|
From: Friedrich L. <fl...@fl...> - 2002-04-04 23:55:37
|
Hi! I just found out that without a running klogd everytime a logging filterrule is hit it gets printed on the console and not only in the syslog. I had to replace the busybox klogd and then start "klogd -c 1". Now it is possible to work on the console while your are eg. under attack and lot of log rules get hit. I'd like to check in my modifications, but I don't know the motivations behind why klogd wasn't started before. -- MfG / Regards Friedrich Lobenstock |
|
From: Heiko Z. <he...@zu...> - 2002-04-05 00:23:18
|
Friedrich Lobenstock wrote:
> Hi!
>
> I just found out that without a running klogd everytime a logging filterrule
> is hit it gets printed on the console and not only in the syslog. I had to
> replace the busybox klogd and then start "klogd -c 1". Now it is possible to
> work on the console while your are eg. under attack and lot of log rules get
> hit.
>
> I'd like to check in my modifications, but I don't know the motivations
> behind why klogd wasn't started before.
When you specify debug (7) as loglevel, then you don't have any problems.
Here is an example I use:
$IPTABLES -N LOG_AND_DROP
$IPTABLES -A LOG_AND_DROP -j LOG --log-level debug \
--log-prefix "DROP " -m limit --limit $LOG_LIMIT
$IPTABLES -A LOG_AND_DROP -j DROP
--
cu
Heiko
We are Penguin, Resistance is futile!
http://www.devil-linux.org
|
|
From: John v. V. <joh...@ya...> - 2002-04-06 15:49:42
|
Hi all,
Mix one 5 $$ harddrive, one 0.50 $$ cdrom ...
I cut the disk, booted (still trying to re-boot from hdc and not moving to hdd
when it fails)
Followed Friedrich's excellent docs on PV, and, with only 64 megs got an LVM
swap working. I then loaded perl and others w/ utter joy and amazement.
( I had to run vgscan first though ;) )
This will be the second time our general meeting will revolve around DL.
I want to add some input espeically about creating the more generic build to
support 486 (which makes sense considering the absolute low cost of a DL
system) as well as the possibility of implementing an Xdesktop to test the
efficiency of the SHMFS paging system.
So, ttyl, thanks again for all your efforts :)
John
=====
John van Vlaanderen
#############################################
# CXN, Inc. Contact: jo...@th... # #
# Proud Sponsor of The Linux Society #
# http://www.thelinuxsociety.org #
#############################################
__________________________________________________
Do You Yahoo!?
Yahoo! Tax Center - online filing with TurboTax
http://taxes.yahoo.com/
|
|
From: Friedrich L. <fl...@fl...> - 2002-04-06 18:01:03
|
"John van V." wrote: > > I cut the disk, booted (still trying to re-boot from hdc and not moving to hdd > when it fails) Hmmm...sorry for my bad English, but I don't understand what you are talking about. > Followed Friedrich's excellent docs on PV, and, with only 64 megs got an LVM > swap working. I then loaded perl and others w/ utter joy and amazement. > ( I had to run vgscan first though ;) ) Ok, forgot the "vgscan" in the harddisk howto. Heiko, how about loading just LVM in with linuxrc and all other packages when the (optional) harddisk ist mounted and swap is available? -- MfG / Regards Friedrich Lobenstock |
|
From: John v. V. <joh...@ya...> - 2002-04-06 18:27:11
|
Hi again,
> Hmmm...sorry for my bad English, but I don't understand what you are talking
> about.
Ok, I burned the disk on hdc ... a slow cd device. I then put it in the fast
CD device, hdd and it booted. But when DL went to look for a CD device, it
went to hdc, the slow one and failed. The code then needs to go look for
another CD device to boot from.. thats all.
> Ok, forgot the "vgscan" in the harddisk howto.
No problem !!
> Heiko, how about loading just LVM in with linuxrc and all other packages when
> the (optional) harddisk ist mounted and swap is available?
Hmmmm, this may get complicated.. for instance how to decide which hard drive
to use ?? This sort of goes back to the 486 vrs 586 conflict.
It may go to the issue of configuration. Either it can be done when you make
the build, or when you boot... Deciding when you make the build seems more
appropriate.
Thanks again, John
BTW, after setting up the LVM, I really wanted to mirror (just the admin in
me!!)
=====
John van Vlaanderen
#############################################
# CXN, Inc. Contact: jo...@th... # #
# Proud Sponsor of The Linux Society #
# http://www.thelinuxsociety.org #
#############################################
__________________________________________________
Do You Yahoo!?
Yahoo! Tax Center - online filing with TurboTax
http://taxes.yahoo.com/
|
|
From: Friedrich L. <fl...@fl...> - 2002-04-06 20:26:15
|
"John van V." wrote:
>
> Ok, I burned the disk on hdc ... a slow cd device. I then put it in the fast
> CD device, hdd and it booted. But when DL went to look for a CD device, it
> went to hdc, the slow one and failed. The code then needs to go look for
> another CD device to boot from.. thats all.
OK, understand. Will take a look into the script.
> > Heiko, how about loading just LVM in with linuxrc and all other packages when
> > the (optional) harddisk ist mounted and swap is available?
>
> Hmmmm, this may get complicated.. for instance how to decide which hard drive
> to use ?? This sort of goes back to the 486 vrs 586 conflict.
No, that's just an easy two step configuration:
1) * start with a config that just includes LVM as the only optional
software to install
* create the "devil-linux" harddisk (see harddisk howto)
with at least swap and other optional "partitions" (lv's)
2) * now edit /etc/sysconfig/software to load all the wanted
software at boot and run "save_config"
* reboot
I guess that 32MB would be enough for this setup.
But ONLY if we make changes that load other (optional) software when
swap is activated!
> It may go to the issue of configuration. Either it can be done when you make
> the build, or when you boot... Deciding when you make the build seems more
> appropriate.
No it's not build time dependent and shouldn't be IMO.
> BTW, after setting up the LVM, I really wanted to mirror (just the admin in
> me!!)
If I'm correct the raidtools, better the successor mdadm
http://www.cse.unsw.edu.au/~neilb/source/mdadm/
is planed for inclusion, sooner or later.
BTW 3Ware IDE raid controllers (http://www.3ware.com/ ) are the real stuff
under linux :-)
--
MfG / Regards
Friedrich Lobenstock
|
|
From: Friedrich L. <fl...@fl...> - 2002-04-06 21:31:27
|
Friedrich Lobenstock wrote: > > "John van V." wrote: > > > > Ok, I burned the disk on hdc ... a slow cd device. I then put it in the fast > > CD device, hdd and it booted. But when DL went to look for a CD device, it > > went to hdc, the slow one and failed. The code then needs to go look for > > another CD device to boot from.. thats all. > > OK, understand. Will take a look into the script. Hmmmm...can you give me more infos because when I simulate this under Vmware I can't reproduce this. See the screen shots: http://www.fl.priv.at/devil-linux/dl-start-01.gif http://www.fl.priv.at/devil-linux/dl-start-02.gif /dev/hda is the physical cdrom drive with no disk in it. /dev/hdb is a cd simulation based on a devil-linux iso image. So for me it works. If there's no cd in the drive the next drive is being tried. -- MfG / Regards Friedrich Lobenstock |
|
From: Heiko Z. <he...@zu...> - 2002-04-08 22:40:24
|
Friedrich Lobenstock wrote: > "John van V." wrote:> I guess that 32MB would be enough for this setup. ping 1.2.3.4 *swap* *swap* *swap* *swap* respone from 1.2.3.4 1 hour 55 minutes ;-) > But ONLY if we make changes that load other (optional) software when > swap is activated! LVM inside Initrd would solve that ( as discussed ). > If I'm correct the raidtools, better the successor mdadm > http://www.cse.unsw.edu.au/~neilb/source/mdadm/ > is planed for inclusion, sooner or later. Jepp. Should we add it to Release Candidate 1 ? Does somebody need it and would actually test it immediatelly ? > BTW 3Ware IDE raid controllers (http://www.3ware.com/ ) are the real stuff > under linux :-) Agreed ! -- cu Heiko We are Penguin, Resistance is futile! http://www.devil-linux.org |
|
From: Heiko Z. <he...@zu...> - 2002-04-08 22:40:23
|
Friedrich Lobenstock wrote: > Ok, forgot the "vgscan" in the harddisk howto. Do you still have no Lyx installed? ;-) > > Heiko, how about loading just LVM in with linuxrc and all other packages when > the (optional) harddisk ist mounted and swap is available? Actually a good idea. We have to check, if ram0 is destroyed correctly after we boot the final system. Otherwise we waste RAM, because we have to install LVM into initrd. Should we install it from CD or should we have it directly in the initrd tarball? -- cu Heiko We are Penguin, Resistance is futile! http://www.devil-linux.org |
|
From: Friedrich L. <fl...@fl...> - 2002-04-09 00:54:59
|
Heiko Zuerker wrote: > > > Heiko, how about loading just LVM in with linuxrc and all other packages when > > the (optional) harddisk ist mounted and swap is available? > > Actually a good idea. > We have to check, if ram0 is destroyed correctly after we boot the final > system. Otherwise we waste RAM, because we have to install LVM into initrd. > Should we install it from CD or should we have it directly in the initrd > tarball? No I would not run a vgscan in the ram0 ramdisk, but would just unpack the LVM package boot the system, let it mount the harddisk, then unpack all other wanted packages and keep on booting. IMHO the initial ramdisk should be kept as small and simple as possible, just enought to start the system - nothing more, nothing less. -- MfG / Regards Friedrich Lobenstock |
|
From: Heiko Z. <he...@zu...> - 2002-04-09 01:20:29
|
On Tue, 09 Apr 2002 02:56:21 +0200 "Friedrich Lobenstock" <fl...@fl...> wrote: > Heiko Zuerker wrote: > > > > > Heiko, how about loading just LVM in with linuxrc and all other packages when > > > the (optional) harddisk ist mounted and swap is available? > > > > Actually a good idea. > > We have to check, if ram0 is destroyed correctly after we boot the final > > system. Otherwise we waste RAM, because we have to install LVM into initrd. > > Should we install it from CD or should we have it directly in the initrd > > tarball? > > No I would not run a vgscan in the ram0 ramdisk, but would just unpack the > LVM package boot the system, let it mount the harddisk, then unpack all other > wanted packages and keep on booting. Hmmm.... I would like to keep the installation of the packages inside Initrd. I planned to encrypt the tarballs of the packages, to make it harder for an intruder add software after he managed to break into the system. Currently he has just to run tar -xzf /cdrom/packages/XYZ.tar.gz . It wouldn't be a problem to initialize the LVM inside initrd, because we use the same /etc as later. > > IMHO the initial ramdisk should be kept as small and simple as possible, just > enought to start the system - nothing more, nothing less. Agreed. We could add only the really needed tools to initialize the LVM. Or we could just work with symlinks to the SHMFS. -- cu Heiko http://www.devil-linux.org |
|
From: Friedrich L. <fl...@fl...> - 2002-04-09 19:49:18
|
On Mon, 8 Apr 2002 21:15, Heiko Zuerker wrote: > I would like to keep the installation of the packages inside Initrd. > I planned to encrypt the tarballs of the packages, to make it harder > for an intruder add software after he managed to break into the > system. Currently he has just to run tar -xzf > /cdrom/packages/XYZ.tar.gz . Ok, point taken. So you're right we need LVM (just /sbin/vgscan, /sbin/vgchange and libs) in the initrd. > We could add only the really needed tools to initialize the LVM. > Or we could just work with symlinks to the SHMFS. I suggest we put chroot on the intial ramdisk then we run the LVM utilities chroot /dev/shm, so when we switch to the real root everything is in place. BTW when you want to be more secure then we should get rid of the /etc/initrd dir and should not rely on possibly forgable scripts. -- MfG / Regards Friedrich Lobenstock |
|
From: Friedrich L. <fl...@fl...> - 2002-04-05 01:33:56
|
Heiko Zuerker wrote: > > > I'd like to check in my modifications, but I don't know the motivations > > behind why klogd wasn't started before. > > When you specify debug (7) as loglevel, then you don't have any problems. So why not klogd? Not only messages to the console would get suppressed, also oopses would get decoded if we'd run klogd. See http://www.balabit.hu/static/syslog-ng/reference/reference.html Example 3-5. Using the file() driver .... NOTE: on Linux, the klogd daemon reads kernel messages, and forwards them to the syslogd process. klogd preprocesses kernel messages and replaces addresses with symbolic names (from /boot/System.map). If you don't want to lose this functionality you'll have to run klogd with syslog-ng as well. -- MfG / Regards Friedrich Lobenstock |
|
From: Heiko Z. <he...@zu...> - 2002-04-05 03:10:53
|
Hey, that's an argument I can't beat. I start adding klogd, hope I can finish it tonight. -- cu Heiko http://www.devil-linux.org |
|
From: Heiko Z. <he...@zu...> - 2002-04-05 03:41:11
|
DL uses now klogd. I included klogd and modified the syslog-ng.conf and syslog-ng start script. @friedl you owe me a beer! ;-) -- cu Heiko http://www.devil-linux.org |