libera/#devuan/ Friday, 2018-09-14

nemodoes devuan use the debian kernel unmodified?04:02
nemohttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876141  ← (asking due to this which impacts my SO's devuan laptop)04:02
gnarfaceyes, devuan uses the debian kernel unmodified04:02
nemodirm04:03
nemo*durn04:03
nemoguess I really will have to build my own04:03
nemoI guess enabling one little flag shouldn't break much hopefully04:03
nemomight have to pin the kernel04:03
gnarfaceif you name it correctly it won't replace your custom kernel04:21
nemowell... given my total lack of familiarity with this, not placing super high odds on that, but here's hoping! ☺04:22
nemo(debian kernel packaging that is)04:23
nemodoing my best w/ guides I've found so far, even though the "up to date" one is addressing situations that don't really apply here04:23
xrogaanW: Failed to fetch http://deb.devuan.org/devuan/dists/ascii-proposed/InRelease: Clearsigned file isn't valid, got 'NOSPLIT' (does the network require authentication?)04:23
xrogaanWhat kind of issue is that?04:24
nemohttps://askubuntu.com/questions/899009/sudo-apt-update-always-giving-clearsigned-file-isnt-valid-got-nosplit-does    (google - no, not familiar ☺ )04:26
xrogaanis it normal that the InRelease file is empty?04:28
xrogaannemo: well devuan is a bit special as it somehow mirrors with debian's repo. I believe we download most packages from debian's repository.04:30
nemoyeah. it's just a thin overlay04:30
xrogaanonly that one is failing, everybody else is just fine.04:31
nemo(thankfully, since it increases the odds I'll be able to convert most of the debian/ubuntu machines over here)04:31
xrogaanoh, I use /devuan/ for proposed, but everybody else uses /merged/04:32
golinuxhttps://devuan.org/os/etc/apt/sources.list04:36
nemoyeeep totally screwed that kernel up.04:41
nemoodd 'cause it was using the amd64 config04:41
nemono more wifi, no more sound, still no touchpad04:42
nemotime to go back to the other one04:42
nemonice. no more usb either04:42
xrogaangolinux: yeah, but the /devuan/ thing generate the NOSPLIT error.05:36
golinuxHow do you know that?05:39
golinuxYou have it right.  There is no /merged on proposed.05:40
xrogaanI know05:41
xrogaanlook at the error, my source is correct.05:42
xrogaanam I the only one with this issue?05:56
xrogaanCan I try a direct mirror instead of deb.devuan.org?05:56
xrogaanCommon wisdom from the internet say that a proxy might be misconfigured. I have none.06:02
jellygolinux: no idea, did not ask06:27
xrogaanyeah, so bad mirror06:51
xrogaanI had some bad experience with the round robin.06:52
xrogaanI need a way to blame somebody.06:52
Humpelst1lzchenuhm, the latest firefox-esr security update broke sound somehow. Any ideas on that?06:56
Jjp137it only supports PulseAudio I believe so if you don't have that installed, that might be why07:03
Humpelst1lzchenJjp137: wtf?07:04
Jjp137you could probably use apulse to work around it07:04
Jjp137yup blame Mozilla07:04
Jjp137I haven't updated it myself b/c of that07:04
Humpelst1lzchennot sure if using a ff with known security issues is a solution..07:05
Humpelst1lzchenlol apulse... "PulseAudio emulation for ALSA07:06
Humpelst1lzchenlets just add another layer on top of another layer on top of another layer07:07
Jjp137lol yea it's silly07:07
Humpelst1lzchensurpris�ngly it works with apulse..07:10
Jjp137nice07:11
ErRandirlol I did not know about apulse. Brilliant.07:49
KatolaZ_xrogaan: which is the issue with deb.devuan.org?08:38
xrogaanit resolved itself08:39
xrogaanInRelease files were empty08:39
xrogaanor something08:40
xrogaanI have no idea what was the issue, just that I got an error and no way to know which mirror generated it.08:40
KatolaZ_xrogaan: which suite?08:41
xrogaan>> <xrogaan> W: Failed to fetch http://deb.devuan.org/devuan/dists/ascii-proposed/InRelease: Clearsigned file isn't valid, got 'NOSPLIT' (does the network require authentication?)08:41
xrogaanwhat's a suite?08:42
KatolaZ_ascii-proposed08:42
xrogaaneventually the InRelease file got populated with content (was 0 byte at the time)08:43
KatolaZ_xrogaan: maybe you just hit the split second when one of the mirror was syncing?08:43
xrogaanno, I did asked several times in a row08:43
xrogaanwell, "in a row" >> as I was trying to figure out what was wrong08:43
KatolaZ_that's pretty strange then08:44
xrogaanThere may have been one or several bad mirrors.08:44
KatolaZ_xrogaan: that's why it's strange08:44
KatolaZ_since we haven't had reports of missing or corrupt files08:45
KatolaZ_:|08:45
KatolaZ_I will keep an eye on that anyway08:45
KatolaZ_thanks for letting us know08:45
KatolaZ_:)08:45
xrogaanwould have given you more detail if I knew how to know which ip apt is hitting08:46
xrogaanby the time I excluded my local network and started to investigate all the different mirrors, the issue was resolved.08:47
xrogaanI would have go through everything in the round robin to see if all InRelease file were empty.08:47
KatolaZ_xrogaan: there is no need to do that08:47
KatolaZ_just shout08:47
KatolaZ_:)08:47
xrogaangot stuff like this: http://dpaste.com/1GHMQ8708:51
KatolaZ_that's an empty file08:54
xrogaanyes, yes it is.08:55
xrogaanbut from where?08:56
KatolaZ_xrogaan: but why do you need to have ascii-proposed in the repos?08:56
KatolaZ_(that' not related, just asking)08:56
xrogaanwhy no?08:57
xrogaanwhy not*?08:57
KatolaZ_well, all the packages in there were migrated to ascii IIRC08:57
KatolaZ_that's just a temporary suite08:57
KatolaZ_anyway, I will keep an eye on this08:59
xrogaanI don't know why it's activated, it's just is.09:03
xkr47another day, another debian 8 -> devuan ascii upgrade20:03
xkr47I like getting back in control. Also the procedure is pleasant. :)20:04
gnu_srs1xkr47: ;)21:20
xkr47I hate to say it but "Make Debian Great Again" sure nails it :D21:26
xkr47or would nail it if the maga thing would not ruin it21:27
xkr47btw on the page https://devuan.org/os/documentation/dev1fanboy/ I would recommend renaming all occurences of "Migrate" to "Migrate from Debian" as to make more people spot the gold that's available for free21:39
xkr47it might even improve SEO21:40
bigtittythe minimal xorg install page is pure sex21:40
bigtittyit's how i did my i3 install21:40
bigtittyarguably the least painful minimali3 install i've ever done in a distro21:40
xkr47if I want to set up a local devuan mirror, what do I need to do?22:16
xkr47wget -r the base directory and just update the urls to my local copy?22:17
xkr47I would just need a snapshot to get a bunch of virtual machines updated from debian to ascii quickly22:17
KatolaZxkr47: mirror of what?22:17
xkr47I'd then change the urls back for future updates/upgrades22:18
gnarfacexkr47: a mirror is overkill for that.  just use apt-cacher-ng22:18
xkr47devuan ascii22:18
KatolaZagain22:18
KatolaZmirror of what?22:18
KatolaZinstall media?22:18
KatolaZor packages?22:18
xkr47thanks, gnarface already closed my issue :D22:18
KatolaZnp22:18
xkr47btw, I'm a little concerned that the swapping of repos from debian to devuan uses http urls, and then you run "apt-get install devuan-keyring --allow-unauthenticated"22:22
xkr47this basically creates a clear mitm attack vector22:22
xkr47if I understood it correctly22:22
gnarfaceyea if you're paranoid about that there's a couple better ways to do it22:23
xkr47BUT it seems pkgmaster.devuan.org (the server used for apt sources) supports https as well22:23
xkr47so I think that would perhaps be good enough22:23
gnarfacethe key in that keyring is on public keyservers, you could just get it with gpg directly and use apt-add-key22:24
gnarfacethen verify it matches the one in the package22:24
xkr47after you get the keyring in you can go back to http (to save devuan cpu load) and be able to verify packages normally22:24
gnarfaceor you could probably just verify the checksum on the package too22:24
banshihttps://software.intel.com/en-us/blogs/2018/09/10/designing-firmware-for-an-open-world22:24
xkr47gnarface, would you recommend against using https (even temporarily) as a solution?22:25
gnarfacehmm. it's not called apt-add-key wtf is it called... i forget22:25
xkr47(I mean, it would solve the problem, do you agree?)22:25
djphapt-key add [...]22:26
gnarfacexkr47: no, if you're worried about a man-in-the-middle attack, https can't protect you if they've hijacked your DNS service22:26
gnarfacedjph: thanks22:26
djph'welcome :)22:26
xkr47true, but then the same goes for public keyservers?22:26
gnarfaceyes, but, the key is visually verifiable22:26
gnarfaceyou can make sure it's the right key before you use it22:27
xkr47how?22:27
gnarfacedjph: do you remember the command for that off the top of your head too?22:27
gnarfacei'd have to dig through the gpg manpage22:27
djphwhich?22:27
gnarfacejust printing a key to the console22:27
gnarfaceso you know it's the same key22:27
gnarfaceor the keysig or whatever it's called22:27
djphgpg --export ?22:28
xkr47so how do you know it's the correct one then?22:28
gnarfaceis that it?  or is it just gpg --list-keys?22:28
xkr47when you have the key dumped on screen..22:28
djphi mran thatll print the ----begin pgp key ---- stuff22:28
gnarfacexkr47: then you compare it to the value listed on the web page and in the package in the repos22:28
djphotherwise gpg --list-keys --fingerprint i think22:28
xkr47gnarface, at least the attack would have to be a lot more sophisticated to swap out all those services :)22:29
gnarfacewell, at some point you have to trust something.  if you can't trust your DNS you can't trust anything though.22:31
xkr47:D22:31
xkr47well at least you have dnssec enabled on your domain, that helps ^^22:32
gnarfacewell not MY domain technically.  i'm not actually a member of the staff.  however, they do hang out here occasionally and any of them could also just paste the key fingerpint in channel for you too22:32
xkr47^^22:33
KatolaZxkr47: the signing key fingerprint is reported in the ASCII Release Notes22:34
KatolaZhttps://files.devuan.org/devuan_ascii/Release_notes.txt22:34
xkr47thanks for taking interest to answer my questions despite the improbability of the issue22:34
KatolaZimprobability is not an excuse22:35
KatolaZwhen it comes to security22:35
xkr47I guess you can't employ gpg in your installation instructions because one might not be able to install it in the before-devuan stage if you have a too old distro22:37
KatolaZuh?22:37
xkr47orr... does apt always depend on gpg?22:37
gnarfaceit has as far back as i can remember22:37
gnarfacei don't think the key formats change very often22:37
gnarfaceit's something you should be able to do from a debian install22:37
xkr47I mean to use gpg to download the keys instead of the --allow-unauthenticated step22:37
KatolaZxkr47: apt Depends: gpg22:37
xkr47right22:38
KatolaZyou can't use gpg to download the keys22:38
gnarfacexkr47: yea, that's the apt add-key command djph mentioned above.  you can totally manually add that key to apt without this package.22:38
xkr47so is the gpg-way more secure than using https servers?22:38
KatolaZunless you trust the source...22:38
xkr47mmmh22:38
KatolaZxkr47: what do you mean?22:39
KatolaZ"more secure" than what?22:39
gnarfacexkr47: the idea is you *don't* trust the public keyserver implicitly without verifying the fingerprint on the key visually22:39
KatolaZyou should get the key22:39
KatolaZand you can verify that you got the correct one22:39
djphgnarface: and trusting a minimum number of signers.22:39
KatolaZby checking that its fingerprints correspods to the one published in the release notes22:39
xkr47would it be too cumbersome to have these steps in the migration docs?22:39
KatolaZxkr47: have you read the release notes file?22:40
KatolaZthose steps are already there22:40
xkr47no :(22:40
xkr47I read https://devuan.org/os/documentation/dev1fanboy/migrate-to-ascii22:40
gnarfacexkr47: (i'm pretty sure the process is outlined somewhere on the debian wiki too)22:40
xkr47here were some instructions to get the signing keys from https://files.devuan.org/ :  https://devuan.org/os/documentation/dev1fanboy/general-information22:42
gnarfacewhen was that written? i'm not sure that hostname still points to the same place22:43
gnarfacethey might have changed it to packages.devuan.org22:44
gnarfaceor maybe pkgmaster.devuan.org22:45
xkr47soo which is the correct hostname for packages22:48
xkr47https://devuan.org/os/documentation/dev1fanboy/migrate-to-jessie says pkgmaster.devuan.org22:48
xkr47https://files.devuan.org/devuan_ascii/Release_notes.txt says deb.devuan.org22:49
gnarfacexkr47: pkgmaster is the primary repo.  deb.devuan.org is the mirror fanout22:50
gnarfacethey should both work but mirrors experience transient failures during updates22:50
gnarface(deb.devuan.org was added more recently)22:51
xkr47where I live (Finland), pkgmaster.devuan.org and *.deb.devuan.org all resolve to 5.196.38.1822:51
xkr47while deb.devuan.org resolves to 14 ips22:52
xkr47of which one is that 5.196.38.1822:52
gnarface5.196.38.18 is correct, i'm getting that here for pkgmaster too22:52
xkr47ah, fi.deb.devuan.org CNAME pkgmaster22:53
KatolaZxkr47: deb.devuan.org is a round-robin pool22:53
KatolaZxkr47: Release notes are authoritative22:53
xkr47yeah.. but why do fi, se, dk, uk, us and ch all go to the same as pkgmaster? country-specifc ones not yet set up properly?22:53
KatolaZ(i.e., use deb.devuan.org)22:53
xkr47ok22:54
KatolaZxkr47: because we don't have 281 mirrors?22:54
KatolaZ:)22:54
KatolaZwe are working on that22:54
KatolaZsee my email on DNG today22:54
xkr47thanks22:54
KatolaZyw22:54
xkr47DNG?22:54
KatolaZuntil 10 months ago we had just 1 master server and 1 mirror22:54
KatolaZnow we have 1722:54
KatolaZDNG is the mailing list22:55
xkr47ok22:55
xkr47https://lists.dyne.org/lurker/message/20180914.151733.910d656f.en.html22:56
xkr47is it very expensive to get localized dns?22:58
xkr47(at least I thought that's a thing :)22:58
xkr47soo https://devuan.org/os/documentation/dev1fanboy/migrate-to-ascii could be updated to use deb.devuan.org...23:00
KatolaZxkr47: what do you mean by "localized DNS"?23:01
xkr47oh, it seems the guide is already updated in git but not on the site.. https://git.devuan.org/dev1fanboy/Upgrade-Install-Devuan/blob/master/migrate-to-ascii.md23:02
KatolaZxkr47: I guessed golinux  is making some edits there23:03
xkr47KatolaZ, in amsterdam I get23:03
xkr47www.google.com.295INA172.217.10.423:03
xkr47sorry for the tabs23:03
xkr47while in Finland I get 6 different IPs starting with 64.233.162.23:03
KatolaZxkr47: have you noticed we are not google Inc.? :)23:04
xkr47YES23:04
xkr47:)23:04
KatolaZgood :)23:04
xkr47"why don't I have a nice cup of shut the irc up now?23:05
bigtittyguys23:05
bigtittyhow do i develop autism23:06
bigtittynot in the literal sense23:06
bigtittybut in the i-dont-know-what-is-boredom-and-lonliness-sense23:06
bigtittyOh fuck, sorry, wrong channel23:06
xkr47you install systemd? :D23:06
xkr47sorry I didn't understand the question fully and went with a cheap answer. sorry for any offense I caused..23:07
bigtittynah no problem23:07
bigtittyguess i'm gonna have to do meth again for it23:08
xkr47sorry I won't be able to help you with anything past that point23:08
DonkeyHoteisorry but doing meth is worse than systemd23:10
xkr47meh, the apt-cacher-ng in devuan jessie does not contain devuan mirrors23:24
golinuxKatolaZ: I emailed a correction to chillfan maybe a month ago ago and never heard that he even received it.  Have not seen him anywhere since last spring.23:29
golinuxI have never made any edits to his pages.  Do not feel comfortable mucking around in his stuff.23:29
gnarfacexkr47: someone else was complaining about that too... can you just change the contents of /usr/lib/apt-cacher-ng/deb_mirrors.gz ?23:34
xkr47sure23:34
xkr47it's a devuan system.. you can do things :)23:35
gnarfacexkr47: lemme know if it works23:35
xkr47heh btrfs snapshots ftw23:37
xkr47I wanted to compress 5G worth of files in a directory with bzip223:37
xkr47now I have 7G worth of files23:38
KatolaZgolinux: OK23:39
KatolaZI remember we actually saw him back in june, at a dev meeting23:39
xkr47gnarface, should I create a merge request on https://git.devuan.org/devuan-packages/apt-cacher-ng if I get it to work?23:43
gnarfacexkr47: i'm the wrong person to ask about that, but i think yes, maybe.  make sure the one in ascii isn't already fixed before you do though.23:44
xkr47welp that oughta be in that repo if that's the case, no?23:44
gnarfacei'm the wrong person to ask about that too, but now that you mention it, probably you're right :)23:44
* xkr47 bows gracefully23:45
gnarfacei really thought that thing just used the system's existing sources.list23:46
gnarfacei guess i was wrong about that23:46
gnarfacethere are other apt caching proxies in there23:46
gnarfacebut it shouldn't be difficult to fix this one either23:46
xkr47I don't know23:49
xkr47let me see :)23:50
xkr47I just looked at the configuration23:50

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!