Showing posts with label gentoo. Show all posts
Showing posts with label gentoo. Show all posts

Monday, 16 April 2012

AlpsPS/2 ALPS DualPoint TouchPad on Arch linux

In my new Dell Latitude, there is an AlpsPS/2 ALPS DualPoint touchpad. When I installed Arch linux on it the touchpad worked fine for me. I do not use the touchpad button and prefer to tap on the touchpad for a click. This feature worked fine with the initial configuration. However, after a system update which included a kernel update too, tap did not work.

I had not gotten into details of the touchpad before this incident. When I found it was not a Synaptics touchpad, I got scared that I might not get a decent linux driver for it. Just about a month ago I was looking for a decent driver that supports Nvidia Optimus tecnology; but all my efforts were in vain.

As I started looking for a driver for my touchpad, I found out that the synaptics driver is not only for synaptics touchpads. So, I installed xf86-input-synaptics package. Tap for click started working as the default /etc/X11/xorg.conf.d/10-synaptics.conf has the configuration for tap.

        Option "TapButton1" "1"
        Option "TapButton2" "2"
        Option "TapButton3" "3"


Also, two finger scroll started working. I had no idea that my touchpad supports it. The freedesktop.org documentation however specifies a config for Alps touchpads. I read through synaptics configuration on Arch wiki to configure the touchpad to suit my usage. The Gentoo wiki also provides a number of configurations, in case you want to try things out. The AccelFactor value mentioned in these wikis turns out to be too slow for me. So, I increased its value. 

Wednesday, 22 February 2012

Partial upgrade messed my system

Although I am aware of the potential risks of a partial upgrade, due to slow connection I thought I will go ahead with it. I was feeling confident that if things mess up I will be able to handle them. I had installed grep and udev without installing upgraded versions of kmod and pcre.



When I restarted [may be I should not have done that], during boot only the system started throwing errors about grep being unable to find libpcre and kmod not being found. I was able to boot into kdm but my keyboard and touchpad were not working. The root of the problem is still unknown; but I thought of trying installing pcre and kmod. However, to install I had to get to the command prompt at least.

So, I created a Gentoo boot disk using my flash drive and chrooted into my system. I connect using 3G USB dongle and from the chrooted environment the mode was not switched. So, I had to get packages downloaded separately and then install them through the chrooted environment. I should have installed the same version as in my system's pacman database; but I installed the latest one. With that I fixed the boot problems and my keyboard was working but it broke a few other things and kdm did not work any more. When I booted now, it took me to the command line. I reinstalled kdebase-workspace; yet the issue persisted. To make things worse, I found that emacs and irssi were also not working. So, I couldn't get to any IRC channel to ask for help. The only good thing that happened was I was able to get to a command line. So, I did not have to download packages elsewhere and install it.

 When I connected to the internet from my system and ran pacman -Syu it showed me downloads of around 650 mb. I found that many of those packages like libreoffice and 32-bit libs are not absolute necessity from a repair perspective. So, I decided to download a small subset to get my KDE back. I downloaded

  • avahi 
  • ca-certificates 
  • compositeproto 
  • cpio 
  • kdelibs 
  • kactivities 
  • libxrandr 
  • xdg-utils 
  • qt  
  • oxygen-icons 
  • kdepimlibs 
  • kdepim-runtime 
  • libxml2 
  • libqalculate  
  • libxcomposite 
  • libmysqlclient 
  • libvorbis 
  • libshout 
  • sdl_image 
  • zvbi 
  • vlc
 The list above is a subset of the packages pacman wanted to download for the system upgrade; but at the same time they also form a superset of the packages I believed could cause my KDM issues.This solved my problem and now I am blogging from my revived linux system.


Caution:
Experiments like these should not be undertaken unless
1. You are crazy like me.
2. You have a backup system and have your /home folder on a separate partition so that even if your system can't be fixed, you can install a fresh new system without losing data. [You can also save configurations in /etc.]
3. You have sufficient bandwidth.

Saturday, 4 February 2012

Alarming state of linux distributions

A random peek at Distrowatch showed me that the top linux distributions were all losing popularity.

Does this mean linux is losing popularity or some rarely known distribution is gaining prominence in the background?

Sunday, 18 September 2011

Arch linux: my perspective

When I finally found an article covering Arch linux, I thought its time I write about the distribution I have been using for over two years. I switched to it from openSUSE. I have been a KDE user all along; seen transitions from stable 3.x to current 4.7.

I am a minimalist and Arch fits right in. It sure is "bleeding edge". Today only Chromium 14 was released and it was available in Arch repositories. In contrast in Gentoo, another rolling release distribution, the policy is they stabilize a package after a month without any bug reports about it. Due to this policy, Gentoo is still at Firefox 3.6.x while Arch provides me latest Firefox. Even when Firefox released an update after the DigiNotar issue, Arch also pushed the update to its repositories. With Gentoo's policy, it certainly is more stable. As Arch provides, bleeding edge software, you need to understand how to act/react when there are inconsistencies. Only yesterday, hit three bugs: filed one in KDE directly, another in Arch and another in Enlightenment. Another time, I was getting a bug related to valgrind because I had an updated version of it as Arch had pushed the update much before any other distribution. I should probably also mention that Arch released a patched version the following day.

Arch is really simple in the sense at the system level. I was able to create init scripts for Arch far more easily than on Gentoo for the same package. Arch however is not as configurable as Gentoo is. No distribution can match or even come close to Gentoo in this regard. It uses a unique system for this called USE flags. With Arch I can not have a custom KDE; but with Gentoo I have a large number of options as to what I want to have and what not. This flexibility of configuration in Gentoo comes at a price: every package is compiled on your system.

I have provided comparisions with Gentoo because it is the only distribution that has comparable features. Both of these distributions are in a way close to me. On my home desktop, I have Gentoo installed; but on my laptop where I do most of my development tasks, I use Arch linux and I do not see a distribution switch in near future.

For me, Arch surely is a base platform to do what I want to do. I have so to say three distributions in one: a distribution that provides nice command line environment, another that provides nice and stable KDE. I have even stopped akonadi and nepomuk search from starting up at all as they started mysql instances and I was not using any of them. The third one provides latest Enlightenment desktop. I compile it instead of using the packages in the repositories so that I am up to date and also to get debug symbols compiled in.

There have been some issues with Arch from time to time though. For example, the Ricoh card reader on my laptop works fine for some kernel versions; but does not work with others. Arch surely is not for the beginners. However, for advanced users, it provides a lean system which can be tweaked to taste.

Monday, 12 September 2011

Recovering Gentoo linux after changing hard disk channel

On my system I have two hard drives a 40 gb old one [reminiscent of the times when that much was enough] and a new one of 1tb. Initially both of them where on channel 2: the new one was the master disk while the old one was the slave disk. When I installed Gentoo, I tried

fdisk -l

and found the new one to be /dev/sda while the old one was /dev/sdb. So while installing grub, I assumed the following mapping:
hd0 --> sda --> 1tb hdd
hd1 --> sdb --> 40gb hdd

Grub was installed successfully and dual boot was working fine. [For those readers who are curious about getting a dual boot system, the best place is to look at the handbook.] However, when I got a new DVD writer, the old hard disk was connected at channel 0 as slave and the new one was connected at channel 2 as master. My BIOS was set to boot from the new one and Windows booted fine but I could not boot into Gentoo. So, I decided to fix it and chrooted into my Gentoo installation from the minimal install iso that I had put on to a usb stick using unetbootin. [Recently there have been questions about the performance of unetbootin. I would just like to add that when I tried unetbootin from Windows it failed me thrice with different distributions. However, when I tried it from linux, it worked just fine.]

From within the chrooted environment, I ran

fdisk -l

and found the old hard disk was now sda and the new one was sdb. So, I assumed the following mapping while reinstalling grub:
hd0 --> sda --> 40gb hdd
hd1 --> sdb --> 1tb hdd

However, when I rebooted, grub showed error 17. A quick look at Grub error collection shows that I had somehow got root(hdX, Y) wrong. While talking about the issue on #gentoo, I found that hd0 is actually the drive the BIOS is set to boot from. So, my assumed mapping was incorrect and it turned out that hd0 was being mapped to 11tb hard drive. So, I went into the BIOS and changed it so that the correct mapping was followed.

P.S. To know more about grub read this article.

Tuesday, 5 July 2011

GridFTP on Gentoo

The Globus Project provides gridftp as one of the modules of its toolkit. I got the source and followed the quickstart guide to start the installation. However, the guide tells you how to run myproxy-server and globus-gridftp-server as xinet daemons. Although Gentoo provides xinetd package, that is not their preferred way of handling daemons. They use their own init scripts. So, I have tried to do it their way. My first script was for myproxy-server.

#!/sbin/runscript

start() {
    ebegin "Starting myproxy-server"
    start-stop-daemon --start --exec /home/titu/soc/gt/sbin/myproxy-server    eend $?
}

stop() {
    ebegin "Stopping myproxy-server"
    start-stop-daemon --stop --exec /home/titu/soc/gt/sbin/myproxy-server
    eend $?
}


My next script was for starting globus-gridftp-server as a daemon; however this process has having problems when I tried it the way I did for myproxy-server. Sometimes start-stop-daemon was not returning and sometimes start-stop-daemon was unable to stop. I tried to store PID values in a pid file by asking start-stop-daemon to create the pidfile by using -m option. However, it turned out that the PID in the pidfile was always slightly less than the actual PID. It was most likely because of forking. So, I modified the script using killall.

#!/sbin/runscript

start() {
    ebegin "Starting globus-gridftp-server"
    start-stop-daemon --start -b -e GLOBUS_LOCATION=/home/titu/soc/gt -e LD_LIBRARY_PATH=/home/titu/soc/gt/lib --exec /home/titu/soc/gt/sbin/globus-gridftp-server -- -S -f -p 2811
    eend $?
}

stop() {
    ebegin "Stopping globus-gridftp-server"
    killall globus-gridftp-server
    eend $?
}


It is essential to set environment variables for the gridftp server.

Sunday, 3 July 2011

Automounting NTFS flash drives in Gentoo

Recently, I noticed flash drives with ntfs file systems on them were nicely automounted on my KDE on Archlinux. However, when I tried it in GNOME on Gentoo, it showed me an error message. Initially I thought if it is a desktop environment issue; but automounting is usually done by udev. So I decided to check for udev and ntfs-3g driver.

emerge -pv udev ntfs3g

I found that the ntfs3g package had "udev" USE flag disabled. I douted this might be the reason. To verify I ran a quick check using the following command.

equery u ntfs3g

I found "udev" USE flag installs udev rule to make udisks use ntfs-3g instead of the kernel NTFS driver. So, I
enabled it by adding the following line to /etc/portage/package.use

sys-fs/ntfs3g udev

Re-emerging the package solved the issue and I can nicely automount flash drives with ntfs filesystems.

Wednesday, 29 June 2011

Removing slotted libpng in Gentoo

While upgrading my Gentoo system, I upgraded gentoolkit package and I got a message saying asking me to run the following command.

glsa-check -p affected

Running it told me that there are no upgrades available for libpng-1.2.44. I found out that there were multiple versions of libpng installed on my system:
  • libpng-1.4.5 and;
  • a slotted version, i.e. libpng-1.2.44.

The solution was to remove all versions of libpng and freshly install it. This can be achieved using the following command.

emerge -C libpng && emerge -1 libpng:0

Monday, 20 June 2011

Installing Google Talk plugin in Gentoo linux

Google provides Google Talk plugin as rpm or deb packages for 32-bit and 64-bit architectures. To get it on Gentoo when you try

emerge -pv google-talkplugin

you can see that it is masked by license. It means you have to accept the license before installing. You can find all licenses at /usr/portage/licenses. To get a specific license try

ls /usr/portage/licenses | grep google

You can read the license and if you accept it then add a line to /etc/portage/package.license to reflect it. In this case, the line would be

www-plugins/google-talkplugin google-talkplugin

and in general it is:

<full package name> <license name>

Now when you try emerging it you get a message saying that the license does not allow mirroring. This is why the fetch restriction is in place. The message also tells you to download the .deb package suitable to your architecture and put it in /usr/portage/distfiles. The problem is Google provides you current version and not the version considered stable by Gentoo. Moreover, the version 1.8 which is considered stable by Gentoo is not available according a Gentoo bug [I wish I had found that out earlier].

So the 1.8 version ebuild is for those who have a copy of the older Google Talk plugin. All others have to unmask the newer version according to their architectures. I had to add the following line to /etc/portage/package.keywords.

=www-plugins/google-talkplugin-2.1.6.0 ~amd64

Now portage can fetch it for you. However, if you have already downloaded latest version of the plugin then you can use the command as root to copy it to you distfiles folder and portage will not have any checksum error either if the versions have not changed.

cp -v Downloads/google-talkplugin_current_amd64.deb /usr/portage/distfiles/google-talkplugin_2.1.6.0-1_amd64.deb

Now portage will not have to redownload the package.

Saturday, 18 June 2011

Bootcharting Gentoo baselayout 2

In this post I shall share my experience of yet another Gentoo installation. I keep coming back to this distribution for its stability, wonderful package management and the experiencing fine grained control.

I have been using KDE for over six years now. I wanted to try GNOME 3. However, as I found out GNOME 3 is not yet stabilized in Gentoo so I had to be content with GNOME 2. They are stabilization by the next release. I believe that it for good reason. Well GNOME 3 does not support Compiz. There are no multiple timezone clocks.

Having prior experience in installing Gentoo linux, I knew that following the handbook strictly you have to wait for downloads while there is compilation going on and vice versa. So this time I chrooted not from a single terminal but from multiple terminals. I could run package downloads separately using

emerge -f <package name>

and compile concurrently on a different terminal using

emerge <different package>

After installation, when I booted the system hung up.

Hung up Gentoo bootscreen

I read a line saying

Ext3-fs: couldn't mount because of unsupported optional features(240)

Adding the following to the kernel line solved the issue.

rootfstype=ext4

However, I was still getting a hung up system. If I inserted or removed USB drives, I was getting appropriate messages printed on screen; but the system was not responding to any keystrokes or mouse, neither was it loading X. Only the error line was gone. So, I understood that it was not the filesystem issue that was causing it. Asking on #gentoo I found that it was a common issue caused by the switch to baselayout 2. Instead of old init scripts Gentoo had started using openRC. Last time  heard about it was about a couple of years ago. It was a nice project started by Roy Marples. However, now it was stable and I was happy to be using it. My issue was solved following Alex's suggestions for the issue.

I wanted to see the boot time with baselayout 2 and openRC so after I had other installations I did a boot chart to find much faster boot than my previous installation on the same machine.
Also noteworthy was the fact that X worked out of the box and I was surprised to see Firefox 3.6.17 in stable tree. I was expecting Firefox 4.0. Well I hope it is stabilized soon.

Tuesday, 8 March 2011

The Beauty of a Gentoo installation

I have installed various linux distributions so far but Gentoo installation has an unmatched beauty to it. It is special because you can stop the installation and resume it at will. You just need to chroot back in if you have not completed the base system installation. Once the base system is installed, you can keep adding features at your pace and suiting your internet speed.

Unlike other distributions, Gentoo offers very fine-grained control over the packages you install and what features those packages have enabled. This is done using USE flags.

If you are looking a graphical installer that does its job without asking you much, this is not for you; but if you want robust control with proper dependency checking and stability, Gentoo is the right choice for you.

While other distributions have trouble connecting to the internet from their install environments, Gentoo minimal install environment had Intel Wireless microcode (iwl3945-ucode) and I could connect to a WPA network and do the installation.

Support on #gentoo sets Gentoo apart from every other distribution. I have solved problems of other distributions on this channel. Every time you have an issue, you can find someone here to help you out.

The beauty of the installation process lies in the freedom and the host of options that it allows you.

Sunday, 6 March 2011

Connecting to WPA networks

Wireless networks using WEP keys are not very secure. WPA keys should be preferred over WEP keys. To connect to a wireless network on linux, first store the passphrase in a configuration file with the following command:

wpa_passphrase "<your essid>" "<your passphrase>" > /etc/wpa_supplicant.conf

Set up WPA handshaking using

wpa_supplicant -Dwext -iwlan0 -B -c/etc/wpa_supplicant.conf

The option -Dwext specifies that generic linux wireless drivers should be used. The -B flag tells wpa_supplicant to work in the background. The -iwlan0 option specifies wlan0 as the interface for communication. Now set up dhcp client on wlan0 using

dhcpcd wlan0

Sunday, 26 December 2010

Sharing internet connection through Wlan

I wanted to share my internet connection with my roomies using wireless LAN. I had done it using bridging in Windows; but I hardly use Windows. So, I needed a solution in linux. I started discussing about it on IRC. At #gentoo, I met a French guy, named Francis Galiegue, who gave me an elegant solution.

We have three laptops and the connection is through wired ethernet. So, the solution was to use one laptop (mine) as a wireless access point giving access to the internet. In this setup, it is granted that the laptop has network connectivity to the internet, and that it has a WiFi device (internal or external) recognised by linux and the kernel is recent enough (2.6.27 or later is recommended). Once you meet the prequisites, there are four parts, which are solved by four linux daemons elegantly:

0. without even configuring the WiFi device, check that the laptop can connect to the internet
1. setting up basic iptables rules (see rule set 1);
2. cooking up a set of rules so that the laptop can access the Internet via the appropriate device (see rule set 2);
3. configure a DHCP server (using dhcpd), complete the firewall rule set to allow it to work (see rule set 3);
4. configure a name server (using BIND), complete the firewall rule set to allow it to work (see rule set 4);
5. configure an access point (using hostapd) - and no, no firewall rules are necessary for the access point to operate (iptables operates at the network layer, hostapd operates below that level);
6. complete firewall configuration so that "client" computers (the other laptops) can actually connect to the Internet.


Rule set #1:

The goal here is to create a generic table which uses Linux's netfilter connection tracking abilities. Here we use the "state" module, which recognizes four states:
  1. ESTABLISHED: the incoming packet is part of a connection known toLinux' connection tracking;
  2. RELATED: the incoming packet either directly relates to, or establishes a new connection related to, a connection known to Linux's connection tracking - such packets are of two types:
    1. ICMP messages (such as: "no route to host", "access prohibited", others);
    2. connection triggers from builtin modules (such as FTP data connections, others);
  3. INVALID: the incoming packet has an invalid payload (header length and/or checksum mismatch at the network layer or upper);
  4. NEW: the incoming packet tries to initiate a new connection.
We create a new chain, named "connstate" (ie, "connection state"), attached to the "filter" table. The purpose of this chain will be to handle all four connection states known to the "state" module. Eventually, all packets, either incoming (INPUT), outgoing (OUTPUT) or going through (FORWARD) will go through this chain, except for the loopback interface (lo), which is special:


#
# Create the chain - note that by default, if the table (the -t option of
# iptables) is not specified, the default is filter - this is what we want
#
iptables -N connstate
#
# All packets of connections already known to netfilter's state tracking
# (ESTABLISHED) or directly related (RELATED) should pass
#
iptables -A connstate -m state --state ESTABLISHED,RELATED -j ACCEPT
#
# All packets deemed invalid by netfilter should be dropped
#
iptables -A connstate -m state --state INVALID -j DROP
#
# From then on, packets have to be NEW. One thing: if the packet is TCP and does
# not have the SYN bit set (which it should have, see RFC 793) should be
# dropped...
#
iptables -A connstate -m state --state NEW -p tcp ! --syn -j DROP
#
# Any other NEW packets are returned to the caller
#
iptables -A connstate -m state --state NEW -j RETURN
#
# Normally, no packet ever should reach this point, netfilter must/will have
# sorted them out earlier on. If not, this is clearly a bug, so log them at the
# highest log level avaibale (CRIT == critical), and drop them for safety.
#
iptables -A connstate -j LOG --log-level CRIT --log-prefix "CONNSTATE BARF: "
iptables -A connstate -j DROP
#
# There is one exception to the rules above: the loopback interface. Packets
# going through the loopback will not go through the normal chain processing,
# we need to accept them unconditionally at the input and output phase.
#
iptables -A INPUT -i lo -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
#
# From here on, the first thing to do is to make all packets of all builtin
# chains of the filter table go through this chain.
#
for i in INPUT OUTPUT FORWARD; do iptables -A $i -j connstate;done

At this stage, this chain enforces no restriction on incoming or outgoing traffic, except for two quite important things:
  1. no TCP and/or IP header fragmentation attack is possible anymore: as soon as you use connection tracking (as we do here), the firewalling engine must have all protocol headers to decide how to deal with the whole packet (attempted fragmentation attacks will be deemed INVALID and therefore DROPped);
  2. some stack implementations disobey RFC 793 with respect to TCP connection initiation, since they don't set the SYN bit on the initial TCP packet of the connection: these will be dropped as well (observed with some versions of Windows).

Rule set #2:

We proceed to allow ICMP (ping) traffic from the wifi interface.


iptables -N local_to_eth0
iptables -A local_to_eth0 -j ACCEPT
iptables -A OUTPUT -o eth0 -j local_to_eth0
iptables -N ping
iptables -A ping -p icmp --icmp-type echo-request -m limit --limit 2/sec -j ACCEPT
iptables -A ping -p icmp --icmp-type echo-request -m limit --limit 2/sec -j DROP
iptables -N eth0_to_local
iptables -A eth0_to_local -j ping
iptables -A INPUT -i eth0 -j eth0_to_local
for i in INPUT OUTPUT FORWARD; do iptables -P $i DROP;done


Rule set #3:

We proceed to allow ICMP (ping) traffic from the wifi interface.


iptables -N dhcp
iptables -A dhcp -p udp --dport 67:68 -j ACCEPT
iptables -N wlan0_to_local
iptables -A wlan0_to_local -j ping
iptables -A wlan0_to_local -j dhcp
iptables -A INPUT -i wlan0 -j wlan0_to_local


There are two ways of being a gateway:

  1. configure a dhcp server and bind
  2. use dnsmasq

We are using the former method here. So, you might want to query your package manager for dhcpd and bind to see whether they are installed.

Next, find out your domain name (hostname -f). Let us say your domain name is "domain_name". Now pick a hostname for your system, say "hostname.domain_name". You might opt for a two component domain name. Now, proceed to assign the selected hostname to your system. Pick an IP in RFC1918 range to assign to this name, say 192.168.1.4. Edit /etc/hosts and add the following line:


192.168.1.4 hostname.domain_name hostname


Now let us ensure that the hostname is assigned to the machine at boot time. It can be done by editting /etc/conf.d/net and /etc/conf.d/hostname in Gentoo linux or by editting /etc/rc.conf in Arch linux. (Set it to the full qualified hostname, i.e. "hostname.domain_name" not just "hostname".)

Next, we setup wlan0 with the address 192.168.1.4 and a /24 subnet mask. It can be done using ifconfig as follows:

ifconfig wlan0 192.168.1.4 netmask 255.255.255.0

This can also be put into /etc/rc.conf so that it is done each time during boot. You may wish to cross check the IP of the wifi device. (See ifconfig ouput and try to ping the IP.)

Now, we configure the DNS server daemon, named. First of all, we are going to create two zone files: one for "domain_name" and the other for 1.168.192.in-addr.arpa. The file /var/named/pri/domain_name.zone is as follows:

$TTL 1d
@       IN      SOA     hostname.domain_name. you.email.address.here.  (
                                      2010102401 ; Serial
                                      28800      ; Refresh
                                      14400      ; Retry
                                      3600000    ; Expire
                                      86400 )    ; Minimum
              IN      NS      fool.man.machine.

5 IN PTR hostname.domain_name.


Now, we edit the named.conf as follows:


//
// /etc/named.conf
//

acl "trusted" {
127.0.0.0/8;
        ::1/128;
        10.142.81.0/24;
};

options {
directory "/var/named";
pid-file "/var/run/named/named.pid";
auth-nxdomain yes;
datasize default;
// Uncomment these to enable IPv6 connections support
// IPv4 will still work:
// listen-on-v6 { any; };
// Add this for no IPv4:
// listen-on { none; };
listen-on {
127.0.0.1;
192.168.1.4;
};


// Default security settings.
allow-query {
trusted;
};
allow-recursion { 127.0.0.1; };
allow-transfer { none; };
allow-update { none; };
version none;
hostname none;
server-id none;

// FORWARDING
forward first;
forwarders {
// The service provider's DNS first
<nameserver>;
<nameserver>;
<nameserver>;
<nameserver>;
                4.2.2.1;                // Level3 Public DNS
                4.2.2.2;                // Level3 Public DNS
                8.8.8.8; // Google Open DNS
                8.8.4.4; // Google Open DNS
};
};

view "internal" in {
match-clients { trusted; };
recursion yes;
additional-from-auth yes;
additional-from-cache yes;

zone "localhost" IN {
type master;
file "localhost.zone";
allow-transfer { any; };
};

zone "0.0.127.in-addr.arpa" IN {
type master;
file "127.0.0.zone";
allow-transfer { any; };
};

zone "." IN {
type hint;
file "root.hint";
};

zone "domain_name" {
type master;
file "pri/domain_name.zone";
allow-update {
none;
};
notify no;
};

zone "1.168.192.in-addr.arpa" {
type master;
file "pri/1.168.192.in-addr.arpa.zone";
allow-update {
none;
};
notify no;
};
};

logging {
        channel xfer-log {
                file "/var/log/named.log";
                print-category yes;
                print-severity yes;
                print-time yes;
                severity info;
        };
        category xfer-in { xfer-log; };
        category xfer-out { xfer-log; };
        category notify { xfer-log; };
};

Now, lets start the server. On Arch, I do it using the following command.

/etc/rc.d/named start

We then edit /etc/resolv.conf.head to add the following line

search domain_name

and /etc/resolv.conf.tail to add the following line.

nameserver 127.0.0.1

Now, the nameserver can be tested using commands like the following.

host hostname.domain_name 127.0.0.1
host slashdot.org 127.0.0.1


You might like to add named to the list of daemons to be started at boot time. I prefer starting them each time.

Rule set #4:

# create a new chain
iptables -N local_to_wlan0
# the only rule of this chain is to accept
iptables -A local_to_wlan0 -j ACCEPT
# In the OUTPUT chain, every packet going out by wlan0 interface is branched out to
# local_to_wlan0 and as a result everything out to wlan0 is accepted.
iptables -A OUTPUT -o wlan0 -j local_to_wlan0


The following iptables rules are to allow the other machines in the LAN to access the DNS server.
Bind listens to TCP/53 and UDP/53 and thus traffic on those ports is accepted.

Rule set #5:

iptables -N named
iptables -A named -p udp --dport 53 -j ACCEPT
iptables -A named -p tcp --dport 53 -j ACCEPT
iptables -A wlan0_to_local -j named


We proceed to configure the dhcp server. The configuration in /etc/dhcpd.conf is as follows:

#
# We don't want dynamic DNS here
#
ddns-update-style none;
subnet 192.168.1.0 netmask 255.255.255.0 {
authoritative;
option subnet-mask 255.255.255.0;
option domain-name "domain_name";
option domain-name-servers 192.168.1.4;
option routers 192.168.1.4;

pool {
range 192.168.1.2 192.168.1.254;
allow unknown-clients;
}
}


Then we have a final set of rules to connect the two interfaces.

Rule set #6:

iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
iptables -N wlan0_to_eth0
iptables -A wlan0_to_eth0 -j ACCEPT
iptables -A FORWARD -i wlan0 -o eth0 -j wlan0_to_eth0


The last piece is hostapd configuration. It is given as follows:

interface=wlan0
driver=nl80211
logger_syslog=-1
logger_syslog_level=0
logger_stdout=-1
logger_stdout_level=0
dump_file=/tmp/hostapd.dump
ctrl_interface=/var/run/hostapd
ctrl_interface_group=0
ssid=test
hw_mode=a
channel=60
beacon_int=100
dtim_period=2
max_num_sta=255
rts_threshold=2347
fragm_threshold=2346
macaddr_acl=0
auth_algs=3
ignore_broadcast_ssid=0
wmm_enabled=1
wmm_ac_bk_cwmin=4
wmm_ac_bk_cwmax=10
wmm_ac_bk_aifs=7
wmm_ac_bk_txop_limit=0
wmm_ac_bk_acm=0
wmm_ac_be_aifs=3
wmm_ac_be_cwmin=4
wmm_ac_be_cwmax=10
wmm_ac_be_txop_limit=0
wmm_ac_be_acm=0
wmm_ac_vi_aifs=2
wmm_ac_vi_cwmin=3
wmm_ac_vi_cwmax=4
wmm_ac_vi_txop_limit=94
wmm_ac_vi_acm=0
wmm_ac_vo_aifs=2
wmm_ac_vo_cwmin=2
wmm_ac_vo_cwmax=3
wmm_ac_vo_txop_limit=47
wmm_ac_vo_acm=0
eap_server=0
own_ip_addr=127.0.0.1
wpa=1
wpa_passphrase=<your passphrase>

Each time I can start sharing using the following commands.

ifconfig wlan0 192.168.1.4 netmask 255.255.255.0
/etc/rc.d/iptables start
/etc/rc.d/hostapd start
/etc/rc.d/dhcpd start
/etc/rc.d/named start


For a rather detailed reading, check out this webpage.

Thursday, 23 September 2010

Connecting to BSNL on linux

I have used BSNL broadband connection for some years now and have connected to the internet through BSNL on various linux distributions like Arch, Gentoo, openSUSE and Debian. I shall share the procedure for the same here. However, before the procedure I would like mention some basics.


  • Basic information
BSNL uses point to point protocol over ethernet (pppoe). So, your kernel should have it enabled. If you want to share your connection through another ethernet port or wifi; then you might be interested in bridging options too. DNS information is obtained from BSNL; you do not have to set it.
  • openSUSE

The easiest of them all is getting it done in openSUSE. The package needed is kinternet; so ensure that you have it installed during initial setup [It is not selected by default in the installer]. In YaST, configure the ethernet interface, which most likely would be eth0. Use static address 192.168.1.2 and subnet mask 255.255.255.0. Configure the gateway 192.168.1.1. The DNS is obtained from the ISP. Clicking the kinternet icon in the tray should get you connected.
  • Gentoo

Gentoo lets users configure their kernels. Make sure your kernel meets the requirements mentioned in the Basics section. I prefer using Roaring Penguin PPPoE scripts. Install them during your installation. To configure before first use, issue the following command as root.
pppoe-setup
Provide you username and password when asked. Enter 'server' when asked for DNS servers. The defaults should do for the rest. Edit /etc/rc.conf to configure the ethernet interface as follows:


eth0="eth0 192.168.1.2 netmask 255.255.255.0 broadcast 192.168.1.255"


INTERFACES=(eth0)


To start and stop the connection, use the commands pppoe-start and pppoe-stop. In case, you can connect yet can't view web pages then set the obtained IP address for the pppoe interface as your DNS server. You may also need to specify the default gateway in rc.conf as 192.168.1.1.
  • Debian

Debian also uses Roaring Penguin scripts. Configure as mentioned for Gentoo and Debian shall connect automatically.
  • Arch

Arch uses the same scripts. However, you will have to issue the commands as in Gentoo.

Thursday, 8 April 2010

Distribution change

So far, I have tried various flavours of linux. I have tasted various desktop environments, stability policies, maintainance policies and packaging policies. I have tried KDE 3, KDE 4, GNOME, Enlightenment, XFCE. KDE 3 is undoubtedly "rock solid". GNOME is simple. XFCE is leaner GNOME. KDE 4 has slowed down with semantic desktop. However, much of the work is yet to be done to get back the old KDE feel. Enlightement is fast and stable; however the development is on. I like working in Enlightenment. However, I also have KDE 4.

Coming down to packaging, I have experienced .debs, .rpms and compressed source files. I also have rpm packaging experience. I would say all of them solve different purposes. They define (or may be match) the distro's policies and philosophies. For business oriented distros, rpms are a good choice. However, Debian's package management is also nice. It is a mark of their stability. Compressed source files however are the most flexible ones. Gentoo's packaging clearly reflects its philosophy of flexibility.

I had been running openSUSE for a long time now. Recently, I had decided to go for a change. I wanted to go for a rolling release as I wanted to keep at the edge of technology. Moreover, events like the okular problem inclined me towards rolling release distros.

The first option that came to my mind was Gentoo: its a lovely distro. However, I didn't have time for all the compilation so I thought of trying Arch. Distrowatch said its a lean distro that provides bleeding edge software. I downloaded the netinstall image and started my installation. After multiple Gentoo installs (successful ones), I was ready for it as soon as I had the image copied to my USB stick.

One common problem that I face while installing any distro is that my internet connection is PPPoE and not many people have it so its hard to find help regarding that. To add to it, I don't like to download unnecessary packages or large images. So, I spent some time trying to figure out how to connect during installation. Once that was done, I had a pretty smooth install. Arch linux is a nice experience. However, I miss Gentoo's community support on Arch. #gentoo is far more responsive and friendly than #archlinux. Interestingly, I solved Arch problems while talking at #gentoo.

I had KDE 4 installed on it. Then I moved on to get the latest svn snapshot of Enlightenment and installed it. Both are working fine. Arch's package management is not as flexible as portage in Gentoo. Also, sometimes you need to know your way around. For example, I had installed Ark on KDE; but was not able to unzip any of my .zip files. It was because I had installed zip with it; but not unzip. After installing unzip, its working fine.

Tuesday, 16 March 2010

Okular problem

Recently, poppler was having a bogus memory allocation bug. It had creeped into okular. Some pdf files were rendered okay; while some others flashed instantaneously and closed. The problem was on both of my systems openSUSE and Gentoo. As soon as poppler fixed the issue, Gentoo was quick at releasing it in stable tree. It was back in February.However, not until a couple of days back was the patch provided by openSUSE. Meanwhile, the inability of accessing my documents was really pissing me off. As my linux experience has evolved, I have gradually drifted away from openSUSE; though I love it as my first distro and still have it on my laptop.

Wednesday, 16 December 2009

Improving boot time on Gentoo




Continuing with my attempts at reducing boot time on my Gentoo x86_64 running desktop, I tried switching off interactive boot and booted in about 20 seconds.


To improve booting, I tried prelinking. However, to my surprise it increased boot time.

Wednesday, 2 December 2009

Slower boot on newer kernels

Recently, I upgraded my kernel on my Gentoo x86 and patched my kernel on openSUSE 11.1 x86_64. I found both booted slower than when I charted booting last time, earlier this year.


The increase in boot-time was more in case of openSUSE compared to Gentoo.

Tuesday, 20 October 2009

Screen brightness

The brightness of the lcd of my Thinkpad R60 was an issue for me because I could only decrease the brightness using Fn+End; but could not increase it using Fn+Home as the Home key was defunct.

I figured may be changing some ".conf" can help me out. I checked out with people at #gentoo. Just as I expected, I just had to write appropriate integer values to
/sys/class/backlight
From the maxbrightness file I found the max value for my system was 7. Checking the brightness file, I found the current screen brightness to be at 0. Setting it to 4 was fine with me.

Wednesday, 30 September 2009

Kernel upgrade

For some time I had been trying to upgrade the kernel on my Gentoo box from 2.6.29 to 2.6.30. I was interested in 2.6.30 kernel because of three reasons.

#1 From what I remembered from the experiements with sreadahead, this kernel was supposed to support it well. However, recently when I dug into the topic, Jeremy told me that it is very much a dead project now. I still have baselayout2 and openRC to tinker with to obtain boot speed improvements.

#2 I had a secondary LAN port installed. So, I had to configure my kernel for that. I decided that since a new kernel is available, I shall install the driver and the kernel too.

#3 This kernel supports LZMA compression. I was interested in trying it out.

I compiled the kernel fine, editted grub.conf and rebooted into my experiemental kernel. During the boot, I could clearly see that sreadahead was a dead project. It took me straight to kdm screen. However, after kdm the system froze.

My first idea was to check the command line. So, I restarted and from kdm went to command line. Invoking the following, I found that the driver for the LAN interface was fine.
lspci -k
I was clueless as to what went wrong. I thought I might need to build xorg-server, input drivers and video drivers against my new kernel. So, I ran the following command.
emerge -v xorg-server xf86-video-intel xf86-input-evdev
After that once again, I tried to get back to GUI using. However the system froze again. I thought lets get some help. Checking on #gentoo, I was suggested to try what I had done as explained above. I kept looking at IRC for four days without any solution to my problem. Then, thinking my KDE might be having issues, I tried at #gentoo-kde where Aleister suggested I might have enabled KMS and using xorg-server 1.5 at the same time. My X server log file at
/var/log/Xorg.0.log.old
was reporting fatal server error. Checking my menuconfig, I found that he was right. Disabling that option, I was able to do away with system freezes. All I lost was the two penguins that appeared during boot. The problem was xorg-server 1.5 does not support kernel mode setting (KMS).