Re: [arch-general] pambase update now requires explicit service files in /etc/pam.d/ - dovecot affected

2019-02-12 Thread Leonid Isaev via arch-general
On Tue, Feb 12, 2019 at 09:15:39AM -0500, Jens John wrote: > On Tue, 12 Feb 2019, at 12:02, Leonid Isaev via arch-general wrote: > > I am sorry to ask this so late in the discussion, but why Arch default of > > the > > "other" module was insecure (and hence why

Re: [arch-general] pambase update now requires explicit service files in /etc/pam.d/ - dovecot affected

2019-02-12 Thread Leonid Isaev via arch-general
gladly do it > again in the future. A strong reaction is not only warranted, but necessary. > I am sorry to ask this so late in the discussion, but why Arch default of the "other" module was insecure (and hence why the change)? Is there something wrong with pam_unix? Thanks, -- Leonid Isaev

Re: [arch-general] Missing auth.log

2018-11-15 Thread Leonid Isaev via arch-general
empts? It seems > that ARCH does not run [r]syslogd. If you want authpriv messages, then run "journalctl SYSLOG_FACILITY=10". See https://en.wikipedia.org/wiki/Syslog#Facility for mapping between numerical and mnemonic facility IDs. Oh, and do install syslog-ng :) Cheers, -- Leonid Isaev

Re: [arch-general] Firefox crashes randomly

2018-09-20 Thread Leonid Isaev via arch-general
dev/shm by default? Half of the RAM size by default, as for any tmpfs... Cheers, -- Leonid Isaev

Re: [arch-general] AppArmor support

2018-09-09 Thread Leonid Isaev via arch-general
On Sun, Sep 09, 2018 at 06:13:24PM -0400, Eli Schwartz via arch-general wrote: > On 9/9/18 4:00 PM, Leonid Isaev via arch-general wrote: > > FWIW, I actually agree with #59733: CONFIG_AUDIT=n was blocking AppArmor > > adoption... Perhaps relevant: > > https://lists.debian.org

Re: [arch-general] AppArmor support

2018-09-09 Thread Leonid Isaev via arch-general
know asap. Thanks and pls take your time. I have a VM that runs linux-hardened and is used to study malicious pdf files. I can test rulesets there... Cheers, L. -- Leonid Isaev

Re: [arch-general] AppArmor support

2018-09-09 Thread Leonid Isaev via arch-general
a question: why was AUDIT enabled in the first place? I thought it was cosidered useless? Cheers, L. -- Leonid Isaev

Re: [arch-general] Services with DefaultDependencies=no

2018-08-27 Thread Leonid Isaev via arch-general
On Mon, Aug 27, 2018 at 12:51:13PM -0400, Eli Schwartz via arch-general wrote: > On 8/27/18 8:45 AM, Leonid Isaev via arch-general wrote: > > Hi, > > > > While going over .service files on my system, I noticed that quite a > > few of them, not belonging

Re: [arch-general] update today causes avantfax_hourly cron: Exec format error?

2018-08-27 Thread Leonid Isaev via arch-general
On Mon, Aug 27, 2018 at 04:04:14PM +0200, Ralf Mardorf wrote: > On Mon, 27 Aug 2018 07:38:12 -0600, Leonid Isaev via arch-general wrote: > >On Mon, Aug 27, 2018 at 03:02:38PM +0200, Ralf Mardorf wrote: > >> Eli, wouldn't it be easier for you to ignore people who ar

Re: [arch-general] update today causes avantfax_hourly cron: Exec format error?

2018-08-27 Thread Leonid Isaev via arch-general
would end up. Cheers, -- Leonid Isaev

[arch-general] Services with DefaultDependencies=no

2018-08-27 Thread Leonid Isaev via arch-general
-nfsd? I thought that setting DD=no is kind of a hack needed only for special services (e.g. called from fstab via x-systemd.requires=). Or am I missing something? Thanks, L. -- Leonid Isaev

Re: [arch-general] ClamAV Flagging systemd package

2018-07-14 Thread Leonid Isaev via arch-general
ou mention a pkg in the cache... Anyway, a brief google search reveals that this particular trojan turned up in many distros, so it is most likely a false positive. Cheers, -- Leonid Isaev

Re: [arch-general] [arch-dev-public] [core] / [extra] cleanup

2018-07-11 Thread Leonid Isaev via arch-general
gt; - b43-fwcutter - Is this still required for more recent broadcom cards? What about logrotate? AFAIU, there are no loggers in [core]... Thanks, -- Leonid Isaev

Re: [arch-general] sshd - limiting sequential no. or files opened via sftp in kate?

2018-06-07 Thread Leonid Isaev via arch-general
the past I would have 120 files > in a project and had no problems at all opening the project either across the > LAN or remotes via the internet on my office server. So this seems like it is > some protection designed to prevent hackers from hammering your server with > ssh requests -- but it seems like it is having the side effect of preventing > me from loading projects with more than say 20 files via sftp. > > -- > David C. Rankin, J.D.,P.E. -- Leonid Isaev

Re: [arch-general] Set ip lan address /etc/environment

2018-06-04 Thread Leonid Isaev via arch-general
On Fri, Jun 01, 2018 at 08:48:03AM +0200, Maykel Franco via arch-general wrote: > 2018-05-31 12:01 GMT+02:00 Leonid Isaev via arch-general > : > > On Thu, May 31, 2018 at 10:44:25AM +0100, Ralph Corderoy wrote: > >> Hi Maykel, > >> > >> > I need define

Re: [arch-general] Set ip lan address /etc/environment

2018-05-31 Thread Leonid Isaev via arch-general
changed throughout the machine uptime? -- Leonid Isaev

Re: [arch-general] Set ip lan address /etc/environment

2018-05-30 Thread Leonid Isaev via arch-general
hanks in advanced. /etc/environment is for PAM not shell, so it only allows ip=xxx.yyy.zzz.aaa . Also, /etc/profile is for LOGIN shells, meaning that from scripts or when doing scp(1) it won't be read. What exactly are you trying to achieve? Cheers, -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2018-05-14 Thread Leonid Isaev via arch-general
treams provide these hashes. Currently, AFAIK the only "upstream" doing that is Gentoo in their Manifests. Cheers, -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2018-05-14 Thread Leonid Isaev via arch-general
psha3.html > I've also seen suggestions that the Keccak team push Kangaroo Twelve > these days over SHA-3 due to SHA-3's comparative slowness. Of course, none of this is relevant for the present thread... Cheers, -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2018-05-13 Thread Leonid Isaev via arch-general
this... Yes, md5 is almost as good these days as crc32... It is ok if the sources are gpg-signed, but not on its own. Cheers, -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2018-05-10 Thread Leonid Isaev via arch-general
at all. The difficulty that prevents its widespread use lies with maintaining the key, and with that no guide can help... > I wish you all good luck, dont hesitate to contact me further if you > have any great ideas regarding GPG etc. Thanks, L. -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2018-05-09 Thread Leonid Isaev via arch-general
on md5 these days is like having no hashes at all or using the source filename as a hash... And there should be no migration -- when a new version of a package is released or a rebuild happens, just update the *sums array. Cheers, -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2018-05-08 Thread Leonid Isaev via arch-general
tance. At least, with sha-2 hashes, point #3 of your previous email makes sense. Thanks, -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2018-05-08 Thread Leonid Isaev via arch-general
pkg (available in git > master and awaiting the 5.1 release) which allows verifying git(1) > signed commits/tags. Thanks for your work! I didn't know about those links, will check them out. But ok, I see your point... Thanks, L. -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2018-05-08 Thread Leonid Isaev via arch-general
On Tue, May 08, 2018 at 08:08:31PM -0600, Leonid Isaev wrote: > [extra] > ... This list should also include "python-retrying". I should have grepped more carefully, sigh... -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2018-05-08 Thread Leonid Isaev via arch-general
On Tue, May 08, 2018 at 08:08:31PM -0600, Leonid Isaev wrote: > [0] https://lists.archlinux.org/pipermail/arch-general/2016-December/042 Oops, this link should have been https://lists.archlinux.org/pipermail/arch-general/2016-December/042700.html -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2018-05-08 Thread Leonid Isaev via arch-general
-- Leonid Isaev

Re: [arch-general] procps-ng 3.3.13 and its new topdefaultrc

2018-04-11 Thread Leonid Isaev via arch-general
toprc flag > that allows choosing between old and new top interfaces? It should also be mentioned that ~/.toprc is the most hideous config file on my system :) And FWIW, I don't think that upstream wanted to provoke any learning -- they just made a change for the sake of it (probably following GNOME 3.x :). Cheers, -- Leonid Isaev

Re: [arch-general] Curious about arch repository policy

2018-03-27 Thread Leonid Isaev via arch-general
On Tue, Mar 27, 2018 at 08:39:30PM +0100, morganamilo via arch-general wrote: > > > On 27/03/18 20:34, Leonid Isaev via arch-general wrote: > > On Tue, Mar 27, 2018 at 08:27:16PM +0530, Sudarshan Kakoty via arch-general > > wrote: > > > Hello... > > > &

Re: [arch-general] Curious about arch repository policy

2018-03-27 Thread Leonid Isaev via arch-general
a" repo, whereas "ninja" > is in "community" repo. The interesting fact is that - is an implicit > dependency to "meson". So why that is (ninja) in the community repo? A more important question is why meson and ninja are not in [core] and base group given that they are build-dependencies of systemd? Cheers, L. -- Leonid Isaev

Re: [arch-general] mandb - numerous parse failures on run (parallel, fribidi, numactl, pcre2, netpbm, etc..)

2018-03-14 Thread Leonid Isaev via arch-general
e. man-db.service is triggered by man-db.timer which should be enabled on your system by default... Cheers, -- Leonid Isaev

Re: [arch-general] Update to 4.15.8 on dual quad-core box locked on ( 3/16) Install DKMS modules, need help resurecting

2018-03-13 Thread Leonid Isaev via arch-general
chicken-and-egg problem, and I > don't really consider this a viable generic solution... Can't this be done from any distro using Arch rootfs? Cheers, -- Leonid Isaev

Re: [arch-general] Update to 4.15.8 on dual quad-core box locked on ( 3/16) Install DKMS modules, need help resurecting

2018-03-12 Thread Leonid Isaev via arch-general
On Mon, Mar 12, 2018 at 11:17:21PM +, Carsten Mattner wrote: > On 3/12/18, Leonid Isaev via arch-general <arch-general@archlinux.org> wrote: > > What's wrong with btrfs? Yeah, I know it is not marked "stable", but this > > is just a label. And people s

Re: [arch-general] Update to 4.15.8 on dual quad-core box locked on ( 3/16) Install DKMS modules, need help resurecting

2018-03-12 Thread Leonid Isaev via arch-general
t's all some compromise that you might or might not accept. What's wrong with btrfs? Yeah, I know it is not marked "stable", but this is just a label. And people shying away from it doesn't help in advancing its stability either. Cheers, -- Leonid Isaev

Re: [arch-general] systemd permissions on run?

2018-02-01 Thread Leonid Isaev via arch-general
is does NOT happen on another Arch laptop I have (with > those same services running). My ls -la results in /run seem to turn up the > same thing, nor are there any differences in shadow/gshadow/passwd etc. Do these seem similar? https://github.com/systemd/systemd/issues/6632 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=888976 Cheers, -- Leonid Isaev

Re: [arch-general] Install Archlinux on HP Elitebook

2017-12-24 Thread Leonid Isaev via arch-general
LABEL ^Vintage SUSE 11.2 Rt What are those ctrl-* characters (like ^Q)? Cheers, -- Leonid Isaev

Re: [arch-general] How to build package in "clean chroot" using the "-U" parameter?

2017-12-22 Thread Leonid Isaev via arch-general
inside the container). And keep it clean. At least this has worked for me for years. Also, with newer -ARCH kernels, you can do non-privileged containers, so makechrootpkg should run as a ordinary user to begin with... Cheers, -- Leonid Isaev

Re: [arch-general] pacman and journalctl

2017-12-02 Thread Leonid Isaev via arch-general
cify a syslog implementation... Journald is simply one of them. If you wonder about facility and/or priority, then yeah, it is not indicated, but I guess it is daemon/info. Cheers, -- Leonid Isaev

Re: [arch-general] pacman and journalctl

2017-12-01 Thread Leonid Isaev via arch-general
On Fri, Dec 01, 2017 at 11:10:51PM +, Tom M. wrote: > ahoy there! > > is there some cleaver way of making pacman log to journalctl? or plans > to implement such a feature? Uncomment UseSyslog in pacman.conf... -- Leonid Isaev

Re: [arch-general] Server Management Tools

2017-10-12 Thread Leonid Isaev via arch-general
ch? Good luck with that. > > Who say something from unattended? I want not only set 20 times the same > command. That's all. And writing a bash script that ssh's in and does everything is sooo difficult? If you can't do it, don't update machines automatically. -- Leonid Isaev

Re: [arch-general] Detect broken DHCP setup

2017-09-06 Thread Leonid Isaev via arch-general
On Wed, Sep 06, 2017 at 11:27:13AM +0200, Giovanni Santini via arch-general wrote: > Il 06/09/2017 01:09, Leonid Isaev via arch-general ha scritto: > > > > What does it mean a valid DHCP setup? By reconnection you mean that your > > client > > re-request a lease from

Re: [arch-general] Detect broken DHCP setup

2017-09-05 Thread Leonid Isaev via arch-general
re mostly default settings. Maybe you need to add "nomtu" in case your ISP does something idiotic with this setting (mine does :)). Oh, and hardcode the DNS settings in /etc/resolv.conf, so a broken dhcp server has no control over them. HTH, -- Leonid Isaev

Re: [arch-general] Login Statistics Similar to Centos

2017-09-01 Thread Leonid Isaev via arch-general
lastlog.so nowtmp silent session optional pam_lastlog.so silent noupdate showfailed -- Cheers, -- Leonid Isaev

Re: [arch-general] Login Statistics Similar to Centos

2017-08-29 Thread Leonid Isaev via arch-general
on pts/0 > Last failed login: Tue Aug 29 17:47:31 EDT 2017 from 116.31.116.18 on > ssh:notty > There were 37 failed login attempts since the last successful login. > > How can I get Arch to do that same info? I've searched the wiki and forums, > but not found anything. man 8 pam_lastlog Cheers, -- Leonid Isaev

Re: [arch-general] How can I set CAPS LOCK as Escape throughout reboot

2017-08-17 Thread Leonid Isaev via arch-general
work. It should work. I have a similar line with caps:none in xinitrc and it works. Perhaps smth from your desktop undoes your setting? Cheers, -- Leonid Isaev

Re: [arch-general] New - systemd 234 - luks partition fails to ask for password - workaround

2017-07-17 Thread Leonid Isaev via arch-general
rk around which is to add timeout=90 > >> > > > > Where to add this? > > > > To the kernel parameters, with luks.options= key. Yes, see "man systemd-cryptsetup-generator" and "man cryptsetup" for details. Cheers, -- Leonid Isaev

Re: [arch-general] gnupg: systemd enable in post_install

2017-06-09 Thread Leonid Isaev via arch-general
any freezes when started inside a container and systemd "is looping too fast" (and no, I'm not reporting it upstream), but works if I manually kill systemd --user instance. If you are not using Xorg, "pkill -9 systemd" in .bash_profile saves lots of hair-pulling :) Cheers, -- Leonid Isaev

Re: [arch-general] libx264 changes

2017-05-08 Thread Leonid Isaev
ke your forked ffmpeg package provide "ffmpeg", thereby ensuring that > > libx264/x264 depend on *your* package! > > Is the idea that I create a machine local repo that has highest prio > and overrides arch extra/testing? Otherwise, I don't know how to unbreak > the cycle w

Re: [arch-general] [arch-dev-public] AUR ToS (aka making AUR user names public)

2017-03-08 Thread Leonid Isaev
ies have ToS because they want to cover their back legally, but Arch is different in this regard... Cheers, -- Leonid Isaev

Re: [arch-general] [arch-dev-public] AUR ToS (aka making AUR user names public)

2017-03-06 Thread Leonid Isaev
security through obscurity: don't rely on a web service not advertising your usernames, if this is an issue, make each username a random string (which defeats the attack [1]). > [1] > http://archive.wired.com/politics/security/commentary/securitymatters/2007/12/securitymatters_1213 Cheers, -- Leonid Isaev

Re: [arch-general] [arch-dev-public] AUR ToS (aka making AUR user names public)

2017-03-05 Thread Leonid Isaev
umber, so it doesn't matter to give away the numbers, > right? ;) Oh, please. Not the usual NSA crap again. Cheers, -- Leonid Isaev

Re: [arch-general] syslinux.cfg

2017-02-16 Thread Leonid Isaev
Systemd may not run smth if it detect a container virtualization. Cheers, -- Leonid Isaev

Re: [arch-general] syslinux.cfg

2017-02-15 Thread Leonid Isaev
ctive /boot's (if desired of course, as you don't need to have /boot mounted). This way you get the menu that you mentioned first. You no longer need data in /dev/sdb1 and can free the partition. HTH, -- Leonid Isaev

Re: [arch-general] Revisiting the SELinux/audit question: Disabling audit on the kernel command line

2017-02-12 Thread Leonid Isaev
On Sun, Feb 12, 2017 at 06:43:22PM +0100, Tobias Markus wrote: > I would be glad if Arch Linux's official kernel could support SELinux > again this way! AFAIR, coreutils and many other things need to be rebuilt to support selinux. -- Leonid Isaev

Re: [arch-general] sandboxing

2017-02-04 Thread Leonid Isaev
hromium can do to the file system(even better with --private); the browser > cannot tamper with .profile/.bash_profile or .ssh. See, this is the problem: Why would a browser need these files? File access should only be possible with user interaction (via a file-open dialog). Cheers, -- Leonid Isaev

Re: [arch-general] sandboxing

2017-02-02 Thread Leonid Isaev
On Thu, Feb 02, 2017 at 09:30:58PM +0100, Bennett Piater wrote: > On 02/02/2017 07:28 PM, Leonid Isaev wrote: > > I already described an approach when one always runs browsers, pdf readers, > > etc, inside an lxc container, as an unprivileged user. That container > > reside

Re: [arch-general] user namespaces

2017-02-02 Thread Leonid Isaev
nst, instead of wasting time on exploring the zoo of sandboxing apps... There is nothing wrong with -ARCH kernel. Cheers, -- Leonid Isaev

Re: [arch-general] sandboxing

2017-02-02 Thread Leonid Isaev
On Thu, Feb 02, 2017 at 03:24:11AM +0100, sivmu wrote: > Am 01.02.2017 um 21:16 schrieb Leonid Isaev: > > > > But you see, sandboxing apps is by itself is a misleading security feature. > > Why do I need to sandbox my browser if it is written properly and allows me > >

Re: [arch-general] user namespaces

2017-02-01 Thread Leonid Isaev
s/people > without providing real prove for your arguments. So, why don't you just build your own kernel? It takes only 20 mins... Cheers, -- Leonid Isaev

Re: [arch-general] user namespaces

2017-02-01 Thread Leonid Isaev
d/gid pairs. That's exactly how this works on > Android for both apps and isolatedProcess services (they each get a > unique uid/gid pair assigned), although they also layer SELinux and > mount namespaces on top. Cool :) thx for the explanation... Cheers, L. -- Leonid Isaev

Re: [arch-general] user namespaces

2017-01-31 Thread Leonid Isaev
eged user inside that container for browsing / viewing of untrusted pdfs, etc? But I still believe that the idea of sandboxing a web browser is idiotic... Cheers, -- Leonid Isaev

Re: [arch-general] Basic questions about Linux's sound system

2017-01-30 Thread Leonid Isaev
A see my headset? ALSA "sees" audio devices as reported by the kernel. If the kernel / udev registers your bluetooth headset as an audio device, you should be able to control it through ALSA. This is similar to USB network adapters, for example. Cheers, -- Leonid Isaev

Re: [arch-general] SSH access to Arch machines for testing

2017-01-26 Thread Leonid Isaev
f you already have any modern linux machine, you can simply install an Archlinux container and compile whatever you want :) -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2016-12-27 Thread Leonid Isaev
[1] https://www.microsoft.com/en-us/download/details.aspx?id=11533 Cheers, -- Leonid Isaev

Re: [arch-general] UID/GID of a systemd container

2016-12-22 Thread Leonid Isaev
On Thu, Dec 22, 2016 at 05:52:10PM +, arnaud gaboury wrote: > On Thu, Dec 22, 2016, 6:16 PM Leonid Isaev <leonid.is...@jila.colorado.edu> > wrote: > > > On Thu, Dec 22, 2016 at 09:16:29AM +, arnaud gaboury via arch-general > > wrote: > > > % s

Re: [arch-general] UID/GID of a systemd container

2016-12-22 Thread Leonid Isaev
> > Thank you for any hint, link to documentation about this new way to show > UID/GID of a container. You are using user namespaces, yes? -- Leonid Isaev

Re: [arch-general] Why was wpa_supplicant.conf renamed wpa_supplicant.conf.pacsav??

2016-12-18 Thread Leonid Isaev
On Sun, Dec 18, 2016 at 09:40:29PM +0100, Maarten de Vries wrote: > On 18 December 2016 at 21:32, Leonid Isaev <leonid.is...@jila.colorado.edu> > wrote: > > > On Sun, Dec 18, 2016 at 02:25:00PM -0600, David C. Rankin wrote: > > > I know this is small-pot

Re: [arch-general] Why was wpa_supplicant.conf renamed wpa_supplicant.conf.pacsav??

2016-12-18 Thread Leonid Isaev
the user? > At least in the cases where you know up-front that existing functionality will > be disabled by the upgrade. (which was apparent from the comment) Hmm, what about reading /var/log/pacman.log? Cheers, -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2016-12-09 Thread Leonid Isaev
On Fri, Dec 09, 2016 at 03:15:34PM +0100, Bruno Pagani wrote: > Le 08/12/2016 à 01:57, Leonid Isaev a écrit : > > > On Thu, Dec 08, 2016 at 10:34:59AM +1000, Allan McRae wrote: > >> On 08/12/16 08:51, sivmu wrote: > >>> Am 07.12.2016 um 10:49 schrieb Allan McRa

Re: [arch-general] Systemd services start by default

2016-12-07 Thread Leonid Isaev
and timesyncd are not enabled in systemd 232-6. You or some program on your system did something... Cheers, L. -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2016-12-07 Thread Leonid Isaev
verify the sig on SHA512SUMS and then paste the sha512sum into PKGBUILD. But this is because I'm paranoid... I guess one can simply do makepkg -g, hmm. Hence the question, why have this flag at all? And should it be possible to specify an external (signed) hash-file in PKGBUILD? Thx, L. -- Leonid Isaev

Re: [arch-general] Stronger Hashes for PKGBUILDs

2016-12-07 Thread Leonid Isaev
en > system because... why again? So you can learn nothing? I think you misunderstood Allan. What he says is that by default makepkg provides only a protection against broken http links at best. If a maintainer wants security, he must take care of it explicitly. I don't see why this is a bad idea... Cheers, L. -- Leonid Isaev

Re: [arch-general] unreadable characters login screen after install

2016-11-28 Thread Leonid Isaev
mproperly displayed with your graphics card. You can try changing it though, as an alternative to cusomising grub.cfg Cheers, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] Arch pkg user and group IDs?

2016-11-28 Thread Leonid Isaev
On Mon, Nov 28, 2016 at 11:04:53AM +0100, Hauke Fath wrote: > On Sun, 27 Nov 2016 19:16:56 -0700, Leonid Isaev wrote: > > But out of curiosity, why is it difficult to change user IDs on all files? I > > assume that you control the storage? Isn't it just a chown -R away? For >

Re: [arch-general] unreadable characters login screen after install

2016-11-27 Thread Leonid Isaev
aphics driver (automatically, early in ramdisk via MODULES= in mkinitcpio.conf, etc.)? Try booting with nomodeset at the kernel cmdline to disable KMS and see if your fonts get back to normal... Cheers, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] Arch pkg user and group IDs?

2016-11-27 Thread Leonid Isaev
On Sun, Nov 27, 2016 at 10:32:38PM -0500, Eli Schwartz via arch-general wrote: > On 11/27/2016 10:03 PM, Leonid Isaev wrote: > >> Well, packages can have files that need to have a specific system > >> user ownership. That is why the UID/GID database exists, right? >

Re: [arch-general] unreadable characters login screen after install

2016-11-27 Thread Leonid Isaev
ght solve the issue. > > > > Oops, I was confusing keyboard with fonts. Not xorg.conf, but much likely > > the display manager configuration provides to chose a font. > > > > > > > > Or tty? > > > > sorry i mean the login at the console,

Re: [arch-general] Arch pkg user and group IDs?

2016-11-27 Thread Leonid Isaev
e user IDs on all files? I assume that you control the storage? Isn't it just a chown -R away? For example, for our NIS passwd/shadow map we use 6-digit IDs... Cheers, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] Installation: How to get HDD > LUKS > GPT working in a clean way

2016-11-27 Thread Leonid Isaev
hich I use to decrypt the LUKS container and load a GRUB configfile > located at /boot/grub/grub.cfg (generated by grub-mkconfig). This works fine. Where is /boot physically located? Can grub2 boot from LV these days? Cheers, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6

Re: [arch-general] On containers. WAS: Re: snapcraft.io ...

2016-11-24 Thread Leonid Isaev
e > an app; don 't contain, use something else. > Sometimes you don't have a choice. Any modern web browser comes to mind... Cheers, L. -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] new /etc/nsswitch.conf

2016-11-06 Thread Leonid Isaev
ot in danger... L. > > -- > damjan -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] ensuring integrity of sources (was: [arch-dev-public] todo list for moving http -> https sources)

2016-10-31 Thread Leonid Isaev
On Tue, Nov 01, 2016 at 03:59:28AM +0100, Lukas Rose wrote: > > On 01 Nov 2016, at 00:35, Leonid Isaev <leonid.is...@jila.colorado.edu> > > wrote: > > > > Well, my mentality is that authenticating plain-text data is usually not > > necessary because a user

Re: [arch-general] ensuring integrity of sources (was: [arch-dev-public] todo list for moving http -> https sources)

2016-10-31 Thread Leonid Isaev
On Mon, Oct 31, 2016 at 07:18:01PM -0400, Eli Schwartz via arch-general wrote: > On 10/31/2016 05:50 PM, Leonid Isaev wrote: > > As a side question... is there a significant difference in signing PKGBUILD > > vs > > the compiled package. > > Do you realize, when you a

Re: [arch-general] ensuring integrity of sources (was: [arch-dev-public] todo list for moving http -> https sources)

2016-10-31 Thread Leonid Isaev
, what attack is possible when the PKGBUILD is not signed? Also, isn't the use of dev signature to validate upstream sources is a logical flaw? A dev might herself be mislead and build a trojaned source... Thx, L. -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C

Re: [arch-general] fluxbox/xscreensaver xterm unresponsive upon screensaver cancel?

2016-10-18 Thread Leonid Isaev
On Tue, Oct 18, 2016 at 12:55:15AM -0500, David C. Rankin wrote: > On 10/11/2016 01:24 AM, Leonid Isaev wrote: > > FWIW, a quick test in a VM doesn't show this behavior. What happens if you > > run > > xscreensaver-command -lock from an xterm? > > I can lock and u

Re: [arch-general] fluxbox/xscreensaver xterm unresponsive upon screensaver cancel?

2016-10-11 Thread Leonid Isaev
o, any solutions, or did > you narrow it down to one of (xterm, xscreensaver, DPMS)? Thanks for any > suggestions. FWIW, a quick test in a VM doesn't show this behavior. What happens if you run xscreensaver-command -lock from an xterm? L. -- Leonid Isaev GPG fingerprints:

Re: [arch-general] Opinions on PowerShell?

2016-08-19 Thread Leonid Isaev
Shell: ls -file | sort -pr length | select length, name -l 3 Since when ls(1) et al are a part of bash? Are you guys comparing apples with oranges, i.e. bash + coreutils and powershell? -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0D

Re: [arch-general] [arch-dev-public] [PATCH 1/1] move initramfs generation from install script to pacman hook

2016-05-19 Thread Leonid Isaev
te. I second that. Touching bootloader config is a bad idea. For example, in my case, I use arch's syslinux to boot multiple distros (with custom syslinux.cfg), which don't even have a bootloader package. Thx, L. -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4

Re: [arch-general] can't balance full btrfs raid6 filesystem

2016-02-22 Thread Leonid Isaev
On Mon, Feb 22, 2016 at 06:48:17PM +, Jameson wrote: > On Mon, Feb 22, 2016 at 1:43 PM Leonid Isaev <leonid.is...@jila.colorado.edu> > wrote: > > > See this: > > > > http://marc.merlins.org/perso/btrfs/post_2014-05-04_Fixing-Btrfs-Filesystem-Full-Problems.

Re: [arch-general] can't balance full btrfs raid6 filesystem

2016-02-22 Thread Leonid Isaev
roblems.html Basically, when your btrfs is full, just create a loopback device, add it to the array, rebalance and then remove the device. This is what I had to do this Sunday :) Cheers, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] Alternative init system proposal

2016-02-07 Thread Leonid Isaev
l use Debian 5 stable in a container as a print server... Cups 2.0+ is a real piece of crap. And yes, these org.xxx.xxx names _are_ stupid especially for filenames. But after using modern Fedoras, I think that systemd services are no longer supposed to be managed manually, but rather through some frontend... Cheers, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] Alternative init system proposal

2016-02-07 Thread Leonid Isaev
that create real problems... HTH, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] Alternative init system proposal

2016-02-07 Thread Leonid Isaev
air share of official repos... Cheers, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] Instructions to mount efivars as readonly should be linked to in Beginner's Guide

2016-02-01 Thread Leonid Isaev
g with it. Exactly, I really don't understand this interest to UEFI (and don't mention secureboot). Also, how can you brick a machine by simply zeroing the harddrive? Cheers, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] btrfs/snapper hook for pacman 5.0?

2016-02-01 Thread Leonid Isaev
hing yet. What is the goal here? Cheers, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] btrfs/snapper hook for pacman 5.0?

2016-02-01 Thread Leonid Isaev
ks. But /boot can not be snapshot with this, right? Cheers, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

Re: [arch-general] Mounting root according to fstab the first time (fstab in initrd)?

2016-01-20 Thread Leonid Isaev
=zlib,ssd,space_cache,autodefrag,subvolid=257,subvol=/_root) ^^^ Also, there is fstab in the initramfs: $ lsinitcpio /boot/initramfs-linux.img | grep fstab etc/fstab Have you tried masking the systemd-remount-fs.service? Cheers,

Re: [arch-general] Firefox without signature checking

2016-01-02 Thread Leonid Isaev
On Sat, Jan 02, 2016 at 05:34:51PM -0600, Doug Newgard wrote: > Just expanding on your point. Ah, OK, sorry :) Also, perhaps one should note that "walled garden" discussions (albeit justified) belong at Mozilla's bug tracker, not Arch's. Cheers, -- Leonid Isaev GPG fingerprints: D

Re: [arch-general] Firefox without signature checking

2016-01-02 Thread Leonid Isaev
On Sat, Jan 02, 2016 at 04:50:06PM -0600, Doug Newgard wrote: > On Sat, 2 Jan 2016 15:35:01 -0700 > Leonid Isaev <leonid.is...@jila.colorado.edu> wrote: > > > On Sat, Jan 02, 2016 at 02:06:05PM -0800, Kyle Terrien wrote: > > > Thank you! I was tempted to reopen it,

Re: [arch-general] Firefox without signature checking

2016-01-02 Thread Leonid Isaev
ally care because I don't use any addons.) Best, -- Leonid Isaev GPG fingerprints: DA92 034D B4A8 EC51 7EA6 20DF 9291 EE8A 043C B8C4 C0DF 20D0 C075 C3F1 E1BE 775A A7AE F6CB 164B 5A6D

  1   2   3   4   5   >