Page 3 of 5

Re: linuxaudio.org compromised - 2018-01-29

Posted: Thu Feb 08, 2018 12:20 am
by raboof
Awesome, hang in there! ;)

Re: linuxaudio.org compromised - 2018-01-29

Posted: Thu Feb 08, 2018 11:00 am
by Schwob
Thank you for your great work!

Re: linuxaudio.org compromised - 2018-01-29

Posted: Thu Feb 08, 2018 1:28 pm
by Linuxmusician01
The KXStudio repositories are to up again too so we can install our favorite software like we used to. :)

Re: linuxaudio.org compromised - 2018-01-29

Posted: Thu Feb 08, 2018 6:26 pm
by scacinto
I have three lab machines that I was unfortunately trying to install KXstudio on (repos) while the servers went down. I now have three systems that *think* kxstudio-meta-all and dependencies are installed, but they are not. After the server came up, I ran an update and upgraded Ardour, the repos, etc. However, a lot of software is missing, specifically plugins like CALF. When I try to reconfigure / force install or reinstall the meta packages they do so without complaint, but don't really seem to install anything. Attempting to install the kxstudio-meta-audio-plugins-vst, for example, also fails with an error:

Code: Select all

omiadmin@OMI-XPS-3:~$ sudo apt install --reinstall kxstudio-meta-audio-plugins-vst 
Reading package lists... Done
Building dependency tree       
Reading state information... Done
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:

The following packages have unmet dependencies:
 kxstudio-meta-audio-plugins-vst : Depends: foo-yc20-vst but it is not installable
                                   Depends: mda-vst but it is not installable
E: Unable to correct problems, you have held broken packages.
Am I hosed and have to reinstall everything from scratch? Are there still packages missing/not yet configured after the crash? All ideas appreciated.

Re: linuxaudio.org compromised - 2018-01-29

Posted: Fri Feb 09, 2018 1:17 am
by scacinto
Thanks, Falk - I'll give this a shot tomorrow.

Re: linuxaudio.org compromised - 2018-01-29

Posted: Fri Feb 09, 2018 2:31 pm
by autostatic
This is going to take some time as it is a huge amount of work. All Apache configs will have to be updated to 2.4 standards (we came from 2.2), PHP code that doesn't work with PHP7 has to be traced down and updated and all database users have to be set up again. The following sites are back online:

Re: linuxaudio.org compromised - 2018-01-29

Posted: Fri Feb 09, 2018 8:43 pm
by scacinto
falkTX wrote:run this:

Code: Select all

sudo apt-get purge kxstudio-repos kxstudio-repos-gcc5
sudo rm -f /etc/apt/sources.list.d/kxstudio*
and add the kxstudio repos again.
So I gave this a shot and still had problems. A little snooping showed that some folders have the wrong permissions for some reason. As an example, /usr/lib/lv2

Code: Select all

...
drwxr-xr-x   2 root    4096 Aug  1  2017 lp_solve
drwx------ 469 root   20480 Feb  9 15:15 lv2
drwxr-xr-x   2 root    4096 Feb  9 15:13 lxvst
...
On my working machine (imaged prior to the hack, this folder as read access for group and world. I started my installs again from scratch figuring that perhaps something borked when the repos were down and messed everything up. However, I can confirm that this problem persists. I cannot confirm what, if any, other folders/files have permissions issues.

Re: linuxaudio.org compromised - 2018-01-29

Posted: Fri Feb 09, 2018 9:29 pm
by autostatic
@scacinto, please open a new thread for this in the appropriate forum section, thanks!

Re: linuxaudio.org compromised - 2018-01-29

Posted: Fri Feb 09, 2018 10:37 pm
by autostatic
The mailing list archives are back online too. Most of the LAC pages work again. This weekend we'll get mail working too. Almost there!

Re: linuxaudio.org compromised - 2018-01-29

Posted: Fri Feb 09, 2018 10:52 pm
by autostatic
For those interested, the setup is now as follows:
- GlusterFS server with 1TB storage, on a private VLAN, no public IP, 2vCPU, 4GB RAM
- Web server with GlusterFS mount with public IP 185.54.115.200 (web1.linuxaudio.cyso.net), 4vCPU, 8GB RAM
- Mail server with public IP 185.54.115.210 (mail1.linuxaudio.cyso.net), 2vCPU, 4GB RAM

All servers are OpenStack Debian 9 VM's hosted at https://fuga.cloud/ which is a part of https://cyso.com/, the company I work for.

Re: linuxaudio.org compromised - 2018-01-29

Posted: Sat Feb 10, 2018 1:55 am
by folderol
Good news indeed. That's an incredible amount of work.
I think we all owe you quite a few beers :lol:

Re: linuxaudio.org compromised - 2018-01-29

Posted: Sun Feb 11, 2018 4:24 pm
by jonetsu
folderol wrote:Good news indeed. That's an incredible amount of work. I think we all owe you quite a few beers :lol:
As a musician, I can offer a few bars.

Re: linuxaudio.org compromised - 2018-01-29

Posted: Mon Feb 12, 2018 8:18 pm
by Lyberta
jonetsu wrote:As a musician, I can offer a few bars.
Zing.

Re: linuxaudio.org compromised - 2018-01-29

Posted: Tue Feb 13, 2018 9:41 pm
by BlackGuyver78
Thanks for all the hardwork. Everyone should definitely pitch in to write an opera about these linux heroes.

Re: linuxaudio.org compromised - 2018-01-29

Posted: Wed Feb 14, 2018 3:53 pm
by jonetsu
Hi,

Is there a need to subscribe again to the list ?

Cheers.