|
From: Bruce S. <bw...@ar...> - 2006-06-08 19:01:10
|
[As someone pointed out to me privately] Dan's Guardian is missing a bunch of config files in /etc/dansguardian/. So I modified the install script to copy the tmp /etc directory over. No problem, except Dan's config directory has a LOT of files using almost 700KB! Do we want that in /etc, taking up memory all the time? Or should we tar it up and stick it on the CD for people who want to use Dan's? (if so, where on the CD should it go?) We're also missing an init.d start file for Dan's ... - BS |
|
From: Friedrich L. <fl...@fl...> - 2006-06-08 19:25:35
|
Bruce Smith wrote on 08.06.2006 21:01 MET: > [As someone pointed out to me privately] Dan's Guardian is missing a > bunch of config files in /etc/dansguardian/. So I modified the install > script to copy the tmp /etc directory over. No problem, except Dan's > config directory has a LOT of files using almost 700KB! > > Do we want that in /etc, taking up memory all the time? Or should we > tar it up and stick it on the CD for people who want to use Dan's? > (if so, where on the CD should it go?) I'd suggest /config/ as we already have etc.tar.bz2 there. What if the init.d start script extracs /config/etc-dansguarding.tar.bz2 over /etc/ if it finds no config directory /etc/dansguardian/. This way only people activating dansguardian would have the configfiles in place and others would save the space. If I think again it might be better to have some command, eg. "extract-config" which expects eg. "dansguardian" (and set $PACKGAE) as command line option and then extracts /config/etc-$PACKAGE.tar.bz2 over /etc/. Maybe this command checks /etc/sysconfig/config for activated packages and only extracts those. A never ending story.... > We're also missing an init.d start file for Dan's ... -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Bruce S. <bw...@ar...> - 2006-06-08 19:37:47
|
> > [As someone pointed out to me privately] Dan's Guardian is missing a > > bunch of config files in /etc/dansguardian/. So I modified the install > > script to copy the tmp /etc directory over. No problem, except Dan's > > config directory has a LOT of files using almost 700KB! > > > > Do we want that in /etc, taking up memory all the time? Or should we > > tar it up and stick it on the CD for people who want to use Dan's? > > (if so, where on the CD should it go?) > > I'd suggest /config/ as we already have etc.tar.bz2 there. What if the init.d > start script extracs /config/etc-dansguarding.tar.bz2 over /etc/ if it finds no > config directory /etc/dansguardian/. This way only people activating > dansguardian would have the configfiles in place and others would save the > space. If I think again it might be better to have some command, eg. > "extract-config" which expects eg. "dansguardian" (and set $PACKGAE) as command > line option and then extracts /config/etc-$PACKAGE.tar.bz2 over /etc/. Maybe > this command checks /etc/sysconfig/config for activated packages and only > extracts those. A never ending story.... Maybe there should be a new menu in `setup` to extract the /etc files for space-intensive packages (separate menu choices per package)? Looking at the disk usage on /etc now, I see two other large directories that have potential for moving their /etc files to /config/*.tar.gz. One is snort. The other is 'l7-protocols' ... no idea what it is ... I see l7-protocols is created in patch-o-matic, but I'm not sure what package(s) use it. Is it something that can be moved too? It's currently the largest subdirectory under /etc (about 1MB). - BS |
|
From: Friedrich L. <fl...@fl...> - 2006-06-08 20:05:46
|
Bruce Smith wrote on 08.06.2006 21:37 MET:
>
> Looking at the disk usage on /etc now, I see two other large directories
> that have potential for moving their /etc files to /config/*.tar.gz.
> One is snort. The other is 'l7-protocols' ... no idea what it is ...
(OSI model) Layer 7 (=application layer) protocol descriptions
Layer 2 = data link layer = Ethernet
Layer 3 = network layer = IP
Layer 4 = transport layer = TCP and UDP
Layer 5 (Internet model) = Layer 7 (OSI Model) = application layer = http, smtp, ...
> I see l7-protocols is created in patch-o-matic, but I'm not sure what
> package(s) use it. Is it something that can be moved too? It's
> currently the largest subdirectory under /etc (about 1MB).
I guess it's used by iptables or some other support tool. I have to admit I did
never use it before. I usually delete those subdirectories which I don't need.
I personally would like to see the following subdirectories of /etc/ moved to
/config/etc-PACKAGE.tar.bz2 or so:
* apache2
* curl
* apcupsd
* awstats
* eagle-usb
* ha.d
* joe/{syntax,doc} (317k)
* l7-protocols (993k)
* lpd
* mgetty+sendfax
* openldap (224k)
* pcmcia (225k)
* postfix (241k)
* ppp
* raddb (305k)
* sarg (101k)
* shorewall (197k)
* snort (689k)
* socks
* ups
* wlan
* zebra
Total of the above is 4.3 MB of 7.0 MB for the whole etc.tar.bz2. So on a very
basic system my config would shrink by more than 50% compared to now.
--
MfG / Regards
Friedrich Lobenstock
____________________________________________________________________
Friedrich Lobenstock Linux Services Lobenstock
URL: http://www.lsl.at/ Email: fl...@fl...
____________________________________________________________________
|
|
From: Heiko Z. <he...@zu...> - 2006-06-08 20:20:03
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I agree that we have to do something about the size of /etc. It eats up a lot of RAM and also makes it harder to fit the config on a floppy. But whatever you do, keep it simple for the user. We can't make them jump through hoops. - -- Regards Heiko Zuerker http://www.devil-linux.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iEYEARECAAYFAkSIhmMACgkQUcytMSbs+YWTaACdGX6zCfisOHu5LajU79m64/lg n7oAnipVA1qn9BUcECjQzpNEQgaPzMW4 =Zoeg -----END PGP SIGNATURE----- |
|
From: Bruce S. <bw...@ar...> - 2006-06-08 20:24:12
|
> I agree that we have to do something about the size of /etc. It eats up a > lot of RAM and also makes it harder to fit the config on a floppy. > But whatever you do, keep it simple for the user. We can't make them jump > through hoops. How about my idea of creating a new 'setup' menu, with selections to unpack each individual package's etc files? We should also limit it to fairly advanced (requires manual configuration), or obscure packages, so it won't effect our less-technical users. - BS |
|
From: Heiko Z. <he...@zu...> - 2006-06-08 20:31:46
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Thu, June 8, 2006 15:24, Bruce Smith wrote: >> I agree that we have to do something about the size of /etc. It eats up >> a lot of RAM and also makes it harder to fit the config on a floppy. But >> whatever you do, keep it simple for the user. We can't make them jump >> through hoops. > > How about my idea of creating a new 'setup' menu, with selections > to unpack each individual package's etc files? > > We should also limit it to fairly advanced (requires manual > configuration), or obscure packages, so it won't effect our less-technical > users. Actually I would prefer a combination of your and Friedl's suggestions. If we add a function which unpacks the config, we can add this to the init scripts to avoid problems when a program gets started. Additionally it make it really easy then, to just call the same function from the setup program. - -- Regards Heiko Zuerker http://www.devil-linux.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iEYEARECAAYFAkSIiRwACgkQUcytMSbs+YW+0ACfZ91wXsUnRyCxW+RJysUWSZNH b3wAn0L/PhIY6/9ey104W6avFuaR6rvf =sSYR -----END PGP SIGNATURE----- |
|
From: Bruce S. <bw...@ar...> - 2006-06-08 20:41:11
|
> >> I agree that we have to do something about the size of /etc. It eats up > >> a lot of RAM and also makes it harder to fit the config on a floppy. But > >> whatever you do, keep it simple for the user. We can't make them jump > >> through hoops. > > > > How about my idea of creating a new 'setup' menu, with selections > > to unpack each individual package's etc files? > > > > We should also limit it to fairly advanced (requires manual > > configuration), or obscure packages, so it won't effect our less-technical > > users. > > Actually I would prefer a combination of your and Friedl's suggestions. > If we add a function which unpacks the config, we can add this to the init > scripts to avoid problems when a program gets started. I was thinking that the files need to be unpacked and customized BEFORE the init script is run. In most cases anyway. But I supposed there are some packages that will run with stock/unmodified configs. I also like your idea of moving the l7 stuff to the CD and sym-linking it from /etc. I don't think they need to be modified by the user... ? > Additionally it make it really easy then, to just call the same function > from the setup program. Yup. - BS |
|
From: Friedrich L. <fl...@fl...> - 2006-06-08 20:49:04
|
Bruce Smith wrote on 08.06.2006 22:41 MET: >>>>I agree that we have to do something about the size of /etc. It eats up >>>>a lot of RAM and also makes it harder to fit the config on a floppy. But >>>>whatever you do, keep it simple for the user. We can't make them jump >>>>through hoops. >>> >>>How about my idea of creating a new 'setup' menu, with selections >>>to unpack each individual package's etc files? >>> >>>We should also limit it to fairly advanced (requires manual >>>configuration), or obscure packages, so it won't effect our less-technical >>>users. >> >>Actually I would prefer a combination of your and Friedl's suggestions. >>If we add a function which unpacks the config, we can add this to the init >>scripts to avoid problems when a program gets started. > > > I was thinking that the files need to be unpacked and customized BEFORE > the init script is run. In most cases anyway. But I supposed there are > some packages that will run with stock/unmodified configs. > > I also like your idea of moving the l7 stuff to the CD and sym-linking > it from /etc. I don't think they need to be modified by the user... ? The user can even set the location to something different from /etc/l7-protocols: <http://l7-filter.sourceforge.net/L7-HOWTO-Netfilter#conform> If possible I'd suggest configuring the default protocols dir to be something like /usr/lib/l7-protocols. Anyway if a user wants to use his own protocol files he can specify the new directory as show on the page referenced above, -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Bruce S. <bw...@ar...> - 2006-06-08 20:56:13
|
> > I also like your idea of moving the l7 stuff to the CD and sym-linking > > it from /etc. I don't think they need to be modified by the user... ? > > The user can even set the location to something different from /etc/l7-protocols: > <http://l7-filter.sourceforge.net/L7-HOWTO-Netfilter#conform> Doesn't that say you have to specify the directory on every 'iptables' command if you use a different directory? That sounds like a pain. I'd put a symlink in /etc for people who use the standard patterns, unless the default location can be specified during the compile. > If possible I'd suggest configuring the default protocols dir to be something > like /usr/lib/l7-protocols. Anyway if a user wants to use his own protocol files > he can specify the new directory as show on the page referenced above, - BS |
|
From: Friedrich L. <fl...@fl...> - 2006-06-08 21:14:15
|
Bruce Smith wrote on 08.06.2006 22:56 MET: >>>I also like your idea of moving the l7 stuff to the CD and sym-linking >>>it from /etc. I don't think they need to be modified by the user... ? >> >>The user can even set the location to something different from /etc/l7-protocols: >> <http://l7-filter.sourceforge.net/L7-HOWTO-Netfilter#conform> > > > Doesn't that say you have to specify the directory on every 'iptables' > command if you use a different directory? That sounds like a pain. L7="-m layer7 --l7dir /usr/lib/l7-protocols" But I won't argue over it ;-) > I'd put a symlink in /etc for people who use the standard patterns, > unless the default location can be specified during the compile. Probably right. >>If possible I'd suggest configuring the default protocols dir to be something >>like /usr/lib/l7-protocols. Anyway if a user wants to use his own protocol files >>he can specify the new directory as show on the page referenced above, -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Bruce S. <bw...@ar...> - 2006-06-08 20:21:16
|
> > Looking at the disk usage on /etc now, I see two other large directories
> > that have potential for moving their /etc files to /config/*.tar.gz.
> > One is snort. The other is 'l7-protocols' ... no idea what it is ...
>
> (OSI model) Layer 7 (=application layer) protocol descriptions
Yeah, I guessed that much. :-)
What I meant was I have no idea what uses it, or what bad things will
happen if it's not there.
> > I see l7-protocols is created in patch-o-matic, but I'm not sure what
> > package(s) use it. Is it something that can be moved too? It's
> > currently the largest subdirectory under /etc (about 1MB).
>
> I guess it's used by iptables or some other support tool. I have to admit I did
> never use it before. I usually delete those subdirectories which I don't need.
I also guessed that it might be used by some iptables module that does
l7 filtering.
It's be good to know for sure what uses it to make sure we don't break
something (like our stock firewall scripts) before we move it.
> I personally would like to see the following subdirectories of /etc/ moved to
> /config/etc-PACKAGE.tar.bz2 or so:
> * apache2
> * curl
> * apcupsd
> * awstats
> * eagle-usb
> * ha.d
> * joe/{syntax,doc} (317k)
> * l7-protocols (993k)
> * lpd
> * mgetty+sendfax
> * openldap (224k)
> * pcmcia (225k)
> * postfix (241k)
> * ppp
> * raddb (305k)
> * sarg (101k)
> * shorewall (197k)
> * snort (689k)
> * socks
> * ups
> * wlan
> * zebra
>
> Total of the above is 4.3 MB of 7.0 MB for the whole etc.tar.bz2. So on a very
> basic system my config would shrink by more than 50% compared to now.
Sounds good to me.
One other thought... We also need to modify the upgrade script (to a
new DL version) so updates to files in those optional directories will
also get applied. I think that can be done without too much hassle.
- BS
|
|
From: Heiko Z. <he...@zu...> - 2006-06-08 20:30:20
|
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Thu, June 8, 2006 15:21, Bruce Smith wrote:
>>> Looking at the disk usage on /etc now, I see two other large
>>> directories that have potential for moving their /etc files to
>>> /config/*.tar.gz.
>>> One is snort. The other is 'l7-protocols' ... no idea what it is ...
>>>
>>
>> (OSI model) Layer 7 (=application layer) protocol descriptions
>>
>
> Yeah, I guessed that much. :-)
>
>
> What I meant was I have no idea what uses it, or what bad things will
> happen if it's not there.
>
>>> I see l7-protocols is created in patch-o-matic, but I'm not sure what
>>> package(s) use it. Is it something that can be moved too? It's
>>> currently the largest subdirectory under /etc (about 1MB).
>>
>> I guess it's used by iptables or some other support tool. I have to
>> admit I did never use it before. I usually delete those subdirectories
>> which I don't need.
>
> I also guessed that it might be used by some iptables module that does
> l7 filtering.
>
> It's be good to know for sure what uses it to make sure we don't break
> something (like our stock firewall scripts) before we move it.
Yes it's for the l7 netfilter module.
As long as people don't load it, they don't need it.
What about moving the l7 stuff to a directory in the CD ? I don't think we
need write access for that.
>> I personally would like to see the following subdirectories of /etc/
>> moved to /config/etc-PACKAGE.tar.bz2 or so:
>> * apache2
>> * curl
>> * apcupsd
>> * awstats
>> * eagle-usb
>> * ha.d
>> * joe/{syntax,doc} (317k)
>> * l7-protocols (993k)
>> * lpd
>> * mgetty+sendfax
>> * openldap (224k)
>> * pcmcia (225k)
>> * postfix (241k)
>> * ppp
>> * raddb (305k)
>> * sarg (101k)
>> * shorewall (197k)
>> * snort (689k)
>> * socks
>> * ups
>> * wlan
>> * zebra
>>
>>
>> Total of the above is 4.3 MB of 7.0 MB for the whole etc.tar.bz2. So on
>> a very basic system my config would shrink by more than 50% compared to
>> now.
>
> Sounds good to me.
>
>
> One other thought... We also need to modify the upgrade script (to a
> new DL version) so updates to files in those optional directories will also
> get applied. I think that can be done without too much hassle.
May be worth it.
- --
Regards
Heiko Zuerker
http://www.devil-linux.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)
iEYEARECAAYFAkSIiLwACgkQUcytMSbs+YVrSACfUTAmESHL3ZIog+lAKQ43wbMt
aS0Anjy4Ay2jvzIGuaBCH4Ms/lOSpC9q
=MJIM
-----END PGP SIGNATURE-----
|
|
From: Heiko Z. <he...@zu...> - 2006-06-09 01:59:47
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Can we hold off these changes until 1.2.10 is out? I really want to release it soon, but this time thing... - -- Regards Heiko Zuerker http://www.devil-linux.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iEYEARECAAYFAkSI1ggACgkQUcytMSbs+YWPjgCeKAt1nQxUYJUy8XC5AGgFGXQg m0IAoIMekgYUaY6iAMWjPSiv2gatw4jD =tpg8 -----END PGP SIGNATURE----- |
|
From: Bruce S. <bw...@ar...> - 2006-06-09 12:11:39
|
> Can we hold off these changes until 1.2.10 is out? Sure. For now, shall I just tar up the dansguardian /etc files and stick them on the CD for people to manually install? - BS |
|
From: Heiko Z. <he...@zu...> - 2006-06-09 13:38:46
|
On Fri, June 9, 2006 07:11, Bruce Smith wrote: >> Can we hold off these changes until 1.2.10 is out? >> > > Sure. > > > For now, shall I just tar up the dansguardian /etc files and stick them > on the CD for people to manually install? Probably best. -- Regards Heiko Zuerker http://www.devil-linux.org |