You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(55) |
Oct
(44) |
Nov
(156) |
Dec
(123) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(130) |
Feb
(156) |
Mar
(162) |
Apr
(171) |
May
(97) |
Jun
(127) |
Jul
(58) |
Aug
(81) |
Sep
(86) |
Oct
(45) |
Nov
(41) |
Dec
(84) |
| 2003 |
Jan
(71) |
Feb
(87) |
Mar
(133) |
Apr
(152) |
May
(151) |
Jun
(232) |
Jul
(320) |
Aug
(237) |
Sep
(271) |
Oct
(536) |
Nov
(301) |
Dec
(393) |
| 2004 |
Jan
(393) |
Feb
(184) |
Mar
(314) |
Apr
(225) |
May
(139) |
Jun
(77) |
Jul
(87) |
Aug
(75) |
Sep
(139) |
Oct
(50) |
Nov
(8) |
Dec
(28) |
| 2005 |
Jan
(66) |
Feb
(63) |
Mar
(14) |
Apr
(14) |
May
(8) |
Jun
(23) |
Jul
(21) |
Aug
(6) |
Sep
(29) |
Oct
(55) |
Nov
(38) |
Dec
(8) |
| 2006 |
Jan
(5) |
Feb
(10) |
Mar
(1) |
Apr
(15) |
May
(32) |
Jun
(44) |
Jul
(11) |
Aug
(8) |
Sep
(9) |
Oct
(14) |
Nov
(4) |
Dec
(3) |
| 2007 |
Jan
(3) |
Feb
(3) |
Mar
(2) |
Apr
|
May
|
Jun
|
Jul
(35) |
Aug
(49) |
Sep
(8) |
Oct
(42) |
Nov
(44) |
Dec
(7) |
| 2008 |
Jan
(2) |
Feb
(7) |
Mar
(8) |
Apr
(80) |
May
(74) |
Jun
(29) |
Jul
(5) |
Aug
(7) |
Sep
(6) |
Oct
(1) |
Nov
|
Dec
|
| 2009 |
Jan
(8) |
Feb
(19) |
Mar
(3) |
Apr
(24) |
May
(22) |
Jun
(23) |
Jul
(8) |
Aug
(23) |
Sep
(8) |
Oct
(27) |
Nov
(52) |
Dec
(27) |
| 2010 |
Jan
(36) |
Feb
(29) |
Mar
(17) |
Apr
(28) |
May
(21) |
Jun
(4) |
Jul
|
Aug
(28) |
Sep
(18) |
Oct
(6) |
Nov
(34) |
Dec
(16) |
| 2011 |
Jan
(18) |
Feb
(12) |
Mar
|
Apr
|
May
(9) |
Jun
(1) |
Jul
(5) |
Aug
(5) |
Sep
(7) |
Oct
(16) |
Nov
(26) |
Dec
(17) |
| 2012 |
Jan
(6) |
Feb
(34) |
Mar
(52) |
Apr
(10) |
May
(3) |
Jun
|
Jul
|
Aug
(1) |
Sep
|
Oct
(4) |
Nov
(1) |
Dec
(4) |
| 2013 |
Jan
(5) |
Feb
|
Mar
|
Apr
(5) |
May
(4) |
Jun
|
Jul
|
Aug
(14) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2014 |
Jan
|
Feb
(2) |
Mar
(5) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(3) |
Dec
(11) |
| 2015 |
Jan
(5) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(1) |
Sep
(1) |
Oct
(1) |
Nov
|
Dec
|
| 2016 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2017 |
Jan
(1) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2018 |
Jan
(2) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Bruce S. <bw...@ar...> - 2004-04-29 13:46:39
|
> >I've been looking at adding "mon" on the feature requests.
> >
> >My research shows it needs a bunch of perl modules we don't have,
> >and I've never added a perl module to DL. Is anything required
> >other than uploading the source of the module to the perl-ext
> >subdirectory?
>
> Sometimes you have to patch the Makefile.PL to get rid of the prompts.
>
> Just copy the stuff into the perl-ext directory and recompile perl.
> If it prompts for something, then you know you have to patch it. ;-)
Maybe I won't add "mon" ...
Any clue what to do about this?
Making IO-Tty-1.02 (nonxs)
Can't load module IO, dynamic loading not available in this perl.
(You may need to build a new perl executable which either supports
dynamic loading or has the IO module statically linked into it.)
at ../../lib/IO/Handle.pm line 260
Compilation failed in require at ../../lib/IO/Handle.pm line 260.
BEGIN failed--compilation aborted at ../../lib/IO/Handle.pm line 260.
Compilation failed in require at ../../lib/IO/Seekable.pm line 101.
BEGIN failed--compilation aborted at ../../lib/IO/Seekable.pm line 101.
Compilation failed in require at ../../lib/IO/File.pm line 117.
BEGIN failed--compilation aborted at ../../lib/IO/File.pm line 117.
Compilation failed in require at Makefile.PL line 5.
BEGIN failed--compilation aborted at Makefile.PL line 5.
Warning: No Makefile!
make[1]: Entering directory `/data/build/tmp/perl-5.8.3/ext/IO-Tty-1.02'
make[1]: *** No rule to make target `config'. Stop.
make[1]: Leaving directory `/data/build/tmp/perl-5.8.3/ext/IO-Tty-1.02'
make config failed, continuing anyway...
make[1]: Entering directory `/data/build/tmp/perl-5.8.3/ext/IO-Tty-1.02'
make[1]: *** No rule to make target `all'. Stop.
make[1]: Leaving directory `/data/build/tmp/perl-5.8.3/ext/IO-Tty-1.02'
make: *** [ext/IO-Tty-1.02/pm_to_blib] Error 2
ERROR
/data/build/scripts/perl build failed
check log file /data/build/tmp/LOGS/build/perl for details
|
|
From: Oliver J. <oli...@mo...> - 2004-04-29 09:49:55
|
another little bit of improving :-) the kernel 2.6 support ... upgrade to 2.6.5... but its in testing state.. but better then nothing config_linux -------------- the config_linux is only a patch against my .config as i can see, was the old config-linux file only a manually updated file, and there is a little bit a mess to merge them together... ideas are welcome !!! pax-grsecurity -------------- http://pax.grsecurity.org/grsecurity-2.0-2.6.5.patch renamed to pax..... looks that only the grsecurity is available now.. must be activated as framework, else compile of pax not work... :-( have not time to do some investigations.. exec-shield 2.6.5 ----------------- http://people.redhat.com/mingo/exec-shield/ prepare script -------------- disable the patching for the net_sched in 2.6 ..... attached the changed config files and the patches against cvs oliver |
|
From: Oliver J. <oli...@mo...> - 2004-04-29 09:13:51
|
On Thu, 2004-04-29 at 10:58, Friedrich Lobenstock wrote: > Oliver Jehle wrote on 29.04.2004 08:25 MET: > > > please replace on the ftp-site > > > > http://sourceforge.net/projects/ipsec-tools/ > > It should be obvious, but have you explicitly verified that it builds > without errors? i've build it and install it... without errors... |
|
From: Friedrich L. <fl...@fl...> - 2004-04-29 08:59:13
|
Oliver Jehle wrote on 29.04.2004 08:25 MET: > please replace on the ftp-site > > http://sourceforge.net/projects/ipsec-tools/ It should be obvious, but have you explicitly verified that it builds without errors? -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Oliver J. <oli...@mo...> - 2004-04-29 06:25:26
|
please replace on the ftp-site http://sourceforge.net/projects/ipsec-tools/ thx oliver |
|
From: <hzu...@ra...> - 2004-04-28 13:31:03
|
On 04/28/2004 08:31:00 AM Bruce Smith wrote: >Looks like good changes to me. > >> OK let's say this is the last change. >> After this patch we release Beta 1 and from there only bugfixes. > >I have one more package I'd like to add if there is still time. >I've been looking at adding "mon" on the feature requests. > >My research shows it needs a bunch of perl modules we don't have, >and I've never added a perl module to DL. Is anything required >other than uploading the source of the module to the perl-ext >subdirectory? Sometimes you have to patch the Makefile.PL to get rid of the prompts. Just copy the stuff into the perl-ext directory and recompile perl. If it prompts for something, then you know you have to patch it. ;-) Heiko |
|
From: Bruce S. <bw...@ar...> - 2004-04-28 12:57:50
|
Looks like good changes to me. > OK let's say this is the last change. > After this patch we release Beta 1 and from there only bugfixes. I have one more package I'd like to add if there is still time. I've been looking at adding "mon" on the feature requests. My research shows it needs a bunch of perl modules we don't have, and I've never added a perl module to DL. Is anything required other than uploading the source of the module to the perl-ext subdirectory? - BS |
|
From: Tim T. <t....@co...> - 2004-04-28 01:31:57
|
Roland Pabel wrote: > > >>>- save device and filename >>>The used device and filename is handed over to /sbin/pre_init from >>>linuxrc, but pre_init discards it. We could save them easily to files in >>>/config , i.e. /config/DL_device_name and /config/DL_archive_name >>>and save-config could ask to save it there as a first option >>> >>> >>/config is on the CD and so read-only >>Throw it somewhere in /etc where only root has read/write access. >> >> >You're right, I thought "/shm" and wrote "/config". If it's placed in /etc/, >it could be saved to the archive, but it's of no use. >How about placing it alongside /shm/DL_DEVICE ? > > That would be excellent! Tim |
|
From: Heiko Z. <he...@zu...> - 2004-04-27 23:26:24
|
Roland Pabel wrote: > On Wednesday 28 April 2004 00:29, Heiko Zuerker wrote: > >>Roland Pabel wrote: >> >>>I thought about the config features Tim needs and thought of this: >>> >>>- a boot flag "config_no_scan" (or short "noscan") which would disable >>>probing for disks and searching for archives >>>This is a one-liner, just skip the 'find' lines in linuxrc >> >>Good idea, but let's name the parameter DL_noscan, so we can avoid >>conflicts. > > ok > > >>>- config parameter lists >>>something like >>>config=/dev/hda1:backup.tar.bz2,/dev/floppy/0 >>>This can become quite complex, unless we do not want to include stuff >>>like search two partitions for one file : >>>config=(/dev/hda1,/dev/hda2):x.tar.bz2 that should be entered like this: >>>config=/dev/hda1:x.tar.bz2,/dev/hda2:x.tar.bz2 >>>This should be easy to implement, split the line at the comma's and >>>handle each block >> >>config=/dev/hda1:x.tar.bz2,/dev/hda2:x.tar.bz2 >>is the better solution. But make the : part optional, if not present >>expect etc.tar.bz2 > > yes, exactly as it is now It would probably be a good idea to also rename this parameter to DL_config . All lowercase would probably be better too.... >>>- save device and filename >>>The used device and filename is handed over to /sbin/pre_init from >>>linuxrc, but pre_init discards it. We could save them easily to files in >>>/config , i.e. /config/DL_device_name and /config/DL_archive_name >>>and save-config could ask to save it there as a first option >> >>/config is on the CD and so read-only >>Throw it somewhere in /etc where only root has read/write access. > > You're right, I thought "/shm" and wrote "/config". If it's placed in /etc/, > it could be saved to the archive, but it's of no use. > How about placing it alongside /shm/DL_DEVICE ? Good idea. >>>- The boot image >>>I wanted to add the version number to the boot image, so you'd see what >>>you're about to boot. pbmtext/pbmtextps doesn't work for me (error's I >>>could resolve yet), and pbmlabel looks bad (the lines are just 1 point >>>thick, much too thin). Writing the text twice just one point displaced to >>>the right makes it look better, but not perfect... does anybody else know >>>of a standard tool for this stuff? (or could someone else try with >>>pbmtext?) >> >>No idea >> >> >>>Roland >>>PS: I think I heard feature freeze somewhere ;-) >> >>What do others think about including those features in 1.2 ? >>I think it would be a good addition. > > the boot option stuff is local to linuxrc, shouldn't introduce any unforseen > bugs anywhere else... OK let's say this is the last change. After this patch we release Beta 1 and from there only bugfixes. Heiko |
|
From: Roland P. <pa...@ta...> - 2004-04-27 23:05:45
|
On Wednesday 28 April 2004 00:29, Heiko Zuerker wrote: > Roland Pabel wrote: > > I thought about the config features Tim needs and thought of this: > > > > - a boot flag "config_no_scan" (or short "noscan") which would disable > > probing for disks and searching for archives > > This is a one-liner, just skip the 'find' lines in linuxrc > > Good idea, but let's name the parameter DL_noscan, so we can avoid > conflicts. ok > > - config parameter lists > > something like > > config=/dev/hda1:backup.tar.bz2,/dev/floppy/0 > > This can become quite complex, unless we do not want to include stuff > > like search two partitions for one file : > > config=(/dev/hda1,/dev/hda2):x.tar.bz2 that should be entered like this: > > config=/dev/hda1:x.tar.bz2,/dev/hda2:x.tar.bz2 > > This should be easy to implement, split the line at the comma's and > > handle each block > > config=/dev/hda1:x.tar.bz2,/dev/hda2:x.tar.bz2 > is the better solution. But make the : part optional, if not present > expect etc.tar.bz2 yes, exactly as it is now > > - save device and filename > > The used device and filename is handed over to /sbin/pre_init from > > linuxrc, but pre_init discards it. We could save them easily to files in > > /config , i.e. /config/DL_device_name and /config/DL_archive_name > > and save-config could ask to save it there as a first option > > /config is on the CD and so read-only > Throw it somewhere in /etc where only root has read/write access. You're right, I thought "/shm" and wrote "/config". If it's placed in /etc/, it could be saved to the archive, but it's of no use. How about placing it alongside /shm/DL_DEVICE ? > > - The boot image > > I wanted to add the version number to the boot image, so you'd see what > > you're about to boot. pbmtext/pbmtextps doesn't work for me (error's I > > could resolve yet), and pbmlabel looks bad (the lines are just 1 point > > thick, much too thin). Writing the text twice just one point displaced to > > the right makes it look better, but not perfect... does anybody else know > > of a standard tool for this stuff? (or could someone else try with > > pbmtext?) > > No idea > > > Roland > > PS: I think I heard feature freeze somewhere ;-) > > What do others think about including those features in 1.2 ? > I think it would be a good addition. the boot option stuff is local to linuxrc, shouldn't introduce any unforseen bugs anywhere else... Roland -- ICQ UIN 49339118 Linux Counter #88774 GPG-Key 1024D/59C6AFA6 2003-02-07 Roland Pabel <ro...@pa...> |
|
From: Diego T. <dt...@co...> - 2004-04-27 22:50:40
|
On Tue, Apr 27, 2004 at 08:52:28AM -0400, Heiko Zuerker wrote: > > On Tue, Apr 27, 2004 at 03:11:34AM +0200, Diego Torres wrote: > > > > an one more... what about 2.4.26? is it ready yet? :) > > It's in CVS for a week... ;-) yeah, i've noticed it... and now, testing... :) -- -- gnupg keyfingerprint -- 48AF 5BF9 8F54 2966 64CC 2327 7CD0 DD91 B09D 5799 -- Use of a keyboard or mouse may be linked to serious injuries or disorders. Diego Torres - dtorres at anthalia dot org - Madrid / España |
|
From: Friedrich L. <fl...@fl...> - 2004-04-27 22:40:47
|
Hi <realname missing>! ]Aphex[ wrote on 27.04.2004 22:58 MET: > Nobody is going to start a project for that little script of let's say 20 > lines in bash which you could probably even shorten to 5 lines. I'll add > some features anyway and make it stable and more spread :)Thanks for the > info. You are always welcome to post a link here on the list. You might even get some people to test it out and maybe also vote for inclusion in DL ;-) -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Heiko Z. <he...@zu...> - 2004-04-27 22:31:18
|
Roland Pabel wrote: > I thought about the config features Tim needs and thought of this: > > - a boot flag "config_no_scan" (or short "noscan") which would disable probing > for disks and searching for archives > This is a one-liner, just skip the 'find' lines in linuxrc Good idea, but let's name the parameter DL_noscan, so we can avoid conflicts. > - config parameter lists > something like > config=/dev/hda1:backup.tar.bz2,/dev/floppy/0 > This can become quite complex, unless we do not want to include stuff like > search two partitions for one file : config=(/dev/hda1,/dev/hda2):x.tar.bz2 > that should be entered like this: > config=/dev/hda1:x.tar.bz2,/dev/hda2:x.tar.bz2 > This should be easy to implement, split the line at the comma's and handle > each block config=/dev/hda1:x.tar.bz2,/dev/hda2:x.tar.bz2 is the better solution. But make the : part optional, if not present expect etc.tar.bz2 > - save device and filename > The used device and filename is handed over to /sbin/pre_init from linuxrc, > but pre_init discards it. We could save them easily to files in /config , > i.e. /config/DL_device_name and /config/DL_archive_name > and save-config could ask to save it there as a first option /config is on the CD and so read-only Throw it somewhere in /etc where only root has read/write access. > - The boot image > I wanted to add the version number to the boot image, so you'd see what you're > about to boot. pbmtext/pbmtextps doesn't work for me (error's I could resolve > yet), and pbmlabel looks bad (the lines are just 1 point thick, much too > thin). Writing the text twice just one point displaced to the right makes it > look better, but not perfect... does anybody else know of a standard tool for > this stuff? (or could someone else try with pbmtext?) No idea > Roland > PS: I think I heard feature freeze somewhere ;-) What do others think about including those features in 1.2 ? I think it would be a good addition. cu Heiko |
|
From: Friedrich L. <fl...@fl...> - 2004-04-27 22:30:51
|
Roland Pabel wrote on 28.04.2004 00:17 MET: > PS: I think I heard feature freeze somewhere ;-) Yes you heard right! -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Roland P. <pa...@ta...> - 2004-04-27 22:18:00
|
I thought about the config features Tim needs and thought of this: - a boot flag "config_no_scan" (or short "noscan") which would disable probing for disks and searching for archives This is a one-liner, just skip the 'find' lines in linuxrc - config parameter lists something like config=/dev/hda1:backup.tar.bz2,/dev/floppy/0 This can become quite complex, unless we do not want to include stuff like search two partitions for one file : config=(/dev/hda1,/dev/hda2):x.tar.bz2 that should be entered like this: config=/dev/hda1:x.tar.bz2,/dev/hda2:x.tar.bz2 This should be easy to implement, split the line at the comma's and handle each block - save device and filename The used device and filename is handed over to /sbin/pre_init from linuxrc, but pre_init discards it. We could save them easily to files in /config , i.e. /config/DL_device_name and /config/DL_archive_name and save-config could ask to save it there as a first option - The boot image I wanted to add the version number to the boot image, so you'd see what you're about to boot. pbmtext/pbmtextps doesn't work for me (error's I could resolve yet), and pbmlabel looks bad (the lines are just 1 point thick, much too thin). Writing the text twice just one point displaced to the right makes it look better, but not perfect... does anybody else know of a standard tool for this stuff? (or could someone else try with pbmtext?) Roland PS: I think I heard feature freeze somewhere ;-) -- ICQ UIN 49339118 Linux Counter #88774 GPG-Key 1024D/59C6AFA6 2003-02-07 Roland Pabel <ro...@pa...> |
|
From: Heiko Z. <he...@zu...> - 2004-04-27 21:01:19
|
> On Tuesday 27 April 2004 22:33, hzu...@ra... wrote: >> On 04/27/2004 04:01:22 PM Tim wrote: >> >Roland Pabel wrote: >> > >> >On Tuesday 27 April 2004 06:14, Tim Tait wrote: >> >[...] > [...] >> >> @Roland >> That reminds me that you probably should write a few lines about it, >> which >> I can copy'n'paste into the documenation. ;-) > there's always a catch ;-) I'll see to it... Hehe. Thx ! > something else: I tried some stuff yesterday to get rid of the "sleep > 15" (waiting for usb-storage) in linuxrc, unsuccessful... > /proc/bus/usb/devices is updated dynamically when the usb bus is probed, > that > just needs time... I was afraid of that. :-( -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: ]Aphex[ <ap...@ap...> - 2004-04-27 20:57:44
|
Nobody is going to start a project for that little script of let's say 20 lines in bash which you could probably even shorten to 5 lines. I'll add some features anyway and make it stable and more spread :)Thanks for the info. Alex Prinsier ----- Original Message ----- From: "Friedrich Lobenstock" <fl...@fl...> To: <dev...@li...> Sent: Tuesday, April 27, 2004 10:44 PM Subject: Re: [Devil-linux-develop] made little script > Hi <realname missing> > > ]Aphex[ wrote on 27.04.2004 22:02 MET: > > > Hello, I have been using devil-linux for a while now, and i really like > > it! That's why I started to customize it to my personal needs and I > > wrote some things. I am writing for example a little script which counts > > bandwith using bash language from /proc/net/dev. Very easy script, but > > there wasn't anything that was that easy to use and already included in > > devil-linux. Would it be possible I could submit it when it's a bit > > stable and see it in a future version of DL? > > > > I don't know how you deal with any new guys and how I could help with > > devil-linux. I would really like to help with it, could someone tell me > > what I should do to put my script (when finished) in devil-linux? If > > it's possible to get my script in DL I'd like to update the docs for my > > program too. > > Hmmm...what about you first make those scripts available for download > somewhere, announce them on FreshMeat.net. This should get them a more wide > spread testing and after that it might be time to consider them for inclusion. > > To avoide the "invent the wheel again" situations I ask you, have you > searched the web for any solution that might do what you want? If you did > not search, please do so and join those projects and then give us > information about those project and if you think they are worth including > in DL. > > It's really more about stability, if your scripts are not used and tested > by anybody else they might break our complete system in the worst case, eg. > by indroducing a security hole. > > > I assume all developing happens through cvs, but that makes me wonder > > why people still submit patches to the mailing list. How exactly happens > > this development? > > There are three developers who have write access to the CVS: > * Heiko > * Bruce > * myself > > and there are other developers with read-only access, which more or less > regularly submit patches to fix bugs, ... > > If you can please first try to find and fix existing bugs. As said above > software projects with some sort of user base are definitely prefered. > > Still some question? Just ask. > > -- > MfG / Regards > Friedrich Lobenstock > ____________________________________________________________________ > Friedrich Lobenstock Linux Services Lobenstock > URL: http://www.lsl.at/ Email: fl...@fl... > ____________________________________________________________________ > > > ------------------------------------------------------- > This SF.Net email is sponsored by: Oracle 10g > Get certified on the hottest thing ever to hit the market... Oracle 10g. > Take an Oracle 10g class now, and we'll give you the exam FREE. > http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop > |
|
From: Roland P. <pa...@ta...> - 2004-04-27 20:49:54
|
On Tuesday 27 April 2004 22:33, hzu...@ra... wrote: > On 04/27/2004 04:01:22 PM Tim wrote: > >Roland Pabel wrote: > > > >On Tuesday 27 April 2004 06:14, Tim Tait wrote: > >[...] [...] > > @Roland > That reminds me that you probably should write a few lines about it, which > I can copy'n'paste into the documenation. ;-) there's always a catch ;-) I'll see to it... something else: I tried some stuff yesterday to get rid of the "sleep 15" (waiting for usb-storage) in linuxrc, unsuccessful... /proc/bus/usb/devices is updated dynamically when the usb bus is probed, that just needs time... Roland -- ICQ UIN 49339118 Linux Counter #88774 GPG-Key 1024D/59C6AFA6 2003-02-07 Roland Pabel <ro...@pa...> |
|
From: Friedrich L. <fl...@fl...> - 2004-04-27 20:44:34
|
Hi <realname missing> ]Aphex[ wrote on 27.04.2004 22:02 MET: > Hello, I have been using devil-linux for a while now, and i really like > it! That's why I started to customize it to my personal needs and I > wrote some things. I am writing for example a little script which counts > bandwith using bash language from /proc/net/dev. Very easy script, but > there wasn't anything that was that easy to use and already included in > devil-linux. Would it be possible I could submit it when it's a bit > stable and see it in a future version of DL? > > I don't know how you deal with any new guys and how I could help with > devil-linux. I would really like to help with it, could someone tell me > what I should do to put my script (when finished) in devil-linux? If > it's possible to get my script in DL I'd like to update the docs for my > program too. Hmmm...what about you first make those scripts available for download somewhere, announce them on FreshMeat.net. This should get them a more wide spread testing and after that it might be time to consider them for inclusion. To avoide the "invent the wheel again" situations I ask you, have you searched the web for any solution that might do what you want? If you did not search, please do so and join those projects and then give us information about those project and if you think they are worth including in DL. It's really more about stability, if your scripts are not used and tested by anybody else they might break our complete system in the worst case, eg. by indroducing a security hole. > I assume all developing happens through cvs, but that makes me wonder > why people still submit patches to the mailing list. How exactly happens > this development? There are three developers who have write access to the CVS: * Heiko * Bruce * myself and there are other developers with read-only access, which more or less regularly submit patches to fix bugs, ... If you can please first try to find and fix existing bugs. As said above software projects with some sort of user base are definitely prefered. Still some question? Just ask. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: <hzu...@ra...> - 2004-04-27 20:33:03
|
On 04/27/2004 04:01:22 PM Tim wrote: >Roland Pabel wrote: > >On Tuesday 27 April 2004 06:14, Tim Tait wrote: >[...] > > >While I'm on the topic, I think another pontential hole is the linuxrc= >script that discovers the etc.tar.bz2 file on boot... since multiple >locations are checked, if an unpriveleged user can introduce an >etc.tar.bz2 file onto a drive that is checked before the real one, the= n >they can control the machine on the next reboot. We should check the >file for "root" ownership and that it is not writeable by anyone else >before loading it. Of course not being a bash master I'm not sure how = to >write that... > > >if you have several users on a system, the most dangerous part is >rebooting. >it's the only time a false config could be injected, but even worse: >just >pass init=3D/bin/bash and you have a root shell. So either: don't rebo= ot, >or: >always attend your reboots and make sure the right config is loaded. >If you want to disable command line passing, you have to change >isolinux.cfg. >When doing that, you can also add a "config=3D/dev/whatever" and if yo= u >protect >that device properly, everything should be fine. >of course, make sure no one swaps CD's and boots a rescue system... >so, IMHO, root ownership may be an additional security check, but it's= >inferior to gpg signing (but maybe we should make that part easier...)= >Roland > >DL supports passing the etc.tar.bz2 file location from boot program? >Cool! And is it just isolinux or does Grub and Lilo work too parameter= >passing from hard disk boots? This would solve a major headache for me= >- I don't want DL scanning all 7 or 8 disk partitions and floppies, us= b >etc. I just want to tell it load=A0 the one on hda1, or the floppy. I = can >make grub menu picks for those. Can/does this parameter also get read >by save-config? My 2nd big concern is a config be written back to >somewhere other than it came from. @Roland That reminds me that you probably should write a few lines about it, wh= ich I can copy'n'paste into the documenation. ;-) >As Bruce pointed out, the floppy FAT doesn't support ownership >attributes, so that may not help. But if I can force the etc.tar.bz2 >location from the boot string, which already has a config file that is= >root only access, then a non priveleged user can not overwrite it so >thats even better. Endeless possibilities... ;-) Heiko = |
|
From: Roland P. <pa...@ta...> - 2004-04-27 20:29:34
|
On Tuesday 27 April 2004 22:01, Tim wrote: > Roland Pabel wrote: > >On Tuesday 27 April 2004 06:14, Tim Tait wrote: > >[...] > > [...] > > DL supports passing the etc.tar.bz2 file location from boot program? yes, I added that a few weeks ago., See the mailing list archive or press F3 at the boot screen The essentials: - config=/dev/hda1:backup.tar.bz2 will search for that file on that device first - config=/dev/hda1 will scan that device first - config=backup.tar.bz2 will scan all devices for that archvie first > Cool! And is it just isolinux or does Grub and Lilo work too parameter > passing from hard disk boots? This would solve a major headache for me - I guess, would surprise me otherwise...but haven't ever booted DL from a harddrive...isolinux,grub and lilo can also protect the boot options, making them un-editable... > I don't want DL scanning all 7 or 8 disk partitions and floppies, usb > etc. I just want to tell it load the one on hda1, or the floppy. I can > make grub menu picks for those. Can/does this parameter also get read by > save-config? My 2nd big concern is a config be written back to somewhere > other than it came from. We could add more features like: - exclusive: scan only one device - lists: config=/dev/hda1,/dev/hda2 ... > As Bruce pointed out, the floppy FAT doesn't support ownership > attributes, so that may not help. But if I can force the etc.tar.bz2 > location from the boot string, which already has a config file that is > root only access, then a non priveleged user can not overwrite it so > thats even better. that shouldn't be a problem... Roland -- ICQ UIN 49339118 Linux Counter #88774 GPG-Key 1024D/59C6AFA6 2003-02-07 Roland Pabel <ro...@pa...> |
|
From: Roland P. <pa...@ta...> - 2004-04-27 20:19:54
|
On Tuesday 27 April 2004 21:39, Heiko Zuerker wrote: > > On Tuesday 27 April 2004 06:14, Tim Tait wrote: > > [...] > > [...] > > > > if you have several users on a system, the most dangerous part is > > rebooting. > > it's the only time a false config could be injected, but even worse: just > > pass init=/bin/bash and you have a root shell. So either: don't reboot, > > or: > > always attend your reboots and make sure the right config is loaded. > > If you want to disable command line passing, you have to change > > isolinux.cfg. > > When doing that, you can also add a "config=/dev/whatever" and if you > > protect > > that device properly, everything should be fine. > > You can NEVER protect a system when somebody has access to the hardware. > There are endless possibilities on how to gain access.... That's true, that "everything" was an overstatement... > > of course, make sure no one swaps CD's and boots a rescue system... > > so, IMHO, root ownership may be an additional security check, but it's > > inferior to gpg signing (but maybe we should make that part easier...) > > Suggestions on how we can make it easier? > At the moment you only put the public key on the CD and it's working. That's nothing we can change, unless you bring the public to the system every time you boot. Improvement's could be: - automatic key pair generation on custom build - use keys the user supplies (both via menuconfig) > I think the signing of the config is the most complicated part, since you > have to get the etc.tar.bz2, sign it and copy the signature to the config > media. the private key must be supplied by root somehow. If he (the admin) is personally present at the system, we could search for the gpg key on another medium (for example usb-stick...) If not, that's difficult...copying the archive around and signing without knowing how the admin wants to access it, no way... Roland -- ICQ UIN 49339118 Linux Counter #88774 GPG-Key 1024D/59C6AFA6 2003-02-07 Roland Pabel <ro...@pa...> |
|
From: Tim <t....@co...> - 2004-04-27 20:01:36
|
Roland Pabel wrote: >On Tuesday 27 April 2004 06:14, Tim Tait wrote: >[...] > > >>While I'm on the topic, I think another pontential hole is the linuxrc >>script that discovers the etc.tar.bz2 file on boot... since multiple >>locations are checked, if an unpriveleged user can introduce an >>etc.tar.bz2 file onto a drive that is checked before the real one, then >>they can control the machine on the next reboot. We should check the >>file for "root" ownership and that it is not writeable by anyone else >>before loading it. Of course not being a bash master I'm not sure how to >>write that... >> >> >if you have several users on a system, the most dangerous part is rebooting. >it's the only time a false config could be injected, but even worse: just >pass init=/bin/bash and you have a root shell. So either: don't reboot, or: >always attend your reboots and make sure the right config is loaded. >If you want to disable command line passing, you have to change isolinux.cfg. >When doing that, you can also add a "config=/dev/whatever" and if you protect >that device properly, everything should be fine. >of course, make sure no one swaps CD's and boots a rescue system... >so, IMHO, root ownership may be an additional security check, but it's >inferior to gpg signing (but maybe we should make that part easier...) >Roland > DL supports passing the etc.tar.bz2 file location from boot program? Cool! And is it just isolinux or does Grub and Lilo work too parameter passing from hard disk boots? This would solve a major headache for me - I don't want DL scanning all 7 or 8 disk partitions and floppies, usb etc. I just want to tell it load the one on hda1, or the floppy. I can make grub menu picks for those. Can/does this parameter also get read by save-config? My 2nd big concern is a config be written back to somewhere other than it came from. As Bruce pointed out, the floppy FAT doesn't support ownership attributes, so that may not help. But if I can force the etc.tar.bz2 location from the boot string, which already has a config file that is root only access, then a non priveleged user can not overwrite it so thats even better. Tim |
|
From: ]Aphex[ <ap...@ap...> - 2004-04-27 20:01:25
|
Hello, I have been using devil-linux for a while now, and i really like = it! That's why I started to customize it to my personal needs and I = wrote some things. I am writing for example a little script which counts = bandwith using bash language from /proc/net/dev. Very easy script, but = there wasn't anything that was that easy to use and already included in = devil-linux. Would it be possible I could submit it when it's a bit = stable and see it in a future version of DL? I don't know how you deal with any new guys and how I could help with = devil-linux. I would really like to help with it, could someone tell me = what I should do to put my script (when finished) in devil-linux? If = it's possible to get my script in DL I'd like to update the docs for my = program too. I assume all developing happens through cvs, but that makes me wonder = why people still submit patches to the mailing list. How exactly happens = this development? Alex |
|
From: Heiko Z. <he...@zu...> - 2004-04-27 19:41:42
|
> On Tuesday 27 April 2004 06:14, Tim Tait wrote: > [...] >> >> While I'm on the topic, I think another pontential hole is the linuxrc >> script that discovers the etc.tar.bz2 file on boot... since multiple >> locations are checked, if an unpriveleged user can introduce an >> etc.tar.bz2 file onto a drive that is checked before the real one, then >> they can control the machine on the next reboot. We should check the >> file for "root" ownership and that it is not writeable by anyone else >> before loading it. Of course not being a bash master I'm not sure how to >> write that... > if you have several users on a system, the most dangerous part is > rebooting. > it's the only time a false config could be injected, but even worse: just > pass init=/bin/bash and you have a root shell. So either: don't reboot, > or: > always attend your reboots and make sure the right config is loaded. > If you want to disable command line passing, you have to change > isolinux.cfg. > When doing that, you can also add a "config=/dev/whatever" and if you > protect > that device properly, everything should be fine. You can NEVER protect a system when somebody has access to the hardware. There are endless possibilities on how to gain access.... > of course, make sure no one swaps CD's and boots a rescue system... > so, IMHO, root ownership may be an additional security check, but it's > inferior to gpg signing (but maybe we should make that part easier...) Suggestions on how we can make it easier? At the moment you only put the public key on the CD and it's working. I think the signing of the config is the most complicated part, since you have to get the etc.tar.bz2, sign it and copy the signature to the config media. -- Regards Heiko Zuerker http://www.devil-linux.org |