Linux 2.2.25-ow1

From: Solar Designer (solar@private)
Date: Fri Mar 21 2003 - 09:30:45 PST


Linux 2.2.25-ow1 is out and a part of Owl-current.  The download URL
for -ow patches is:

Linux 2.2.25 fixes the kmod/ptrace race condition vulnerability
discovered by Andrzej Szombierski.  The vulnerability could result in
a local root compromise if the kernel is built with support for
auto-loading modules (CONFIG_KMOD) and the path to a module loader
program is specified in /proc/sys/kernel/modprobe.  It is recommended
that you not enable or use kmod, for both security and reliability
reasons.  The kernels used on Owl CDs have never been built with
support for kmod.  Owl startup scripts, unlike those used on some
other distributions, don't setup a path to modprobe with the kernel.

Linux 2.2.24+ also corrects "Etherleak" issues with a number of
Ethernet drivers (a common class of vulnerabilities publicized by Ofir
Arkin and Josh Anderson of @stake) and a local DoS vulnerability with
mmap(2) of /proc/<pid>/mem files discovered by Michal Zalewski of

Finally, Linux 2.2.25-ow1 patch makes the added RLIMIT_NPROC
enforcement also work for 32-bit syscalls on sparc64 (thanks to Brad
Spengler for noticing that this was missing).

For those who are wondering about 2.4.x, I am going to put out a new
version of the patch when 2.4.21 comes out.  Meanwhile, if you must
use 2.4.x for whatever reason, make sure you aren't using kmod.

Some references for the Linux kernel vulnerabilities I've mentioned:

The kmod/ptrace race:


mmap(2) of /proc/<pid>/mem DoS:

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3K368O28072
	for <jwa@private>; Sat, 19 Apr 2003 20:06:08 -0700
Received: from ( [])
	by (Postfix) with SMTP id 554BD70
	for <jwa@private>; Sat, 19 Apr 2003 20:06:01 -0700 (PDT)
Received: (qmail 1324 invoked by uid 1011); 20 Apr 2003 03:05:31 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 1316 invoked from network); 20 Apr 2003 03:05:30 -0000
Date: Sun, 20 Apr 2003 05:09:57 +0200
From: "Meka[ni]" <meka@private>
To: owl-users@private
Subject: ports
Message-Id: <20030420050957.5189554c.meka@private>
X-Mailer: Sylpheed version 0.8.6claws (GTK+ 1.2.10; i386-portbld-freebsd5.0)
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
X-Spam-Status: No, hits=-0.9 required=5.0
X-Spam-Checker-Version: SpamAssassin 2.53 (

	I've just been on a site and I didn't understand if there are something like ports system
found on *BSD?

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3K3G8O28287
	for <jwa@private>; Sat, 19 Apr 2003 20:16:08 -0700
Received: from ( [])
	by (Postfix) with SMTP id 230C570
	for <jwa@private>; Sat, 19 Apr 2003 20:16:04 -0700 (PDT)
Received: (qmail 1629 invoked by uid 1011); 20 Apr 2003 03:15:50 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 1621 invoked from network); 20 Apr 2003 03:15:50 -0000
Date: Sun, 20 Apr 2003 05:20:17 +0200
From: "Meka[ni]" <meka@private>
To: Owl <owl-users@private>
Subject: XFree
Message-Id: <20030420052017.029b3dc3.meka@private>
X-Mailer: Sylpheed version 0.8.6claws (GTK+ 1.2.10; i386-portbld-freebsd5.0)
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
X-Spam-Status: No, hits=-0.9 required=5.0
X-Spam-Checker-Version: SpamAssassin 2.53 (

	Is there any graphical environment? Of course, I can always compile it on my own but it's
hard to update compiled programs.

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3KAs8O12671
	for <jwa@private>; Sun, 20 Apr 2003 03:54:08 -0700
Received: from ( [])
	by (Postfix) with SMTP id 85A2F70
	for <jwa@private>; Sun, 20 Apr 2003 03:54:01 -0700 (PDT)
Received: (qmail 5328 invoked by uid 1011); 20 Apr 2003 10:53:42 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 5320 invoked from network); 20 Apr 2003 10:53:42 -0000
Date: Sun, 20 Apr 2003 14:50:05 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: ports
Message-ID: <20030420105005.GA7150@private>
References: <20030420050957.5189554c.meka@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20030420050957.5189554c.meka@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-30.2 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Sun, Apr 20, 2003 at 05:09:57AM +0200, Meka[ni] wrote:


> 	I've just been on a site and I didn't understand if there are something like ports system
> found on *BSD?

The entire Owl userland is maintained in a somewhat similar way:

As for a system for add-on functionality, we don't maintain one yet.
You may add stuff into the two source trees and build it in the same
way as the official Owl userland, or you may build additional RPM
packages independently from the rest of Owl (see rpminit(1) on Owl
for an easy way to setup building RPM packages under an arbitrary
non-root account).

We might add an official collection of Owl add-ons, -- for stuff which
doesn't qualify for the main Owl for whatever reason.  We might then
extend our build environment to allow for handling of such add-ons
separately from our core packages.

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3LIfAO04510
	for <jwa@private>; Mon, 21 Apr 2003 11:41:10 -0700
Received: from ( [])
	by (Postfix) with SMTP id E527670
	for <jwa@private>; Mon, 21 Apr 2003 11:41:04 -0700 (PDT)
Received: (qmail 24416 invoked by uid 1011); 21 Apr 2003 18:40:32 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 24408 invoked from network); 21 Apr 2003 18:40:31 -0000
Date: Mon, 21 Apr 2003 19:57:21 +0400 (MSD)
From: Lunar <lunar@private>
X-X-Sender: lunar@private
To: owl-users@private
Subject: Next Release
In-Reply-To: <20030420105005.GA7150@private>
Message-ID: <Pine.LNX.4.53.0304211953040.5788@private>
References: <20030420050957.5189554c.meka@private> <20030420105005.GA7150@private>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Status: No, hits=-16.6 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Dear colleagues !

When you planed use 2.4.x kernel in next release ?
The kernel 2.2 - good, but Kernel 2.4 need rice for more reasons :
Database/Firewall + Iptables/TCP/IP stack with extension's.
I think that be necessary recompile all packages ;-(


B.R. Lunar
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3LJgNO08180
	for <jwa@private>; Mon, 21 Apr 2003 12:42:23 -0700
Received: from ( [])
	by (Postfix) with SMTP id 38C7A70
	for <jwa@private>; Mon, 21 Apr 2003 12:42:19 -0700 (PDT)
Received: (qmail 25249 invoked by uid 1011); 21 Apr 2003 19:42:02 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 25241 invoked from network); 21 Apr 2003 19:42:01 -0000
Date: Mon, 21 Apr 2003 23:40:52 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: Next Release
Message-ID: <20030421194052.GA11561@private>
References: <20030420050957.5189554c.meka@private> <20030420105005.GA7150@private> <Pine.LNX.4.53.0304211953040.5788@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.LNX.4.53.0304211953040.5788@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-33.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Mon, Apr 21, 2003 at 07:57:21PM +0400, Lunar wrote:
> When you planed use 2.4.x kernel in next release ?

Most likely not in the next release of Owl, although that depends on
when we actually make it and the state of 2.4.x kernels by that time.

Currently, I am unsatisfied with 2.4.x.  I'd complain that 2.4.21
isn't coming out for months when there're publicly-known security
holes in 2.4.20, but some final fixes are simply not yet available,
not even in 2.4.21-pre's. :-(

Yet there's nothing which stops you from using Linux 2.4.x with Owl
already now, or with the 1.0 release.

> The kernel 2.2 - good, but Kernel 2.4 need rice for more reasons :
> Database/Firewall + Iptables/TCP/IP stack with extension's.

I have no idea of what you mean by "Database/Firewall".

> I think that be necessary recompile all packages ;-(

To use Linux 2.4.x with current Owl?  No.  You just do, and it works.

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3MGZVO25993
	for <jwa@private>; Tue, 22 Apr 2003 09:35:31 -0700
Received: from ( [])
	by (Postfix) with SMTP id D2E5770
	for <jwa@private>; Tue, 22 Apr 2003 09:35:26 -0700 (PDT)
Received: (qmail 8181 invoked by uid 1011); 22 Apr 2003 16:35:02 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 8173 invoked from network); 22 Apr 2003 16:35:01 -0000
X-Qmail-Scanner-Mail-From: steveb@private via exmail
X-Qmail-Scanner: (Clear:. Processed in 0.0699650000000001 secs)
From: "Steve Bremer" <steveb@private>
Organization: NEBCO, Inc.
To: owl-users@private
Date: Tue, 22 Apr 2003 11:29:48 -0500
MIME-Version: 1.0
Subject: Re: Next Release
Message-ID: <3EA527AB.5735.D96F9A@localhost>
Priority: normal
In-reply-to: <20030421194052.GA11561@private>
References: <Pine.LNX.4.53.0304211953040.5788@private>
X-mailer: Pegasus Mail for Windows (v4.02a)
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
Content-description: Mail message body
X-Spam-Status: No, hits=-21.1 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

I thought I'd throw in my .02.

> Most likely not in the next release of Owl, although that depends on
> when we actually make it and the state of 2.4.x kernels by that time.

Although I wouldn't mind seeing the 2.4 kernel become the default, 
I've learned to really like the slow/steady/safe development pace 
taken by Owl.  Heck, even current is extremely stable in my 
experience.  I _really_ like that security comes before features.  

> > The kernel 2.2 - good, but Kernel 2.4 need rice for more reasons :
> > Database/Firewall + Iptables/TCP/IP stack with extension's.

I do think 2.4 has some nice firewalling/networking features that 2.2 
lacks, but I can live with 2.2 for awhile if it means Owl continues to 
stay as stable and reliable as it has been.

Steve Bremer
System & Security Administrator
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3MJhcO00860
	for <jwa@private>; Tue, 22 Apr 2003 12:43:38 -0700
Received: from ( [])
	by (Postfix) with SMTP id CDD6670
	for <jwa@private>; Tue, 22 Apr 2003 12:43:23 -0700 (PDT)
Received: (qmail 11200 invoked by uid 1011); 22 Apr 2003 19:42:52 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 11192 invoked from network); 22 Apr 2003 19:42:51 -0000
Date: Tue, 22 Apr 2003 23:40:57 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: Next Release
Message-ID: <20030422194057.GA15164@private>
References: <Pine.LNX.4.53.0304211953040.5788@private> <3EA527AB.5735.D96F9A@localhost>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <3EA527AB.5735.D96F9A@localhost>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-33.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Tue, Apr 22, 2003 at 11:29:48AM -0500, Steve Bremer wrote:
> Although I wouldn't mind seeing the 2.4 kernel become the default, 
> I've learned to really like the slow/steady/safe development pace 
> taken by Owl.

It's nice to know that.

> Heck, even current is extremely stable in my experience.

It is, but I don't view this as an obviously good thing.  When we
released 1.0, the plan was to start more aggressive development in
current and maintain a 1.0-stable for the security fixes.

In reality, we simply didn't have enough time to start doing all that
was planned for post-1.0 Owl right away, so current continued to
evolve at about the same pace that it had shortly before 1.0.  And it
became in all ways better than 1.0, -- including being even more
stable (well, we break things in our private cvs for a few days once
in a while, but I simply delay anoncvs/ftp updates in those cases).

So the new plan is to continue with safe changes only for a while
longer, make a 1.1 release, and only then hopefully do the major
updates that were originally planned for shortly after 1.0.  (I am
talking primarily of the gcc and glibc updates.)

To do these heavy changes now, without making another release first,
would be counter-productive because fewer people would then be able to
benefit from the stability improvements achieved in current so far.

> I do think 2.4 has some nice firewalling/networking features that 2.2 
> lacks, but I can live with 2.2 for awhile if it means Owl continues to 
> stay as stable and reliable as it has been.

To me, the primary reasons for Owl to move to 2.4.x aren't the more
extensive firewalling features, but rather availability of drivers
for newer hardware (most importantly disk controllers) and improved
kernel interfaces which allow to do neat things such as Olaf Kirch's
non-SUID/SGID traceroute that behaves more like the traditional one.

Thank you for your feedback, -- it really helps.

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3MKMjO02281
	for <jwa@private>; Tue, 22 Apr 2003 13:22:45 -0700
Received: from ( [])
	by (Postfix) with SMTP id 0749470
	for <jwa@private>; Tue, 22 Apr 2003 13:22:41 -0700 (PDT)
Received: (qmail 12284 invoked by uid 1011); 22 Apr 2003 20:22:23 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 12276 invoked from network); 22 Apr 2003 20:22:22 -0000
X-Qmail-Scanner-Mail-From: steveb@private via exmail
X-Qmail-Scanner: (Clear:. Processed in 0.070627 secs)
From: "Steve Bremer" <steveb@private>
Organization: NEBCO, Inc.
To: owl-users@private
Date: Tue, 22 Apr 2003 15:17:15 -0500
MIME-Version: 1.0
Subject: Re: Next Release
Message-ID: <3EA55CFA.20293.1A9B42C@localhost>
Priority: normal
In-reply-to: <20030422194057.GA15164@private>
References: <3EA527AB.5735.D96F9A@localhost>
X-mailer: Pegasus Mail for Windows (v4.02a)
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
Content-description: Mail message body
X-Spam-Status: No, hits=-20.5 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

> To me, the primary reasons for Owl to move to 2.4.x aren't the more
> extensive firewalling features, but rather availability of drivers for
> newer hardware (most importantly disk controllers) and improved kernel

That's a very good point.  I've stayed with the 3ware IDE RAID 
controllers for all of my Owl machines (which is well supported in 
2.2.x).  So, I haven't ran into driver issues yet.

> interfaces which allow to do neat things such as Olaf Kirch's
> non-SUID/SGID traceroute that behaves more like the traditional one.

I did not realize that.  Indeed that would be a nice benefit.  Is it 
possible in 2.2.x to have ping and traceroute use capabilities and 
drop all other root privs shortly after startup?

> Thank you for your feedback, -- it really helps.

You're welcome.  Thanks for Owl!

Steve Bremer
System & Security Administrator
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3MN2dO08721
	for <jwa@private>; Tue, 22 Apr 2003 16:02:40 -0700
Received: from ( [])
	by (Postfix) with SMTP id 6F10870
	for <jwa@private>; Tue, 22 Apr 2003 16:02:36 -0700 (PDT)
Received: (qmail 14152 invoked by uid 1011); 22 Apr 2003 23:02:18 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 14144 invoked from network); 22 Apr 2003 23:02:17 -0000
Date: Wed, 23 Apr 2003 03:01:00 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: Next Release
Message-ID: <20030422230100.GA774@private>
References: <3EA527AB.5735.D96F9A@localhost> <3EA55CFA.20293.1A9B42C@localhost>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <3EA55CFA.20293.1A9B42C@localhost>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-33.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Tue, Apr 22, 2003 at 03:17:15PM -0500, Steve Bremer wrote:
> Is it possible in 2.2.x to have ping and traceroute use capabilities
> and drop all other root privs shortly after startup?

They do already, -- before even parsing command line options.  And
this doesn't require capabilities, only a raw socket fd is kept.

But the real danger here isn't with ping and traceroute themselves,
but rather with generic SUID/SGID program startup code: in libc, in
the dynamic linker, and even in the kernel itself.  While the kernel
is highly privileged either way, there may still be logic errors in it
where the executing program's new effective credentials would be
leaked or misused.  We've seen several kernel vulnerabilities of this
nature in the past.

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3PAR2O14565
	for <jwa@private>; Fri, 25 Apr 2003 03:27:02 -0700
Received: from ( [])
	by (Postfix) with SMTP id 2E88970
	for <jwa@private>; Fri, 25 Apr 2003 03:25:41 -0700 (PDT)
Received: (qmail 25294 invoked by uid 1011); 25 Apr 2003 10:25:02 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 25286 invoked from network); 25 Apr 2003 10:25:01 -0000
Date: Fri, 25 Apr 2003 14:25:31 +0400 (MSD)
From: Lunar <lunar@private>
To: <owl-users@private>
Subject: Current ISO images
In-Reply-To: <20030422194057.GA15164@private>
Message-ID: <20030425141946.C76942-100000@private>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Status: No, hits=-4.2 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Dear Solar !

Some questions :

1. I see in current ISO

Owl-1.0-release-i386.iso.gz ->

but this old version , or current iso not exist ?

2. A you planed include  RBAC in Owl ?


Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3PEeZO24136
	for <jwa@private>; Fri, 25 Apr 2003 07:40:35 -0700
Received: from ( [])
	by (Postfix) with SMTP id 659B470
	for <jwa@private>; Fri, 25 Apr 2003 07:40:26 -0700 (PDT)
Received: (qmail 29517 invoked by uid 1011); 25 Apr 2003 14:40:02 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 29509 invoked from network); 25 Apr 2003 14:40:01 -0000
X-Qmail-Scanner-Mail-From: steveb@private via exmail
X-Qmail-Scanner: (Clear:. Processed in 0.069334 secs)
From: "Steve Bremer" <steveb@private>
Organization: NEBCO, Inc.
To: owl-users@private
Date: Fri, 25 Apr 2003 09:34:50 -0500
MIME-Version: 1.0
Subject: Re: Next Release
Message-ID: <3EA9013A.29895.1F44DE@localhost>
Priority: normal
In-reply-to: <20030422230100.GA774@private>
References: <3EA55CFA.20293.1A9B42C@localhost>
X-mailer: Pegasus Mail for Windows (v4.02a)
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
Content-description: Mail message body
X-Spam-Status: No, hits=-20.5 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

> But the real danger here isn't with ping and traceroute themselves,
> but rather with generic SUID/SGID program startup code: in libc, in
> the dynamic linker, and even in the kernel itself.  

Good point.  Doesn't matter how secure the app is written if the host 
is compromised before the app itself actually launches.  Using a 
static binary should eliminate the linker problem, but you're still left 
with bugs in libc and the kernel.  

Thanks for the info,
Steve Bremer
System & Security Administrator
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h3PF6VO25060
	for <jwa@private>; Fri, 25 Apr 2003 08:06:31 -0700
Received: from ( [])
	by (Postfix) with SMTP id 53ECD70
	for <jwa@private>; Fri, 25 Apr 2003 08:06:24 -0700 (PDT)
Received: (qmail 30187 invoked by uid 1011); 25 Apr 2003 15:06:04 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 30179 invoked from network); 25 Apr 2003 15:06:03 -0000
Date: Fri, 25 Apr 2003 19:05:11 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: Current ISO images
Message-ID: <20030425150511.GA8768@private>
References: <20030422194057.GA15164@private> <20030425141946.C76942-100000@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20030425141946.C76942-100000@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-33.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Fri, Apr 25, 2003 at 02:25:31PM +0400, Lunar wrote:
> 1. I see in current ISO
> Owl-1.0-release-i386.iso.gz ->
> ../../1.0-release/iso/Owl-1.0-release-i386.iso.gz
> but this old version , or current iso not exist ?

I haven't been generating current ISOs for a long time now.  You're
right in that it's time to generate one, or to make another release.
If the release will be getting delayed much further, I will probably
put out a new current-based ISO image.

But I don't see this as a major problem.  It's trivial to update to
current right upon installing 1.0 off a CD.

> 2. A you planed include  RBAC in Owl ?

I'll assume you mean RSBAC.  The short answer is: yes, but not soon.
In my opinion, it makes little sense to integrate RSBAC when there's
still so much room for improvement within the traditional Linux
kernel's abilities.

But I know that some people are currently using Owl with RSBAC.  We
even included a patch in our "dialog" package needed specifically for

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h4T3n9O30429
	for <jwa@private>; Wed, 28 May 2003 20:49:09 -0700
Received: from ( [])
	by (Postfix) with SMTP id AA3F570
	for <jwa@private>; Wed, 28 May 2003 20:49:05 -0700 (PDT)
Received: (qmail 5125 invoked by uid 1011); 29 May 2003 03:48:25 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 5117 invoked from network); 29 May 2003 03:48:24 -0000
Date: Thu, 29 May 2003 07:49:37 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Owl: tcb is now the default
Message-ID: <20030529034937.GA6828@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-13.5 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (


The latest Owl-current snapshot makes tcb the default password
shadowing scheme.  This affects both new installs and updating
existing ones: automatic conversion from /etc/shadow is attempted when
updating with "make installworld".

This automatic conversion won't be performed if /etc/nsswitch.conf is
locally-modified (as it will be if you unconvert a system from tcb).
However, as a number of configuration files now default to tcb,
maintaining and keeping updated a system with /etc/shadow is a little
more work than it used to be, -- for the sake of making it trivial to
stay with tcb.  I expect that 99% of Owl installs will use tcb.

The packages which have been touched for this change are listed in the
entry in CHANGES-current.

Please test and report any problems this might cause you before we
make it part of a release.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h4TGLmO28155
	for <jwa@private>; Thu, 29 May 2003 09:21:48 -0700
Received: from ( [])
	by (Postfix) with SMTP id 8537A70
	for <jwa@private>; Thu, 29 May 2003 09:21:41 -0700 (PDT)
Received: (qmail 27597 invoked by uid 1011); 29 May 2003 16:21:08 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 27587 invoked from network); 29 May 2003 16:21:08 -0000
Date: Thu, 29 May 2003 20:22:22 +0400
From: Solar Designer <solar@private>
To: Simon B <simonb@private>
Cc: owl-users@private
Subject: Re: Sparc Port
Message-ID: <20030529162222.GA8211@private>
References: <Pine.BSO.4.55.0305291056370.9295@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.BSO.4.55.0305291056370.9295@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Hi Simon,

I assume, you wanted to post this to owl-users (but mistyped the list
address as @owl instead of @lists), so I'll reply CC'ing the list.

On Thu, May 29, 2003 at 10:57:54AM +0100, Simon B wrote:
> Does anyone have a bootable ISO image for the Sparc port, or is it a
> DIY job?

Neither.  It's a piece of work on Owl that is waiting for a volunteer
to be completed.  This has been once discussed on owl-devel and Pedro
Inacio wanted to do it, but I don't think he ever did.

This work involves certain updates to the owl-cdrom package and more.

It is possible that I will just do it myself eventually, but so far I
have too many higher priority things to do and those I definitely can't
delegate to someone else.  So I leave this one for others.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h4TGaPO28997
	for <jwa@private>; Thu, 29 May 2003 09:36:25 -0700
Received: from ( [])
	by (Postfix) with SMTP id 977D970
	for <jwa@private>; Thu, 29 May 2003 09:36:22 -0700 (PDT)
Received: (qmail 28579 invoked by uid 1011); 29 May 2003 16:36:02 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 28564 invoked from network); 29 May 2003 16:36:01 -0000
Date: Thu, 29 May 2003 17:36:21 +0100 (BST)
From: Simon B <simonb@private>
To: Solar Designer <solar@private>
Cc: owl-users@private
Subject: Re: Sparc Port
In-Reply-To: <20030529162222.GA8211@private>
Message-ID: <Pine.BSO.4.55.0305291731380.24862@private>
References: <Pine.BSO.4.55.0305291056370.9295@private>
X-Copyright: (c)2003 Simon B.  Forwarding not allowed without prior permission.
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Status: No, hits=-35.6 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Thu, 29 May 2003, Solar Designer wrote:

SD! Hi Simon,
SD! I assume, you wanted to post this to owl-users (but mistyped the list
SD! address as @owl instead of @lists), so I'll reply CC'ing the list.

I *wondered* where my mail had gone ;-)

SD! On Thu, May 29, 2003 at 10:57:54AM +0100, Simon B wrote:
SD! > Does anyone have a bootable ISO image for the Sparc port, or is it a
SD! > DIY job?
SD! Neither.  It's a piece of work on Owl that is waiting for a volunteer
SD! to be completed.  This has been once discussed on owl-devel and Pedro
SD! Inacio wanted to do it, but I don't think he ever did.
SD! This work involves certain updates to the owl-cdrom package and more.
SD! It is possible that I will just do it myself eventually, but so far I
SD! have too many higher priority things to do and those I definitely can't
SD! delegate to someone else.  So I leave this one for others.

Yes.  I'm having some success using a Suse CDROM, installing a base system
on what will be /home and chrooting my way thru a make installworld.  It's
working so far, even if my little SS10 is *still* building a kernel...

Thanks for the info.  If I find an easier way to do it I'll be sure to let
people know.  I'm not confident I could invent a magic installer, which
would be the best solution ;-)

One day I'll stop looking for boxes to Owl'ise round here......


Simon B.                      spb!
        I am dyslexic of borg prepare to have your ass laminated
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h55F8LO14596
	for <jwa@private>; Thu, 5 Jun 2003 08:08:21 -0700
Received: from ( [])
	by (Postfix) with SMTP id BC16270
	for <jwa@private>; Thu,  5 Jun 2003 08:08:17 -0700 (PDT)
Received: (qmail 31877 invoked by uid 1011); 5 Jun 2003 15:06:35 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 31869 invoked from network); 5 Jun 2003 15:06:34 -0000
Message-ID: <20030605150606.27843.qmail@private>
From: "Ihsan" <ishobr@private>
To: owl-users@private
Subject: stmpclean problem
Date: Thu, 05 Jun 2003 22:06:06 +0700
Mime-Version: 1.0
Content-Type: text/plain; format=flowed; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Sender: ishobr@private
X-Spam-Status: No, hits=-7.2 required=5.0
X-Spam-Checker-Version: SpamAssassin 2.53 (

I just deleted by accident very large number of non root file on my server.
And that's happen after I run this command: 

# cd /var/spool/mailfilter/tmp
# stmpclean ./ 

Looks like stmpclean interpreted "./" as "/". 

A lost all of non root file on /var and /home. This trashing stop on /proc/, 
on /var/log/messages I find this: 

.... stmpclean[16747]: RACE?: isemptydir(): opendir("fd") in /proc/13703: 
Permission denied, exiting 

May be someone familiar with smtpclean can explain this problem? 

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h561nhO10239
	for <jwa@private>; Thu, 5 Jun 2003 18:49:43 -0700
Received: from ( [])
	by (Postfix) with SMTP id 9E19670
	for <jwa@private>; Thu,  5 Jun 2003 18:49:34 -0700 (PDT)
Received: (qmail 17906 invoked by uid 1011); 6 Jun 2003 01:49:08 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 17896 invoked from network); 6 Jun 2003 01:49:07 -0000
Date: Fri, 6 Jun 2003 05:49:16 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: stmpclean problem
Message-ID: <20030606014916.GA24875@private>
References: <20030605150606.27843.qmail@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20030605150606.27843.qmail@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (


This is Bcc'ed to the author of stmpclean.

I've confirmed the problem.  Unfortunately.

stmpclean simply expects to see absolute pathnames on its command
line, such as /tmp.  When it receives a relative one instead, it
interprets it relative to the root directory, not the current one.
A rather unfortunate behavior.

We'll think if we can quickly enough come up with a fix better than
refusing to work with non-absolute pathnames.  (stmpclean cd's to /
before starting the work not without a reason.)

On Thu, Jun 05, 2003 at 10:06:06PM +0700, Ihsan wrote:
> I just deleted by accident very large number of non root file on my server.
> And that's happen after I run this command: 
> # cd /var/spool/mailfilter/tmp
> # stmpclean ./ 
> Looks like stmpclean interpreted "./" as "/". 
> A lost all of non root file on /var and /home. This trashing stop on 
> /proc/, on /var/log/messages I find this: 
> .... stmpclean[16747]: RACE?: isemptydir(): opendir("fd") in /proc/13703: 
> Permission denied, exiting 
> May be someone familiar with smtpclean can explain this problem? 
> ishobr
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h56JkZO12080
	for <jwa@private>; Fri, 6 Jun 2003 12:46:35 -0700
Received: from ( [])
	by (Postfix) with SMTP id C0B6A70
	for <jwa@private>; Fri,  6 Jun 2003 12:46:31 -0700 (PDT)
Received: (qmail 13208 invoked by uid 1011); 6 Jun 2003 19:45:53 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Delivered-To: moderator for owl-users@private
Received: (qmail 24278 invoked from network); 6 Jun 2003 05:31:45 -0000
To: Solar Designer <solar@private>, owl-users@private
Subject: Re: stmpclean problem
References: <20030605150606.27843.qmail@private> <20030606014916.GA24875@private>
From: stanislav shalunov <shalunov@private>
Date: 06 Jun 2003 01:31:40 -0400
In-Reply-To: <20030606014916.GA24875@private>
Message-ID: <87vfvj6abn.fsf@private>
Lines: 28
X-Mailer: Gnus v5.7/Emacs 20.4
X-Virus-Scanned: by AMaViS 0.3.12pre8
X-Spam-Status: No, hits=-19.3 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (


While stmpclean is not supposed to be used to clean up directories
other than publicly writable temporary stores (/tmp, /var/tmp, and
such), there's no excuse for what it did to your filesystem.  There's
no way you could have foreseen such drastic action as interpreting
`./' as `/' and then going around your whole system looking for things
to delete.  This was an unforseen consequence of an action that seemed
to make sense; I simply haven't considered the case of relative
pathnames---obviously.  I am sorry about this.


I will make modifications that should prevent such harmless usage
mistake from becoming a disaster again.  There doesn't appear to be
any significant drawback to not allowing relative pathnames, so I'll
check for `/' as the first character of the directory name as given on
the command line.  I'm also considering checking permissions and
making sure it's 1777 and refusing to run otherwise to minimize the
chances of people using the utility in unintended ways.  (In a
non-publicly-writable directory, `find | xargs rm' is safe.)

Opinions about the permissions check?

Stanislav Shalunov

This message is designed to be viewed in boustrophedon.
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h573wMO32232
	for <jwa@private>; Fri, 6 Jun 2003 20:58:22 -0700
Received: from ( [])
	by (Postfix) with SMTP id 518FB70
	for <jwa@private>; Fri,  6 Jun 2003 20:58:19 -0700 (PDT)
Received: (qmail 24628 invoked by uid 1011); 7 Jun 2003 03:57:55 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 24615 invoked from network); 7 Jun 2003 03:57:54 -0000
Date: Sat, 7 Jun 2003 07:58:12 +0400
From: Solar Designer <solar@private>
To: owl-users@private, stanislav shalunov <shalunov@private>
Subject: Re: stmpclean problem
Message-ID: <20030607035812.GA27353@private>
References: <20030605150606.27843.qmail@private> <20030606014916.GA24875@private> <87vfvj6abn.fsf@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <87vfvj6abn.fsf@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Fri, Jun 06, 2003 at 01:31:40AM -0400, stanislav shalunov wrote:
> I will make modifications that should prevent such harmless usage
> mistake from becoming a disaster again.  There doesn't appear to be
> any significant drawback to not allowing relative pathnames, so I'll
> check for `/' as the first character of the directory name as given on
> the command line.

Currently, the chdir("/") is also done to ensure logging uses absolute
pathnames.  This means that you will need to do realpath(3) or an
equivalent on any relative pathnames for logging, right?

> I'm also considering checking permissions and
> making sure it's 1777 and refusing to run otherwise to minimize the
> chances of people using the utility in unintended ways.

This may be a good idea, but it will break valid uses, including even
the default use on Owl:

david!root:~# cat /etc/cron.daily/stmpclean 
# $Id: stmpclean.cron,v 1.1 2002/03/30 01:13:18 solar Exp $

/usr/sbin/stmpclean -t 10d /tmp /var/tmp

if [ -d /var/catman ]; then
        /usr/sbin/stmpclean -t 10d /var/catman/{,X11R6/,local/}cat[123456789n]

david!root:~# ls -ld /var/catman/{,X11R6/,local/}cat[123456789n] | head
drwxrwxr-x    2 root     man          4096 Jun  6 05:28 /var/catman/cat1
drwxrwxr-x    2 root     man          4096 May 16 04:43 /var/catman/cat2
drwxrwxr-x    2 root     man          4096 May 16 04:43 /var/catman/cat3
drwxrwxr-x    2 root     man          4096 May 16 04:43 /var/catman/cat4
drwxrwxr-x    2 root     man          4096 May 16 04:43 /var/catman/cat5
drwxrwxr-x    2 root     man          4096 May 16 04:43 /var/catman/cat6
drwxrwxr-x    2 root     man          4096 May 16 04:43 /var/catman/cat7
drwxrwxr-x    2 root     man          4096 May 16 04:43 /var/catman/cat8
drwxrwxr-x    2 root     man          4096 May 16 04:43 /var/catman/cat9
drwxrwxr-x    2 root     man          4096 May 16 04:43 /var/catman/catn

This really needs to be stmpclean (or another race-safe program)
because the /var/catman tree is writable by group "man".  It shouldn't
be possible to mount additional attacks having obtained that level of

> (In a non-publicly-writable directory, `find | xargs rm' is safe.)

Not necessarily.  A directory tree may contain directories writable by
non-root users or by groups.  Alternatively, it may not contain
writable directories, but its contents may still be untrusted and the
above "find" command will produce unintended behavior on certain
special characters in filenames (it may be solved with "find -print0",
"xargs -0", and "rm --").

Our version of find has the "-delete" option, which allows for its
safe use in cases like these.  But stmpclean may be better suited for
cleaning directories from old files.

> Opinions about the permissions check?

Maybe make it the default, but allow for a way to bypass it or
explicitly specify alternate permissions (and owner/group?) to check
for.  But is it worth the hassle?

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h575X7O03592
	for <jwa@private>; Fri, 6 Jun 2003 22:33:07 -0700
Received: from ( [])
	by (Postfix) with SMTP id B3EA170
	for <jwa@private>; Fri,  6 Jun 2003 22:33:03 -0700 (PDT)
Received: (qmail 27353 invoked by uid 1011); 7 Jun 2003 05:32:40 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 27324 invoked from network); 7 Jun 2003 05:32:39 -0000
To: Solar Designer <solar@private>
Cc: owl-users@private
Subject: Re: stmpclean problem
References: <20030605150606.27843.qmail@private> <20030606014916.GA24875@private> <87vfvj6abn.fsf@private> <20030607035812.GA27353@private>
From: stanislav shalunov <shalunov@private>
Date: 07 Jun 2003 01:32:33 -0400
In-Reply-To: <20030607035812.GA27353@private>
Message-ID: <87adcuzc3y.fsf@private>
Lines: 34
X-Mailer: Gnus v5.7/Emacs 20.4
X-Virus-Scanned: by AMaViS 0.3.12pre8
X-Spam-Status: No, hits=-35.5 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Solar Designer <solar@private> writes:

> Currently, the chdir("/") is also done to ensure logging uses absolute
> pathnames.  This means that you will need to do realpath(3) or an
> equivalent on any relative pathnames for logging, right?

Right.  So I wanted to avoid that rathole by requiring absolute
pathnames on the command line (realpath() should work fine on Linux,
but, being a nonstandard---even if widely available function---might
not be there on other systems; besides the CAVEATS section of its man
page on FreeBSD mentions that Solaris realpath() `will, under certain
circumstances, return a relative resolved_path when given a relative

The current behavior of silently treating relative paths as relative
to `/' clearly violates the Principle Of Least Astonishment.  It
should not be violated by bailing on relative pathnames and should not
inconvenience users too much.

> [permissions=1777 check] may be a good idea, but it will break valid
> uses, including even the default use on Owl:

OK, you convinced me that it might not be a good idea after all.
Clearing man catfiles (and, I now notice, teTeX METAFONT-generated pk
fonts) requires stmpclean-like functionality, so it makes sense to
make sure stmpclean can do that job.

How about I check for `/' as the first char of the pathname from the
command line and refuse to run if it's not there?

Stanislav Shalunov

This message is designed to be viewed upside down.
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h57DXjO22178
	for <jwa@private>; Sat, 7 Jun 2003 06:33:45 -0700
Received: from ( [])
	by (Postfix) with SMTP id A370870
	for <jwa@private>; Sat,  7 Jun 2003 06:33:32 -0700 (PDT)
Received: (qmail 4994 invoked by uid 1011); 7 Jun 2003 13:33:04 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 4983 invoked from network); 7 Jun 2003 13:33:03 -0000
Date: Sat, 7 Jun 2003 17:33:14 +0400
From: Solar Designer <solar@private>
To: stanislav shalunov <shalunov@private>
Cc: owl-users@private
Subject: Re: stmpclean problem
Message-ID: <20030607133314.GA30788@private>
References: <20030605150606.27843.qmail@private> <20030606014916.GA24875@private> <87vfvj6abn.fsf@private> <20030607035812.GA27353@private> <87adcuzc3y.fsf@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <87adcuzc3y.fsf@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Sat, Jun 07, 2003 at 01:32:33AM -0400, stanislav shalunov wrote:
> How about I check for `/' as the first char of the pathname from the
> command line and refuse to run if it's not there?

That's what I was going to do for a quick fix.  If you do it in an
official stmpclean release in a few days, then I'll just import that.

Thank you!

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h59FAIO29679
	for <jwa@private>; Mon, 9 Jun 2003 08:10:18 -0700
Received: from ( [])
	by (Postfix) with SMTP id 3A08370
	for <jwa@private>; Mon,  9 Jun 2003 08:10:14 -0700 (PDT)
Received: (qmail 13546 invoked by uid 1011); 9 Jun 2003 15:09:32 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 13538 invoked from network); 9 Jun 2003 15:09:31 -0000
From: Fridtjof Busse <owl-list@private>
To: owl-users@private
Subject: PPP
Date: Mon, 9 Jun 2003 17:09:31 +0200
X-OS: Linux on i686
MIME-Version: 1.0
Content-Type: text/plain;
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Message-Id: <200306091709.31015@private>
X-Spam-Status: No, hits=-7.2 required=5.0
X-Spam-Checker-Version: SpamAssassin 2.53 (

Is there any way to install Owl with ppp/pppoe out of the box, i.e. 
without installing it manually after having installed Owl?
I didn't find a ppp-package, so it seems not to be possible.
Will this package maybe added in the future?
BTW: When will postfix be updated to 2.0 or at least 1.1? This 1999 
build is really old now :) Especially the proxymap in 2.0 is very 
useful for chroot-setup.
Fridtjof Busse
/* When we have more time, we can teach the penguin to say 
 * "By your command" or "Activating turbo boost, Michael".
	2.2.16 /usr/src/linux/arch/sparc/prom/sun4prom.c
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h5B19dO31767
	for <jwa@private>; Tue, 10 Jun 2003 18:09:39 -0700
Received: from ( [])
	by (Postfix) with SMTP id 4A42170
	for <jwa@private>; Tue, 10 Jun 2003 18:09:30 -0700 (PDT)
Received: (qmail 1402 invoked by uid 1011); 11 Jun 2003 01:08:55 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 1393 invoked from network); 11 Jun 2003 01:08:54 -0000
Date: Wed, 11 Jun 2003 05:08:49 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: PPP
Message-ID: <20030611010849.GB13009@private>
References: <200306091709.31015@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <200306091709.31015@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Mon, Jun 09, 2003 at 05:09:31PM +0200, Fridtjof Busse wrote:
> Is there any way to install Owl with ppp/pppoe out of the box, i.e. 
> without installing it manually after having installed Owl?

No, we don't provide them out of the box yet.

> I didn't find a ppp-package, so it seems not to be possible.
> Will this package maybe added in the future?

ppp -- yes, quite likely.
pppoe -- probably not, although you're not the first one asking.

Meanwhile, the ppp package found in Red Hat Rawhide builds on Owl
without a single problem (rpminit; rpm --rebuild ppp-*.src.rpm).

> BTW: When will postfix be updated to 2.0 or at least 1.1? This 1999 
> build is really old now :)

Well, the patchlevel and back-ports we're using are newer than that,
but you're right in that it's high time to get it updated.

> Especially the proxymap in 2.0 is very useful for chroot-setup.

We're working on an update to 2.0.x.  Yes, the new package will use

As for a time estimate, I don't know.  This depends on a volunteer
who's doing it in his spare time.  But it's on my list of things which
need to be done before Owl 1.1 and I wouldn't want to delay that for
too long.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h5BFY1O25368
	for <jwa@private>; Wed, 11 Jun 2003 08:34:01 -0700
Received: from ( [])
	by (Postfix) with SMTP id AA02A70
	for <jwa@private>; Wed, 11 Jun 2003 08:33:43 -0700 (PDT)
Received: (qmail 25246 invoked by uid 1011); 11 Jun 2003 15:33:10 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Delivered-To: moderator for owl-users@private
Received: (qmail 8759 invoked from network); 11 Jun 2003 05:25:25 -0000
From: Fridtjof Busse <fridtjof@private>
To: owl-users@private
Subject: Re: PPP
Date: Wed, 11 Jun 2003 07:25:24 +0200
References: <200306091709.31015@private> <20030611010849.GB13009@private>
In-Reply-To: <20030611010849.GB13009@private>
X-OS: Linux on i686
MIME-Version: 1.0
Content-Type: text/plain;
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Message-Id: <200306110725.24153@private>
X-Spam-Status: No, hits=-33.7 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Wednesday 11 June 2003 03:08, Solar Designer wrote:
> > I didn't find a ppp-package, so it seems not to be possible.
> > Will this package maybe added in the future?
> ppp -- yes, quite likely.
> pppoe -- probably not, although you're not the first one asking.

I'd be really happy if Owl was capable of DSL/Modem-connections out of 
the box.

> Meanwhile, the ppp package found in Red Hat Rawhide builds on Owl
> without a single problem (rpminit; rpm --rebuild ppp-*.src.rpm).

I'll look into that, thanks.

> > Especially the proxymap in 2.0 is very useful for chroot-setup.
> We're working on an update to 2.0.x.  Yes, the new package will use
> proxymap.

OK, that's fine.
If you can need any help, just let me know :)

Fridtjof Busse
Mind your own business, Spock.  I'm sick of your halfbreed interference.
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h767xPO31368
	for <jwa@private>; Wed, 6 Aug 2003 00:59:25 -0700
Received: from ( [])
	by (Postfix) with SMTP id A6ADA70
	for <jwa@private>; Wed,  6 Aug 2003 00:59:20 -0700 (PDT)
Received: (qmail 23877 invoked by uid 1011); 6 Aug 2003 07:58:44 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 23869 invoked from network); 6 Aug 2003 07:58:42 -0000
X-Authentication-Warning: lunar owned process doing -bs
Date: Wed, 6 Aug 2003 11:58:26 +0400 (MSD)
From: Lunar <lunar@private>
To: owl-users@private
Subject: Re: stmpclean problem
In-Reply-To: <20030606014916.GA24875@private>
Message-ID: <20030806115704.B38208@private>
References: <20030605150606.27843.qmail@private>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Status: No, hits=-18.3 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Hi !

Solar, what you think about upgrade postfix up to 2.x version ?

B.R. Lunar
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h768xGO01851
	for <jwa@private>; Wed, 6 Aug 2003 01:59:17 -0700
Received: from ( [])
	by (Postfix) with SMTP id 3512C70
	for <jwa@private>; Wed,  6 Aug 2003 01:59:09 -0700 (PDT)
Received: (qmail 29232 invoked by uid 1011); 6 Aug 2003 08:58:45 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 29222 invoked from network); 6 Aug 2003 08:58:45 -0000
Message-ID: <3F30C36B.9010309@private>
Date: Wed, 06 Aug 2003 12:59:23 +0400
From: Michael Tokarev <mjt@private>
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.3) Gecko/20030327 Debian/1.3-4
X-Accept-Language: en, ru
MIME-Version: 1.0
To: owl-users@private
Subject: Re: stmpclean problem
References: <20030605150606.27843.qmail@private> <20030606014916.GA24875@private> <20030806115704.B38208@private>
In-Reply-To: <20030806115704.B38208@private>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Lunar wrote:
> Hi !
> Solar, what you think about upgrade postfix up to 2.x version ?

I'm working on this.  I promised to package postfix for Owl quite
some time ago.  It is a shame for me it is still not done.

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h7710jO29699
	for <jwa@private>; Wed, 6 Aug 2003 18:00:45 -0700
Received: from ( [])
	by (Postfix) with SMTP id 0BF18E0
	for <jwa@private>; Wed,  6 Aug 2003 18:00:34 -0700 (PDT)
Received: (qmail 32154 invoked by uid 1011); 7 Aug 2003 01:00:11 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 32145 invoked from network); 7 Aug 2003 01:00:09 -0000
Date: Thu, 7 Aug 2003 04:22:33 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Postfix (Re: stmpclean problem)
Message-ID: <20030807002233.GA1150@private>
References: <20030605150606.27843.qmail@private> <20030606014916.GA24875@private> <20030806115704.B38208@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20030806115704.B38208@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Wed, Aug 06, 2003 at 11:58:26AM +0400, Lunar wrote:
> Solar, what you think about upgrade postfix up to 2.x version ?

It should and will be done.

But it's not related to the Postfix DoS that Michal has discovered
recently (and gave us advance notification).  The reason I chose to
not fix that for Owl urgently is that our Postfix is based off a
version that is old enough to not be affected in the default

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h7CMWFO26993
	for <jwa@private>; Tue, 12 Aug 2003 15:32:15 -0700
Received: from ( [])
	by (Postfix) with SMTP id 4FD7A70
	for <jwa@private>; Tue, 12 Aug 2003 15:32:11 -0700 (PDT)
Received: (qmail 14741 invoked by uid 1011); 12 Aug 2003 22:31:29 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 14733 invoked from network); 12 Aug 2003 22:31:28 -0000
From: "Dudek Paragliding - Wojtek Domanski" <wojtek@private>
To: <owl-users@private>
Subject: ST5481 USB ISDN modem in kernel 2.2.x
Date: Wed, 13 Aug 2003 00:31:39 +0200
Message-ID: <001601c36121$7f78e3f0$669a63d9@private>
MIME-Version: 1.0
Content-Type: text/plain;
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
In-Reply-To: <1060694464.10093.ezmlm@private>
Importance: Normal
X-Spam-Status: No, hits=-10.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (


I have a passive ISDN/USB modem that requires: "ST5481 USB ISDN modem
(EXPERIMENTAL)" feature to be enabled in a kernel configuration. This
feature is available in kernels 2.4.x and is NOT available in kernels 2.2.x.
According to your advice, I would prefer to run my Owl-ISDN_access_router on
2.2.x kernel (I can use ready ipchains scripts from init.d instead of
configuring my own iptables scripts, etc.).

Is there a way to link "ST5481 USB ISDN modem (EXPERIMENTAL)" code to kernel
Where shall I look for a description of it?

With best regards,
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h7D4eGO08919
	for <jwa@private>; Tue, 12 Aug 2003 21:40:16 -0700
Received: from ( [])
	by (Postfix) with SMTP id 3067170
	for <jwa@private>; Tue, 12 Aug 2003 21:40:10 -0700 (PDT)
Received: (qmail 8655 invoked by uid 1011); 13 Aug 2003 04:39:49 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 8646 invoked from network); 13 Aug 2003 04:39:48 -0000
Date: Wed, 13 Aug 2003 08:45:04 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: ST5481 USB ISDN modem in kernel 2.2.x
Message-ID: <20030813044504.GA4635@private>
References: <1060694464.10093.ezmlm@private> <001601c36121$7f78e3f0$669a63d9@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <001601c36121$7f78e3f0$669a63d9@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (


On Wed, Aug 13, 2003 at 12:31:39AM +0200, Dudek Paragliding - Wojtek Domanski wrote:
> I have a passive ISDN/USB modem that requires: "ST5481 USB ISDN modem
> (EXPERIMENTAL)" feature to be enabled in a kernel configuration. This
> feature is available in kernels 2.4.x and is NOT available in kernels 2.2.x.
> According to your advice, I would prefer to run my Owl-ISDN_access_router on
> 2.2.x kernel (I can use ready ipchains scripts from init.d instead of
> configuring my own iptables scripts, etc.).

While, yes, 2.2.x may be preferred, staying with 2.2.x is not
necessarily worth it at this time and in your case.  If the driver was
in 2.2.x, that's what you would install.  But as the driver is not
there, it's easiest for you to go with 2.4.x which Owl supports as
well and ensure you keep it up to date (the latest 2.4.x-ow patch).

If you pick Linux 2.4.x, you absolutely need to use 2.4.21-ow2
currently.  (For 2.2.x, as old as 2.2.22 which was released last year
is still reasonable to keep on some existing installs.  You can't do
that for 2.4.x, too many 2.4.x-specific critical security holes have
been fixed since then.)

As for using ipchains, they work (somewhat) with netfilter in 2.4.x if
you build the kernel with that feature.

We do plan to package iptables and make 2.4.x kernels the default
(while leaving support for 2.2.x as well) for Owl 1.1.  Then drop
support for Linux 2.2.x in post-1.1 Owl-current (probably not very
soon, but it will happen eventually).

> Is there a way to link "ST5481 USB ISDN modem (EXPERIMENTAL)" code to kernel
> 2.2.x?
> Where shall I look for a description of it?

I'm not familiar with that driver and can't answer your question
without looking into it myself.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h7FBwOO17428
	for <jwa@private>; Fri, 15 Aug 2003 04:58:24 -0700
Received: from ( [])
	by (Postfix) with SMTP id E229870
	for <jwa@private>; Fri, 15 Aug 2003 04:58:20 -0700 (PDT)
Received: (qmail 5338 invoked by uid 1011); 15 Aug 2003 11:57:38 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 5330 invoked from network); 15 Aug 2003 11:57:37 -0000
X-Authentication-Warning: lunar owned process doing -bs
Date: Fri, 15 Aug 2003 15:58:07 +0400 (MSD)
From: Lunar <lunar@private>
To: owl-users@private
Subject: Re: ST5481 USB ISDN modem in kernel 2.2.x
In-Reply-To: <20030813044504.GA4635@private>
Message-ID: <20030815155609.N47132@private>
References: <1060694464.10093.ezmlm@private>
 <001601c36121$7f78e3f0$669a63d9@private> <20030813044504.GA4635@private>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Status: No, hits=-34.5 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Hello !

On Wed, 13 Aug 2003, Solar Designer wrote:

> Hi,
> On Wed, Aug 13, 2003 at 12:31:39AM +0200, Dudek Paragliding - Wojtek Domanski wrote:
> > I have a passive ISDN/USB modem that requires: "ST5481 USB ISDN modem
> > (EXPERIMENTAL)" feature to be enabled in a kernel configuration. This
> > feature is available in kernels 2.4.x and is NOT available in kernels 2.2.x.
> > According to your advice, I would prefer to run my Owl-ISDN_access_router on
> > 2.2.x kernel (I can use ready ipchains scripts from init.d instead of
> > configuring my own iptables scripts, etc.).
> While, yes, 2.2.x may be preferred, staying with 2.2.x is not
> necessarily worth it at this time and in your case.  If the driver was
> in 2.2.x, that's what you would install.  But as the driver is not
> there, it's easiest for you to go with 2.4.x which Owl supports as
> well and ensure you keep it up to date (the latest 2.4.x-ow patch).
> If you pick Linux 2.4.x, you absolutely need to use 2.4.21-ow2
> currently.  (For 2.2.x, as old as 2.2.22 which was released last year
> is still reasonable to keep on some existing installs.  You can't do
> that for 2.4.x, too many 2.4.x-specific critical security holes have
> been fixed since then.)

Solar, may be use 2.6.xx for OWL Release 1.1 ? The Kernel 2.4.x have more
bad strings, so as :

Copyright (c) International Business Machines Corp., 2001 This program is
free software; you can redistribute it and/or modify it under the terms of
the GNU General Public License as published by the Free Software
Foundation; either version 2 of the License, or (at your option) any later
version. This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
Public License for more details. You should have received a copy of the
GNU General Public License along with this program; if not, write to the
Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA
02111-1307, USA. Author: Dipankar Sarma (Based on a Dynix/ptx
implementation by Paul Mckenney

> As for using ipchains, they work (somewhat) with netfilter in 2.4.x if
> you build the kernel with that feature.
> We do plan to package iptables and make 2.4.x kernels the default
> (while leaving support for 2.2.x as well) for Owl 1.1.  Then drop
> support for Linux 2.2.x in post-1.1 Owl-current (probably not very
> soon, but it will happen eventually).
> > Is there a way to link "ST5481 USB ISDN modem (EXPERIMENTAL)" code to kernel
> > 2.2.x?
> > Where shall I look for a description of it?
> I'm not familiar with that driver and can't answer your question
> without looking into it myself.
> --
> Alexander Peslyak <solar@private>
> GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598
> - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h7FHeGO01268
	for <jwa@private>; Fri, 15 Aug 2003 10:40:16 -0700
Received: from ( [])
	by (Postfix) with SMTP id 01D0D70
	for <jwa@private>; Fri, 15 Aug 2003 10:40:06 -0700 (PDT)
Received: (qmail 27839 invoked by uid 1011); 15 Aug 2003 17:39:31 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 27830 invoked from network); 15 Aug 2003 17:39:30 -0000
Date: Fri, 15 Aug 2003 21:42:49 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: ST5481 USB ISDN modem in kernel 2.2.x
Message-ID: <20030815174249.GA8283@private>
References: <1060694464.10093.ezmlm@private> <001601c36121$7f78e3f0$669a63d9@private> <20030813044504.GA4635@private> <20030815155609.N47132@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20030815155609.N47132@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Fri, Aug 15, 2003 at 03:58:07PM +0400, Lunar wrote:
> On Wed, 13 Aug 2003, Solar Designer wrote:
> > If you pick Linux 2.4.x, you absolutely need to use 2.4.21-ow2
> > currently.  (For 2.2.x, as old as 2.2.22 which was released last year
> > is still reasonable to keep on some existing installs.  You can't do
> > that for 2.4.x, too many 2.4.x-specific critical security holes have
> > been fixed since then.)
> Solar, may be use 2.6.xx for OWL Release 1.1 ?

s/OWL/Owl/ please. ;-)

No, I don't see a valid reason to do so unless the release gets
delayed by at least a year. ;-)

> The Kernel 2.4.x have more bad strings, so as :
> Copyright (c) International Business Machines Corp., 2001 This program is
> free software; you can redistribute it and/or modify it under the terms of
> the GNU General Public License as published by the Free Software
> Foundation; either version 2 of the License, or (at your option) any later
> version. This program is distributed in the hope that it will be useful,
> but WITHOUT ANY WARRANTY; without even the implied warranty of
> Public License for more details. You should have received a copy of the
> GNU General Public License along with this program; if not, write to the
> Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA
> 02111-1307, USA. Author: Dipankar Sarma (Based on a Dynix/ptx
> implementation by Paul Mckenney

I don't understand what is so bad about those copyright notices and
what you're trying to say by it.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h7HN6RO09089
	for <jwa@private>; Sun, 17 Aug 2003 16:06:27 -0700
Received: from ( [])
	by (Postfix) with SMTP id 6F1C170
	for <jwa@private>; Sun, 17 Aug 2003 16:06:21 -0700 (PDT)
Received: (qmail 2895 invoked by uid 1011); 17 Aug 2003 23:05:41 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 2886 invoked from network); 17 Aug 2003 23:05:39 -0000
Message-ID: <3F400A27.4010009@private>
Date: Sun, 17 Aug 2003 18:05:11 -0500
From: Justin Heath <justin@private>
User-Agent: Mozilla/5.0 (X11; U; FreeBSD i386; en-US; rv:1.4) Gecko/20030726
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: owl-users@private
Subject: A few questions
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
X-Spam-Status: No, hits=-13.5 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (


I just installed Owl (current) an have a few questions. Where can I find 
an errata for bugs/security issues? On this note I do see a "Change Log" 
section that does have some Security fixes noted. It does note various 
levels of the security fixes listed such as "none", "medium" etc. Are 
these levels of the security fix defined somewhere? Also, I see a few 
mailing lists mentioned on the web page, is there an archive of these 
somewhere I can browse/search through? Any other advice for getting 
started with Owl?

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h7I6dUO29735
	for <jwa@private>; Sun, 17 Aug 2003 23:39:30 -0700
Received: from ( [])
	by (Postfix) with SMTP id F128AE0
	for <jwa@private>; Sun, 17 Aug 2003 23:39:16 -0700 (PDT)
Received: (qmail 994 invoked by uid 1011); 18 Aug 2003 06:38:48 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 986 invoked from network); 18 Aug 2003 06:38:48 -0000
X-Authentication-Warning: lunar owned process doing -bs
Date: Mon, 18 Aug 2003 10:38:17 +0400 (MSD)
From: Lunar <lunar@private>
To: owl-users@private
Subject: Re: ST5481 USB ISDN modem in kernel 2.2.x
In-Reply-To: <20030815174249.GA8283@private>
Message-ID: <20030818103705.J862@private>
References: <1060694464.10093.ezmlm@private>
 <001601c36121$7f78e3f0$669a63d9@private> <20030813044504.GA4635@private>
 <20030815155609.N47132@private> <20030815174249.GA8283@private>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Status: No, hits=-34.5 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Fri, 15 Aug 2003, Solar Designer wrote:

> On Fri, Aug 15, 2003 at 03:58:07PM +0400, Lunar wrote:
> > On Wed, 13 Aug 2003, Solar Designer wrote:
> > > If you pick Linux 2.4.x, you absolutely need to use 2.4.21-ow2
> > > currently.  (For 2.2.x, as old as 2.2.22 which was released last year
> > > is still reasonable to keep on some existing installs.  You can't do
> > > that for 2.4.x, too many 2.4.x-specific critical security holes have
> > > been fixed since then.)
> >
> > Solar, may be use 2.6.xx for OWL Release 1.1 ?
> s/OWL/Owl/ please. ;-)

Oops, sorry ;-)

> No, I don't see a valid reason to do so unless the release gets
> delayed by at least a year. ;-)
> > The Kernel 2.4.x have more bad strings, so as :
> >
> > Copyright (c) International Business Machines Corp., 2001 This program is
> > free software; you can redistribute it and/or modify it under the terms of
> > the GNU General Public License as published by the Free Software
> > Foundation; either version 2 of the License, or (at your option) any later
> > version. This program is distributed in the hope that it will be useful,
> > but WITHOUT ANY WARRANTY; without even the implied warranty of
> > Public License for more details. You should have received a copy of the
> > GNU General Public License along with this program; if not, write to the
> > Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA
> > 02111-1307, USA. Author: Dipankar Sarma (Based on a Dynix/ptx
> > implementation by Paul Mckenney
> I don't understand what is so bad about those copyright notices and
> what you're trying to say by it.

IMHO the kernel 2.6.x not include more codes from SCO development ;-)

> --
> Alexander Peslyak <solar@private>
> GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598
> - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h7J6X6O30377
	for <jwa@private>; Mon, 18 Aug 2003 23:33:07 -0700
Received: from ( [])
	by (Postfix) with SMTP id 2CA7570
	for <jwa@private>; Mon, 18 Aug 2003 23:32:45 -0700 (PDT)
Received: (qmail 18580 invoked by uid 1011); 19 Aug 2003 06:32:08 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 18571 invoked from network); 19 Aug 2003 06:32:07 -0000
Date: Tue, 19 Aug 2003 10:38:16 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: ST5481 USB ISDN modem in kernel 2.2.x
Message-ID: <20030819063816.GC4624@private>
References: <1060694464.10093.ezmlm@private> <001601c36121$7f78e3f0$669a63d9@private> <20030813044504.GA4635@private> <20030815155609.N47132@private> <20030815174249.GA8283@private> <20030818103705.J862@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20030818103705.J862@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-40.0 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Mon, Aug 18, 2003 at 10:38:17AM +0400, Lunar wrote:
> On Fri, 15 Aug 2003, Solar Designer wrote:
> > On Fri, Aug 15, 2003 at 03:58:07PM +0400, Lunar wrote:

> > > The Kernel 2.4.x have more bad strings, so as :
> > >
> > > Copyright (c) International Business Machines Corp., 2001 This program is
> > > free software; you can redistribute it and/or modify it under the terms of
> > > the GNU General Public License as published by the Free Software
> > > Foundation; either version 2 of the License, or (at your option) any later
> > > version. This program is distributed in the hope that it will be useful,
> > > but WITHOUT ANY WARRANTY; without even the implied warranty of
> > > Public License for more details. You should have received a copy of the
> > > GNU General Public License along with this program; if not, write to the
> > > Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA
> > > 02111-1307, USA. Author: Dipankar Sarma (Based on a Dynix/ptx
> > > implementation by Paul Mckenney
> >
> > I don't understand what is so bad about those copyright notices and
> > what you're trying to say by it.
> IMHO the kernel 2.6.x not include more codes from SCO development ;-)

I still don't get it.  There's no mention of SCO in the copyright
notices you've quoted and I have no problem with SCO (Caldera) or
anyone else owning copyright on a part of Linux kernel as long as
they've already released that part under GNU GPL.

I feel that you're missing something.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h7LNe1O22965
	for <jwa@private>; Thu, 21 Aug 2003 16:40:01 -0700
Received: from ( [])
	by (Postfix) with SMTP id 9EFFAE1
	for <jwa@private>; Thu, 21 Aug 2003 16:37:22 -0700 (PDT)
Received: (qmail 19826 invoked by uid 1011); 21 Aug 2003 23:36:40 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 19818 invoked from network); 21 Aug 2003 23:36:39 -0000
Date: Fri, 22 Aug 2003 03:42:38 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: A few questions
Message-ID: <20030821234238.GD20366@private>
References: <3F400A27.4010009@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <3F400A27.4010009@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (


On Sun, Aug 17, 2003 at 06:05:11PM -0500, Justin Heath wrote:
> I just installed Owl (current) an have a few questions. Where can I find 
> an errata for bugs/security issues? On this note I do see a "Change Log" 
> section that does have some Security fixes noted. It does note various 
> levels of the security fixes listed such as "none", "medium" etc. Are 
> these levels of the security fix defined somewhere?

I've been meaning to document those vulnerability severity ratings,
but so far there're only some past owl-users postings which should
give you an idea:

> Also, I see a few 
> mailing lists mentioned on the web page, is there an archive of these 
> somewhere I can browse/search through?

Actually, there's only one mailing list mentioned on the web page and
it's owl-users.  The other e-mail addresses mentioned are not mailing
lists.  You may browse owl-users archive on MARC:

We do have more mailing lists, but those are internal to the project.

> Any other advice for getting started with Owl?

It depends on what else you're looking for.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h8GCS8r11363
	for <jwa@private>; Tue, 16 Sep 2003 05:28:08 -0700
Received: from ( [])
	by (Postfix) with SMTP id 8EC9570
	for <jwa@private>; Tue, 16 Sep 2003 05:27:59 -0700 (PDT)
Received: (qmail 6202 invoked by uid 1011); 16 Sep 2003 12:27:15 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 6194 invoked from network); 16 Sep 2003 12:27:15 -0000
From: excapersgarden@private
To: owl-users@private
Subject: a graphical Owl
Date: Tue, 16 Sep 2003 12:26:33 +0000
User-Agent: KMail/1.5
MIME-Version: 1.0
Content-Type: text/plain;
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Message-Id: <200309161226.33326@ciaoiosonounheadrcustomizzato>
X-Spam-Status: No, hits=-6.1 required=5.0
X-Spam-Checker-Version: SpamAssassin 2.53 (

hi list,
i have searched in archives but i have found no answer.
i'm tryng to use Owl as primaty os because i like a lot this distro, but i 
need also a graphical context.

my optimus should be a kde 3.1 (with liquid style) and X 4.3.. 
but i'm opened to every solution.
in the condition of Owl 1.0 which are rpm, libraries or source i need
and what are the known problems with that (mainly at securiyt level)
or at graphical ie: with slk 9.0 and X 4.3 fonts look very bad nor with X 4.2.

tnx, a new but willing user.
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h8GKpRr05443
	for <jwa@private>; Tue, 16 Sep 2003 13:51:27 -0700
Received: from ( [])
	by (Postfix) with SMTP id 0527CE0
	for <jwa@private>; Tue, 16 Sep 2003 13:51:23 -0700 (PDT)
Received: (qmail 23645 invoked by uid 1011); 16 Sep 2003 20:51:01 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 23637 invoked from network); 16 Sep 2003 20:51:00 -0000
X-Qmail-Scanner-Mail-From: steveb@private via exmail
X-Qmail-Scanner: (Clear:. Processed in 0.407855 secs)
From: "Steve Bremer" <steveb@private>
Organization: NEBCO, Inc.
To: owl-users@private
Date: Tue, 16 Sep 2003 15:48:37 -0500
MIME-Version: 1.0
Subject: iproute2 & iputils fail to compile
Message-ID: <3F6730D3.25024.4BCA36C@localhost>
Priority: normal
X-mailer: Pegasus Mail for Windows (v4.11)
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
Content-description: Mail message body
X-Spam-Status: No, hits=-7.1 required=5.0
X-Spam-Checker-Version: SpamAssassin 2.53 (

	While building a new machine, I ran into troubles getting the above 
packages to compile.  They are being compiled against a 2.4.22 kernel 
source tree.  I thought the BUILD doc used to say that a 2.2 kernel 
tree was required to build user land, but the latest BUILD doc says a 
2.2 or 2.4 kernel will work.  Is a 2.2 kernel tree still required to 
build user land?
	Both packages are returning the same error messages.  I've included 
the relevant parts of the iproute2 build log below:

+ make KERNEL_INCLUDE=/usr/include 'CCOPTS=-pipe -march=i386 -
mcpu=i686 -O2 -fomit-frame-pointer -mpreferred-stack-boundary=2 -Wall 
-Wstrict-prototypes -D_GNU_SOURCE'
make[1]: Entering directory `/usr/src/world/rpm-work-
make[2]: Entering directory `/usr/src/world/rpm-work-
gcc -pipe -march=i386 -mcpu=i686 -O2 -fomit-frame-pointer -mpreferred-
stack-boundary=2 -Wall -Wstrict-prototypes -D_GNU_SOURCE -I../include-
glibc -include ../include-glibc/glibc-bugs.h -I/usr/include -
I../include -DRESOLVE_HOSTNAMES   -c -o ll_map.o ll_map.c
In file included from ../include-glibc/netinet/in.h:7,
                 from ll_map.c:19:
/usr/include/linux/in.h:140: field `gr_group' has incomplete type
/usr/include/linux/in.h:146: field `gsr_group' has incomplete type
/usr/include/linux/in.h:147: field `gsr_source' has incomplete type
/usr/include/linux/in.h:153: field `gf_group' has incomplete type
/usr/include/linux/in.h:156: field `gf_slist' has incomplete type
make[2]: *** [ll_map.o] Error 1
make[2]: Leaving directory `/usr/src/world/rpm-work-
make[1]: *** [all] Error 2
make[1]: Leaving directory `/usr/src/world/rpm-work-1/BUILD/iproute2'
Bad exit status from /usr/src/world/tmp-work/rpm-tmp.20124 (%build)
Command exited with non-zero status 1

These are the only two packages that failed (besides the arch 
specific ones).

Any help would be appreciated.

Steve Bremer
System & Security Administrator
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h8GKubr05584
	for <jwa@private>; Tue, 16 Sep 2003 13:56:37 -0700
Received: from ( [])
	by (Postfix) with SMTP id B32A2E1
	for <jwa@private>; Tue, 16 Sep 2003 13:56:33 -0700 (PDT)
Received: (qmail 24619 invoked by uid 1011); 16 Sep 2003 20:56:15 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 24610 invoked from network); 16 Sep 2003 20:56:14 -0000
X-Qmail-Scanner-Mail-From: steveb@private via exmail
X-Qmail-Scanner: (Clear:. Processed in 0.071804 secs)
From: "Steve Bremer" <steveb@private>
Organization: NEBCO, Inc.
To: owl-users@private
Date: Tue, 16 Sep 2003 15:54:07 -0500
MIME-Version: 1.0
Subject: Re: iproute2 & iputils fail to compile
Message-ID: <3F67321C.29183.4C1AACA@localhost>
Priority: normal
In-reply-to: <3F6730D3.25024.4BCA36C@localhost>
X-mailer: Pegasus Mail for Windows (v4.11)
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
Content-description: Mail message body
X-Spam-Status: No, hits=-10.3 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Forgot to mention that this is a build of current pulled early this 

Steve Bremer
System & Security Administrator
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h8GKxtr05718
	for <jwa@private>; Tue, 16 Sep 2003 13:59:55 -0700
Received: from ( [])
	by (Postfix) with SMTP id 5849BE0
	for <jwa@private>; Tue, 16 Sep 2003 13:59:53 -0700 (PDT)
Received: (qmail 25164 invoked by uid 1011); 16 Sep 2003 20:59:39 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 25156 invoked from network); 16 Sep 2003 20:59:38 -0000
Date: Wed, 17 Sep 2003 01:04:16 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: iproute2 & iputils fail to compile
Message-ID: <20030916210416.GA16798@private>
References: <3F6730D3.25024.4BCA36C@localhost>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <3F6730D3.25024.4BCA36C@localhost>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.3 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Hi Steve,

Thank you for the report.

On Tue, Sep 16, 2003 at 03:48:37PM -0500, Steve Bremer wrote:
> 	While building a new machine, I ran into troubles getting the above 
> packages to compile.  They are being compiled against a 2.4.22 kernel 
> source tree.  I thought the BUILD doc used to say that a 2.2 kernel 
> tree was required to build user land, but the latest BUILD doc says a 
> 2.2 or 2.4 kernel will work.  Is a 2.2 kernel tree still required to 
> build user land?

No, either 2.2.x or 2.4.x should do.  (But the produced binaries are
slightly different.  In particular, you only get Large File Support if
you build against 2.4.x.)

> 	Both packages are returning the same error messages.  I've included 
> the relevant parts of the iproute2 build log below:

> /usr/include/linux/in.h:140: field `gr_group' has incomplete type
> /usr/include/linux/in.h:146: field `gsr_group' has incomplete type
> /usr/include/linux/in.h:147: field `gsr_source' has incomplete type
> /usr/include/linux/in.h:153: field `gf_group' has incomplete type
> /usr/include/linux/in.h:156: field `gf_slist' has incomplete type

> These are the only two packages that failed (besides the arch 
> specific ones).

Something broke between 2.4.21 and 2.4.22.  I can reproduce this now,
and will deal with it.

Meanwhile, you can try with 2.4.21-ow2.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h8GLCLr06754
	for <jwa@private>; Tue, 16 Sep 2003 14:12:21 -0700
Received: from ( [])
	by (Postfix) with SMTP id 569A270
	for <jwa@private>; Tue, 16 Sep 2003 14:12:13 -0700 (PDT)
Received: (qmail 26828 invoked by uid 1011); 16 Sep 2003 21:11:55 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 26819 invoked from network); 16 Sep 2003 21:11:54 -0000
X-Qmail-Scanner-Mail-From: steveb@private via exmail
X-Qmail-Scanner: (Clear:. Processed in 0.071707 secs)
From: "Steve Bremer" <steveb@private>
Organization: NEBCO, Inc.
To: owl-users@private
Date: Tue, 16 Sep 2003 16:09:51 -0500
MIME-Version: 1.0
Subject: Re: iproute2 & iputils fail to compile
Message-ID: <3F6735CD.26014.4D01374@localhost>
Priority: normal
In-reply-to: <20030916210416.GA16798@private>
References: <3F6730D3.25024.4BCA36C@localhost>
X-mailer: Pegasus Mail for Windows (v4.11)
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
Content-description: Mail message body
X-Spam-Status: No, hits=-17.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

> Meanwhile, you can try with 2.4.21-ow2.

Will do.  

Thank you.

Steve Bremer
System & Security Administrator
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h8I9jGr06110
	for <jwa@private>; Thu, 18 Sep 2003 02:45:16 -0700
Received: from ( [])
	by (Postfix) with SMTP id 6977370
	for <jwa@private>; Thu, 18 Sep 2003 02:45:04 -0700 (PDT)
Received: (qmail 24636 invoked by uid 1011); 18 Sep 2003 09:44:17 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 24628 invoked from network); 18 Sep 2003 09:44:15 -0000
Date: Thu, 18 Sep 2003 13:48:50 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: a graphical Owl
Message-ID: <20030918094850.GA11225@private>
References: <200309161226.33326@ciaoiosonounheadrcustomizzato>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <200309161226.33326@ciaoiosonounheadrcustomizzato>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Tue, Sep 16, 2003 at 12:26:33PM +0000, excapersgarden@private wrote:
> i'm tryng to use Owl as primaty os because i like a lot this distro, but i 
> need also a graphical context.
> my optimus should be a kde 3.1 (with liquid style) and X 4.3.. 
> but i'm opened to every solution.
> in the condition of Owl 1.0 which are rpm, libraries or source i need
> and what are the known problems with that (mainly at securiyt level)
> or at graphical ie: with slk 9.0 and X 4.3 fonts look very bad nor with X 4.2.

While Owl is intended for servers and we have no intent to ever
include X in the base system, yes, you can also use it on a desktop if
you like.  I do.

There're several approaches:

1. Use binary packages from Red Hat Linux 6.2 updates, or from a RHL
6.x clone.  This is probably the easiest.  There're just two caveats
that I remember: their X server package relies on pam_console, which
we chose to not package, and xlock will need special permissions to
work on Owl.

The first is solved by replacing the pam_console line in
/etc/pam.d/xserver with:

auth       required     /lib/security/ item=user sense=allow onerr=fail file=/etc/xserver.allow

Then you list the users which need to run X in /etc/xserver.allow.

The second is solved by making /usr/X11R6/bin/xlock SGID to group
chkpwd, like this:

-rwx--s--x    1 root     chkpwd     751328 Mar 30  2001 /usr/X11R6/bin/xlock

I've tested this setup with WindowMaker as the window manager.  I
don't use or like KDE, sorry.

The obvious drawback of this approach is that the versions of XFree86
and other software you may install in this way are rather old.  Some
may also contain known vulnerabilities (you'd get less if you bother
to check RHL 6.2 updates).

2. Try and build newer packages, such as from Red Hat Rawhide.  Some
will likely require minor tweaking of RPM .spec files, so be prepared.
I haven't tried this for XFree86 itself, but I built things such as
Mozilla on Owl in this way.

3. Build everything from source, without the use of packages, and
install under /usr/local.  I know people have been doing that:

Some generic advices on using X reasonably safely:

It's a good idea to create group xusers and restrict access to either
the X server binary or to /usr/X11R6/bin/Xwrapper (make it mode 4710,

Make sure you either filter the X server ports (6000/tcp and a few
above it in case you ever run a second, third, etc. instance of X
server), or tell it to not listen for TCP connections (start it as
"startx -- -nolisten tcp").  Note that if you use SSH X11 forwarding,
the SSH client will need to be permitted to connect to your X server
via TCP locally.

In order to use xlock meaningfully, you may start X by adding these
lines to your /etc/profile.d/ (create one):

if [ "`tty`" = "/dev/tty1" -a -n "`fgrep -x "$USER" /etc/xserver.allow`" ]; then
	exec startx -- -nolisten tcp

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h8UIoVr10203
	for <jwa@private>; Tue, 30 Sep 2003 11:50:31 -0700
Received: from ( [])
	by (Postfix) with SMTP id 0BAAF70
	for <jwa@private>; Tue, 30 Sep 2003 11:50:26 -0700 (PDT)
Received: (qmail 30123 invoked by uid 1011); 30 Sep 2003 18:49:50 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 30115 invoked from network); 30 Sep 2003 18:49:49 -0000
Date: Tue, 30 Sep 2003 15:43:57 -0300
Message-ID: <>
From: "Vinicius Moreira Mello" <vinicius@private>
Subject: Pump package
To: owl-users@private
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Spam-Status: No, hits=-7.2 required=5.0
X-Spam-Checker-Version: SpamAssassin 2.53 (

I installed openwall and noticed that there is no pump package nor any ot=
dchp client, although in the initialization scripts there is a reference
to /sbin/pump. I looked for packages in the ftp and didn't find. Where is=

the pump package?

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h8UJZRr12220
	for <jwa@private>; Tue, 30 Sep 2003 12:35:27 -0700
Received: from ( [])
	by (Postfix) with SMTP id E0CFEE0
	for <jwa@private>; Tue, 30 Sep 2003 12:35:24 -0700 (PDT)
Received: (qmail 3846 invoked by uid 1011); 30 Sep 2003 19:35:03 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 3835 invoked from network); 30 Sep 2003 19:35:03 -0000
Date: Tue, 30 Sep 2003 20:35:18 +0100 (BST)
From: Simon B <simonb@private>
To: owl-users@private
Subject: Re: a graphical Owl
In-Reply-To: <20030918094850.GA11225@private>
Message-ID: <Pine.BSO.4.58.0309302032170.7120@private>
References: <200309161226.33326@ciaoiosonounheadrcustomizzato>
X-include: <stupid/disclaimer.h>
X-Copyright: (c)2003 Simon B.  Forwarding not allowed without prior permission.
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Status: No, hits=-22.6 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Just another item to add to the X discussion...

I've built Mozilla Firebird for Owl, as the default one you
can download from complains the Glibc is too old.



Simon B.                      spb!
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h8UKwUr15174
	for <jwa@private>; Tue, 30 Sep 2003 13:58:30 -0700
Received: from ( [])
	by (Postfix) with SMTP id 922B470
	for <jwa@private>; Tue, 30 Sep 2003 13:58:27 -0700 (PDT)
Received: (qmail 14617 invoked by uid 1011); 30 Sep 2003 20:58:04 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Delivered-To: moderator for owl-users@private
Received: (qmail 13908 invoked from network); 30 Sep 2003 20:50:55 -0000
Date: Tue, 30 Sep 2003 22:50:55 +0200
From: Matthias Schmidt <schmidt@private>
To: owl-users@private
Subject: Re: Pump package
Message-ID: <20030930205055.GB8323@private>
Mail-Followup-To: owl-users@private
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-16.7 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (


* Vinicius Moreira Mello wrote:
> I installed openwall and noticed that there is no pump package nor any other
> dchp client, although in the initialization scripts there is a reference
> to /sbin/pump. I looked for packages in the ftp and didn't find. Where is
> the pump package?

There is no pump package in Owl, but you can use dhclient from the dhcp
package (native/Owl/packages/dhcp).

Set BUILD_DHCP_CLIENT to 1 in dhcp.spec, recompile and install
dhcp-client. Note: The client runs currently as user root without privilege
separation or anything else.

Matthias Schmidt
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h9129Wr27431
	for <jwa@private>; Tue, 30 Sep 2003 19:09:32 -0700
Received: from ( [])
	by (Postfix) with SMTP id D423BE0
	for <jwa@private>; Tue, 30 Sep 2003 19:09:24 -0700 (PDT)
Received: (qmail 26643 invoked by uid 1011); 1 Oct 2003 02:09:00 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 26632 invoked from network); 1 Oct 2003 02:08:59 -0000
Date: Wed, 1 Oct 2003 06:08:33 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: a graphical Owl
Message-ID: <20031001020833.GA25280@private>
References: <200309161226.33326@ciaoiosonounheadrcustomizzato> <20030918094850.GA11225@private> <Pine.BSO.4.58.0309302032170.7120@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.BSO.4.58.0309302032170.7120@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Tue, Sep 30, 2003 at 08:35:18PM +0100, Simon B wrote:
> Just another item to add to the X discussion...
> I've built Mozilla Firebird for Owl, as the default one you
> can download from complains the Glibc is too old.

It wasn't the case when I built Mozilla 1.1 on Owl a year ago.  You
can get the RPMs here:

Of course, this stuff is very unofficial and unsupported.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id h912Fpr27718
	for <jwa@private>; Tue, 30 Sep 2003 19:15:51 -0700
Received: from ( [])
	by (Postfix) with SMTP id DDAA270
	for <jwa@private>; Tue, 30 Sep 2003 19:15:48 -0700 (PDT)
Received: (qmail 27929 invoked by uid 1011); 1 Oct 2003 02:15:24 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 27899 invoked from network); 1 Oct 2003 02:15:22 -0000
Date: Wed, 1 Oct 2003 06:14:55 +0400
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: Pump package
Message-ID: <20031001021455.GA25311@private>
References: <>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Tue, Sep 30, 2003 at 03:43:57PM -0300, Vinicius Moreira Mello wrote:
> I installed openwall and noticed that there is no pump package nor any other
> dchp client, although in the initialization scripts there is a reference
> to /sbin/pump.

That's a leftover from Red Hat's networking scripts.  We should
replace them, it's on TODO.

> I looked for packages in the ftp and didn't find. Where is
> the pump package?

There won't be one.  But as Matthias has pointed out, there's the dhcp
package which by default builds as DHCP server only.  You can enable
building the client as well, but you do so at your own risk.  This is
because the TODO item for a DHCP client isn't completed yet:

[ASSIGNED: schmidt@, solar@]
The DHCP client should be modified to run as a dedicated pseudo-user
and in a chroot jail.  This requires privilege separation within the
client (not easy).

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hA9Ig4F09679
	for <jwa@private>; Sun, 9 Nov 2003 10:42:04 -0800
Received: from ( [])
	by (Postfix) with SMTP id CA07B70
	for <jwa@private>; Sun,  9 Nov 2003 10:42:00 -0800 (PST)
Received: (qmail 2804 invoked by uid 1011); 9 Nov 2003 18:41:17 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 2772 invoked from network); 9 Nov 2003 18:41:15 -0000
Date: Sun, 9 Nov 2003 21:38:16 +0300
From: Solar Designer <solar@private>
To: announce@private, owl-users@private
Subject: Owl-current 2003/11/03 ISO image / CDs available; pam_passwdqc 0.7.5
Message-ID: <20031109183816.GA30407@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-13.5 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (


As Openwall GNU/*/Linux (Owl) is approaching a new release, I have
started generating ISO images of the current branch snapshots.  The
latest snapshot dated 2003/11/03 is also available with the CD orders
you may place off the web page:

Alternatively, it may be downloaded from /pub/Owl/current/iso/ on the
FTP mirrors listed at:

This is the first Owl ISO image / CD to officially use Linux 2.4.x
kernels (2.4.22-ow1 currently).  Linux 2.2.x remains supported too.

On another topic, there's a new version of pam_passwdqc, the password
strength checking PAM module.  pam_passwdqc 0.7.5 will now assume
invocation by root only if both the UID is 0 and the PAM service name
is "passwd"; this should fix changing expired passwords on Solaris
and HP-UX and make "enforce=users" safe.  The proper English
explanations of requirements for strong passwords will now be
generated for a wider variety of possible settings.  pam_passwdqc is
available at:

Of course, this new version of pam_passwdqc is also a part of the
Owl-current snapshot above.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hAQFmPZ23251
	for <jwa@private>; Wed, 26 Nov 2003 07:48:25 -0800
Received: from ( [])
	by (Postfix) with SMTP id 37C3370
	for <jwa@private>; Wed, 26 Nov 2003 07:48:17 -0800 (PST)
Received: (qmail 17584 invoked by uid 1011); 26 Nov 2003 15:47:23 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 17576 invoked from network); 26 Nov 2003 15:47:23 -0000
To: owl-users@private
Subject: Bug in Postfix remove script
X-Favourite-Drink: Cherry-Coke
X-Favourite-Pizza-Place: Anker
Organization: Towarzystwo
X-Jabber-Id: maciekp@private
X-Balcerowicz: Musi odejsc!
From: Maciek Pasternacki <maciekp@private>
Date: Wed, 26 Nov 2003 16:47:16 +0100
Message-ID: <8765h76sjf.fsf@private>
User-Agent: Gnus/5.1003 (Gnus v5.10.3) Emacs/21.2 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Status: No, hits=-19.8 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

I use Owl with qmail as MTA, so I don't need Postfix on my system;
when I try to uninstall Postfix, rpm script quits with an error

rmdir: `/var/spool/postfix/[^m]*': No such file or directory

When I create any subdirectory under /var/spool/postfix not starting
with `m', everything works fine, but IMHO this is a bug in Postfix'
preun script.  Following patch (made against current CVS version of
the native tree) should fix the problem:

diff -u -r1.19 postfix.spec
--- packages/postfix/postfix.spec	30 Oct 2003 21:15:47 -0000	1.19
+++ packages/postfix/postfix.spec	26 Nov 2003 15:45:32 -0000
@@ -183,7 +183,7 @@
 	rm -f /etc/postfix/aliases.db
 	find /var/spool/postfix \( -type p -o -type s \) -delete
 	rm -f /var/spool/postfix/{pid,etc,lib}/*
-	rmdir /var/spool/postfix/[^m]*
+	rmdir /var/spool/postfix/[^m]* || true
 %files -f filelist

__    Maciek Pasternacki <maciekp@private> [ ]
`| _   |_\  / { claimed all this time that you would die for me,
,|{-}|}| }\/ why then are you so surprised when you hear your own eulogy... }
\/   |____/                                             ( M. J. Keenan )  -><-
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hAQGjIZ26040
	for <jwa@private>; Wed, 26 Nov 2003 08:45:18 -0800
Received: from ( [])
	by (Postfix) with SMTP id 94A6FE0
	for <jwa@private>; Wed, 26 Nov 2003 08:45:14 -0800 (PST)
Received: (qmail 26791 invoked by uid 1011); 26 Nov 2003 16:44:52 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 26783 invoked from network); 26 Nov 2003 16:44:52 -0000
Date: Wed, 26 Nov 2003 17:44:15 +0100 (CET)
From: Andreas Ericsson <exon@private>
To: owl-users@private
Subject: Re: Bug in Postfix remove script
In-Reply-To: <8765h76sjf.fsf@private>
Message-ID: <Pine.LNX.4.58.0311261700290.6218@private>
References: <8765h76sjf.fsf@private>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Status: No, hits=-38.6 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

> rmdir: `/var/spool/postfix/[^m]*': No such file or directory
> When I create any subdirectory under /var/spool/postfix not starting
> with `m', everything works fine, but IMHO this is a bug in Postfix'
> preun script.  Following patch (made against current CVS version of
> the native tree) should fix the problem:

> #v+
> diff -u -r1.19 postfix.spec
> --- packages/postfix/postfix.spec	30 Oct 2003 21:15:47 -0000	1.19
> +++ packages/postfix/postfix.spec	26 Nov 2003 15:45:32 -0000
> @@ -183,7 +183,7 @@
>  	rm -f /etc/postfix/aliases.db
>  	find /var/spool/postfix \( -type p -o -type s \) -delete
>  	rm -f /var/spool/postfix/{pid,etc,lib}/*
> -	rmdir /var/spool/postfix/[^m]*
> +	rmdir /var/spool/postfix/[^m]* || true
> fi
> %files -f filelist
> #v-

This will cause rpm to happily move on no matter what the error, which
isn't the intended behaviour.
'find' will fail on access violations only, which will work properly in
case rpm administration has been delegated (to wheel, for instance).
The neater fix follows.

diff -u -r1.19 postfix.spec
--- packages/postfix/postfix.spec	30 Oct 2003 21:15:47 -0000	1.19
+++ packages/postfix/postfix.spec	26 Nov 2003 15:45:32 -0000
@@ -183,7 +183,7 @@
 	rm -f /etc/postfix/aliases.db
 	find /var/spool/postfix \( -type p -o -type s \) -delete
 	rm -f /var/spool/postfix/{pid,etc,lib}/*
-	rmdir /var/spool/postfix/[^m]*
+	find /var/spool/postfix \( -type d -name "[^m]*" \) -delete

%files -f filelist

/Andreas Ericsson

I don't know this .spec (or even the rpm program's man page) by heart.
There might be a better / easier / neater fix available.
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hAQHx6Z28867
	for <jwa@private>; Wed, 26 Nov 2003 09:59:06 -0800
Received: from ( [])
	by (Postfix) with SMTP id 389EB70
	for <jwa@private>; Wed, 26 Nov 2003 09:59:03 -0800 (PST)
Received: (qmail 3646 invoked by uid 1011); 26 Nov 2003 17:58:38 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 3638 invoked from network); 26 Nov 2003 17:58:37 -0000
Date: Wed, 26 Nov 2003 20:54:37 +0300
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: Bug in Postfix remove script
Message-ID: <20031126175437.GA5243@private>
References: <8765h76sjf.fsf@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <8765h76sjf.fsf@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Wed, Nov 26, 2003 at 04:47:16PM +0100, Maciek Pasternacki wrote:
> I use Owl with qmail as MTA, so I don't need Postfix on my system;
> when I try to uninstall Postfix, rpm script quits with an error
> message:
> rmdir: `/var/spool/postfix/[^m]*': No such file or directory
> When I create any subdirectory under /var/spool/postfix not starting
> with `m', everything works fine, but IMHO this is a bug in Postfix'
> preun script.

Thank you for reporting this.  However, I cannot reproduce it here.

Those directories are normally created by the invocation of
"/usr/sbin/postfix check" from the %post script.  This means that if
you've installed Postfix cleanly and didn't mess with the install, it
will also uninstall cleanly.  It does here.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hAQI41Z29452
	for <jwa@private>; Wed, 26 Nov 2003 10:04:01 -0800
Received: from ( [])
	by (Postfix) with SMTP id 1B8F670
	for <jwa@private>; Wed, 26 Nov 2003 10:03:59 -0800 (PST)
Received: (qmail 4382 invoked by uid 1011); 26 Nov 2003 18:03:37 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 4374 invoked from network); 26 Nov 2003 18:03:36 -0000
Date: Wed, 26 Nov 2003 20:59:35 +0300
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: Bug in Postfix remove script
Message-ID: <20031126175935.GA5456@private>
References: <8765h76sjf.fsf@private> <Pine.LNX.4.58.0311261700290.6218@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.LNX.4.58.0311261700290.6218@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-38.6 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Wed, Nov 26, 2003 at 05:44:15PM +0100, Andreas Ericsson wrote:
> > -	rmdir /var/spool/postfix/[^m]*
> > +	rmdir /var/spool/postfix/[^m]* || true

> This will cause rpm to happily move on no matter what the error, which
> isn't the intended behaviour.

Actually it is.

The purpose of this rmdir is to remove directories which are empty,
but leave around those which aren't such that you don't lose your
queued e-mail messages just because you happened to (temporarily?)
uninstall Postfix.

If you install Postfix but don't use it and just uninstall, then
everything gets removed cleanly.

> -	rmdir /var/spool/postfix/[^m]*
> +	find /var/spool/postfix \( -type d -name "[^m]*" \) -delete

This is very different: find is recursive.  A similar effect to the
rmdir may be achieved with find -maxdepth 1, but I don't see the need.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hAQISPZ30200
	for <jwa@private>; Wed, 26 Nov 2003 10:28:25 -0800
Received: from ( [])
	by (Postfix) with SMTP id 2194A70
	for <jwa@private>; Wed, 26 Nov 2003 10:28:17 -0800 (PST)
Received: (qmail 7498 invoked by uid 1011); 26 Nov 2003 18:27:55 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 7490 invoked from network); 26 Nov 2003 18:27:55 -0000
Date: Wed, 26 Nov 2003 19:27:21 +0100 (CET)
From: Andreas Ericsson <exon@private>
To: owl-users@private
Subject: Re: Bug in Postfix remove script
In-Reply-To: <20031126175935.GA5456@private>
Message-ID: <Pine.LNX.4.58.0311261913300.12871@private>
References: <8765h76sjf.fsf@private> <Pine.LNX.4.58.0311261700290.6218@private>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Status: No, hits=-32.3 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

> On Wed, Nov 26, 2003 at 05:44:15PM +0100, Andreas Ericsson wrote:
> > > -	rmdir /var/spool/postfix/[^m]*
> > > +	rmdir /var/spool/postfix/[^m]* || true
> > This will cause rpm to happily move on no matter what the error, which
> > isn't the intended behaviour.
> Actually it is.
Then what's the point of having rpm break on errors?

> The purpose of this rmdir is to remove directories which are empty,
> but leave around those which aren't such that you don't lose your
> queued e-mail messages just because you happened to (temporarily?)
> uninstall Postfix.
And with the fix, everything but the 'maildrop' directory and
any directory the user hasn't got access to will be removed.
Isn't that the general idea? (I'm trying to learn something here)

> If you install Postfix but don't use it and just uninstall, then
> everything gets removed cleanly.
With exception of the rare times when installation halts before or
during %post due to some error or the user pressing Ctrl-C because
they don't want postfix.


"Woohoo!! ... Doh!"
	-- Homer Simpson
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hAQIhXZ31088
	for <jwa@private>; Wed, 26 Nov 2003 10:43:33 -0800
Received: from ( [])
	by (Postfix) with SMTP id BDB4270
	for <jwa@private>; Wed, 26 Nov 2003 10:43:26 -0800 (PST)
Received: (qmail 9854 invoked by uid 1011); 26 Nov 2003 18:43:02 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 9831 invoked from network); 26 Nov 2003 18:43:01 -0000
Date: Wed, 26 Nov 2003 21:38:57 +0300
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: Bug in Postfix remove script
Message-ID: <20031126183857.GA5765@private>
References: <8765h76sjf.fsf@private> <Pine.LNX.4.58.0311261700290.6218@private> <20031126175935.GA5456@private> <Pine.LNX.4.58.0311261913300.12871@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.LNX.4.58.0311261913300.12871@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-39.2 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Wed, Nov 26, 2003 at 07:27:21PM +0100, Andreas Ericsson wrote:
> > On Wed, Nov 26, 2003 at 05:44:15PM +0100, Andreas Ericsson wrote:
> > > > -	rmdir /var/spool/postfix/[^m]*
> > > > +	rmdir /var/spool/postfix/[^m]* || true
> >
> > > This will cause rpm to happily move on no matter what the error, which
> > > isn't the intended behaviour.
> >
> > Actually it is.
> Then what's the point of having rpm break on errors?

It depends.  In %prep, %build, and %install scripts, we don't want a
broken package to get built.  In %pre, we don't want to install a
package if we can't do the preparations.  However, when it comes to
%post, %preun, and especially %postun, we most often want to continue
on errors (this does not imply we ignore them: we may choose to act
differently or at least to let an error message get displayed).

> > The purpose of this rmdir is to remove directories which are empty,
> > but leave around those which aren't such that you don't lose your
> > queued e-mail messages just because you happened to (temporarily?)
> > uninstall Postfix.
> And with the fix,

I'm not sure which fix you're referring to here.

> everything but the 'maildrop' directory

This one is a part of the package and will be removed by RPM itself,
this is why we don't to remove it manually.

(Actually, the entire Postfix package will change as we update to
2.0.x and things will be done differently.)

> and any directory the user hasn't got access to

I'm not sure what you mean here.

> will be removed.
> Isn't that the general idea? (I'm trying to learn something here)

I think I've explained it already: all directories which don't hold
queued messages are to be removed on uninstall.  Those which do are
left around in case of re-install or for manual removal, -- the admin
has to make that decision explicitly and the "rmdir" will report any
such non-empty directory such that the admin will get notified.

> > If you install Postfix but don't use it and just uninstall, then
> > everything gets removed cleanly.
> With exception of the rare times when installation halts before or
> during %post due to some error or the user pressing Ctrl-C because
> they don't want postfix.

Correct, -- and in that case a harmless error message on uninstall is
quite normal.  In fact, RPM itself can complain too.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hAQIqdZ31416
	for <jwa@private>; Wed, 26 Nov 2003 10:52:39 -0800
Received: from ( [])
	by (Postfix) with SMTP id 201C870
	for <jwa@private>; Wed, 26 Nov 2003 10:52:29 -0800 (PST)
Received: (qmail 11093 invoked by uid 1011); 26 Nov 2003 18:52:08 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 11085 invoked from network); 26 Nov 2003 18:52:08 -0000
Date: Wed, 26 Nov 2003 19:51:34 +0100 (CET)
From: Andreas Ericsson <exon@private>
To: owl-users@private
Subject: Re: Bug in Postfix remove script
In-Reply-To: <20031126183857.GA5765@private>
Message-ID: <Pine.LNX.4.58.0311261948230.14685@private>
References: <8765h76sjf.fsf@private> <Pine.LNX.4.58.0311261700290.6218@private>
 <20031126175935.GA5456@private> <Pine.LNX.4.58.0311261913300.12871@private>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Status: No, hits=-38.8 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Ah. I see things clearar now. ;)

/Andreas (too tired, too hungry, and still at work)

On Wed, 26 Nov 2003, Solar Designer wrote:

> On Wed, Nov 26, 2003 at 07:27:21PM +0100, Andreas Ericsson wrote:
> > > On Wed, Nov 26, 2003 at 05:44:15PM +0100, Andreas Ericsson wrote:
> > > > > -	rmdir /var/spool/postfix/[^m]*
> > > > > +	rmdir /var/spool/postfix/[^m]* || true
> > >
> > > > This will cause rpm to happily move on no matter what the error, which
> > > > isn't the intended behaviour.
> > >
> > > Actually it is.
> >
> > Then what's the point of having rpm break on errors?
> It depends.  In %prep, %build, and %install scripts, we don't want a
> broken package to get built.  In %pre, we don't want to install a
> package if we can't do the preparations.  However, when it comes to
> %post, %preun, and especially %postun, we most often want to continue
> on errors (this does not imply we ignore them: we may choose to act
> differently or at least to let an error message get displayed).
> > > The purpose of this rmdir is to remove directories which are empty,
> > > but leave around those which aren't such that you don't lose your
> > > queued e-mail messages just because you happened to (temporarily?)
> > > uninstall Postfix.
> >
> > And with the fix,
> I'm not sure which fix you're referring to here.
> > everything but the 'maildrop' directory
> This one is a part of the package and will be removed by RPM itself,
> this is why we don't to remove it manually.
> (Actually, the entire Postfix package will change as we update to
> 2.0.x and things will be done differently.)
> > and any directory the user hasn't got access to
> I'm not sure what you mean here.
> > will be removed.
> > Isn't that the general idea? (I'm trying to learn something here)
> I think I've explained it already: all directories which don't hold
> queued messages are to be removed on uninstall.  Those which do are
> left around in case of re-install or for manual removal, -- the admin
> has to make that decision explicitly and the "rmdir" will report any
> such non-empty directory such that the admin will get notified.
> > > If you install Postfix but don't use it and just uninstall, then
> > > everything gets removed cleanly.
> >
> > With exception of the rare times when installation halts before or
> > during %post due to some error or the user pressing Ctrl-C because
> > they don't want postfix.
> Correct, -- and in that case a harmless error message on uninstall is
> quite normal.  In fact, RPM itself can complain too.
> --
> Alexander Peslyak <solar@private>
> GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598
> - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hB98mOZ20256
	for <jwa@private>; Tue, 9 Dec 2003 00:48:24 -0800
Received: from ( [])
	by (Postfix) with SMTP id 2BDB470
	for <jwa@private>; Tue,  9 Dec 2003 00:48:12 -0800 (PST)
Received: (qmail 7120 invoked by uid 1011); 9 Dec 2003 08:47:35 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 7112 invoked from network); 9 Dec 2003 08:47:34 -0000
Date: Tue, 9 Dec 2003 09:54:06 +0100
To: owl-users@private
From: Robert Baranowski <robertik@private>
Subject: tc filter fwmark didn't work
Message-ID: <f1e5984eb5176cf4705e3766454bb414@private>
X-Priority: 3
X-Mailer: UebiMiau [PHPMailer version 1.70]
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset="iso-8859-2"
X-Spam-Status: No, hits=-6.4 required=5.0
X-Spam-Checker-Version: SpamAssassin 2.53 (

I have problem with tc filter fwmark.
My htb script:

tc qdisc add dev eth2 root handle 1:0 htb default 2
tc class add dev eth2 parent 1:0 classid 1:1 htb rate 500kbit ceil 500kbit
tc class add dev eth2 parent 1:1 classid 1:2 htb rate 512kbit ceil 512kbit
burst 15k
tc class add dev eth2 parent 1:1 classid 1:3 htb rate 500kbit ceil 500kbit
prio 9
tc qdisc add dev eth2 parent 1:3 sfq perturb 10
iptables: Chain already exists
tc class add dev eth2 parent 1:2 classid 1:20 htb rate 128kbit ceil 128kbit
burst 9k
tc filter add dev eth2 protocol ip parent 1:2 prio 9 u32 match ip dst flowid 1:20
iptables -t mangle -N
iptables -t mangle -A POSTROUTING -o eth2 -d -j
iptables -t mangle -A -o eth2 -s -d -j
MARK --set-mark 20
iptables -t mangle -A -o eth2 -s -d -j
MARK --set-mark 20
tc filter add dev eth2 protocol ip parent 1:1 prio 1 handle 20 fw flowid 1:
iptables -t mangle -A -o eth2 -p icmp -d -j MARK
--set-mark 21
tc class add dev eth2 parent 1:20 classid 1:21 htb rate 20kbit ceil 128kbit
burst 15k quantum 1500 prio 3
tc qdisc add dev eth2 parent 1:21 handle 21: sfq perturb 1
tc filter add dev eth2 protocol ip parent 1:20 prio 3 handle 21 fw flowid

It return no errors, but i can't see any tc filter on eth2 :(
I try iproute from htb home site, iproute2 compiled from source with

What is wromg ?
kernel 2.4.22-ow1, 2.4.23, 2.4.23+pom
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hB99LZZ21766
	for <jwa@private>; Tue, 9 Dec 2003 01:21:35 -0800
Received: from ( [])
	by (Postfix) with SMTP id A814F70
	for <jwa@private>; Tue,  9 Dec 2003 01:21:31 -0800 (PST)
Received: (qmail 11840 invoked by uid 1011); 9 Dec 2003 09:21:03 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 11832 invoked from network); 9 Dec 2003 09:21:03 -0000
Message-ID: <008401c3be35$c35cf860$4e72da91@private>
From: "Adam Sosnowski" <A.Sosnowski@private>
To: <owl-users@private>
References: <f1e5984eb5176cf4705e3766454bb414@private>
Subject: Re: tc filter fwmark didn't work
Date: Tue, 9 Dec 2003 10:21:01 +0100
Organization: Promexim Sp. z o.o.
MIME-Version: 1.0
Content-Type: text/plain;
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4922.1500
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4925.2800
X-Spam-Status: No, hits=-18.2 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

I had the same problem when I wanted to use HTB.
Problem is with "/sbin/tc". This "tc" is not supporting
( in my opinion ) the HTB. You have to download
new HTB from this url:
There should be the latest archive with patches called
htb3.6-020525.tgz. Inside this archive is new "tc".
If you will change the "tc" from "/sbin/tc" to the new one
every thing should work ok.

PS. You do not have to change original kernel.
       Of course the HTB should be compile in the kernel.
      I did it and in my OWL it is working just fine !!!

----- Original Message -----
From: "Robert Baranowski" <robertik@private>
To: <owl-users@private>
Sent: Tuesday, December 09, 2003 9:54 AM
Subject: tc filter fwmark didn't work

> I have problem with tc filter fwmark.
> My htb script:
> tc qdisc add dev eth2 root handle 1:0 htb default 2
> tc class add dev eth2 parent 1:0 classid 1:1 htb rate 500kbit ceil 500kbit
> tc class add dev eth2 parent 1:1 classid 1:2 htb rate 512kbit ceil 512kbit
> burst 15k
> tc class add dev eth2 parent 1:1 classid 1:3 htb rate 500kbit ceil 500kbit
> prio 9
> tc qdisc add dev eth2 parent 1:3 sfq perturb 10
> iptables: Chain already exists
> tc class add dev eth2 parent 1:2 classid 1:20 htb rate 128kbit ceil
> burst 9k
> tc filter add dev eth2 protocol ip parent 1:2 prio 9 u32 match ip dst
> flowid 1:20
> iptables -t mangle -N
> iptables -t mangle -A POSTROUTING -o eth2 -d -j
> iptables -t mangle -A -o eth2 -s -d -j
> MARK --set-mark 20
> iptables -t mangle -A -o eth2 -s -d -j
> MARK --set-mark 20
> tc filter add dev eth2 protocol ip parent 1:1 prio 1 handle 20 fw flowid
> iptables -t mangle -A -o eth2 -p icmp -d -j MARK
> --set-mark 21
> tc class add dev eth2 parent 1:20 classid 1:21 htb rate 20kbit ceil
> burst 15k quantum 1500 prio 3
> tc qdisc add dev eth2 parent 1:21 handle 21: sfq perturb 1
> tc filter add dev eth2 protocol ip parent 1:20 prio 3 handle 21 fw flowid
> 1:21
> It return no errors, but i can't see any tc filter on eth2 :(
> I try iproute from htb home site, iproute2 compiled from source with
> patches.
> What is wromg ?
> owl-current
> kernel 2.4.22-ow1, 2.4.23, 2.4.23+pom
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hB9AHnZ24226
	for <jwa@private>; Tue, 9 Dec 2003 02:17:49 -0800
Received: from ( [])
	by (Postfix) with SMTP id CF1C970
	for <jwa@private>; Tue,  9 Dec 2003 02:17:37 -0800 (PST)
Received: (qmail 19940 invoked by uid 1011); 9 Dec 2003 10:17:07 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 19932 invoked from network); 9 Dec 2003 10:17:07 -0000
Date: Tue, 9 Dec 2003 11:53:49 +0200
From: Michail Litvak <mci@private>
To: owl-users@private
Subject: Re: tc filter fwmark didn't work
Message-ID: <20031209115349.A13334@private>
References: <f1e5984eb5176cf4705e3766454bb414@private> <008401c3be35$c35cf860$4e72da91@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/
In-Reply-To: <008401c3be35$c35cf860$4e72da91@private>; from A.Sosnowski@private on Tue, Dec 09, 2003 at 10:21:01AM +0100
X-Spam-Status: No, hits=-22.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Hello Adam Sosnowski! 

 Tue, Dec 09, 2003 at 10:21:01AM +0100, A.Sosnowski wrote about "Re: tc filter fwmark didn't work": 

AS> I had the same problem when I wanted to use HTB.
AS> Problem is with "/sbin/tc". This "tc" is not supporting

Yes, so... tc in Owl lack of support htb3, because
Owl now support building with 2.2.x and 2.4.x kernel.

When we drop building Owl with 2.2.x kerenels - htb3 patch
will be included into iproute2 package.

AS> ( in my opinion ) the HTB. You have to download
AS> new HTB from this url:
AS> There should be the latest archive with patches called
AS> htb3.6-020525.tgz. Inside this archive is new "tc".
AS> If you will change the "tc" from "/sbin/tc" to the new one
AS> every thing should work ok.
AS> PS. You do not have to change original kernel.
AS>        Of course the HTB should be compile in the kernel.
AS>       I did it and in my OWL it is working just fine !!!

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hB9B9QZ26671
	for <jwa@private>; Tue, 9 Dec 2003 03:09:26 -0800
Received: from ( [])
	by (Postfix) with SMTP id 43299E0
	for <jwa@private>; Tue,  9 Dec 2003 03:09:22 -0800 (PST)
Received: (qmail 263 invoked by uid 1011); 9 Dec 2003 11:08:40 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 255 invoked from network); 9 Dec 2003 11:08:40 -0000
Message-ID: <00cf01c3be44$cc5238e0$4e72da91@private>
From: "Adam Sosnowski" <A.Sosnowski@private>
To: <owl-users@private>
References: <f1e5984eb5176cf4705e3766454bb414@private> <008401c3be35$c35cf860$4e72da91@private> <20031209115349.A13334@private>
Subject: Re: tc filter fwmark didn't work
Date: Tue, 9 Dec 2003 12:08:39 +0100
Organization: Promexim Sp. z o.o.
MIME-Version: 1.0
Content-Type: text/plain;
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4922.1500
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4925.2800
X-Spam-Status: No, hits=-19.7 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Hello Michail Litvak,

If my e-mail hurt you ore any body else


That was not my intention. I just wanted to help.
I know that in current OWL the CBQ is working
fine this is the standard every body should know it.
But I wanted something much simple and HTB
it just I was looking for.


----- Original Message -----
From: "Michail Litvak" <mci@private>
To: <owl-users@private>
Sent: Tuesday, December 09, 2003 10:53 AM
Subject: Re: tc filter fwmark didn't work

> Hello Adam Sosnowski!
>  Tue, Dec 09, 2003 at 10:21:01AM +0100, A.Sosnowski wrote about "Re: tc
filter fwmark didn't work":
> AS> I had the same problem when I wanted to use HTB.
> AS> Problem is with "/sbin/tc". This "tc" is not supporting
> Yes, so... tc in Owl lack of support htb3, because
> Owl now support building with 2.2.x and 2.4.x kernel.
> When we drop building Owl with 2.2.x kerenels - htb3 patch
> will be included into iproute2 package.
> AS> ( in my opinion ) the HTB. You have to download
> AS> new HTB from this url:
> AS> There should be the latest archive with patches called
> AS> htb3.6-020525.tgz. Inside this archive is new "tc".
> AS> If you will change the "tc" from "/sbin/tc" to the new one
> AS> every thing should work ok.
> AS>
> AS> PS. You do not have to change original kernel.
> AS>        Of course the HTB should be compile in the kernel.
> AS>       I did it and in my OWL it is working just fine !!!
> CU!
> --
> //ShaD0w
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hB9CYlZ30847
	for <jwa@private>; Tue, 9 Dec 2003 04:34:47 -0800
Received: from ( [])
	by (Postfix) with SMTP id 4CABCE0
	for <jwa@private>; Tue,  9 Dec 2003 04:34:42 -0800 (PST)
Received: (qmail 11587 invoked by uid 1011); 9 Dec 2003 12:34:10 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 11579 invoked from network); 9 Dec 2003 12:34:10 -0000
Date: Tue, 9 Dec 2003 13:40:58 +0100
To: owl-users@private
From: Robert Baranowski <robertik@private>
Subject: Odp: Re: tc filter fwmark didn't work
Message-ID: <2c720980867c92cda7b78fb880d5ff20@private>
X-Priority: 3
X-Mailer: UebiMiau [PHPMailer version 1.70]
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset="iso-8859-2"
X-Spam-Status: No, hits=-9.6 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

--------- Wiadomość oryginalna --------
Od: owl-users@private
Do: owl-users@private <owl-users@private>
Temat: Re: tc filter fwmark didn't work
Data: 09/12/03 10:28

> I had the same problem when I wanted to use HTB.
> Problem is with &quot;/sbin/tc&quot;. This &quot;tc&quot; is not
> ( in my opinion ) the HTB. You have to download
> new HTB from this url:
> There should be the latest archive with patches called
> htb3.6-020525.tgz. Inside this archive is new &quot;tc&quot;.
> If you will change the &quot;tc&quot; from &quot;/sbin/tc&quot; to the new
> every thing should work ok.

But it didn't work, i have this tc.
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hBN1X7Z08925
	for <jwa@private>; Mon, 22 Dec 2003 17:33:07 -0800
Received: from ( [])
	by (Postfix) with SMTP id C6C7D70
	for <jwa@private>; Mon, 22 Dec 2003 17:33:00 -0800 (PST)
Received: (qmail 30608 invoked by uid 1011); 23 Dec 2003 01:32:24 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 30577 invoked from network); 23 Dec 2003 01:32:21 -0000
Date: Tue, 23 Dec 2003 04:26:01 +0300
From: Solar Designer <solar@private>
To: announce@private
Cc: owl-users@private, lwn@private
Subject: Openwall GNU/*/Linux (Owl) 1.1 release
Message-ID: <20031223012601.GA4344@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-12.7 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (


For those few who don't know yet, Openwall GNU/*/Linux (or Owl) is a
security-enhanced operating system with Linux and GNU software as its
core, intended as a server platform.  More detailed information is
available on the web site:

After another year of development Owl 1.1 release is finally out.

Owl 1.1 is currently available for purchase on a CD and will also be
available for download after January 7, 2004.  Owl 1.1 CDs may be
ordered online with delivery worldwide via this web page:

The major changes made since 1.0 release are documented:

CDs are bootable on x86 and include a live system, x86 binary
packages for installation to a hard disk, and full source code which
may be rebuilt with one simple command ("make buildworld").  Security
tools such as John the Ripper and Nmap are usable right off the CD,
without requiring a hard disk, -- and indeed they're also available
with Owl installs you make.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hBN1vYZ09557
	for <jwa@private>; Mon, 22 Dec 2003 17:57:35 -0800
Received: from ( [])
	by (Postfix) with SMTP id 771D270
	for <jwa@private>; Mon, 22 Dec 2003 17:57:29 -0800 (PST)
Received: (qmail 1385 invoked by uid 1011); 23 Dec 2003 01:57:12 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Delivered-To: moderator for owl-users@private
Received: (qmail 1053 invoked from network); 23 Dec 2003 01:54:06 -0000
To: owl-users@private
Subject: Re: Openwall GNU/*/Linux (Owl) 1.1 release
X-Favourite-Drink: Cherry-Coke
X-Favourite-Pizza-Place: Anker
Organization: Towarzystwo
X-Jabber-Id: maciekp@private
X-Balcerowicz: Musi odejsc!
In-Reply-To: <20031223012601.GA4344@private> (Solar Designer's message
	of "Tue, 23 Dec 2003 04:26:01 +0300")
References: <20031223012601.GA4344@private>
Date: Tue, 23 Dec 2003 02:53:59 +0100
Message-ID: <87y8t4e1u0.fsf@private>
User-Agent: Gnus/5.1002 (Gnus v5.10.2) Emacs/21.2 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
From: Maciek Pasternacki <maciekp@private>
X-Delivery-Agent: TMDA/0.80+ (Swaps)
X-TMDA-Fingerprint: cyf9CasH5MJggAnRdqj13VMAFhU
X-Spam-Status: No, hits=-39.4 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Boomtime, The Aftermath 65, 3169 YOLD, Solar Designer wrote:

> After another year of development Owl 1.1 release is finally out.

Is there any chance that Owl will include Perl in newer version than
current 5.6.0?  I am running Jabber server on Owl and some transports
written in Perl require libraries working only with Perl 5.6.1 or
later.  As for now I have Perl 5.8 installed from source in
/opt/perl58 and I use it only for these transports, but I'd be very
glad to have more recent version of the interpreter in the distribution.


__    Maciek Pasternacki <maciekp@private> [ ]
`| _   |_\  / { -It's possible that people in my life are actually detrimental
,|{-}|}| }\/ to what I'm trying to do right now--And what is it you're trying
\/   |____/ to do? -- I'm trying to stay sane. }         ( I Feel Sick )  -><-
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hBN29WZ10266
	for <jwa@private>; Mon, 22 Dec 2003 18:09:32 -0800
Received: from ( [])
	by (Postfix) with SMTP id A31E370
	for <jwa@private>; Mon, 22 Dec 2003 18:09:25 -0800 (PST)
Received: (qmail 2467 invoked by uid 1011); 23 Dec 2003 02:09:06 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 2459 invoked from network); 23 Dec 2003 02:09:05 -0000
Date: Tue, 23 Dec 2003 05:02:45 +0300
From: Solar Designer <solar@private>
To: owl-users@private
Subject: Re: Openwall GNU/*/Linux (Owl) 1.1 release
Message-ID: <20031223020245.GA4772@private>
References: <20031223012601.GA4344@private> <87y8t4e1u0.fsf@private>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <87y8t4e1u0.fsf@private>
User-Agent: Mutt/1.4.1i
X-Spam-Status: No, hits=-38.6 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

On Tue, Dec 23, 2003 at 02:53:59AM +0100, Maciek Pasternacki wrote:
> Is there any chance that Owl will include Perl in newer version than
> current 5.6.0?  I am running Jabber server on Owl and some transports
> written in Perl require libraries working only with Perl 5.6.1 or
> later.  As for now I have Perl 5.8 installed from source in
> /opt/perl58 and I use it only for these transports, but I'd be very
> glad to have more recent version of the interpreter in the distribution.

Of course.  This is something we should do before 2.0, but it's quite
some work to do it right, -- repeating the audit of 5.8+ for unsafe
temporary file handling issues as I know our fixes didn't get in (we
did submit, but they were not quick enough to review our patches while
Perl development continued and patches became outdated).

P.S. Please post to the list with a fixed envelope-from address, or
I'd have to approve each of your postings manually.

Alexander Peslyak <solar@private>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598 - bringing security into open computing environments
Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hBN2A3Z10313
	for <jwa@private>; Mon, 22 Dec 2003 18:10:03 -0800
Received: from ( [])
	by (Postfix) with SMTP id 9154F70
	for <jwa@private>; Mon, 22 Dec 2003 18:10:01 -0800 (PST)
Received: (qmail 2624 invoked by uid 1011); 23 Dec 2003 02:09:18 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 2609 invoked from network); 23 Dec 2003 02:09:18 -0000
From: Steve <steve@private>
To: owl-users@private
Subject: Re: Openwall GNU/*/Linux (Owl) 1.1 release
Date: Mon, 22 Dec 2003 20:09:36 -0600
User-Agent: KMail/1.5.4
References: <20031223012601.GA4344@private>
In-Reply-To: <20031223012601.GA4344@private>
MIME-Version: 1.0
Content-Type: Text/Plain;
Content-Transfer-Encoding: quoted-printable
Content-Description: clearsigned data
Content-Disposition: inline
Message-Id: <200312222009.37037.steve@private>
X-Spam-Status: No, hits=-37.3 required=5.0
	autolearn=ham version=2.53
X-Spam-Checker-Version: SpamAssassin 2.53 (

Hash: SHA1

> After another year of development Owl 1.1 release is finally out.

Excellent.  Kudos to all of the Owl Developers!

=2D --=20
Steve Bremer
=2D --
Real Men don't make backups. They upload it via ftp and let the world=20
mirror it. -- Linus Torvalds
=2D --
GnuPG Key fingerprint =3D 7F06 4D73 7963 BE96 5189  953A E285 CB2C BA03 2746
Available on key servers.

Version: GnuPG v1.2.3 (GNU/Linux)

Return-Path: <>
Received: from ( [])
	by (8.11.6/8.11.6) with ESMTP id hBTFqlv01104
	for <jwa@private>; Mon, 29 Dec 2003 07:52:47 -0800
Received: from ( [])
	by (Postfix) with SMTP id 5B43670
	for <jwa@private>; Mon, 29 Dec 2003 07:52:40 -0800 (PST)
Received: (qmail 29540 invoked by uid 1011); 29 Dec 2003 15:52:01 -0000
Mailing-List: contact owl-users-help@private; run by ezmlm
Precedence: bulk
List-Post: <mailto:owl-users@private>
List-Help: <mailto:owl-users-help@private>
List-Unsubscribe: <mailto:owl-users-unsubscribe@private>
List-Subscribe: <mailto:owl-users-subscribe@private>
Reply-To: owl-users@private
Delivered-To: mailing list owl-users@private
Received: (qmail 29532 invoked from network); 29 Dec 2003 15:52:01 -0000
From: "Benjamin Lutz" <bl@private>
To: <owl-users@private>
Subject: How to install Owl remote using an existing Linux installation
Date: Mon, 29 Dec 2003 16:51:57 +0100
Message-ID: <000001c3ce23$b0ed6130$0601a8c0@win32>
MIME-Version: 1.0
Content-Type: text/plain;
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Provags-ID: abuse@private auth:f6e337ce49203e843f5213b9ca99edbd
X-Spam-Status: No, hits=-0.6 required=5.0
X-Spam-Checker-Version: SpamAssassin 2.53 (

I have a remote server currently running a SuseLinux installation on
which I have only access by a console-server to ttyS0. I also can start
a recoverymanager which create a ramdisk and provide network access.

This archive was generated by hypermail 2.1.3 : Sun Jan 15 2006 - 13:43:18 PST