2023-11-02 08:02:54 morning 2023-11-02 08:03:00 mkdir: can't create directory '/builds/alpine/aports/community/openmp/src': No space left on device 2023-11-02 08:03:04 CI is out of diskspace 2023-11-02 08:03:47 sorry, I made a mess with !54607 2023-11-02 08:04:07 and I have no idea how to fix it 2023-11-02 08:04:43 oh.... haha! 2023-11-02 08:04:46 no worries 2023-11-02 08:05:04 (now I'm thinking this gitlab workflow is not for me, and I should stop to work with it) 2023-11-02 08:05:38 no, dont worry 2023-11-02 08:05:51 what happened was you had wrong target branch 2023-11-02 08:06:01 yes 2023-11-02 08:06:08 i changed it from master to 3.16-stable now 2023-11-02 08:06:49 ncopa: the runners on usa-bld-1 have limited disk space 2023-11-02 08:08:29 i also think that dotnet is building? 2023-11-02 08:08:47 which eats all diskspace it gets, regardless how much disk you have... 2023-11-02 08:09:09 patchwwork was a better workflow for me 2023-11-02 08:09:31 i think you do pretty well with gitlab 2023-11-02 08:10:30 and im happy that you are able to adapt. patchwork was a mess to keep track of what was fixed and what was not 2023-11-02 08:10:36 and was a mess when it came to rebases etc 2023-11-02 08:10:45 could be, but I always feel some 'fear in fingers' when creating or merging something 2023-11-02 08:10:45 And no CI 2023-11-02 08:11:35 a little "fear" may be healthy. makes you be careful. 2023-11-02 08:11:41 yes, I remember that I proposed switch from patchwork to gitlab instead to github 2023-11-02 08:11:56 and im very happy we did that 2023-11-02 08:12:28 yes, yes, overall it is really good for alpine 2023-11-02 08:12:37 and dont worry. messing up a little bit happens to all of us 2023-11-02 08:13:00 thankfully there are protections in gitlab to prevent real disasters (like force push to master branch) 2023-11-02 08:14:01 and we have to give big thanks to ikke and clandmeter for making gitlab working very well 2023-11-02 08:19:13 btw, I noticed that some uses telegram-desktop, and it is lagging in alpine. I have it fixed for few months with this APKBUILD locally https://tpaste.us/ggYx if someone need new and fancy version 2023-11-02 08:21:52 seems like we have issues with s390x again? 2023-11-02 08:35:47 ncopa: i checked this morning, and it still continued 2023-11-02 08:36:17 Just a large llvm rebuild that's taking a long time 2023-11-02 14:11:29 was go bootstrap for 3.19 fixed? I was on vacation last week and just came back. didn't look into it in the meantime 2023-11-02 14:11:34 *on i386 2023-11-02 14:12:04 no, it still fails 2023-11-02 14:12:38 https://build.alpinelinux.org/buildlogs/build-3-19-x86/community/go/go-1.21.3-r1.log 2023-11-02 14:20:44 ok 2023-11-02 16:12:29 clandmeter, we need to renew the docker sponsored open source program each year. its just a formality 2023-11-02 16:12:38 ..said justin 2023-11-02 16:13:04 who redirected me to the correct person. I need to fill in the form again 2023-11-02 16:13:09 Ok, how do we do that? 2023-11-02 16:13:16 ok 2023-11-02 16:13:56 https://www.docker.com/community/open-source/application/ 2023-11-02 16:14:09 I'm working on it, but I'm not sure how we filled it in last time 2023-11-02 16:14:56 It's something you did. You just mentioned that you did it 2023-11-02 16:16:36 ha! 2023-11-02 16:19:22 Enter the existing Docker ID for your organization on Docker Hub. 2023-11-02 16:19:28 I suppose that is alpinelinux, right? 2023-11-02 16:19:32 correct 2023-11-02 16:19:44 https://hub.docker.com/u/alpinelinux 2023-11-02 16:19:45 I mean, that's the namespace 2023-11-02 16:19:51 indeed 2023-11-02 16:26:18 How many core developers are actively contributing to this project? 2023-11-02 16:26:25 those questions are hard :) 2023-11-02 16:26:37 yes 2023-11-02 16:26:45 2-4 2023-11-02 16:31:14 do we have an infra@alpinelinux.org email address? 2023-11-02 16:31:26 they send notifications to ncopa@alpinelinux.org currently 2023-11-02 16:31:38 which likely drown in my inbox 2023-11-02 16:34:53 yes, we have 2023-11-02 16:35:40 it is infra@alpinelinux.org? 2023-11-02 16:36:02 yes 2023-11-02 16:38:26 I have sent an owner invite to that email 2023-11-02 16:40:32 Ok, that means we need to create an account with that e-mail? 2023-11-02 16:43:11 Created one 2023-11-02 19:49:48 hello 2023-11-02 19:49:56 whats up guys 2023-11-02 19:53:09 mps: someone in #alpine-linux asks about https://gitlab.alpinelinux.org/alpine/aports/-/issues/14476 2023-11-02 19:54:04 ikke: iirc I answered this question long ago 2023-11-02 19:55:05 At least that ticket does not have a response and I could not find another ticket 2023-11-02 19:55:35 well, maybe not answered but asked for reasonable explanation why this is needed. Telling 'it is enabled on -lts' is not good enough reason imo 2023-11-02 19:57:03 but maybe 'we' should enable it? would be nice to hear opinion of more devs 2023-11-02 19:57:40 guys i have a question 2023-11-02 19:58:38 noleak238974: don't ask to ask on IRC, just ask 2023-11-02 19:59:18 okay okay tx can i use anonsurf from parrot linux in alpine linux 2023-11-02 20:01:14 you should ask this question on #alpine-linux channel, which is for user help 2023-11-02 20:01:41 is parrot linux musl or glibc based 2023-11-02 20:02:26 i think it´s glibc but i m not sure 2023-11-02 20:03:25 if it is glibc based then binaries from it probably will not work on alpine 2023-11-03 08:11:07 tomalok: what is your email address? 2023-11-03 08:11:20 maybe i can get it from gitlab 2023-11-03 08:14:08 tomalok, ikke: i created an agenda item with google meet. should popup in your mailbox. 2023-11-03 08:15:13 Received it 2023-11-03 11:28:29 ncopa: Does the suggestion in https://gitlab.alpinelinux.org/alpine/security/secfixes-tracker/-/merge_requests/16 make sense? I'd like to merge and deploy that MR 2023-11-03 11:35:36 not sure. there is something current_app from flask i think: https://flask.palletsprojects.com/en/2.3.x/appcontext/#purpose-of-the-context 2023-11-03 11:35:44 how can i reproduce the issue? 2023-11-03 11:36:56 I ran it with: https://gitlab.alpinelinux.org/alpine/infra/docker/secfixes-tracker and then this diff https://tpaste.us/VqD8 2023-11-03 11:37:19 docker compose run -u python --entrypoint /bin/sh crond 2023-11-03 11:38:55 ncopa: " View functions, error handlers, and other functions that run during a request will have access to current_app." 2023-11-03 11:41:16 In the container, run flask update-states (not sure if you need to run something like import-nvd recent first) 2023-11-03 11:45:22 i wonder if we can catch it in the testsuite? 2023-11-03 11:45:30 the error 2023-11-03 11:46:28 In the function tests you run the importers, can you run update-states similarly as well? 2023-11-03 11:49:12 ah, i havent done the update-states tests yet? 2023-11-03 11:49:38 no 2023-11-03 11:50:12 that explains 2023-11-03 11:50:29 iirc the udpate-states needed a bit more work than the other tests 2023-11-03 11:56:14 looks like i already discussed it with chatgpt some time ago 2023-11-03 11:58:20 problem is the current_app is not available in that context (I don't think there are global variables that automatically are made available) 2023-11-03 12:18:10 maybe we can use db.get_app() https://flask-sqlalchemy.palletsprojects.com/en/2.x/api/#flask_sqlalchemy.SQLAlchemy.get_app 2023-11-03 12:18:30 - return self.package_name in current_app.config.get('PACKAGE_EXCLUSIONS', []) 2023-11-03 12:18:30 + return self.package_name in db.get_app().config.get('PACKAGE_EXCLUSIONS', []) 2023-11-03 12:23:05 👍 2023-11-03 12:47:05 nope. does not work they removed get_app() in SQLAlchemy 3.x 2023-11-03 12:48:15 Ok 2023-11-03 12:51:21 I don't think adding a global is a good solution, but I don't know how to fix it properly 2023-11-03 12:51:41 Yeah, I'm not a fan of that myself either 2023-11-03 12:52:33 but I have a test for it 2023-11-03 12:52:47 I'm not sure the db model is the correct place for that logic either 2023-11-03 12:54:58 ah... we only need to import current_app 2023-11-04 21:04:19 cleaned up usa2 a bit. distfiles took up some space 2023-11-06 10:42:01 !54890 2023-11-06 11:00:47 fix '// typedef Elf64_Relr GElf_Relr;' in /usr/include/gelf.h pkg elfutils-dev 2023-11-06 11:01:01 is omni here? 2023-11-06 11:10:18 'typedef Elf64_Relr GElf_Relr' is probably bug 2023-11-06 11:23:27 im working on fixing musl for Elf64_Relr 2023-11-06 18:23:15 ncopa: now that linux-asahi kernel works fine with GPU I think to merge mesa-asahi to testing. any objection? 2023-11-06 18:50:56 do anyone have some time to review !54926 2023-11-06 19:40:31 do we need a separate build for asahi? 2023-11-06 19:48:42 ncopa: yes, mainline mesa doesn't work with asahi GPU 2023-11-06 19:51:10 asahi project also have it https://github.com/AsahiLinux/PKGBUILDs/tree/main/mesa-asahi-edge 2023-11-06 19:51:23 and I think fedora, debian ... 2023-11-06 19:51:53 ikke, ncopa or someone else with builder access: could you check why lld16 didn't get built on edge aarch64? 2023-11-06 19:52:11 or, well, did get built but not uploaded to the mirrors(?) 2023-11-06 19:56:51 did I made pkgver wrong? If not I think it is ready to merge 2023-11-06 19:57:23 someone with better knowledge about mesa could fix and polish it later 2023-11-06 19:58:02 I use it for about 10-11 months now, iirc 2023-11-06 19:58:32 and some other people also by downloading from my repo 2023-11-06 20:00:49 mps: if you mean the mesa-asahi MR, imo the pkgver looks correct 2023-11-06 20:01:10 ptrc: yes, I mean it. thanks 2023-11-06 20:01:22 the commented out deps and source could be removed, but that's just a nitpick 2023-11-06 20:01:59 yes, I know it is not proper APKBUILD but that could be fixed later 2023-11-06 20:03:16 after nearly two years working on making alpine good on apple silicon I think it is time to put all in aports so other people can make it better 2023-11-06 20:03:47 and it will be easier for end users to install and use 2023-11-06 20:04:47 I prepared bottle of good red wine to celebrate, hehe 2023-11-06 20:18:05 ptrc: lld16 was built on edge aarch64 2023-11-06 20:18:59 and it was uploaded: https://dl-master.alpinelinux.org/alpine/edge/community/aarch64/ 2023-11-06 20:19:42 ah, i've checked a while ago and it wasn't there yet but the buildlog was, so i assumed something went wrong 2023-11-06 20:20:04 but yeah, i can see it now in the apkindex as well 2023-11-06 20:20:07 thanks 2023-11-06 20:23:54 ok, merged mesa-asahi 2023-11-06 20:29:14 and tested this from alpine repo, work very well. 2023-11-06 20:29:17 \o/ 2023-11-06 20:30:06 after two years alpine on apple silicon have all needed pkgs in aports 2023-11-06 20:31:05 though alpine was first distro used as daily driver on apple silicon, by tmlind (I only know his IRC nick) and me 2023-11-06 20:31:23 now wine, cheers!!! 2023-11-06 20:37:13 ptrc: aarch64 edge was blocked by qt6-qtwebengine for some time 2023-11-06 20:38:55 ikke: it is disabled by omni on aarch64 and I disabled calibre because it depends on qt6-qtwebengine 2023-11-06 20:39:43 Yes, I'm aware, just stating why lld16 was not available for some time 2023-11-07 21:33:45 ncopa: starting secfixes-tracker locally consumes a lot of memory 2023-11-07 21:33:58 Immediately on startup it takes ~8GB 2023-11-07 21:35:10 hum, ok 2023-11-07 21:35:20 just starting it? 2023-11-07 21:35:25 or importing stuff 2023-11-07 21:36:34 just starting it 2023-11-07 21:42:33 trying to get a memory profile, but takes forever 2023-11-07 21:48:58 ncopa: seems to also happen with 0.4.0, so not a new symptom 2023-11-07 21:53:58 doesn't seem to happen with 0.3.1 2023-11-07 21:58:20 i can have a look at the log tomorrow 2023-11-07 22:00:19 what about 0.3.2? 2023-11-07 22:01:38 and 0.3.3 2023-11-08 06:24:53 ncopa: 0.3.3 low memory, 0.4.0 high memory 2023-11-08 14:02:52 so its likely due to my performance optimizations when importing stuff 2023-11-08 14:07:06 I was bisecting it 2023-11-08 16:22:34 ncopa: seems to be the difference between alpine 3.15 and 3.18 2023-11-08 16:22:46 (didn't check any versions in between yet) 2023-11-08 16:23:26 sorry, no it was not running yet 2023-11-08 16:32:28 It's strange, it's doing it even on older versions 2023-11-08 16:32:39 and it's a sudden increase in memory usage, not gradual 2023-11-08 16:37:38 is it the public site? 2023-11-08 16:38:32 yes 2023-11-08 16:38:39 running it in the docker compose project 2023-11-08 16:38:50 so it may be accessed from outside? 2023-11-08 16:39:05 Oh sorry, this one is just running locally on my machine 2023-11-08 16:39:11 ok 2023-11-08 16:39:23 is it a cron job that does imports? 2023-11-08 16:39:48 Yes, but I'm not running the cron service 2023-11-08 16:40:01 maybe the data it uses during imports is not garbage collected? 2023-11-08 16:40:15 It's the uwsgi process that is taking the memory 2023-11-08 16:41:15 python 9 5.8 51.3 8452204 8382712 ? S 16:40 0:02 uwsgi --master --plugin python3 --manage-script-name --mount /=secfixes_tracker:app --plugin http --http 0.0.0.0:8080 --processes=1 --threads=1 2023-11-08 16:41:21 using 8G memory 2023-11-08 16:41:27 immediately after startup 2023-11-08 16:41:48 do you have much in the database? 2023-11-08 16:42:00 Starting with a database from scratch 2023-11-08 16:42:12 so an empty db? 2023-11-08 16:42:57 yes 2023-11-08 16:45:43 Note that I don't see it happening in production, so it may be something local 2023-11-08 16:46:27 from memory_profiler import profile 2023-11-08 16:46:35 have you tried memory_profiler? 2023-11-08 16:47:19 no, not yet 2023-11-08 18:44:44 ncopa: memory usage seems normal when running flask in development mode, so I think it has to do with uwsgi 2023-11-08 18:51:20 I think I may have found it 2023-11-08 18:54:37 ncopa: "detected max file descriptor number: 1073741816" 2023-11-08 18:55:04 I lowered it to 2048 and memory usage is normal 2023-11-08 19:00:13 https://github.com/unbit/uwsgi/issues/2299 2023-11-08 19:11:30 interesting 2023-11-08 19:11:53 yes 2023-11-08 19:12:10 good job finding it! 2023-11-08 19:12:34 I just happen to notice in the output of running uwsgi 2023-11-09 06:44:13 cleaned up usa-bld-1 2023-11-09 07:15:39 thanks 2023-11-09 10:12:50 ncopa: linux-lts currently fails to build on x86_64 builder due to lack of space 2023-11-09 10:14:47 mkdir: can't create directory '/home/buildozer/aports/main/linux-lts/src': No space left on device 2023-11-09 10:24:42 slow machine... 2023-11-09 11:38:53 ncopa: are you cleaning up nld9, or should I do that? 2023-11-09 11:39:26 i cleaned a bit already 2023-11-09 11:39:39 but please go ahead and try clean it up even more if possible 2023-11-09 11:39:45 ok, will do 2023-11-09 11:39:55 i wonder if we should start remove older builders 2023-11-09 11:40:14 i think it was full because there were several failed builds, which left the sources trees there 2023-11-09 11:40:15 Yeah, would make sense, but at the same time, the older builders are relativelt small 2023-11-09 11:40:23 ncopa: yeah, definitely 2023-11-09 11:40:34 dotnet, chromium, qt6-qtwebengine, etc 2023-11-09 11:40:37 yup 2023-11-09 11:40:54 and there were multiple kernel buidls at the same time 2023-11-09 11:40:57 We need at some point think about community 2023-11-09 11:41:07 it's growing immensely 2023-11-09 11:41:53 yes 2023-11-09 11:45:00 [9564446.734442] oom-kill:constraint=CONSTRAINT_NONE,nodemask=(null),cpuset=lxc.payload.build-3-9-x86_64,mems_allowed=0-1,global_oom,task_memcg=/lxc.payload.build-3-19-x86_64,task=regression_test,pid=26809,uid=1000 2023-11-09 11:45:09 it runs out of memory too... 2023-11-09 11:46:37 hmm 2023-11-09 11:48:18 didn't realize linux also takes a lot of space to build 2023-11-09 11:48:31 21G source dir 2023-11-09 13:03:06 ncopa: 40G .cargo dir on build-edge-x86_64 2023-11-09 13:03:11 pruning it now 2023-11-09 13:04:47 great! thanks! 2023-11-09 13:05:08 deployed secfixes-tracker v0.4.1 2023-11-09 13:11:26 ncdu is a great tool to clean up disk space 2023-11-09 14:15:00 yes it is 2023-11-09 14:48:21 clandmeter: fyi, I'm running garbage collection on our docker registry to clean it up a bit 2023-11-09 16:23:22 clandmeter: Object storage usage went from ~70G to ~15G :) 2023-11-09 16:24:30 hope nothing broke, initial tests seems things are still working 2023-11-09 19:23:29 nice 2023-11-09 19:24:59 Gives me a bit more confidence in the sustainability 2023-11-09 19:27:50 I had one issue where one image couldn't be pushed, but apparently that was some bug in the container registries s3 implementation, found a post on the linode community forum with the solution 2023-11-09 19:29:05 clandmeter: for simple cases, it should be enough to include https://gitlab.alpinelinux.org/alpine/infra/gitlab-ci-templates/-/blob/master/exec/docker-image-x86_64.yml in the .gitlab-ci.yml file to push an image to the registry 2023-11-10 13:50:20 aports/main/librtlsdr needs some care 2023-11-10 13:51:22 I changed it a lot locally, not sure if it is ok to take maintainership, me or anyone else active 2023-11-11 20:11:49 algitbot: retry master 2023-11-12 07:41:58 kunkku: do we manually need to renew spoke certificates for dmvpn? I just hade one site with an expired certificate 2023-11-12 07:45:17 There is also a hub-1 cert that has expired 2023-11-12 09:20:20 how to find what block 'apk upgrade'? apk fix doesn't help 2023-11-12 11:20:18 mps: block in what way? 2023-11-12 11:21:30 ikke: `apk upgrade` doesn't work, just says 'OK: 3543 MiB in 1157 packages' but nothing is upgraded 2023-11-12 11:22:00 I guess something in dependencies block it but can't find what 2023-11-12 11:22:37 `apk fix -v` says same 2023-11-12 11:23:01 yeah, apk fix does not do anything in that regard 2023-11-12 11:23:11 mps: what does apk version -l '<' return? 2023-11-12 11:23:56 show pkgs which should be upgraded 2023-11-12 11:24:24 same as `apk version` only 2023-11-12 11:24:27 and then `apk add -s pkgname=version` 2023-11-12 11:24:40 where you try to explicitly install a newer version of a package 2023-11-12 11:24:48 oh, and apk list --orphan 2023-11-12 11:27:21 unrar, vim-help, svt-av1-libs, light and some locally build pkgs 2023-11-12 11:27:35 from the last command? 2023-11-12 11:27:42 yes 2023-11-12 11:27:52 Either one of those could be blocking other packages from being upgraded 2023-11-12 11:29:16 here is output https://tpaste.us/BJ5W 2023-11-12 11:29:35 output of the `apk add -s firefox=119.0.1-r0` 2023-11-12 11:30:26 what arch? 2023-11-12 11:31:07 apk info -R unrar vim-help 2023-11-12 11:31:35 uhm, a lot of manual works 2023-11-12 11:31:58 icu-data is culprit 2023-11-12 11:32:36 Somethign is keeping the old version of icu-data-en installed 2023-11-12 11:33:15 current solution for is `apk del fluffychat` 2023-11-12 11:34:08 price for running edge 2023-11-12 11:34:13 yes 2023-11-12 11:34:34 lets hope fluffychat will be rebuilt soon 2023-11-12 11:34:49 what arch? 2023-11-12 11:35:11 aarch64 2023-11-12 11:35:18 right, testing still needs to be completed 2023-11-12 11:35:35 and libreoffice with upgrade right now is not fixed 2023-11-12 11:35:37 It's building electron now 2023-11-12 11:35:58 yes, I follow build procces 2023-11-12 11:36:41 this is how I'm 'testing' edge 2023-11-12 11:37:06 yes, which is good, but after big rebuilds like icu things are broken for a while 2023-11-12 11:37:25 though I would really like if we have less pkgs 2023-11-12 11:39:23 The problem is that everyone has a different set of minimal amount of packages they need 2023-11-12 11:41:12 I thought busybox is enough for working system ;p 2023-11-12 22:14:15 https://gitlab.alpinelinux.org/alpine/aports/-/merge_requests/55177 2023-11-12 22:14:21 ikke: suspiciously stuck pipeline 2023-11-13 20:30:48 I bet a lot of people will ask soon for bcachefs-tools in alpine, especially when we upgrade linux-edge to 6.7 2023-11-13 20:31:47 I made pkg and thinking to merge it to testing for now, but maybe even to community where is linux-edge 2023-11-13 20:33:00 have to add that these days I don't have much free time to test it extensively 2023-11-14 00:18:59 ikke: do we have some stuff left over on the 3.19 ppc64le builder? i'm trying to reproduce the iproute2 failure locally and it doesn't install some of the stuff that the builder does, for some reason 2023-11-14 00:19:07 https://tpaste.us/vNLW 2023-11-14 05:04:15 ptrc: no, world is clean 2023-11-14 06:30:16 ptrc: these are the packages that are installed in a clean docker container installing the depends and makepends from iproute2: https://tpaste.us/QRk8 2023-11-14 06:32:40 ptrc: note that I did check the elf headers on ppc64le and they did not include the missing symbol / macro 2023-11-15 11:15:01 https://gitlab.alpinelinux.org/alpine/aports/-/jobs/1182389#L71 2023-11-15 11:15:30 anyone know why it can't find rdfind? I works fine in my LXC 2023-11-15 14:48:44 ncopa: next longterm stable kernel is 6.6, https://www.kernel.org/category/releases.html 2023-11-15 14:49:35 so !54530 should be merged 2023-11-15 16:06:36 mps: cool. I'm having an alpine break for two weeks. will get to it when I get back 2023-11-15 16:07:19 ikke, clandmeter, docker ppl reached out to us an mentioned that someone is using alpine namespace: https://hub.docker.com/u/alpine. Their github repositories are here: https://github.com/alpine-docker 2023-11-15 16:07:37 ncopa: I can merge it if you agree 2023-11-15 16:08:01 I confirmed that it is not us or official alpine. they asked If we wanted them to reclaim the namespace for us? 2023-11-15 16:08:08 mps: i will look at it when I get back 2023-11-15 16:08:13 ok 2023-11-15 16:08:17 We were aware of that, but never took any action against it 2023-11-15 16:08:26 they ask if we want take action 2023-11-15 16:08:37 so alpine 3.19 will be later 2023-11-15 16:08:39 I wonder if we should ask them to join us and make it official 2023-11-15 16:08:39 Yeah, the name can imply it's sanctioned / provided by us 2023-11-15 16:09:06 How would that look like 2023-11-15 16:09:12 i dont know 2023-11-15 16:09:14 Not sure if we want to disrupt the current images 2023-11-15 16:09:21 exactly 2023-11-15 16:09:29 and I don't know if we care too much either 2023-11-15 16:09:44 they did not use the official alpine logo, so it seems like they want to play nice 2023-11-15 16:09:48 but I don't know 2023-11-15 16:10:16 so i respond to docker that we don't bother to take action yet, but maybe later? 2023-11-15 16:10:42 it is misleading 2023-11-15 16:11:38 ikke: do you think you can ask around in the team what alpine people would prefer? 2023-11-15 16:11:47 ncopa: sure 2023-11-15 16:11:47 I'm slightly busy with other stuff right now 2023-11-15 16:11:51 thanks! 2023-11-15 16:11:51 yeah, no worry 2023-11-15 22:01:26 ikke: about renewing dmvpn certs 2023-11-15 22:02:33 'dmvpn-ca cert generate' renews all certs that have expired or will soon expire 2023-11-15 22:03:39 setup-dmvpn must be run on the respective hosts with the new pfx file 2023-11-16 01:36:54 mps: i was about to look at the linux 6.6 thing but I realised that you talked about the headers 2023-11-16 01:37:38 the headers is only for compiling user space, and we already built 90+ of user space for alpine 3.19 2023-11-16 01:38:21 if we upgrade the headers, we risk that things may break when rebuilds (eg when we do security fixes for the future 3.19-stable branch) 2023-11-16 01:38:42 so I think we should wait with linux headers 6.6 til after the 3.19 release 2023-11-16 01:38:59 the headers themselves does not really provide any value 2023-11-16 01:39:48 what we may consider is bump linux-its to 6.6 2023-11-16 01:40:18 but I don't want include more work at this point 2023-11-16 11:31:18 ncopa: yes, I talked about linux-headers, not linux-lts 2023-11-16 11:32:24 I can't remember when upgrading linux-headers break anything 2023-11-16 11:32:46 most safe pkg in alpine 2023-11-16 11:32:54 safest* 2023-11-19 16:56:09 clandmeter: I've tagged _rc1, but the trigger failed, says that there is no permission to trigger downstream pipeline 2023-11-19 16:58:50 Yes 2023-11-19 16:59:04 you are not ncopa 2023-11-19 16:59:27 I added him to the project 2023-11-19 16:59:41 I’m in Spain atm 2023-11-19 16:59:57 can you add yourself and try retry? 2023-11-19 17:00:11 Best is to move the project 2023-11-19 17:12:39 clandmeter: yeah, works after I've added myself 2023-11-19 17:40:58 Something changed in gitlab in recent versions that broke it. 2023-11-19 17:41:43 They tightened the implicit permissions 2023-11-19 17:43:04 https://gitlab.alpinelinux.org/clandmeter/alpine-disk-image/-/settings/ci_cd Token access section 2023-11-19 20:47:34 ikke, clandmeter: rc1 successfully tagged? i can start doing tome cloud image testing... 2023-11-19 20:47:54 tomalok: yes 2023-11-19 20:48:19 tomalok: I'll try to work next week on the image forwarder 2023-11-19 20:48:37 are we expecting a release of the 3.16..3.18 around the same time as 3.19? 2023-11-19 20:48:57 ikke: 👍 i've got some signing work to do yet too 2023-11-19 20:49:11 tomalok: I don't know when ncopa expects to do those minor releases 2023-11-19 20:49:36 saw something about openssl in devel 2023-11-19 20:49:39 yeah 2023-11-19 20:57:47 fwiw it's 3.19_rc1 and not 3.19.0_rc1? (thought we had a 'z' last time) 2023-11-19 20:58:31 either that or my code to resolve the latest release is off 2023-11-19 20:59:39 tag is right. it's releases.json maybe? 2023-11-19 20:59:54 no, alpine-base :( 2023-11-19 21:03:16 apk_ver = self.apk_version('main', 'x86_64', 'alpine-base', ver=ver) yep, looks like that's where it comes from 2023-11-19 21:03:18 I can fix the package, but that won't change what's in the image 2023-11-19 21:03:53 let me see how it got resolved in the work/images.yaml -- version vs release 2023-11-19 21:04:13 real fix would be rc2 2023-11-19 21:04:37  release: 3.19_rc1 2023-11-19 21:04:37 version: '3.19' 2023-11-19 21:04:52 ThisIsFine™ 2023-11-19 21:05:11 especially since this won't be published 2023-11-19 21:05:21 or released 2023-11-19 21:07:53 Ok 2023-11-19 23:13:33 3.19_rc1 aws images all seem fine (x86_64/aarch64, bios/uefi, tiny/cloudinit) 2023-11-22 08:11:06 good morning 2023-11-22 08:11:14 ikke: thx for fixing things 2023-11-22 08:11:23 i did not expect you to tag releases :) 2023-11-22 08:19:06 I tagged an rc while ncopa was away (with his approval) 2023-11-22 11:47:06 I rebooted it 2023-11-22 11:51:12 FYI I've stopped the 3.19 arm* builders so that edge can build qt5-qtwebengine. Otherwise it runs OOM 2023-11-22 14:38:05 is the riscv64 builder stuck? 2023-11-23 14:42:54 is it to late to add new openssl 3.2 to alpine 3.19 https://www.openssl.org/blog/blog/2023/11/23/OpenSSL32/ 2023-11-23 14:44:07 yes 2023-11-23 14:46:07 yes means late? 2023-11-23 14:46:13 indeed 2023-11-23 14:47:15 it's a pity, but ... 2023-11-23 14:56:34 all of 3.19 has already been built, and we want to make a release. Rebuilding against a new openssl would cost a lot of time and would perhaps encounter new build issues 2023-11-23 14:59:24 I know I know 2023-11-27 07:26:52 are we having issues with the s390x machine? im trying to upgrade my s390x dev container, but its dog slow. and CI appears to be broken for s390x 2023-11-27 07:26:59 https://gitlab.alpinelinux.org/alpine/aports/-/jobs/1194624 2023-11-27 07:34:59 usa2-dev1 [~]# uptime 2023-11-27 07:34:59 07:34:42 up 47 days, 18:59, load average: 3.46, 2.88, 3.80 2023-11-27 07:35:26 what is causing the load avg to be that high? 2023-11-27 07:55:10 gitlab-runner-s390x is also unusually slow. im tempted to reboot it 2023-11-27 07:55:44 maybe I should try upgrade the kernel and reboot it 2023-11-27 08:00:18 Don't see a constant high load on that machine 2023-11-27 08:42:34 i rebooted it 2023-11-27 12:35:51 Is che-bld-1 unavailable for everyone or just me? 2023-11-27 12:50:19 ncopa: i can ssh into it 2023-11-27 13:23:35 aha, its only my tunnels that are broke 2023-11-27 13:44:24 my dmvpn is broken. AUTH_FAILED 2023-11-27 13:44:27 Nov 27 13:43:03 rtr-copa daemon.info : 09[NET] received packet: from 172.105.69.172[500] to 85.167.243.86[500] (61 bytes) 2023-11-27 13:44:27 Nov 27 13:43:03 rtr-copa daemon.info : 05[ENC] parsed IKE_AUTH response 1 [ N(AUTH_FAILED) ] 2023-11-27 13:44:27 Nov 27 13:43:03 rtr-copa daemon.info : 09[IKE] received AUTHENTICATION_FAILED notify error 2023-11-27 13:44:27 Nov 27 13:43:03 rtr-copa daemon.info : 09[ENC] parsed IKE_AUTH response 1 [ N(AUTH_FAILED) ] 2023-11-27 13:44:27 Nov 27 13:43:03 rtr-copa daemon.info : 05[NET] received packet: from 176.58.106.16[500] to 85.167.243.86[500] (61 bytes) 2023-11-27 13:44:29 Nov 27 13:43:03 rtr-copa daemon.info : 05[IKE] received AUTHENTICATION_FAILED notify error 2023-11-27 14:40:49 cert expired? 2023-11-27 15:13:48 could be. not sure how I check that 2023-11-27 15:14:29 /etc/swanctl 2023-11-27 15:14:40 Or on dmvpn1.a.o 2023-11-27 15:40:02 OU=DEV-NCOPA, CN=VPNc-1 11/15/18 10:32:53 Expired 11/14/23 10:32:53 2023-11-27 15:40:05 ncopa: 2023-11-27 16:15:32 so yes, it's expired 2023-11-27 16:33:43 thank you for helping finding that out. I'll create a new one (later) 2023-11-27 16:33:56 banging my head into this rpi stuff 2023-11-28 08:45:41 ncopa: what you think, should we move some asahi pkg to community 2023-11-28 08:51:00 good question. maybe we should 2023-11-28 08:53:15 m1n1, u-boot-asahi, tiny-dfr and maybe asahi-fwextract are candidates 2023-11-28 11:18:37 ncopa: when you have some time, could you take a look at https://gitlab.alpinelinux.org/alpine/security/secfixes-tracker/-/merge_requests/17? This will make sure we're ready for the decomissioning of the NVD feeds at the 15th 2023-11-28 11:25:47 ok will try have a look at that today, but I need to prioritize (rpi) kernels 2023-11-28 11:26:08 Yes, no hurry 2023-11-28 13:10:58 drats... che-bld-1 is missing and I had some work inprogress there... 2023-11-28 13:11:46 i can continue to work on my mbp but i dont know if I should redo the work or wait for the che machine to come back 2023-11-28 13:20:36 ncopa: looks like it works now 2023-11-28 13:21:12 hmm, no 2023-11-28 13:21:28 how then I work on my lxc there 2023-11-28 13:46:47 ncopa: seems resolved 2023-11-28 13:46:57 yup 2023-11-28 13:47:14 im working on pushing it to the MR so I can move my work out from there 2023-11-28 15:54:13 ikke: how do I rebase an MR which uses 'master' as branch? 2023-11-28 15:54:20 eg https://gitlab.alpinelinux.org/alpine/mkinitfs/-/merge_requests/131 2023-11-28 15:56:56 You need to unprotect it in the fork 2023-11-28 15:57:24 In the repository settings of the fork 2023-11-28 16:00:23 got it. thanks! 2023-11-29 16:34:58 ikke: any chance i could get access to some aarch64 machine? trying to debug this firefox issue locally but it takes ages to rebuild everything 2023-11-29 16:35:10 ptrc: yeah 2023-11-29 16:38:56 how would i go about that then? :p 2023-11-29 16:39:39 do you have ipv6 connectivity? 2023-11-29 16:39:54 yeah, i think so 2023-11-29 17:12:39 guess I'll have to clean up again 2023-11-29 17:19:59 thank you so much for taking care of it 2023-11-30 02:35:41 Btw, MilkV is releasing the following this summer: https://community.milkv.io/t/introducing-the-milk-v-oasis-with-sg2380-a-revolutionary-risc-v-desktop-experience/780 2023-11-30 02:36:32 16 core RISCV64 cpu for 160 USD, seems too good to be true given the pioneer's 1500 USD price tag 2023-11-30 02:37:16 None the less,4-5 of those in a cluster might do something nice, although one beefy system would be better for compilation services 2023-11-30 09:26:09 i think I may need generate a new cert for my dmvpn, but I dont remember how or where 2023-11-30 09:37:12 ok, i am not able to log in to build-3-17-armhf. I cannot tag release until i know whats going on there. 2023-11-30 09:37:23 apparently my ssh key is not on usa9-dev1.a.o either 2023-11-30 09:41:29 its on the master iirc 2023-11-30 09:41:41 the dmvpn.a.o? 2023-11-30 09:41:47 one of them yes 2023-11-30 09:42:11 ah! we have two of them! 2023-11-30 09:42:26 high availability :) 2023-11-30 09:43:31 dmvpn1 2023-11-30 09:43:47 yup i found it. trying to figure out how to generate a cert 2023-11-30 09:44:11 i guess you could use shell history 2023-11-30 09:44:16 that would be my first go to :) 2023-11-30 09:44:46 and having the password would be a prio 2023-11-30 10:01:41 dmvpn-ca cert generate site 2023-11-30 11:18:42 now to figure out how to install the cert 2023-11-30 11:19:17 dmvpn-setup 2023-11-30 11:19:33 does that work even if dmvpn is already setup? 2023-11-30 11:20:03 yes 2023-11-30 11:20:18 That's how I updated the cert on usa2 2023-11-30 11:21:26 setup-dmvpn 2023-11-30 11:21:30 but yay! that worked 2023-11-30 11:57:02 https://security.alpinelinux.org/vuln/CVE-2023-5678 shows possible vulnerable for 3.15, 3.16, 3.17, but i think we have backported the patch for those, and its in secfixes comment. 2023-11-30 11:57:13 109910c17d51d060eec185e649bb6a2d513f010d 2023-11-30 11:57:26 3.16: 109910c17d51d060eec185e649bb6a2d513f010d 2023-11-30 11:58:07 3.17: I added it a minut ago, so that may show up later. 36ea41b5179ee066fc011b52b63040d900e0b872 2023-11-30 11:59:07 3.15: afb7a0b731d6486b1dd51c531f7783dae3f1f9a3