openbsd-misc mailing list

FromSubjectsort iconDate
David
library resolution in 4.1

Hi all

Set up fresh copy of 4.1 on my laptop, installed all the base tgz
modules (including all X server stuff), set PKG_PATH to my local ftp
mirror, and to get xfce, used the command:
pkg_add -nv xfwm4

which produced

parsing xfwm4-4.2.3.2p1
Dependencies for xfwm4-4.2.3.2p1 resolve to: libxfce4mcs-4.2.3p0,
xfce-mcs-manager-4.2.3p2, libxfcegui4-4.2.3p3, gettext-0.14.6,
libiconv-1.9.2p3 (todo: libxfce4mcs-4.2.3p0,libxfcegui4-4.2.3p3,xfce-
mcs-manager-4.2.3p2)
xfwm4-4.2.3.2p1:parsing libxfce...

Oct 29, 8:16 pm 2007
Unix Fan
Silver River R3.5 Enclosure, IDE/ATA - MBR write failure?

Hey, I'm using OpenBSD 4.1-STABLE and I just today purchased a 250GiG Western Digital drive and a cheap USB 2.0 enclosure..

I'm trying to setup the partitions on the device using an old Pentium 2 with a USB 1.0 controller, (usb0 at uhci0.)

Anyway, the device ""does"" show up when I plug it in.. but when I attempt to save any MBR changes it displays an error..

[Copy & Pasted]
umass0 at uhub0 port 1 configuration 1 interface 0
umass0: Super Top USB 2.0 IDE DEVICE, rev 2.00/2.01, addr 2
umass0...

Oct 30, 7:48 pm 2007
Gerardo Santana Góm...
OpenBSD CD sets arriving to Mexico

I ordered it on September 18th and I got them today, October 30th (for
those paisanos that want to know how long it takes.)

I'm already running OpenBSD 4.2 of course from some time ago, but
didn't want to miss the opportunity to get my DVD case and stickers to
show off to my co-workers.

Actually I bought two sets because I'm giving one to a client.
Everyone of them gets an original CD set.

A note for the maintainer of www.openbsd.org/orders.html: e-compugraf
doesn't seem to sell OpenBSD in Mex...

Oct 30, 7:13 pm 2007
Theo de Raadt
Re: OpenBSD CD sets arriving to Mexico

It is three stickers on one sheet. The stickiest stickers we've ever
found.

Oct 30, 7:32 pm 2007
Greg Thomas
Re: OpenBSD CD sets arriving to Mexico

Is there artwork online for these? I ask because I rarely crack open
my CD sets. But the "big puffy" sounds intriguing.

Greg

--
Ticketmaster and Ticketweb suck, but everyone knows that:
http://ticketmastersucks.org
Strangeness in the low desert: http://lodesertprotosites.org
Dethink to survive - Mclusky

Oct 30, 7:41 pm 2007
Antti Harri
Re: OpenBSD CD sets arriving to Mexico

One? I have big puffy, "OpenBSD" and "OpenSSH"
stickers.

--
Antti Harri

Oct 30, 7:25 pm 2007
Dragos Ruiu
In Memoriam: Jun-ichiro Hagino

With great sadness, I regret to inform you that Itojun
will not be presenting his great knowledge of IPv6 at
PacSec. I have been informed by several sources
that he passed away yesterday.

Funeral services will be held on Nov 7th at Rinkai-Saijo
in Tokyo. There aren't many details of his passing,
so please let his family and relatives mourn in peace
for now. My heartfelt condolances go out to them,
and all of his many friends.

I knew Itojun as one of the smartest and kindest persons
I have ...

Oct 30, 6:10 pm 2007
Eduardo Tongson
Re: In Memoriam: Jun-ichiro Hagino

Thats sad man. He was still active 10/25
$Id: index.html,v 1.32 2007/10/25 06:28:10 itojun Exp $
<http://ipv6samurais.com/ipv6samurais/>

I noticed on his videos he was always coughing. Must be a respiratory ailment.
May he rest in peace.

Oct 30, 6:59 pm 2007
Diana Eichert
Re: In Memoriam: Jun-ichiro Hagino

I only knew him from the work he did with IPv6 but I know
he will be missed by myself and many, many others. I was
just thinking about him a couple of weeks ago when I
attended a NANOG / ARIN meeting that centered around IPv6
almost in it's entirety.

Itojun, may you find eternal peace.

diana

Oct 30, 6:36 pm 2007
Claus
Server trouble shooting

Background:

I'm running an web server with the Apache from the base install, php,
pureftp and postgresql database to serve multiple websites. Each
websites runs in its own instance of apache and one extra instance of
apache is doing reverse proxy via the domain name. In all 5 independent
apache instances are started. I've done this to separate the domains so
that php won't be able to access the data from another domain.

A simplified graphic representation:

Internet
...

Oct 30, 2:49 pm 2007
Brian A. Seklecki
Re: Server trouble shooting

...you could be researching a Lights-out-Management solution for your
server (Dell DRAC, Sun LOM). Best all-around solution is a PC-Weasel
(realweasel.com) connected to the system next to it (Or a RAS
concentrator)

If the system is completing 3-way TCP handshake, then you're dead in the
water. Consider making the system highly available.

~BAS

Oct 30, 7:30 pm 2007
Claus Niesen
Re: Server trouble shooting

The console terminal didn't respond either. I could use Ctrl-Alt-F2 to switch consoles but the console terminal wouldn't respond at all to key strokes. I didn't see any error messages on the console itself either. Faulty hardware or is it lack of RAM due to the multiple apache instances?

OpenBSD 4.0-stable (GENERIC) #3: Wed Mar 14 14:13:09 CDT 2007
claus@server1.xxxxxx.us:/usr/src/sys/arch/i386/compile/GENERIC
cpu0: Intel Pentium II ("GenuineIntel" 686-class, 512KB L2 cache) 266 MHz
cpu0: FPU...

Oct 30, 6:47 pm 2007
Karsten McMinn
Re: Server trouble shooting

ddb (4). (trace and ps) Have remote accesible console on the server.
Check for hardware problems. Check for irregular network traffic.

Oct 30, 5:58 pm 2007
Karel Kulhavy
OpenBSD kernel janitors

Is there a list similar to Linux kernel janitors also for OpenBSD? It's a list
of tasks for which you don't have to be experienced in the particular OS
internals to be able to complete them properly.

CL<

Oct 30, 3:31 pm 2007
Miod Vallat
Re: OpenBSD kernel janitors

No, there isn't.

There are, however, two de-facto janitors for the OpenBSD kernels:
martin@ and I. Those janitors, however, are experienced developers.

Quite frankly, the idea of the janitor being a rookie scares the hell
out of me. How can you trust people if these people admittedly do not
know what they are doing, or why they are doing things one way and not
another?

That said, I have a huge todolist, as a brain dump in text format. A
good quarter of it are simple tasks, which one may cons...

Oct 30, 4:26 pm 2007
Unix Fan
Re: Interesting articles about drivers support

And why exactly are you spamming an "OpenBSD" related mailing list with this information?.....

Oct 30, 3:26 pm 2007
Alexey Suslikov
Interesting articles about drivers support

Hello.

I have found interesting articles (opinions) about hardware
support in Linux. Just FYI and interesting to read (learn).

Linux Doesn't Lack Drivers, it Lacks Complete Drivers.
http://www.apreche.net/2007/10/27/linux-doesnt-lack-drivers-it-lacks-com...

This is a list of hardware that does not have support on Linux
and needs Linux kernel drivers written for them.
http://linuxdriverproject.org/twiki/bin/view/Main/DriversNeeded

Linux device driver project needs more unsupported ...

Oct 30, 12:47 pm 2007
Damon McMahon
Re: Hoe to specify multiple transform suites in ipsec.conf(5)

Heinrich,

I've tried to do the same - see http://readlist.com/lists/openbsd.org/
misc/12/62613.html - as of 4.1 this is not supported by ipsec.conf(5).

Best wishes,
Damon

Oct 30, 8:16 am 2007
Heinrich Rebehn
Re: Hoe to specify multiple transform suites in ipsec.conf(5)

Thanks for your reply, Damon. I missed your post when searching the
archives.
You wrote that isakmpd.conf is "deprecated". Obviously this is not (yet)
quite so.

Kind regards,

Heinrich

Oct 30, 10:06 am 2007
Chris
hydra libssh support

I installed hydra (4.1/i386) from the package list and tried:

hydra -l user -p password localhost ssh2 and I get an error -

Error: Compiled without LIBSSH support, module not available!

Does anyone know where I can get "LIBSSH" module support or how I can
enable this?

I installed Hydra from the ports tree as well but when I run the
above command it gives me the same error.

Any help would be much appreciated. Thanks.

Oct 30, 5:52 am 2007
Markus Bergkvist
update mixerctl on shutdown

Currently I have 'outputs.master=127' in /etc/mixerctl.conf. I want this
value to be updated to the current value in mixerctl whenever the system
is rebooted. Any suggestion on how this could be accomplished?

/Markus

Oct 30, 3:36 am 2007
Gilles Chehade
Re: update mixerctl on shutdown

You might want to take a look at rc.shutdown(8)

Gilles

--
Gilles Chehade
=> http://www.evilkittens.org/blog/gilles/

Oct 29, 9:51 pm 2007
Paul de Weerd
Re: update mixerctl on shutdown

On Tue, Oct 30, 2007 at 08:36:41AM +0100, Markus Bergkvist wrote:
| Currently I have 'outputs.master=127' in /etc/mixerctl.conf. I want this
| value to be updated to the current value in mixerctl whenever the system
| is rebooted. Any suggestion on how this could be accomplished?

Add something to /etc/rc.shutdown, maybe :

mixerctl -a > /etc/mixerctl.conf

If you want to filter certain settings out, pipe through grep.

Good luck !

Paul 'WEiRD' de Weerd

+++++++++++>-]<.>++[&l...

Oct 30, 3:49 am 2007
Stefan Olsson
snapshots

Hello,

I've been using snapshots quite a bit lately but am a little bit
confused regarding the snapshot packages vs the snapshots themselves. At
the time of writing there are i386 snapshots dated the 27th of October
while the snapshot packages for i386 are dated 22nd of October. -Do they
belong together or do these packages belong to the previous i386
snapshot? Is there any way to tell which snapshot-packages belong to
which snapshot-build?

Kind Regards,

Stefan

Oct 30, 6:55 am 2007
Theo de Raadt Oct 30, 1:41 pm 2007
Josh Grosse
Re: snapshots

Stefan,

I'm just a user -- so I do not speak for the Project -- but to the best of my
knowledge and experience, the snapshot packages are merely for the convenience
of -current users. There is no guarantee of synchronicity, and you may or may
not be able to use snapshot packages, depending on the state of /usr/lib.

Oct 30, 11:44 am 2007
Earin Gregor
Re: snapshots

Hi

Snapshots packages may sometimes not work due to them not beeing as actual
as the rest. I was tol packages get compiled every 2-3 weeks normaly.
Just try the package, if it breaks use the ports. Just grad a ports snapshot
same time you update the rest.

Cheerz

Oct 30, 12:12 pm 2007
Edd Barrett
Re: snapshots

Hi,

My understanding is that you should keep userland and packages as in
sync as possible. I remember thinks starting to go wrong in the past
as the skew nears 2-3 weeks.

Good question though. I guess the packages are built separately to the
install sets.

--
Best Regards

Edd

---------------------------------------------------
http://students.dec.bournemouth.ac.uk/ebarrett

Oct 30, 9:38 am 2007
Markus Bergkvist
Re: update mixerctl on shutdown

Excellent, just what I was looking for. Thanks.

/Markus

Oct 30, 6:02 am 2007
Balázs
bge driver problem

I'm trying to convert a 22 node ~100 CPU cluster from Linux to
OpenBSD. The motivation is to increase reliability and security.
However, I have a peculiar problem with the bge driver. It seems that
bge doesn't detect properly the media type the hardware supports. The
nodes I'm trying to convert are on PenguinComputing BladeRunners with
AMD procs and broadcom NICs. When the bge driver loads, the link
lights turn off on the NICs, here is more info:

# dmesg | grep bg
bge0 at pci4 dev 4 function 0...

Oct 29, 11:44 pm 2007
Aaron
carp on wan interface

I've been reading about and want to set up a set of (2) carp/pf/pfsync
redundant firewalls but I haven't seen anything in the docs or on the
list similar to what i'm hoping to accomplish so here goes:

I'm horrible at ascii art so i'll try to describe the scenario as best i
can:

2 firewalls, each firewall will have 4 interfaces, san0(wan),
fxp0(backup/redundant/load balancing wan , fxp1(dmz) and fxp2(lan).
From what I have read in the docs and from questions that other people
have asked...

Oct 29, 11:27 pm 2007
Stuart Henderson
Re: carp on wan interface

No, don't do this. This would be like plugging a phone line and

You're describing something which is normally handled by speaking
BGP with your provider(s).

Oct 30, 5:28 am 2007
Aaron
Re: carp on wan interface

ok, scratch that idea. Are there any csu/dsu units out there that can
take the incoming t1 signal and then output directly to an ethernet
interface on the obsd box or do they all have to output via v.35 or 8
position cable to a 'standard' router (a'la cisco etc.....) before
coming into the openbsd machine? Even a cheap router that could do all
of the signal conversion (I'm looking over adtran's site now...... any
recommendations) so that i don't need 3 (csu/dsu---router---obsd
They aren'...

Oct 30, 7:05 am 2007
Stuart Henderson
Re: carp on wan interface

I think you get some T1/E1<>ethernet bridge-like devices (needing the
same box at both ends of the line), but you won't be able to use carp to

BGP may not be flexible enough to balance the incoming packets
between the lines in that case. e.g. in the case where the ISP with
the slower connection is a downstream customer of an ISP sourcing
a lot of traffic (localpref is more important than path length,
so it can be difficult or impossible to influence this).

But if the majority of traff...

Oct 30, 7:33 am 2007
Aaron P. Martinez
Re: carp on wan interface

Now that i know i can't carp the actual san0 interfaces, the ultimate
objective would be to just have some type of automatic failover for this
interface. I could have a san0 interface on each machine and if one box
dies, someone there could simply move the cable to the machine still
running, but I'm trying to avoid this manual step.

Even if i had a router doing the conversion from t1 to ethernet, running
into a switch and then instead of san0 interfaces in the redundant
firewalls I had some ethern...

Oct 30, 12:13 pm 2007
Jon Radel
Re: carp on wan interface

Getting a /24 (or bigger) so that BGP is more than a theoretical
exercise, and convincing certain classes of ISPs that they wish to do
BGP, are the bigger hurdles. At least in the U.S.

--Jon Radel

[demime 1.01d removed an attachment of type application/x-pkcs7-signature which had a name of smime.p7s]

Oct 30, 10:38 am 2007
Claudio Jeker
Re: carp on wan interface

Have a look at ifstated, you can track the link state with it and switch
between the two links. Then you can demote the carp interface depending on
the link state of the wan link. This will most porbably not work with a
external T1 to ethernet media converter as they do not change the link
state depending on the T1 link. (I never had a lot of success with media
converters anyway, mine always crashed or behaved flaky).

Oct 30, 7:21 am 2007
Henning Brauer
Re: carp on wan interface

I actually have one that works OK, a RAD STM-1 to FastEthernet
converter... but the management interface sucks big time :)

but in general, I totally agree with claudio here. they often cause
issues. and if it is only the missing link state forwarding (why can't
the box take down the ethernet link when the wan link fails, at least
as an option?). So your best bet is to terminate wans directly on
OpenBSD boxes. And then you still want ethernet where possible. And if
you spec Ethernet, you oft...

Oct 30, 8:03 am 2007
Henning Brauer
Re: carp on wan interface

no. carp does not speak g.703 or whatever the t1 encoding was :)

you have a t1 switch/hub? i kinda doubt that.

--
Henning Brauer, hb@bsws.de, henning@openbsd.org
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting - Hamburg & Amsterdam

Oct 30, 5:20 am 2007
Tony Sarendal
using bgpd and ospfd

I set up a test network with bgpd/ospfd, a standard service provider design
where ospf carries the network links and loopbacks and bgp carries
everything,
bgp routers doing nexthop self, core full mesh and access routers rr-clients
of the two nearest core routers.

I'm seeing some pretty odd behaviour that I haven't seen before when only
using bgpd.

Are there any know issues with using this kind of design with bgpd/ospfd ?

Quick example:

View from an access router at another prefix on the ...

Oct 29, 9:19 pm 2007
Henning Brauer
Re: using bgpd and ospfd

lookslike there is a case we miss listening to the routing socket, or
there is sth in the message that makes us skip it.
can you run "route monitor" on the misbehaving machine while causing
the change and send me the output (no need to spam the list with that
tho)?

--
Henning Brauer, hb@bsws.de, henning@openbsd.org
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting - Hamburg & Amsterdam

Oct 30, 5:16 am 2007
Tony Sarendal
Re: using bgpd and ospfd

Will do.

So running a setup where ospfd and bgpd carries the same prefixes should
work ?
In the lab setup both ospf and bgp carry the loopback and links, and all
non-core
prefixes are in bgp only.

When I run bgp-only things work like a charm, except for a bit of funkiness
with
existing tcp-sessions to routers showing a bit of funky routing...

/Tony

Oct 30, 6:17 am 2007
Henning Brauer
Re: using bgpd and ospfd

oh. the same ones. that is a bit iffy right now.

--
Henning Brauer, hb@bsws.de, henning@openbsd.org
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting - Hamburg & Amsterdam

Oct 30, 6:50 am 2007
Tony Sarendal
Re: using bgpd and ospfd

That was the answer I was looking for =)

No worries, I will adapt the live design I'm implementing as I want it
working
well on 4.2. I can either make sure ospfd and bgpd and don't carry the same
prefixes, which is possibly in this particulare case, or I can go bgp-only.
I'm most likely going bgp-only, hot-potato routing is something I want.

If there is any testing I can do to assist please let me know,
otherwise I'll just continue to play with it. It is my form of mediation
to clear my mi...

Oct 30, 7:09 am 2007
Stuart Henderson
Re: using bgpd and ospfd

I had problems with this, I think bgpd was stomping on the ospf route
of my IX's /24, causing the routes from peers to fail nexthop validation
on the other routers. I didn't get to the bottom of it so I just started
filtering that /24 in bgpd but I don't think it's meant to do that.

The routing table doesn't handle multiple routes with differing
priorities, so the daemons must watch for updates on the routing socket
and react to them, I guess this is somewhat delicate but I don't have
a diff so I...

Oct 30, 6:31 am 2007
Chris Smith
Re: Marginal boot CD #1 in OpenBSD 4.2 sets

I have an older Sony CD/DVD burner that is crapping in this manner.
Machine is so old as to have a floppy disk, as well; I'll see about
doing the boot floppy approach first, and get back to you if that
no-worky-worky.
Appreciate Theo's remarks, and your offer, but time is cheaper than
postage in this case.
Best,
Chris

Oct 30, 9:08 am 2007
ropers Oct 30, 12:44 pm 2007
Bob Beck
Re: spamdb expire value gets default value instead of spamd_...

Who put the 36 hour date in there? spamd or spamlogd?

spamlogd may have done that for you. look at your syslogs

-Bob

--
#!/usr/bin/perl
if ((not 0 && not 1) != (! 0 && ! 1)) {
print "Larry and Tom must smoke some really primo stuff...\n";
}

Oct 30, 10:18 am 2007
Balázs
Re: About Xen: maybe a reiterative question but ..

I don't think you can run OpenBSD in LPARs. From the official IBM
docs, all I see available is:

- AIX
- RHEL
- SuSE

I would love to hear about anyone that made OBSD work on p-Series in LPARs.

B)

Oct 29, 11:56 pm 2007
Matthew Szudzik
Re: Non-x86

I agree that sparc64 is currently the best alternative to the x86
architecture in i386 and amd64. For me, the biggest obstacles to
buying a sparc64 machine are:

* sparc64 machines the are significantly more expensive than their x86
counterparts.

* There is no binary emulator that would allow me to run proprietary
software like Mathematica on sparc64. (In contrast, I can run Mathematica
on i386 with the Linux binary emulator.)

NetBSD has a Solaris binary emulator for sparc64, so with...

Oct 30, 2:26 pm 2007
previous daytodaynext day
NoneOctober 30, 2007None