Showing posts with label Fedora. Show all posts
Showing posts with label Fedora. Show all posts
Thursday, 10 July 2014
Fedora Catchup
The couple of packages I maintain in Fedora have been sitting stable for so long that I've not really had much to do with Fedora recently (that, and getting a mac laptop for $work), but I've just discovered https://badges.fedoraproject.org/ so it's now time to claim a few extras (oh, and push an update to PyEphem while I'm at it...)
Tuesday, 28 February 2012
Yubico / Yubikeys
I'm impressed.
I have small keyring with a USB memory stick, 2 yubikeys and a cofee machine cashless RFID key on. Stupidly I left said key in the vending machine. The system operators at work collected it and set about finding the owner. 1st up, they discovered that they can't read any files off yubikeys (heh) but googled the image and found the manufacturers website and said they had found serial #.... and #.....
Having spend the last 2 days rummaging in car / home looking for it, I got an email from yubico saying that <email> had found my key, based on the serial no of the one I purchased. Work also got an email for the other serial no, which they traced to me.
I'm *very* impressed by this level of attention at yubico, and it means when distributing keys within the business it pays to keep track of the serial no (printed under the 2d barcode).
It does raise the question of how (if) one should notify yubico if they're passed on - especially if I overwrite the yubi profile (as I have done) to prove that I am the rightful owner of the key.
Things to consider with revocation / blocking, especially with a distributed architecture like Fedora....
I have small keyring with a USB memory stick, 2 yubikeys and a cofee machine cashless RFID key on. Stupidly I left said key in the vending machine. The system operators at work collected it and set about finding the owner. 1st up, they discovered that they can't read any files off yubikeys (heh) but googled the image and found the manufacturers website and said they had found serial #.... and #.....
Having spend the last 2 days rummaging in car / home looking for it, I got an email from yubico saying that <email> had found my key, based on the serial no of the one I purchased. Work also got an email for the other serial no, which they traced to me.
I'm *very* impressed by this level of attention at yubico, and it means when distributing keys within the business it pays to keep track of the serial no (printed under the 2d barcode).
It does raise the question of how (if) one should notify yubico if they're passed on - especially if I overwrite the yubi profile (as I have done) to prove that I am the rightful owner of the key.
Things to consider with revocation / blocking, especially with a distributed architecture like Fedora....
Saturday, 25 February 2012
apcupsd via Python to Pachube
In python, the 'default' URL accessing toolkit (urllib2) doesn't support PUT, however I've discovered requests which a) does and b) is in Fedora. So one apt-get install python-requests.noarch and you're off.
So - one trivial script (reusing much of the code for my MQTT variant) you get https://gist.github.com/1903259. The only minor niggle was working out how to prepend the minimum extra json content (version and datastreams) as I'd not used the json libs before. (Hmm yet another github toy - embeddable gists with syntax highlighting. Nice) Update now I have 24h worth of data - plot attached
So - one trivial script (reusing much of the code for my MQTT variant) you get https://gist.github.com/1903259. The only minor niggle was working out how to prepend the minimum extra json content (version and datastreams) as I'd not used the json libs before. (Hmm yet another github toy - embeddable gists with syntax highlighting. Nice) Update now I have 24h worth of data - plot attached
Friday, 27 January 2012
Fedora / Netatalk / OS X Lion / TimeMachine
Being the cheapskate that I am, I'm not buying a shiny apple-branded time-capsule for backups when I have a perfectly stylish NAS (since the pic was taken I'm using the via-eden board there's a 1.5TB HDD in the box)
I'd previously used netatalk with leopard under mythbuntu, but following a clean-up and migration to Fedora 16 (Verne) it needed reinstalling (esp as we upgraded to Lion on some of the macs)
So, a HOWTO if anyone is hunting for this and some notes
1) Create a separate disk partition for time machine and mount it (I'm using LVM and XFS)
(I added -mimicmodel Macmini and uams_guest.so to -uamlist: I have a ro media share)
In the time machine preferences I could then select the remote TimeMachine volume on the NAS, enter my 'timelord' username/password combo and it started to so a backup.
More news (and a rest restore) to follow...
I'd previously used netatalk with leopard under mythbuntu, but following a clean-up and migration to Fedora 16 (Verne) it needed reinstalling (esp as we upgraded to Lion on some of the macs)
So, a HOWTO if anyone is hunting for this and some notes
- You don't need avahi separately anymore - new netatalk includes it
- You need to allow tcp/548 in your iptables rules (I added to /etc/sysconfig/iptables)
-A INPUT -p tcp -m state --state NEW -m tcp --dport 548 -j ACCEPT - SELinux. Yeah. probably needs fixing but 'setenforce permissive' worked :-/
- I'm not convinced you need the 'defaults write com.apple.systempreferences TMShowUnsupportedNetworkVolumes 1' anymore.
1) Create a separate disk partition for time machine and mount it (I'm using LVM and XFS)
$> grep time /etc/fstab2) create a separate user for the backups (not strictly needed but I chowned /export/rimemachine to that user to sort out permissions
/dev/mapper/linuxvg-timemachinelv /export/timemachine xfs defaults 1 2
$> df -h /export/timemachine
Filesystem Size Used Avail Use% Mounted on
/dev/mapper/linuxvg-timemachinelv 200G 6.0G 194G 3% /export/timemachine
#> useradd timelord3) Install and configure netatalk (although 2.2.0 is in Fedora 16, I decided to use the rawhide version of 2.2.2)
#> passwd timelord
#> chown timelord: /export/timemachine
#> yum --enablerepo rawhide install netatalkThe config files are in /etc/netatalk and (see the gude at An Esurient Trollop ) you'll need to edit afpd.conf
(I added -mimicmodel Macmini and uams_guest.so to -uamlist: I have a ro media share)
- -tcp -noddp -mimicmodel Macmini -uamlist uams_guest.so,uams_dhx.so,uams_dhx2.so -nosavepassword
and AppleVolumes.default
# Share out the Videos
/export/media/Video Videos options:ro,noadouble
#Time Machine
/export/timemachine TimeMachine options:tm
Startup netatalk
#> systemctl start netatalk.serviceSo far so good -- assuming no failures you should see something like this in your logs
#> systemctl enable netatalk.service
afpd[28742]: AFP/TCP started, advertising 192.168.1.251:548 (2.2.2)Now, onto the mac -- I wasn't seeing the host automatically appear in the finder, but a simple command-k (connect to server) and typing the hostname worked (it expands to afp://hostname automatically), and was prompted for my (normal) username and password to connect to $HOME on the netatalk server.
In the time machine preferences I could then select the remote TimeMachine volume on the NAS, enter my 'timelord' username/password combo and it started to so a backup.
More news (and a rest restore) to follow...
Monday, 4 April 2011
Bash, PS1, PROMPT_COMMAND and other fun
I've just spent 30 mins trying to understand the flow between the various files that set a bash prompt on fedora to do the following: (assumption is here that you're in a colour xterm)
I want:
* my username to change colour depending if I still have a valid kerberos token
* the hostname of the machine I'm on to be in RED if I'm root
* displayed path to be as simple as possible
* $ if I'm a minion, # if root as mormal
* command line editing to work sensibly, no wierdisms on wrapping long lines
so - I used to have on my machine something like the following:
and something similar for root.
But on my laptop (F14) I wanted it system wide, so went down the approach of customising /etc/bashrc where you find calls to
PROMPT_COMMAND=/etc/sysconfig/bash-prompt-xterm
1) /etc/sysconfig/bash-prompt-* aren't included, so you're on your own
2) It must point to an executable script that is run every time before displaying the prompt
3) PS1 is still displayed *AND* if you use tab completion / ctrl-l, its *only* PS1 thats displayed on your screen, not the output from PROMPT_COMMAND
so: DON'T do the following:
because you end up with stuff like
aelwell@pcitgtelwell:~[aelwell@pcitgtelwell ~]$
until you press ctrl-l and end up with just
[aelwell@pcitgtelwell ~]$ (ie, $PS1)
but *DO* make the call to see if you have a valid token and set the xterm titlebar in /etc/sysconfig/bash-prompt-xterm, but if you're altering PS1, then do so in the traditional places of /etc/bashrc and (as suggested in that file) a custom modification shell script in /etc/profile.d/ directory.
Ho Hum. Hope this clears up for anyone else trying to work out what the sysconfig/bash-prompt-* files do.
oh, and does anyone know a lighter call to see if a token is still valid than 'klist -s'?
I want:
* my username to change colour depending if I still have a valid kerberos token
* the hostname of the machine I'm on to be in RED if I'm root
* displayed path to be as simple as possible
* $ if I'm a minion, # if root as mormal
* command line editing to work sensibly, no wierdisms on wrapping long lines
so - I used to have on my machine something like the following:
if [ "$PS1" != "" ] ; then
klist -s
if [ $? -eq 0 ] ; then
PS1='\[\033[32m\]\u@\h\[\033[0m\]:\w\$ '
else
PS1='\[\033[36m\]\u\[\033[32m\]@\h\[\033[0m\]:\w\$ '
fi
fi
and something similar for root.
But on my laptop (F14) I wanted it system wide, so went down the approach of customising /etc/bashrc where you find calls to
PROMPT_COMMAND=/etc/sysconfig/bash-prompt-xterm
1) /etc/sysconfig/bash-prompt-* aren't included, so you're on your own
2) It must point to an executable script that is run every time before displaying the prompt
3) PS1 is still displayed *AND* if you use tab completion / ctrl-l, its *only* PS1 thats displayed on your screen, not the output from PROMPT_COMMAND
so: DON'T do the following:
(where ^[ is 'ctrl-v, esc' in vim)
cat /etc/sysconfig/bash-prompt-xterm
#!/usr/bin/env bash
# set green username if we have a valid kerberos token, else cyan
klist -s
if [ $? -eq 0 ] ; then
K='[32m'
else
K='[36m'
fi
# set hostname in red if we're root, green otherwise
if [ ${USER} = 'root' ] ; then
U='[31m'
else
U='[32m'
fi
printf "^[%s%s^[[37m@^[%s%s^[[0m:%s " ${K} ${USER} ${U} ${HOSTNAME%%.*} "${PWD/#$HOME/~}"
#echo -ne "\033]0;${USER}@${HOSTNAME%%.*}:${PWD/#$HOME/~}\007"
because you end up with stuff like
aelwell@pcitgtelwell:~[aelwell@pcitgtelwell ~]$
until you press ctrl-l and end up with just
[aelwell@pcitgtelwell ~]$ (ie, $PS1)
but *DO* make the call to see if you have a valid token and set the xterm titlebar in /etc/sysconfig/bash-prompt-xterm, but if you're altering PS1, then do so in the traditional places of /etc/bashrc and (as suggested in that file) a custom modification shell script in /etc/profile.d/ directory.
Ho Hum. Hope this clears up for anyone else trying to work out what the sysconfig/bash-prompt-* files do.
oh, and does anyone know a lighter call to see if a token is still valid than 'klist -s'?
Friday, 18 March 2011
Makefile Faffage
I've inherited a piece of legacy code (an inirscript that needed bringing up to FHS and Fedora packaging guidelines) -- as part of the testing I realised I needed a noddy way to generate the tar.gz sources. There was already a Makefile in the package (for ETICS) but I hacked in the following to quickly build up a NVR-tarfile.
Not pretty, but if anyone fancies some Makefile golf, I'm open to suggestions:
and yes, it bears a striking resemblance to the GNU Complex Makefile Example
Not pretty, but if anyone fancies some Makefile golf, I'm open to suggestions:
dist:
echo ${package}-`sed \
-e '/^Version:/!d' \
-e 's/[^0-9.]*\([0-9.]*\).*/\1/' \
-e q \
${package}.spec` > .fname
-rm -rf `cat .fname`
cp -lvr src/ `cat .fname`
tar chzf `cat .fname`.tar.gz `cat .fname`
-rm -rf `cat .fname` .fname
and yes, it bears a striking resemblance to the GNU Complex Makefile Example
Sunday, 23 January 2011
Sponsored
Yay. So tibbs has taken up the challenge and become my sponsor for Fedora. So far I've got libfap built in koji, just working out the ins and outs of Bodhi, and we're good for multiple platform / arch builds. Seems rather simple compared to some other buildsystems I'm using :-)
Anyway, lets see if planet.fp.o picks up on the Fedora tag correctly
Anyway, lets see if planet.fp.o picks up on the Fedora tag correctly
Wednesday, 15 December 2010
Fedora Packaging
OK, so I needed to get my touchatag reader working under fedora, and RFIDIOt needs pyscard. Much yak-shaving later I've come up with a .spec file for pyscard, and its now ready for review.
spec file - http://dl.dropbox.com/u/6594808/Fedora/pyscard.spec
src rpm - http://dl.dropbox.com/u/6594808/Fedora/pyscard-1.6.12-1.fc14.src.rpm
oh well, lets see who'll pick up my Review Request
spec file - http://dl.dropbox.com/u/6594808/Fedora/pyscard.spec
src rpm - http://dl.dropbox.com/u/6594808/Fedora/pyscard-1.6.12-1.fc14.src.rpm
oh well, lets see who'll pick up my Review Request
Subscribe to:
Posts (Atom)
Ressurection of a WirelessThings OpenPi (from kickstarter)
Many years ago, I was handed one of the openpi kickstarter devices (see https://www.kickstarter.com/projects/wirelessthings/openpi-wireless-...
-
During the trials of concerto at CERN, I wanted to make the text fields a bit more dynamic like say following a specific twitter feed. This...
-
Since there's no european satellite stream of Nasa TV it means you have to watch a streamed version over here. Also I'd like to w...
-
We have a small cabin on the site that used to have a 200w panel, 65Ah deep cycle lead acid battery, el-cheapo PWM charger to power some LED...
