Thursday, September 20, 2007

SVN tips

Ok here are some more tips in addition to the earlier ones. Sometimes, you want to create a copy of an existing directory to another one before making significant changes. I know that's why we have SVN in the first place, to revert to last known working copy, but at times (especially when it involves looks) it can be quite tiresome. However, SVN will not add the copied directory as it considers it already under version control. Hmm..a tough one. Actually, its pretty easy. Here's how I did it :-
  • cd /path/to/project/copied directory
  • find ./ -name ".svn" | xargs rm -fr
Now the directory is no longer under version control. You can run "cd /path/to/project/;svn add * --force" to add the copied folder to the version control. Thats all folks :D

Wednesday, September 12, 2007

Safeguard your streams

Question:
If you wish to secure a connection from 1 service to another, what would you use?
a.) Why would I want to do that?
b.) Set up VPN.
c.) SSH tunneling.
d.) Stunnel.

Answer
a.) There is no such thing as being too paranoid.
b.) Ever heard the phrase "using a nuke to kill an ant"?
c.) Same as above by replace nuke with high explosive.
d.) BINGO!!

Stunnel is an application which wraps your normal connection over SSL/TLS to make sure no one can eavesdrop on your connection. This is particularly useful when you wish to secure your mail (SMTP, POP3) or securing your SVN server (heh, its what I am using it for:P). Its main benefits is that its extremely easy to set up (within 5 minutes) and it
only establishes a connection when needed, and not
maintain its secure tunnel perpetually, which eats up
your bandwidth unnecessarily.

This is my instruction on setting it up (for Ubuntu) on the server (svn as an example). Feel free to change the location and/or configuration to suit your needs.

  • sudo apt-get install stunnel
  • mkdir -p /home/shinning/secure_services/pid
  • mkdir -p /home/shinning/secure_services/service
  • cd /home/shinning/secure_services/
  • [create server cert] - openssl req -new -days 365 -nodes -out newreq.pem -keyout stunnel.pem
  • vi /home/shinning/secure_services/service/svn.sh
  • stunnel -P /home/shinning/secure -p /home/shinning/secure_services/stunnel.pem -d 4000 -r localhost:3690

And that it. Your SVN server is now running securely on top of SSL/TLS making it hard for anyone to sniff your traffic. You can also make your client authenticate itself against your server if you want to by following this guide. There are also tonnes of other examples here. Happy securing ;)

Monday, September 10, 2007

Fortune, meet planning

"Good fortune is what happens when opportunity meets with planning - Thomas Alva Edison"

The above saying is SOO true. How many times have we had the oppurtunity to do big things, but we failed because we didn't have a proper plan. And NO, I'm not talking about a bid to take over the world. Unless that's your plan of course, then I ain't gonna stop you. Perhaps the following tool can help you list out the things you have to do and set a timeline for it :P

The tool I'm talking about is called Planner which exists for both Linux and Windows. Think MS Project, but cross platform. Having never used MS Project before, its hard for me to say what are its limitations. However, its been really useful to me so far and far easier to use than some other project management software i.e. TaskJuggler.

For those using Linux, you can probably find it in your repository. In Ubuntu "sudo apt-get install planner" is sufficient to download and install this nifty software. Happy planning :D

Some screenshots are below for your viewing pleasure
Task allocation


Resource allocation and usage


GANTT chart

Saturday, September 08, 2007

My first version control

Ok, now we've got our versioning control server up and running. Now what? Now we start using it. I'll list the more basic command/uses here using the CLI. If you like, you can check out some other documentation on SVN.

  • Creating a repository
    • Log in to svn_srv
    • svnadmin create --fs-type fsfs /path/to/svn/repository_name
    • chgrp -R svn /path/to/svn/repository_name
    • cdmod -R 770 /path/to/svn/repository_name
    • cd /path/to/svn/repository_name/conf
    • Edit the svnserve.conf, authz and passwd file appropriately if you wish to disallow anonymous access and only allow authorized users to access your repository (recommended).

  • Importing an existing project to the above created repository
    • svn import /path/of/existing/project/folder svn://svn_srv/repository_name --username user_in_authz_file -m "Log message"

  • Downloading a fresh copy of the repository
    • svn checkout svn://svn_srv/repository_name /destination --username user_in_authz_file

  • Sync-ing a local copy with the changes in the repository
    • svn update --username user_in_authz_file  [-r revision_we_want_to_sync_with]

  • Show exact changes in files which have changed from repository and your local copy
    • svn diff --username user_in_authz_file [-r revision_we_want_to_compare_with]

  • Show things which have changed on your local copy and the repository
    • svn status -u

  • Adding new files to be added to the version control (recursively adds files and folders)
    • svn add * --force

  • Merging changes from two sources to the current copy
    • svn merge --username user_in_authz_file --no-auth-cache -r revision_to_merge_to:revision_to_merge_from /path/to/changed/copy
    • svn merge --username user_in_authz_file --no-auth-cache  URL@revision_1 URL@revision_2 /working/copy/path

  • Deleting a file from the local copy or in the repository
    • svn delete svn://svn_srv/repository_name/file
    • svn delete path/to/file
  • Undo all local changes (does not work with removed directories)
    • svn revert --recursive
    • svn revert path/to/file
  • Commit your changes to the repository
    • svn commit


By no means is the above a complete list of options or things you can do with SVN. Read the documentation and try it out for yourself to see the power of this tool.Or, if all this looks too complicated, we could use a GUI for it. Some of the are listed below :-

So many versions, so much confusion

How many times have you worked on a project or document only to
accidentally delete a critical file, made a modification and wished you
had the original copy, or simply keep track of all the changes to your
project. The most common way is to create an exact copy before doing any changes. It works, but it takes up unnecessary space and unless you keep a good listing of your changes, you'll be scratching your head wondering where to begin.

Obviously there is a solution for this, otherwise it'd be pointless to
write this entry now wouldn't it:P The solution is pretty simple
actually. Install a version control software :D And yes it IS easy to
set up as it sounds. It's the using it that's slightly confusing, but
I'll address it in a later post. For those who don't know what version
control is, check out this Wikipedia article.

This HOW-TO is based on thw howto from this site. I DO NOT take credit for this work and I'd like to express my appreciation to all the people who made ubuntuguide.org possible. I'll be using the client/server version for this guide. It is also possible to set one up to be accessible via web but I'm not going to touch it here. The HOW-TO for that is already available.

On Ubuntu (regardless of version), follow the following step-by-step to
get your version control software up and running :-
  1. Install the necessary software needed.

    • sudo apt-get install subversion subversion-tools xinetd

  2. Create a user and group that will be have read/write access to the repository directory.

    • sudo adduser --system --no-create-home --home /var/svn --group --disabled-login svn

  3. Create the directory where the repositories will reside (your projects/documents)

    • mkdir /opt/svn
    • chown -R svn:svn /opt/svn

  4. Lets make the software listen on its own connection port.

    1. vi /etc/xinetd.conf/svnserve

      • add the following to the above file

      • service svn
        {
        port = 3690
        socket_type = stream
        protocol = tcp
        wait = no
        user = svn
        server = /usr/bin/svnserve
        server_args = -i -r /var/svn
        }
      • quit and save the contents. This makes our svn server listen to TCP connections on port 3690.

    2. vi /etc/services

      • Check if there is an entry similar to "svn 3690/tcp subversion # Subversion protocol". If you changed the port to something else, make the changes appropriately.
      • If it doesn't exist, add it in, otherwise just quit.
      • Note : If the above entry doesn't exist in /etc/services, the svn will not start.

    3. /etc/init.d/xinetd restart

    4. Check if our svn server is now listening on our
      designated port.

      • netstat -tuanp | grep 3690

And that's all there is to it. Now you have your very own version
control software ready to use. My next post will cover creating and
managing your repository.

I'm also thinking on how to make this also useful for incremental backups. Until then, stay sharp and lets support Open/Free software :D.

Rise of the Star

Gosh. It's been more than a YEAR since I last blogged. Damn where DOES the time go. Been caught up in some projects and getting distracted here and there ;) Well lets see how long I can keep this blogging thing again before I get lazy :P

P/S : I will also try to answer any questions or comments posted from now on. I apologize for the comments which have not been answered earlier.

Monday, July 31, 2006

Multipost

This is a multipost. Kinda tired to write up invididual posts, hehehehe.

Anyway just came back from FOSSCAR. It was a really intersting event where I got to meet the rest of the #myoss guys. The presentations were really intersting especially the "10 worst sysadmin mistakes" and "Using open source for enterprise networks". You can get the presentation slide for "Using open source for enterprise networks" from here. Got a few photos which I'll upload once I extract it out.

Also, after looking at some of the guys using Expose-like features from OS X, I decided topost the app for others who want a similar feature. I tried it a few months back for sheer eye candy but disabled it cause didn't quite enjoy it especially without a proper graphics card. You can actually see the lagginess. Anyway the app is called skippy. For ubuntu, just "sudo apt-get install skippy" and its done;)

Well seems like a multi post just turned out to be 2 post:P. Off now, cheerioz;)

Sunday, July 23, 2006

Mon It

Recently I tried an application that aids in ensuring your system is running smoothly called monit. From the website of monit "monit is a utility for managing and monitoring, processes, files, directories and devices on a UNIX system. Monit conducts automatic maintenance and repair and can execute meaningful causal actions in error situations." There are packages available for FreeBSD and Ubuntu.

Installing and setting up monit on ubuntu is fairly easy, just do "sudo apt-get install monit" and its installed. Configuring monit is extremely easy. In fact the "/etc/monit/monitrc" file explains in depth the options available and how to use the variables.

The installation step for FreeBSD is "pkg_add -rvv monit". The monitrc file is in "/usr/local/etc/monitrc".

I'm posting a sample of my monitrc here as a simple guide.
#start sample monitrc
set daemon 120 #monitor the system every 2 minutes
set mailserver localhost #use localhost as the mailserver
set mail-format {from: monit@system} #set the from field of the mail
set alert user@localhost #who will receive the mail
#set the http port in which monit will report its status, the address it listens on, who can connect to it as well as the username and password required to login to monit
set httpd port 10123 and
use address localhost
allow localhost
allow admin:monit
include /etc/monit/services/* #Include files containing services, filesystem to monitor
#end sample monitrc

sample /etc/services/ssh #sample file that monitors the ssh service
#start /etc/services/ssh
check process SSH with pidfile /var/run/sshd.pid
start program = "/etc/init.d/ssh start"
stop program = "/etc/init.d/ssh stop"
if cpu is greater than 60% for 2 cycles then alert
if cpu > 80% for 5 cycles then restart
if totalmem > 200.0 MB for 5 cycles then restart
if children > 250 then restart
if loadavg(5min) greater than 10 for 8 cycles then stop
if 3 restarts within 5 cycles then timeout
group Server
#end /etc/services/ssh

As you can notice, the file is pretty self explanatory. Some other things that you can do are monitor if other machines are alive, alert you if the filesystem usage exceeds a certain percentage, ensure that filesystem permissions are set correctly, ensure that the checksum for specific system files are not changed, etc. Feel free to try out the various combination and options available.

Happy MonIt-oring;)

Friday, June 09, 2006

Emu v2

I've managed to get qemu installed and working using the guide posted here. However I'll post a short HOW-TO here as well:) I do not take credit for getting this to work;)

  1. Download the QEMU + KQEMU package from here.
  2. Install the following packages which includes your linux kernel headers "sudo apt-get install linux-headers-$(uname -r) libsdl1.2-dev zlib1g-dev checkinstall qemu".
  3. Create a symlink to your linux kernel for simplifying things at a later stage (which includes updates) using 'sudo ln -s /usr/src/linux-headers-$(uname -r) /usr/src/linux-headers'
  4. Extract the qemu package to a folder of your choice (i.e. /home/user/qemu) and also extract the kqemu package into the same directory. Remain in this directory.
  5. edit the qemu 'configure' file and change the kernel_path="" to
    'kernel_path="/usr/src/linux-headers"', quit and save the file.
  6. type './configure' and look for the line that says "kqemu support yes".
  7. type 'make'. This process might take some time.
  8. Now we're ready to create the debian package. Type 'sudo checkinstall -D' and you will be prompted to answer a few questions. "
    1st question: Answer = default y
    2nd question: Answer = Any description you like about qemu
    "
  9. In my case after the creation of the package I had to install the .deb file manually. This is accomplished using 'sudo dpkg -i '.
  10. Now we have to make sure that the modules required for functionality are loaded. Edit '/etc/modules' and add kqemu and tun to the file. To load it manually type 'sudo modprobe kqemu' and 'sudo modprobe tun'.
  11. Edit your '/etc/rc.local' and add the following
mknod /dev/kqemu c 250 0 # Create the KQEMU device
chmod 666 /dev/kqemu # Make it accessible to all users
chmod 666 /dev/net/tun # Make tun accessible by all
mount -o remount,size=544m /dev/shm
echo 1024 > /proc/sys/dev/rtc/max-user-freq

Now your system can emulate any OS of your choice;) Enjoy

Saturday, June 03, 2006

Dragon Reborn

YESS!!! Dapper Drake has been officially released on the 1st of June. This time we only require a single CD for both the live CD and the installer which makes things easier to manage. I've successfully installed it using the GUI without any hitch and I'm 1 happy dragon rider:D

Friday, May 19, 2006

Pics from Thailand Trip

A beautiful sight to behold indeed




People on the beach during the day




People on the beach during the night

Sunday, May 07, 2006

I see colors

On OpenBSD using 'vi' or 'ls' doesn't yield color by default. Also as I'm too used to having bash I usually install that as well

To start off you first have to install the fileutils, vim and bash package to get the 'gls', 'vim' and 'bash' command respectively. Copy the /usr/local/share/vim/vim64/vimrc_example.vim to ~/.vimrc which will automatically enable syntax highlighting for you. If it still isn't, check to make sure that 'syntax on' is in the ~/.vimrc file.

To make bash your default shell, type 'chpass' and edit the line that says 'shell' to point to /usr/local/bin/bash (I always set the absolute path). Quit and save (ESC,:wq) to store your new information.

Once that is done edit your ~/.profile and add these lines
export TERM=xterm-color
alias ls='gls --color'
alias vi='vim'

Quit and save the file. Now logout and login again and voiila, you will now be able to see colors when you type ls and edit files using vi;) Ciaoz

Thursday, May 04, 2006

Mod to Devil Worshipper's treats

Ok seems like I left out a small step in my procedure for getting various keycodes to work. Not that it doesn't work using that method just that you'll see various messages when you try to scp things over/from. Oopsy. Sorry bout that.

Here is the correct fix for it

instead of putting the keycodes into .bashrc, create a .inputrc and put all the keycodes into that. In the .bashrc put the following 'export INPUTRC=".inputrc"
'. This will fix those darned messages.

Ciaoz

It's alive

I finally managed to burn an OpenBSD cd successfully without any hitches. kekeke. Used this article as a reference to get it working. Basically its easy if you have a linux machine because tools such as mkhybrid are already available by default.

Steps
1. create a folder to store all the OpenBSD files i.e $HOME/openbsd. cd into that newly created folder.

2. download the OpenBSD files from any of the OpenBSD ftp mirrors. I used ftp://openbsd.cc.ntu.edu.tw/pub/OpenBSD/3.9/i386 because it turned out much faster. i used the command 'wget -rc ftp://openbsd.cc.ntu.edu.tw/pub/OpenBSD/3.9/i386/*'. this will recursively download all the files from the remote folder into your current folder.

3. depending on your internet connection the download might take up to 1 hour or more. The layout of the folder will be 'openbsd.cc.ntu.edu.tw/pub/OpenBSD/3.9/i386/' (substituting the host with whichever host you may have chosen. Now comes the interesting part, the creation of the ISO.

from the $HOME/openbsd folder, type 'mkhybrid -b openbsd.cc.ntu.edu.tw/pub/OpenBSD/3.9/i386/cdrom39.fs -c boot.catalog -l -J -L -r -o obsd39.iso ./'

Take note the last ./ as this will be the BASE working path that will be used to navigate to openbsd.cc.ntu.edu.tw/pub/OpenBSD/3.9/i386/cdrom39.fs

It will now begin creating the iso and after its done from the folder you're in you will find a obsd39.iso. Feel free to use any CD burning software to burn the image onto your CD. I used k3b to do burn my image. You could always use 'cdrecord' if you want everything executed from the console. After you've burned it do try to boot the cd to make sure all is working well. If all works then you can delete the files downloaded including the iso or you can share it with your friends.

Thats all folks :D

Wednesday, May 03, 2006

I am watching you

For some time I've been using a tool called ntop to monitor the traffic that goes through my machine. Just thought I'd share the tool with everyone else who is looking to see what goes on behind closed interfaces. The name of the tool is called ntop and listed below are the instructions to install it (on Breezy of course). Since its a web based tool all you need is a web browser to check the statistics.

apt-get intsall ntop.
first time run ntop -u ntop [-u indicates which user to run as]
it will ask for admin password (min 5 char)

to access the page type this in your browser "http://localhost:3000"

the only snag to this is that it only monitors up to the last 12 hours but its more than enough for normal users who just want to know what kind of traffic passes through their machine ;)

Emuuuuuuuuuuuuuuuuuu

We've all at one point or another wanted to run multiple OSes in a single machine simultaneously. One of the best ways to do it was to use VMware. However there is that small issue of licensing fee. There is however a FREE VMWare player for various platforms that can run images of various OSes but it didn't work for me. Earlier on one my friends mentioned bout QEMU which allows you to do exactly what VMWare allows.

My previous incarnation of Breezy had QEMU + KQEMU set up all well but after the resurrection I seem to have forgotten to install it. Till now that is. The basic guide I used for Breezy was based on this link.

Sunday, March 12, 2006

Devil Worshippers treats

Here's a little trick i would like to share with my Devil Worshipper buddies (even if I don't use it. Argh! Gotta stop using shortforms. Damn IMs).
This trick is to enable all those keys such as HOME, DELETE which don't work as well out of the box in *BSD. Since I'm really used to having them, I searched a solution and I hope this helps someone else.

Create a '~/.bashrc' and add the following lines

set meta-flag on
set output-meta on
set convert-meta off
"\e[1~": beginning-of-line
"\e[2~": yank
"\e[3~": delete-char
"\e[4~": end-of-line
"\e[C": forward-char
"\e[D": backward-char
"\e[A": previous-history
"\e[B": next-history
"\C-?": delete-char
"\C-H": backward-delete-char
"\e[1~": beginning-of-line
"\e[4~": end-of-line

Quit out your existing session and re-log back in and now all those keys that were unavailable earlier are now at your disposable. Enjoy;)

Quickies

Here are some quick tips to help using Linux easier.

  • We tend to use 'grep' to search through our files but finding the occourence of the word can be tricky especially if there are alot of output. grep comes with color option to highlight the word using the --color=auto option. I add an alias in my .bash_profile so I don't have to keep typing it all the time.
    • alias grep='grep --color=auto'

  • vi can be your best friend as it's a very powerful editor and it's always available in every Linux distribution. However, it can get tedious looking at merely looking at black and white fonts. The newer distribution of vi is called vim (vi improved) which offers color options. To enable it (if it isn't) just fire up vi and press the ESC key, and type ':syntax on' exactly. NOTE: The following instruction is for Ubuntu. To make sure every file you open has syntax highlighting, copy '/etc/vim/vimrc' to '~/.vimrc'. Open '~/.vimrc' and look for the line that says 'syntax on' which is disabled by default. Quit and save and every file you open from now on will have syntax highlighting. The syntax highlighting information is stored in '/usr/share/vim/vim63/syntax'.
  • GTK fonts too small? When using Fluxbox, most of the GTK application fonts tend to be really tiny. This doesn't appear in GNOME because it will load 'gnome-settings-daemon' to make the apps streamlined. This however is not a good approach for minimalistic WMs (isn't that why we CHOSE the minimalistic WMs in the 1st place:P). Here is a trick that will make your fonts in the GTK apps, appear exactly as you want them. Edit (or create) a '~/.gtkrc-2.0' and add 'gtk-font-name="<font name> <font size>"', save the file, reload your GTK applications and voila all your fonts are now as you defined them.
Well that's all for now folks;) Gotta go configure my development tools now. Ciaoz.

Wednesday, March 08, 2006

Return of the Badger

Geez. Looks like an agreement with the devil didn't go so well. The installation went just fine however the update didn't go as expected (as usual). Yeah i see 1 guy starting to curse me now. You know who you are Tough luck man. Told you i never could get it to work properly for me. Now i've reinstalled my ol failthful Badger and surprise surprise. Lost my tutorials again. Gotta redo it but now that I've got it I can ACTUALLY paste it up now. WHEE!!!

Thursday, March 02, 2006

Rise of the Devil

Finally running FreeBSD the way its meant to be;). When you initially start up Fluxbox you will notice that all your GTK applications will be utilizing REALLY small fonts. Previously I used to run gnome-settings-daemon to get the fonts in the right size but now I've found another way to get the fonts just right.

I execute Fluxbox using the "Use system default" option in GDM. This will look for a .xprofile (as opposed to .xsession in UIbuntu) in your home directory. However in my case I symlink .xprofile to .xinitrc (just used to the normal standards I guess). I find this a better way to start up new WMs as I can logout and login to change different settings without disrupting the other users WM settings. Also, I can start up any custom apps I would like loaded using this method. Couldn't get fluxbox to read the startup file in the ~/.fluxbox folder though. Have to check that out later.

My .xprofile file contains the following lines

fbpager -rc ~/.fluxbox/fbpager&
exec /usr/X11R6/bin/fluxbox

I guess I'm just used to having a pager in my previous WMs that I just had to have it in fluxbox itself. A pager application is the one you use to switch to multiple desktops in XFCE4, GNOME or KDE.

Will add more on the status of the devil after I find more things to do >:)