  | 1.10.12-1


Suggests   (Version) | Installed
-+-===
systemd-ui   | systemd-container| 232-6
policykit-1  | 0.105-17



--- Output from package bug script ---




-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#836576: [sssd] After reboot first login attempts fail until sssd is restarted

2016-09-04 Thread Dirk Heinrichs
Package: sssd
Version: 1.13.4-3
Severity: normal

--- Please enter the report below this line. ---
sssd is used to authenticate users against MIT Kerberos 5 and OpenLDAP.
User's home directories are stored in OpenAFS. Whenever the system is
rebooted, the first login attempts fail with "Cannot enter homedir,
using /", until I login as root and restart sssd using "systemctl
restart sssd". After this, everything works as expected.

--- System information. ---
Architecture: amd64
Kernel: Linux 4.6.0-1-amd64

Debian Release: stretch/sid
990 testing www.deb-multimedia.org
990 testing ftp.de.debian.org
500 syncthing apt.syncthing.net
500 stable update.devolo.com
500 stable repo.saltstack.com
500 nightly pkg.tox.chat

--- Package information. ---
Package's Depends field is empty.

Package's Recommends field is empty.

Package's Suggests field is empty.

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#823748: Other binaries produce "illegal instruction" errors, too

2016-05-08 Thread Dirk Heinrichs
Hi,

looks like there are other binaries which produce "illegal instruction"
errors after upgrade, one of them being /usr/sbin/sshd.

Please fix this ASAP, as the system becomes unusable because of this.

Thanks...

Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



Bug#823748: tar: illegal hardware instruction breaks apt-get upgrade

2016-05-08 Thread Dirk Heinrichs
Package: tar
Version: 1.28-2.2
Severity: critical
Justification: breaks unrelated software

Dear Maintainer,

upgrading tar breaks apt-get/dpkg due to "illegal instruction" errors.

   * What led up to the situation?

   tar was upgraded: tar (1.28-2.1 => 1.28-2.2)

   * What exactly did you do (or not do) that was effective (or
 ineffective)?

   apt-get dist-upgrade

   * What was the outcome of this action?

   All packages upgraded after tar failed during unpack:

   dpkg-deb: error: subprocess tar was killed by signal (Illegal instruction)
   dpkg: error processing archive
   /var/cache/apt/archives/libssl1.0.2_1.0.2h-1_i386.deb (--unpack):
subprocess dpkg-deb --control returned error exit status 2
   dpkg-deb: error: subprocess tar was killed by signal (Illegal instruction)
   dpkg: error processing archive 
/var/cache/apt/archives/ntp_1%3a4.2.8p7+dfsg-3_i386.deb (--unpack):
subprocess dpkg-deb --control returned error exit status 2
   dpkg-deb: error: subprocess tar was killed by signal (Illegal instruction)
   dpkg: error processing archive 
/var/cache/apt/archives/libselinux1_2.5-2_i386.deb (--unpack):
subprocess dpkg-deb --control returned error exit status 2
   Errors were encountered while processing:
/var/cache/apt/archives/libssl1.0.2_1.0.2h-1_i386.deb
/var/cache/apt/archives/ntp_1%3a4.2.8p7+dfsg-3_i386.deb
/var/cache/apt/archives/libselinux1_2.5-2_i386.deb
   E: Sub-process /usr/bin/dpkg returned an error code (1)


   * What outcome did you expect instead?

   All package upgrades should have succeeded.

I could temporarily resolve the problem by copying the previous tar
version from another box.


-- System Information:
Debian Release: stretch/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i586)

Kernel: Linux 4.4.7
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages tar depends on:
ii  libacl1  2.2.52-3
ii  libc62.22-7
ii  libselinux1  2.5-2

tar recommends no packages.

Versions of packages tar suggests:
ii  bzip21.0.6-8
pn  ncompress
pn  tar-scripts  
ii  xz-utils 5.1.1alpha+20120614-2.1

-- no debconf information



Bug#822415: [src:linux] Kernel 4.5 breaks OpenAFS client module build

2016-04-24 Thread Dirk Heinrichs
Package: src:linux
Version: 4.5.0-1
Severity: important

--- Please enter the report below this line. ---
OpenAFS client kernel module (openafs-modules-dkms) don't build for kernel 
4.5:

# dkms build -k 4.5.0-1-amd64 -m openafs -v 1.6.17

Kernel preparation unnecessary for this kernel.  Skipping...

Building module:
cleaning build area(bad exit status: 2)
(./configure --disable-linux-syscall-probing --with-afs-sysname=amd64_linux26 
--with-linux-kernel-packaging --with-linux-kernel-
headers=/lib/modules/4.5.0-1-amd64/build && make && mv src/libafs/MODLOAD-
*/openafs.ko 
.)
(bad exit status: 2)
Error! Bad return status for module build on kernel: 4.5.0-1-amd64 (x86_64)
Consult /var/lib/dkms/openafs/1.6.17/build/make.log for more information.

make.log is attached.

--- System information. ---
Architecture: amd64
Kernel:   Linux 4.4.0-1-amd64

Debian Release: stretch/sid
  990 testing www.deb-multimedia.org 
  990 testing vwakviie2ienjx6t.onion 
  990 testing security.debian.org 
  500 utopic  ppa.launchpad.net 
  500 unstabledownload.jitsi.org 
  500 syncthing   apt.syncthing.net 
  500 stable  update.devolo.com 
  500 nightly pkg.tox.chat 

--- Package information. ---
Package's Depends field is empty.

Package's Recommends field is empty.

Package's Suggests field is empty.
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de
DKMS make.log for openafs-1.6.17 for kernel 4.5.0-1-amd64 (x86_64)
So 24. Apr 08:43:33 CEST 2016
checking for a BSD-compatible install... /usr/bin/install -c
checking whether build environment is sane... yes
/var/lib/dkms/openafs/1.6.17/build/build-tools/missing: Unknown `--is-lightweight' option
Try `/var/lib/dkms/openafs/1.6.17/build/build-tools/missing --help' for more information
configure: WARNING: 'missing' script is too old or missing
checking for a thread-safe mkdir -p... /bin/mkdir -p
checking for gawk... gawk
checking whether make sets $(MAKE)... yes
checking whether make supports nested variables... yes
checking for gcc... gcc
checking whether the C compiler works... yes
checking for C compiler default output file name... a.out
checking for suffix of executables... 
checking whether we are cross compiling... no
checking for suffix of object files... o
checking whether we are using the GNU C compiler... yes
checking whether gcc accepts -g... yes
checking for gcc option to accept ISO C89... none needed
checking whether gcc understands -c and -o together... yes
checking for style of include used by make... GNU
checking dependency style of gcc... none
checking build system type... x86_64-pc-linux-gnu
checking host system type... x86_64-pc-linux-gnu
checking how to run the C preprocessor... gcc -E
checking for grep that handles long lines and -e... /bin/grep
checking for egrep... /bin/grep -E
checking for ANSI C header files... yes
checking for sys/types.h... yes
checking for sys/stat.h... yes
checking for stdlib.h... yes
checking for string.h... yes
checking for memory.h... yes
checking for strings.h... yes
checking for inttypes.h... yes
checking for stdint.h... yes
checking for unistd.h... yes
checking for flex... no
checking for lex... no
checking for pkg-config... /usr/bin/pkg-config
checking pkg-config is at least version 0.9.0... yes
checking for libxslt... no
checking for saxon... no
checking for xalan-j... no
checking for xsltproc... xsltproc
checking for docbook2pdf... no
checking for dblatex... dblatex
checking for library containing strerror... none required
checking for pid_t... yes
checking for size_t... yes
checking whether ln -s works... yes
checking for ranlib... ranlib
checking for bison... bison -y
checking if lex is flex... no
checking whether byte order is known at compile time... yes
checking whether byte ordering is bigendian... no
checking whether printf understands the %z length modifier... yes
checking your OS... linux
checking if gcc accepts -march=pentium... no
checking if gcc needs -fno-strength-reduce... yes
checking if gcc needs -fno-strict-aliasing... yes
checking if gcc supports -fno-common... yes
checking if gcc supports -pipe... yes
checking if linux kbuild requires EXTRA_CFLAGS... yes
checking for linux kernel module build works... yes
checking operation follow_link in inode_operations... no
checking operation put_link in inode_operations... no
checking for linux/config.h... no
checking for linux/completion.h... yes
checking for linux/exportfs.h... yes
checking for linux/freezer.h... yes
checking for linux/key-type.h... yes
checking for linux/semaphore.h... yes
checking for linux/seq_file.h... yes
checking for struct vfs_path... no
checking for kuid_t... yes
checking for back

Bug#809408: [systemd] systemctl -a: Failed to list units: No such method 'ListUnitsFiltered'

2015-12-31 Thread Dirk Heinrichs
Am Donnerstag 31 Dezember 2015, 00:42:56 schrieb Michael Biebl:

> Control: tags -1 moreinfo unreproducible
> 
> Am 30.12.2015 um 13:26 schrieb Dirk Heinrichs:
> > Package: systemd
> > Version: 228-2+b1
> > Severity: important
> > 
> > 
> > Debian Release: stretch/sid
> > 
> > --- Package information. ---
> > libsystemd0 (= 215-5+b1) |
> 
> systemctl -a works fine here (on v228)
> 
> You seem to be mixing different versions. I'm unsure how you managed to
> do that, given that systemd has a strictly versioned dependency on
> libsystemd. Are the versions in this bug report correct?

Didn't recognize that. But no, that's not correct, don't know where that 
version comes from.

# dpkg --list|grep systemd 
ii  libpam-systemd:amd64  228-2+b1  
 
amd64system and service manager - PAM module
ii  libsystemd0:amd64 228-2+b1  
 
amd64systemd utility library
ii  libsystemd0:i386  228-2+b1  
 
i386 systemd utility library
ii  python-systemd231-2 
 
amd64Python 2 bindings for systemd
ii  systemd   228-2+b1  
 
amd64system and service manager
ii  systemd-sysv  228-2+b1  
 
amd64    system and service manager - SysV links

Bye...

Dirk
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de


signature.asc
Description: This is a digitally signed message part.


Bug#809408: Error message changed after reinstalling systemd packages

2015-12-31 Thread Dirk Heinrichs
Am Donnerstag 31 Dezember 2015, 14:16:52 schrieben Sie:

> Am 31.12.2015 um 10:57 schrieb Dirk Heinrichs:
> > I've meanwhile reinstalled all systemd-related packages. It still doesn't
> > work, but I get a different error message now:
> > 
> > # systemctl -a
> > Failed to list units: Launch helper exited with unknown return code 1
> 
> Are you sure systemd is your active PID 1?

Aaargh, it wasn't. Don't know why, somehow the "init=/bin/systemd" part 
disappeared from my kernel command line. dpkg-reconfigure'd grub-pc to add it 
again and rebooted. Everything's fine again.

> Do you have systemd-sysv installed?

Yes, I do.

Anyway, works again. Can be closed.

Thanks a lot and sorry for the fuzz.

Bye...

Dirk
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de


signature.asc
Description: This is a digitally signed message part.


Bug#807741: Everything's fine

2015-12-31 Thread Dirk Heinrichs
Hi again,

no need to re-open, it's working for me now.

Bye...

Dirk
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de


signature.asc
Description: This is a digitally signed message part.


Bug#809409: Solved

2015-12-31 Thread Dirk Heinrichs
This was a side effect of #809408. Can be closed.

Bye...

Dirk
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de


signature.asc
Description: This is a digitally signed message part.


Bug#809408: Error message changed after reinstalling systemd packages

2015-12-31 Thread Dirk Heinrichs
I've meanwhile reinstalled all systemd-related packages. It still doesn't 
work, but I get a different error message now:

# systemctl -a
Failed to list units: Launch helper exited with unknown return code 1

Bye...

Dirk
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de


signature.asc
Description: This is a digitally signed message part.


Bug#809408: [systemd] systemctl -a: Failed to list units: No such method 'ListUnitsFiltered'

2015-12-30 Thread Dirk Heinrichs
Package: systemd
Version: 228-2+b1
Severity: important

--- Please enter the report below this line. ---
See subject, cannot list units anymore.

--- System information. ---
Architecture: amd64
Kernel:   Linux 4.3.0-1-amd64

Debian Release: stretch/sid
  990 testing www.deb-multimedia.org 
  990 testing security.debian.org 
  990 testing ftp.de.debian.org 
  500 utopic  ppa.launchpad.net 
  500 unstabledownload.jitsi.org 
  500 stable  update.devolo.com 
  500 nightly pkg.tox.chat 

--- Package information. ---
Depends(Version) | Installed
-+-==
libacl1(>= 2.2.51-8) | 2.2.52-2
libaudit1   (>= 1:2.2.1) | 1:2.4.4-4
libblkid1(>= 2.19.1) | 2.27.1-1
libcap2  (>= 1:2.10) | 1:2.24-12
libcryptsetup4  (>= 2:1.4.3) | 2:1.6.6-5
libkmod2 (>= 5~) | 21-1
libpam0g   (>= 0.99.7.1) | 1.1.8-3.1
libselinux1   (>= 2.1.9) | 
libsystemd0 (= 215-5+b1) | 
util-linux (>= 2.19.1-2) | 
initscripts(>= 2.88dsf-53.2) | 
sysv-rc  | 
udev | 
acl  | 
adduser  | 
libcap2-bin  | 


Package Status  (Version) | Installed
=-+-===
udev  | 228-2+b1


Recommends  (Version) | Installed
=-+-===
libpam-systemd| 228-2+b1
dbus  | 1.10.6-1


Suggests(Version) | Installed
=-+-===
systemd-ui| 



--- Output from package bug script ---
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de


signature.asc
Description: This is a digitally signed message part.


Bug#809409: [libvirt-bin] Can't start LXC containers anymore: "error: At least one cgroup controller is required: No such device or address"

2015-12-30 Thread Dirk Heinrichs
Package: libvirt-bin
Version: 1.2.21-2
Severity: important

--- Please enter the report below this line. ---
I cannot start LXC containers anymore, which worked fine ~10 days ago. When I 
try to start a container today, I get this error:

% virsh --connect lxc:/// start stretch32
error: Failed to start domain stretch32
error: At least one cgroup controller is required: No such device or address

There hasn't been any change in the configuration of any container, nor an 
update of any libvirt or lxc related package since then. There has been a 
kernel update, though. Don't know whether that could be related or not.

--- System information. ---
Architecture: amd64
Kernel:   Linux 4.3.0-1-amd64

Debian Release: stretch/sid
  990 testing www.deb-multimedia.org 
  990 testing security.debian.org 
  990 testing ftp.de.debian.org 
  500 utopic  ppa.launchpad.net 
  500 unstabledownload.jitsi.org 
  500 stable  update.devolo.com 
  500 nightly pkg.tox.chat 

--- Package information. ---
Package's Depends field is empty.

Package's Recommends field is empty.

Package's Suggests field is empty.
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de


signature.asc
Description: This is a digitally signed message part.


Bug#809311: [package:liblmdb0] /sbin/ldconfig.real: /usr/lib/x86_64-linux-gnu/liblmdb.so.0 is not a symbolic link

2015-12-29 Thread Dirk Heinrichs
Package: package:liblmdb0
Version: 0.9.17-1
Severity: minor

--- Please enter the report below this line. ---
Whenever ldconfig runs, I get the output as in the subject.

--- System information. ---
Architecture: amd64
Kernel:   Linux 4.3.0-1-amd64

Debian Release: stretch/sid
  990 testing www.deb-multimedia.org 
  990 testing security.debian.org 
  990 testing ftp.de.debian.org 
  500 utopic  ppa.launchpad.net 
  500 unstabledownload.jitsi.org 
  500 stable  update.devolo.com 
  500 nightly pkg.tox.chat 

--- Package information. ---
Package's Depends field is empty.

Package's Recommends field is empty.

Package's Suggests field is empty.
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de


signature.asc
Description: This is a digitally signed message part.


Bug#809203: linux-image-586 4.3+70 installs a 4.3.3 kernel for 686 only, which doesn't boot on 586

2015-12-28 Thread Dirk Heinrichs
Package: linux-image-586
Version: 4.3+70
Severity: important

Dear Maintainer,

I'm running Debian on an old AMD K6-III system, which went fine up to
kernel 4.2.6. After upgrading to 4.3.3, I only have a i686-capable
kernel, which doesn't run on this system anymore.

I needed to select the older kernel to make the system boot again.

*** Reporter, please consider answering these questions, where appropriate ***

   * What led up to the situation?

 apt-get update; apt-get dist-upgrade

   * What exactly did you do (or not do) that was effective (or
 ineffective)?

 Reboot after above commands.

   * What was the outcome of this action?

 System went into reboot loop.

   * What outcome did you expect instead?

 System should have rebooted into working state.

*** End of the template - remove these template lines ***


-- System Information:
Debian Release: stretch/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i586)

Kernel: Linux 4.2.0-1-586
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages linux-image-586 depends on:
ii  linux-image-686  4.3+70

linux-image-586 recommends no packages.

linux-image-586 suggests no packages.

-- no debconf information



Bug#807741: Not fixed

2015-12-20 Thread Dirk Heinrichs
Hi,

Got the new version (2015.8.3+ds-2) per todays apt-get update.
Unfortunately, it's not fixed. I still get:

[...]
salt-master (2015.8.3+ds-2) wird eingerichtet ...
Job for salt-master.service failed because a timeout was exceeded. See
"systemctl status salt-master.service" and "journalctl -xe" for details.
invoke-rc.d: initscript salt-master, action "start" failed.
dpkg: Fehler beim Bearbeiten des Paketes salt-master (--configure):
 Unterprozess installiertes post-installation-Skript gab den Fehlerwert
1 zurück
Trigger für systemd (228-2) werden verarbeitet ...
Fehler traten auf beim Bearbeiten von:
 salt-master
E: Sub-process /usr/bin/dpkg returned an error code (1)
apt-get install salt-master  4,90s user 2,89s system 4% cpu 2:36,58 total
100 root@moria ~ # systemctl status
salt-master.service 
  
:(
● salt-master.service - The Salt Master Server
   Loaded: loaded (/lib/systemd/system/salt-master.service; enabled;
vendor preset: enabled)
   Active: failed (Result: timeout) since So 2015-12-20 10:06:56 CET;
15s ago
 Main PID: 9014 (code=exited, status=0/SUCCESS)

Dez 20 10:05:25 moria systemd[1]: Starting The Salt Master Server...
Dez 20 10:06:55 moria systemd[1]: salt-master.service: Start operation
timed out. Terminating.
Dez 20 10:06:56 moria systemd[1]: Failed to start The Salt Master Server.
Dez 20 10:06:56 moria systemd[1]: salt-master.service: Unit entered
failed state.
Dez 20 10:06:56 moria systemd[1]: salt-master.service: Failed with
result 'timeout'.

Please re-open.

Bye...

Dirk

-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de




signature.asc
Description: OpenPGP digital signature


Bug#807731: [package:bogofilter] dist-upgrade removes bogofilter-sqlite in favour of bogofilter-bdb

2015-12-12 Thread Dirk Heinrichs
Package: package:bogofilter
Version: 1.2.4+dfsg1-3+b1
Severity: normal

--- Please enter the report below this line. ---
Since a few days, doing an apt-get dist-upgrade results in bogofilter-sqlite 
being replaced by bogofilter-bdb. As I try to avoid BDB as much as possible, I 
need to remove bogofilter-bdb and reinstall bogofilter-sqlite afterwards. This 
is quite annoying.

--- System information. ---
Architecture: amd64
Kernel:   Linux 4.2.0-1-amd64

Debian Release: stretch/sid
  990 testing www.deb-multimedia.org 
  990 testing security.debian.org 
  990 testing ftp.de.debian.org 
  500 utopic  ppa.launchpad.net 
  500 unstabledownload.jitsi.org 
  500 stable  update.devolo.com 
  500 nightly pkg.tox.chat 

--- Package information. ---
Package's Depends field is empty.

Package's Recommends field is empty.

Package's Suggests field is empty.
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de


signature.asc
Description: This is a digitally signed message part.


Bug#807741: [package:salt-master] salt-master.service start times out

2015-12-12 Thread Dirk Heinrichs
Package: package:salt-master
Version: 2015.8.3+ds-1
Severity: serious

--- Please enter the report below this line. ---
After upgrade from version 2015.8.1+ds-2 to 2015.8.3+ds-1 the salt-
master.service times out upon start. This already happens during apt-get. If I 
try to start it afterwards, I get:

# systemctl start salt-master
Job for salt-master.service failed because a timeout was exceeded. See 
"systemctl status salt-master.service" and "journalctl -xe" for details.

However, the process runs for some time, I can see logging output using 
journactl -f in a 2nd shell, but once systemctl returns the salt-master 
process is also gone.

If I start it from the shell directly, it runs just fine.

Since the package is not usable in this state, I've set the severity to 
"serious"...
--- System information. ---
Architecture: amd64
Kernel:   Linux 4.2.0-1-amd64

Debian Release: stretch/sid
  990 testing www.deb-multimedia.org 
  990 testing security.debian.org 
  990 testing ftp.de.debian.org 
  500 utopic  ppa.launchpad.net 
  500 unstabledownload.jitsi.org 
  500 stable  update.devolo.com 
  500 nightly pkg.tox.chat 

--- Package information. ---
Package's Depends field is empty.

Package's Recommends field is empty.

Package's Suggests field is empty.
-- 
Dirk Heinrichs <dirk.heinri...@altum.de>
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de


signature.asc
Description: This is a digitally signed message part.


Bug#776987: Jessie backports

2015-06-13 Thread Dirk Heinrichs
Hi,

any chance to get this into jessie-backports? It's needed by RetroShare
http://www.retroshare.org, which is heading towards its 0.6 release.

Bye...

Dirk

-- 
Dirk Heinrichs dirk.heinri...@altum.de
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de



signature.asc
Description: OpenPGP digital signature


Bug#778196: No, not fixed

2015-02-28 Thread Dirk Heinrichs

Hi,

installation of 1.6.9-2+deb8u1 produces the following error:

Setting up openafs-modules-dkms (1.6.9-2+deb8u1) ...
Loading new openafs-1.6.9 DKMS files...
Building only for 3.16.0-4-amd64
Building initial module for 3.16.0-4-amd64
Error! Bad return status for module build on kernel: 3.16.0-4-amd64 
(x86_64)
Consult /var/lib/dkms/openafs/1.6.9/build/make.log for more 
information.


make.log attached.

Please reopen.

Thanks...

Dirk

--
Dirk Heinrichs dirk.heinri...@altum.de
Tel: +49 (0)2471 209385 | Mobil: +49 (0)176 34473913
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de

DKMS make.log for openafs-1.6.9 for kernel 3.16.0-4-amd64 (x86_64)
Sa 28. Feb 20:48:36 CET 2015
checking for a BSD-compatible install... /usr/bin/install -c
checking whether build environment is sane... yes
/var/lib/dkms/openafs/1.6.9/build/build-tools/missing: Unknown `--is-lightweight' option
Try `/var/lib/dkms/openafs/1.6.9/build/build-tools/missing --help' for more information
configure: WARNING: 'missing' script is too old or missing
checking for a thread-safe mkdir -p... /bin/mkdir -p
checking for gawk... gawk
checking whether make sets $(MAKE)... yes
checking whether make supports nested variables... yes
checking for gcc... gcc
checking whether the C compiler works... yes
checking for C compiler default output file name... a.out
checking for suffix of executables... 
checking whether we are cross compiling... no
checking for suffix of object files... o
checking whether we are using the GNU C compiler... yes
checking whether gcc accepts -g... yes
checking for gcc option to accept ISO C89... none needed
checking whether gcc understands -c and -o together... yes
checking for style of include used by make... GNU
checking dependency style of gcc... none
checking build system type... x86_64-unknown-linux-gnu
checking host system type... x86_64-unknown-linux-gnu
checking how to run the C preprocessor... gcc -E
checking for grep that handles long lines and -e... /bin/grep
checking for egrep... /bin/grep -E
checking for ANSI C header files... yes
checking for sys/types.h... yes
checking for sys/stat.h... yes
checking for stdlib.h... yes
checking for string.h... yes
checking for memory.h... yes
checking for strings.h... yes
checking for inttypes.h... yes
checking for stdint.h... yes
checking for unistd.h... yes
checking for flex... no
checking for lex... no
checking for pkg-config... /usr/bin/pkg-config
checking pkg-config is at least version 0.9.0... yes
checking for libxslt... no
checking for saxon... no
checking for xalan-j... no
checking for xsltproc... xsltproc
checking for docbook2pdf... no
checking for dblatex... dblatex
checking for library containing strerror... none required
checking for pid_t... yes
checking for size_t... yes
checking whether ln -s works... yes
checking for ranlib... ranlib
checking for bison... no
checking for byacc... no
checking if lex is flex... no
checking whether byte order is known at compile time... yes
checking whether byte ordering is bigendian... no
checking whether printf understands the %z length modifier... yes
checking your OS... linux
checking if gcc accepts -march=pentium... no
checking if gcc needs -fno-strength-reduce... yes
checking if gcc needs -fno-strict-aliasing... yes
checking if gcc supports -fno-common... yes
checking if gcc supports -pipe... yes
checking if linux kbuild requires EXTRA_CFLAGS... yes
checking for linux kernel module build works... yes
checking for linux/config.h... no
checking for linux/completion.h... yes
checking for linux/exportfs.h... yes
checking for linux/freezer.h... yes
checking for linux/key-type.h... yes
checking for linux/semaphore.h... yes
checking for linux/seq_file.h... yes
checking for struct vfs_path... no
checking for kuid_t... yes
checking for write_begin in struct address_space_operations... yes
checking for name in struct backing_dev_info... yes
checking for session_keyring in struct cred... yes
checking for ctl_name in struct ctl_table... no
checking for d_u.d_alias in struct dentry... yes
checking for d_automount in struct dentry_operations... yes
checking for i_alloc_sem in struct inode... no
checking for i_blkbits in struct inode... yes
checking for i_blksize in struct inode... no
checking for i_mutex in struct inode... yes
checking for i_security in struct inode... yes
checking for flock in struct file_operations... yes
checking for iterate in struct file_operations... yes
checking for read_iter in struct file_operations... yes
checking for sendfile in struct file_operations... no
checking for mount in struct file_system_type... yes
checking for truncate in struct inode_operations... no
checking for preparse in struct key_type... yes
checking for instantiate_prep in struct key_type... no
checking for path in struct nameidata... yes
checking for owner in struct proc_dir_entry

Bug#775718: installation-guide: Appendix B.4: Several security flaws

2015-01-19 Thread Dirk Heinrichs
Source: installation-guide
Severity: normal

Dear Maintainer,

in appendix B.4 (http://d-i.debian.org/manual/en.i386/apbs04.html) of
the installation guide the user is advised to generate an encrypted
password using the command

printf r00tme | mkpasswd -s -m md5

This is severely flawed in two ways:

1. It leaves the password in the shells history file as clear text.
2. It still uses MD5 instead of SHA512.

Better use a simple

mkpasswd -m sha-512

It's also not clear that the user needs to install the whois package
to get the mkpasswd command.

Bye...

Dirk


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#742976: Please promote to testing

2014-11-24 Thread Dirk Heinrichs
Hi,

given that this is a security related package and that this version is the 
first one to be able to work with systemd's journal, it would be nice if it 
would be promoted to jessie soon.

Thanks...

Dirk
-- 
Dirk Heinrichs dirk.heinri...@altum.de
Tel: +49 (0)2471 209385 | Mobil: +49 (0)176 34473913
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Tox: he...@toxme.se
Sichere Internetkommunikation: http://www.retroshare.org
Privacy Handbuch: https://www.privacy-handbuch.de


signature.asc
Description: This is a digitally signed message part.


Bug#706069: Same here

2014-08-10 Thread Dirk Heinrichs
Hi,

I see the same problem here, on Jessie. However, in my case the connections 
are local (lxc:/// and qemu:///system). Everything works fine, except creating 
new VMs. The New VM dialog freezes after ~5 seconds and the program needs to 
be killed.

Meanwhile, upstream has released version 1.0.1 5 months ago.

Bye...

Dirk
-- 
Dirk Heinrichs dirk.heinri...@altum.de
Tel: +49 (0)2471 209385 | Mobil: +49 (0)176 34473913
GPG Public Key CB614542 | Jabber: dirk.heinri...@altum.de
Sichere Internetkommunikation: http://www.retroshare.org


signature.asc
Description: This is a digitally signed message part.


Bug#734161: krb5-kdc: Init script for kpropd missing

2014-01-04 Thread Dirk Heinrichs
Package: krb5-kdc
Version: 1.11.3+dfsg-3+nmu1
Severity: wishlist

Dear Maintainer,
reading about setting up incremental database propagation to slave
KDCs, I found that there is no init script available for the kerberos
propagation daemon (kpropd) which handles this incremental db
propagation (see
http://web.mit.edu/~kerberos/krb5-latest/doc/admin/database.html#incr-db-prop).

Systemd service files for all Kerberos services would also be nice
(should already be available in Fedora and/or Arch).

Thanks a lot.

-- System Information:
Debian Release: jessie/sid
  APT prefers testing
  APT policy: (500, 'testing'), (1, 'experimental')
Architecture: i386 (i586)

Kernel: Linux 3.11-2-486
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages krb5-kdc depends on:
ii  debconf [debconf-2.0]  1.5.52
ii  krb5-config2.3
ii  krb5-user  1.11.3+dfsg-3+nmu1
ii  libc6  2.17-97
ii  libcomerr2 1.42.8-1
ii  libgssapi-krb5-2   1.11.3+dfsg-3+nmu1
ii  libgssrpc4 1.11.3+dfsg-3+nmu1
ii  libk5crypto3   1.11.3+dfsg-3+nmu1
ii  libkadm5clnt-mit8  1.11.3+dfsg-3+nmu1
ii  libkadm5srv-mit8   1.11.3+dfsg-3+nmu1
ii  libkdb5-7  1.11.3+dfsg-3+nmu1
ii  libkeyutils1   1.5.6-1
ii  libkrb5-3  1.11.3+dfsg-3+nmu1
ii  libkrb5support01.11.3+dfsg-3+nmu1
ii  libverto-libev10.2.4-1
ii  libverto1  0.2.4-1
ii  lsb-base   4.1+Debian12

krb5-kdc recommends no packages.

Versions of packages krb5-kdc suggests:
ii  krb5-admin-server  1.11.3+dfsg-3+nmu1
pn  krb5-kdc-ldap  none
ii  xinetd [inet-superserver]  1:2.3.15-3

-- debconf information excluded


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#734161: systemd service files

2014-01-04 Thread Dirk Heinrichs
I once wrote systemd service files for the KDC and Admin Server for 
Exherbo. Maybe they can be used as a starting point.


--
Dirk Heinrichs dirk.heinri...@altum.de
Tel: +49 (0)2471 209385 | Mobil: +49 (0)176 34473913
GPG Public Key C2E467BB | Jabber: dirk.heinri...@altum.de

[Unit]
Description=Kerberos 5 Admin Server
After=syslog.target network.target

[Service]
PIDFile=/run/kadmind.pid
ExecStart=/usr/sbin/kadmind -P /run/kadmind.pid

[Install]
WantedBy=multi-user.target
[Unit]
Description=Kerberos 5 Key Distribution Center
After=syslog.target network.target

[Service]
PIDFile=/run/krb5kdc.pid
EnvironmentFile=/etc/conf.d/krb5kdc.conf
ExecStart=/usr/sbin/krb5kdc -P /run/krb5kdc.pid $KDC_ARGS

[Install]
WantedBy=multi-user.target


Bug#636214: u-boot-tools: /etc/fw_env.config for Guruplug

2013-01-04 Thread Dirk Heinrichs
Hi,

since u-boot-tools still doesn't contain sample fw_env.config files,
I've attached mine for Guruplug.

Bye...

Dirk
-- 
Dirk Heinrichs dirk.heinri...@altum.de
Tel: +49 (0)2471 209385 | Mobil: +49 (0)176 34473913
GPG Public Key C2E467BB | Jabber: dirk.heinri...@altum.de
# Configuration file for fw_(printenv/saveenv) utility.
# Up to two entries are valid, in this case the redundant
# environment sector is assumed present.
# Notice, that the Number of sectors is ignored on NOR.

# MTD device name   Device offset   Env. size   Flash sector size   
Number of sectors

# NAND example
/dev/mtd0   0x6 0x2 0x2 
1



signature.asc
Description: Digital signature


Bug#658904: Any chance to get this released for wheezy?

2012-04-29 Thread Dirk Heinrichs
Am 04.04.2012 11:22, schrieb Ian Campbell:

 On Mon, 2012-04-02 at 17:59 +0200, Dirk Heinrichs wrote:
 Hi,

 my Guruplug is still running kernel 3.1.0, but the current kernel
 package is 3.2.0. This means that the plug wont be able to reboot w/o
 manual intervention until the fixed uboot is released.
 
 The new version has been uploaded but has not yet transitioned from sid
 to wheezy.
 
 According to
 http://release.debian.org/migration/testing.pl?package=u-boot
 this is due to a build failure on ia64:
 https://buildd.debian.org/status/fetch.php?pkg=u-bootarch=ia64ver=2011.12-3stamp=1331486439
 
 I've no idea what's going on there though, the failure looks pretty
 wierd to me (a cat from /dev/null appears to have produced something
 other than an empty file!). Might be something to do with #630386?

Although it's nice to know that my poor little guruplug survived another
month w/o reboot, I'd really like to have that fixed u-boot released.
There are lots of other packages which are not available on every
platform, so I wonder why a build failure on ia64 (What's that anyway
:)? ) can block an ARM package for such a long time? Or is there
anything relevant to ia64 in this package?

Bye...

Dirk



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#658904: Any chance to get this released for wheezy?

2012-04-02 Thread Dirk Heinrichs
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Hi,

my Guruplug is still running kernel 3.1.0, but the current kernel
package is 3.2.0. This means that the plug wont be able to reboot w/o
manual intervention until the fixed uboot is released.

I'm currently crossing fingers, hoping that nothing happens which
would cause a reboot, so please, please, please release the fixed uboot.

Thanks...

Dirk
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iD8DBQFPeczy8NVtnsLkZ7sRAtP9AJ4nqNq9iVFKBkR7clfb/eFg73IBFgCghsGG
9zHMHWBMwIzQ5HPbKZbaPZE=
=b/6/
-END PGP SIGNATURE-



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#664177: libpam-ssh has been removed from Debian

2012-03-16 Thread Dirk Heinrichs
Package: libpam-ssh
Severity: important

Dear Maintainer,

the package seems to have been removed from Wheezy. However, it is an
important part in case users home directories are located in AFS. It
seems to be the only reliable and desktop/shell independant solution
for spawning an ssh-agent AND adding the users keys to it (in case
login and key password are identical).

Please consider re-adding it before wheezy is released.

Thanks...

Dirk

BTW: Having it patched to support ecdsa keys would also be nice :)

-- System Information:
Debian Release: wheezy/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: armel (armv5tel)

Kernel: Linux 3.1.0-1-kirkwood
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#645788: openssh-server: /run on tmpfs breaks sshd started from inetd

2012-02-24 Thread Dirk Heinrichs

Am 24.02.2012 09:55, schrieb Colin Watson:

On Tue, Oct 18, 2011 at 06:56:07PM +0200, Dirk Heinrichs wrote:

I'm running sshd with priviledge separation enabled from inetd, but
since some time I can't login anymore after reboot.

In /var/log/auth.log, I see the followin message:

fatal: Missing privilege separation directory: /var/run/sshd

The reason for this is that /var/run is now a symlink to /run, which
is mounted as a tmpfs, thus it doesn't survive a reboot.


I'm not sure what I can do about this.  The init script ensures that
/var/run/sshd exists; isn't it your responsibility to make suitable
arrangements when locally configuring sshd to start from inetd?


Well, that's what I did, of course. I've put this into /etc/rc.local:

[[ -d /run/sshd ]] || mkdir -p /run/sshd


(I suppose you could argue that the Debian packaging should set the
privsep path to /var/lib/sshd instead.  That seems quite difficult to
change now though ...)


Hmm, why has it been changed from the default (/var/empty) in the first 
place?


If the package would simply do what README.privsep says, everything 
would be fine, no matter how sshd is finally invoked. From README.privsep:


You should do something like the following to prepare the privsep
preauth environment:

# mkdir /var/empty
# chown root:sys /var/empty
# chmod 755 /var/empty
# groupadd sshd
# useradd -g sshd -c 'sshd privsep' -d /var/empty -s /bin/false sshd

/var/empty should not contain any files.

configure supports the following options to change the default
privsep user and chroot directory:

  --with-privsep-path=xxx Path for privilege separation chroot
  --with-privsep-user=user Specify non-privileged user for privilege 
separation


Bye...

Dirk



--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#645788: Wish: Let the user choose how sshd should be used

2012-02-24 Thread Dirk Heinrichs

Hi again,

if I think about it, it would be nice if the package came with the 
possibility to use both methods (normal daemon mode and (x)inetd mode 
for not so powerful machines). This way, the user could choose at 
installation time (or later via dpkg-reconfigure) how sshd should be 
started.


Bye...

Dirk



--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#645788: openssh-server: /run on tmpfs breaks sshd started from inetd

2011-10-18 Thread Dirk Heinrichs
Package: openssh-server
Version: 1:5.9p1-1
Severity: important

Dear Maintainer,

I'm running sshd with priviledge separation enabled from inetd, but since some 
time I can't login anymore after reboot.

In /var/log/auth.log, I see the followin message:

fatal: Missing privilege separation directory: /var/run/sshd

The reason for this is that /var/run is now a symlink to /run, which is mounted 
as a tmpfs, thus it doesn't survive a reboot.

Bye...

Dirk

-- System Information:
Debian Release: wheezy/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: armel (armv5tel)

Kernel: Linux 2.6.39.4
Locale: LANG=de_DE.utf8, LC_CTYPE=de_DE.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages openssh-server depends on:
ii  adduser3.113
ii  debconf [debconf-2.0]  1.5.40   
ii  dpkg   1.16.1   
ii  libc6  2.13-21  
ii  libcomerr2 1.42~WIP-2011-07-02-1
ii  libgcc11:4.6.1-4
ii  libgssapi-krb5-2   1.9.1+dfsg-1 
ii  libkrb5-3  1.9.1+dfsg-1 
ii  libpam-modules 1.1.3-4  
ii  libpam-runtime 1.1.3-4  
ii  libpam0g   1.1.3-4  
ii  libselinux12.1.0-1  
ii  libssl1.0.01.0.0e-2 
ii  libwrap0   7.6.q-21 
ii  lsb-base   3.2-28   
ii  openssh-client 1:5.9p1-1
ii  procps 1:3.2.8-11   
ii  zlib1g 1:1.2.3.4.dfsg-3 

Versions of packages openssh-server recommends:
ii  openssh-blacklist0.4.1
ii  openssh-blacklist-extra  0.4.1
ii  xauth1:1.0.6-1

Versions of packages openssh-server suggests:
pn  molly-guard   none
pn  monkeysphere  none
pn  rssh  none
pn  ssh-askpass   none
pn  ufw   none

-- debconf information excluded



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#616560: Fix works

2011-03-25 Thread Dirk Heinrichs
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Hi,

I can confirm that the fix from msg #5 works. All local filesystems are
cleanly unmounted upon reboot.

Bye...

Dirk
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iD8DBQFNjOY38NVtnsLkZ7sRAqEAAJ9deAwHQRxhFyPWI4ZX06XUsJAN5ACgmb45
sB3k7kXKPMm+1XKB2dGrWV8=
=PD//
-END PGP SIGNATURE-



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#616560: umountfs: nothing to unmount if / is on UBI volume

2011-03-23 Thread Dirk Heinrichs
Package: initscripts
Version: 2.88dsf-13.1
Severity: normal

I also see this issue on a *Plug. It's not only that due to this bug the
system doesn't umount local file systems, it also forces entering a maintenance
shell upon next boot to fix the not cleanly unmounted filesystems. 
Unfortunately,
on the Plug Computer this means attaching the JTAG module and get access via
serial console.

This really needs a fix ASAP.

Here are the last few lines of output for halting the system, just for 
reference:

==
Cleaning up ifupdown
Will now deactivate swap:swapoff on /dev/mapper/rohan-swap
.
Shutting down LVM Volume Groups  Can't deactivate volume group rohan with 5 
open logical volume(s)
 failed!
Mounting root filesystem read-only...done.
Will now halt.
sd 0:0:0:0: [sda] Synchronizing SCSI cache
sd 0:0:0:0: [sda] Stopping disk
System halted.
==

Bye...

Dirk

-- System Information:
Debian Release: 6.0.1
  APT prefers stable
  APT policy: (500, 'stable'), (1, 'experimental')
Architecture: armel (armv5tel)

Kernel: Linux 2.6.38
Locale: LANG=de_DE.utf8, LC_CTYPE=de_DE.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages initscripts depends on:
ii  coreutils   8.5-1GNU core utilities
ii  debianutils 3.4  Miscellaneous utilities specific t
ii  libc6   2.11.2-10Embedded GNU C Library: Shared lib
ii  lsb-base3.2-23.2squeeze1 Linux Standard Base 3.2 init scrip
ii  sysv-rc 2.88dsf-13.1 System-V-like runlevel change mech
ii  sysvinit-utils  2.88dsf-13.1 System-V-like utilities

Versions of packages initscripts recommends:
ii  e2fsprogs 1.41.12-2  ext2/ext3/ext4 file system utiliti
ii  psmisc22.11-1utilities that use the proc file s

initscripts suggests no packages.

-- no debconf information



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#505092: update stuck at 99% [5 Packages gzip 0]

2011-01-21 Thread Dirk Heinrichs
Package: apt
Version: 0.8.10
Severity: normal

I also see this on squeeze/armel. A quick look at the process list shows
a hanging /usr/lib/apt/methods/rred process, which is not killable (even
with -9), the only way to get rid of it is a reboot.

18563 root  20   0 36048  30m  30m R 98.1  6.1  44:22.07 rred   
  

-- Package-specific info:

-- apt-config dump --

APT ;
APT::Architecture armel;
APT::Build-Essential ;
APT::Build-Essential:: build-essential;
APT::Install-Recommends 1;
APT::Install-Suggests 0;
APT::Acquire ;
APT::Acquire::Translation environment;
APT::NeverAutoRemove ;
APT::NeverAutoRemove:: ^firmware-linux.*;
APT::NeverAutoRemove:: ^linux-firmware$;
APT::NeverAutoRemove:: ^linux-image.*;
APT::NeverAutoRemove:: ^kfreebsd-image.*;
APT::NeverAutoRemove:: ^linux-restricted-modules.*;
APT::NeverAutoRemove:: ^linux-ubuntu-modules-.*;
APT::Never-MarkAuto-Sections ;
APT::Never-MarkAuto-Sections:: metapackages;
APT::Never-MarkAuto-Sections:: restricted/metapackages;
APT::Never-MarkAuto-Sections:: universe/metapackages;
APT::Never-MarkAuto-Sections:: multiverse/metapackages;
APT::Never-MarkAuto-Sections:: oldlibs;
APT::Never-MarkAuto-Sections:: restricted/oldlibs;
APT::Never-MarkAuto-Sections:: universe/oldlibs;
APT::Never-MarkAuto-Sections:: multiverse/oldlibs;
Dir /;
Dir::State var/lib/apt/;
Dir::State::lists lists/;
Dir::State::cdroms cdroms.list;
Dir::State::mirrors mirrors/;
Dir::State::extended_states extended_states;
Dir::State::status /var/lib/dpkg/status;
Dir::Cache var/cache/apt/;
Dir::Cache::archives archives/;
Dir::Cache::srcpkgcache srcpkgcache.bin;
Dir::Cache::pkgcache pkgcache.bin;
Dir::Etc etc/apt/;
Dir::Etc::sourcelist sources.list;
Dir::Etc::sourceparts sources.list.d;
Dir::Etc::vendorlist vendors.list;
Dir::Etc::vendorparts vendors.list.d;
Dir::Etc::main apt.conf;
Dir::Etc::netrc auth.conf;
Dir::Etc::parts apt.conf.d;
Dir::Etc::preferences preferences;
Dir::Etc::preferencesparts preferences.d;
Dir::Etc::trusted trusted.gpg;
Dir::Etc::trustedparts trusted.gpg.d;
Dir::Bin ;
Dir::Bin::methods /usr/lib/apt/methods;
Dir::Bin::dpkg /usr/bin/dpkg;
Dir::Media ;
Dir::Media::MountPath /media/apt;
Dir::Log var/log/apt;
Dir::Log::Terminal term.log;
Dir::Log::History history.log;
Dir::Ignore-Files-Silently ;
Dir::Ignore-Files-Silently:: ~$;
Dir::Ignore-Files-Silently:: \.disabled$;
Dir::Ignore-Files-Silently:: \.bak$;
Dir::Ignore-Files-Silently:: \.dpkg-[a-z]+$;
DPkg ;
DPkg::Pre-Install-Pkgs ;
DPkg::Pre-Install-Pkgs:: /usr/sbin/dpkg-preconfigure --apt || true;
CommandLine ;
CommandLine::AsString apt-config dump;

-- (no /etc/apt/preferences present) --


-- /etc/apt/sources.list --

deb http://ftp.de.debian.org/debian/ squeeze main contrib non-free
deb http://security.debian.org/ squeeze/updates main contrib non-free
#deb http://volatile.debian.org/debian-volatile squeeze/volatile main contrib 
non-free

#deb http://xi.rename-it.nl/debian/ testing-auto/dovecot-2.0 main
deb-src http://xi.rename-it.nl/debian/ testing-auto/dovecot-2.0 main

deb http://ftp.debian.org/debian experimental main

-- System Information:
Debian Release: 6.0
  APT prefers testing
  APT policy: (500, 'testing'), (1, 'experimental')
Architecture: armel (armv5tel)

Kernel: Linux 2.6.37
Locale: LANG=de_DE.utf8, LC_CTYPE=de_DE.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages apt depends on:
ii  debian-archive-keyring  2010.08.28   GnuPG archive keys of the Debian a
ii  gnupg   1.4.10-4 GNU privacy guard - a free PGP rep
ii  libc6   2.11.2-7 Embedded GNU C Library: Shared lib
ii  libgcc1 1:4.4.5-8GCC support library
ii  libstdc++6  4.4.5-8  The GNU Standard C++ Library v3
ii  zlib1g  1:1.2.3.4.dfsg-3 compression library - runtime

apt recommends no packages.

Versions of packages apt suggests:
pn  apt-doc   none (no description available)
ii  aptitude  0.6.3-3.2  terminal-based package manager (te
ii  bzip2 1.0.5-6high-quality block-sorting file co
ii  dpkg-dev  1.15.8.8   Debian package development tools
pn  lzma  none (no description available)
pn  python-aptnone (no description available)

-- no debconf information



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#505092: update stuck at 99% [18 Packages rred 0 B]

2011-01-21 Thread Dirk Heinrichs
Hmm, seems I was to quick in responding to this bug, my output differs
by one word: rred instead of gzip:

99% [18 Packages rred 0 B]

So it may be a different one.



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#527161: Seems it has reappeared in 2.1.22.dfsg1-23+squeeze1

2009-06-19 Thread Dirk Heinrichs
Hi,

just updated my squeeze system, and now I also get this error:

# sasldblistusers2
DB-get: method not permitted before handle's open method

If I look at the executable, I see that it's linked against libdb-4.6.so. From 
the previous posts I got the impression that it should be linked against 
libdb-4.7.so.

Bye...

Dirk


signature.asc
Description: This is a digitally signed message part.