<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=1810&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Meltdown and Spectre]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=1810</link>
		<description><![CDATA[The most recent posts in Meltdown and Spectre.]]></description>
		<lastBuildDate>Sun, 14 Jan 2018 00:31:09 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7151#p7151</link>
			<description><![CDATA[<div class="quotebox"><cite>fungus wrote:</cite><blockquote><div><div class="quotebox"><cite>golinux wrote:</cite><blockquote><div><p>@fungus . . . possibly PEBKAC?</p></div></blockquote></div><p>What is PEBKAC?</p></div></blockquote></div><p><a href="https://classic.startpage.com//do/search?&amp;query=PEBKAC" rel="nofollow">https://classic.startpage.com//do/search?&amp;query=PEBKAC</a></p>]]></description>
			<author><![CDATA[dummy@example.com (golinux)]]></author>
			<pubDate>Sun, 14 Jan 2018 00:31:09 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7151#p7151</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7150#p7150</link>
			<description><![CDATA[<div class="quotebox"><cite>golinux wrote:</cite><blockquote><div><p>@fungus . . . possibly PEBKAC?</p></div></blockquote></div><p>No, I am good with copy paste of instructions.&#160; I installed, updated, and upgraded the Refracta 9 and only added Openbox and a few LXDE pkgs.&#160; Then I tried installing OpenRC and I reported all the files that appeared uninstallable due to missing dependencies.&#160; Then I switched to ceres and they were there.&#160; So I installed OpenRC with ceres being open.&#160; It was the only way I could install OpenRC, then deleted sysv-rc and executed a command specified by the installation to reboot.&#160; All well.&#160; I repeated the whole procedure a 2nd time on a different machine.&#160; Same repositories.&#160; Same problem.<br />Some days later when I checked to what is installed and appears as local I thought with ceres disabled the pkg that came from there would seem as local with no counterpart in ascii.&#160; Wrong, they appeared as ascii pkgs.</p><p>If there is a pebkac problem it exists around the chair of the repository manager, or there is a MIM problem.<br />I urge you to check on the vegetable addresses of the reps and whether they correspond to the pkgmaster.&#160; I think something is messed up in there.</p>]]></description>
			<author><![CDATA[dummy@example.com (fungus)]]></author>
			<pubDate>Sun, 14 Jan 2018 00:26:31 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7150#p7150</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7127#p7127</link>
			<description><![CDATA[<p>@fungus . . . possibly PEBKAC?</p>]]></description>
			<author><![CDATA[dummy@example.com (golinux)]]></author>
			<pubDate>Fri, 12 Jan 2018 15:56:15 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7127#p7127</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7122#p7122</link>
			<description><![CDATA[<p>We still do not have an answer for the puzzling behavior when using the refracta9/ascii image I was not able to install OpenRC without using ceres repository, while when @fsmithred did the same it worked.</p><p>So there is some funky business going on with the amprolla3 repositories that make them misbehave from time to time.<br />At a later point when ceres was turned off and reupdated, the ceres packages should have been seen as &quot;local&quot; installations, but didn&#039;t, they appeared as native to ascii.&#160; So I assume that part of the repository is available and unavailable without producing an error to the user.</p>]]></description>
			<author><![CDATA[dummy@example.com (fungus)]]></author>
			<pubDate>Fri, 12 Jan 2018 10:41:30 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7122#p7122</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7118#p7118</link>
			<description><![CDATA[<div class="quotebox"><cite>greenjeans wrote:</cite><blockquote><div><p>Well I did the update just now, reloading Synaptic just showed the Linux image metapackage and one other as upgradable, not the kernel itself, but when I upgraded the two packages it installed the new kernel but in addition to the older kernel, so now have two. I assume the older can be deleted but just wondering why it didn&#039;t do it as an upgrade instead?</p></div></blockquote></div><p>If I understand what you&#039;re saying, I believe the same happened to me, and I&#039;d assume that&#039;s the desired behavior. I have the linux-image-amd64 meta package installed, and after adding the jessie-security source the upgrade pulled in linux-image-3.16.0-5-amd64 (with the new 3.16.51-3+deb8u1 version) in addition to my existing linux-image-3.16.0-4-amd64, making the newer the default in grub.</p><p>If the new kernel were to cause any issues, I&#039;d be able to boot to the old one using the arrow keys in the grub menu. Since it was OK, after rebooting, I uninstalled the old one, and did an update-grub. If that&#039;s what you&#039;re referring to I&#039;d expect that as a safeguard.</p>]]></description>
			<author><![CDATA[dummy@example.com (tlathm)]]></author>
			<pubDate>Thu, 11 Jan 2018 23:41:00 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7118#p7118</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7116#p7116</link>
			<description><![CDATA[<p>Well I did the update just now, reloading Synaptic just showed the Linux image metapackage and one other as upgradable, not the kernel itself, but when I upgraded the two packages it installed the new kernel but in addition to the older kernel, so now have two. I assume the older can be deleted but just wondering why it didn&#039;t do it as an upgrade instead?</p>]]></description>
			<author><![CDATA[dummy@example.com (greenjeans)]]></author>
			<pubDate>Thu, 11 Jan 2018 22:14:03 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7116#p7116</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7107#p7107</link>
			<description><![CDATA[<div class="quotebox"><cite>fungus wrote:</cite><blockquote><div><p>Those are all valid jessie repositories, pick and choose.&#160; Some may not have a contrib and non-free components.</p></div></blockquote></div><p>Thanks! I think the fact that I used the expert non-graphical install may be how I ended up with just the jessie source. I&#039;ve now added the security source. For our purposes I think that will do for now, as adding either the updates or the backports actually doesn&#039;t cause anything new to install anyway. Sorry for sending the thread a bit off topic too.</p>]]></description>
			<author><![CDATA[dummy@example.com (tlathm)]]></author>
			<pubDate>Thu, 11 Jan 2018 17:03:41 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7107#p7107</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7100#p7100</link>
			<description><![CDATA[<p>Those are all valid jessie repositories, pick and choose.&#160; Some may not have a contrib and non-free components.</p><div class="codebox"><pre><code>deb https://pkgmaster.devuan.org/merged/ jessie main contrib non-free
deb https://pkgmaster.devuan.org/merged/ jessie-backports main contrib non-free
deb https://pkgmaster.devuan.org/devuan/ jessie-proposed main contrib non-free
deb https://pkgmaster.devuan.org/devuan/ jessie-proposed-backports main contrib non-free
deb https://pkgmaster.devuan.org/devuan/ jessie-proposed-security main contrib non-free
deb https://pkgmaster.devuan.org/merged/ jessie-proposed-updates main contrib non-free
deb https://pkgmaster.devuan.org/merged/ jessie-security main contrib non-free
deb https://pkgmaster.devuan.org/merged/ jessie-updates main contrib non-free</code></pre></div><p><a href="https://sysdfree.wordpress.com/151" rel="nofollow">https://sysdfree.wordpress.com/151</a></p>]]></description>
			<author><![CDATA[dummy@example.com (fungus)]]></author>
			<pubDate>Thu, 11 Jan 2018 15:04:43 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7100#p7100</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7099#p7099</link>
			<description><![CDATA[<div class="quotebox"><cite>tlathm wrote:</cite><blockquote><div><p> I used the expert non-graphical install. I&#039;m wondering if there wasn&#039;t something in that that I selected incorrectly, though I don&#039;t recall that.</p></div></blockquote></div><p>Strange... I used the expert+graphical install, here&#039;s my &quot;uncommented&quot; sources.list</p><div class="codebox"><pre><code>deb http://it.mirror.devuan.org/merged/ jessie main non-free contrib 
deb http://it.mirror.devuan.org/merged/ jessie-security main contrib non-free 
deb http://it.mirror.devuan.org/merged/ jessie-updates main contrib non-free 

deb http://packages.devuan.org/devuan/ jessie-proposed main 
deb http://packages.devuan.org/merged/ jessie main contrib non-free </code></pre></div><p>I&#039;m not 100% sure but I think I never modified this by hand</p>]]></description>
			<author><![CDATA[dummy@example.com (joril)]]></author>
			<pubDate>Thu, 11 Jan 2018 14:56:46 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7099#p7099</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7089#p7089</link>
			<description><![CDATA[<div class="quotebox"><cite>joril wrote:</cite><blockquote><div><p>I have to say that I did find your sources.list quite strange-looking... ^__^; Are you sure no one &quot;tinkered&quot; with it?</p></div></blockquote></div><p>That wasn&#039;t the entire file, but it was in fact the only uncommented source in the file. The only change I made to the original one from the install was to comment out the line for the install CD ISO, as I was packaging it as a VM. The file also has the sources for the deb-src commented.</p><p>I can tell you for sure that jessie-security wasn&#039;t in there.</p><p>EDIT: Are backports and updates also supposed to be in there? Those were never in mine either. I used the expert non-graphical install. I&#039;m wondering if there wasn&#039;t something in that that I selected incorrectly, though I don&#039;t recall that.</p><p>Tom</p>]]></description>
			<author><![CDATA[dummy@example.com (tlathm)]]></author>
			<pubDate>Wed, 10 Jan 2018 20:51:30 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7089#p7089</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7086#p7086</link>
			<description><![CDATA[<div class="quotebox"><cite>tlathm wrote:</cite><blockquote><div><p>Is there some reason that the default sources.list from the install wouldn&#039;t include that by default? I can also see we were missing a number of updates because of that.</p></div></blockquote></div><p>I have to say that I did find your sources.list quite strange-looking... ^__^; Are you sure no one &quot;tinkered&quot; with it?</p>]]></description>
			<author><![CDATA[dummy@example.com (joril)]]></author>
			<pubDate>Wed, 10 Jan 2018 19:42:54 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7086#p7086</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7084#p7084</link>
			<description><![CDATA[<p>Here is some reading material</p><p>You should look up the three debian security alerts</p><p><a href="https://meltdownattack.com/" rel="nofollow">https://meltdownattack.com/</a><br /><a href="https://spectreattack.com/" rel="nofollow">https://spectreattack.com/</a><br /><a href="https://meltdownattack.com/meltdown.pdf" rel="nofollow">https://meltdownattack.com/meltdown.pdf</a><br /><a href="https://spectreattack.com/spectre.pdf" rel="nofollow">https://spectreattack.com/spectre.pdf</a></p><p><a href="https://security-tracker.debian.org/tracker/CVE-2017-5715" rel="nofollow">https://security-tracker.debian.org/tra … -2017-5715</a><br /><a href="https://security-tracker.debian.org/tracker/CVE-2017-5753" rel="nofollow">https://security-tracker.debian.org/tra … -2017-5753</a><br /><a href="https://security-tracker.debian.org/tracker/CVE-2017-5754" rel="nofollow">https://security-tracker.debian.org/tra … -2017-5754</a></p><p><a href="https://xenbits.xen.org/xsa/advisory-254.html" rel="nofollow">https://xenbits.xen.org/xsa/advisory-254.html</a><br /><a href="https://googleprojectzero.blogspot.co.uk/2018/01/reading-privileged-memory-with-side.html" rel="nofollow">https://googleprojectzero.blogspot.co.u … -side.html</a><br /><a href="http://blog.cyberus-technology.de/posts/2018-01-03-meltdown.html" rel="nofollow">http://blog.cyberus-technology.de/posts … tdown.html</a><br /><a href="https://01.org/security/advisories/intel-oss-10003" rel="nofollow">https://01.org/security/advisories/intel-oss-10003</a></p>]]></description>
			<author><![CDATA[dummy@example.com (fungus)]]></author>
			<pubDate>Wed, 10 Jan 2018 17:41:52 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7084#p7084</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7083#p7083</link>
			<description><![CDATA[<div class="quotebox"><cite>joril wrote:</cite><blockquote><div><p>It looks like you are missing jessie-security... Try adding this:</p><div class="codebox"><pre><code>deb http://us.mirror.devuan.org/merged/ jessie-security main non-free contrib</code></pre></div></div></blockquote></div><p>That doesn&#039;t do it either. What it gets me is even more confusing:</p><div class="codebox"><pre><code>apt list --upgradable | grep linux

WARNING: apt does not have a stable CLI interface yet. Use with caution in scripts.

linux-image-3.16.0-4-amd64/stable 3.16.51-2 amd64 [upgradable from: 3.16.43-2+deb8u2]
linux-image-amd64/jessie-security 3.16+63+deb8u1 amd64 [upgradable from: 3.16+63]</code></pre></div><p>I have no clue what that second one even is.</p><p>I do in fact have the linux-image-amd64 meta package installed. Nothing I do seems to find that linux-image-3.16.0-5-amd64, but rather newer versions of linux-image-3.16.0-4-amd64. Earlier I tried adding jessie-updates and that didn&#039;t work either and was even more confusing. That wanted to pull in a version of linux-image-3.16.0-4-amd64 that was 3.16.51-3, but NOT the 3.16.51-3+deb8u1 that actually has the fix. Insane.</p><p>My company is sort of really dying for this one. I hope someone has suggestions because this is getting more confusing with everything I try.</p><p>SOLVED: OK...Now I think I get it. That new version of the linux-image-amd64 meta package from jessie-security (3.16+63+deb8u1) actually ends up pulling in linux-image-3.16.0-5-amd64 with the 3.16.51-3+deb8u1 version.</p><p>That was confusing. Is there some reason that the default sources.list from the install wouldn&#039;t include that by default? I can also see we were missing a number of updates because of that.</p><p>Tom</p>]]></description>
			<author><![CDATA[dummy@example.com (tlathm)]]></author>
			<pubDate>Wed, 10 Jan 2018 17:14:54 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7083#p7083</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7082#p7082</link>
			<description><![CDATA[<p>It looks like you are missing jessie-security... Try adding this:</p><div class="codebox"><pre><code>deb http://us.mirror.devuan.org/merged/ jessie-security main non-free contrib</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (joril)]]></author>
			<pubDate>Wed, 10 Jan 2018 16:18:20 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7082#p7082</guid>
		</item>
		<item>
			<title><![CDATA[Re: Meltdown and Spectre]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=7080#p7080</link>
			<description><![CDATA[<div class="quotebox"><cite>joril wrote:</cite><blockquote><div><div class="quotebox"><cite>tlathm wrote:</cite><blockquote><div><p>Am I missing something here or am I maybe just hitting a mirror that hasn&#039;t synced yet or something?</p></div></blockquote></div><p>I assume you did run &quot;apt-get update&quot;, so I guess you are indeed using a mirror not updated yet...?</p></div></blockquote></div><p>Definitely. I just updated to 3.16.51-2 and now it tells me everything&#039;s up to date. Really seems odd. This is all I have enabled in /etc/apt/sources.list:</p><div class="codebox"><pre><code>deb http://us.mirror.devuan.org/merged/ jessie main non-free contrib</code></pre></div><p>Is that correct?</p><p>Tom</p>]]></description>
			<author><![CDATA[dummy@example.com (tlathm)]]></author>
			<pubDate>Wed, 10 Jan 2018 15:12:20 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=7080#p7080</guid>
		</item>
	</channel>
</rss>
