ssh no longer able to connect to older hosts

Fedora33 implements higher security standards, not only for server side, but even when it comes to client connections.

This includes more restrictive rules on accepted Ciphers, Kex (key exchange) algorithms, etc.

Unfortunately this leads to situation in which you can no longer connect to older hosts, like CentOS5, some switches, for example JunOS12.

If you start getting the similar SSH errors:

=================

debug1: send_pubkey_test: no mutual signature algorithm
debug1: kex: algorithm: (no match)
Unable to negotiate with xx.xx.xx.xx port 22: no matching key exchange method found. Their offer: diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1 

=================

 

What you can do is  slightly tune the openssh client requirements.
 
You can put this on your config. This exact config will cover all hosts which you connect to, but if you wish this only on specific machines, instead of the wildcard '*' put the name or the IP of your machines, separated by 'space'

In file: ~/.ssh/config

Add/Edit the following section

=================
Host *
        KexAlgorithms +diffie-hellman-group1-sha1
        Ciphers +aes256-cbc
        PubkeyAcceptedKeyTypes +ssh-rsa
=================
 
This will probably fix a lot of issues for you. 


git: error: gpg failed to sign the data

If you try to sign commit with git, and you get the following error:

====================== 

error: gpg failed to sign the data
fatal: failed to write commit object
======================
 
  1. Check your ~/.gitconfig file, which must include at least the following sections:
    [user]
    name = Your Name Here
    email = your@email.com
    #key ID coming from gpg --list-keys
    signingkey = AABBCCDDFF112233445566
    [commit]
    gpgsign = 1
    [gpg]
    #could be gpg or gpg2 or full path to them
    program = gpg2
     
  2. If above is fine, check if your GPG is working correctly on the following link:
 gpg or gpg2 gpg: signing failed: Inappropriate ioctl for device 

gpg or gpg2 gpg: signing failed: Inappropriate ioctl for device

 If you ever get the following error, while trying to sign with gpg:

gpg: signing failed: Inappropriate ioctl for device

try the following steps

Test if gpg is actually working:

======================

echo "test" | gpg2 --clearsign
======================
If you get error like this: 
 
====================== 
[root@localhost]# echo "test" | gpg2 --clearsign
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

test
gpg: signing failed: Inappropriate ioctl for device
gpg: [stdin]: clear-sign failed: Inappropriate ioctl for device 
======================
 

then try the following:

======================
[root@localhost]# export GPG_TTY=$(tty)
======================
 
If this fixes the problem, add it to your .bashrc or .bash_profile file 



growpart: no tools available to resize disk with 'gpt'

If you get the following message while trying to resize GPT partition:


[root@localhost ~]# growpart /dev/sda 1
no tools available to resize disk with 'gpt'
FAILED: failed to get a resizer for id ''
 
This is because you are missing the package: gdisk
 
Install it, and the problem is solved:
 
[root@localhost ~]# yum -y install gdisk
 
   

BlueGate sip GSM gateway - very bad choice

Some time ago, we bought new SIP GSM gateway for our PBX. The GSM gw is BlueGate sip GSM gateway, dual SIM (http://www.alphatechtechnologies.cz/en/products/gsm-gateways/voip-gsm-gateway-bluegate-sip/).

I read in the spec that it is coming with Siemens radio module and decided that the GW will be made with high quality in mind.

Unfortunately  this was not the case and we faced our firs issue.

The operators started complaining that they hear noise during call, and despite the fact that the signal to noise ratio is very good, the noise which is heard during call is too loud and very very annoying.

The noise is coming from the radio module and the producer of the GW confirmed it, but they said that they will not do anything about it. Here is their last answer from the communication with them:

Hello,
    I haven't good news. I got the BG SIP twin yesterday. I tested it with our specialist for analog signals. The moment BG SIP twin connect analog output from GSM modul we hear the noise from the GSM modul too. But we can't take out only noice incomming from GSM modul. I do nothing with it.


Until now we used Vierling GSM GW which was using ISDN to connect with PBX and we have had no problem with it, but I decided to switch to SIP and bought the crap described above.

The second issue we have had with this device, is that probably in 99% of the cases, it was not passing DTMF tones to the PBX.  We just did not get any DTMF and the clients which were calling us on these lines were not able to choose anything from the IVR menu.

Considering the issues with the noise, we did not even bothered to write again to their support, because we already knew that this device is dead for us.

As a conclusion: DO NOT buy BlueGate SIP GSM gateway from http://www.alphatechtechnologies.cz. They suck.

Now we have direct land line SIP trunk with the mobile operator, and all is just fine.

How to apply OTA update or UNROOT rooted nexus 5 without loosing user data.

These days I got notification from my phone (Nexus5 with android 5.0) that I have update to android 5.0.1.

The phone is rooted without modification of the boot partition. 

I tried to update, the phone rebooted and started the update process and after a few seconds it say ERROR, and stops.

It appears that the updater checks for modifications on  system partition and if some are found, the update is stopped.

Here is how I managed to update, without flashing all back to stock and suffering the pain of reinstalling all my apps, loosing user data (if not backed up), loosing app states and so on, basically a lot of time can be lost.

The below instructions will probably work on all nexus devices with slight modifications.

All the commands which I am going to present you are tested on linux, but they should work on windows and mac too, as long as you have downloaded android SDK.
 
I assume that your bootloader is unlocked. If not, you can not do anything without wiping out the phone.

How to check if bootloader is locked, two ways:

1. When you power on the phone you see the GOOGLE logo. If the bootloader is unlocked you will see unlocked padlock below the google logo.
2. Switch OFF the phone, then hold for 5-6 seconds Volume Down + Power.

This will start the bootloader for you (one lying down android with open stomach :))
Below the android you will see some info, about your phone, bootloader version etc.
On the last line it says: "LOCK STATE - unlocked"  if bootloader is unlocked


1. Download android sdk. http://developer.android.com/sdk/index.html#Other

If you do not intend to develop, you DO NOT need the "android studio", just download 'SDK tool only"

2. If undr Linus/Mac, extract the contents of the package

3. Run android-sdk-linux/tools/android. This will start GUI which will let you choose which components to install

4. Choose "Android Platform SDK tools" and hit install

5. If all went fine, you will have folder android-sdk-linux/platform-tools/ which contains the tools you need.

6. Switch On "usb debugging" on your device.

7. When you connect the phone, try this simple command:

sudo  android-sdk-linux/platform-tools/adb shell

The phone will probably pop up a dialog, asking for confirmation to allow the connection from the computer.
Hit YES and the command you executed will be drop you in a shell on the phone.
If this happens then all is good, you can continue

8. Download the stock images for your current version of android:
https://developers.google.com/android/nexus/images

9. Extract the file, in my case (hammerhead-lrx21o-factory-01315e08.tgz). You will get ZIP file called hammerhead-lrx21o/image-hammerhead-lrx21o.zip

10. Extract it too and you will get the image files

cache.img              
boot.img               
recovery.img           
userdata.img           
system.img             

11. If you want to root your phone after the update, download also:
Chanfire installable ZIP: As of time of this writing, version 2.40 (http://download.chainfire.eu/641/SuperSU/UPDATE-SuperSU-v2.40.zip)

You can see which is the latest version here: http://forum.xda-developers.com/apps/supersu

12. Upload the file to your device, you can do this with the following command:

android-sdk-linux/platform-tools/adb push  UPDATE-SuperSU-v2.40.zip /sdcard/Downloads

This will place the file in your Download folder on the phone.

13. Download TWRP rescue image:
http://techerrata.com/browse/twrp2/hammerhead

14. Be very careful from now on :)

15. Go in to fastboot mode by doing either power off the phone, then hit volumedown + power for a few seconds, or if the phone is on, with the following command:

sudo android-sdk-linux/platform-tools/adb reboot bootloader

This is supposed to send you in bootloader.

15. Flash stock recovery image: (you should be in the dir where the extracted images are )

sudo android-sdk-linux/platform-tools/fastboot flash boot boot.img 

reboot bootloader again
sudo android-sdk-linux/platform-tools/fastboot reboot-bootloader

16. Flash recovery image to stock

sudo android-sdk-linux/platform-tools/fastboot flash recovery recovery.img

reboot bootloader again
sudo android-sdk-linux/platform-tools/fastboot reboot-bootloader

17.  Flash the system img

sudo android-sdk-linux/platform-tools/fastboot flash system system.img





18. Reboot the device.
In the bootloader, navigate with (volume +/-) and when it shows "REBOOT", hit power to confirm, this will reboot the phone and boot android. And you now have unrooted device.

19. Apply the update, either go to settings-> about -> check for updates.
If nothing is shown there you can wait for some time and the notification will pop up again. (there is a faster method for update, but I intentionally do not show it here)

20. When the update is applied, if you want to root again the device, do the following:

sudo  android-sdk-linux/platform-tools/adb reboot bootloader

21. Flash the recovery image with the twrp image which you downloaded earlier:

sudo android-sdk-linux/platform-tools/fastboot flash recovery openrecovery-twrp-2.8.2.0-hammerhead.img

22. Reboot bootloader

sudo android-sdk-linux/platform-tools/fastboot reboot-bootloader

23. With volume +/- navigate to menu "Recovery Mode"
24. You will see a interface with buttons.
25. Go to Install
26. Navigate to your download folder and select the file you uploaded there earlier. In current case this is UPDATE-SuperSU-v2.40.zip
27. At the bottom "Swipe to Confirm Flash"
28. If all went fine, your device is rooted at this step
29. Reboot the phone and enjoy your root.

How to concatenate files containing columns of data in Linux

Ever wondered how to concatenate text files containing columns next to each other ?

One little bash trick which can help you do this the easy way:

Assume you have for example three files containing something like this:

file1.txt

a    b    c

a    b    c

a    b    c

a    b    c

 

file2.txt

1    2    3

1    2    3

1    2    3

1    2    3

file3.txt

m    n    p

m    n    p

m    n    p

m    n    p

What we want to achieve is the following result:

a    b    c    1    2    3    m    n    p

a    b    c    1    2    3    m    n    p

a    b    c    1    2    3    m    n    p

a    b    c    1    2    3    m    n    p

You have two options

Option 1: Try to do it in bash and die in pain. This is usually not funny.

Option 2: The easy way, use the command "paste":

[user@host ~]$ paste file1.txt file2.txt file3.txt
a    b    c     1    2    3     m    n    p

a    b    c     1    2    3     m    n    p

a    b    c     1    2    3     m    n    p

a    b    c     1    2    3     m    n    p

 

The command paste will concatenate the files for you

The program have some cool options, like you can set separator, or use the -s option which will cause the following behavior "paste one file at a time instead of in parallel"

Here is an example with the same files:


[user@host ~]$ paste -s file1.txt file2.txt file3.txt

a    b    c             a    b    c             a    b    c             a    b    c

1    2    3            1    2    3             1    2    3             1    2    3

m    n    p          m    n    p            m    n    p            m    n    p

Each row, becomes a new column.

Have fun :)

Broadcom BCM 802.11 linux-sta driver compilation issues

I am using one lenovo netbook, which is coming with Broadcom wireless adapter.
Since I was having performance issues with the open source driver I started using the driver provided by Broadcom:

http://www.broadcom.com/support/802.11/linux_sta.php

On the newer kernel there are two compilation issues which need patching.

The patches provided below are for version 5.100.82.112 of the driver.

The first issue which I hit was the following error during compilation
/usr/src/linux-sta/src/wl/sys/wl_linux.c:396:2: error: unknown field ‘ndo_set_multicast_list’ specified in initializer
/usr/src/linux-sta/src/wl/sys/wl_linux.c:396:2: warning: initialization from incompatible pointer type [enabled by default]
/usr/src/linux-sta/src/wl/sys/wl_linux.c:396:2: warning: (near initialization for ‘wl_netdev_ops.ndo_validate_addr’) [enabled by default]
make[2]: *** [/usr/src/linux-sta/src/wl/sys/wl_linux.o] Error 1
make[1]: *** [_module_/usr/src/linux-sta] Error 2
make[1]: Leaving directory `/usr/src/kernels/3.4.0-1.fc17.i686'

The secon issue is the following error

/usr/src/linux-sta/src/wl/sys/wl_linux.c:43:24: fatal error: asm/system.h: No such file or directory

which is caused by dropping the header asm/system.h in kernel 3.4 in favor of 5 new headers.

More about this can be read here:

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=0195c002



Here is a patch witch fixes both of the issues.


You can download the patch from pastebin:

http://pastebin.com/C8TZ8q88

I am pasting the code in pastebin, because blogger.com has an "incredibly good" editor and I am fighting for half an hour to make it not hiding most of the source code and as you can see he wins :).

place this text in a file and save it

then go in the dirver directory in my case:

cd /usr/src/linux-sta/src/wl/sys/

and run the patch

patch -p0 < /path/where/the/you/saved/the/patchfile.patch

then try to compile as usual

cd /usr/src/linux-sta/
make clean
make install
depmod -a
modprobe wl

Errors when trying to compile tp_smapi on recent kernels (for me on Fedora 16)

Whoever from you who have a ThinkPad laptop and is using tp_smapi kernel module is probably having troubles compiling the module on recent kernels.

I especially experience problems compiling it on Fedora 16 kernel 3.2.7-1.fc16.i686 but as far as I can see, others people have the same issue on Fedora 15 and other distros too.

For the ones who does not know, this module is giving you an interface to the shock sensor which can be used from hdapsd to protect your HDD from shocks and also gives you some very cool features to control the charge/discharge of your battery and presents you some very useful information about the battery, which can be found in /proc and /sys

Now back to the problem.

When I try to compile the kernel module, version tp_smapi-0.40, I get the following error:


===================================================
make -C /lib/modules/3.2.7-1.fc16.i686/build M=/usr/src/tp_smapi-0.40 O=/lib/modules/3.2.7-1.fc16.i686/build modules
make[1]: Entering directory `/usr/src/kernels/3.2.7-1.fc16.i686'
  CC [M]  /usr/src/tp_smapi-0.40/thinkpad_ec.o
/usr/src/tp_smapi-0.40/thinkpad_ec.c:91:8: warning: type defaults to ‘int’ in declaration of ‘DECLARE_MUTEX’ [-Wimplicit-int]
/usr/src/tp_smapi-0.40/thinkpad_ec.c:91:1: warning: parameter names (without types) in function declaration [enabled by default]
/usr/src/tp_smapi-0.40/thinkpad_ec.c: In function ‘thinkpad_ec_lock’:
/usr/src/tp_smapi-0.40/thinkpad_ec.c:108:28: error: ‘thinkpad_ec_mutex’ undeclared (first use in this function)
/usr/src/tp_smapi-0.40/thinkpad_ec.c:108:28: note: each undeclared identifier is reported only once for each function it appears in
/usr/src/tp_smapi-0.40/thinkpad_ec.c: In function ‘thinkpad_ec_try_lock’:
/usr/src/tp_smapi-0.40/thinkpad_ec.c:122:23: error: ‘thinkpad_ec_mutex’ undeclared (first use in this function)
/usr/src/tp_smapi-0.40/thinkpad_ec.c: In function ‘thinkpad_ec_unlock’:
/usr/src/tp_smapi-0.40/thinkpad_ec.c:134:6: error: ‘thinkpad_ec_mutex’ undeclared (first use in this function)
/usr/src/tp_smapi-0.40/thinkpad_ec.c: At top level:
/usr/src/tp_smapi-0.40/thinkpad_ec.c:91:8: warning: ‘DECLARE_MUTEX’ declared ‘static’ but never defined [-Wunused-function]
/usr/src/tp_smapi-0.40/thinkpad_ec.c: In function ‘thinkpad_ec_try_lock’:
/usr/src/tp_smapi-0.40/thinkpad_ec.c:123:1: warning: control reaches end of non-void function [-Wreturn-type]
make[3]: *** [/usr/src/tp_smapi-0.40/thinkpad_ec.o] Error 1
make[2]: *** [_module_/usr/src/tp_smapi-0.40] Error 2
make[1]: *** [sub-make] Error 2
make[1]: Leaving directory `/usr/src/kernels/3.2.7-1.fc16.i686'
make: *** [modules] Error 2
===================================================

After some digging I found the solution in one forum thread, and the solution is:

Replace all the occurrences of DECLARE_MUTEX with DEFINE_SEMAPHORE, which, at the time I am writing this, are in files:

thinkpad_ec.c on line 91
tp_smapi.c on line 112

For those of you who want a patch:

------------- cut below this line -------------
--- thinkpad_ec.c.orig  2008-12-16 07:03:06.000000000 +0200
+++ thinkpad_ec.c       2012-03-04 22:58:10.409371153 +0200
@@ -88,7 +88,7 @@
 #define TPC_PREFETCH_JUNK   (INITIAL_JIFFIES+1)   /*   Ignore prefetch */
 
 /* Locking: */
-static DECLARE_MUTEX(thinkpad_ec_mutex);
+static DEFINE_SEMAPHORE(thinkpad_ec_mutex);
 
 /* Kludge in case the ACPI DSDT reserves the ports we need. */
 static int force_io;    /* Willing to do IO to ports we couldn't reserve? */
--- tp_smapi.c.orig     2008-12-16 07:03:06.000000000 +0200
+++ tp_smapi.c  2012-03-04 22:58:22.074334276 +0200
@@ -109,7 +109,7 @@
 #define SMAPI_PORT2 0x4F           /* fixed port, meaning unclear */
 static unsigned short smapi_port;  /* APM control port, normally 0xB2 */
 
-static DECLARE_MUTEX(smapi_mutex);
+static DEFINE_SEMAPHORE(smapi_mutex);
 
 /**
  * find_smapi_port - read SMAPI port from NVRAM
-------------- cut above this line ---------------

Get the text, place it in a file, save the file.
change the directory in the source dir:

cd tp_smapi-0.40

apply the patch

patch -p0 < /path/to/the/file/with/the/patch

you can try "make" now.

Load the module and happy shock protecting :)

Nvidia support sucks

I am using Linux for quite some time and my laptop has Nvidia video card.

All was working fine for some time, but approximately a year ago I started experiencing really weird video behavior when using NVidia driver and all was just fine with nouveau driver.

I tried to resolve my issue and posted a thread in http://forums.nvidia.com/ but I did not get any help, just some other guy was experiencing the same problem.

Then I tried the next logical thing, contact nvidia support directly.

I described my problem with explanation how to reproduce, but unfortunatelly they told me that were unable to reproduce and closed the tickets.

Some time after that I did really deep research about this issue and found other users experiencing the same behavior and I got some more additinal information about the case.

I opened another ticket with their support and it looks like the same guy tried to support me, but this time he really really made me mad with his answers.

here is the complete history


----------------------------------------------------------------------------------------------------------------
ticket opened on 05/13/2011 05:19 AM

Hello,

I have a thinkpad R61 with Quadro NVS 140M.
OS: Fedora 14
Kernel: 2.6.35.13-91.fc14.i686
NV Driver: 270.41.06

I am experiencing the following behavior:

After I install the nvidia driver I have really bad experience while switching between the apps. The worst speed comes when I try to switch back from some other app to Firefox with site open.
It draws the toolbar, menus, address bar and then sometimes it takes 2 secs to display the page pane.

The things are getting really ugly if I start Open Office Calc (spreadsheets), OpenOffice Draw and try to work with them. Even marking an area with the mouse in OpenOffice Draw is very slow.

The speed slows down with time and finally can drive you crazy.

This effect is temporarily cured if I "flush" Pixmap Cache with the following commands:

nvidia-settings -a PixmapCache=0
nvidia-settings -a PixmapCache=1


I dont have any of the above symptoms if I use nouveau, however I have other problems with this driver :).

The above happens with KDE and GNOME.

In the same time I have no problems watching video using VDPAU video output and decoding x264 encoded movie.

I read in the net that lots of users have similar problems and tried a LOT of things in order to prevent this behavior from happening and no luck:

Here is my device section in xorg.conf

=============================
Section "Device"
Identifier "Device0"
Driver "nvidia"
VendorName "NVIDIA Corporation"
Option "TripleBuffer" "false"
Option "BackingStore" "false"
Option "RenderAccel" "True"
Option "PixmapCacheSize" "2000000"
Option "OnDemandVBlankInterrupts" "True"
Option "AllowSHMPixmaps" "0"
Option "AllowIndirectPixmaps" "True"
Option "DamageEvents" "True"

EndSection
=============================

However with or without the additional directives, it does not make much difference.
The only thing that can almost normalize the things for some time are the above mentioned commands which disable and enable PixmapCache

Please help.
----------------------------------------------------------------------------------------------------------------

NVIDIA SUPPORT:  Response (Mike)     05/13/2011 02:05 PM

He even wrote my name wrong, but I can live with that.


Hi Devan,

Thank you for contacting NVIDIA Customer Care.

It appears that you contacted us already about this issue in December 2010 in support case id 101118-000139 which I handled.

Thank you for the new information that flushing the pixmap cache also temporarily works around the problem.

I reviewed the case notes from December and we could not identify or resolve the problem from your logs, and also I tried and could not reproduce the problem with a borrowed laptop with an NVS 140M.

Let me know if there is any additional information about the problem and I will help if I can, but based on the previous and current information unfortunately I could not help you.

Best regards,

Mike
NVIDIA Customer Care

----------------------------------------------------------------------------------------------------------------
Me. 05/14/2011 09:57 AM

Hello,

In order to reproduce the issue you really need some time of work on the laptop. You have to agree that the fact that you were unable to reproduce, does not mean that the problem does not exists. I tried different distributions and always get the same behavior and the only thing that fixes it, is switching to nouveau driver. This fact itself means a lot for me.

If you search in google for things like:
nvidia pixmap
nvidia kde slow

and some other similar phrases you will find really long threads (not only for problems with quadro NVS but others too) with many different supposed work arounds. Some threads are old some are new, they blame one thing or another, I have tried all the recommendations in these forums and did not find anything, that eliminates the problem.

If I send you a video file with the speed for simple things, but using different driver, is this going to convince you ?

----------------------------------------------------------------------------------------------------------------
NVIDIA SUPPORT 05/16/2011 10:55 AM

THE MOST IMPUDENT ANSWER EVER


Hi Deyan,

I am already convinced that you have a real problem!

The problem is, I can't solve your problem from information in the logs, and I can't solve it by watching a video of the problem.

The only way I can solve this problem is to reproduce it, which is why I borrowed the laptop with NVS 140M and did a lot of testing on it to try to reproduce the problem.

I want to help you but please understand my limitations, as I need relevant information in the log (which was not there) or a reproduction of the problem to help you. Or sometimes I can help if your problem is already known based on the symptoms but this is not the case.

Best regards,
Mike

----------------------------------------------------------------------------------------------------------------

ME: 05/18/2011 04:04 AM

Hello,

I am still willing to record a video, so you can see how I reproduce the problem and try to reproduce it for yourself.

I will submit you a video link shortly

I really want to use the nvidia driver.

----------------------------------------------------------------------------------------------------------------

NVIDIA SUPPORT 05/18/2011 09:08 AM

OK, I'll watch the video and see if there are steps to reproduce the problem that I missed when I tested this.

----------------------------------------------------------------------------------------------------------------
ME: 05/20/2011 12:20 AM

Hello,

I just uploaded the video to youtube.
It does not look very beautiful but you can see more details on full screen.

Here is a link to youtube:

http://www.youtube.com/watch?v=_xxxxxxxxx

If you want to take a look at the original uncompressed video,

Here is a link to it too:

http://xxxxxxxxx/xxxxxx.MOV



This was 1 month ago. No answer no nothing after that.

Here there are 2 possibilities:

1. The do know about the problem and now facing the fact that I have a video showing the problem, they just ignore me and no fix provided.
This behavior is BAD BAD BAD.

2. They do not care about my problem and just ignore me. It looks like NVIDIA support is so badly organized that their support department does not even have a supervisor who can monitor their support staff and trying to make them solve users problem.

Again: BAD BAD BAD

This is really annoying and I really hate the fucking video card now.

How to run cron jobs on even/odd days, minutes etc..

Ever wondered how to start a cron job on even/odd minute/day/hour ?

Here are some examples:

Example1: You want to run job on even/odd minute:

0-59/2 * * * * /path/to/evenjob.sh
1-59/2 * * * * /path/to/oddjob.sh

Example2: You want to run job in 10th minutie of every even/odd hour:

10 0-23/2 * * * /path/to/evenjob.sh
10 1-23/2 * * * /path/to/oddjob.sh

Example3: You want to run job at 5pm every even/odd date

0 17 2-31/2 * * /path/to/evenjob.sh
0 17 1-31/2 * * /path/to/oddjob.sh

If you dont clearly remember the positions of the minutes/hours/days you can find them in this man page:

man 5 crontab

here is a snippet from it:


field allowed values
minute 0-59
hour 0-23
day of month 1-31
month 1-12 (or names, see below)
day of week 0-7 (0 or 7 is Sun, or use names)

How to access IPv6 IP address from web browser

These days I am playing with IPv6 and tried to access few sites directly by IP address.

It looks like the browsers are trying to interpret the IPv6 address as name:port and the connection of course fail.

If you type directly in the browser, for example:

http://2a02:2e0:3fe:100::8

you will get error message.

If you want this to be interpreted as IPv6 address you will have to type the address like this:

http://[2a02:2e0:3fe:100::8]

I tested this on Linux with the following browsers:

Firefox
Opera
Google Chrome

CentOS 5 / RedHat Enterprise Linux (RHEL) 5 not IPv6 ready

These days I am trying to start using IPv6 on CentOS 5, but unfortunately I found that this distro is not exactly ready to run IPv6. What is the main problem for me: The kernel version coming with the distro is not, I repeat it is NOT, capable of doing connection tracking, which is very very bad.
We are being brought back in the days of kernel 2.2 and ipchains.
Probably some of you remember how crippled it was, compared to 2.4 and 2.6 + iptables.

Well it looks like the users of RHEL 5 are screwed (at least for now) even though they are paying.
In this bug report,

https://bugzilla.redhat.com/show_bug.cgi?id=243739

the RH developers basically say that backporting of xtables to kernel 2.6.18 is not possible, which sounds very bad for me. They can at least try to release a newer kernel version even though this is against the versioning policy accepted by RedHat, but you have to agree that this is too expensive distro and to not support IPv6.
They recommend building kernel from source with enabled IPv6 connection tracking features.
Come on guys what I am paying for, for building my custom kernels ?

Old but still good :): HDD performance degradation by screaming on the disk array

Hi,

This is old but very useful movie, which shows how the HDD performance degrades when there is a vibration.

Google datacenter tour

Hello guys,

I just found this cool video, which is basically a tour in one of Google's datacenters.

Allied Telesis (Allied Telesyn) green switches, really bad choice

Hi guys,

It has been awhile since my last post, but not because I have nothing to write about, its just I can go crazy while I am writing about the problem and kind of experiencing it again while writing :).

We are using Allied Telesys (Allied Telesyn) switches for some years now. Since we needed and still need only Layer 2 switches we decided to go with Allied Telesis AT-2000/24. Although this model has some really nasty things which annoy me (like 32bit counters on 1G interfaces, which is insane), they were working and doing their main purpose, switching and VLAN support.

However a new series were released, the green AT-9000/28 and AT-9000/52, this is basically 28/52 port Layer2, manageable, gigabit switch.

First we bought 28 port model, it is working, but after a couple of days working the switch os crashes and the switch becomes unmanageable, but still switching, they released a completely rewritten firmware these days, but I have not tested it yet, because they are not supporting backward compatibility of the config and I have the rewrite it manually again. Can you imagine how stupid is this?

The big problem comes with AT-9000/52. We bought 2 pieces, and I have a really hard time making them work with Cisco 76xx router.

The problem is that both of the switches simply refuse to accept ARP reply from the router.

I receive internet from ISP over a tagged VLAN 500. I connect one PC to AT-9000/52. The PC port is untagged member of VLAN500. With arping I am able to see the entire network, I get arp reply from any machine located no matter in which rack, however I am unable to receive arp reply from the ISP router (CISCO 76xx). The router can see my MAC address (which mean it can send arp request and get arp reply from me), but I can not receive the arp reply from the router no matter what I do. If I manually put the MAC address of the router in the ARP table of the PC, I have no problems communicating with it.

Here is what I tried to do in order to resolve the problem, but unfortunatelly without any luck.


1. I connected a PC directly on the cable which comes from the upstream switch, set up a tagged interface on the laptop, I can see the router without any glitches. However If I plug the cable in the switch AT9000/52 I just cant receive a single ARP reply from the router and router only, everything else in vlan 500 is visible (Linux machines).

2. I attached a different switch the same model AT9000/52, he acts exatly the same.

3. I have a switch AT9000/28 which is the same firmware version which is working without problem with the same config.


Considering the fact that the 28 port switch is working and 52 port switches are unable to work using the exactly same config, makes me think, that this is basically a hardware issue.

The Allied Telesis support is trying to reproduce the problem but they say that they are unable to reproduce and refuse to log in and take a look at my test environment, which really drives me crazy. Their inability to reproduce the problem in the lab does not mean that that the switch is working and this can not happen in my network.

I am waiting almost 6 months for any resolution, but honestly speaking I dont expect one. They just dont care.

Since I can not use this brand any more because it simply does not work I decided to switch to Juniper switches. I hope I will have less problem with them. The first disadvantage of the Juniper over the Allied Telesis is the price :).

Conclusion: Do not buy Allied Telesis AT-9000/52 green switches, they obviously dont work in all environments. This so basic feature of VLAN support is turned into a crap in this model and although, they improved the cli very much compared to the previous model, they crapped basic functionality. The switch totally sux and I really hate it.

UPDATE 16.06.2012: We are using Juniper EX2200 ever since and I want to say that I love them.
Very good switches and very good price per features ration. Cisco does not have such switch for this price, actually they do not have any switch with such features for the price of Juniper switches.

Supermicro with Tylersburg chipset, stupid IPMI behavior. - UPDATE1

Hi again.

Following my previous post regarding Supermicro with Tylersburg chipset, stupid IPMI behavior.

I just want to add that this behaviour is fixed on IPMI firmware level.
There is an check-box added in the Configuration -> LAN Select, where one can choose whether to use the dedicated IPMI LAN or On-Board LAN. However still a little crippled menu, because you can not choose which Onboard port to use.

Kaspersky support is real crap

We have in the office a pack of 10 licenses for Kaspersky Internet Security (KIS).

Since we suspect a serial number leak, we asked Kaspersky support to generate for us a new key and make the old one invalid. Guess what we are waiting 1 month already for answer, any answer.

The ticket is in status: "Waiting for reply from global support team"

I really hate such crappy support.

Conclusion: Kapspersky support sucks (sux )

CD/DVD tray LOCK/UNLOCK under Linux


LOCK/UNLOCK your CD/DVD under Linux

==== UPDATE ====

UPDATE: As you can see in the comments, one reader suggested using eject utility:

Lock the drive: eject -i 1
Unlock the drive: eject -i 0

The option was not available when coded the below program. 

This works perfectly for me.
==============


==== UPDATE ====
It looks like when the time passes by, the things get changed
The below program stopped working after some changes in udev rules.
In order to make it work again you have to grab control over your eject button from udevd

comment the following line:
ENV{DISK_EJECT_REQUEST}=="?*", RUN+="cdrom_id --eject-media $tempnode", GOTO="cdrom_end"
in /lib/udev/rules.d/60-cdrom_id.rules,
restart udev

voila, the program is working again.

============================

When I am home, my kid is playing with my laptop DVD and tries to grab the tray and take it away :).

As you can imagine I am not very happy with this and wanted to find a program to lock the tray but unfortunately did not find any usable.

I found one but it is for Windows, and it costs money. Come on guys you want 15 US$ for 10 rows of code. This is a robbery.

Besides that I am working under Linux and this programs is no good to me.

I am not a programmer but since I was unable to find a suitable program I wrote one.

It is tested under Linux (Fedora 11 if that matters at all).

How to compile:

gcc -o cd-dvd-lock cd-dvd-lock.c

Usage ./cd-dvd-lock lock|unlock

Depending on the parameter it either locks or unlock the tray.

Copy the source below and save it in file called cd-dvd-lock.c



------------ COPY BELOW THIS LINE------------

/*
* cd-dvd-lock.c
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License version 2 as
* published by the Free Software Foundation.
*
* The initial developer of the original code is Deyan T. Chepishev
* http://www.poweradded.net/
*
* (C) 2009             Deyan T. Chepishev
*/

/*
*
* The CD/DVD device is expected to be /dev/cdrom. This is
* usually a symlink to the real device. If you dont want to create a symlink
* just edit the path in the code and point it to your CD/DVD device.
*
*/

#include <sys/types.h>
#include <sys/stat.h>
#include <fcntl.h>
#include <linux/cdrom.h>
#include <stdlib.h>
#include <stdio.h>
#include <strings.h>
#include <sys/ioctl.h>

void usage( char a[] );

int main(int argc, char *argv[]){

//The location of cd/dvd device. Edit this if necessary
char device[]="/dev/cdrom";

int fd,lock=9999;


// Set unbuffered output
setvbuf(stdout, NULL, _IONBF, 0);

if( 2 != argc ){
 usage(argv[0]);
 exit(1);
}

if (0 == strcasecmp(argv[1],"lock")){
 lock=1;
}

if(0 == strcasecmp(argv[1],"unlock")){
 lock=0;
}

if( (0!=lock) && (1!=lock) ){
 usage(argv[0]);
 exit(1);
}

if (-1 == (fd=open(device,O_RDWR|O_NONBLOCK))){
 printf("Error opening device: \"%s\", ",device);
        perror("");
       exit(1);
}
if (0 != ioctl(fd, CDROM_LOCKDOOR,lock)){
 printf("Error locking device: \"%s\", ",device);
        perror("");
        exit(1);
}
}

void usage( char a[] ){
printf("\n\nUsage %s [lock|unlock]\n\n", a);
}


------------ COPY ENDS ABOWE THIS LINE------------