Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Soricidus
Oct 21, 2010
freedom-hating statist shill

OldAlias posted:

digging around for 10 seconds brought up :nsa: , though not actually useful or up to date https://web.archive.org/web/20160305103603/https://www.nsa.gov/research/selinux/docs.shtml

god drat it snowden you had one job

Adbot
ADBOT LOVES YOU

Tankakern
Jul 25, 2007

i just wonder if male shoegaze got the speakers working

DONT THREAD ON ME
Oct 1, 2002

by Nyc_Tattoo
Floss Finder

Tankakern posted:

i just wonder if male shoegaze got the speakers working

they're working as we speak, but i havent tried unplugging them yet today to see if that kills it

e: just went for it. plugged + unplugged and it worked, so yay

now i just need to get my monitors at work working and figure out how to lock my screen and i'll be happy

bobson
Dec 25, 2007
wa we wa wa

ratbert90 posted:

Well, not... really. At least not that I could find.

What I was doing (and did) was I wanted to create a "system_u:object_r:mycompany_t" context for security purposes. That isn't covered very well that I could find. Although that was a year or so ago, so perhaps documentation has become better.

It's still terrible, I just went through the same thing.

DONT THREAD ON ME
Oct 1, 2002

by Nyc_Tattoo
Floss Finder
well i installed a lock thing and i dont know what password it used because i couldn't unlock it

b0red
Apr 3, 2013

MALE SHOEGAZE posted:

well i installed a lock thing and i dont know what password it used because i couldn't unlock it

it doesn't use your account password???

FlapYoJacks
Feb 12, 2009

bobson posted:

It's still terrible, I just went through the same thing.

Oh good. I just grabbed refpolicy and did a bunch of grepping. Ended up working out.

eschaton
Mar 7, 2007

Don't you just hate when you wind up in a store with people who are in a socioeconomic class that is pretty obviously about two levels lower than your own?
whereas the only trouble I have with audio on my Mac running the world's most advanced operating system is when I do a clean install at work, it doesn't remember that I prefer my sound be routed to my fancy Rule 36 speakers via USB

a quick choice from the table in the Sound pref pane clears that right up until I do another clean install

eschaton
Mar 7, 2007

Don't you just hate when you wind up in a store with people who are in a socioeconomic class that is pretty obviously about two levels lower than your own?

MALE SHOEGAZE posted:

now i just need to get my monitors at work working and figure out how to lock my screen and i'll be happy

just ask jwz, I'm sure he'll be happy to help you get it working with xscreensaver

DONT THREAD ON ME
Oct 1, 2002

by Nyc_Tattoo
Floss Finder

b0red posted:

it doesn't use your account password???

it used whatever was stored in pam (nothing??)

DONT THREAD ON ME
Oct 1, 2002

by Nyc_Tattoo
Floss Finder

eschaton posted:

just ask jwz, I'm sure he'll be happy to help you get it working with xscreensaver

i really doubt he would be happy to talk to me

Last Chance
Dec 31, 2004

eschaton posted:

whereas the only trouble I have with audio on my Mac running the world's most advanced operating system is when I do a clean install at work, it doesn't remember that I prefer my sound be routed to my fancy Rule 36 speakers via USB

a quick choice from the table in the Sound pref pane clears that right up until I do another clean install

if you alt-click the sound icon in the tray you can switch audio input/outputs (including airplay) without touching the prefs panel. its great

b0red
Apr 3, 2013

MALE SHOEGAZE posted:

it used whatever was stored in pam (nothing??)

lmao

FlapYoJacks
Feb 12, 2009
Upgraded to Fedora24 on day one like a boss. Only thing that was kind of hokey was the nvidia driver. Reinstalled it and all is good.

Soricidus
Oct 21, 2010
freedom-hating statist shill
I'm trying fedora 24 in a vm, it finally seems to be managing to deliver hidpi support almost ootb which is nice

Sapozhnik
Jan 2, 2005

Nap Ghost
Currently posting from a Wayland session :whatup: unfortunately not even Wayland has the power to make those posts anything other than garbage

(been like that since GNOME 3.20.1 came out a month or two ago, though. Arch ftw)

b0red
Apr 3, 2013

anyone wanna lend me some iptables/networking knowledge. i wouldn't normally ask anything like this here but i've looked around a good bit and feel some of you guys would have a better idea than half poo poo on serverfault/stackoverflow/random mailing lists

basically i want to mirror all my network traffic from 10.0.0.110 and forward it to 192.168.1.100. if they resided in the same subnet this would be very easy because all i'd have to do is
code:
iptables -t mangle -A OUTPUT -j TEE --gateway 192.168.1.100
the problem is TEE only works for next-hop stuff soooo what do i do
code:
sudo iptables -t nat -A PREROUTING -i eth0 -d 0.0.0.0/0 -j DNAT --to-destination 192.168.1.100
sudo iptables -t nat -A POSTROUTING -o eth0 -s 0.0.0.0/0 -j SNAT --to-source 192.168.1.100
tried some poo poo like this with no dice.
it sucks that i even have to jump through this hoop. maybe like another node on the 10.0.0.0 network that has ipv4 forwarding enabled and they all TEE mirror at it and it forwards that data to 192.168.1.100. i don't fuckin know, all the network duplication poo poo i've found on github deals with specific ports and poo poo. maybe i'll just look into writing something myself or the possibility of loving with the iptables TEE code

b0red fucked around with this message at 01:00 on Jun 23, 2016

celeron 300a
Jan 23, 2005

by exmarx
Yam Slacker

b0red posted:

anyone wanna lend me some iptables/networking knowledge. i wouldn't normally ask anything like this here but i've looked around a good bit and feel some of you guys would have a better idea than half poo poo on serverfault/stackoverflow/random mailing lists

basically i want to mirror all my network traffic from 10.0.0.110 and forward it to 192.168.1.100. if they resided in the same subnet this would be very easy because all i'd have to do is
code:
iptables -t mangle -A OUTPUT -j TEE --gateway 192.168.1.100
the problem is TEE only works for next-hop stuff soooo what do i do
code:
sudo iptables -t nat -A PREROUTING -i eth0 -d 0.0.0.0/0 -j DNAT --to-destination 192.168.1.100
sudo iptables -t nat -A POSTROUTING -o eth0 -s 0.0.0.0/0 -j SNAT --to-source 192.168.1.100
tried some poo poo like this with no dice.
it sucks that i even have to jump through this hoop. maybe like another node on the 10.0.0.0 network that has ipv4 forwarding enabled and they all TEE mirror at it and it forwards that data to 192.168.1.100. i don't fuckin know, all the network duplication poo poo i've found on github deals with specific ports and poo poo. maybe i'll just look into writing something myself or the possibility of loving with the iptables TEE code

So, the destination is farther than just one hop? You'll need to start mangling the IP packets so that they can correctly reach your listener, but you'll lose your source/destination IP info.

What you might want to try is duplicating a packet and sending it to your listener with an encapsulation protocol like GRE or ipsec. This should allow the packet to be forwarded correctly.

celeron 300a
Jan 23, 2005

by exmarx
Yam Slacker
also, there are comedy options like storing it as pcap and sending it over nfs, or using vlans (like, create a massive bridging vlan over all your routers) and have your listener and transmitter on the same vlan and you can do your old TEE target solution.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

celeron 300a posted:

also, there are comedy options like storing it as pcap and sending it over nfs

holy lmao why would anyone ever do this

this is truly a comedy option because i cannot stop laughing

(listen for network traffic) -> (write to pcap) -> (copy to nfs destination) -> (read pcap) -> (inject into network stack)

Cybernetic Vermin
Apr 18, 2005

everything is a file, lol if you don't route your network requests with dd

b0red
Apr 3, 2013

celeron 300a posted:

So, the destination is farther than just one hop? You'll need to start mangling the IP packets so that they can correctly reach your listener, but you'll lose your source/destination IP info.

What you might want to try is duplicating a packet and sending it to your listener with an encapsulation protocol like GRE or ipsec. This should allow the packet to be forwarded correctly.

Appreciate the input, I'll look into GRE. I'm probably just going to have to hack something together myself.

Captain Foo posted:

holy lmao why would anyone ever do this

this is truly a comedy option because i cannot stop laughing

(listen for network traffic) -> (write to pcap) -> (copy to nfs destination) -> (read pcap) -> (inject into network stack)

You can't listen for network traffic in aws :mmmhmm:

VAGENDA OF MANOCIDE
Aug 1, 2004

whoa, what just happened here?







College Slice

Captain Foo posted:

holy lmao why would anyone ever do this

this is truly a comedy option because i cannot stop laughing

(listen for network traffic) -> (write to pcap) -> (copy to nfs destination) -> (read pcap) -> (inject into network stack)


Cybernetic Vermin posted:

everything is a file, lol if you don't route your network requests with dd

it's the unix philosophy

trilljester
Dec 7, 2004

The People's Tight End.
2 days into using Fedora 24 in a VM. Have to say out of all of the other distros I tried (I even tried Gentoo, lol), this one is the most polished. I would even recommend it to my Mom, except she needs Windows for TurboTax.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

trilljester posted:

2 days into using Fedora 24 in a VM. Have to say out of all of the other distros I tried (I even tried Gentoo, lol), this one is the most polished. I would even recommend it to my Mom, except she needs Windows for TurboTax.

If you're using turbo tax you should do your taxes by hand

Tankakern
Jul 25, 2007

trilljester posted:

2 days into using Fedora 24 in a VM. Have to say out of all of the other distros I tried (I even tried Gentoo, lol), this one is the most polished. I would even recommend it to my Mom, except she needs Windows for TurboTax.

turbotax might work with wine staging if you want to try :sureboat:

cowboy beepboop
Feb 24, 2001

I upgraded to Fedora 24 and now gnome crashes after 5 minutes and dumps me in the boot tty. Ctrl alt f2 fixes it and this is in dmesg:
traps: gnome-shell[1584] trap int3

how fix what do

celeron 300a
Jan 23, 2005

by exmarx
Yam Slacker

my stepdads beer posted:

I upgraded to Fedora 24 and now gnome crashes after 5 minutes and dumps me in the boot tty. Ctrl alt f2 fixes it and this is in dmesg:
traps: gnome-shell[1584] trap int3

how fix what do

Out of curiosity, what kind of video driver do you have?

And if you're using wayland, try disabling it or vice versa.

This opinion comes from someone who is still on fc23

Symbolic Butt
Mar 22, 2009

(_!_)
Buglord

my stepdads beer posted:

I upgraded to Fedora 24 and now gnome crashes after 5 minutes and dumps me in the boot tty. Ctrl alt f2 fixes it and this is in dmesg:
traps: gnome-shell[1584] trap int3

how fix what do

good old cc

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)

so wait does wayland work on f24 on nvidia or not?

i don't get the option on the login screen for wayland specifically

Soricidus
Oct 21, 2010
freedom-hating statist shill
should i care about wayland yet

e: i tried it and it crashed, so i guess not

Soricidus fucked around with this message at 00:02 on Jun 24, 2016

cowboy beepboop
Feb 24, 2001

celeron 300a posted:

Out of curiosity, what kind of video driver do you have?

And if you're using wayland, try disabling it or vice versa.

This opinion comes from someone who is still on fc23

nvidia, with their binary drivers. I might reinstall the drivers and see if that fixes this. using X afaik

celeron 300a
Jan 23, 2005

by exmarx
Yam Slacker

my stepdads beer posted:

nvidia, with their binary drivers. I might reinstall the drivers and see if that fixes this. using X afaik

Yeah, maybe see if using nouveau instead of the binary drivers will help it.

If it does, then you'll just have to wait until the binary only drivers catch up or just install centos 7.

Notorious b.s.d.
Jan 25, 2003

by Reene

trilljester posted:

2 days into using Fedora 24 in a VM. Have to say out of all of the other distros I tried (I even tried Gentoo, lol), this one is the most polished. I would even recommend it to my Mom, except she needs Windows for TurboTax.

turbotax has a web product at feature parity with the desktop now

Notorious b.s.d.
Jan 25, 2003

by Reene

b0red posted:

anyone wanna lend me some iptables/networking knowledge. i wouldn't normally ask anything like this here but i've looked around a good bit and feel some of you guys would have a better idea than half poo poo on serverfault/stackoverflow/random mailing lists

basically i want to mirror all my network traffic from 10.0.0.110 and forward it to 192.168.1.100. if they resided in the same subnet this would be very easy because all i'd have to do is
code:
iptables -t mangle -A OUTPUT -j TEE --gateway 192.168.1.100
the problem is TEE only works for next-hop stuff soooo what do i do
code:
sudo iptables -t nat -A PREROUTING -i eth0 -d 0.0.0.0/0 -j DNAT --to-destination 192.168.1.100
sudo iptables -t nat -A POSTROUTING -o eth0 -s 0.0.0.0/0 -j SNAT --to-source 192.168.1.100
tried some poo poo like this with no dice.
it sucks that i even have to jump through this hoop. maybe like another node on the 10.0.0.0 network that has ipv4 forwarding enabled and they all TEE mirror at it and it forwards that data to 192.168.1.100. i don't fuckin know, all the network duplication poo poo i've found on github deals with specific ports and poo poo. maybe i'll just look into writing something myself or the possibility of loving with the iptables TEE code

this is not a good idea in general. just nothing about this makes sense

if you want a perfect record of the network traffic: either do this inside your switch with port mirroring, or send digested statistics with netflow

if you are only interested in the payload: set up a transparent proxy, and dump it at that point

b0red
Apr 3, 2013

Notorious b.s.d. posted:

this is not a good idea in general. just nothing about this makes sense

if you want a perfect record of the network traffic: either do this inside your switch with port mirroring, or send digested statistics with netflow

if you are only interested in the payload: set up a transparent proxy, and dump it at that point

well the whole reason behind this is to recreate our lab network/product in AWS, which requires having an IDS to show its worth. aws being aws means jumping through some hoops for this to work.

fml maybe can convince the higher ups to collocate some equipment somewhere for this poo poo

Soricidus
Oct 21, 2010
freedom-hating statist shill
fedora 24 updat: tried to install chrome because some google stuff isn't working in firefox for some reason i can't be bothered to debug

clicking on the chrome install link brings up what actually looks like quite a friendly software installer with useful information and stuff. is this packagekit? i thought it was bad but it looks like it's ok. maybe linux is finally ready for the deskt
code:
cannot download Packages/p/perl-B-Lint-1.20-6.fc24.noarch.rpm to /var/cache/PackageKit/24/metadata/fedora/packages/: Curl error (35): SSL connect error for [url]https://mirrors.fedoraproject.org/metalink?repo=fedora-24&arch=x86_64[/url] [Encountered end of file]

Sapozhnik
Jan 2, 2005

Nap Ghost
well yeah, the package server is experiencing issues. On Windows the installer would just would say "The operation could not be completed (gently caress you, I'm not going to tell you why, that would take effort)"

Soricidus
Oct 21, 2010
freedom-hating statist shill

Mr Dog posted:

well yeah, the package server is experiencing issues. On Windows the installer would just would say "The operation could not be completed (gently caress you, I'm not going to tell you why, that would take effort)"

"well yeah" is all very well but it sounds like that's the kind of thing that they could trivially display an actual friendly error message for

like here's a 10-second idea: if the repo is one that the user has connected to successfully in the past, and the error is the sort you'd get when the server is experiencing issues, then before you dive into the technical details you also display an explanation like, i don't know, maybe "the package server is experiencing issues"

I'm now getting "Error: Failed to synchronize cache for repo 'updates'", which i assume also means "the package server is experiencing issues" and not "something is broken on your computer"? idk, i have literally no idea whether the error message is telling me i need to fix poo poo or just wait.

Adbot
ADBOT LOVES YOU

Apocadall
Mar 25, 2010

Aren't you the guitarist for the feed dogs?

i am having such a bitch of a time getting a yealink voip phone talking through a linux openvpn server to an asterisk pbx

kill me

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply