顯示具有 Debian 標籤的文章。 顯示所有文章
顯示具有 Debian 標籤的文章。 顯示所有文章

2026年7月21日 星期二

正確地使用 git send-email 來發 @debian.org 來源的郵件

因為現在許多 Email 垃圾郵件機制會擋掉非正式來源的信件(例如:透過 gmail.com 來發來自 debian.org 的郵件),參考 Sending @debian.org mails from Debian infrastructure 的步驟

首先寫一封簽章過的 email 寄給 echo "Please change my mail password" | gpg --clearsign | mail chpasswd@db.debian.org 然後會收到一封加密的密碼可以搭配自己的 Debian ID 使用

然後設定好 sendemail.smtp*

$ git config --global --list | grep ^sendemail | sed 's/sendemail.smtppass=.*/sendemail.smtppass=XXXXXXXXX/'
sendemail.smtpserver=mail-submit.debian.org
sendemail.smtpserverport=587
sendemail.smtpuser=fourdollars
sendemail.smtppass=XXXXXXXXX
sendemail.smtpencryption=tls

之後就可以使用 git send-email 來提交 patch 到 mailing list 上面了,來源正確經過驗證應該就不會被 Email 垃圾郵件機制給擋掉,就可以避開導致其他開發者可能會收不到信件的問題。

也就是說 kernel.org, gnome.org, ... 這類的 forwarding email address 都要有自己的一套 SMTP server 來給成員用來寄信。

2024年11月29日 星期五

${shlibs:Depends} 使用上的一些陷阱

其實 0~git202411270842.3c1cdd3 這樣的 Debian Version 會等於 0~git202411270842.3c1cdd3-0

$ dpkg --compare-versions 0~git202411270842.3c1cdd3-0 eq 0~git202411270842.3c1cdd3; echo $?
0

於是 0~git202411270842.3c1cdd3-0~ 這樣的 Debian Version 就會小於 0~git202411270842.3c1cdd3

$ dpkg --compare-versions 0~git202411270842.3c1cdd3-0~ lt 0~git202411270842.3c1cdd3; echo $?
0

例如套件 A 使用了 0~git202411270842.3c1cdd3-0~ 這樣的版號。

陷阱來自於在套件 B 的 debian/control 裡面相依性使用 ${shlibs:Depends} 時,只會找到套件 A 的 upstream version 而已,然後會自動代入 (>= 0~git202411270842.3c1cdd3) 這樣的版號相依。

於是在套件 B 的 Debian packaging 打包後,就會遇到明明套件 B 的 Debian source packages 可以成功編譯成 Debian binary packages,但是卻無法安裝使用的情況。

$ sudo apt install libcamhal-ipu6ep
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:

The following packages have unmet dependencies:
 libcamhal-ipu6ep : Depends: libbroxton-ia-pal-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libgcss-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-aiq-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-aiqb-parser-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-bcomp-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-cca-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-cmc-parser-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-coordinate-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-dvs-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-emd-decoder-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-exc-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-isp-bxt-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-lard-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-log-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-ltm-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-mkn-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
                    Depends: libia-nvm-ipu6ep0 (>= 0~git202411270842.3c1cdd3) but it is not going to be installed
E: Unable to correct problems, you have held broken packages.

至於解決方法就是避免使用比 0~git202411270842.3c1cdd3-0 還要小的版號,像是可以改用 0~git202411270842.3c1cdd3-1~ 這樣的版號就不會產生問題了。

$ dpkg --compare-versions 0~git202411270842.3c1cdd3-1~ gt 0~git202411270842.3c1cdd3; echo $?
0

以上是測試打包 ppa:oem-solutions-group/intel-ipu6 時的一些心得感想。

2017年11月26日 星期日

線上編輯與分享 Debian 與 Ubuntu 的自動安裝設定

多年前在弄 https://fourdollars.github.io/d-i/ 時,就已經想到這個主意了,趁這個週末有點時間就用 Python Flask 硬幹出來。

主要是利用下面的機制做出來的:

運作的原理是根據使用者的 IPv4 位址來儲存設定檔,所以另一台透過同樣的 IPv4 位址就可以拿到同一份設定檔,分享的時候也是透過分享 IPv4 位址來達成,但是只有該 IPv4 位址的使用者才能夠編輯給該 IPv4 位址使用的設定。

專案網址:https://fourdollars.github.io/diaas/

我另外弄了一個專門給 Ubuntu 台灣中文社群的通用設定在 https://sylee.org/d-i/?share=08080808,點進去後按下 Save 就可以使用了。

debian-installer (d-i) and preseed.cfg

There is an "Auto mode" while automating the Debian/Ubuntu installation using preseeding.

You can check Debian's or Ubuntu's documentions for details.

Basically if we have prepared a "preseed.cfg" at some right place, like http://example.com/d-i/stretch/preseed.cfg, and then we can use "auto url=example.com" to install Debian stretch by that "preseed.cfg".

"preseed.cfg" is usually a static file so I come out some ideas. How about making it dynamic and we can share it to others.

If you are interested, please check https://fourdollars.github.io/diaas/.

2017年5月29日 星期一

成為 Debian Developer 之後的例行雜事

首先會收到一封含加密密碼的信件,使用自己的 PGP 解密後,就可以使用登入 https://db.debian.org/(這是第一組密碼),然後就可以修改自己在 https://sso.debian.org/ 上面的密碼(這是第二組密碼),登入 https://sso.debian.org/ 後就可以取得一組通行憑證給 Mozilla Firefox 使用,這個憑證之後可以使用在像是 https://tracker.debian.org/ 或是 https://nm.debian.org/ 上面,由於憑證是儲存在本機的瀏覽器裡面,所以有支援憑證登入的網站就不用再輸入密碼了。

另外就是可以到 https://alioth.debian.org/ 上面輸入自己 <username>@debian.org 的 <username> 然後按下忘記密碼來設定自己的密碼(這是第三組密碼),由於 https://alioth.debian.org/ 並沒有支援原本的 *-guest 帳號轉移,所以只能使用新帳號登入重新加入每一個之前加入過的專案,然後再請管理員將原本的 *-guest 帳號刪除掉,當然如果不在意的話,也可以繼續使用原本的 *-guest 帳號。

如果忘了https://db.debian.org/ 的密碼,可以參考 https://db.debian.org/doc-mail.html 寄信要求重設一組密碼。

echo "Please change my Debian password" | gpg --clearsign | mail chpasswd@db.debian.org

另外就是透過 SSH 登入的公鑰也可以透過寄信來設定。

cat .ssh/id_rsa.pub | gpg --clearsign | mail changes@db.debian.org

設定完 SSH 公鑰後就可以登入像是 people.debian.org 這樣的主機,來放自己的個人網頁 ~/public_html/index.html,例如: https://people.debian.org/~fourdollars/ 這樣。

https://db.debian.org/machines.cgi 上面列了一堆機器,目前還不曉得所有機器的使用方法,只知道要注意 https://www.debian.org/devel/dmup 上面的規範,不可以濫用大家共用的資源。

2017年5月16日 星期二

正式成為 Debian Developer

我的個人資料在 https://nm.debian.org/public/person/fourdollars 可以找到。

雖然說資格在 2017-05-07 就拿到了,可是相關帳號權限今天才開好,而且還有不少要花時間去瞭解設定的東西。Orz

特別感謝 czchen 一直在 TOSSUG 的聚會上 push 我去申請,不然我都是懶懶地慢慢摸。

2016年3月5日 星期六

在 Debian/Ubuntu amd64 上面解決 Google Chrome 更新的問題 (2016/03/11 已修正)

Google Chrome 已經不再提供 Linux i386 的版本,所以在 Debian/Ubuntu amd64 使用上可能會遇到下面的問題,並不會導致無法正常更新系統,只是老是看到它很討厭。

W: 無法取得 https://dl.google.com/linux/chrome/deb/dists/stable/Release,在 Release 檔案找不到要有的「main/binary-i386/Packages」項目 (sources.list 項目有問題或檔案格式不對)

E: 某些索引檔未能下載。其已遭略過,或改為使用舊的。

此時可以參考 https://wiki.debian.org/Multiarch/HOWTO 將 /etc/apt/sources.list.d/google-chrome.list 內容修改成下面這樣就可以解決問題了。

deb [arch=amd64] https://dl.google.com/linux/chrome/deb/ stable main

2016/03/07 補充:

修改後隔天又恢復原狀了,查了一下是 /etc/cron.daily/google-chrome 的關係,所以只能等到 Issue 1759243002: Add multiarch specification to apt repo config. 被釋出到穩定版本才能真正解決問題。

2016/03/11 補充:

google-chrome-stable 49.0.2623.87-1 已經修好了

2015年11月17日 星期二

第一次上傳 Debian package 到 Debian 上去

今天是我正式成為 Debian Maintainer (DM) 之後,第一次自己直接上傳套件到 Debian 裡面。

成為 DM 之後,必需要有 Debian Developer (DD) 的幫忙,開特定套件的上傳權限,DM 才能夠自己上傳套件。

我正在處理的是 kore - Fast SPDY capable web server for web development in C

我參考 DebianMaintainer/Tutorial - Debian Wiki,先用 git-buildpackage -S -sa 將 Debian source package 創建出來,然後再用 sbuild -s -A -d sid-amd64 kore_1.2.3-2.dsc 來編譯成 Debian binary package,然後再用 debsign kore_1.2.3-2_amd64.changes 簽上數位簽章,然後用 dput ftp-master kore_1.2.3-2_amd64.changes 上傳。

只是上傳後馬上收到一封 kore_1.2.3-2_amd64.changes REJECTED 的通知信,覺得很奇怪,我的步驟跟方法應該都正確啊!為什麼會有問題呢?

No target suite found. Please check your target distribution and that you uploaded to the right archive.

===

Please feel free to respond to this email if you don't understand why
your files were rejected, or if you upload new files which address our
concerns.

後來到 OFTC IRC 的 #debian-mentors 求助,結果有人叫我去檢查 kore_1.2.3-2_amd64.changes 的內容,然後我發現了。

...
Distribution: sid-amd64
...

原來是 sbuild 時指定使用了 sid-amd64,所以產生出來的 kore_1.2.3-2_amd64.changes 自然也會是寫著 sid-amd64,手動將它改成 Distribution: unstable 後,再用 debsign 簽章一下用 dput 上傳後就順利的進去了。

2015年9月17日 星期四

從 git repository 自行製作上游軟體的 snapshot tarball

在 Linux 系統上面的軟體開發,偶而會遇到需要直接從 git repository 取出尚未正式釋出的版本,以下分享一下我在參加 DebConf15 後,學會的使用流程。

以下以 http://www.freedesktop.org/wiki/Software/libmbim/ 為例子。

首先要找到 git repository 的位置,然後使用 git 指令 clone 到本地端。

$ git clone git://anongit.freedesktop.org/libmbim/libmbim

然後在該目錄底下,找出最後 commit 的日期。

$ git log -1 --format=%cd --date=short . | sed 's/-//g'
20150910

找出目前的版本號碼,libmbim 的版本號碼在寫作這篇文章時寫在 configure.ac 裡面。

dnl Process this file with autoconf to produce a configure script.                                                                                                                                                                             
AC_PREREQ([2.68])

dnl The libmbim version number
m4_define([mbim_major_version], [1])
m4_define([mbim_minor_version], [13])
m4_define([mbim_micro_version], [0])
m4_define([mbim_version],
          [mbim_major_version.mbim_minor_version.mbim_micro_version])

版本號碼也就是 1.13.0 這樣。

然後檢查一下有沒有 .gitignore,如果有的話要先另建一個文字檔 .gitattributes 放入下面的內容。

.gitattributes export-ignore
.gitignore export-ignore

然後就可以使用 git 跟 xz 指令來產生 tarball 檔案。

$ git archive --worktree-attributes --format=tar --prefix=libmbim-1.13.0+20150910/ HEAD | xz > ../libmbim-1.13.0+20150910.tar.xz

如果本來就沒有 .gitignore 的話,就可以不需要使用參數 --worktree-attributes,這樣產生出來的 tarball 檔案就不會包含 .gitignore 在裡面,在使用 Debian 上的一些 git based 的管理工具,會因為 .gitignore 的存在而產生問題。

最後檢查一下 libmbim-1.13.0+20150910.tar.xz 的內容,看看是否沒有那些不應該存在的 .git 開頭的檔案在裡面。

$ tar tf libmbim-1.13.0+20150910.tar.xz
libmbim-1.13.0+20150910/
libmbim-1.13.0+20150910/AUTHORS
libmbim-1.13.0+20150910/COPYING
libmbim-1.13.0+20150910/COPYING.LIB
libmbim-1.13.0+20150910/Makefile.am
libmbim-1.13.0+20150910/NEWS
libmbim-1.13.0+20150910/README
libmbim-1.13.0+20150910/autogen.sh
libmbim-1.13.0+20150910/build-aux/
libmbim-1.13.0+20150910/build-aux/Makefile.am
libmbim-1.13.0+20150910/build-aux/mbim-codegen/
libmbim-1.13.0+20150910/build-aux/mbim-codegen/Makefile.am
libmbim-1.13.0+20150910/build-aux/mbim-codegen/Message.py
libmbim-1.13.0+20150910/build-aux/mbim-codegen/ObjectList.py
libmbim-1.13.0+20150910/build-aux/mbim-codegen/Struct.py
libmbim-1.13.0+20150910/build-aux/mbim-codegen/mbim-codegen
libmbim-1.13.0+20150910/build-aux/mbim-codegen/utils.py
libmbim-1.13.0+20150910/build-aux/templates/
libmbim-1.13.0+20150910/build-aux/templates/Makefile.am
libmbim-1.13.0+20150910/build-aux/templates/mbim-enum-types-template.c
libmbim-1.13.0+20150910/build-aux/templates/mbim-enum-types-template.h
libmbim-1.13.0+20150910/build-aux/templates/mbim-error-quarks-template.c
libmbim-1.13.0+20150910/build-aux/templates/mbim-error-types-template.c
libmbim-1.13.0+20150910/build-aux/templates/mbim-error-types-template.h
libmbim-1.13.0+20150910/configure.ac
libmbim-1.13.0+20150910/data/
libmbim-1.13.0+20150910/data/Makefile.am
libmbim-1.13.0+20150910/data/mbim-service-auth.json
libmbim-1.13.0+20150910/data/mbim-service-basic-connect.json
libmbim-1.13.0+20150910/data/mbim-service-dss.json
libmbim-1.13.0+20150910/data/mbim-service-ms-firmware-id.json
libmbim-1.13.0+20150910/data/mbim-service-ms-host-shutdown.json
libmbim-1.13.0+20150910/data/mbim-service-phonebook.json
libmbim-1.13.0+20150910/data/mbim-service-proxy-control.json
libmbim-1.13.0+20150910/data/mbim-service-sms.json
libmbim-1.13.0+20150910/data/mbim-service-stk.json
libmbim-1.13.0+20150910/data/mbim-service-ussd.json
libmbim-1.13.0+20150910/data/pkg-config/
libmbim-1.13.0+20150910/data/pkg-config/Makefile.am
libmbim-1.13.0+20150910/data/pkg-config/mbim-glib.pc.in
libmbim-1.13.0+20150910/docs/
libmbim-1.13.0+20150910/docs/Makefile.am
libmbim-1.13.0+20150910/docs/libmbim-icon.svg
libmbim-1.13.0+20150910/docs/libmbim-logo.png
libmbim-1.13.0+20150910/docs/libmbim-logo.svg
libmbim-1.13.0+20150910/docs/man/
libmbim-1.13.0+20150910/docs/man/Makefile.am
libmbim-1.13.0+20150910/docs/reference/
libmbim-1.13.0+20150910/docs/reference/Makefile.am
libmbim-1.13.0+20150910/docs/reference/libmbim-glib/
libmbim-1.13.0+20150910/docs/reference/libmbim-glib/Makefile.am
libmbim-1.13.0+20150910/docs/reference/libmbim-glib/libmbim-glib-common.sections
libmbim-1.13.0+20150910/docs/reference/libmbim-glib/libmbim-glib-docs.xml
libmbim-1.13.0+20150910/docs/reference/libmbim-glib/version.xml.in
libmbim-1.13.0+20150910/gtester.make
libmbim-1.13.0+20150910/m4/
libmbim-1.13.0+20150910/m4/compiler-warnings.m4
libmbim-1.13.0+20150910/src/
libmbim-1.13.0+20150910/src/Makefile.am
libmbim-1.13.0+20150910/src/libmbim-glib/
libmbim-1.13.0+20150910/src/libmbim-glib/Makefile.am
libmbim-1.13.0+20150910/src/libmbim-glib/generated/
libmbim-1.13.0+20150910/src/libmbim-glib/generated/Makefile.am
libmbim-1.13.0+20150910/src/libmbim-glib/libmbim-glib.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-cid.c
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-cid.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-compat.c
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-compat.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-device.c
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-device.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-enums.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-errors.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-message-private.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-message.c
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-message.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-proxy-helpers.c
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-proxy-helpers.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-proxy.c
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-proxy.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-utils.c
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-utils.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-uuid.c
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-uuid.h
libmbim-1.13.0+20150910/src/libmbim-glib/mbim-version.h.in
libmbim-1.13.0+20150910/src/libmbim-glib/test/
libmbim-1.13.0+20150910/src/libmbim-glib/test/Makefile.am
libmbim-1.13.0+20150910/src/libmbim-glib/test/test-cid.c
libmbim-1.13.0+20150910/src/libmbim-glib/test/test-fragment.c
libmbim-1.13.0+20150910/src/libmbim-glib/test/test-message-builder.c
libmbim-1.13.0+20150910/src/libmbim-glib/test/test-message-parser.c
libmbim-1.13.0+20150910/src/libmbim-glib/test/test-message.c
libmbim-1.13.0+20150910/src/libmbim-glib/test/test-proxy-helpers.c
libmbim-1.13.0+20150910/src/libmbim-glib/test/test-uuid.c
libmbim-1.13.0+20150910/src/mbim-proxy/
libmbim-1.13.0+20150910/src/mbim-proxy/76-mbim-proxy-device-ownership.rules.in
libmbim-1.13.0+20150910/src/mbim-proxy/Makefile.am
libmbim-1.13.0+20150910/src/mbim-proxy/mbim-proxy.c
libmbim-1.13.0+20150910/src/mbimcli/
libmbim-1.13.0+20150910/src/mbimcli/Makefile.am
libmbim-1.13.0+20150910/src/mbimcli/mbimcli-basic-connect.c
libmbim-1.13.0+20150910/src/mbimcli/mbimcli-completion
libmbim-1.13.0+20150910/src/mbimcli/mbimcli-dss.c
libmbim-1.13.0+20150910/src/mbimcli/mbimcli-helpers.c
libmbim-1.13.0+20150910/src/mbimcli/mbimcli-helpers.h
libmbim-1.13.0+20150910/src/mbimcli/mbimcli-ms-firmware-id.c
libmbim-1.13.0+20150910/src/mbimcli/mbimcli-ms-host-shutdown.c
libmbim-1.13.0+20150910/src/mbimcli/mbimcli-phonebook.c
libmbim-1.13.0+20150910/src/mbimcli/mbimcli.c
libmbim-1.13.0+20150910/src/mbimcli/mbimcli.h
libmbim-1.13.0+20150910/utils/
libmbim-1.13.0+20150910/utils/Makefile.am
libmbim-1.13.0+20150910/utils/mbim-network.in

2015年8月17日 星期一

在 Ubuntu 14.04 上面使用 git-pbuilder 來編譯 Debian packages 給 sid 使用

在使用

$ DIST=sid ARCH=amd64 git-pbuilder create
之前,可以先編輯 ~/.pbuilderrc 檔案,加上下面的內容。

MIRRORSITE=http://ftp.debian.org/debian
DEBOOTSTRAPOPTS=( '--keyring' '/usr/share/keyrings/debian-archive-keyring.gpg' )

然後安裝 debian-archive-keyring cowbuilder git-buildpackage 這幾個套件。

 $ sudo apt-get install debian-archive-keyring cowbuilder git-buildpackage

然後就可以使用

$ DIST=sid ARCH=amd64 git-pbuilder create
來產生 /var/cache/pbuilder/base-sid-amd64.cow 這個目錄。

之後就可以在有使用 gbp 管理的 Debian package 的 git repository 底下使用

$ gbp buildpackage --git-pbuilder --git-arch=amd64 --git-dist=sid --git-export-dir=../build-dir
來編譯 Debian package 了。

2015年7月10日 星期五

關於 Debian/Ubuntu 裡面的 foreign-architectures 這件事

Debian 跟 Ubuntu 都在某個版本後開始支援了 Multiarch 這樣的架構,主要的中心思想是要改善檔案系統的結構,讓它能夠共存多種不同 CPU 架構的應用程式跟檔案;然後如果使用者安裝的系統是 amd64 的話,Debian 跟 Ubuntu 都會自動加入 i386 來使用。

只不過也許有些人像筆者一樣有潔癖,不喜歡系統裡面存在著其它根本完全不會去使用的東西,於是在 Ubuntu 14.04 裡面就可以用下面的指令將 i386 給移除掉。

$ sudo dpkg --remove-architecture i386

如果哪天反悔了,也可以再加回來。

$ sudo dpkg --add-architecture i386

或者想要看看目前使用了哪些額外的架構。

$ dpkg --print-foreign-architectures
i386

或是想要看看目前主要使用的架構是什麼。

$ dpkg --print-architecture
amd64

或許想要試試看 i386 跟 amd64 以外的架構(P.S. Ubuntu 只有提供少部份的幾種,Debian 也不是每個 Mirror Site 都會包含所有部份)

$ dpkg-architecture -L
...
armhf
armel
mipsn32
mipsn32el
mips64
mips64el
powerpcspe
x32
lpia
i386
ia64
alpha
amd64
armeb
arm
arm64
avr32
hppa
m32r
m68k
mips
mipsel
powerpc
ppc64
ppc64el
s390
s390x
sh3
sh3eb
sh4
sh4eb
sparc
sparc64
...

最後是在 amd64 系統裡面將 i386 移除掉,也可以順便省下一些在 apt-get update 或是 apt update 的時間,搭配以前寫過的「在 Ubuntu 上面減少 apt-get update 的時間」使用效果最好。

2015年6月25日 星期四

Spotify 的 2015-06-25 金鑰到期了

如果有原本在使用 Spotify 的 Debian repository,從今天 2015-06-26 開始可能會遇到下面的問題。

W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: http://repository.spotify.com stable InRelease: 由於無法取得它們的公鑰,以下簽章無法進行驗證: NO_PUBKEY 13B00F1FD2C19886

W: 無法取得 http://repository.spotify.com/dists/stable/InRelease,

W: 某些索引檔未能下載。其已遭略過,或改為使用舊的。

這是因為原本的金鑰到期了

pub   2048R/94558F59 2012-06-25 [到期: 2015-06-25]
uid                  Spotify Public Repository Signing Key <operations@spotify.com>

這時候只要新增金鑰就可以解決了。

sudo apt-key adv --recv-key --keyserver keyserver.ubuntu.com D2C19886

順便將原本到期的金鑰給移除掉。

sudo apt-key del 94558F59

2015年5月9日 星期六

在 Ubuntu 14.04 上面使用 sbuild 來建立 Debian unstable 的編譯環境

首先是安裝所需要的套件

$ sudo apt-get install sbuild ubuntu-dev-tools lintian piuparts

接著是產生給 sbuild 使用的公私鑰(需要去做其它的操作來產生足夠的系統亂數,例如去瀏覽網頁)

$ sudo sbuild-update --keygen
Generating archive key.

Not enough random bytes available.  Please do some other work to give
the OS a chance to collect more entropy! (Need 186 more bytes)

接下來將自己加入 sbuild 群組

$ sudo sbuild-adduser $LOGNAME
正將 `sylee' 使用者新增至 `sbuild' 群組 ...
正在將使用者“sylee”加入到“sbuild”群組中
完成。

# Setup tasks for sudo users:

# BUILD
# HOME directory in chroot, user:sbuild, 0770 perms, from
# passwd/group copying to chroot, filtered
# Maybe source 50sbuild, or move into common location.

Next, copy the example sbuildrc file to the home directory of each user and
set the variables for your system:

  cp /usr/share/doc/sbuild/examples/example.sbuildrc /home/sylee/.sbuildrc

Now try a build:

  cd /path/to/source
  sbuild-update -ud 
  (or "sbuild-apt  apt-get -f install"
       first if the chroot is broken)
  sbuild -d  _

然後登出 X Window System 再重新登入來使 sbuild 群組權限生效,如果不想重新登出登入的話,可以使用下面指令直接取得 sbuild 的群組權限。

$ newgrp sbuild

複製 sbuild 的設定範本到家目錄底下

$ cp /usr/share/doc/sbuild/examples/example.sbuildrc $HOME/.sbuildrc

開始建立 Debian unstable 的編譯環境

$ mk-sbuild --arch amd64 --distro debian unstable
[...中略]

Done building sid-amd64.

 To CHANGE the golden image: sudo schroot -c source:sid-amd64 -u root
 To ENTER an image snapshot: schroot -c sid-amd64
 To BUILD within a snapshot: sbuild -A -d sid-amd64 PACKAGE*.dsc

接下來就可以使用 sbuild -A -d sid-amd64 PACKAGE*.dsc 來編譯 Debian binary package 了。

$ sbuild -A -d sid-amd64 x11-touchscreen-calibrator_0.2-2.dsc

另外可以修改 ~/.sbuildrc 在編譯完成時,自動加上 lintian 以及 piuparts 的檢查。

$run_lintian = 1;
$lintian_opts = ['-EviIL', '+pedantic', '--profile', 'debian'];

$run_piuparts = 1;
$piuparts_opts = ['-D', 'debian', '--schroot=chroot:sid-amd64'];

參考資料:https://wiki.debian.org/sbuild

2015-11-04 補充:

在使用 $run_lintian 跟 $lintian_opts 時,要特別注意是否要在 sbuild 加上 -s 或是 --source 的參數,這樣才會去檢查 source package,不然就只會檢查 binary package 而已。

$ sbuild -s -A -d sid-amd64 x11-touchscreen-calibrator_0.2-2.dsc

另外 SimpleSbuild - Ubuntu Wiki 也提供一些加速編譯過程的方法,像是使用記憶體來做檔案系統,或是使用 apt-cacher-ng 來儲存可重覆使用的 deb 檔案。

2015-12-10 補充:

編譯過程中可能會有無法預期的問題發生,導致 sbuild 所使用的 schroot 無法正常結束,這種時候可能會需要參考 man schroot-faq 裡面的 "How do I manually cleaning up a broken session?" 來手動清除壞掉的東西。

2017-12-05 補充:

可以在執行 mk-sbuild 時,指定一個比較近的 mirror 來使用,例如為 Ubuntu xenial 建立 schroot 環境時就可以:

$ mk-sbuild --arch amd64 --distro ubuntu --debootstrap-mirror=http://mirror01.idc.hinet.net/ubuntu xenial

2014年9月13日 星期六

解決 Debian packaging 過程中的 compiler-flags-hidden 警告訊息

compiler-flags-hidden 警告訊息的說明在 https://qa.debian.org/bls/bytag/W-compiler-flags-hidden.html 可以看到。

裡面提到的

可以參考一下,其主要的目的是要盡可能地強化執行檔的安全性。

以 x11-touchscreen-calibrator 0.2-1 為例,將其編譯導向某個檔案儲存,然後再使用 blhc 指令來檢查,就可以看到:

$ blhc --all --color ../log
NONVERBOSE BUILD:   CC       x11_touchscreen_calibrator-x11-touchscreen-calibrator.o
NONVERBOSE BUILD:   CCLD     x11-touchscreen-calibrator

因為 x11-touchscreen-calibrator 上游將 Automake Silent Rules 預設開啟,然後 x11-touchscreen-calibrator 又只使用最簡單的 debian/rules 如下:

#!/usr/bin/make -f                                                                                                                                      
# -*- makefile -*-

%:
        dh  $@

然而 debhelper 到了 9.20140817 預設上還是不會將 --disable-silent-rules 自動加上使用,請見 https://wiki.debian.org/ReleaseGoals/VerboseBuildLogs 的資料。

不過在 Debian Bug report logs - #751207 在有設定 DH_VERBOSE 且 DH_VERBOSE 的值不為空字串的條件下,會自動加上 --disable-silent-rules,所以將 debian/rules 改寫成如下:

#!/usr/bin/make -f                                                                                                                                      
# -*- makefile -*-

export DH_VERBOSE=1

%:
        dh  $@

這樣就可以將 --disable-silent-rules 加上,而且有更詳細的套件包裹編譯過程,不過 blhc 的檢查還是會看到其它的訊息:

$ blhc --all --color ../log
CFLAGS missing (-fPIE): gcc -DHAVE_CONFIG_H -I.   -D_FORTIFY_SOURCE=2  -g -O2 -fstack-protector --param=ssp-buffer-size=4 -Wformat -Werror=format-security -c -o x11_touchscreen_calibrator-x11-touchscreen-calibrator.o `test -f 'x11-touchscreen-calibrator.c' || echo './'`x11-touchscreen-calibrator.c
LDFLAGS missing (-fPIE -pie -Wl,-z,now): libtool: link: gcc -g -O2 -fstack-protector --param=ssp-buffer-size=4 -Wformat -Werror=format-security -Wl,-Bsymbolic-functions -Wl,-z -Wl,relro -o x11-touchscreen-calibrator x11_touchscreen_calibrator-x11-touchscreen-calibrator.o  -lX11 -lXi -lXrandr

這時候就可以將 debian/rules 改成如下:

#!/usr/bin/make -f                                                                                                                                      
# -*- makefile -*-

export DH_VERBOSE=1
export DEB_CFLAGS_MAINT_APPEND=-fPIE
export DEB_LDFLAGS_MAINT_APPEND=-fPIE -pie -Wl,-z,now

%:
        dh  $@

這樣就可以將缺少的 CFLAGS 跟 LDFLAGS 參數加入使用。

最後我們可以使用 hardening-check 來檢查一下執行檔。

使用前:

$ hardening-check /usr/bin/x11-touchscreen-calibrator 
/usr/bin/x11-touchscreen-calibrator:
 Position Independent Executable: no, normal executable!
 Stack protected: yes
 Fortify Source functions: yes
 Read-only relocations: yes
 Immediate binding: no, not found!

使用後:

$ hardening-check /usr/bin/x11-touchscreen-calibrator 
/usr/bin/x11-touchscreen-calibrator:
 Position Independent Executable: yes
 Stack protected: yes
 Fortify Source functions: yes
 Read-only relocations: yes
 Immediate binding: yes

這也是 W-compiler-flags-hidden 這個警告訊息想要讓我們做的事情,透過調整編譯時的參數來強化執行檔的安全性。

2014年5月28日 星期三

使用 virt-manager 透過 URL 安裝 Debian/Ubuntu 系統

常常需要快速地安裝不同版本的 Debian/Ubuntu 的 VM 環境,但是卻又覺得老是在那裡下載 ISO 還是設定 PXE 也很麻煩,那麼有沒有更簡便的安裝方式呢?於是就搜尋了一下,還真的有方法可以達成,以下利用 Debian/Ubuntu installer 內建的 tasksel 機制來安裝一個 openssh-server 為例。

首先是安裝 qemu 相關的軟體套件。

sudo apt-get install virt-manager qemu-kvm qemu-system python-spice-client-gtk

然後再重新登入帳號,讓 libvirtd 的權限生效。

接下來就可以執行 virt-manager 這個應用程式來新增 VM 指定使用網路安裝

接下來將 http://free.nchc.org.tw/ubuntu/dists/precise-updates/main/installer-amd64/ 這樣的網址輸入進去,並且自訂 tasks=openssh-server gfxpayload=800x600x16,800x600 -- quiet 這樣的內核選項。

然後設定一下記憶體使用量跟 CPU 數量。

接著設定一下硬碟大小。

最後結束前看看需要不要在開始安裝前,使用自訂組態進行最後的微調,如果不要直接按完成就可以了。

接下來的動作就是 Debian/Ubuntu installer 原本的安裝過程,如果想要更進一步自動化安裝流程的話,則可搭配使用 preseed.cfg 跟我在 http://fourdollars.github.io/d-i/ 上面所使用的機制一樣。

以此類推,如果想要安裝哪一個 Debian/Ubuntu installer 的版本,只要輸入相對應的 URL 即可,再搭配在 kernel parameter 輸入 tasksel 提供的 task 選項來執行安裝預先設定好的項目即可。

以下是目前 Ubuntu 14.04 上面 tasksel 所提供的 task 選項。

$ tasksel --list-tasks
u server Basic Ubuntu server
u openssh-server OpenSSH server
u dns-server DNS server
u lamp-server LAMP server
u mail-server Mail server
u postgresql-server PostgreSQL database
i print-server Print server
u samba-server Samba file server
u tomcat-server Tomcat Java server
u cloud-image Ubuntu Cloud Image (instance)
u virt-host Virtual Machine host
u ubuntustudio-graphics 2D/3D creation and editing suite
u ubuntustudio-audio Audio recording and editing suite
u edubuntu-desktop-gnome Edubuntu desktop
u kubuntu-active Kubuntu Active
u kubuntu-desktop Kubuntu desktop
u kubuntu-full Kubuntu full
u ubuntustudio-font-meta Large selection of font packages
u lubuntu-desktop Lubuntu Desktop
u lubuntu-core Lubuntu minimal installation
u mythbuntu-desktop Mythbuntu additional roles
u mythbuntu-frontend Mythbuntu frontend
u mythbuntu-backend-master Mythbuntu master backend
u mythbuntu-backend-slave Mythbuntu slave backend
u ubuntustudio-photography Photograph touchup and editing suite
u ubuntustudio-publishing Publishing applications
u ubuntu-gnome-desktop Ubuntu GNOME desktop
i ubuntu-desktop Ubuntu desktop
u ubuntu-usb Ubuntu desktop USB
u ubuntustudio-video Video creation and editing suite
u xubuntu-desktop Xubuntu desktop
u edubuntu-dvd-live Edubuntu live DVD
u kubuntu-active-live Kubuntu Active Remix live CD
u kubuntu-live Kubuntu live CD
u kubuntu-dvd-live Kubuntu live DVD
u lubuntu-live Lubuntu live CD
u ubuntu-gnome-live Ubuntu GNOME live CD
u ubuntustudio-dvd-live Ubuntu Studio live DVD
u ubuntu-live Ubuntu live CD
u ubuntu-usb-live Ubuntu live USB
u xubuntu-live Xubuntu live CD
u manual Manual package selection

至於 Debian 請參考 tasksel-data 裡面的 /usr/share/tasksel/descs/debian-tasks.desc 的內容。

參考資料:Should I use tasksel, tasks in APT or install regular metapackages?

2014年2月27日 星期四

Debian package 打包時遇到需要使用 Pre-Depends 來解決問題

最近在使用 Python 的 XlsxWriter 來產生 Excel 檔案。

可是在 Ubuntu 上面只有在 Trusty 裡面才有 python-xlsxwriter/python3-xlsxwriter 可以使用。

但是我自己在使用的是 Ubuntu 13.10 (Saucy) 於是我就先自己從 Trusty 上面抓 Debian source package 回來 backport 到 Saucy 上面使用。

本來想說等到程式寫好的差不多再來 backport 到 Ubuntu 12.04 (Precise) 上面給人家使用,結果卻發現事情並非如此單純,因為 xlsxwriter 這個套件還需要使用 dh-python 來編譯,但是在 Precise 上面根本就沒有這個套件,於是這件事就變成要先去 backport dh-python 到 Precise 上面使用。

想說不然就從跟 Precise 比較接近的 Wheezy 來抓 Debian source package 回來 backport 好了,於是就找到了 wheezy-backports 裡面的 dh-python,原本以為只要抓回來改一下 debian/changelog 再推到 PPA 上編譯完成就可以了,沒想到 dh-python 已經編譯好了,再去修改 xlsxwriter 裡面的 debian/control 加上 dh-python 的相依性來編譯就可以了,結果卻又遇到了下面這段錯誤訊息:

running python rtupdate hooks for python3.2...
Usage: py3clean [-V VERSION] [-p PACKAGE | DIR_OR_FILE]

py3clean: error: only one action is allowed at the same time (cleaning directory or a package)
error running python rtupdate hook dh-python
dpkg: error processing python3 (--configure):
 subprocess installed post-installation script returned error exit status 4
dpkg: dependency problems prevent configuration of dh-python:
 dh-python depends on python3 (>= 3.2.3-0); however:
  Package python3 is not configured yet.
dpkg: error processing dh-python (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of python3-all:
 python3-all depends on python3 (= 3.2.3-0ubuntu1.2); however:
  Package python3 is not configured yet.
dpkg: error processing python3-all (--configure):
 dependency problems - leaving unconfigured
Processing triggers for libc-bin ...
No apport report written because the error message indicates its a followup error from a previous failure.
No apport report written because the error message indicates its a followup error from a previous failure.
ldconfig deferred processing now taking place
Errors were encountered while processing:
 python3
 dh-python
 python3-all
E: Sub-process /usr/bin/dpkg returned an error code (1)

後來追查了一下才發現,原來 dh-python 在 python3 還沒有安裝好的時候會去執行 py3clean 才導致這個問題的發生,於是查了一下 Debian Policy Manual,發現在 7.2 Binary Dependencies 這一章節提到 Pre-Depends 可以使用來解決我遇到的問題。

於是我就再修改一下 dh-python 將 ${python3:Depends} 移到 Pre-Depends 上面,等 dh-python 推上 PPA 編譯完成後,再來編譯 xlsxwriter 這個額外加上 dh-python 相依性的套件,才順利過關。

xlsxwriter backports 的 PPA 放在 ppa:fourdollars/xlsxwriter

2013年12月4日 星期三

Debian/Ubuntu 無人值守的系統更新

Debian/Ubuntu 上面有一個套件叫做 unattended-upgrades - automatic installation of security upgrades 可以用來設定系統的自動更新,這對於一些特別講究系統安全的伺服器特別有用。

以 Ubuntu 12.04 為例,安裝完成及在下面 APT::Periodic::Unattended-Upgrade 打開之後,預設上只會做安全更新,但是我想要它做一般性的系統更新,於是就修改 /etc/apt/apt.conf.d/50unattended-upgrades

// Automatically upgrade packages from these (origin:archive) pairs
Unattended-Upgrade::Allowed-Origins {
        "${distro_id}:${distro_codename}-security";
        "${distro_id}:${distro_codename}-updates";
//      "${distro_id}:${distro_codename}-proposed";
//      "${distro_id}:${distro_codename}-backports";
};

// Do automatic removal of new unused dependencies after the upgrade
// (equivalent to apt-get autoremove)
Unattended-Upgrade::Remove-Unused-Dependencies "true";

// Automatically reboot *WITHOUT CONFIRMATION* if a
// the file /var/run/reboot-required is found after the upgrade
Unattended-Upgrade::Automatic-Reboot "true";

簡單說就是包含使用 precise-updates 上面的更新,更新之後再用 apt-get autoremove 把多餘的套件移除掉,如果有些更新需要重開機才會生效的話,就重開機吧。

然後再修改一下 /etc/apt/apt.conf.d/10periodic

APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Download-Upgradeable-Packages "1";
APT::Periodic::AutocleanInterval "7";
APT::Periodic::Unattended-Upgrade "1";

意思是每日檢查更新,如果有更新的話先下載,每週自動清除不需要的套件快取,使用無人值守自動更新。

關於 linux kernel 的更新,有一個腳本程式 /etc/kernel/postinst.d/apt-auto-removal 產生 /etc/apt/apt.conf.d/01autoremove-kernels,用來保留當下正在使用、或是最新安裝、或是上一份使用的 linux kernel。

至於詳細的運作細節則可以參考 /etc/cron.daily/apt 裡面的內容。

2013年9月25日 星期三

Debian/Ubuntu 上好用的 Spotify 網路音樂串流軟體

有高興看到有原生支援 Debian/Ubuntu 的網路音樂軟體。

在 Ubuntu 上面使用的方法如下:

$ echo "deb http://repository.spotify.com stable non-free" | sudo tee /etc/apt/sources.list.d/spotify.list
$ sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 94558F59
$ sudo apt-get update
$ sudo apt-get install spotify-client

然後就可以執行 Spotify 來使用了。

目前的 Spotify 似乎無法自動偵測到正體中文的環境,所以要手動去偏好設定裡面調整。

最後一點小小的想法,看到許多好用的軟體都會在推出的時候,都會同時支援跨平台的 Windows/Mac/Linux 桌面系統,還有 Android 與 iOS 的移動平台,也許 Linux 桌面的使用族群相對稀少,也許支援 Linux 並沒有什麼高獲利可言,但是卻會讓人感受到該軟體對於使用者的誠意在哪裡,套一句從 Even Wu 那邊看到的:「正確 > 進度,是我的理念。因為正確會有未來的尾速!」。

2013年8月28日 星期三

在 Ubuntu 上面 Linux Container 的使用心得

Linux Container (以下簡稱為 lxc) 是一個輕量級的虛擬化系統,介於 VirtualBox/VMWare/... 以及打過類固醇的 chroot 之間,簡單來說 lxc 建立了一個 chroot 的環境,但是這個 chroot 的環境卻可以做資源控制,像是 CPU 用量、硬碟空間、記憶體空間、網路還有其它資源等等。

我們可以在上面安裝其它 Linux Distribution 的環境,看看 /usr/share/lxc/templates 這個目錄底下有支援 Arch, Debian, Fedora, openSUSE, Ubuntu 還有其它。

lxc 也可以用來建立雲端作業環境,又或者用來玩 Steam(TM) 上面的遊戲。

參考 LXC LXC 這兩份線上文件也許是個不錯的入門起點。

在 Ubuntu 上面使用只要安裝 lxc 這個軟體套件就可以了。

sudo apt-get install lxc

如果是在 Ubuntu 12.04 上面,建議使用 precise-backports 裡面的 lxc 效果會比較好,如果想要在 x86 上面建立 arm 的虛擬環境就要借助安裝使用 qemu-user-static 這個軟體套件。

sudo apt-get install qemu-user-static

在使用 lxc 之前可以先執行 `lxc-checkconfig` 來檢查環境。

然後就可以開始建立一個 lxc 的實體了,例如想要建立 Ubuntu 12.04 i386 就可以執行以下指令。

sudo lxc-create -t ubuntu -n myLXC -- -r precise -a i386

當中的 precise 可以換成 quantal/raring/saucy/... 而 i386 則可以換成 amd64/armel/armhf/... 然後 myLXC 則是這個 lxc 實體的名稱。

等待一段時間後,等到它建立完成就可以執行以下指令在背景啟動它。

sudo lxc-start -n myLXC -d

如果想要登入就可以執行:

sudo lxc-console -n myLXC

如果想要離開就要使用特殊的指令組合 <Ctrl+a q>

`sudo lxc-list`
可以看到每個 lxc 的情況。
`sudo lxc-stop -n myLXC`
停止 myLXC 這個 lxc 實體。
`sudo lxc-destroy -n myLXC`
刪除 myLXC 這個 lxc 實體。
`sudo lxc-start-ephemeral -o myLXC -d`
從 myLXC 建立並啟動一個暫時用完即丟的 lxc 實體

大概就是這樣。:-)

P.S. 執行 `sudo SUITE=sid MIRROR=http://ftp.tw.debian.org/debian/ lxc-create -t debian -n sid` 可以用來建立一個 Debian sid 的環境。

2013年8月26日 星期一

使用 git-buildpackage 維護原本就是使用 Git 維護的上游軟體的 Debian package

首先是將上游軟體的原始碼庫抓回來。

git clone https://github.com/fourdollars/x11-touchscreen-calibrator.git

然後是進到該原始碼目錄底下匯入已經釋出的 tarball

git-import-orig --upstream-vcs-tag=0.0 --upstream-branch=master --pristine-tar ../x11-touchscreen-calibrator_0.0.orig.tar.xz

上面這個指令會建立一個 commit 將 tarball 的內容 import 進去,並且建立一個 upstream/0.0 的 tag,只不過 master 也會指過去,所以再執行以下的指令倒回。

git reset --hard HEAD^

接下來是開始製作 Debian package 的部份,先建立一個 debian 的分支。

git checkout -b debian

然後在將 debian/ 這個目錄所需要的檔案都準備好,最後再 commit,然後就可以使用下面的指令來產生 Debian source package。

git-buildpackage --git-pristine-tar --git-debian-branch=debian -S --lintian-opts --profile debian

上面指令中的 `--lintian-opts --profile debian` 是在 Ubuntu 上面才需要加入的,如果在 Debian 裡面應該不需要使用。

另外,在還沒有完全準備好 debian/ 底下的檔案之前,也可以加入使用 `--git-ignore-new` 先試試看產生出來的 Debian source package 的品質如何,再決定要不要 commit。

等到這個 Debian package 已經成功被放進 Debian 官方套件庫裡面,就可以執行以下指令建立 debian/0.0-1 的 tag。

git-buildpackage --git-tag --git-pristine-tar --git-debian-branch=debian -S --lintian-opts --profile debian

最後就可以執行

git push --tags
將所有的 commit 跟 tag 都送回原本的 Git Repo 裡面。

參考文件: