Showing posts with label Debian. Show all posts
Showing posts with label Debian. Show all posts

Sunday, May 24, 2009

Five Game-Changing Features in Firefox 3.5


The latest Firefox may still be in beta but it boasts a number of behind-the-scenes features that will make developing for the web easier as well as end-user changes that add new functionality, like private browsing and support for drag and drop.




Firefox 3.5 is coming very soon, and this release includes a number of features that up the ante for Web browsers and the Web as an application platform. Some of the game-changing features in Firefox 3.5 won’t be immediately visible to end-users, but they’ll allow Web developers to build Web applications that make the Web even more fun and useful than it already is. Let’s take a look at five of the prominent features you can test drive today in Firefox 3.5.


You can grab tarballs from Mozilla the Mozilla beta announcement page, though many Linux distros also have testing packages available as add-on repositories. For instance, openSUSE users can add the mozilla:beta repository to track the latest Firefox development packages. This gives the added advantage of allowing you to track updates via your distro’s update process, but does mean that updates will usually lag a few days behind the official Moz builds.

Because it’s beta software, the standard disclaimers apply: While Firefox betas are pretty stable, you can expect that it will have some bugs and might even do unexpected things like eating your data. I’ve never had this happen, but take reasonable precautions before running the beta — like backing up your profile directory.

Audio and Video Support in Firefox

Ever get sick of worrying about plugins and helper applications to enjoy multimedia content online? Firefox 3.5 may be the beginning of the end for that particular hassle with support for HTML 5 audio and video elements, and support for the Ogg and WAV formats in the browser itself.

The audio and video elements make it easier to add video and audio to Web pages, with a few lines of HTML Take this example from the Firefox developer site:

If you’re using a supported browser like Firefox 3.5, you’ll see test bars just like we used to enjoy at the end of the broadcast day on television. (Remember when the broadcast day actually ended?) If not, you should just see: “Your browser does not support the video element.”

As a side note, Firefox’s inclusion of Ogg might just help make the free but not yet mainstream format break through. This would be a big win for Linux users who have excellent tools for encoding and decoding Ogg but not a lot of mainstream content in Ogg to view or listen to. Labels like Magnatune that support Ogg out of the box are few and far between.

If you’re running Firefox 3.5, you can catch a number of sample videos on TinyVid.

Private Browsing

Over the years, Firefox has added a number of features that make it easier to erase your browsing tracks — so if you’re sharing a computer with others, you can erase history, cookies, cache and other bits that would let snoopers see how you spend your browsing time. Unfortunately, it’s a bit of a shotgun approach — meaning you lose history and so forth from all the sites you visit, and not just the ones you want to keep private.

The 3.5 release will take care of this problem by introducing Private Browsing, or what’s more often referred to as “Porn Mode” for Mozilla. Of course, it has much more work safe applications as well. If you’re doing gift shopping, for example, it’s sort of a dead giveaway if your significant other stumbles on your shopping history. For the paranoid security conscious, it’s also a good feature for logging into banking sites or any other type of Web site that displays a lot of private data. Whatever the reason, Firefox’s Private Browsing mode is much more convenient for users than just deleting history at random intervals.

Using Private Browsing, you can start up a Firefox session that doesn’t record cookies, history, etc., so that there’s no trace of your session. When you finish, all of your previous settings and history are untouched, so you lose nothing — unlike the “Clear History” tool in older versions, which clobbers all cookies, etc.

Firefox 3.5 also has added more finely grained options to the Clear History tool. Instead of an “all or nothing” approach, you can get rid of the last hour, two hours, four hours, day, or entire history.

Offline Application Support

Being dependent on a Web application is a bit of a problem when you’re offline. Firefox 3.5 tries to remedy this a bit by adding support for the HTML 5 specs for caching resources for Web apps.

Offline application support isn’t entirely new, Firefox shipped bits of this with Firefox 3.0 and add-ons like Google Gears have provided offline support for Gears-enabled Web apps. However, Firefox 3.5 fully supports the HTML 5 specification for offline application support — which ought to give a boost to offline Web apps, beyond Google Gears.

Drag and Drop

Typically, Web applications lack the same feature functionality that desktop applications do. Case in point: Drag and drop between applications. Sure, you can copy and paste some things between browser windows and different Web sites, but drag and drop capabilities are seriously limited compared to desktop applications.

Firefox 3.5 beefs up the abilities to drag and drop data types between applications and even multiple items. It may seem like a minor feature, but it gives Web apps the ability to work more like desktop applications, which is another hurdle for those who’d like to see Web applications replace fat apps.

Geolocation

Geolocation seems to be all the rage these days — services like Google Latitude allow users to report their location via the computer or mobile phone so your friends and stalkers can track your location more conveniently. Ecommerce sites can pick up your location to suggest nearby stores, and so forth.

I’m not entirely sure this is a desirable feature, but a lot of users seem to want it — and Firefox 3.5 gives developers and users the tools to make it possible beyond services like Latitude. If you’re totally freaked out by the prospect of Web sites knowing your location, it can be turned off.

Basically, service providers can report your location based on wireless access points and IP address. Depending where you are in the world, this can be very accurate (within a few meters, which is pretty darn specific) or wildly inaccurate. With your permission, Firefox can then report the location to Web sites that request it.

My experience with the technology so far is that it’s good at getting within the general city/county, but beyond that not so much. But the technology is only going to get better (especially with mobile devices that have GPS) and more widely used.

All in all, Firefox 3.5 has a lot of new functionality that’s going to be really useful regardless whether you’re a Web developer or an end-users.

Wednesday, May 13, 2009

Free Linux Ebooks Collection For Newbie

I'm listing here a free book collection and sure it will very useful among Linux users and rightfully so, who doesn’t like free books? No matter how experienced you are with Linux systems, there is always something new you can learn from a good book that focuses on specific aspects of a Linux system. I tried to make a list of free books by categories. “Beginners”, “Advanced” and “Administrators”.

Here I have listed e-Books for "Linux Ebooks For Newbie", "Intermediate and Advanced Linux Users" and "Linux System Administrators".

Here's listed a comprehensive list of Free Linux related e-books. I didn't arrange the ebooks in proper categories.

E-books:

  1. Linux Client Migration Cookbook, Version 2: A Practical Planning and Implementation Guide for Migrating to Desktop Linux by Chris Almond
  2. Linux Compute Clusters by Chander Kant
  3. Linux Device Drivers by Alessandro Rubini and Jonathan Corbet
  4. Linux Installation and Getting Started by Matt Welsh
  5. Linux Kernel Module Programming Guide by Ori Pomerantz
  6. Linux Network Administrator’s Guide by Olaf Kirch and Terry Dawson
  7. Securing and Optimizing Linux by Gerhard Mourani
  8. Self-Service Linux: Mastering the Art of Problem Determination by Dan Behman and Mark Wilding
  9. Slackware Linux Essentials by Alan Hicks, Chris Lumens, David Cantrell, and Logan Johnson
  10. The Linux Cookbook: Tips and Techniques for Everyday Use by Michael Stutz
  11. Advanced Linux Programming by CodeSourcery LLC
  12. Comprehensive Linux Textbook by Muayyad Saleh Al-Sadi
  13. Java Application Development on Linux by Carl Albing and Michael Schwarz (PDF)
  14. Linux Admins Security Guide
  15. Linux Security Howto
  16. Linux Firewall Configuration, Packet Filtering & netfilter/iptables
  17. Linux Device Drivers, Third Edition
  18. GNU Bash Reference Manual
  19. Knowing Knoppix
  20. Linux Client Migration Cookbook
  21. Vi iMproved (VIM)
  22. Linux: Rute User’s Tutorial and Exposition
  23. The Book of Webmin
  24. Linux From Scratch
  25. GNU Emacs manual
  26. Writing GNOME Applications
  27. KDE 2.0 Development
  28. GTK+/Gnome Application Development
  29. GNU Autoconf, Automake and Libtool
  30. Advanced Linux Programming
  31. Secure Programming for Linux and Unix
  32. The Art of Unix Programming
  33. The Linux Development Platform
  34. C++ GUI Programming With Qt 3
  35. Unofficial Ubuntu Guide
  36. The Easiest Linux Guide You’ll Ever Read - An Introduction to Linux for Windows users
  37. SUSE Linux Administration Guide
  38. Red Hat Enterprise Linux Installation Guide
  39. Red Hat Enterprise Linux Reference Guide
  40. Red Hat Enterprise Linux Step By Step Guide
  41. Fedora Linux EssentialsVisual Basic Essentials
  42. Fedora Core 7 Desktop Guide
  43. LDAP Operations HOWTOLearning Debian GNU/Linux
  44. Learning the Unix Operating System
  45. Linux Administration Made Easy
  46. Linux Dictionary
  47. The Linux kernel
  48. Linux Kernel 2.4 Internals
  49. The Linux Kernel Module Programming Guide
  50. LINUX: Rute User’s Tutorial and Exposition
  51. Maximum RPM, Taking the Red Hat Package Manager to the Limit
  52. Pocket Linux Guide
  53. Secure Programming for Linux and Unix HOWTO
  54. Linux+ Study Guide
  55. Ubuntu Linux Essentials
  56. PHP Essentials
  57. Javascript Essentials
  58. Red Hat Fedora Core 7 Installation Guide
  59. The Art of Unix Programming
  60. Bash Guide for Beginners
  61. Beyond Linux from Scratch
  62. The Book of Webmin Or: How I Learned to Stop Worrying and Love UNIX
  63. Brian and Tom’s Linux Book
  64. Debian GNU/Linux Desktop Survival Guide
  65. Debian GNU/Linux System Administrator’s Manual
  66. Everyday Linux
  67. FreeBSD HandbookGNU Manuals OnlineIn The Beginning Was The Command Line
  68. Introduction to Linux - A Hands on Guide

Free Linux Ebooks For Newbie:


1. Ubuntu Pocket Guide and Reference

Author: Keir Thomas
Format: PDF




2. Linux Newbie Administrator Guide

Author: Peter and Stan Klimas
Format: HTML


3. Introduction to Linux - A Hands on Guide

Author: Machtelt Garrels
Format: HTML



4. Bash Guide for Beginners

Author: Machtelt Garrels
Format: HTML



5. Rute User’s Tutorial and Exposition

Author: Paul Sheer
Format: HTML



6. The Linux Starter Pack

Author: Paul Hudson
Format: PDF



7. FLOSS Manuals

Author: FSF
Format: HTML & PDF



8. The Easiest Linux Guide You’ll Ever Read

Author: Scott Morris
Format: PDF



9. Linux Knowledge Base and Tutorial

Author: James Mohr
Format: PDF



10. Slackware Linux Basics

Author: Daniƫl de Kok
Format: HTML


Saturday, May 9, 2009

Speed up your system by avoiding the swap file

Most modern operating systems are capable of using a file or partition known as a swap or paging file. Most Linux distributions will also install one for you by default. This file is used to extend the amount of available RAM by writing some of it to your hard drive.

There's just one problem: hard drives are slow. We can't fix that problem yet, but we can avoid it. The Linux kernel provides a tweakable setting that controls how often the swap file is used, called swappiness. A swappiness setting of zero means that the disk will be avoided unless absolutely necessary (you run out of memory), while a swappiness setting of 100 means that programs will be swapped to disk almost instantly.

My Ubuntu system comes with a default of 60, meaning that the swap file will be used fairly often if the memory usage is around half of my RAM. You can check your own system's swappiness value by running:

cat /proc/sys/vm/swappiness

My HDD is insanely slow and I have 2 GB of RAM, so I'd like to turn that down to 10 or 15. The swap file will then only be used when my RAM usage is around 80 or 90 percent. To change the system swappiness value, open /etc/sysctl.conf as root. Then, change or add this line to the file:

vm.swappiness = 15

Reboot for the change to take effect. You can also change the value while your system is still running:

sysctl vm.swappiness=15

However, you won't get the full effect of rebooting because there is probably already memory stored in swap that won't instantly be moved out.

Update: Readers have noted that you can clear your swap by running swapoff -a and then swapon -a as root instead of rebooting to achieve the same effect.

Rescuing a Lost Root Password

Sometimes you wind up taking over a machine for which the root password has been lost. Here are a couple of solutions.

  • Reboot (hard reboot by pulling the power cable if rebooting requires the root password), and hit 'e' to edit the boot line when you get to the grub menu. Scroll down to the line that starts with kernel, then hit 'e' again to edit it, add 'single' to the end, and hit Enter to accept. Now 'b' to boot and eventually you'll be dumped into a root shell. From here type passwd to change the root password.
  • Some systems require the root password to boot into 'single' mode. In this case, try editing the grub boot line to add 'init=/bin/bash' to the end of the kernel line. This will boot you into a very basic system, using the bash shell instead of init. You may have to mount the root partition read/write:
    mount -no remount,rw /
  • Then use passwd to reset the password.

  • If grub is protected, try booting from a LiveCD or USB stick. Open a root shell, and use fdisk -l to show the available disk partitions. Mount the root partition with
    mount -o,rw /dev/hda1 /mnt
    Check it's the right directory with ls /mnt, then change into that as your root directory:
    chroot /mnt
    Now use passwd as before.
  • NOTE: It's important to bear in mind that all of these are also potential security risks if people have physical access to your machines.

    Friday, May 8, 2009

    Linux Proves - The Best Things In Life Are Free


    They say - there's no such thing as a free lunch. But, Linux and FOSS software can be used to start, run and grow your business for, you guessed it, free. February survey of IT managers by IDC indicated that hard times are accelerating the adoption of Linux. The open source operating system will emerge from the recession in a stronger data center position than before, concluded an IDC white paper. Reducing costs and stronger interoperability with Windows were listed as the two top issues in a new survey of IT managers.

    Sun Microsystems, Novell, Microsoft and many more have been down because of bad economy. But, Free software vendor such as Red Hat, IBM and others are doing fine. Here in India, many Government projects and schools found success with Linux. Also, Linux found good successes in emerging economies where Microsoft Windows doesn't already dominate end user computing. The increasing use of Linux as a pre-loaded system on mobile devices is another area where Linux use is likely to grow on.

    However, Linux may be free, but you still need to invest in the training and getting involved in the community to get support. What do you thing? Have you found success with Linux in your data center? Please add your thoughts in the comments below.

    Monday, May 4, 2009

    Set up a LAN gateway with DHCP, Dynamic DNS and iptables on Debian Etch

    Linux is a perfect platform to act as a router/gateway.

    In this tutorial, I will explain how to set up a Linux box to operate as a network router. The box will provide the following services:

    • DHCP server to provide the ip addresses to the machines in the LAN
    • DNS server to resolve domain names
    • Gateway with IP tables to give access to the Internet.
    • Firewall with IP tables.

    The resulting machine will have quite a small footprint: about 600M, and except if your network is intensively used, a low spec computer can be recycled to do the job.

    As the machine is going to operate as a router/firewall

    This tutorial is based on a Debian Etch 4.0 r3 minimal network install, i.e that during the install, at the "Software selection" step, I unselected everything.

    The box has 2 network interfaces:

    • eth0: ip 192.168.1.9 which is connected to internet (not directly though, but it is the box that is routing the traffic toward internet for this LAN)
    • eth1: ip 192.168.2.1, this is the interface connected to our LAN and that will forward the traffic to and from internet.

    Also, we are going to manage the domain name lan.debuntu.local, so each machine will be able to communicate with each others by using their hostname.

    So first let's get started with the set up of bind9

    1. DNS server

    As a DNS server we are going to use bind9, it will be configured to resolve the names of the host for our network lan.debuntu.local.

    The DNS server will also accept dynamic DNS update from the local DHCP server.

    In this tutorial, I will be using the Dynamic DNS feature of bind.

    1.1. Installing the DNS server

    Make sure you are installing bind9 as older version of bind do not not support dynamic dns updates.

    # apt-get install bind9

    1.2. Configuring the DNS server

    In order to keep the default install files clean, we are going to only edit /etc/bind/named.conf.local . In this file we are going to allow dns updates from local host using "rndc-key" (which is installed by default with bind9 package)

    We are also going to define 2 zones:

    • lan.debuntu.local : our local domain name
    • 2.168.192.in-addr.arpa : our local network ip zone, this will allow us to reverse lookup names.

    So let's go and edit /etc/bind/named.conf.local and add:

    #allow dns updates from localhost with key "rndc-key"
    include "/etc/bind/rndc.key";
    controls {
    inet 127.0.0.1 allow { localhost; } keys { "rndc-key"; };
    };

    #defines lan.debuntu.local
    zone "lan.debuntu.local" {
    type master;
    file "db.lan.debuntu.local";
    allow-update { key "rndc-key"; };
    };

    #defines our local subnet 192.168.2.0/24
    zone "2.168.192.in-addr.arpa" {
    type master;
    notify no;
    file "db.2.168.192";
    allow-update { key "rndc-key"; };
    };

    Then, we need to create those 2 files : /var/cache/bind/db.lan.debuntu.local and /var/cache/bind/db.2.168.192 .

    The first one will be used to resolve names, while the second one to reverse name lookup.

    /var/cache/bind/db.lan.debuntu.local will look like:

    ;
    ; Zone file for lan.debuntu.local
    ;
    ; The full zone file
    ;
    $TTL 3D
    @ IN SOA ns.lan.debuntu.local. postmaster.lan.debuntu.local. (
    200806281; serial, todays date + todays serial #
    8H ; refresh, seconds
    2H ; retry, seconds
    4W ; expire, seconds
    1D ) ; minimum, seconds
    ;
    NS ns ; Inet Address of name server
    MX 10 mail ; Primary Mail Exchanger
    ;
    A 192.168.2.1 ; IP address
    ;
    router A 192.168.2.1
    ns CNAME router
    dhcp CNAME ns.lan.debuntu.local.
    * A 192.168.2.1

    While /var/cache/bind/db.2.168.192 will look like:

    $TTL 3D
    @ IN SOA lan.debuntu.local. postmaster.lan.debuntu.local. (
    200806281 ; serial, todays date + todays serial #
    8H ; refresh, seconds
    2H ; retry, seconds
    4W ; expire, seconds
    1D ) ; minimum, seconds
    ;
    @ IN NS ns.lan.debuntu.locl.
    @ IN PTR lan.debuntu.local.

    1 IN PTR router.lan.debuntu.local.


    2. DHCP server

    In order to provide an IP address to the other machines in the network, we need to use a DHCP server.
    This DHCP server will provide the host with all the information needed to connect to any other accessible host. i.e, the IP, netmask, gateway, domain name server.
    The DHCP server will also update bind with a nt set of hostname and IP when the client is requesting a specific hostname.

    2.1. Installing the DHCP server

    We are going to install the dhcp server packaged under the name of dhcp3-server. To install it, simply type:

    # apt-get install dhcp3-server

    Make sure you are installing dhcp3-server and not dhcp as the latter does not support dynamic dns updates.

    2.2. Configuring the DHCP server

    The configuration is all in /etc/dhcp3/dhcpd.conf.

    In our set up, we want to give IPs in the range 192.168.2.0/24 and we want to set up our domain name to be lan.debuntu.local

    We are only going to listen for DHCP queries on eth1 and thus will need to bind the service for only this specific address. To achieve this, go and edit /etc/default/dhcp3-server and make sure INTERFACES is set as follow:

    ... ... # On what interfaces should the DHCP server (dhcpd) serve DHCP requests? # Separate multiple interfaces with spaces, e.g. "eth0 eth1". INTERFACES="eth1"

    Then, go and edit /etc/dhcp3/dhcpd.conf and make it look as follows:

    #naming the server # and enabling ddns server-identifier router; authoritative; ddns-update-style interim; include "/etc/bind/rndc.key"; # Use what key in what zone zone lan.debuntu.local. { primary 127.0.0.1; key "rndc-key"; } #Standard DHCP info option domain-name "lan.debuntu.local"; option domain-name-servers ns.lan.debuntu.org; default-lease-time 600; max-lease-time 7200; log-facility local7; subnet 192.168.2.0 netmask 255.255.255.0 { range 192.168.2.5 192.168.2.200; option routers router.lan.debuntu.local; zone 2.168.192.in-addr.arpa. { primary ns.lan.debuntu.local; key "rndc-key"; } zone lan.debuntu.local. { primary ns.lan.debuntu.local; key "rndc-key"; } }

    Which says that we provide IP addresses on the range 192.168.2.5 to 192.168.2.200, and the traffic for this network will be routed by router.lan.debuntu.local

    On the top of this, the domain name to be used for dns ueries is lan.debuntu.local and the DNS server is machine ns.lan.debuntu.local

    The host names where defined earlier in the DNS section, dhcp3-server will query his DNS server to find there IP. Only the IP will be sent back to the host clients.

    Now our DHCP server should be ready, it is time to restart it.

    # /etc/init.d/dhcp3-server restart

    Same here, if anything goes wrong, /var/log/messages, /var/log/syslog and /var/log/daemon.log will be your friends.

    At this stage, you should normally be able to provide IPs to all the host in the network, provide them domain name resolution service and all the host should be able to communicate with each others using hostnames.

    BUT, except for the gateway, none of the host can connect to the internet.

    3. Forwarding Internet traffic with IPtables

    IPtables is both used to act as a firewall, but it is also the one passing packets from one network to another.

    3.1. Enabling IP forwarding

    IP forwarding is enabled at the kernel level. The way to enable it is to set /proc/sys/net/ipv4/ip_forward to 1.
    This can be done during runtime by typing:

    # echo 1 > /proc/sys/net/ipv4/ip_forward

    To make those changes permanent upon reboots, edit /etc/sysctl.conf and make sure there is the following values:

    net.ipv4.conf.default.forwarding=1
    net.ipv4.conf.all.forwarding=1

    3.2. Setting iptables rules

    The next step is to set up iptables rules, the ones that will tell the kernel what to do with the packet depending on their states.

    This firewall will only accept ssh connection from the WAN, anything from the LAN and will forward port 2222 from the WAN to machine 192.168.2.2 on port 22.

    Here is the script used:

    #!/bin/sh
    #
    # this script requires iptables package to be
    # installed on your machine


    # Where to find iptables binary
    IPT="/sbin/iptables"
    # The network interface you will use
    # WAN is the one connected to the internet
    # LAN the one connected to your local network
    WAN="eth0"
    LAN="eth1"
    # First we need to clear up any existing firewall rules
    # and chain which might have been created
    $IPT -F
    $IPT -F INPUT
    $IPT -F OUTPUT
    $IPT -F FORWARD
    $IPT -F -t mangle
    $IPT -F -t nat
    $IPT -X

    # Default policies: Drop any incoming packets
    # accept the rest.
    $IPT -P INPUT DROP
    $IPT -P OUTPUT ACCEPT
    $IPT -P FORWARD ACCEPT

    # To be able to forward traffic from your LAN
    # to the Internet, we need to tell the kernel
    # to allow ip forwarding
    echo 1 > /proc/sys/net/ipv4/ip_forward

    # Masquerading will make machines from the LAN
    # look like if they were the router
    $IPT -t nat -A POSTROUTING -o $WAN -j MASQUERADE


    $IPT -t nat -A PREROUTING -i $WAN -p tcp --dport 2222 -j DNAT --to-destination 192.168.2.2:22
    $IPT -A FORWARD -i $WAN -p tcp --dport 22 -m state --state NEW -j ACCEPT

    # Do not allow other new or invalid connections to reach your internal network
    $IPT -A FORWARD -i $WAN -m state --state NEW,INVALID -j DROP

    # Accept any connections from the local machine
    $IPT -A INPUT -i lo -j ACCEPT
    # plus from your local network
    $IPT -A INPUT -i $LAN -j ACCEPT

    # log those packets and inform the sender that the packet was rejected
    $IPT -N Rejectwall
    $IPT -A Rejectwall -m limit --limit 10/minute -j LOG --log-prefix "Rejectwall: "
    $IPT -A Rejectwall -j REJECT
    # use the following instead if you want to simulate that the host is not reachable
    # for fun though
    #$IPT -A Rejectwall -j REJECT --reject-with icmp-host-unreachable

    $IPT -A INPUT -p icmp -j ACCEPT

    # Accept ssh connections from the Internet
    $IPT -A INPUT -i $WAN -p tcp --dport 22 -j ACCEPT

    # or only accept from a certain ip
    #$IPT -A INPUT -i $WAN -s 125.124.123.122 -p tcp --dport 22 -j ACCEPT

    # Accept related and established connections
    $IPT -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT

    # Drop netbios from the outside, no log, just drop
    $IPT -A INPUT -p udp --sport 137 --dport 137 -j DROP

    # Finally, anything which was not allowed yet
    # is going to go through our Rejectwall rule
    $IPT -A INPUT -j Rejectwall

    Now, run the script:

    # sh iptables.sh

    All host within the LAN should now be able to access the internet!

    now we have to make sure that the changes are permanent upon reboot.

    3.3. Making iptables rules persistent

    I like to be able to easily start and stop iptables using an init.d script. Unfortunately, this is gone from debian packages.

    Anyhow, here is a script that you can copy to /etc/init.d/iptables :

    #!/bin/sh

    IPTABLES="/sbin/iptables"

    # load options
    if [ -f /etc/default/iptables ] ; then
    . /etc/default/iptables
    else
    exit 1
    fi

    # Check for daemon presence
    test -x ${IPTABLES} || exit 0

    # Get lsb functions
    . /lib/lsb/init-functions
    . /etc/default/rcS

    # Check for saved state
    if [ x$1 != "xsave" ] && [ x$1 = "xstart" ] && ! test -r ${IPTABLES_SAVE}; then
    log_warning_msg "Skipping iptables configuration..."
    exit 0
    fi

    flush() {
    if [ -f /proc/net/ip_tables_names ] ; then
    for table in `cat /proc/net/ip_tables_names`; do
    ${IPTABLES} -F -t $table
    ${IPTABLES} -X -t $table
    if [ $table = nat ]; then
    ${IPTABLES} -t nat -P PREROUTING ACCEPT
    ${IPTABLES} -t nat -P POSTROUTING ACCEPT
    ${IPTABLES} -t nat -P OUTPUT ACCEPT
    elif [ $table = mangle ]; then
    ${IPTABLES} -t mangle -P PREROUTING ACCEPT
    ${IPTABLES} -t mangle -P INPUT ACCEPT
    ${IPTABLES} -t mangle -P FORWARD ACCEPT
    ${IPTABLES} -t mangle -P OUTPUT ACCEPT
    ${IPTABLES} -t mangle -P POSTROUTING ACCEPT
    elif [ $table = filter ]; then
    ${IPTABLES} -t filter -P INPUT ACCEPT
    ${IPTABLES} -t filter -P FORWARD ACCEPT
    ${IPTABLES} -t filter -P OUTPUT ACCEPT
    fi
    done
    fi
    return 0
    }

    case "$1" in
    start)
    log_begin_msg "Loading iptables settings..."
    ${IPTABLES}-restore ${SAVE_RESTORE_OPTIONS} ${IPTABLES_SAVE}
    log_end_msg $?
    ;;
    save)
    log_begin_msg "Saving iptables settings..."
    ${IPTABLES}-save ${SAVE_RESTORE_OPTIONS} > ${IPTABLES_SAVE}
    log_end_msg $?
    ;;
    stop)
    log_begin_msg "Clearing iptables settings..."
    flush
    log_end_msg $?
    ;;
    restart)
    $0 stop
    $0 start
    ;;
    status)
    ${IPTABLES} -L
    ;;
    *)
    log_success_msg "Usage: $0 {start|stop|restart|status|save}"
    exit 1
    esac

    and another one to /etc/default/iptables :

    IPTABLES_SAVE="/etc/iptables-rules"
    SAVE_RESTORE_OPTIONS="-c"

    finally, once you are satisfied with your actual rules, save them by typing the following:

    # /etc/init.d/iptables save

    We also need to make sure that the service will be started upon boot up by typing:

    # update-rc.d iptables defaults 20

    And that's it, here we are with a box that provide full access t internet!

    4. Troubleshooting

    Even though this tutorial is made in such a way that you could just copy and paste, issues may arise.

    You might find useful to install the packages dnsutils, telnet, tcpdump and nmap to get a better idea of what is going on.

    In /var/log , action is going to be mailly in messages, daemon.log and syslog.





    In zone lan.debuntu.local, we define the standard bind headers and finally, some static hosts in our network: router, ns, dhcp and any other host to point to 192.168.2.1.

    In zone 2.168.192.in-addr.arpa, we define our reverse lookup name for IP 192.168.2.1.

    You need to make sure that the directory holding those db files is writable as bind will need to create journal files to get DDNS to work.

    Finally, we just have to restart bind. If there is anything wrong, /var/log/syslog is your best friend, along with goolge :).

    /etc/init.d/bind9 restart

    now that our DNS server is up and running, we need to handle DHCP request.



    Remote syslog logging on Debian and Ubuntu

    syslogd is the Linux system logging utility that take care of filling up your files in /var/log when it is asked to.

    On a standard system, logging is only done on the local drive. But syslog can be configured to receive logging from a remote client, or to send logging to a remote syslog server.

    Some of the use cases could be:

    • A machine which filesystem goes read-only
    • Log replication

    this tutorial will explain how to set up both the server, to receive message from a remote client, and the client to emit messages to a syslogd server.

    In this tutorial I will consider that you do not have any firewalls interfering with the traffic.
    The syslogd server will be called etch32 and has IP 192.168.2.1.
    The client is called hardy32-1. Its IP do not matter.

    syslogd is using UDP on port 514

    1. Setting up the syslogd server

    The distribution used for the server is, as its hostname says, a Debian Etch. But, unless you are not using a debian based distro, the changes will be the same.

    changes for syslogd are pretty minor. We basically simply have to tell syslogd to listen for remote messages.
    It is either opened or closed, there is no filtering, so if you need to only accept a subset of machines, IPtables will be your friend.

    To enable remote logging, go and edit /etc/default/syslogd and make sure SYSLOGD is set to:

    SYSLOGD="-r"

    then, restart syslogd:

    # /etc/init.d/syslogd restart

    Now, let set a client to send messages to our remote syslogd server.

    2. syslogd clients

    The action is in /etc/syslog.conf. In this example, I am going to send to both the remote syslogd server and to the filesystem the messages written to /var/log/messages.

    In Ubuntu, this is the bit of conf that handle that:

    *.=info;*.=notice;*.=warn;\
    auth,authpriv.none;\
    cron,daemon.none;\
    mail,news.none -/var/log/messages

    The default is to send the messages to /var/log/messages without "synching" after each log messages ("-" in front of the file name.).

    to specify a remote host, the name or the ip of the remote host as to be given instead of a file, and, prepended with an "@". So, to send the messages writtent to /var/log/messages, our syslog.conf file will look like:

    *.=info;*.=notice;*.=warn;\
    auth,authpriv.none;\
    cron,daemon.none;\
    mail,news.none -/var/log/messages
    *.=info;*.=notice;*.=warn;\
    auth,authpriv.none;\
    cron,daemon.none;\
    mail,news.none @etch32

    to have etch32 receiving messages from hardy32-1.

    now, we need to make syslog aware of the chances:

    $ sudo /etc/init.d/sysklogd restart

    3. What happens then

    Well, lets take a look at each /var/log/messages after I restarted syslogd on hardy32-1 and I started tcpdump on eth0:

    Jun 30 23:01:59 etch32 dhcpd: added reverse map from 198.2.168.192.in-addr.arpa. to hardy32-1.lan.debuntu.local
    Jun 30 23:01:59 etch32 dhcpd: DHCPREQUEST for 192.168.2.198 (192.168.2.1) from 00:0c:29:d4:01:57 (hardy32-1) via eth1
    Jun 30 23:01:59 etch32 dhcpd: DHCPACK on 192.168.2.198 to 00:0c:29:d4:01:57 (hardy32-1) via eth1
    Jun 30 23:04:15 hardy32-1.lan.debuntu.local syslogd 1.5.0#1ubuntu1: restart.
    Jun 30 23:05:01 hardy32-1.lan.debuntu.local kernel: [ 6268.923820] device eth0 entered promiscuous mode
    Jun 30 23:05:01 hardy32-1.lan.debuntu.local kernel: [ 6268.923847] audit(1214863498.177:3): dev=eth0 prom=256 old_prom=0 auid=4294967295
    Jun 30 23:05:11 hardy32-1.lan.debuntu.local kernel: [ 6278.677844] device eth0 left promiscuous mode
    Jun 30 23:05:11 hardy32-1.lan.debuntu.local kernel: [ 6278.677869] audit(1214863510.404:4): dev=eth0 prom=0 old_prom=256 auid=4294967295

    As you can see, messages from hardy32-1 contains the box FQDN: hardy32-1.lan.debuntu.local and we see that eth0 went temporarily in promiscuous mode.

    Wednesday, January 28, 2009

    Firefox 3 browser on Debian Etch

    First, some updates:
    These days, I've been busy doing in research and development and somehow I found time to document on installing firefox 3 browser in Debian Etch. There were a few problems that I was facing
    1. I didn't want to kill of the old firefox
    2. I didn't want to use what's considered to be unstable by debian etch in the core system
    First of all, I got the error that firefox 3 needed gtk+2.10. I just downloaded the file from http://ftp.gnome.org/pub/gnome/sources/gtk+/2.10/gtk+-2.10.14.tar.bz2 and installed it at /opt/gtk

    Here are the commands:
    $ wget http://ftp.gnome.org/pub/gnome/sources/gtk+/2.10/gtk+-2.10.14.tar.bz2
    $ tar -xvjf gtk+-2.10.14.tar.bz2
    $ cd gtk+-2.10.14
    $ ./configure --prefix=/opt/gtk
    $ sudo su
    # make && make install
    # exit

    Then I downloaded firefox from http://www.mozilla.com/products/download.html?product=firefox-3.0&os=linux&lang=en-US
    and modified the run-mozilla.sh to make it run.
    Here are the commands:
    $ wget http://www.mozilla.com/products/download.html?product=firefox-3.0&os=linux&lang=en-US
    $ sudo tar -xvf firefox-3.0.tar.gz -C /opt
    This will give us a /opt/firefox folder
    First of all, we need to make sure that firefox actually run by run-mozilla.sh file.
    So, I added this for firefox path in the beginning (right after ****END LICENSE BLOCK****)
    FF_PATH="/opt/firefox"
    and changed MOZ_PROGRAM="" to MOZ_PROGRAM="$FF_PATH/firefox". Now firefox should run with the
    Since all this is about gtk+ 2.10, I added
    GLIB210_PATH="/opt/gtk/lib" ( I know it's a misnomer, I don't care about it at this point, you can change it to appropriate name)
    and added it to the
    LD_LIBRARY_PATH=${MOZ_DIST_BIN}:${MOZ_DIST_BIN}/plugins:${GLIB210_PATH}:${MRE_HOME}${LD_LIBRARY_PATH+":$LD_LIBRARY_PATH"}
    in line 357.
    Now firefox runs with ./run-mozilla.sh command.

    But that's not enough, we want to have firefox run with a command, we want it on the menu along with iceweasel. So, I added firefox.desktop in /usr/share/applications
    with this data:
    [Desktop Entry]
    Encoding=UTF-8
    Name=Firefox 3 Web Browser
    Exec=/opt/firefox/run-mozilla.sh %u
    Comment= Firefox 3 - The latest and greatest from Mozilla
    Terminal=false
    X-MultipleArgs=false
    Type=Application
    Icon=firefox3.png
    Categories=Application;Network;
    MimeType=text/html;text/xml;application/xhtml+xml;application/xml;application/vnd.mozilla.xul+xml;application/rss+xml;application/rdf+xml;image/gif;image/jpeg;image/png
    StartupNotify=true

    Then I copied the file into /var/lib/menu-xdg/applications/X-Debian-Apps-Net-firefox.desktop
    I copied the bundled icon with firefox from /opt/firefox/icons/mozicon128.png to /usr/share/pixmaps/firefox3.png
    and voila, firefox-3 in the menu without upgrading the system's gtk. You could use it in your home directory if your system administrator doesn't upgrade it soon enough

    Download
    ftp://ftp.ubuntu.org.np/firefox-3-lab.tar.bz2
    and do the following if you don't want to go through all that
    $ wget ftp://ftp.ubuntu.org.np/firefox-3-lab.tar.bz2
    This is for downloading, if you have downloaded already cd to that folder
    $sudo tar -xjvf firefox-3-lab.tar.bz2 -C /
    It saves the firefox 3 files in the /opt/firefox directory and adds icon to the Applications menu.
    If you are on gnome do
    $killall gnome-panel
    wait a while for it to reload with your updated icons

    Sunday, November 16, 2008

    How to use your blackberry as a modem in Debian

    After aquiring a BlackBerry cellphone, I wanted to use it as a modem for my laptop, running Debian. Here's how to do it via USB:

    I recommend you read all this procedure before starting


    • Install barry (so you can use the cellphone via USB, this makes it chargeable too

    • Install XmBlackBerry

    • connect your mobile phone to your computer, via USB

    • sudo XmBlackBerry

    • clicking in the options menu you'll see in the stderr (console where you
      run this app) a /dev/pts/something , which is your GPRS device

    • click "connect" and see if your phone tells you that you're connected to the desktop

    • sudo vi /etc/chatscripts/blackberry :


      ABORT BUSY ABORT ‘NO CARRIER’ ABORT VOICE ABORT ‘NO DIALTONE’ ABORT ‘NO DIAL TONE’ ABORT ‘NO ANSWER’ ABORT DELAYED ABORT ERROR
      SAY “Initializing\n”
      ” ATZ
      SAY "ATE\n"
      OK 'AT+CGDCONT=1,"IP","wap.voicestream.com"'
      OK 'AT'OK 'ATDT*99***1#'
      SAY "Dialing\n"


    • (change "device" here) sudo vi /etc/ppp/peers/blackberry


      debug debug debug
      nodetach
      /dev/pts/device
      115200
      connect "/usr/sbin/chat -f /etc/chatscripts/blackberry"
      nomultilink
      defaultroute
      noipdefault
      ipcp-restart 7
      ipcp-accept-local
      ipcp-accept-remote
      lcp-echo-interval 0
      lcp-echo-failure 999
      modem
      noauth
      nocrtscts
      noipdefault
      novj
      usepeerdns
      user ""
      password ""


    • sudo pppd call blackberry



    And you're on!

    Yeah, but how to install XmBlackBerry?



    Here are the steps to install XmBlackBerry:

    * get and install libmotif 2.3.0 debian packages here
    * aptitude install xaw3dg-dev xorg-dev x11proto-print-dev autoconf libtool libopensync-dev libcurl4-openssl-dev
    * As root, run
    ln -s /usr/include/X11/Xaw3d /usr/include/X11/Xaw
    * Install Xlt (tested with 13.0.13): get it here, untar it and, in its directory...
    *

    ./configure --with-motif-libraries=/usr/X11R6/lib --prefix=/usr
    make && make install

    * Install XmBlackBerry:

    cvs -d:pserver:anonymous@xmblackberry.cvs.sourceforge.net:/cvsroot/xmblackberry co XmBlackBerry
    cd XmBlackBerry/
    cvs -d :pserver:anonymous@libusb.cvs.sourceforge.net:/cvsroot/libusb co libusb
    cd libusb
    make && make install
    cd ..
    ./CVSMake
    ./configure --enable-maintainer-mode --disable-shared --with-motif-libraries=/usr/X11R6/lib
    make
    sudo make install
    sudo ln -s /usr/X11R6/lib/libXm.so.4 /usr/lib/libXm.so.4


    And how to install Barry?


    In Pearl's case you need CVS version of it.

    * Install barry:
    cvs -d:pserver:anonymous@barry.cvs.sourceforge.net:/cvsroot/barry login
    cvs -z3 -d:pserver:anonymous@barry.cvs.sourceforge.net:/cvsroot/barry co -P barry
    cd barrysh
    buildgen.sh
    ./configure --prefix=/usr
    make
    sudo make install
    sudo cp udev/*b* /etc/udev/rules.d/.

    Monday, February 25, 2008

    APT HOWTO

    Introduction


    A new dilemma quickly took hold of the minds of the makers of GNU/Linux. They needed a rapid, practical, and efficient way to install packages that would manage dependencies automatically and take care of their configuration files while upgrading. Here again, Debian led the way and gave birth to APT, the Advanced Packaging Tool, which has since been ported by Conectiva for use with rpm and has been adopted by some other distributions.

    2.1 The /etc/apt/sources.list file


    As part of its operation, APT uses a file that lists the 'sources' from which packages can be obtained. This file is /etc/apt/sources.list.

    The entries in this file normally follow this format:

         deb http://host/debian distribution section1 section2 section3
    
    deb-src http://host/debian distribution section1 section2 section3

    Of course, the above entries are fictitious and should not be used. The first word on each line, deb or deb-src, indicates the type of archive: whether it contains binary packages (deb), that is, the pre-compiled packages that we normally use, or source packages (deb-src), which are the original program sources plus the Debian control file (.dsc) and the diff.gz containing the changes needed for `debianizing' the program.

    We usually find the following in the default Debian sources.list:

         # See sources.list(5) for more information, especially
    
    # Remember that you can only use http, ftp or file URIs
    # CDROMs are managed through the apt-cdrom tool.
    deb http://http.us.debian.org/debian stable main contrib non-free
    deb http://non-us.debian.org/debian-non-US stable/non-US main contrib non-free
    deb http://security.debian.org stable/updates main contrib non-free

    # Uncomment if you want the apt-get source function to work
    #deb-src http://http.us.debian.org/debian stable main contrib non-free
    #deb-src http://non-us.debian.org/debian-non-US stable/non-US main contrib non-free

    These are the lines needed by a basic Debian install. The first deb line points to the official archive, the second to the non-US archive and the third to the archive of Debian security updates.

    The two last lines are commented out (with a `#' in front), so apt-get will ignore them. These are deb-src lines, that is, they point to Debian source packages. If you often download program sources for testing or recompiling, uncomment them.

    The /etc/apt/sources.list file can contain several types of lines. APT knows how to deal with archives of types http, ftp, file (local files, e.g., a directory containing a mounted ISO9660 filesystem) and ssh, that I know of.

    Do not forget to run apt-get update after modifying the /etc/apt/sources.list file. You must do this to let APT obtain the package lists from the sources you specified.


    2.2 How to use APT locally

    Sometimes you have lots of packages .deb that you would like to use APT to install so that the dependencies would be automatically solved.

    To do that create a directory and put the .debs you want to index in it . For example:

         # mkdir /root/debs
    

    You may modify the definitions set on the package's control file directly for your repository using an override file. Inside this file you may want to define some options to override the ones that come with the package. It looks like follows:

         package priority section
    

    package is the name of the package, priority is low, medium or high and section is the section to which it belongs. The file name does not matter, you'll have to pass it as an argument for dpkg-scanpackages later. If you do not want to write an override file, just use /dev/null. when calling dpkg-scanpackages.

    Still in the /root directory do:

         # dpkg-scanpackages debs file | gzip > debs/Packages.gz
    

    In the above line, file is the override file, the command generates a file Packages.gz that contains various information about the packages, which are used by APT. To use the packages, finally, add:

         deb file:/root debs/
    

    After that just use the APT commands as usual. You may also generate a sources repository. To do that use the same procedure, but remember that you need to have the files .orig.tar.gz, .dsc and .diff.gz in the directory and you have to use Sources.gz instead of Packages.gz. The program used is also different. It is dpkg-scansources. The command line will look like this:

         # dpkg-scansources debs | gzip > debs/Sources.gz
    

    Notice that dpkg-scansources doesn't need an override file. The sources.list's line is:

         deb-src file:/root debs/
    

    2.3 Deciding which mirror is the best to include in the sources.list file: netselect, netselect-apt

    A very frequent doubt, mainly among the newest users is: "which Debian mirror to include in sources.list?". There are many ways to decide which mirror. The experts probably have a script that measures the ping time through the several mirrors. But there's a program that does this for us: netselect.

    To install netselect, as usual:

    # apt-get install netselect

    Executing it without parameters shows the help. Executing it with a space-separated list of hosts (mirrors), it will return a score and one of the hosts. This score takes in consideration the estimated ping time and the hops (hosts by which a network query will pass by to reach the destination) number and is inversely proportional to the estimated download speed (so, the lower, the better). The returned host is the one that had the lowest score (the full list of scores can be seen adding the -vv option). See this example:

    # netselect ftp.debian.org http.us.debian.org ftp.at.debian.org download.unesp.br ftp.debian.org.br 365 ftp.debian.org.br #

    This means that, from the mirrors included as parameters to netselect, ftp.debian.org.br was the best, with an score of 365. (Attention!! As it was done on my computer and the network topography is extremely different depending on the contact point, this value is not necessarily the right speed in other computers).

    Now, just put the fastest mirror found by netselect in the /etc/apt/sources.list file (see The /etc/apt/sources.list file, Section 2.1) and follow the tips in Managing packages, Chapter 3.

    Note: the list of mirrors may always be found in the file http://www.debian.org/mirror/mirrors_full.

    Beginning with the 0.3.ds1 version, the netselect source package includes the netselect-apt binary package, which makes the process above automatic. Just enter the distribution tree as parameter (the default is stable) and the sources.list file will be generated with the best main and non-US mirrors and will be saved under the current directory. The following example generates a sources.list of the stable distribution:

    # ls sources.list ls: sources.list: File or directory not found # netselect-apt stable (...) # ls -l sources.list sources.list #

    Remember: the sources.list file is generated under the current directory, and must be moved to the /etc/apt directory.


    2.4 Adding a CD-ROM to the sources.list file

    If you'd rather use your CD-ROM for installing packages or updating your system automatically with APT, you can put it in your sources.list. To do so, you can use the apt-cdrom program like this:

         # apt-cdrom add
    

    with the Debian CD-ROM in the drive. It will mount the CD-ROM, and if it's a valid Debian CD it will look for package information on the disk. If your CD-ROM configuration is a little unusual, you can also use the following options:

         -h           - program help
    
    -d directory - CD-ROM mount point
    -r - Rename a recognized CD-ROM
    -m - No mounting
    -f - Fast mode, don't check package files
    -a - Thorough scan mode

    For example:

         # apt-cdrom -d /home/kov/mycdrom add
    

    You can also identify a CD-ROM, without adding it to your list:

         # apt-cdrom ident
    

    Note that this program only works if your CD-ROM is properly configured in your system's /etc/fstab.

    Managing packages

    3.1 Updating the list of available packages

    The packaging system uses a private database to keep track of which packages are installed, which are not installed and which are available for installation. The apt-get program uses this database to find out how to install packages requested by the user and to find out which additional packages are needed in order for a selected package to work properly.

    To update this list, you would use the command apt-get update. This command looks for the package lists in the archives found in /etc/apt/sources.list; see The /etc/apt/sources.list file, Section 2.1 for more information about this file.

    It's a good idea to run this command regularly to keep yourself and your system informed about possible package updates, particularly security updates.

    3.2 Installing packages

    Finally, the process you've all been waiting for! With your sources.list ready and your list of available packages up to date, all you have to do is run apt-get to get your desired package installed. For example, you can run:

         # apt-get install xchat
    

    APT will search it's database for the most recent version of this package and will retrieve it from the corresponding archive as specified in sources.list. In the event that this package depends on another -- as is the case here -- APT will check the dependencies and install the needed packages. See this example:

         # apt-get install nautilus
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    The following extra packages will be installed:
    bonobo libmedusa0 libnautilus0
    The following NEW packages will be installed:
    bonobo libmedusa0 libnautilus0 nautilus
    0 packages upgraded, 4 newly installed, 0 to remove and 1 not upgraded.
    Need to get 8329kB of archives. After unpacking 17.2MB will be used.
    Do you want to continue? [Y/n]

    The package nautilus depends on the shared libraries cited, therefore APT will get them from the archive. If you had specified the names of these libraries on the apt-get command line, APT would not have asked if you wanted to continue; it would automatically accept that you wanted to install all of those packages.

    This means that APT only asks for confirmation when it needs to install packages which weren't specified on the command line.

    The following options to apt-get may be useful:

         -h  This help text.
    
    -d Download only - do NOT install or unpack archives
    -f Attempt to continue if the integrity check fails
    -s No-act. Perform ordering simulation
    -y Assume Yes to all queries and do not prompt
    -u Show a list of upgraded packages as well

    Multiple packages may be selected for installation in one line. Files downloaded from the network are placed in the directory /var/cache/apt/archives for later installation.

    You can specify packages to be removed on the same command line, as well. Just put a '-' immediately after the name of the package to be removed, like this:

         # apt-get install nautilus gnome-panel-      
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    The following extra packages will be installed:
    bonobo libmedusa0 libnautilus0
    The following packages will be REMOVED:
    gnome-applets gnome-panel gnome-panel-data gnome-session
    The following NEW packages will be installed:
    bonobo libmedusa0 libnautilus0 nautilus
    0 packages upgraded, 4 newly installed, 4 to remove and 1 not upgraded.
    Need to get 8329kB of archives. After unpacking 2594kB will be used.
    Do you want to continue? [Y/n]

    See section Removing packages, Section 3.3 for more details on package removal.

    If you somehow damage an installed package, or simply want the files of a package to be reinstalled with the newest version that is available, you can use the --reinstall option like so:

         # apt-get --reinstall install gdm
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    0 packages upgraded, 0 newly installed, 1 reinstalled, 0 to remove and 1 not upgraded.
    Need to get 0B/182kB of archives. After unpacking 0B will be used.
    Do you want to continue? [Y/n]

    3.3 Removing packages

    If you no longer want to use a package, you can remove it from your system using APT. To do this just type: apt-get remove package. For example:

         # apt-get remove gnome-panel
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    The following packages will be REMOVED:
    gnome-applets gnome-panel gnome-panel-data gnome-session
    0 packages upgraded, 0 newly installed, 4 to remove and 1 not upgraded.
    Need to get 0B of archives. After unpacking 14.6MB will be freed.
    Do you want to continue? [Y/n]

    As you can see in the above example, APT also takes care of removing packages which depend on the package you have asked to remove. There is no way to remove a package using APT without also removing those packages that depend on it.

    Running apt-get as above will cause the packages to be removed but their configuration files, if any, will remain intact on the system. For a complete removal of the package, run:

         # apt-get --purge remove gnome-panel
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    The following packages will be REMOVED:
    gnome-applets* gnome-panel* gnome-panel-data* gnome-session*
    0 packages upgraded, 0 newly installed, 4 to remove and 1 not upgraded.
    Need to get 0B of archives. After unpacking 14.6MB will be freed.
    Do you want to continue? [Y/n]

    Note the '*' after the names. This indicates that the configuration files for each of these packages will also be removed.

    Just as in the case of the install method, you can use a symbol with remove to invert the meaning for a particular package. In the case of removing, if you add a '+' right after the package name, the package will be installed instead of being removed.

         # apt-get --purge remove gnome-panel nautilus+
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    The following extra packages will be installed:
    bonobo libmedusa0 libnautilus0 nautilus
    The following packages will be REMOVED:
    gnome-applets* gnome-panel* gnome-panel-data* gnome-session*
    The following NEW packages will be installed:
    bonobo libmedusa0 libnautilus0 nautilus
    0 packages upgraded, 4 newly installed, 4 to remove and 1 not upgraded.
    Need to get 8329kB of archives. After unpacking 2594kB will be used.
    Do you want to continue? [Y/n]

    Note that apt-get lists the extra packages which will be installed (that is, the packages whose installation is needed for the proper functioning of the package whose installation has been requested), those which will be removed, and those which will be installed (including the extra packages again).

    3.4 Upgrading packages

    Package upgrades are a great success of the APT system. They can be achieved with a single command: apt-get upgrade. You can use this command to upgrade packages within the same distribution, as well as to upgrade to a new distribution, although for the latter the command apt-get dist-upgrade is preferred; see section Upgrading to a new release, Section 3.5 for more details.

    It's useful to run this command with the -u option. This option causes APT to show the complete list of packages which will be upgraded. Without it, you'll be upgrading blindly. APT will download the latest versions of each package and will install them in the proper order. It's important to always run apt-get update before you try this. See section Updating the list of available packages, Section 3.1. Look at this example:

         # apt-get -u upgrade
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    The following packages have been kept back
    cpp gcc lilo
    The following packages will be upgraded
    adduser ae apt autoconf debhelper dpkg-dev esound esound-common ftp indent
    ipchains isapnptools libaudiofile-dev libaudiofile0 libesd0 libesd0-dev
    libgtk1.2 libgtk1.2-dev liblockfile1 libnewt0 liborbit-dev liborbit0
    libstdc++2.10-glibc2.2 libtiff3g libtiff3g-dev modconf orbit procps psmisc
    29 packages upgraded, 0 newly installed, 0 to remove and 3 not upgraded.
    Need to get 5055B/5055kB of archives. After unpacking 1161kB will be used.
    Do you want to continue? [Y/n]

    The process is very simple. Note that in the first few lines, apt-get says that some packages were kept back. This means that there are new versions of these packages which will not be installed for some reason. Possible reasons are broken dependencies (a package on which it depends doesn't have a version available for download) or new dependencies (the package has come to depend on new packages since the last version).

    3.5 Upgrading to a new release

    This feature of APT allows you to upgrade an entire Debian system at once, either through the Internet or from a new CD (purchased or downloaded as an ISO image).

    It is also used when changes are made to the relationships between installed packages. With apt-get upgrade, these packages would be kept untouched (kept back).

    For example, suppose that you're using revision 0 of the stable version of Debian and you buy a CD with revision 3. You can use APT to upgrade your system from this new CD. To do this, use apt-cdrom (see section Adding a CD-ROM to the sources.list file, Section 2.4) to add the CD to your /etc/apt/sources.list and run apt-get dist-upgrade.

    It's important to note that APT always looks for the most recent versions of packages. Therefore, if your /etc/apt/sources.list were to list an archive that had a more recent version of a package than the version on the CD, APT would download the package from there.

    In the example shown in section Upgrading packages, Section 3.4, we saw that some packages were kept back. We'll solve this problem now with the dist-upgrade method:

         # apt-get -u dist-upgrade
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    Calculating Upgrade... Done
    The following NEW packages will be installed:
    cpp-2.95 cron exim gcc-2.95 libident libopenldap-runtime libopenldap1
    libpcre2 logrotate mailx
    The following packages have been kept back
    lilo
    The following packages will be upgraded
    adduser ae apt autoconf cpp debhelper dpkg-dev esound esound-common ftp gcc
    indent ipchains isapnptools libaudiofile-dev libaudiofile0 libesd0
    libesd0-dev libgtk1.2 libgtk1.2-dev liblockfile1 libnewt0 liborbit-dev
    liborbit0 libstdc++2.10-glibc2.2 libtiff3g libtiff3g-dev modconf orbit
    procps psmisc
    31 packages upgraded, 10 newly installed, 0 to remove and 1 not upgraded.
    Need to get 0B/7098kB of archives. After unpacking 3118kB will be used.
    Do you want to continue? [Y/n]

    Note now that the packages will be upgraded, and new packages will also be installed (the new dependencies of the packages). Note too that lilo is still being kept back. It probably has a more serious problem than a new dependency. We can find out by running:

         # apt-get -u install lilo
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    The following extra packages will be installed:
    cron debconf exim libident libopenldap-runtime libopenldap1 libpcre2
    logrotate mailx
    The following packages will be REMOVED:
    debconf-tiny
    The following NEW packages will be installed:
    cron debconf exim libident libopenldap-runtime libopenldap1 libpcre2
    logrotate mailx
    The following packages will be upgraded
    lilo
    1 packages upgraded, 9 newly installed, 1 to remove and 31 not upgraded.
    Need to get 225kB/1179kB of archives. After unpacking 2659kB will be used.
    Do you want to continue? [Y/n]

    As noted in the above, lilo has a new conflict with the package debconf-tiny, which means it couldn't be installed (or upgraded) without removing debconf-tiny.

    To know what's keeping or removing a package you may use:

         # apt-get -o Debug::pkgProblemResolver=yes dist-upgrade
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    Calculating Upgrade... Starting
    Starting 2
    Investigating python1.5
    Package python1.5 has broken dep on python1.5-base
    Considering python1.5-base 0 as a solution to python1.5 0
    Holding Back python1.5 rather than change python1.5-base
    Investigating python1.5-dev
    Package python1.5-dev has broken dep on python1.5
    Considering python1.5 0 as a solution to python1.5-dev 0
    Holding Back python1.5-dev rather than change python1.5
    Try to Re-Instate python1.5-dev
    Done
    Done
    The following packages have been kept back
    gs python1.5-dev
    0 packages upgraded, 0 newly installed, 0 to remove and 2 not upgraded.

    This way, it's easy to notice that the python1.5-dev package cannot be installed because of an unsatisfied dependency: python1.5.

    3.6 Removing unused package files: apt-get clean and autoclean

    When you install a package APT retrieves the needed files from the hosts listed in /etc/apt/sources.list, stores them in a local repository (/var/cache/apt/archives/), and then proceeds with installation, see Installing packages, Section 3.2.

    In time the local repository can grow and occupy a lot of disk space. Fortunately, APT provides tools for managing its local repository: apt-get's clean and autoclean methods.

    apt-get clean removes everything except lock files from /var/cache/apt/archives/ and /var/cache/apt/archives/partial/. Thus, if you need to reinstall a package APT should retrieve it again.

    apt-get autoclean removes only package files that can no longer be downloaded.

    The following example show how apt-get autoclean works:

         # ls /var/cache/apt/archives/logrotate* /var/cache/apt/archives/gpm*
    
    logrotate_3.5.9-7_i386.deb
    logrotate_3.5.9-8_i386.deb
    gpm_1.19.6-11_i386.deb

    In /var/cache/apt/archives there are two files for the package logrotate and one for the package gpm.

         # apt-show-versions -p logrotate
    
    logrotate/stable uptodate 3.5.9-8
    # apt-show-versions -p gpm
    gpm/stable upgradeable from 1.19.6-11 to 1.19.6-12

    apt-show-versions shows that logrotate_3.5.9-8_i386.deb provides the up to date version of logrotate, so logrotate_3.5.9-7_i386.deb is useless. Also gpm_1.19.6-11_i386.deb is useless because a more recent version of the package can be retrieved.

         # apt-get autoclean
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    Del gpm 1.19.6-11 [145kB]
    Del logrotate 3.5.9-7 [26.5kB]

    Finally, apt-get autoclean removes only the old files. See How to upgrade packages from specific versions of Debian, Section 3.9 for more information on apt-show-versions.

    3.7 Using APT with dselect

    dselect is a program that helps users select Debian packages for installation. It's considered somewhat complicated and rather boring, but with practice you can get the hang of its console-based ncurses interface.

    One feature of dselect is that it knows how to make use of the capacity Debian packages have for "recommending" and "suggesting" other packages for installation. To use the program, run `dselect' as root. Choose 'apt' as your access method. This isn't truly necessary, but if you're not using a CD ROM and you want to download packages from the Internet, it's the best way to use dselect.

    To gain a better understanding of dselect's usage, read the dselect documentation found on the Debian page http://www.debian.org/doc/ddp.

    After making your selections with dselect, use:

         # apt-get -u dselect-upgrade
    

    as in the example below:

         # apt-get -u dselect-upgrade
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    The following packages will be REMOVED:
    lbxproxy
    The following NEW packages will be installed:
    bonobo console-tools-libs cpp-3.0 enscript expat fingerd gcc-3.0
    gcc-3.0-base icepref klogd libdigest-md5-perl libfnlib0 libft-perl
    libgc5-dev libgcc300 libhtml-clean-perl libltdl0-dev libsasl-modules
    libstdc++3.0 metamail nethack proftpd-doc psfontmgr python-newt talk tidy
    util-linux-locales vacation xbill xplanet-images
    The following packages will be upgraded
    debian-policy
    1 packages upgraded, 30 newly installed, 1 to remove and 0 not upgraded.
    Need to get 7140kB of archives. After unpacking 16.3MB will be used.
    Do you want to continue? [Y/n]

    Compare with what we see when running apt-get dist-upgrade on the same system:

         # apt-get -u dist-upgrade  
    
    Reading Package Lists... Done
    Building Dependency Tree... Done
    Calculating Upgrade... Done
    The following packages will be upgraded
    debian-policy
    1 packages upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
    Need to get 421kB of archives. After unpacking 25.6kB will be freed.
    Do you want to continue? [Y/n]

    Note that many of the packages from above are being installed because other packages "suggested" or "recommended" them. Others are being installed or removed (in the case of lbxproxy, for example) per the choices we made while navigating through dselect's package listing. Dselect can be a powerful tool when used in conjunction with APT.

    3.9 How to upgrade packages from specific versions of Debian

    apt-show-versions provides a safe way for users of mixed distributions to upgrade their systems without getting more of the less-stable distribution than they had in mind. For instance, it is possible to upgrade just your unstable packages by running after having installed the apt-show-versions package:

         # apt-get install `apt-show-versions -u -b | grep unstable | cut -d ' ' -f 

    3.10 How to keep specific versions of packages installed (complex)

    You may have occasion to modify something in a package and don't have time or don't want to port those changes to a new version of the program. Or, for instance, you may have just upgraded your Debian distribution to 3.0, but want to continue with the version of a certain package from Debian 2.2. You can "pin" the version you have installed so that it will not be upgraded.

    Using this resource is simple. You just need to edit the file /etc/apt/preferences.

    The format is simple:

         Package: 
    
    Pin:
    Pin-Priority:

    Each entry must be separated from any other entries by a blank line. For example, to keep package sylpheed that I have modified to use "reply-to-list" at version 0.4.99, I add:

         Package: sylpheed
    
    Pin: version 0.4.99*

    Note that I used an * (asterisk). This is a "wildcard"; it say that I want that this "pin" to be valid for all versions beginning with 0.4.99. This is because Debian versions its packages with a "Debian revision" and I don't want to avoid the installation of these revisions. So, for instance, versions 0.4.99-1 and 0.4.99-10 will be installed as soon as they are made available. Note that if you modified the package you won't want to do things this way.

    The pin priority helps determine whether a package matching the "Packages:" and "Pin:" lines will be installed, with higher priorities making it more likely that a matching package will be installed. You can read apt_preferences(7) for a thorough discussion of priorities, but a few examples should give the basic idea. The following describes the effect of setting the priority field to different values in the sylpheed example above.

    1001
    Sylpheed version 0.4.99 will never be replaced by apt. If available, apt will install version 0.4.99 even if it would replace an installed package with a higher version. Only packages of priority greater than 1000 will ever downgrade an existing package.
    1000
    The effect is the same as priority 1001, except that apt will refuse to downgrade an installed version to 0.4.99
    990
    Version 0.4.99 will be replaced only by a higher version available from a release designated as preferred using the "APT::Default-Release" variable (see How to keep a mixed system, Section 3.8, above).
    500
    Any version higher than 0.4.99 of sylpheed which is available from any release will take preference over version 0.4.99, but 0.4.99 will still be preferred to a lower version.
    100
    Higher versions of sylpheed available from any release will take preference over version 0.4.99, as will any installed higher version of slypheed; so 0.4.99 will be installed only if no version is installed already. This is the priority of installed packages.
    -1
    Negative priorities are allowed as well, and prevent 0.4.99 from ever being installed.

    A pin can be specified on a package's version, release or origin.

    Pinning on a version, as we have seen, supports literal version numbers as well as wildcards to specify several versions at one time.

    Option release depends on the Release file from an APT repository or from a CD. This option may be of no use at all if you're using package repositories that don't provide this file. You may see the contents of the Release files that you have on /var/lib/apt/lists/. The parameters for a release are: a (archive), c (components), v (version), o (origin) and l (label).

    An example:

         Package: *
    
    Pin: release v=2.2*,a=stable,c=main,o=Debian,l=Debian
    Pin-Priority: 1001

    In this example, we chose version 2.2* of Debian (which can be 2.2r2, 2.2r3 -- this accommodates "point releases" that typically include security fixes and other very important updates), the stable repository, section main (as opposed to contrib or non-free) and origin and label Debian. Origin (o=) defines who produced that Release file, the label (l=) defines the name of the distribution: Debian for Debian itself and Progeny for Progeny, for example. A sample Release file:

         $ cat /var/lib/apt/lists/ftp.debian.org.br_debian_dists_potato_main_binary-i386_Release
    
    Archive: stable
    Version: 2.2r3
    Component: main
    Origin: Debian
    Label: Debian
    Architecture: i386

    Monday, January 28, 2008

    5 Ways to Contribute to Open Source Projects Without Coding

    Maybe you've seen many good Open Source projects that are no longer maintained. One of the many reasons for that may be lack of contribution. In fact, there are many one-man projects out there. Most of any program's users are just that, users, not developers. Nevertheless, average users still can contribute to Open Source programs to make them better.

    I made a search for ways to contribute before writing this and I didn't find much. However, I found two very good articles: "How to Contribute to Open Source Without Coding" and "HOWTO Pay for Free Software". These articles explain how to contribute to Open Source. I summarize the information in this post, with a little info added by me.
    1. Contribute quality: help to make a better project, better looking and with new features
      • Submit bug reports
      • Suggest new features and options
      • Suggest ways to improve the framework (maybe comparing it to similar OS or comercial projects)
      • Submit some artwork (icons, backgrounds, logos) to use in the program
      • Correct spelling and grammar mistakes in documentation
      • Help maintain a web site for an Open Source project

    2. Contribute documentation: Some Open Source projects have a poor or insufficient documentation
      • Help write good documentation
      • Translate the documentation (and program text) into another language
      • Read existing documentation, follow the examples, and make corrections
      • Create diagrams, screen-shots, and graphics for documentation
      • Develop spelling and grammar style conventions for documentors
      • Build a glossary of technical terms (so non geek people can understand)
      • Convert documentation into more useful formats (i.e. DocBook)

    3. Contribute support: everybody need it at least once. Let programmer do their work while you help other people
      • Answer questions on forums, mailing lists or IRC channels
      • Contribute to (or start) an online support group
      • Help other people learn how to use the program (or programming library)
      • Write HOWTOS and post them in related forums or your own blog (you can find more info in "How To Write a Good Howto" post)

    4. Contribute money: many Open Source projects have a donate button or a shop where to buy related products, but there are other ways to contribute money
      • Send a developer, project or company some money
      • Buy a Free Software product, or associated products
      • Hire Free Software developers
      • Contribute hardware
      • Contribute bandwidth
      • Advertise in their web site if they show ads
      • Buy products from companies that support Free Software

    5. Contribute publicity: If the project gets popular there will be more people wanting to contribute
      • Package the application for a particular Linux distro (or other OS)
      • Convince people to chose Open Source products when possible
      • Write reviews
      • Write about new ways of using an Open Source program

    6. Contribute appreciation: it's an extra way to contribute but may be the most important
      • Express your appreciation to developers (through email or forum post)
      • Send the programmers post cards
      • Give a project or developer a gift (some have wish lists for this)
      • Be polite when reporting bugs or asking for new features; developers has no obligation to do it after all
    Although most of the list is self-explanatory I plan to post more in depth info in the future.

    Finally, this list is in no way complete. You can read the mentioned articles for more information or add more tips in the comments.