To whom it might concern:

I've had a terrible experience with UltraLinux is from the RH6.1
distribution. I don't know what happened, but I concider it spooky enough
to let other people know:

I had 3 Ultra5 Creator 3D sparcs up and running RH6.0 with the last
updates. On of my sparcs acted as file server, with one 4.2 G drive as boot
disk, and 2* 18G Seagate drives as data disks. Both data disks only had 1
big partition. The server ran ypserv for about a week, and was the result
of a migration from an IRIX file server.
A week ago, one of the other 2 systems started to behave strangely. When I
type du, df, mount, halt, reboot,... it replied something like "exec binary
format error". The disk started to make awkward noises, so I decided to
halt it. It refused to reboot, since none of the lilo information was
accessible. 
Right after that the server started to behave in the same way. The console
spitted esp messages, so fast they were unreadable. I immediately stopped
the server as well. It didn't reboot for the same reason as the other one. 
Closer examination showed that both systemdisks were completely corrupted
and the partition tables of the datadisks were gone. The partition table of
the data disks missed every other byte, instead of "Linux Custom Disk
(etc)" it had "iu Cso Ds (etc)".
Since those phenomenas happened at the practically the same time, our
suspicion was that we had been hit by a worm or a hacker. No traces were
found, since the systemdisks were zapped. We managed to repair the
partition tables and to repair the file system, installed RH6.1 and
rebuilded our environment. 
Just today, wehne everything was becoming quite stable same thing happened
again. The YPclients started missing files in people's home directories,
programs were gone, and the console started spitting out esp messages like
crazy. Luckily enough I attached two extra drives, both 18G, and they got
murdered to. Again, partition tables were gone, inode 0 was reported bad,
file system completely corrupted, the works. I'm spending my evening
repairing the stuff. 
Only this time I don't believe in a uninvited guest. The system was
practically nailed shut, no rlogins, no ftp, no print, no mail, only nfs
and ypbind were running. 

The harder the drive was used, the bigger the damage.

This scares the hell out of me. I am busy installing Solaris2.6 again,
since I seriously doubt Linux on my server, and I want to weed out a
possible bug. I'll still run it on the other 2 sparcs, but more  in order
to repeat the error ( but without the 18G drives), and I keep my eyes open.


Some questions I hope somebody can anwser for me:
- Is it possible that this happens due to a bug in the esp driver?
- Can kflushd do this to me?
- Did this happen because I have (had) 4 18G partitions?
- Is it possible there is a relation with ypserv? ( The first time it
happened after I installed ypserv, the second time ypserv was already  
installed, both events occurred app. a week after the last boot)
- Is it possible I have an early release of sparc? I know they were some of
the first to enter the field.
- Is it possible it had something to do with external scsi devices? ( the
othre system had a dat attached to it, wich I was installing)
- If I was cracked, how did they a) manage to get in and b) manage to be so
destructive. I tried it at home, but I just couldn't zap my   drives except
when logged in as root.
- Why don't the syslog show anything?


Of course we found some bugs/thingies  as well.
- running badblocks on the disks gave  a message like "1024 possible bug",
which resulted in a file full of bad blocks.
-  when creating a filesystem with a 2048 block size ( and other sizes as
well) the superblock starts at 0, where it normally starts at 1
- You can safely dd your partition table from disk and store it in a file.
You can re -dd it when needed.
- running e2fsck (6.1) dumped core  while checking a drive that had
duplicate blocks in the inodes.


As I said, I don't hope this is a bug, cause if it is, I think a lot of
people will go ballistic.

Some response please, I don't know any longer where to look.  

Thanks,
Yves Geunes
[EMAIL PROTECTED]
-
To unsubscribe from this list: send the line "unsubscribe sparclinux" in
the body of the message to [EMAIL PROTECTED]

Reply via email to