1 <?xml version=
"1.0" encoding=
"utf-8"?>
2 <rss version='
2.0' xmlns:lj='http://www.livejournal.org/rss/lj/
1.0/' xmlns:
atom=
"http://www.w3.org/2005/Atom">
4 <title>Petter Reinholdtsen
</title>
5 <description></description>
6 <link>http://people.skolelinux.org/pere/blog/
</link>
7 <atom:link href=
"http://people.skolelinux.org/pere/blog/index.rss" rel=
"self" type=
"application/rss+xml" />
10 <title>Install hardware dependent packages using tasksel (Isenkram
0.7)
</title>
11 <link>http://people.skolelinux.org/pere/blog/Install_hardware_dependent_packages_using_tasksel__Isenkram_0_7_.html
</link>
12 <guid isPermaLink=
"true">http://people.skolelinux.org/pere/blog/Install_hardware_dependent_packages_using_tasksel__Isenkram_0_7_.html
</guid>
13 <pubDate>Wed,
23 Apr
2014 14:
50:
00 +
0200</pubDate>
14 <description><p
>It would be nice if it was easier in Debian to get all the hardware
15 related packages relevant for the computer installed automatically.
16 So I implemented one, using
17 <a href=
"http://packages.qa.debian.org/isenkram
">my Isenkram
18 package
</a
>. To use it, install the tasksel and isenkram packages and
19 run tasksel as user root. You should be presented with a new option,
20 "Hardware specific packages (autodetected by isenkram)
". When you
21 select it, tasksel will install the packages isenkram claim is fit for
22 the current hardware, hot pluggable or not.
<p
>
24 <p
>The implementation is in two files, one is the tasksel menu entry
25 description, and the other is the script used to extract the list of
26 packages to install. The first part is in
27 <tt
>/usr/share/tasksel/descs/isenkram.desc
</tt
> and look like
30 <p
><blockquote
><pre
>
33 Description: Hardware specific packages (autodetected by isenkram)
34 Based on the detected hardware various hardware specific packages are
36 Test-new-install: mark show
38 Packages: for-current-hardware
39 </pre
></blockquote
></p
>
41 <p
>The second part is in
42 <tt
>/usr/lib/tasksel/packages/for-current-hardware
</tt
> and look like
45 <p
><blockquote
><pre
>
50 isenkram-autoinstall-firmware -l
52 </pre
></blockquote
></p
>
54 <p
>All in all, a very short and simple implementation making it
55 trivial to install the hardware dependent package we all may want to
56 have installed on our machines. I
've not been able to find a way to
57 get tasksel to tell you exactly which packages it plan to install
58 before doing the installation. So if you are curious or careful,
59 check the output from the isenkram-* command line tools first.
</p
>
61 <p
>The information about which packages are handling which hardware is
62 fetched either from the isenkram package itself in
63 /usr/share/isenkram/, from git.debian.org or from the APT package
64 database (using the Modaliases header). The APT package database
65 parsing have caused a nasty resource leak in the isenkram daemon (bugs
66 <a href=
"http://bugs.debian.org/
719837">#
719837</a
> and
67 <a href=
"http://bugs.debian.org/
730704">#
730704</a
>). The cause is in
68 the python-apt code (bug
69 <a href=
"http://bugs.debian.org/
745487">#
745487</a
>), but using a
70 workaround I was able to get rid of the file descriptor leak and
71 reduce the memory leak from ~
30 MiB per hardware detection down to
72 around
2 miB per hardware detection. It should make the desktop
73 daemon a lot more useful. The fix is in version
0.7 uploaded to
74 unstable today.
</p
>
76 <p
>I believe the current way of mapping hardware to packages in
77 Isenkram is is a good draft, but in the future I expect isenkram to
78 use the AppStream data source for this. A proposal for getting proper
79 AppStream support into Debian is floating around as
80 <a href=
"https://wiki.debian.org/DEP-
11">DEP-
11</a
>, and
81 <a href=
"https://wiki.debian.org/SummerOfCode2014/Projects#SummerOfCode2014.2FProjects
.2FAppStreamDEP11Implementation.AppStream
.2FDEP-
11_for_the_Debian_Archive
">GSoC
82 project
</a
> will take place this summer to improve the situation. I
83 look forward to seeing the result, and welcome patches for isenkram to
84 start using the information when it is ready.
</p
>
86 <p
>If you want your package to map to some specific hardware, either
87 add a
"Xb-Modaliases
" header to your control file like I did in
88 <a href=
"http://packages.qa.debian.org/pymissile
">the pymissile
89 package
</a
> or submit a bug report with the details to the isenkram
91 <a href=
"http://people.skolelinux.org/pere/blog/tags/isenkram/
">all my
92 blog posts tagged isenkram
</a
> for details on the notation. I expect
93 the information will be migrated to AppStream eventually, but for the
94 moment I got no better place to store it.
</p
>
99 <title>FreedomBox milestone - all packages now in Debian Sid
</title>
100 <link>http://people.skolelinux.org/pere/blog/FreedomBox_milestone___all_packages_now_in_Debian_Sid.html
</link>
101 <guid isPermaLink=
"true">http://people.skolelinux.org/pere/blog/FreedomBox_milestone___all_packages_now_in_Debian_Sid.html
</guid>
102 <pubDate>Tue,
15 Apr
2014 22:
10:
00 +
0200</pubDate>
103 <description><p
>The
<a href=
"https://wiki.debian.org/FreedomBox
">Freedombox
104 project
</a
> is working on providing the software and hardware to make
105 it easy for non-technical people to host their data and communication
106 at home, and being able to communicate with their friends and family
107 encrypted and away from prying eyes. It is still going strong, and
108 today a major mile stone was reached.
</p
>
110 <p
>Today, the last of the packages currently used by the project to
111 created the system images were accepted into Debian Unstable. It was
112 the freedombox-setup package, which is used to configure the images
113 during build and on the first boot. Now all one need to get going is
114 the build code from the freedom-maker git repository and packages from
115 Debian. And once the freedombox-setup package enter testing, we can
116 build everything directly from Debian. :)
</p
>
118 <p
>Some key packages used by Freedombox are
119 <a href=
"http://packages.qa.debian.org/freedombox-setup
">freedombox-setup
</a
>,
120 <a href=
"http://packages.qa.debian.org/plinth
">plinth
</a
>,
121 <a href=
"http://packages.qa.debian.org/pagekite
">pagekite
</a
>,
122 <a href=
"http://packages.qa.debian.org/tor
">tor
</a
>,
123 <a href=
"http://packages.qa.debian.org/privoxy
">privoxy
</a
>,
124 <a href=
"http://packages.qa.debian.org/owncloud
">owncloud
</a
> and
125 <a href=
"http://packages.qa.debian.org/dnsmasq
">dnsmasq
</a
>. There
126 are plans to integrate more packages into the setup. User
127 documentation is maintained on the Debian wiki. Please
128 <a href=
"https://wiki.debian.org/FreedomBox/Manual/Jessie
">check out
129 the manual
</a
> and help us improve it.
</p
>
131 <p
>To test for yourself and create boot images with the FreedomBox
132 setup, run this on a Debian machine using a user with sudo rights to
133 become root:
</p
>
136 sudo apt-get install git vmdebootstrap mercurial python-docutils \
137 mktorrent extlinux virtualbox qemu-user-static binfmt-support \
139 git clone http://anonscm.debian.org/git/freedombox/freedom-maker.git \
141 make -C freedom-maker dreamplug-image raspberry-image virtualbox-image
142 </pre
></p
>
144 <p
>Root access is needed to run debootstrap and mount loopback
145 devices. See the README in the freedom-maker git repo for more
146 details on the build. If you do not want all three images, trim the
147 make line. Note that the virtualbox-image target is not really
148 virtualbox specific. It create a x86 image usable in kvm, qemu,
149 vmware and any other x86 virtual machine environment. You might need
150 the version of vmdebootstrap in Jessie to get the build working, as it
151 include fixes for a race condition with kpartx.
</p
>
153 <p
>If you instead want to install using a Debian CD and the preseed
154 method, boot a Debian Wheezy ISO and use this boot argument to load
155 the preseed values:
</p
>
158 url=
<a href=
"http://www.reinholdtsen.name/freedombox/preseed-jessie.dat
">http://www.reinholdtsen.name/freedombox/preseed-jessie.dat
</a
>
159 </pre
></p
>
161 <p
>I have not tested it myself the last few weeks, so I do not know if
162 it still work.
</p
>
164 <p
>If you wonder how to help, one task you could look at is using
165 systemd as the boot system. It will become the default for Linux in
166 Jessie, so we need to make sure it is usable on the Freedombox. I did
167 a simple test a few weeks ago, and noticed dnsmasq failed to start
168 during boot when using systemd. I suspect there are other problems
169 too. :) To detect problems, there is a test suite included, which can
170 be run from the plinth web interface.
</p
>
172 <p
>Give it a go and let us know how it goes on the mailing list, and help
173 us get the new release published. :) Please join us on
174 <a href=
"irc://irc.debian.org:
6667/%
23freedombox
">IRC (#freedombox on
175 irc.debian.org)
</a
> and
176 <a href=
"http://lists.alioth.debian.org/mailman/listinfo/freedombox-discuss
">the
177 mailing list
</a
> if you want to help make this vision come true.
</p
>
182 <title>Språkkoder for POSIX locale i Norge
</title>
183 <link>http://people.skolelinux.org/pere/blog/Spr_kkoder_for_POSIX_locale_i_Norge.html
</link>
184 <guid isPermaLink=
"true">http://people.skolelinux.org/pere/blog/Spr_kkoder_for_POSIX_locale_i_Norge.html
</guid>
185 <pubDate>Fri,
11 Apr
2014 21:
30:
00 +
0200</pubDate>
186 <description><p
>For
12 år siden, skrev jeg et lite notat om
187 <a href=
"http://i18n.skolelinux.no/localekoder.txt
">bruk av språkkoder
188 i Norge
</a
>. Jeg ble nettopp minnet på dette da jeg fikk spørsmål om
189 notatet fortsatt var aktuelt, og tenkte det var greit å repetere hva
190 som fortsatt gjelder. Det jeg skrev da er fortsatt like aktuelt.
</p
>
192 <p
>Når en velger språk i programmer på unix, så velger en blant mange
193 språkkoder. For språk i Norge anbefales følgende språkkoder (anbefalt
194 locale i parantes):
</p
>
197 <dt
>nb (nb_NO)
</dt
><dd
>Bokmål i Norge
</dd
>
198 <dt
>nn (nn_NO)
</dt
><dd
>Nynorsk i Norge
</dd
>
199 <dt
>se (se_NO)
</dt
><dd
>Nordsamisk i Norge
</dd
>
200 </dl
></p
>
202 <p
>Alle programmer som bruker andre koder bør endres.
</p
>
204 <p
>Språkkoden bør brukes når .po-filer navngis og installeres. Dette
205 er ikke det samme som locale-koden. For Norsk Bokmål, så bør filene
206 være navngitt nb.po, mens locale (LANG) bør være nb_NO.
</p
>
208 <p
>Hvis vi ikke får standardisert de kodene i alle programmene med
209 norske oversettelser, så er det umulig å gi LANG-variablen ett innhold
210 som fungerer for alle programmer.
</p
>
212 <p
>Språkkodene er de offisielle kodene fra ISO
639, og bruken av dem i
213 forbindelse med POSIX localer er standardisert i RFC
3066 og ISO
214 15897. Denne anbefalingen er i tråd med de angitte standardene.
</p
>
216 <p
>Følgende koder er eller har vært i bruk som locale-verdier for
217 "norske
" språk. Disse bør unngås, og erstattes når de oppdages:
</p
>
219 <p
><table
>
220 <tr
><td
>norwegian
</td
><td
>-
> nb_NO
</td
></tr
>
221 <tr
><td
>bokmål
</td
><td
>-
> nb_NO
</td
></tr
>
222 <tr
><td
>bokmal
</td
><td
>-
> nb_NO
</td
></tr
>
223 <tr
><td
>nynorsk
</td
><td
>-
> nn_NO
</td
></tr
>
224 <tr
><td
>no
</td
><td
>-
> nb_NO
</td
></tr
>
225 <tr
><td
>no_NO
</td
><td
>-
> nb_NO
</td
></tr
>
226 <tr
><td
>no_NY
</td
><td
>-
> nn_NO
</td
></tr
>
227 <tr
><td
>sme_NO
</td
><td
>-
> se_NO
</td
></tr
>
228 </table
></p
>
230 <p
>Merk at når det gjelder de samiske språkene, at se_NO i praksis
231 henviser til nordsamisk i Norge, mens f.eks. smj_NO henviser til
232 lulesamisk. Dette notatet er dog ikke ment å gi råd rundt samiske
234 <a href=
"http://www.divvun.no/
">Divvun-prosjektet
</a
> en bedre
237 <p
><strong
>Referanser:
</strong
></p
>
241 <li
><a href=
"http://www.rfc-base.org/rfc-
3066.html
">RFC
3066 - Tags
242 for the Identification of Languages
</a
> (Erstatter RFC
1766)
</li
>
244 <li
><a href=
"http://www.loc.gov/standards/iso639-
2/langcodes.html
">ISO
245 639</a
> - Codes for the Representation of Names of Languages
</li
>
247 <li
><a href=
"http://std.dkuug.dk/jtc1/sc22/wg20/docs/n897-
14652w25.pdf
">ISO
248 DTR
14652</a
> - locale-standard Specification method for cultural
249 conventions
</li
>
251 <li
><a href=
"http://std.dkuug.dk/jtc1/sc22/wg20/docs/n610.pdf
">ISO
252 15897: Registration procedures for cultural elements (cultural
254 <a href=
"http://std.dkuug.dk/jtc1/sc22/wg20/docs/n849-
15897wd6.pdf
">(nytt
255 draft)
</a
></li
>
257 <li
><a href=
"http://std.dkuug.dk/jtc1/sc22/wg20/
">ISO/IEC
258 JTC1/SC22/WG20
</a
> - Gruppen for i18n-standardisering i ISO
</li
>
265 <title>S3QL, a locally mounted cloud file system - nice free software
</title>
266 <link>http://people.skolelinux.org/pere/blog/S3QL__a_locally_mounted_cloud_file_system___nice_free_software.html
</link>
267 <guid isPermaLink=
"true">http://people.skolelinux.org/pere/blog/S3QL__a_locally_mounted_cloud_file_system___nice_free_software.html
</guid>
268 <pubDate>Wed,
9 Apr
2014 11:
30:
00 +
0200</pubDate>
269 <description><p
>For a while now, I have been looking for a sensible offsite backup
270 solution for use at home. My requirements are simple, it must be
271 cheap and locally encrypted (in other words, I keep the encryption
272 keys, the storage provider do not have access to my private files).
273 One idea me and my friends had many years ago, before the cloud
274 storage providers showed up, was to use Google mail as storage,
275 writing a Linux block device storing blocks as emails in the mail
276 service provided by Google, and thus get heaps of free space. On top
277 of this one can add encryption, RAID and volume management to have
278 lots of (fairly slow, I admit that) cheap and encrypted storage. But
279 I never found time to implement such system. But the last few weeks I
280 have looked at a system called
281 <a href=
"https://bitbucket.org/nikratio/s3ql/
">S3QL
</a
>, a locally
282 mounted network backed file system with the features I need.
</p
>
284 <p
>S3QL is a fuse file system with a local cache and cloud storage,
285 handling several different storage providers, any with Amazon S3,
286 Google Drive or OpenStack API. There are heaps of such storage
287 providers. S3QL can also use a local directory as storage, which
288 combined with sshfs allow for file storage on any ssh server. S3QL
289 include support for encryption, compression, de-duplication, snapshots
290 and immutable file systems, allowing me to mount the remote storage as
291 a local mount point, look at and use the files as if they were local,
292 while the content is stored in the cloud as well. This allow me to
293 have a backup that should survive fire. The file system can not be
294 shared between several machines at the same time, as only one can
295 mount it at the time, but any machine with the encryption key and
296 access to the storage service can mount it if it is unmounted.
</p
>
298 <p
>It is simple to use. I
'm using it on Debian Wheezy, where the
299 package is included already. So to get started, run
<tt
>apt-get
300 install s3ql
</tt
>. Next, pick a storage provider. I ended up picking
301 Greenqloud, after reading their nice recipe on
302 <a href=
"https://greenqloud.zendesk.com/entries/
44611757-How-To-Use-S3QL-to-mount-a-StorageQloud-bucket-on-Debian-Wheezy
">how
303 to use S3QL with their Amazon S3 service
</a
>, because I trust the laws
304 in Iceland more than those in USA when it come to keeping my personal
305 data safe and private, and thus would rather spend money on a company
306 in Iceland. Another nice recipe is available from the article
307 <a href=
"http://www.admin-magazine.com/HPC/Articles/HPC-Cloud-Storage
">S3QL
308 Filesystem for HPC Storage
</a
> by Jeff Layton in the HPC section of
309 Admin magazine. When the provider is picked, figure out how to get
310 the API key needed to connect to the storage API. With Greencloud,
311 the key did not show up until I had added payment details to my
314 <p
>Armed with the API access details, it is time to create the file
315 system. First, create a new bucket in the cloud. This bucket is the
316 file system storage area. I picked a bucket name reflecting the
317 machine that was going to store data there, but any name will do.
318 I
'll refer to it as
<tt
>bucket-name
</tt
> below. In addition, one need
319 the API login and password, and a locally created password. Store it
320 all in ~root/.s3ql/authinfo2 like this:
322 <p
><blockquote
><pre
>
324 storage-url: s3c://s.greenqloud.com:
443/bucket-name
325 backend-login: API-login
326 backend-password: API-password
327 fs-passphrase: local-password
328 </pre
></blockquote
></p
>
330 <p
>I create my local passphrase using
<tt
>pwget
50</tt
> or similar,
331 but any sensible way to create a fairly random password should do it.
332 Armed with these details, it is now time to run mkfs, entering the API
333 details and password to create it:
</p
>
335 <p
><blockquote
><pre
>
336 # mkdir -m
700 /var/lib/s3ql-cache
337 # mkfs.s3ql --cachedir /var/lib/s3ql-cache --authfile /root/.s3ql/authinfo2 \
338 --ssl s3c://s.greenqloud.com:
443/bucket-name
340 Enter backend password:
341 Before using S3QL, make sure to read the user
's guide, especially
342 the
'Important Rules to Avoid Loosing Data
' section.
343 Enter encryption password:
344 Confirm encryption password:
345 Generating random encryption key...
346 Creating metadata tables...
356 Compressing and uploading metadata...
357 Wrote
0.00 MB of compressed metadata.
358 #
</pre
></blockquote
></p
>
360 <p
>The next step is mounting the file system to make the storage available.
362 <p
><blockquote
><pre
>
363 # mount.s3ql --cachedir /var/lib/s3ql-cache --authfile /root/.s3ql/authinfo2 \
364 --ssl --allow-root s3c://s.greenqloud.com:
443/bucket-name /s3ql
365 Using
4 upload threads.
366 Downloading and decompressing metadata...
376 Mounting filesystem...
378 Filesystem Size Used Avail Use% Mounted on
379 s3c://s.greenqloud.com:
443/bucket-name
1.0T
0 1.0T
0% /s3ql
381 </pre
></blockquote
></p
>
383 <p
>The file system is now ready for use. I use rsync to store my
384 backups in it, and as the metadata used by rsync is downloaded at
385 mount time, no network traffic (and storage cost) is triggered by
386 running rsync. To unmount, one should not use the normal umount
387 command, as this will not flush the cache to the cloud storage, but
388 instead running the umount.s3ql command like this:
390 <p
><blockquote
><pre
>
393 </pre
></blockquote
></p
>
395 <p
>There is a fsck command available to check the file system and
396 correct any problems detected. This can be used if the local server
397 crashes while the file system is mounted, to reset the
"already
398 mounted
" flag. This is what it look like when processing a working
399 file system:
</p
>
401 <p
><blockquote
><pre
>
402 # fsck.s3ql --force --ssl s3c://s.greenqloud.com:
443/bucket-name
403 Using cached metadata.
404 File system seems clean, checking anyway.
405 Checking DB integrity...
406 Creating temporary extra indices...
407 Checking lost+found...
408 Checking cached objects...
409 Checking names (refcounts)...
410 Checking contents (names)...
411 Checking contents (inodes)...
412 Checking contents (parent inodes)...
413 Checking objects (reference counts)...
414 Checking objects (backend)...
415 ..processed
5000 objects so far..
416 ..processed
10000 objects so far..
417 ..processed
15000 objects so far..
418 Checking objects (sizes)...
419 Checking blocks (referenced objects)...
420 Checking blocks (refcounts)...
421 Checking inode-block mapping (blocks)...
422 Checking inode-block mapping (inodes)...
423 Checking inodes (refcounts)...
424 Checking inodes (sizes)...
425 Checking extended attributes (names)...
426 Checking extended attributes (inodes)...
427 Checking symlinks (inodes)...
428 Checking directory reachability...
429 Checking unix conventions...
430 Checking referential integrity...
431 Dropping temporary indices...
432 Backing up old metadata...
442 Compressing and uploading metadata...
443 Wrote
0.89 MB of compressed metadata.
445 </pre
></blockquote
></p
>
447 <p
>Thanks to the cache, working on files that fit in the cache is very
448 quick, about the same speed as local file access. Uploading large
449 amount of data is to me limited by the bandwidth out of and into my
450 house. Uploading
685 MiB with a
100 MiB cache gave me
305 kiB/s,
451 which is very close to my upload speed, and downloading the same
452 Debian installation ISO gave me
610 kiB/s, close to my download speed.
453 Both were measured using
<tt
>dd
</tt
>. So for me, the bottleneck is my
454 network, not the file system code. I do not know what a good cache
455 size would be, but suspect that the cache should e larger than your
456 working set.
</p
>
458 <p
>I mentioned that only one machine can mount the file system at the
459 time. If another machine try, it is told that the file system is
462 <p
><blockquote
><pre
>
463 # mount.s3ql --cachedir /var/lib/s3ql-cache --authfile /root/.s3ql/authinfo2 \
464 --ssl --allow-root s3c://s.greenqloud.com:
443/bucket-name /s3ql
465 Using
8 upload threads.
466 Backend reports that fs is still mounted elsewhere, aborting.
468 </pre
></blockquote
></p
>
470 <p
>The file content is uploaded when the cache is full, while the
471 metadata is uploaded once every
24 hour by default. To ensure the
472 file system content is flushed to the cloud, one can either umount the
473 file system, or ask S3QL to flush the cache and metadata using
476 <p
><blockquote
><pre
>
477 # s3qlctrl upload-meta /s3ql
478 # s3qlctrl flushcache /s3ql
480 </pre
></blockquote
></p
>
482 <p
>If you are curious about how much space your data uses in the
483 cloud, and how much compression and deduplication cut down on the
484 storage usage, you can use s3qlstat on the mounted file system to get
487 <p
><blockquote
><pre
>
489 Directory entries:
9141
492 Total data size:
22049.38 MB
493 After de-duplication:
21955.46 MB (
99.57% of total)
494 After compression:
21877.28 MB (
99.22% of total,
99.64% of de-duplicated)
495 Database size:
2.39 MB (uncompressed)
496 (some values do not take into account not-yet-uploaded dirty blocks in cache)
498 </pre
></blockquote
></p
>
500 <p
>I mentioned earlier that there are several possible suppliers of
501 storage. I did not try to locate them all, but am aware of at least
502 <a href=
"https://www.greenqloud.com/
">Greenqloud
</a
>,
503 <a href=
"http://drive.google.com/
">Google Drive
</a
>,
504 <a href=
"http://aws.amazon.com/s3/
">Amazon S3 web serivces
</a
>,
505 <a href=
"http://www.rackspace.com/
">Rackspace
</a
> and
506 <a href=
"http://crowncloud.net/
">Crowncloud
</A
>. The latter even
507 accept payment in Bitcoin. Pick one that suit your need. Some of
508 them provide several GiB of free storage, but the prize models are
509 quite different and you will have to figure out what suits you
512 <p
>While researching this blog post, I had a look at research papers
513 and posters discussing the S3QL file system. There are several, which
514 told me that the file system is getting a critical check by the
515 science community and increased my confidence in using it. One nice
517 "<a href=
"http://www.lanl.gov/orgs/adtsc/publications/science_highlights_2013/docs/pg68_69.pdf
">An
518 Innovative Parallel Cloud Storage System using OpenStack’s SwiftObject
519 Store and Transformative Parallel I/O Approach
</a
>" by Hsing-Bung
520 Chen, Benjamin McClelland, David Sherrill, Alfred Torrez, Parks Fields
521 and Pamela Smith. Please have a look.
</p
>
523 <p
>Given my problems with different file systems earlier, I decided to
524 check out the mounted S3QL file system to see if it would be usable as
525 a home directory (in other word, that it provided POSIX semantics when
526 it come to locking and umask handling etc). Running
527 <a href=
"http://people.skolelinux.org/pere/blog/Testing_if_a_file_system_can_be_used_for_home_directories___.html
">my
528 test code to check file system semantics
</a
>, I was happy to discover that
529 no error was found. So the file system can be used for home
530 directories, if one chooses to do so.
</p
>
532 <p
>If you do not want a locally file system, and want something that
533 work without the Linux fuse file system, I would like to mention the
534 <a href=
"http://www.tarsnap.com/
">Tarsnap service
</a
>, which also
535 provide locally encrypted backup using a command line client. It have
536 a nicer access control system, where one can split out read and write
537 access, allowing some systems to write to the backup and others to
538 only read from it.
</p
>
540 <p
>As usual, if you use Bitcoin and want to show your support of my
541 activities, please send Bitcoin donations to my address
542 <b
><a href=
"bitcoin:
15oWEoG9dUPovwmUL9KWAnYRtNJEkP1u1b
&label=PetterReinholdtsenBlog
">15oWEoG9dUPovwmUL9KWAnYRtNJEkP1u1b
</a
></b
>.
</p
>
547 <title>EU-domstolen bekreftet i dag at datalagringsdirektivet er ulovlig
</title>
548 <link>http://people.skolelinux.org/pere/blog/EU_domstolen_bekreftet_i_dag_at_datalagringsdirektivet_er_ulovlig.html
</link>
549 <guid isPermaLink=
"true">http://people.skolelinux.org/pere/blog/EU_domstolen_bekreftet_i_dag_at_datalagringsdirektivet_er_ulovlig.html
</guid>
550 <pubDate>Tue,
8 Apr
2014 11:
30:
00 +
0200</pubDate>
551 <description><p
>I dag kom endelig avgjørelsen fra EU-domstolen om
552 datalagringsdirektivet, som ikke overraskende ble dømt ulovlig og i
553 strid med borgernes grunnleggende rettigheter. Hvis du lurer på hva
554 datalagringsdirektivet er for noe, så er det
555 <a href=
"http://tv.nrk.no/program/koid75005313/tema-dine-digitale-spor-datalagringsdirektivet
">en
556 flott dokumentar tilgjengelig hos NRK
</a
> som jeg tidligere
557 <a href=
"http://people.skolelinux.org/pere/blog/Dokumentaren_om_Datalagringsdirektivet_sendes_endelig_p__NRK.html
">har
558 anbefalt
</a
> alle å se.
</p
>
560 <p
>Her er et liten knippe nyhetsoppslag om saken, og jeg regner med at
561 det kommer flere ut over dagen. Flere kan finnes
562 <a href=
"http://www.mylder.no/?drill=datalagringsdirektivet
&intern=
1">via
563 mylder
</a
>.
</p
>
567 <li
><a href=
"http://e24.no/digital/eu-domstolen-datalagringsdirektivet-er-ugyldig/
22879592">EU-domstolen:
568 Datalagringsdirektivet er ugyldig
</a
> - e24.no
2014-
04-
08
570 <li
><a href=
"http://www.aftenposten.no/nyheter/iriks/EU-domstolen-Datalagringsdirektivet-er-ulovlig-
7529032.html
">EU-domstolen:
571 Datalagringsdirektivet er ulovlig
</a
> - aftenposten.no
2014-
04-
08
573 <li
><a href=
"http://www.aftenposten.no/nyheter/iriks/politikk/Krever-DLD-stopp-i-Norge-
7530086.html
">Krever
574 DLD-stopp i Norge
</a
> - aftenposten.no
2014-
04-
08
576 <li
><a href=
"http://www.p4.no/story.aspx?id=
566431">Apenes: - En
577 gledens dag
</a
> - p4.no
2014-
04-
08
579 <li
><a href=
"http://www.nrk.no/norge/_-datalagringsdirektivet-er-ugyldig-
1.11655929">EU-domstolen:
580 – Datalagringsdirektivet er ugyldig
</a
> - nrk.no
2014-
04-
08</li
>
582 <li
><a href=
"http://www.vg.no/nyheter/utenriks/data-og-nett/eu-domstolen-datalagringsdirektivet-er-ugyldig/a/
10130280/
">EU-domstolen:
583 Datalagringsdirektivet er ugyldig
</a
> - vg.no
2014-
04-
08</li
>
585 <li
><a href=
"http://www.dagbladet.no/
2014/
04/
08/nyheter/innenriks/datalagringsdirektivet/personvern/
32711646/
">-
586 Vi bør skrote hele datalagringsdirektivet
</a
> - dagbladet.no
587 2014-
04-
08</li
>
589 <li
><a href=
"http://www.digi.no/
928137/eu-domstolen-dld-er-ugyldig
">EU-domstolen:
590 DLD er ugyldig
</a
> - digi.no
2014-
04-
08</li
>
592 <li
><a href=
"http://www.irishtimes.com/business/sectors/technology/european-court-declares-data-retention-directive-invalid-
1.1754150">European
593 court declares data retention directive invalid
</a
> - irishtimes.com
594 2014-
04-
08</li
>
596 <li
><a href=
"http://www.reuters.com/article/
2014/
04/
08/us-eu-data-ruling-idUSBREA370F020140408?feedType=RSS
">EU
597 court rules against requirement to keep data of telecom users
</a
> -
598 reuters.com
2014-
04-
08</li
>
603 <p
>Jeg synes det er veldig fint at nok en stemme slår fast at
604 totalitær overvåkning av befolkningen er uakseptabelt, men det er
605 fortsatt like viktig å beskytte privatsfæren som før, da de
606 teknologiske mulighetene fortsatt finnes og utnyttes, og jeg tror
607 innsats i prosjekter som
608 <a href=
"https://wiki.debian.org/FreedomBox
">Freedombox
</a
> og
609 <a href=
"http://www.dugnadsnett.no/
">Dugnadsnett
</a
> er viktigere enn
612 <p
><strong
>Update
2014-
04-
08 12:
10</strong
>: Kronerullingen for å
613 stoppe datalagringsdirektivet i Norge gjøres hos foreningen
614 <a href=
"http://www.digitaltpersonvern.no/
">Digitalt Personvern
</a
>,
615 som har samlet inn
843 215,- så langt men trenger nok mye mer hvis
617 ikke Høyre og Arbeiderpartiet bytter mening i saken. Det var
618 <a href=
"http://www.holderdeord.no/parliament-issues/
48650">kun
619 partinene Høyre og Arbeiderpartiet
</a
> som stemte for
620 Datalagringsdirektivet, og en av dem må bytte mening for at det skal
621 bli flertall mot i Stortinget. Se mer om saken
622 <a href=
"http://www.holderdeord.no/issues/
69-innfore-datalagringsdirektivet
">Holder
623 de ord
</a
>.
</p
>
628 <title>ReactOS Windows clone - nice free software
</title>
629 <link>http://people.skolelinux.org/pere/blog/ReactOS_Windows_clone___nice_free_software.html
</link>
630 <guid isPermaLink=
"true">http://people.skolelinux.org/pere/blog/ReactOS_Windows_clone___nice_free_software.html
</guid>
631 <pubDate>Tue,
1 Apr
2014 12:
10:
00 +
0200</pubDate>
632 <description><p
>Microsoft have announced that Windows XP reaches its end of life
633 2014-
04-
08, in
7 days. But there are heaps of machines still running
634 Windows XP, and depending on Windows XP to run their applications, and
635 upgrading will be expensive, both when it comes to money and when it
636 comes to the amount of effort needed to migrate from Windows XP to a
637 new operating system. Some obvious options (buy new a Windows
638 machine, buy a MacOSX machine, install Linux on the existing machine)
639 are already well known and covered elsewhere. Most of them involve
640 leaving the user applications installed on Windows XP behind and
641 trying out replacements or updated versions. In this blog post I want
642 to mention one strange bird that allow people to keep the hardware and
643 the existing Windows XP applications and run them on a free software
644 operating system that is Windows XP compatible.
</p
>
646 <p
><a href=
"http://www.reactos.org/
">ReactOS
</a
> is a free software
647 operating system (GNU GPL licensed) working on providing a operating
648 system that is binary compatible with Windows, able to run windows
649 programs directly and to use Windows drivers for hardware directly.
650 The project goal is for Windows user to keep their existing machines,
651 drivers and software, and gain the advantages from user a operating
652 system without usage limitations caused by non-free licensing. It is
653 a Windows clone running directly on the hardware, so quite different
654 from the approach taken by
<a href=
"http://www.winehq.org/
">the Wine
655 project
</a
>, which make it possible to run Windows binaries on
658 <p
>The ReactOS project share code with the Wine project, so most
659 shared libraries available on Windows are already implemented already.
660 There is also a software manager like the one we are used to on Linux,
661 allowing the user to install free software applications with a simple
662 click directly from the Internet. Check out the
663 <a href=
"http://www.reactos.org/screenshots
">screen shots on the
664 project web site
</a
> for an idea what it look like (it looks just like
665 Windows before metro).
</p
>
667 <p
>I do not use ReactOS myself, preferring Linux and Unix like
668 operating systems. I
've tested it, and it work fine in a virt-manager
669 virtual machine. The browser, minesweeper, notepad etc is working
670 fine as far as I can tell. Unfortunately, my main test application
671 is the software included on a CD with the Lego Mindstorms NXT, which
672 seem to install just fine from CD but fail to leave any binaries on
673 the disk after the installation. So no luck with that test software.
674 No idea why, but hope someone else figure out and fix the problem.
675 I
've tried the ReactOS Live ISO on a physical machine, and it seemed
676 to work just fine. If you like Windows and want to keep running your
677 old Windows binaries, check it out by
678 <a href=
"http://www.reactos.org/download
">downloading
</a
> the
679 installation CD, the live CD or the preinstalled virtual machine
685 <title>Debian Edu interview: Roger Marsal
</title>
686 <link>http://people.skolelinux.org/pere/blog/Debian_Edu_interview__Roger_Marsal.html
</link>
687 <guid isPermaLink=
"true">http://people.skolelinux.org/pere/blog/Debian_Edu_interview__Roger_Marsal.html
</guid>
688 <pubDate>Sun,
30 Mar
2014 11:
40:
00 +
0200</pubDate>
689 <description><p
><a href=
"http://www.skolelinux.org/
">Debian Edu / Skolelinux
</a
>
690 keep gaining new users. Some weeks ago, a person showed up on IRC,
691 <a href=
"irc://irc.debian.org/#debian-edu
">#debian-edu
</a
>, with a
692 wish to contribute, and I managed to get a interview with this great
693 contributor Roger Marsal to learn more about his background.
</p
>
695 <p
><strong
>Who are you, and how do you spend your days?
</strong
></p
>
697 <p
>My name is Roger Marsal, I
'm
27 years old (
1986 generation) and I
698 live in Barcelona, Spain. I
've got a strong business background and I
699 work as a patrimony manager and as a real estate agent. Additionally,
700 I
've co-founded a British based tech company that is nowadays on the
701 last development phase of a new social networking concept.
</p
>
703 <p
>I
'm a Linux enthusiast that started its journey with Ubuntu four years
704 ago and have recently switched to Debian seeking rock solid stability
705 and as a necessary step to gain expertise.
</p
>
707 <p
>In a nutshell, I spend my days working and learning as much as I
708 can to face both my job, entrepreneur project and feed my Linux
711 <p
><strong
>How did you get in contact with the Skolelinux / Debian Edu
712 project?
</strong
></p
>
714 <p
>I discovered the
<a href=
"http://www.ltsp.org/
">LTSP
</a
> advantages
715 with
"Ubuntu
12.04 alternate install
" and after a year of use I
716 started looking for an alternative. Even though I highly value and
717 respect the Ubuntu project, I thought it was necessary for me to
718 change to a more robust and stable alternative. As far as I was using
719 Debian on my personal laptop I thought it would be fine to install
720 Debian and configure an LTSP server myself. Surprised, I discovered
721 that the Debian project also supported a kind of Edubuntu equivalent,
722 and after having some pain I obtained a Debian Edu network up and
723 running. I just loved it.
</p
>
725 <p
><strong
>What do you see as the advantages of Skolelinux / Debian
726 Edu?
</strong
></p
>
728 <p
>I found a main advantage in that, once you know
"the tips and
729 tricks
", a new installation just works out of the box. It
's the most
730 complete alternative I
've found to create an LTSP network. All the
731 other distributions seems to be made of plastic, Debian Edu seems to
732 be made of steel.
</p
>
734 <p
><strong
>What do you see as the disadvantages of Skolelinux / Debian
735 Edu?
</strong
></p
>
737 <p
>I found two main disadvantages.
</p
>
739 <p
>I
'm not an expert but I
've got notions and I had to spent a considerable
740 amount of time trying to bring up a standard network topology. I
'm quite
741 stubborn and I just worked until I did but I
'm sure many people with few
742 resources (not big schools, but academies for example) would have switched
743 or dropped.
</p
>
745 <p
>It
's amazing how such a complex system like Debian Edu has achieved
746 this out-of-the-box state. Even though tweaking without breaking gets
747 more difficult, as more factors have to be considered. This can
748 discourage many people too.
</p
>
750 <p
><strong
>Which free software do you use daily?
</strong
></p
>
752 <p
>I use Debian, Firefox, Okular, Inkscape, LibreOffice and
753 Virtualbox.
</p
>
756 <p
><strong
>Which strategy do you believe is the right one to use to
757 get schools to use free software?
</strong
></p
>
759 <p
>I don
't think there is a need for a particular strategy. The free
760 attribute in both
"freedom
" and
"no price
" meanings is what will
761 really bring free software to schools. In my experience I can think of
762 the
<a href=
"http://www.r-project.org/
">"R
" statistical language
</a
>; a
763 few years a ago was an extremely nerd tool for university people.
764 Today it
's being increasingly used to teach statistics at many
765 different level of studies. I believe free and open software will
766 increasingly gain popularity, but I
'm sure schools will be one of the
767 first scenarios where this will happen.
</p
>
772 <title>Dokumentaren om Datalagringsdirektivet sendes endelig på NRK
</title>
773 <link>http://people.skolelinux.org/pere/blog/Dokumentaren_om_Datalagringsdirektivet_sendes_endelig_p__NRK.html
</link>
774 <guid isPermaLink=
"true">http://people.skolelinux.org/pere/blog/Dokumentaren_om_Datalagringsdirektivet_sendes_endelig_p__NRK.html
</guid>
775 <pubDate>Wed,
26 Mar
2014 09:
50:
00 +
0100</pubDate>
776 <description><p
><a href=
"http://www.nuug.no/
">Foreningen NUUG
</a
> melder i natt at
777 NRK nå har bestemt seg for
778 <a href=
"http://www.nuug.no/news/NRK_viser_filmen_om_Datalagringsdirektivet_f_rste_gang_2014_03_31.shtml
">når
779 den norske dokumentarfilmen om datalagringsdirektivet skal
780 sendes
</a
> (se
<a href=
"http://www.imdb.com/title/tt2832844/
">IMDB
</a
>
781 for detaljer om filmen) . Første visning blir på NRK2 mandag
782 2014-
03-
31 kl.
19:
50, og deretter visninger onsdag
2014-
04-
02
783 kl.
12:
30, fredag
2014-
04-
04 kl.
19:
40 og søndag
2014-
04-
06 kl.
15:
10.
784 Jeg har sett dokumentaren, og jeg anbefaler enhver å se den selv. Som
785 oppvarming mens vi venter anbefaler jeg Bjørn Stærks kronikk i
786 Aftenposten fra i går,
787 <a href=
"http://www.aftenposten.no/meninger/kronikker/Autoritar-gjokunge-
7514915.html
">Autoritær
788 gjøkunge
</a
>, der han gir en grei skisse av hvor ille det står til med
789 retten til privatliv og beskyttelsen av demokrati i Norge og resten
790 verden, og helt riktig slår fast at det er vi i databransjen som
791 sitter med nøkkelen til å gjøre noe med dette. Jeg har involvert meg
792 i prosjektene
<a href=
"http://www.dugnadsnett.no/
">dugnadsnett.no
</a
>
793 og
<a href=
"https://wiki.debian.org/FreedomBox
">FreedomBox
</a
> for å
794 forsøke å gjøre litt selv for å bedre situasjonen, men det er mye
795 hardt arbeid fra mange flere enn meg som gjenstår før vi kan sies å ha
796 gjenopprettet balansen.
</p
>
798 <p
>Jeg regner med at nettutgaven dukker opp på
799 <a href=
"http://tv.nrk.no/program/koid75005313/tema-dine-digitale-spor-datalagringsdirektivet
">NRKs
800 side om filmen om datalagringsdirektivet
</a
> om fem dager. Hold et
801 øye med siden, og tips venner og slekt om at de også bør se den.
</p
>
806 <title>Public Trusted Timestamping services for everyone
</title>
807 <link>http://people.skolelinux.org/pere/blog/Public_Trusted_Timestamping_services_for_everyone.html
</link>
808 <guid isPermaLink=
"true">http://people.skolelinux.org/pere/blog/Public_Trusted_Timestamping_services_for_everyone.html
</guid>
809 <pubDate>Tue,
25 Mar
2014 12:
50:
00 +
0100</pubDate>
810 <description><p
>Did you ever need to store logs or other files in a way that would
811 allow it to be used as evidence in court, and needed a way to
812 demonstrate without reasonable doubt that the file had not been
813 changed since it was created? Or, did you ever need to document that
814 a given document was received at some point in time, like some
815 archived document or the answer to an exam, and not changed after it
816 was received? The problem in these settings is to remove the need to
817 trust yourself and your computers, while still being able to prove
818 that a file is the same as it was at some given time in the past.
</p
>
820 <p
>A solution to these problems is to have a trusted third party
821 "stamp
" the document and verify that at some given time the document
822 looked a given way. Such
823 <a href=
"https://en.wikipedia.org/wiki/Notarius
">notarius
</a
> service
824 have been around for thousands of years, and its digital equivalent is
826 <a href=
"http://en.wikipedia.org/wiki/Trusted_timestamping
">trusted
827 timestamping service
</a
>.
<a href=
"http://www.ietf.org/
">The Internet
828 Engineering Task Force
</a
> standardised how such service could work a
829 few years ago as
<a href=
"http://tools.ietf.org/html/rfc3161
">RFC
830 3161</a
>. The mechanism is simple. Create a hash of the file in
831 question, send it to a trusted third party which add a time stamp to
832 the hash and sign the result with its private key, and send back the
833 signed hash + timestamp. Both email, FTP and HTTP can be used to
834 request such signature, depending on what is provided by the service
835 used. Anyone with the document and the signature can then verify that
836 the document matches the signature by creating their own hash and
837 checking the signature using the trusted third party public key.
838 There are several commercial services around providing such
839 timestamping. A quick search for
840 "<a href=
"https://duckduckgo.com/?q=rfc+
3161+service
">rfc
3161
841 service
</a
>" pointed me to at least
842 <a href=
"https://www.digistamp.com/technical/how-a-digital-time-stamp-works/
">DigiStamp
</a
>,
843 <a href=
"http://www.quovadisglobal.co.uk/CertificateServices/SigningServices/TimeStamp.aspx
">Quo
845 <a href=
"https://www.globalsign.com/timestamp-service/
">Global Sign
</a
>
846 and
<a href=
"http://www.globaltrustfinder.com/TSADefault.aspx
">Global
847 Trust Finder
</a
>. The system work as long as the private key of the
848 trusted third party is not compromised.
</p
>
850 <p
>But as far as I can tell, there are very few public trusted
851 timestamp services available for everyone. I
've been looking for one
852 for a while now. But yesterday I found one over at
853 <a href=
"https://www.pki.dfn.de/zeitstempeldienst/
">Deutches
854 Forschungsnetz
</a
> mentioned in
855 <a href=
"http://www.d-mueller.de/blog/dealing-with-trusted-timestamps-in-php-rfc-
3161/
">a
856 blog by David Müller
</a
>. I then found
857 <a href=
"http://www.rz.uni-greifswald.de/support/dfn-pki-zertifikate/zeitstempeldienst.html
">a
858 good recipe on how to use the service
</a
> over at the University of
859 Greifswald.
</p
>
861 <p
><a href=
"http://www.openssl.org/
">The OpenSSL library
</a
> contain
862 both server and tools to use and set up your own signing service. See
863 the ts(
1SSL), tsget(
1SSL) manual pages for more details. The
864 following shell script demonstrate how to extract a signed timestamp
865 for any file on the disk in a Debian environment:
</p
>
867 <p
><blockquote
><pre
>
870 url=
"http://zeitstempel.dfn.de
"
871 caurl=
"https://pki.pca.dfn.de/global-services-ca/pub/cacert/chain.txt
"
872 reqfile=$(mktemp -t tmp.XXXXXXXXXX.tsq)
873 resfile=$(mktemp -t tmp.XXXXXXXXXX.tsr)
875 if [ ! -f $cafile ] ; then
876 wget -O $cafile
"$caurl
"
878 openssl ts -query -data
"$
1" -cert | tee
"$reqfile
" \
879 | /usr/lib/ssl/misc/tsget -h
"$url
" -o
"$resfile
"
880 openssl ts -reply -in
"$resfile
" -text
1>&2
881 openssl ts -verify -data
"$
1" -in
"$resfile
" -CAfile
"$cafile
" 1>&2
882 base64
< "$resfile
"
883 rm
"$reqfile
" "$resfile
"
884 </pre
></blockquote
></p
>
886 <p
>The argument to the script is the file to timestamp, and the output
887 is a base64 encoded version of the signature to STDOUT and details
888 about the signature to STDERR. Note that due to
889 <a href=
"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=
742553">a bug
890 in the tsget script
</a
>, you might need to modify the included script
891 and remove the last line. Or just write your own HTTP uploader using
892 curl. :) Now you too can prove and verify that files have not been
895 <p
>But the Internet need more public trusted timestamp services.
896 Perhaps something for
<a href=
"http://www.uninett.no/
">Uninett
</a
> or
897 my work place the
<a href=
"http://www.uio.no/
">University of Oslo
</a
>
903 <title>Video DVD reader library / python-dvdvideo - nice free software
</title>
904 <link>http://people.skolelinux.org/pere/blog/Video_DVD_reader_library___python_dvdvideo___nice_free_software.html
</link>
905 <guid isPermaLink=
"true">http://people.skolelinux.org/pere/blog/Video_DVD_reader_library___python_dvdvideo___nice_free_software.html
</guid>
906 <pubDate>Fri,
21 Mar
2014 15:
25:
00 +
0100</pubDate>
907 <description><p
>Keeping your DVD collection safe from scratches and curious
908 children fingers while still having it available when you want to see a
909 movie is not straight forward. My preferred method at the moment is
910 to store a full copy of the ISO on a hard drive, and use VLC, Popcorn
911 Hour or other useful players to view the resulting file. This way the
912 subtitles and bonus material are still available and using the ISO is
913 just like inserting the original DVD record in the DVD player.
</p
>
915 <p
>Earlier I used dd for taking security copies, but it do not handle
916 DVDs giving read errors (which are quite a few of them). I
've also
918 <a href=
"http://people.skolelinux.org/pere/blog/Ripping_problematic_DVDs_using_dvdbackup_and_genisoimage.html
">dvdbackup
919 and genisoimage
</a
>, but these days I use the marvellous python library
921 <a href=
"http://bblank.thinkmo.de/blog/new-software-python-dvdvideo
">python-dvdvideo
</a
>
922 written by Bastian Blank. It is
923 <a href=
"http://packages.qa.debian.org/p/python-dvdvideo.html
">in Debian
924 already
</a
> and the binary package name is python3-dvdvideo. Instead
925 of trying to read every block from the DVD, it parses the file
926 structure and figure out which block on the DVD is actually in used,
927 and only read those blocks from the DVD. This work surprisingly well,
928 and I have been able to almost backup my entire DVD collection using
929 this method.
</p
>
931 <p
>So far, python-dvdvideo have failed on between
10 and
932 20 DVDs, which is a small fraction of my collection. The most common
934 <a href=
"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=
720831">DVDs
935 using UTF-
16 instead of UTF-
8 characters
</a
>, which according to
936 Bastian is against the DVD specification (and seem to cause some
937 players to fail too). A rarer problem is what seem to be inconsistent
938 DVD structures, as the python library
939 <a href=
"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=
723079">claim
940 there is a overlap between objects
</a
>. An equally rare problem claim
941 <a href=
"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=
741878">some
942 value is out of range
</a
>. No idea what is going on there. I wish I
943 knew enough about the DVD format to fix these, to ensure my movie
944 collection will stay with me in the future.
</p
>
946 <p
>So, if you need to keep your DVDs safe, back them up using
947 python-dvdvideo. :)
</p
>