1129421038 J * lilo tor@lilo.usercloak.oftc.net 1129421345 Q * lilo Remote host closed the connection 1129421369 J * lilo ~lilo@lilo.usercloak.oftc.net 1129423510 Q * SiD3WiNDR Ping timeout: 480 seconds 1129423586 J * SiD3WiNDR luser@bastard-operator.from-hell.be 1129424435 Q * SiD3WiNDR jupiter.oftc.net quasar.oftc.net 1129424435 Q * lilo jupiter.oftc.net quasar.oftc.net 1129424435 Q * click jupiter.oftc.net quasar.oftc.net 1129424435 Q * meebey jupiter.oftc.net quasar.oftc.net 1129424435 Q * AndrewLee jupiter.oftc.net quasar.oftc.net 1129424435 Q * lonewolff jupiter.oftc.net quasar.oftc.net 1129424435 Q * ag-2 jupiter.oftc.net quasar.oftc.net 1129424435 Q * locksy jupiter.oftc.net quasar.oftc.net 1129424435 Q * pjay jupiter.oftc.net quasar.oftc.net 1129424435 Q * alexx jupiter.oftc.net quasar.oftc.net 1129424435 Q * derbien jupiter.oftc.net quasar.oftc.net 1129424435 Q * mountie jupiter.oftc.net quasar.oftc.net 1129424435 Q * DaCa jupiter.oftc.net quasar.oftc.net 1129424435 Q * neofutur jupiter.oftc.net quasar.oftc.net 1129424435 Q * sladen jupiter.oftc.net quasar.oftc.net 1129424435 Q * Hunger jupiter.oftc.net quasar.oftc.net 1129424496 J * Hunger Hunger.hu@Hunger.hu 1129424506 J * meebey meebey@booster.qnetp.net 1129424513 J * SiD3WiNDR luser@bastard-operator.from-hell.be 1129424521 J * neofutur ~neofutur@neofutur.net 1129424522 J * derbien ~derbien@whiterabbit.nbmc.de 1129424528 J * lilo ~lilo@lilo.usercloak.oftc.net 1129424543 J * sladen paul@starsky.19inch.net 1129424544 J * lonewolff ~lonewolff@host86-128-128-38.range86-128.btcentralplus.com 1129424550 J * click click@ti511110a080-4596.bb.online.no 1129424554 J * AndrewLee ~andrew@linux3.cc.ntu.edu.tw 1129424566 J * mrec_ ~revenger@p54B016E6.dip0.t-ipconnect.de 1129424723 J * ag-2 ag@muaddib.roxor.cx 1129424773 Q * jayeola Quit: leaving 1129424775 J * DaCa ~danny@mail.limehouse.org 1129424983 Q * mrec Ping timeout: 480 seconds 1129425213 J * alexx ~alexx@proxy.ikse.net 1129425218 J * mountie ~mountie@CPEdeaddeaddead-CM000a739acaa4.cpe.net.cable.rogers.com 1129425660 J * romke ~romke@procyon.romke.net 1129426415 Q * tchan Remote host closed the connection 1129426725 J * tchan ~tchan@c-67-174-18-204.hsd1.il.comcast.net 1129427050 J * ntrs ~ntrs@68-188-50-87.dhcp.stls.mo.charter.com 1129428078 M * daniel_hozac Bertl_zZ: narrowing it down further, it seems to be specific to HIGHMEM64G, SMP, Fedora, and a non-standard memory split... remove either and it works again. 1129428106 M * daniel_hozac i'll just remove HIGHMEM64G for now. 1129428722 N * nokoya nokoya- 1129428732 N * nokoya- nokoya 1129429066 J * yungyuc ~yungyuc@220-135-53-220.HINET-IP.hinet.net 1129430332 Q * shuri Remote host closed the connection 1129431935 M * FireEgl I'm trying to use usrquota/grpquota quotas to work as described in http://linux-vserver.org/Standard+non-shared+quota ..But when I do a "quotaon -a" all I get is a Segmentation fault/kernel Oops.. I'm using v2.6.13.4-vs2.1.0-rc4..does anybody here have quotas working with that version? 1129431975 M * FireEgl BTW, doing "quotaon -a" segfaults/Oopses both on the host and in the guest. 1129431985 J * locksy ~locksy@mrtg.sisgroup.com.au 1129436051 J * dddd44 dhb55@60.49.78.240 1129437442 J * serving serving@86.108.21.61 1129437815 Q * dddd44 Read error: Connection reset by peer 1129441958 J * coocoon ~coocoon@p54A05D33.dip.t-dialin.net 1129441999 Q * coocoon Quit: 1129442031 Q * Eyck Read error: Connection reset by peer 1129442529 J * eyck eyck@81.219.64.71 1129442825 N * Bertl_zZ Bertl 1129442885 M * Bertl morning folks! 1129443007 M * Bertl FireEgl: what filesystem do you use for quota? could you upload the oops/trace please? (e.g. pastebin.com) 1129443049 M * Bertl daniel_hozac: hmm, okay, maybe they modified something somewhere ... 1129443096 M * Bertl (well, they probably have :) what I meant was, something memory split related 1129443381 M * Bertl okay, off again ... back later 1129443410 N * Bertl Bertl_oW 1129443753 M * FireEgl Bertl: ext3 http://pastebin.com/395131 1129447907 J * dddd44 dhb55@60.49.78.240 1129448283 Q * dddd44 Read error: Connection reset by peer 1129448374 J * dddd44 dhb55@60.49.78.240 1129449833 J * Aiken__ ~james@tooax6-126.dialup.optusnet.com.au 1129450103 Q * dddd44 Read error: Connection reset by peer 1129450170 Q * Aiken_ Ping timeout: 480 seconds 1129450190 Q * Hollow Remote host closed the connection 1129450253 Q * Aiken__ Quit: Leaving 1129450394 J * Hollow ~hollow@82.135.28.84 1129451587 N * Bertl_oW Bertl 1129451710 J * RoT ~bob@203.59.146.87 1129451717 M * Bertl welcome RoT! 1129451768 M * Bertl Fie 1129451784 M * Bertl +reEgl: interesting oops ... 1129451797 M * RoT hi mate 1129451890 M * RoT hey Bertl, at the moment is gentoo guest the only option for a guest built against 2.6 kernel? 1129451907 M * Bertl no, a lot of other distros work quite fine ... 1129451929 M * Bertl (some of them need some cleanup, though) 1129451971 M * RoT ok is there a knowledge base anywhere for building your own guests? 1129452010 M * Bertl you know the alpha util-vserver page? 1129452026 M * Bertl http://linux-vserver.org/alpha+util-vserver 1129452045 M * Bertl there are some examples how to install different guests! 1129452149 M * RoT ok so something like an openbsd guest is something that is in the realm of the developers then :) 1129452211 M * RoT or it wouldn't work anyway because it needs to use the same kernel yeah? 1129452438 M * Bertl precisely, openbsd yes, but only if it runs on a linux kernel *G* 1129452973 M * Bertl FireEgl: do you use the vroot device? 1129453136 M * Bertl FireEgl: you have selinux enabled and configured? 1129453549 M * chwi Bertl u prefer ovz or vserver ? 1129453566 M * Bertl linux-vserver of course :) 1129453584 M * Bertl (but I guess I'm biased) 1129453639 M * chwi it says ovz has a virtualized network stack 1129453951 M * Bertl which of course adds more overhead .. 1129454071 M * Bertl (but there will be a version/patch called ngnet, which will provide similar network virtualization for linux-vserver, for those who really need it :) 1129454139 M * chwi ho kewl 1129454153 M * FireEgl Bertl: Yes to vroot, and I do have selinux compiled and enabled, but it's not enforcing. 1129454256 M * Bertl because the oops seems to be in the selinux code ... 1129454290 J * dddd44 dhb55@60.49.78.240 1129454311 M * Bertl FireEgl: but it might be that the vroot device 'should' assign some additional selinux permission check/functions to work properly ... 1129454376 M * Bertl FireEgl: definitely a quick fix would be to disable selinux ... 1129454390 A * Bertl is looking into it right now ... 1129454420 M * FireEgl Bertl: Will the selinux=0 boot parameter be enough? Or should I compile the kernel without selinux? 1129454506 M * Bertl don't know yet, you might try, but I suspect a recompile is required 1129454531 M * FireEgl okee.. 1129454650 M * ag- chwi: what's ovz? i don't know about it... 1129454678 M * Bertl ag-: open-virtuozzo 1129454692 M * Bertl swsoft finally released the kernel modifications 1129454715 M * ag- Bertl: ah, i didn't know the short name ;P 1129454741 M * Bertl yes, they changed to open-vz recently, and ovz stuck ... 1129454768 M * Bertl FireEgl: do you still have your kernel tree? 1129454783 M * chwi now im begin to learn vserver, im arlady about to change to ovz :-[ 1129454807 M * FireEgl Bertl: Yah. 1129454820 M * Bertl FireEgl: okay, could you issue a few commands for me there? 1129454871 M * FireEgl sure 1129454903 M * Bertl objdump -d vmlinux | grep -A 40 'superblock_has_perm>:' 1129454922 M * Bertl chwi: because of the virtual network stack? 1129454982 M * ag- Bertl: however, their virtual network stack doesn't seem to support ipv6 :( 1129455017 M * Bertl ngnet will :) 1129455018 M * FireEgl Bertl: http://pastebin.com/395199 1129455032 M * ag- Bertl: yup, i really prefer the ngnet approach ;) 1129455507 M * FireEgl Bertl: selinux=0 fixed the Oops. =) 1129455578 M * Bertl great, could you do another test for me? 1129455583 M * FireEgl sure =) 1129455614 M * Bertl I would like to know if the oops/trace happens if you boot with selinux, but use the real device instead of the vroot device 1129455748 Q * dddd44 Read error: Connection reset by peer 1129455819 M * FireEgl Well, on bootup of the HOST I see the Oops when one of my init scripts runs quotaon.. So the Oops happens on both the host and in the guest when I run quotaon in it.. I haven't tried setting the guest to use the real device. 1129455835 M * Bertl ah, excellent, I guess I found it ... 1129455844 M * Bertl it's a bug in the quota hash abstraction ... 1129455846 J * misko ~misko@slovakia.sh.cvut.cz 1129455851 M * misko ehlo bertl 1129455853 M * Bertl welcome misko! :) 1129455884 A * Bertl .o( somewhere behind me? ) 1129455894 M * misko wht kind of pizza would you like to eat ? 1129455899 M * misko or something different 1129455951 M * Bertl cheese would be fine 1129455989 M * Bertl (corn and ham optional, no salami) 1129456024 M * misko okay will try 1129456028 M * Bertl thanks! 1129456029 M * misko when do you leave? 1129456057 M * misko did you enjoy prague at least a bit? 1129456067 M * Bertl train will leave at 18:00 so a little earlier I guess 1129456087 M * Bertl yes, had a nice walk/journey yesterday ... 1129456108 M * Bertl nice city, nice people ... 1129456118 M * misko ok :) some people asked me about the recording of your workshop 1129456179 M * Bertl guess you have some pictures at least :) 1129456187 M * misko yes, a couple 1129456198 M * misko slovakia.sh.cvut.cz/~misko/dsc_1333.jpg 1129456252 M * Bertl OMG :) 1129456429 M * Bertl FireEgl: okay, I should have a patch in a few minutes ... 1129456438 M * FireEgl =) 1129456573 M * chwi Bertl: no, because it says ovz has also better ressource control. And perhaps there will have open mgnt tool like plesk soon :p 1129456613 J * dddd44 dhb55@60.49.78.240 1129456665 M * Bertl chwi: regarding resource control you have to tell me what is missing (because I do not know of any missing resource control), regarding mgnt tools, you think? after all, that's what they are selling no? 1129456760 M * chwi im a sweet dreamer 1129456836 M * Bertl no problem with that here ... it's your choice :) 1129456928 M * Bertl FireEgl: http://vserver.13thfloor.at/Experimental/delta-2.6.13.3-vs2.1.0-rc4-rc4.1.diff 1129456958 M * Bertl FireEgl: this should fix the issue properly .. I would appreciate if you could give it a try and let me know ... 1129456965 M * chwi if i want to stop using the port 22 of my host box for sshd to use it on vservers, i can use the port 23 (usualy used for telnet) ? There 's no problem about that ? Anyway i dont have telned running. 1129456994 M * chwi or i must use a >1024 port ? 1129457028 M * FireEgl Bertl: Okee, I will. =) 1129457070 M * Bertl chwi: no problem, but it would be sufficient to restrict the host's sshd to the host ips ... 1129457084 M * Bertl chwi: but of course a different port address is a good option too 1129457117 M * chwi yes i though about this solution but my host ip has dynamical ip (adsl) so i couldnt. 1129457245 M * Bertl ah, i.c. well, you can :) 1129457265 M * Bertl it might be non-obvious, but actually it's trivial 1129457284 M * Bertl chwi: you assign a local ip (maybe of your guest range?) to the host 1129457311 M * Bertl then you add an iptable rule (or separate chain) to SNAT that ip to the current public ip 1129457320 J * liquid3649 ~liquid@p549778AF.dip.t-dialin.net 1129457331 M * Bertl this rule is changed from within the script which assigns the dynamic ip 1129457335 M * Bertl welcome liquid3649! 1129457352 M * liquid3649 hi bertl 1129457394 Q * dddd44 Read error: Connection reset by peer 1129457457 M * chwi yes and i could start the update rule script simply by my /etc/ppp/ip-up file 1129457464 M * chwi good idea 1129457497 M * Bertl exactly, you can also use the same chain/rule for guests you want to allow network/internet access 1129457528 M * Bertl just add a rule to branch to the SNAT chain for those guest ips which should get access 1129458351 Q * lilo Remote host closed the connection 1129458365 J * lilo ~lilo@lilo.usercloak.oftc.net 1129458378 J * dddd44 dhb55@60.49.78.240 1129458676 M * chwi Bertl> then you add an iptable rule (or separate chain) to SNAT that ip to the current public ip <- but i also have to update and restart the ssh daemon each time the public ip change. 1129458701 Q * lilo Remote host closed the connection 1129458733 J * lilo tor@lilo.usercloak.oftc.net 1129458824 M * Bertl chwi: nope, not at all 1129458874 M * Bertl it's like this: 1129458909 M * Bertl remote ---> ssh to public:22 --DNAT-> private:22 1129458931 M * Bertl then you configure the sshd to listen just to the private host ip 1129458943 Q * dddd44 Read error: Connection reset by peer 1129459016 M * chwi and for the vservers guests ? 1129459028 M * chwi to reach them. 1129459044 M * Bertl well, that is trickier .. you need to assign one port (on the public) for each guest 1129459062 M * Bertl e.g. 2001 -> guest 1, 2002 -> guest 2 1129459074 M * Bertl (or get more public ips of course :) 1129459078 M * chwi ok 1129459091 Q * lilo Quit: leaving 1129459103 M * chwi with ipv6 i could =) 1129459104 M * Bertl OTOH, you could configure the port forwarding in the start/stop scripts 1129459158 M * Bertl chwi: don't know if ipv6->ipv4 forwarding/nat works, but if, you could also redirect the ipv6 connect to a private ipv4 address ... 1129459209 J * dddd44 dhb55@60.49.78.240 1129459210 M * chwi no but i have a lot of ipv6 public address, i could set one different ip by guest. 1129459221 M * chwi if ipv6 was supported. 1129459252 M * Bertl ipv6 on the host is supported 1129459257 M * chwi yes 1129459266 M * Bertl if you know a way to 'map' it, it could/would work 1129459325 Q * dddd44 Read error: Connection reset by peer 1129459483 M * Bertl okay, pizza time ... :) 1129459500 M * chwi bon appetit 1129459585 J * dddd44 dhb55@60.49.78.240 1129460081 J * ocien ~okie@5354E684.cable.casema.nl 1129460725 Q * dddd44 Read error: Connection reset by peer 1129460817 M * Bertl chwi: thanks, it was quite good ... 1129461235 J * dddd44 dhb55@60.49.78.240 1129461252 M * Bertl welcome ocien! 1129462158 M * ocien thanks 1129462185 M * matti Bertl: Enjoy your pizza :) 1129462279 M * Bertl matti: I already did ... but thanks :) 1129462335 M * matti :) 1129462521 M * FireEgl Is this right? vrsetup /dev/vroot/0 /dev/hdb2 With /dev/hdb2 being the ext3 partition I have my guest on by itself. 1129462578 M * Bertl yes that looks fine ... 1129462593 M * Bertl (given that you use/have /dev/vroot/0) 1129462705 M * FireEgl I actuall had to mknod it by hand.. anyways.. 1129462714 M * FireEgl Okee, I've got usrquota,grpquota set in my /etc/vservers/ariel/apps/init/mtab file, but do I need usrquota,grpquota in the host /etc/fstab for /dev/hdb2 as well? 1129462728 M * Bertl no, not at all 1129462747 M * FireEgl Okee good, cuz I don't. =) 1129462748 M * Bertl it's just for the tools, you also want to use ufs as filesystem type in the guest 1129462778 M * Bertl (this prevents the tools from trying direct disk io) 1129462888 M * FireEgl Next, and last.. /var/lib/vservers/ariel/ariel/ is the root directory of my guest. While /var/lib/vservers/ariel/ is the root of /dev/hdb2. Is that alright? Cuz doing quotaon -a tells me this: quotaon: using //aquota.group on /dev/hdv1 [/]: No such device 1129462958 M * Bertl well, it's an unusual setup 1129463001 M * Bertl normally I'd mount /dev/hdb2 on /var/lib/vservers or alternatively use /var/lib/vservers/ariel/ (for both, mount and root) 1129463036 M * Bertl the message itself means that you want to run quotacheck inside the guest 1129463054 M * FireEgl I did run quotacheck first. 1129463085 M * FireEgl I'll try mounting it different and see if that fixes it.. 1129463088 M * Bertl what is /dev/hdv1 ? could you do an ls -la on that? 1129463111 M * FireEgl rw-r--r-- 2 root root 4, 0 Oct 15 00:05 hdv1 1129463114 M * FireEgl err 1129463118 M * FireEgl brw-r--r-- 2 root root 4, 0 Oct 15 00:05 hdv1 1129463120 M * FireEgl that. 1129463135 M * Bertl okay, that should be fine, the vroot setup did succeed too, right? 1129463141 M * FireEgl yep 1129463171 M * Bertl and inside the guest, what does the /etc/mtab contain? 1129463194 Q * dddd44 Read error: Connection reset by peer 1129463274 M * FireEgl $ cat /etc/mtab 1129463274 M * FireEgl none /proc proc defaults,uid=3,gid=3 0 0 1129463274 M * FireEgl none /tmp tmpfs size=96m,mode=1777 0 0 1129463274 M * FireEgl none /dev/pts devpts gid=5,mode=620 0 0 1129463279 M * FireEgl dangit 1129463281 M * FireEgl $ cat /etc/mtab 1129463281 M * FireEgl /dev/hdv1 / ufs rw,usrquota,grpquota 0 0 1129463281 M * FireEgl none /proc proc defaults,uid=3,gid=3 0 0 1129463281 M * FireEgl none /tmp tmpfs size=96m,mode=1777 0 0 1129463281 M * FireEgl none /dev/pts devpts gid=5,mode=620 0 0 1129463284 M * FireEgl that. 1129463301 M * Bertl okay, looks fine too ... 1129463334 M * Bertl what about the quota capability? 1129463379 M * FireEgl Could I move all the files in /var/lib/vservers/ariel/ariel/ to /var/lib/vservers/ariel/ and then change the /etc/vservers/ariel/vdir to point to /var/lib/vservers/ariel instead? 1129463392 M * Bertl should work ... 1129463410 M * FireEgl [Melody] root:/etc/vservers/ariel$ cat ccapabilities 1129463410 M * FireEgl quota_ctl 1129463448 M * Bertl okay .. then let's strace -fF -o trace.out the quota command, and please upload the output somewhere ... 1129463668 M * FireEgl You want the output of this, right? [Ariel] root:~$ strace -fF -o trace.out quotaon -a 1129463683 M * Bertl well, it writes to teace.out (hopefully) 1129463687 M * Bertl *trace.out 1129463694 M * FireEgl Yah it did.. I'll paste that on pastebin... 1129463700 M * Bertl excellent! 1129463727 M * FireEgl http://pastebin.com/395284 1129463896 J * sebi_ ~sebi@Fcc17.f.strato-dslnet.de 1129463911 M * Bertl FireEgl: just to verify, fs is ext3, kernel is 2.6.13.4/vs2.1.0-rc4, right? 1129463913 M * Bertl welcome sebi_! 1129463945 M * FireEgl Bertl: ext3 and v2.6.13.4-vs2.1.0-rc4.1 now ;) 1129463971 M * Bertl yeah, okay, good, do you have debug (especially VSERVER_DEBUG) enabled? 1129463982 M * FireEgl no.. 1129463991 M * FireEgl Where do I set that at? 1129464005 Q * sebi Ping timeout: 480 seconds 1129464005 M * Bertl hmm, kernel config .. would it be a probelm to enable that? 1129464023 M * FireEgl Requires a recompile? =/ 1129464031 M * Bertl hmm, yes :/ 1129464037 M * Bertl CONFIG_DEBUG_KERNEL=y 1129464046 M * Bertl CONFIG_DEBUG_BUGVERBOSE=y 1129464049 M * Bertl CONFIG_DEBUG_INFO=y 1129464053 M * Bertl CONFIG_VSERVER_DEBUG=y 1129464079 M * Bertl I'm pretty sure it's something trivial, but I do not see it right now ... 1129464123 M * Bertl but let me check the source code once again ... maybe this gives a clue 1129464209 M * FireEgl I was getting something different from quotaon before that rc4.1 patch.. Lemme reboot to the rc4 kernel and see if I can make it show it again.. 1129464376 M * Bertl could it be that you enabled journaled quota on that fs? 1129464383 M * Bertl (on the host) 1129464415 M * FireEgl journaled quota? o_O I don't even know what that is. 1129464454 M * Bertl okay, the filesystem is mounted on /var/lib/vservers/ariel/ now? 1129464843 M * FireEgl Right. 1129464861 M * FireEgl Anyway.. with the rc4 I get this from quotaon: 1129464861 M * FireEgl quotaon: using //aquota.group on /dev/hdv1 [/]: Invalid argument 1129464861 M * FireEgl quotaon: Maybe create new quota files with quotacheck(8)? 1129464879 M * FireEgl rc4.1 doesn't tell me that. 1129464898 M * FireEgl (selinux is set to 0 now BTW) 1129464911 M * Bertl k 1129465016 M * Bertl hmm, seems like ext3 needs the quota to be enabled on mount 1129465023 M * Bertl try the following: 1129465054 M * Bertl mount -o usrquota,grpquota ... (on the host for the hdb2) 1129465062 M * Bertl (add it to the fstab for example) 1129465397 Q * RoT Quit: Leaving 1129465589 M * FireEgl It's working on rc4 =) But gimme a bit.. I'll have more to tell. =) 1129466334 M * Bertl k 1129466420 Q * ocien Ping timeout: 480 seconds 1129466465 M * FireEgl Bertl: Well, the host does the quotaon.. so I can't do quotaon in the guest without first doing quotaoff and then quotaon. Is that bad? 1129466500 M * Bertl no, that should be fine .. as long as the host quota is not journaled 1129466518 M * FireEgl How do I know if it's journaled or not? 1129466557 M * Bertl I'm not sure .. but let's simply try it ... 1129466614 M * FireEgl o_O 1129466982 M * FireEgl It's important to do the quotaon in the guest's context right? So long as I stop the host from doing the quotaon everything should be fine..right? 1129467320 M * Bertl yes 1129467386 M * FireEgl Okee.. Now I'll boot rc4.1 again to make sure it's working as it should.. 1129467927 M * FireEgl This is weird.. Running rc4.1 now.. It seems the host did a quotaon, but I can't do a quotaoff/quotaon in the guest. quotaoff: quotactl on /dev/hdv1 [/]: No such device 1129467928 M * FireEgl quotaon: using //aquota.group on /dev/hdv1 [/]: No such device 1129467959 M * FireEgl and quotacheck tells me: quotacheck: Cannot rename new quotafile //aquota.user.new to name //aquota.user: Operation not permitted 1129468016 M * Bertl hmm, what if you do quotaoff on the host? 1129468058 M * Bertl btw, the 4.0->4.1 change only affects selinux 1129468266 M * FireEgl Well, doing quotaoff -a on the host, lets me run quotacheck on the guest, but quotaon on the guest still tells me quotaon: using //aquota.group on /dev/hdv1 [/]: No such device 1129468336 M * FireEgl selinux is set to 0 still.. So why does it not work in rc4.1, but does work in rc4.0? 1129468385 M * Bertl I'll try to recreate it here ... 1129468665 M * Bertl FireEgl: please try to copy the 'real' device node into the guest (as /dev/hdv1) instead of the vroot device ... and check if this makes it work on 4.1 1129468948 M * FireEgl yah that works 1129468978 M * Bertl okay, so either the vroot setup is bad, or the ext3 doesn't set up the quota ops properly ... 1129469017 M * Bertl a kernel with debugging enabled might help here .. but I have a special debug patch too, which should shed some light on it (if you want to investigate) 1129469194 M * FireEgl Well it's got to be fixed... So yah, I can enable debugging I guess. ..Or you could login to my box and compile the kernel/reboot/debug/fix it while I sleep? =) 1129469526 M * FireEgl Want me to enable all those debugging options you mentioned earlier? And your special debug patch..where is it? 1129469622 M * Bertl give me a second to check something ... are you heading off to bed soon? 1129469667 M * FireEgl Yah I am.. but you're welcome to have root on the host to compile/patch or whatever you need to do.. 1129469693 M * Bertl well, I'd prefer to continue this tomorrow then ... if that is an option for you? 1129469711 M * Bertl (I should be able to get an idea what causes that till then) 1129469716 M * FireEgl yah 1129469837 M * FireEgl Well.. talk to ya tomorrow then.. =) 1129469911 M * Bertl okay, thanks and cya! 1129472109 A * virtuoso looks around 1129472146 M * virtuoso Good evening, guys. 1129472290 M * virtuoso Bertl: What's the latest kernel and vserver version known to work? 1129472311 A * virtuoso looks forward to upgrade from 2.6.10. 1129472355 M * Bertl welcome virtuoso! 1129472365 M * Bertl for the releases/versions see the topic :) 1129472381 M * virtuoso My dear god. 1129472409 M * virtuoso Right, but as for kernel versions? 1129472443 M * virtuoso I've just pulled a git repo and now I'm wondering will something apply there. 1129473033 M * Bertl probably .. but I'd suggest to stay with 2.6.13.x for now 1129473154 M * Bertl okay, leaving now ... will be back in the evening 1129473164 N * Bertl Bertl_oO 1129473413 J * Blissex pcg@82-69-39-138.dsl.in-addr.zen.co.uk 1129473887 M * chwi i have set a rule on my fw: dnat to 192.168.1.2:2000 inface ppp+ proto tcp dport 2000 1129473916 M * chwi from my host i can ssh -p 2000 192.168.1.2 1129473922 M * chwi but not from outside 1129473944 M * chwi is it perhaps because my vservers run on the gtw it-self ? 1129475072 M * Hollow Gentoo folks: http://planet.gentoo.org/developers/hollow/2005/10/16/consolidated_virtualization_effort_in_ge 1129475452 J * doener doener@i5387E6B0.versanet.de 1129476132 J * Dr4g Dr4g@80-195-133-230.cable.ubr06.uddi.blueyonder.co.uk 1129476297 M * chwi what is the rule to forward ssh connexion from a special port to port 22 of my vsevers ? 1129477156 M * chwi i do the same to forward a special port like 80 to my internal web server for example .. I suppose it's because in this case, the vservers run on the gtw itself. But i dont find how to correct my iptables chain. 1129478365 M * doener chwi: iptables -t nat -A PREROUTING -p tcp --dport 12345 -j DNAT --to-destination 1.2.3.4:22 1129478371 M * doener that should do IIRC 1129478502 M * chwi iptables -t nat -A PREROUTING -p tcp --dport 2001 -i ppp+ -j DNAT --to-destination 192.168.1.2:2000 1129478531 M * chwi i can ssh -p 2000 192.168.1.2 from the host but i cant ssh -p 2001 public_ip from internet 1129478562 M * chwi isnt it perhaps because the guests are on the gtw itself and not on another internal box? 1129478617 M * doener from inside the guest you can access the net, right? 1129478636 M * chwi yes by a snat setting 1129478654 M * chwi (and not by simple masquerading) 1129478664 M * doener yep, that is expected 1129478708 M * doener could you check with tcpdump what happens with the traffic when you try to ssh to that port from the internet? 1129478737 M * chwi uh 1129478749 M * chwi i can install tcpdump if u want :) 1129478754 M * chwi i never used that tool. 1129478814 M * doener would be nice 1129478820 M * chwi ha that work after i dropped all others iptables settings exept this dnat and snat rules 1129478830 M * chwi so i suppose i was blocking it by another rule. 1129478842 M * chwi thanks for ur help doener 1129478842 M * doener ok, then i guess we don't need tcpdump ;) 1129478870 M * doener you're welcome (although i didn't really do anything ;) 1129478913 M * chwi no but ur presence probably helps me :p 1129479085 J * menomc ~amery@200.75.27.91 1129479193 Q * mnemoc Ping timeout: 480 seconds 1129479193 N * menomc mnemoc 1129480170 M * mef where do I look for a log of the irc messages? 1129480197 M * mef bertl gave me some URLs earlier which are no longer in my ksirc buffer. :( 1129480238 M * doener http://irc.13thfloor.at/LOG/ 1129480268 M * mef thanks 1129480325 M * mef doener: vielen dank! 1129480348 M * doener no problem! kein problem! ;) 1129480398 M * chwi oh my texts are published 1129480400 M * chwi im famous 1129480404 M * chwi :D 1129480429 J * stefani ~stefani@c-24-19-46-211.hsd1.wa.comcast.net 1129480764 M * chwi doener i perhaps will need u though 1129480807 M * chwi in fact my iptables default rules are to refuses everything. And i specify what i want to accept. 1129480860 M * chwi and with ur iptables -t nat -A PREROUTING -p tcp --dport 2001 -i ppp+ -j DNAT --to-destination 192.168.1.2:2000 it works only when I accept everything by default. So it probably need another ACCEPT rule ? 1129480980 M * doener no idea, i'm happy to know how to get that nat stuff working with iptables 1129481340 M * chwi i installed tcpdump how can i check ? 1129481391 Q * liquid3649 Quit: Verlassend 1129483363 M * daniel_hozac chwi: do you have an ACCEPT rule for -d 192.168.1.2 -p tcp --dport 2000? 1129483969 J * lilo tor@lilo.usercloak.oftc.net 1129483994 M * chwi heu 1129483996 M * chwi i test 1129484143 M * chwi on input chain ? 1129484151 M * chwi it dont work 1129485704 P * stefani parting (is such sweet sorrow) 1129486397 M * chwi daniel_hozac thanks, it works. 1129486906 Q * Blissex Read error: Connection reset by peer 1129487562 J * dddd44 dhb55@60.49.78.240 1129487571 J * lilo_ ~lilo@lilo.usercloak.oftc.net 1129487895 J * lilo__ tor@tor-irc.dnsbl.oftc.net 1129487960 Q * lilo Ping timeout: 480 seconds 1129488301 Q * lilo_ Ping timeout: 480 seconds 1129489243 J * Sonarman_ ~cleetus@71.141.156.125 1129489553 Q * Sonarman Ping timeout: 480 seconds 1129490403 Q * chwi Quit: 1129490783 J * Blissex pcg@82-69-39-138.dsl.in-addr.zen.co.uk 1129491891 Q * Dr4g Ping timeout: 480 seconds 1129494380 J * traffic ~gorecki@home.negativeiq.com 1129494391 M * traffic good afternoon. 1129494428 M * traffic what do you guys recommend for traffic accounting and graphing? 1129495280 Q * serving Ping timeout: 480 seconds 1129495393 Q * yarihm Quit: Leaving 1129497366 J * Aiken ~james@tooax6-170.dialup.optusnet.com.au 1129497909 Q * Blissex Remote host closed the connection 1129498210 J * lilo ~lilo@lilo.usercloak.oftc.net 1129498315 Q * lilo__ Ping timeout: 480 seconds 1129498701 Q * doener Quit: leaving 1129501840 Q * mef Remote host closed the connection 1129502003 J * serving serving@213.186.173.240 1129502521 J * bascos bascos@d213-103-196-25.cust.tele2.fr 1129502553 Q * bascos Quit: 1129503221 Q * serving Ping timeout: 480 seconds 1129506127 J * litage ~nick@203.220.55.70 1129506354 J * jayeola ~jayeola@host-87-74-49-120.bulldogdsl.com