i wonder if he was doing a survey mornin' hrmph. just upgraded my VPS to freebsd 8.1 \o/ went smooth as it could, i love freebsd-update :) zfs gpt boot? nope i'm not crazy ahh, simpler. :) :) i need things to 'just work' me too. but I like snapshots and rollbacks oh yeah, zfs is nice... i'm just not happy to use it in production *just* yet :q! lol So How would I secure my fresh, new freebsd installation? If I don't have enough space to jail my users on arpnetworks? should have enough space :-) yeah - even the smallest plans can run a jail they nullmount back to your existing /bin etc or rather a bin built for all jails dxtr: http://erdgeist.org/arts/software/ezjail/ ezjail rocks +1 :D dxtr: Get rid of the users Then shutdown -h now heh... I'm stuck on the guru level of he.net ipv6 certification turns out, using he.net as a secondary for my domain is actually stopping me from getting he.net certification! ns1.he.net is ipv4 only (!!!) so my nameservers aren't all reachable from v6 "a clever trap they have laid, and I fell for it!" the handbook's method to construct jails is quite straightforward as well. ezjail just makes it way easier to manage afterwards, plus bringing up a new jail just takes a few seconds but yes, the handbook method is fine too if you're just after one or two standalone jails bob^^: i've done both and i find ezjail really saves on the drudgework agreed :) i'll give it a try then. :-) Is it safe to compile a new kernel with a new cnofiguration without first rebuilding world? It's the same version and everything. Just a different kernconf if it's the same version and nothing's been updated, you'll be fine Cool just don't let kernel and world get out of step... Bad Things (tm) will happen :) Hehe I don't need support for "USB Serial Devices", right? :P are you using USB Serial Devices? On the VPS? you never said it was for your vps :) i wouldn't think you'd need that, no I thought it was obvious, sorry :) :) Do I need any USB support for thinks to function? things* i'm not sure let me check on mine yeah :) i've not *noticed* any USB (apart from a usb mouse, but i don't need/use that nayway) I wanna disable as much as possible don't see anything in dmesg.boot that looks to use USB you're not going to save a huge amount by removing those sorts of things though imho these days i tend to run everything with GENERIC tbh hehe Just playing around :) hehe it's not quite the same as the old days where saving a couple of MBs made a huge difference when your box only had 16mb to start with :D Hehe yeah. I run GENERIC, but I change the name is all. I used to bother pulling modules on my *old* sparc machine, but now it's not worth it. exactly :) cedwards, i suppose you don't use freebsd-update, since you rename GENERIC to something else? i <3 freebsd-update so very much ziyourenxiang: I build everything. with ccache it really doesn't take long. On one machine I can do a kernel in <1m and world in <5m. i like freebsd-update, but i also want IPsec, so i can't run GENERIC... bummer... any suggestion for a user-space site-to-site VPN thingie? i know of openVPN. openvpn is superb, i can highly recommend it somehow it feels a bit "impure" to run TCP over SSL (assuming that's what openVPN does) not really ssl it has its own encryption and yes, I highly recommend openvpn as the best solution since it tunnels using UDP, not TCP tcp over tcp is troublesome ah, it uses UDP? didn't know that. ok, will give it a whirl. and you can use either layer 3 or layer 2 with layer 2, it's a bit fatter packets, but you can tunnel *anything* eseentially, your interface looks like a participant on the remote net i'm looking to tunnel something like zero MQ or one of those AMQP thingies among 2-3 servers. I really need to learn openvpn too. something on my (long) list of topics. the one thing that won't work is behind-NAT to behind-NAT the server has to have a public face the client can be behind-NAT though well.. behind NAT to behind NAT will work, with port forwarding it works fine providing you configure it correctly presuming you have a public IP too well yes there are some ISPs that never give you a public IP my advice there would be "it's NATs... all the way down!" move to an actual ISP at the moment my two servers are all arpnetworks VPS. at some point i expect to have one or more linux 64bit servers (to run GLASS). any of you guys run linux on arpnetworks? indeed. but there are some solutions (like hamachi) that don't require public IPs jus' sayin'. meh i'd hardly call hamachi a solution but whatever floats your boat well *I* would never use it either ziyourenxiang: i'm sure plenty of chaps use linux around here too :) openvpn works fine on linux as well - i've done freebsd > linux > windows with openvpn, no problems at all hmm, if all my machines are on arpnetworks maybe i might just use GRE for tunneling and rely on higher layers to provide security. GRE is tcp over tcp though, right? you'll have openvpn up and running in five minutes :) GRE is anything-over-ip indeed it is i've done some horrible things with GRE in my time :) but they work! ok, i'll try openvpn next. i've done GRE before too and know that it surely works. of course it works, and stop calling me shirley. :) heh feh, tcp tunnels. +1 openvpn well... i learned the hard way that binary system updates dont play well with zfs at this point. I ran across this issue: http://forums.freebsd.org/showthread.php?t=8958 (except the accepted fix doesnt want to work for me) Err Did console.cust.arpnetworks.com just go down? Oh no it didn't about how long does it take for a vps to be setup? usually under 24 hrs Cool. I'm excited :D It's pretty awesome, that's for sure. Except for me having to wipe mine and start over because im an idiot :P :o Thats not good. What happened? I rebuilt w/ ZFS, and apparently freebsd's binary system upgrades (to go to 8.1) dont play well with zfs http://forums.freebsd.org/showthread.php?t=8958 <--- that, except their fix doesnt work for me excuse the ignorance but what's different about ZFS? hell if i know... its supposed to be better :P was just about to read this: http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/filesystems-zfs.html not that ill understand a single word of it IPv6Freely: you should ask RandalSchwartz fink_: about my broken system or about zfs in general? yours humph... i dont know whats the deal with my vps, i connect w/ chicken of the vnc and it appears to connect but i get no window love that program doesn't seem to work with VirtualBox though virtualbox's vnc that is IPv6Freely: i like cotvnc too, but i've had better luck with jollysfastvnc w/arpnetworks IPv6Freely: I got that too earlier with tightvnc Just connect a couple of times hmmmm frustrating no luck :( fail there we go.. shut down the vps and booted. now i can get in RandalSchwartz: awake? :) booted into fixit... says to chroot into my installation, which should just be "chroot /zboot" right? zroot rather hehe you guys and your ZFS I don't understand why you love heart ache so much UFS rox lol@ufs zfs=future yeah well guess what it's present day :) the future is yet to come :P nesta: it's great, on a dedicated server, but to use it on a vps looks downright ridiculous to me yes DaCa DaCa: i'm using it now on root on an arp vps yea i think im just gonna build a standard install i dont think ill get anything out of it zfs snapshot management rules does ZFS just get installed to /root ? I am kinda confused about that what about multiple partitions there's a tutorial on the freebsd wiki no idea http://wiki.freebsd.org/RootOnZFS/GPTZFSBoot i just followed that yeah I saw it but it does not really makew it clear about multiple paritions unless I totally missed it hehe whihc is likely no clue. dxtr: how was the re-install? great success? nesta: Yeah. Been doing stuff for a couple of hours now ah okay, did you get all the seperate partitons okay? hmm now i cant even do a default install unable to find device node for /dev/ad0s1b in /dev! The creation of filesystems will be aborted IPv6Freely: the first time i followed that tutorial; the second time i did this: http://anonsvn.h3q.com/projects/freebsd-patches/browser/manageBE/create-zfsboot-gpt_livecd.sh that was with 8.0 release it was pretty awesome cool but that doesnt help me with either issue im having whats your issue? you can't do an install? just erase you disk man well first the zfs was broken, then i tried wiping and starting over and it wont let me how do i erase a disk? ive always just done that and partitions in sysinstall I think... im just going to cancel my account. sounds a bit hasty they provide you with a perfect working installation and i break it people decide to do all sorts] yeh you can easily fix :) apparently not are you booted to cd? i was well go back, why give up? now im at a boot: prompt the devil loves a trier i have no idea how to reboot from here log into your webpanel that Arp provides for you, IPv6Freely ok you can shut it down there and then boot it booting.. okay in the sysinstall main menu okay do a standard install when you go to the disk part don't do anything just shout me :) yeah im in that part okay you select the drive yeh? then it brings you to black screen yea the fdisk partition editor see the middle line? it has 'freebsd' on it press down arrow to get to it then press d then press a i have "unused, unknown, unknown, unknown, unused" ok just delete all basically go to all them and press d once k all unused. this is how i normally do it tell me when you done that k done press arrow back up to top then press a yep now i have ad0s1 freebsd cool go to that one and press s done press q k now choose yes for the bootmanager like the top option is fine ya done? k now what size is your hard drive 20GB i usually just do auto here too is that what you would like to do? sure why not you can carry on now as normal it should fdisk just fine if not then you got me :) yeh go with auto just auto and then q to get out auto and then q now i was gonna use "user" here since im gonna cvsup src anyway yeah sure jsut get to the fdisk hehe asking where to install from, i pick CD obviously yep okay, the final yes/no window. "last chance, are you sure?" YES :D same error as before lol wow okay ZFS really *is* evil hey IPv6Freely don't worry when up_the_irons is here he will reinstall for you np :) its part of the contract http://a.imageshack.us/img401/2599/screenshot20100804at102.png wowee thats a funny one alright *thumbs up* I am sure there is some sensical explanation okay, IPv6Freely .. ya got me. :) lol had zfs, zfs broke, tried to install normally, and failsauce. Thats the summary of my last two days :P I have thus far steared clear of it for I knew all of this lay before me :D I heeded the warning calls of others lost in the wilderness i made the mistake of trying to do a binary upgrade from 8.0 to 8.1, which apparently is broken if you use zfs ah yes I never binary upgrade id never done it before, i figured id try it I always upgrade via fresh source and build it its much more fun freebsd-update is boring imho me too, though i dont find it fun :P :P i didnt know binary upgrades even existed until a couple days ago ya gota make it fun hehe, dangerous kernel options etc.. ha. no. im not a tinkerer playing with MAC and ACL and ttoally breaking your shit i want it to just work like I did the other night lol i hate computers, i have zero interest aww come on thats not true clearly no really... if i ever had to do sysadmin shit id go nuts you have a FreeBSD vps most 'normal' people ]have NOidea what that is the only reason i got a vps is because the shell i have gets rebooted every night and therefore sucks for screen+irssi. rebooted every night? dang sometimes not but when i log in and do screen -r and it says no screen to be resumed... man does that ever piss me off but you don't care about computers :P i dont. i care about irc :P hahaha i want my irc and dont want to have to mess with shit to get it a shell is also super useful for testing my networks from the outside Hmm... but otherwise i hate computers. thats why i use a mac, because everything just works and i can spend my time doing my work rather than dicking with my OS Exactlt what is "cputime" in login.conf? I'm thinking it essentially says how long a proccess can run ("Use the cpu") IPv6Freely, whatever i want to do on my VPS, i try first on a vbox instance on my laptop... if nothing else i get familiar with the procedure and screens. oh ok, didn't see that bit where you say you don't do sysadmin :-) heh yea Next project: OpenVPN on my VPS. So I can have "local" network access to it. That's probably pretty easy. About to configure VPN today actually. Though, its a Juniper SSL VPN appliance, so slightly different :P heheh yeah. purpose-build. built. Although, JunOS is based on FreeBSD I think. sort of It runs on top of freebsd not really based on it heh... got an answer back from he.net about how to pass their test "remove ns1.he.net from your list" great. :) lol RandalSchwartz: want me to remove it from your rdns? i happen to be in my name server right now... Hey, you guys can help me :D Exactly what is "cputime" in login.conf? I'm thinking it essentially says how long a proccess can run ("Use the cpu") hiya up_the_irons :) man login.conf dxtr: I believe that is the case. but it's not how long it can run, it's how long it can RUN ie actually be on the cpu. man login.conf says it's a limit on cputime ;) right. it actually says "CPU USage Limit" :P which does indeed explain it a bit more up_the_irons - I think it only matters on the forward so lemme see if that fixes it yet RandalSchwartz: roger since I'll put it back in after I get my badge. :) any idea why a line like this won't work .. pass in quick log on $ext_if inet proto tcp from group { bakeneko } to $iplist port $ssh flags S/SA keep state heh seems to be an issue with the group part of the rule man page is useless and google is like 'what?' >_< =] hi BeBoo_ :))) long time hey nesta, how are ya super duper great to hear just waiting for my new vps to be created :D (impatiently) niiiice FreeBSD? lol of course excellent yeah, element talked me into getting my own VPS since i keep taking his over haha so i figured if i'm getting my own, i want a freebsd one, not linux how is he doing? hell yeh pretty good, we've both been busy busy his b'day is coming up anything exciting? ahhh we're goin to the shore not really exciting... bought a PS2 and a bunch of games we miss playing lol feh. even after removing ns1.he.net from stonehenge.com, it's still failing so much for your global redundancy ;) bah. Another day, another "rdns still not setup properly" classless delegation is hard :( woo hoo... I'm a Sage! http://ipv6.he.net/certification/cert-main.php ... http://ipv6.he.net/certification/scoresheet.php?pass_name=merlyn well done :) woohoo i dont know the systems side of ipv6 :( its easy :) well actually I retract that i guess ill find out lol but adding your ipv6 aliases for arp with FreeBSD .. is easy :) # ipv6 ipv6_enable=YES ipv6_defaultrouter="2607:f2f8:12c0::1" #ipv6_ifconfig_em0="2607:f2f8:12c0::2 prefixlen 48" #ipv6_ifconfig_em0_alias0="2607:f2f8:12c0::3 prefixlen 48" #ipv6_ifconfig_em0_alias1="2607:f2f8:12c0::4 prefixlen 48" just change to your info and put this in /etc/rc.conf ask me to configure OSPFv3 over point to multipoint frame relay... no problem. Configure on a desktop? completely lost. and reboot yea i had v6 on my vps, but no idea how to be able to actually use it... i wasnt able to resove hostnames to ipv6 addresses and such oh well you have to relegate your vps dns to some servers fo your choice then email up_the_irons the info the sets them you make the AAAA records and set the ipv6 as above for the addresses you set the AAAA Records for and ba da bing the=he yea im lost. i dont understand dns tell ya what me either but I can help you do this sir, make an account on afraid.org sign up with them don't have to pay just make an account heh URL blocked ? The URL that you are attempting to access is a potential security risk. Trend Micro Core Protection Module for Mac has blocked this URL in keeping with network security policy. damn corp laptops bhaha ignore that i cant o hmm do nm heh you can do it wiith he.net dont worry about it now I think make an account there on tunnelbroker.net? okay account created, now logged in sorry IPv6Freely https://dns.he.net/ thats the one prolly works across board your login anyway they do dns now fpr ipv6 free IPv6Freely: why do you have AV on your Mac? yep works BeBoo_: because they put it there so just give up_the_irons the info... ie. the he.net nameservers ip addresses "they"? BeBoo_: work ah interesting if its not there, i cant log into vpn yeh fucking wierd silly IT dept indeed Macs don't get virii :D hug yours too nesta do it now i7 yummyness nesta: so just ns1-5.he.net ? sure email him all them how many ever they have sorry to butt in but are you talking about dns mgmt for ipv6? ask him to set them for your ipv6 dns sure BeBoo_ reverse or just NS? no idrea idea* im just doing as im told haha wel I dunno how he.net works I am just trying to help :X Element was telling me that up_the_irons doesn't have any DNS manager that I either have to do it myself or have him forward to somewhere butr I know for sure oooh. I get a t-shirt for being a sage no worries. i think im gonna get food nah BeBoo_ you can make tons of subs of afraid.org or your own ones it's eeeeasssssy you can't do reverse on afraid.org, can you? i want reverse yeah you can doesnt help that i dont know how to config ipv4 dns either I do Anyone know how to place an upgrade order? Just email support@ or is there a form? I'm gonna have fun setting my vps up :D hehe I'm blanking, what's this character called: ~ Tilde? i thought thats what ` was I call that a back tick ^_^' http://en.wikipedia.org/wiki/Tilde yup, it's a tilde. thanks ^; ^^; woot! You mean \/\/|-|0()t don't you? ;) Sure. he.net will forward and reverse domains (including v6 records) for up to 25 domains, *and* they have 5 servers all over the world I'm moving everything away from afraid.org to he.net ... https://dns.he.net/ there ya go IPv6Freely ^ RandalSchwartz: whats the story with subdomaains on he.net ? do they have free one like on afraid.org ? that question doesn't make sense to me you handle your own subdomains using your own master files on afraid.orf there is tons of domains available for people to use everyone knows this and uses them subsequently you are probably aware :) yeah so am sasking of he.net has similar I do not imagine so oh - those crappy little vanity domains? I wouldn't trust anything I couldn't re-register right, those crappy lil vanity dmoains domains k for IRC its not such a big deal to me :) nesta: heh thanks, but i still have nfi about any of that :P time to learn! try http://lmgtfy.com/?q=dns+tutorial hehe heh bleh feh and finally meh try http://lmgtfy.com/?q="words+that+end+in+'eh'" lmgtfy is awesome oops, that broke bad-encoding fail :P up_the_irons: wake up :P what do you need from him? my vps to be rebuilt rebuilt? was it configured wrong? i broke it that happens. indeed but i cant even wipe it and start over anymore ah yes you can :) woot! I now have VPN tunnels from my apartment's router to my VPS, my parents' router to my VPS, and it's fully routed. So next time my mom can't do something on her computer, it's just a VNC click away ;) nice one awyeah that sounds cool i do that with my parents too :) it is *very* useful you will not regret the time spent setting it up awyeah ;D heh It wasn't so bad. Actually the hardest part was getting DD-WRT to listen to me. Because once I got it set up, the openvpn client kept dying, so I had to figure out how to make it restart properly. i've just started using dd-wrt here too not got it terminating my VPNs yet though they still arrive in to a freebsd box that sits underneath my router :) my aim is to get it all onto the dd-wrt though and save some power ;) Yeah, I don't use my BSD box here for any of that stuff either, it's just a local server well... it also handles my IPv6 tunnel to he. but no other internet routing. nesta: heh no i cant... we already tried :P yeah IPv6Freely - you can boot from a totally wiped disk just use the VNC console in fact, that's the first thing I do when I get a new VPS here. Wipe the disk entirely. just go to the VNC console, hit F12 during the bios boot, and select the DVD cant do that man i tried wiping it you know how it says "are you sure you want to do this?" right at the end of the sysinstall process? When i select YES, I get this: http://a.imageshack.us/img401/2599/screenshot20100804at102.png IPv6Freely: can't what? cant wipe it and start over. up_the_irons needs to fix it :P well as I said.. it can be fixed. :) yea, just needs somebody else to fix it :P I told you that earlier. ;) i know :) just use the fixit shell and wipe it diretly that's pretty easy oh? do tell :) try http://lmgtfy.com/?q=freebsd+fixit+shell well thats not very helpful sure it is you're gonna have to learn some day get into the fixit shell use gpart to reconfig the disk fixit shell is in the first menu of sysinstall there. everything you need, handed to you on a platter. happy? ill have to go find out what gpart is yes. "man gpart" So. Very. Hard. unable to find the file /etc/manpath.config I bet there's even some tutorials on THAT if you google or even sections of the handbook im sure there is none of which i will understand learn or hire. ill just have up_the_irons fix it pay with your time, or your money it's amazing. the plethora of info on the net. it's ... almost like it .. was designed for .. that? :P and I hope up_the_irons charges you consulting for that. that's Above And Beyond to restore my vps to a default image? he keeps the prices low because he can keep his labor to a minimum http://support.arpnetworks.com/faqs/vps/what-is-supported im aware up_the_irons: ive seen it. i will reset a vps back to "factory defaults" if requested up_the_irons: nesta said earlier that youd restore it he may give you this one as a freebie. :) im just going to cancel RandalSchwartz: factory default resets are actually free. I suppose, because it's just a button push or two. nobody has really come back and wanted it done ten times or anything, so i kinda don't care up_the_irons: can you just kill my account? IPv6Freely: if you want to cancel, send an email to support@arpnetworks.com with your vps uuid and it'll be taken care of thanks np it was worth a try, i guess vps isnt for me thanks anyway up_the_irons , you had good prices. i appreciate the help. IPv6Freely: no problem cancellation email sent never read that URL before. So, do you guys add custom contacts to nagios? Like, if i'd like to be notified if it loses ping? no, we don't, just staff gets the email gotcha "thy rod and thy staff, they comfort me" :) I suppose I should probably be monitoring it on my own anyway ;) oh, up_the_irons, that reminds me, I need to file a support ticket to validate my reverse DNS delegation I spent hours yesterday trying to figure it out and I Still don't have things working I kept telling you, paste it to me. :) i'm pretty confident that my nameserver response authoritatively to those requests awyeah: just so you know, I will show you what I have in my DNS for your delegation, and I will make any changes requested. But as for your setup, you're on your own :) Understood. I just want to validate what you have. I'm sure it's right, but I need to do it for piece of mind ;) yeah i understand Randal: I don't want to paste all that crap in the channel... try http://lmgtfy.com/?q=pastebin I love lmgtfy.com. I use that on my boss all the time. okay so I'm going to use the ipv4 stuff first, it's also not working... and it's easier to remember stuff. http://pastebin.com/a8YQUzen 2010 08 03 *001*??? I think your int is too big I've always used just "01" "02" "03" in that last piece RFC1912 section 2.2 that might be why your nameserver doesn't consider itself an authority :) did you check the errors when you reload or restart? awyeah? hmmm no errors. so, first, fix that though but i'll reduce the size of the serial. stand by. 10^11 > 2^31 :) there's a reason they chose YYYYMMDDss no one chose that though okay, reload you can use 1, 2, 3, 4 if you like ;) bob - see RFC referenced above it *is* the recommendation it's just easier to use YYYYMMDDxx to prevent the serial rolling back it's a recommendation not a requirement yup I didn't say requirement you can *choose* a recommendation :) pfft ;) SHOULD not MUST :) having 001 at the will probably cause it to roll over though i'd have thought... i can't imagine BIND liking that much ;) *at the end you know what... that may be why I see unrelated serial numbers in my logs. heh! yeah, 2^31 overflow hehe that'll do nasty things yup I found that within 30 seconds you could have had those 30 seconds yesterday :) but no, you didn't want to paste. :( next time, trust me. New Pairs Of Eyes Are Always Better true that :) especially if it's "spooky fail" well, let's see if it works now... it might not your slaves might need kicking because you've done weird serial things there *is* a technique to force a reset of serial no matter what it is but you didn't do that just now. :) and it takes 2 * TTL times to do it hopefully your TTL is small-ish I just forced my secondary to reload it, twisted4life allows that... stand by eww. twisted? I used them a long time ago moved to afraid about six months ago you realize twisted is in aspac space, right? I think I only use them for my reverse stuff apnic space Fine by me whatever the name is interesting - dig +nssearch 173.125.206.in-addr.arpa. still says arp's serving it hehehe Aug 4 15:25:28 excelsior named[43094]: zone 173.125.206.IN-ADDR.ARPA/IN: zone serial has gone backwards yeah - you're toasty for a while at least twisted has the same SOA okay. secondary's got it. so in this case, you're mostly there. that "dig" is odd though I'd get that fixed first looks like arp isn't delegating it yet if you do @206.125.173.26 on your queries, you do get authoritative responses. so the problem may be with arp $ dig +trace 206.125.173.26 ... 26.173.125.206.in-addr.arpa. 3600 IN CNAME 26.24-31.173.125.206.in-addr.arpa. 24-31.173.125.206.in-addr.arpa. 3600 IN NS 206.125.173.26. 24-31.173.125.206.in-addr.arpa. 3600 IN NS 202.157.182.142. ;; Received 125 bytes from 208.79.89.9#53(ns2.arpnetworks.com) in 0 ms does that look right? the only thing that makes me scratch my head is that the delegation NS are IPs, not hostnames not sure if that matters probably not anyway I need to eat dinner now, I gotta feed the beast i'll be back in a bit. up_the_irons: ping. up_the_irons: so I've got xmonad and I'm slowly making peace with the key bindings... except I can't make Evolution behave. I can shift it to its own workspace, but I can't identify the various windows. ie I want to have the main window fullscreened and everything else floating. ... except evolution doesn't give me any useful info for differentiating them :/ jdoe: it may be difficult to enumerate every window. you can find the window class names with 'xprop | grep WM_CLASS' and then click on the window. but if i were doing what you just described, i would tell xmonad to always float Evolution as a whole. I do this with GNUCash, b/c of all the little popup windows having to maximize it myself kinda bugs me though. but if that's the only way, shrug. I dunno, it's a little irritating that they consider preferences a dialog window, but not compose etc. jdoe: what is a dialog and what is not is somewhat a mystery to me. most of the time, it "works". if I maximize gnucash, it opens up maximzed again. evolution doesn't do the same? haven't tried floating it yet. I don't remember how it opened before. ... works nicely for pidgin though. stole that example xmonad.hs with split 6:1 screen for conversations + buddy list you have pidgin floated? oh i c shit, i need to look at that.. ;) no, pidgin isn't floated the screen is split 6:1, 6/7ths for the chat window, 1/7th for the buddy list. dedicated im workspace. the only stuff that's explicitly floated right now is firefox dialogs. oh i c what class is firefox dialogs? i never tried to float those.. they're actually dialogs. ah ... so if you're just floating those anyway, shrug. some end up floating, some don't. prefs doesn't, but most others do on OSX, the "green" button means only "toggle between two strange sizes" there's no "maximize" buton, and there should be. green is like "change the size somewhat, and move around so you have to find the green button again" RandalSchwartz: It's not really a maximize button, it's a "fit to content" button first size: the size that it is set to open up as, second size: the size that "optimally" fits the screen given what is around it Well - in practice, it never does what I want haha I want a maximize button then send an email to steve mobs err jobs ;p it's the "randomize this window for no damn reason" button most of the time up_the_irons: xprop will tell you which class RandalSchwartz: the maximize button varies depending on app. Firefox behaves as you'd expect. Safari tries to have maximize "fit all the user content and no bigger" nesta cat RandalSchwartz: I agree though, the behaviour of the default osx apps is... crazy. Completely unintuitive. up_the_irons: lol the best suggestion from #xmonad was a secondary haskell script that stringified the window icon and calling that from xmonad.hs. Terrifying.