IRC log of #maemo for Sunday, 2013-06-02

DocScrutinizer05please check
Win7Macthat site seems good, the text in your post seems a bit out of place01:28
Win7Mactakes quite a while to load01:28
bef0rdI don't see the create new thread01:33
DocScrutinizer05yes, www seems pretty slow01:36
DocScrutinizer05bef0rd: can you reply?01:36
bef0rdThere is a reply text with an envelope image, but its not clickable01:37
bef0rdi'm logged in01:37
DocScrutinizer05somebody at some point in time seriously ... "ignored" any handling of user permissions on particular objects in midgard01:49
DocScrutinizer05which resulted in that unspeakable vulnerability and by fixing that removed the means by which normal users e.g. could open new threads or answer on existing threads in
bef0rdwhat unspeakable vuln?01:51
DocScrutinizer05every user was allowed to edit or even delete any arbitrary object01:51
DocScrutinizer05incl whole repositories01:52
bef0rdah, who noticed it?01:52
DocScrutinizer05I never would have, since I'm admin on midgard and thus am supposed to have those permissions01:53
bef0rdI never login into midgard, just tmo01:54
DocScrutinizer05that's also why I'm still able to open a new thread on
DocScrutinizer05errr wait!!!! you were not logged in to (midgard) when you checked if you could answer my thread or create a new one?01:57
bef0rdno, I am, but normally I'm not logged in01:58
Win7Macon forum page there is no button, in post there is reply, but unclickable01:59
DocScrutinizer05yes, I got that01:59
Win7Macno matter logged in or not02:00
DocScrutinizer05which is what you'd expect to see for visitors that are not authenticated to midgard/maemo.org02:00
Win7Maci didn't check reply while not logged in though02:01
Win7Macno logout, ya know02:02
DocScrutinizer05could you check and my thread again?02:04
DocScrutinizer05I chenged some permissions, though I doubt it's possible to set them right02:05
Win7Macworks. Great, well done!02:07
DocScrutinizer05please create another screenshot for me, if possible with any menus opened to show what they contain02:08
DocScrutinizer05but I'm interested the most if you get a way to create new thready on now02:13
Win7MacI prefer thready ;-)02:13
Win7Macsorry, I can't02:14
DocScrutinizer05the main issue seems to be that somebody ... "ignored" that normal users don't (or shouldn't) see a midgard toolbar02:14
Win7Macsomebody 'forgot' on purpose?02:16
DocScrutinizer05most likely not on purpose02:17
DocScrutinizer05also the "no logout2 problem02:18
DocScrutinizer05same root02:18
DocScrutinizer05logout is in midgard toolbar02:18
Win7Macyou know I don't have that bar right?02:19
DocScrutinizer05that's the problem02:19
DocScrutinizer05it's unclear if users are supposed to have it but not all options enabled, or they shouldn't see it at all02:19
*** bef0rd has joined #maemo02:19
bef0rdi see the reply option but still can't see the create new thread02:20
DocScrutinizer05anyway the aforementioned vulnerability been that all users had that toolbar and it had menu entries to delete object, on repos, packages, posts, everything02:20
DocScrutinizer05as a first stopgap measure, Rambo removed permission for midgard menu from group "all users imported from garage"02:21
Win7Machide the unwanted options?02:21
DocScrutinizer05I dunno if that worked like that before02:22
bef0rdi remember the toolbar, can't see it now though02:22
DocScrutinizer05anyway we're not able to enable the menubar for above quoted usergroup now, since those are >>1000 users and midgard admin GUI blows chunks on editing the permissions for those02:23
DocScrutinizer05Rambo removed it via hacking the midgard mysql tables02:23
DocScrutinizer05via SQL02:23
DocScrutinizer05we're between a rock and a hard place now02:24
Win7Macif smth gets deleted it can't be undone?02:25
bef0rdi suppose there are no plans to move from midgard at the moment02:25
DocScrutinizer05no such plans02:27
DocScrutinizer05to put it simple (though useless info): never loads02:27
DocScrutinizer05resp loads a blank page02:27
DocScrutinizer05since it tries to build a list of all users belonging to that usergroup02:28
DocScrutinizer05and that makes midgard/asgard explode02:28
Win7Mac^^ I get "Login02:29
Win7MacAccess denied: You need the privilege midcom.admin.user:access."02:29
DocScrutinizer05above group is "All users imported from"02:29
DocScrutinizer05sure, since you're no admin. that's why I said it's useless info for you02:29
Win7Macbut it doesn't load a blank page or never loads at all...02:31
DocScrutinizer05sure, since you're no admin. that's why I said it's useless info for you02:32
Win7Maci finally even got it already by now... ;-)02:33
Win7Macso a usergroup has to be manually setup?02:37
DocScrutinizer05 is what I should get, and "Enable centralized toolbar" is what I'd need to set to "allow"02:38
Win7Macoh BTW, no idea if means anything, but woody mentioned that karma should work again by monday02:38
DocScrutinizer05"Enable centralized toolbar" is what Rambo set to "Deny" for "All users imported from" and that made midgard toolbar vanish02:40
DocScrutinizer05as you can see, the stupid page tries to load all users belonging to a group, and for "All users imported from" the number of records makes the page never load02:41
Win7Maccan't you set up new user group and re-import from garage?02:45
Win7Mac*as group owner02:46
DocScrutinizer05this particular usergroup is a special customization using unix passwd authentication instead of midgard user table in db02:46
DocScrutinizer05nfc how to create such a usergroup02:46
DocScrutinizer05thus "imported from garage"02:47
Win7Macfrom your screenshot... "owner group"... "Group hierarchie imported from garage..." is that some kind of commend or just a comment?02:50
DocScrutinizer05it's still completely non-understood why regular users had the "delete" menu enabled in midgard toolbar02:50
DocScrutinizer05seems it's the name of this group02:51
DocScrutinizer05no idea02:51
DocScrutinizer05the footer is awesome too: >>GUID: 0748dfa0638f11e1a42b472f08bfb405b405, ID: 7568. Created by test admin on Thu Mar 1 11:09:35 2012 <<02:53
DocScrutinizer05first name "test", last name "admin"02:53
Win7Macsurely a pro...02:53
Win7Macare you into what woody meant when he said karma should work by monday?02:55
DocScrutinizer05not exactly02:56
Win7Macprobably check with him if it's any midgard related02:56
DocScrutinizer05meh, we check with each other each day03:05
DocScrutinizer05I know about woody's karma work03:05
DocScrutinizer05and yes, it's faintly midgard related as well, but absolutely not user/group permissions related03:06
Win7Macmy best shot would be to establish new user group and try to re-link that to garage. or would that be overkill again?03:15
DocScrutinizer05again, I have no idea how that special custom made usergroup gets implemented in midgard03:25
DocScrutinizer05definitely NOT via midgard admin GUI03:26
DocScrutinizer05but maybe you gave me another funny idea03:26
DocScrutinizer05I could replace /etc/passwd and /etc/groups with files that don't have 60k users in them. This might the midgard admin page to open for editing the group03:27
DocScrutinizer05s/might the/might allow the/03:28
infobotDocScrutinizer05 meant: I could replace /etc/passwd and /etc/groups with files that don't have 60k users in them. This might allow the midgard admin page to open for editing the group03:28
Win7Macwell, how can it be done at all, if NOT via midgard admin GUI?03:30
DocScrutinizer05might make explode into my face03:30
DocScrutinizer05as mentioned above, Eero did it via direct mySQL command to tweak the midgard database03:31
DocScrutinizer05nobody on this planet except him and maybe max half a dozen other Nemein employees has the knowledge to do so03:32
Win7Macthat really sucks03:33
Win7Macand there is no pre-migration backup?03:34
Win7Macoh, just hit "report this"... button or mouse-over is not there, but link seems to work03:38
Win7Mac* here:
*** discopig has joined #maemo07:06
*** discopig has quit IRC07:06
*** discopig has joined #maemo07:06
*** _rd has quit IRC10:35
*** zammy has joined #maemo10:43
*** OkropNick has joined #maemo10:43
*** zammy has quit IRC10:44
*** zammy has joined #maemo10:46
*** _rd has joined #maemo11:02
*** Pali has joined #maemo11:13
lowkyalurgood morning12:09
*** CaCO3 has joined #maemo14:18
*** CaCO3 has joined #maemo16:07
*** Win7Mac has joined #maemo16:11
Win7Macwas just about to report that m.o is extreeemly slow, but right now it's very snappy again16:17
DocScrutinizer05yeah, it's quite changing. Nagios already tagged the www port80 service as "CRITICAL flapping"16:23
DocScrutinizer05ganglia even had a stall for quite a time, until I restarted it16:25
DocScrutinizer05strange enough load is pretty low, but general traffic on whole system is really high16:25
DocScrutinizer05or rather been16:26
Win7Macwhat's the difference in load/general traffic?16:26
DocScrutinizer05the (probably mirroring) attacker anyway seems has finished his maxing out of upling some 10min ago16:26
DocScrutinizer05load is CPU, traffic is tcp16:27
DocScrutinizer05simplified explanation16:27
DocScrutinizer05THEHECK! ganglia on www down again16:28
DocScrutinizer05monitor.m.o if you're interested16:29
Win7Macthat guy uploadedß16:32
*** piggz has joined #maemo16:38
DocScrutinizer05well, no. MRTG shows that uplink just sent to internet with 100Mbps16:38
DocScrutinizer05but that seems not the root cause of www lags, nor of ganglia daemon lockups16:39
DocScrutinizer05http: //monitor . maemo . org/ganglia/?r=4hr&cs=&ce=&c=maemo&h=www&tab=m&vn=&mc=2&z=medium&metric_group=ALLGROUPS   actually Network on www been pretty low16:41
Win7Macphew... no idea16:47
DocScrutinizer05xes tuned www apache parameters quite a bit during last 2 days, since on friday the poor VM been really crying16:48
DocScrutinizer05OOM kicked processes like mad, due to apached processes hogging all RAM16:49
DocScrutinizer05so we reduced resources allocated to apache _drastically_ which seems to have helped cure the RAM hogging ( ) but also seems to have reduced the responsiveness way more than we expected16:50
Win7Macprobably tweak the values again less conservative? Hopefully somebody with better knowledge can help.16:55
DocScrutinizer05we still see those bursts every morning 6:00
DocScrutinizer05but those might be our well-hated cronjobs, we will give more resources to apache nevertheless16:58
DocScrutinizer05our approach been to cut down resources for apache radically and observe for the weekend, then evaluate and re-adjust based on our findings16:59
DocScrutinizer05great, I'm an idiot posting the ganglia URLs here17:02
DocScrutinizer05((Hopefully somebody with better knowledge can help.)) I think our knowledge is sufficient, it's just our historical data that's sparse, to base the optimal settings for apache on17:10
DocScrutinizer05another 32GB of RAM would do wonders I bet17:11
DocScrutinizer05a 64GB ram total for THREE blades would be a dream17:14
DocScrutinizer05and another 2TB storage on skeiron also could help take out some pressure17:16
Win7Macanother 32GB of RAM - how much $ would that be?17:16
* DocScrutinizer05 knew this question would come up17:16
Win7Maccan we afford it with some donations?17:17
DocScrutinizer05a few hundred17:17
DocScrutinizer05I can't find the invoice/specs-sheet/order for the supermicro right now17:18
RaimuThank god RAM is pretty cheap per GB these days.17:18
rikaneeRaimu: it's probably 32GB of ECC RAM17:19
DocScrutinizer05yep, not that expensive17:19
rikaneeDocScrutinizer05: how many GB per DIMM needed to get 32GB on the server?17:19
rikanee4GB RDIMM is peanuts17:20
DocScrutinizer05> >2. Up to 256GB DDR3 1600MHz ECC    Registered DIMM; 8x DIMM sockets<<17:20
rikaneehow many of them are populated?17:21
DocScrutinizer05err, one or two17:21
DocScrutinizer05that's the problem, per blade we have two slots iirc17:21
DocScrutinizer05err nope17:22
DocScrutinizer05each such blade consist of two systems17:23
rikaneeDocScrutinizer05: interesting, that's a two-node blade?17:23
DocScrutinizer05we got 4 blades = 8 potential systems, of which two (blade-a, blade-b) are populated17:23
rikaneeI thought it was a dual-socket node.17:23
DocScrutinizer05rikanee: yes17:23
DocScrutinizer05well, I thought we have two separate systems on each blade. Might however also be dual-socket system per blade17:24
rikaneeDocScrutinizer05: so each node has 2x2GB DDR3 RDIMM?17:25
*** shamus has quit IRC17:25
DocScrutinizer05ugh? no17:25
DocScrutinizer05each blade has 32GB17:25
DocScrutinizer05I *think* in 2 SIMM a 16GB17:26
rikaneeah, so 2x8GB per node, making 32GB/blade.17:26
rikanee1x16GB per node x2?17:27
DocScrutinizer05we have one processor and 2*16GB, on two physical blades17:27
rikanee16GB DIMMs are /expensive/17:27
DocScrutinizer05toldya, a frw hundred17:27
rikanee(to match them for dual-channel operation, of course)17:28
*** piggz has joined #maemo17:28
Win7Macfrom specs: "Support ECC and non-ECC UDIMMs"17:29
*** Jooles_ has joined #maemo17:29
rikaneeWin7Mac: running UDIMM on a server is a no-no17:30
Win7Macah ok17:31
DocScrutinizer05  <- server component list17:37
DocScrutinizer05so 8 * 8GB17:38
DocScrutinizer054 per blade17:38
GeneralAntillesDocScrutinizer05, should I do a Twitter plug? "A new blade for was discussed in the last council meeting, hit DocScrutinizer's PayPal if you'd like to help out." Or something <140 chars.17:40
DocScrutinizer05GeneralAntilles: I wouldn't mind, though I honestly think HiFo shall pay it, they already gathered >4000bucks17:42
DocScrutinizer05the birdseed for populating a third blade is ~1000EUR IIRC17:42
DocScrutinizer05plus HDD?17:42
GeneralAntillesFor replenishing the 4k, then.17:43
*** Martix has joined #maemo17:43
DocScrutinizer05you're free to amazon/ebay/google the components according to
DocScrutinizer058x 240-pin DDR3 DIMM sockets17:44
Win7Macso RAM can't be added but has to be replaced by 16GB modules because all slots already in use?17:44
DocScrutinizer05Supports up to 256 GB DDR3 ECC Registered memory (RDIMM)17:44
DocScrutinizer05Supports up to 64 GB DDR3 ECC/non-ECC Un-Buffered memory (UDIMM)17:44
DocScrutinizer05Win7Mac: still to be evaluated17:44
rikaneeDocScrutinizer05: you'll have to make sure timing/latency and ranking is the same too17:45
DocScrutinizer05having only one CPU populated might restrict DIMM slot usage to 4 of the 817:45
DocScrutinizer05rikanee: there's a comprehensive memory population guide in the blades' UM17:46
DocScrutinizer05I'm just too lazy to read it right now17:46
DocScrutinizer05rikanee: anyway, you're absolutely right17:47
DocScrutinizer05PC3-12800R CL1117:48
Win7Macin order to add RAM we'd have to know what exactly is place now, maker/model17:49
DocScrutinizer05no idea about the brand17:49
*** valerius has joined #maemo17:50
DocScrutinizer05I don't think that's generally true, just for same bank17:50
*** Martix has quit IRC17:50
rikaneeDocScrutinizer05: apparently, the Xeon E5 can't do PC3-12800 on factory dividers, so you can save some cash by buying PC3-10600 instead17:50
DocScrutinizer05or channel, or whatever17:50
DocScrutinizer05rikanee: I'd like to go with
RaimuOh, supermicro17:53
RaimuTakes me back17:53
Win7Macso there should be 4 slots available17:54
Win7Macin case they match17:59
DocScrutinizer05hmm yup, ~300bucks per 32GB sounds correct18:04
DocScrutinizer05((so there should be 4 slots available)) still unclear, might need a 2nd CPU on the blade to use them18:05
DocScrutinizer05but yes, 4 are free18:05
DocScrutinizer054 are used by 4 * 8GB18:05
DocScrutinizer05supermicro certifies for hynix, samsung, and micron:
Win7Macfor 4GB modules:
Win7Macif you're lucky it's the samsungs:
DocScrutinizer05nope, those:
Win7Macsure? they are Low Voltage only18:16
Win7Macgooood ;-)18:16
DocScrutinizer05we need18:17
DocScrutinizer05populated with K4B2G0446D-HCK018:18
DocScrutinizer05or M393B2G70BH0-CK0 16GB modules ;-)18:19
DocScrutinizer05"yeah" wasn't "yeah, i'm sure" but "yeah, you're right, those are low voltage and probably the wrong ones"18:20
DocScrutinizer05usually that's given18:22
fastlane`but when they change nick they get unignored,18:39
fastlane`on xchat that is18:39
DocScrutinizer05well, that's irc18:39
fastlane`can i ignore on ident18:40
fastlane`or ip18:40
DocScrutinizer05wildcard allowed18:40
*** sixwheeledbeast has joined #maemo18:41
DocScrutinizer05ignore DocScrutinizer*, or *!joerg_rw@*, or *!*@openmoko/*18:41
DocScrutinizer05/hois DocScrutinizer0518:42
DocScrutinizer05/whois DocScrutinizer0518:42
fastlane`why r 2 of you here18:42
fastlane`05 and 5118:42
fastlane`other is some bot of yours?18:42
DocScrutinizer05because I have up to 5 clients running, one of them _not_ via a bouncer18:43
DocScrutinizer05since, sometimes the bouncer (ZNC) also might get disconnected18:43
fastlane`i see18:44
fastlane`testing ..18:44
DocScrutinizer05GeneralAntilles: thanks20:03
Sc0rpiusI'm editing a post in TMO20:06
Sc0rpiusand the changes doesn't get saved?20:07
Sc0rpiusthe "Title" of the post specifically20:07
Sc0rpius <-- trying to change the verrsion number to 0.0.34 and I just can't :(20:09
*** piggz has joined #maemo21:02
*** _rd has joined #maemo21:05
Vibedamn my n900 screen got broken22:12
Vibemy fault..22:12
Vibewhere do you recommend to buy new one?22:12
*** _rd has joined #maemo22:13
kralorVibe: ebay? :P22:23
*** _rd has quit IRC22:29
*** _rd has joined #maemo22:29
*** piggz has joined #maemo22:53
*** piggz has quit IRC22:55
*** piggz has joined #maemo22:55
*** Win7Mac has quit IRC22:58
*** Win7Mac has joined #maemo22:59
DocScrutinizer05incredibly good offer23:03
DocScrutinizer05consider to get a new digitizer as well23:03
DocScrutinizer05aka touchpanel23:04
*** SmilyOrg has joined #maemo23:04
DocScrutinizer05wait, "Idealer Ersatz für jedes zerkratzte oder defekte Display"??? When that's the LCD then it hardly ever gets scratched23:05
DocScrutinizer05when it's the digitizer (which gets scratched) then it's probably not what's broken for you23:05
*** Smily has quit IRC23:07
DocScrutinizer05Vibe: rather consider this:
*** sunny_s has joined #maemo23:19
*** sixwheeledbeast has joined #maemo23:20
*** sixwheeledbeast^ has quit IRC23:27
