up_the_ironsan active channel is a happy channel [01:15]
nestahehe [01:16]
up_the_ironsmercutio: urxvt +1
phlux: nice screenshot
jbergstroemup_the_irons: what kind of hw monitoring is on arp and what's on the client?
sorry - meant to say that this is regarding a dedicated server
up_the_irons? [01:40]
jbergstroemup_the_irons: well, if a disk dies for instance [01:40]
up_the_ironsah [01:40]
jbergstroemor a nic, or one of the two psu's [01:40]
up_the_ironswe have a nagios plugin for the disks
nic is not monitored (we encourage both nic's to be used in case one dies)
that Source Code Pro font looks nice
jbergstroemso, all the client should care about is software? good to know
will most likely go to dedicated in june. What would a 128G ssd cost me/mo?
up_the_ironsso the 128GB SSDs are the same price as 1TB SATA [01:45]
jbergstroemok, $20/mo then. sounds good [01:45]
up_the_irons(haven't updated the website yet, but that will be the official pricing)
jbergstroemintel 7xx series? [01:46]
up_the_ironsdepends on price, u have a link for one you like?
i was looking at these: http://www.newegg.com/Product/Product.aspx?Item=N82E16820227726
damn, missed the sale... they were $89 a few days ago
jbergstroemi'm going to use mine for cache, so one of those msata things woudl work just as well for me. not sure there's supermicro boards for "enterprise" with those features just yet
(referring to these: http://www.newegg.com/Product/Product.aspx?Item=N82E16820167040)

well, doesn't matter much tbh. if you have something that works, lets go with that.
up_the_ironsok cool
what is the msata thing? :)
oh,, that link...
where the heck does that thing plug in? some PCI slot?? ;)
mercutiothey have a special slot for them normally i think [02:01]
up_the_ironscool [02:02]
mercutio$89 seems insanely cheap for a ssd
i wondered if US pricing was diff than NZ pricing by that much
but newegg doesn't seem to have anything like that pricing normally, maybe they were getting rid of old stock
actually last i knew msata pricing was attractive for really small sizes, 20gb, 30gb etc
hmm corsair force is cheap
i have no idea what they're like
oh it's refurbished
nesta$20/mo for a dedi ?
did I read that right
mercutionesta: for a disk for a dedicated i think :) [02:05]
nestao lol
nesta goes back to observing
jbergstroemup_the_irons: ivy bridege has a designted thing for cache ssd's [02:05]
mercutioheh ocz has more reburshied than other people [02:05]
up_the_ironsjbergstroem: ah [02:06]
jbergstroemup_the_irons: talk about expanding to server boards as well, haven't seen it yet [02:07]
mercutiojber: can't hotswap i imagine
they need little msata slots on the front or something
jbergstroemup_the_irons: called SRT or something. basically helps you to create a transparent drive on semi-hw raid plus one cache ssd [02:07]
mercutiojber: only on windows isn't it? [02:08]
jbergstroemmercutio: no, i think its hardware based. i tried booting os x on one which worked but i didn't really need it so i went for a single ssd instead [02:08]
mercutiojber: oh, the help i meant [02:08]
jbergstroemcan't say i trust it 100% [02:08]
mercutioit may passtrhough drive normally too [02:09]
jbergstroemmercutio: ah, yeah probably. there's a lot of software/drivers built around it [02:09]
mercutioit's evolving [02:09]
jbergstroemmercutio: actually, os x has "fusion drive" nowadays too. something similar. http://rochetechnology.com/quick-hackintosh-tip-create-a-fusion-drive/ [02:09]
mercutioi'd rather see flash-based-write-cache controllers bulit into motherboards
with passthrough disks rather than hw raid
jbergstroemmercutio: yeah. for sure. plus a small battery [02:10]
mercutioor capacitor
the idea about having flash is that you only need enough charge to write the memory contents to flash
and then the battery doesn't have to last forever
up_the_ironsjbergstroem: ah cool [02:12]
mercutiohmm amazon seem cheaper than newegg for ssd's
i was thinking of trying to buy one from the US before if it would be cheaper...
still more than $89 though
jbergstroemdaym newegg for not shipping to aus/nz :( [02:14]
mercutiothey do
jbergstroemthrough third party ? [02:15]
mercutiowell you can get delivery addresses in the US
that then send to you
they repackage things now
to keep prices down
cos some places use huge boxes etc :/
well nz has an easy to use service that isn't the cheapest
btu there are also international onces
it's still probably $10 to $20 for delivery even for something small like a ssd
jbergstroemurl? [02:17]
i've never used any of thse'
jbergstroemok thanks [02:28]
mercutioare you in au? [02:28]
jbergstroemyeah [02:29]
mercutiothere's prob something local there
i assume demand is similar there
jbergstroemlast time i compared, it basically added up comparing to local companies. preferred giving them my monnies instead [02:29]
mercutiosomeone on local forum said shipito.com was expensive
you can easily pay > $200 USD for heavy things like servers
on various shipping things
but small things like ram/ssds/etc is where it probably could make more diff
although servers seem to cost a lot more in nz and au than the US
jbergstroemeverything is more expensive :( [02:38]
software is too :/
even if downloading over the internet
jbergstroembtw, is it advised to run your own ntpd (i still do) even if you have a linux vm and run the kvm-clock tsc?
i guess it boils down to if the host runs ntpd or not?
mercutioi don't think running openntpd locally should be a problem
but i have no idea if it's necessary or not
you could compare running it versus not, but ram usage isn't that high
jbergstroemi compared at least 6 months ago, and localtime had drifted - so i installed openntpd (and nowadays run busybox-ntpd); but still, running ntpd if host already does is pointless.
(assuming you run kvm-clock)
mercutiowhat's kvm-clock? [02:59]
jbergstroemits a driver for hte linux clock source
back in the days, people switched from the rc to a tsc from processors since it gave you a higher accuracy. kvm-clock is a way of getting hte host clock so the os doesn't have to keep track of this themselves
from the rtc, sorry
mercutiohmm i wonder what openbsd does
i still don't quite understand what hpet does
but it seems hpet is the normal timer these days for modern os's?
jbergstroemhpet is hardware timing, introduced in newer mobo's, replacing rtc
yep, its very reliable
but you can never avoid drift if you don't rely on ntp/clock protocols
pertty sure openbsd has support for both hpet and tsc
don't think it picks up kvm clock though. i just upgraded my 5.2 to 5.3 and still get unknown clock source
yeh old kvm version on most nodes
up_the_irons: you around?
heavysixer has joined #arpnetworks
ChanServ sets mode: +o heavysixer
brycecup_the_irons: To answer your question - mSATA stuff plugs into mini PCIe slots, but it's not strictly PCIe and the slot has to support mSATA. It's found inside most laptops nowadays, and I think I've seen it on some recent Intel desktop motherboards. Generally, mSATA is what laptops use for SSDs given the chance (Apple and Chromebooks to name a couple) since it's smaller and lighter and you could probably still fit an old-fashioned hard ...
... drive too.
And I can vouch for the expense of shipping servers to NZ - My company's stuff is usually about 15lbs at shipping and costs the customer $300-$400USD for shipping (FedEx), plus duties. International shipping just sucks.
up_the_irons: btw I have a handful of those OCZ Agility3 120GB SSDs and so far they've all been fantastic! Been running them for about 18mos now and still going strong, and fast. Using them from everything - cache and log drives in ZFS pools, raid1 on my desktop (good lord the speed!), in the missus' gaming machine, and in most of my laptops.
Can't vouch for any of there more recent stuff (I know they changed controllers in the Agility 4, trading IOPS for throughput), but I'm happy.
sean_if anyone uses openbsd… don't upgrade to 5.3 on arpnetwork vps' … you won't have a good time. [12:29]
What's the problem?
aslrI use OpenBSD 5.3 on ArpNetworks and it's just fine? [12:30]
CaZeDid you disable mpbios? [12:31]
sean_hmm… em0 just doesn't want to work.
watchdog timeouts everywhere
if i can try to intercept the boot loader i'm going to try mpbios.
CaZeI've had to disable mpbios since forever.
I don't know how you've been getting along without doing it.
sean_(using console over ssh)
kvm page said it wasn't required anymore
this is maddening. :P
CaZeDo you still have an old kernel that you can boot? [12:35]
sean_CaZe: do you use the vnc console interface? doesn't seem very useful. [12:35]
CaZeI use the console server.
I added a longer timeout to my boot script though.
sean_sean_ CaZe: how did you do that? [12:38]
CaZeCaZe sean_: echo "set timesout 60" >> /etc/boot.conf
But I think I was able to still make it in at the default timeout, if you time it right.
sean_it seems the console doesn't connect fast enough. [12:43]
VNC should work though.
sean_it swaps to com0
(sry after)
CaZeset tty com0 [12:44]
sean_if i power off from a console session the vnc session disconnects and it doesn't reconnect fast enough at power on. [12:44]
CaZeCan't you send a reboot through VNC? [12:44]
sean_just waiting now for config command to respond.
not sure.
CaZeWell, do you have an old kernel you can boot? [12:45]
sean_u using 32 bit or 64bit kernel?
I'm using an old snpashot though.
sean_ah. just tried upgrade to release. [12:47]
CaZeWell, try to get the timing right on the bootloader.
Or, just boot off the cd image.
(assuming you have an openbsd installer cd loaded)
Doesn't really matter which version installer.
sean_yeah not sure. how can do you dhtat without access to the boo loader? [12:48]
CaZeYou have to get in on VNC. [12:51]
sean_k. [12:51]
CaZeJust have your vnc client ready to login, with you login and password already typed in.
And when you boot your VM from the console server, wait like five seconds before clicking connect on VNC.
Maybe less.
Maybe not at all, I dunno.
Play around with it.
sean_mpbios seemed to do the trick… lying KVM bastards
blargh. didn't fix icmp issue from 5.2
CaZeWhat ICMP issue? [12:56]
sean_with pf enabled icmp drops, every 1 of 25 echo requests are returned.
(that's with an empty pf.conf)
disable pf.. and it works just fine.
one of these days i'm going to buy another vps to collect the info for a sendbug.
i've had this VPS since 4.7 so could be infrastructure related as well (ie. old KVM, old VM template etc.)
CaZe: thank or the boot.conf idea. definitely popped that in.
sean_ CaZe: does your vps have the same pf behaviour with 5.3?
(using amd64 kernel)
(non mp)
CaZeWhat is it again? It drops pings? [13:07]
Set pf debug logging… log fills with: /bsd: pf: icmp type 8 in wrong direction (1): ICMP out wire:
this happens from all over the internet so i'm pretty sure it's not just my devices. :P
CaZeWell, my snapshot is from August.
100 packets transmitted, 5 packets received, 95.0% packet loss
sean_sean_ to me I assume? :) [13:11]
CaZeYes. [13:11]
sean_sean_ it's just ICMP.. all other IP traffic is perfectly fine which makes sense. [13:11]
phluxwho was complaining that i3 is 700kb yesterday?
because it's not true
ah, aslr
aslrHow is it not true? I du -sh'd the src directory, phlux. [14:37]
phluxmaintainer claims it's mainly documentation that you're looking at
says the source is not 700kb
mercutioi3? ion3? [16:10]
mercutiois it a fork of ion? [16:18]
brycecDoesn't look like it http://en.wikipedia.org/wiki/I3_(window_manager) [16:19]
mercutiothey prob should have used a more differnt name then [16:19]
brycecmay be in tribute to it? *shrug*
There was a lot of excitement over I3 a few months back
i been using ion for over 10 years
so i suppose i'm not jumping at the chance to try other wm's
unless can see benefit
tried them all orig :/
brycecbenefit: Not writing config in LUA [16:22]
mercutioi don't do shit all lua, my config is simple
i don't even write a config, it writes it for me
but in the past i've changed some key bindings around
to execute different stuff
and that may or may not have involved lua
it is good to see more people getting into tiling window managers though
brycecbrycec sticks to using Awesome [16:23]
mercutioi found awesome meant constantly trying to rotate through different layouts
i prefer to just set layout myself
but i like they're using the new X stuff
brycecAwesome isn't perfect :/ But I've made it work for me. Besides there's only a couple layouts I use consistently
Float, one of the tiling ones, and fullscreen
mercutioi am quite enjoying urxvt
only problem is i still haven't got the best colour scheme
it actually feels faster than gnome-terminal
and doesn't flicker
staticsafeflicker? [16:39]
mercutioxterm flickers [16:39]
staticsafeo [16:39]
mercutiowhen you scroll
gnome-terminal flickers white when you make new terminal
urxvt does neither of those
roxterm also goes white when you make new terminal
(i use dark background)
URxvt*background: #000229
have that as a background currently, it's like very dark blue
i suppose now my main issue is that ssh connectinos to remote hosts can be too slow to connect
i'm half tempted to use multiplexing which can speed it up, but can also mean they all die at once
it's partially cpu speed partially latency partially os
openbsd connects quicker than linux by about 2x for close hosts
staticsafeO_o [16:42]
mercutio174 msce versus 279 msec, and the openbsd host is slower cpu
with faster connect
that's for ~10 msec away
it's 4.1 seconds to connect to uk host
brycec#kiwiproblems [16:43]
mercutioheh [16:43]
staticsafeyep [16:44]
mercutioi dunno maybe something needs caching [16:44]
staticsafeDNS is the only thing you can cache here [16:44]
mercutioi remember a while back there was a https optimisation that chrome started doing that reduced one rtt
but broke some sites
dns is anycast should be fast
it seems now days anycast is the main way to speed up dns
but hardly anything seems to do anycast on reverse lookups
and lots of dodgy sites have slow dns
like if you do lookups on random ip's that connect to you uninvited
staticsafethat might be where its slowing down, openssh does reverse lookups on connecting IPs [16:45]
mercutioyeah cache at remote end
but reverse dns isn't anycast
i wonder what ttl it has
staticsafe2607:5300:60:e3a::1 - do a reverse on that, how long does that take you? [16:47]
mercutiohost 2607:5300:60:e3a::1 0.00s user 0.00s system 1% cpu 0.633 total
i'll try from somewehre else too
huge diff
both in nz
actually that may have been nameservers with 86400 ttl
i'm ahving problems finding the ttl using dig
staticsafethat particular PTR has 1800 TTL [16:49]
try timing a host lookup on
brycechost 2607:5300:60:e3a::1 0.00s user 0.00s system 1% cpu 0.322 total [16:50]
staticsafe;; Query time: 633 msec - resolving via local recursor [16:50]
brycechost 0.00s user 0.00s system 1% cpu 0.462 total [16:50]
bryce has faster dns :)
brycec:D [16:50]
mercutiothat's actually interesting
static got same query time for my reverse lookup, as i got for his reverse lookup
brycec(dnsmasq on my router, spread between Google's public DNS servers v4 and v6, as well has HE's DNS servers v4 and v6) [16:51]
staticsafe;; Query time: 0 msec - now its in my cache :) [16:51]
mercutiobryce: using all-servers? [16:51]
bryceclol staticsafe [16:51]
staticsafeI run my own DNS recursors [16:51]
mercutioahh i used to do that [16:51]
staticsafebecause why not :) [16:51]
mercutiousing unbound? [16:51]
staticsafeBIND because i do authoritative as well [16:51]
brycecmercutio: yes, all-servers [16:52]
mercutioeww :/
brycec: that's what i shifted to doing at home
staticsafe*shrug* I've taken a liking to BIND [16:52]
mercutioi wonder why that other server i tried took 1.7 seconds
probably didn't have cache of some steps before hand
cold caches
mercutiothat's one of the reasons i don't run my own dns resolver [16:53]
staticsafeI find that pointing my home network towards my 2 resolvers builds up a nice cache :) [16:54]
mercutioi wonder how many qps before it makes sense? 20? 100? 200 ?
i benchmarked heaps of dns resolvers before
then found that the way i was benchmarking didn't really measure real world performance
it's a kind of complex issue
staticsafehttp://stats.asininetech.com/asininetech.com/uriel.asininetech.com/bind9.html - this one is also my mail server, so lots of queries [16:54]
mercutiolike no-one in nz probably looks up domains in ethiopia
so everyone will have slow lookups to there
staticsafeyes [16:55]
mercutiobut that doesn't matter
so if you randomly pick domain names
you'll probably find some international focused dns stuff will be faster than local stuff
but if you pick real usage domains, closer will be better
like facebook has a high chance of being cached
staticsafeI originally started doing my own DNS because my ISP's one was so shit [16:56]
mercutiodo you run web stats?
i see lots of spikes
staticsafeweb stats? [16:56]
mercutiolike looking up heaps of reverses
using webalyser or such
staticsafehttp://mx1.stats.staticsafe.ca/ [16:57]
mercutioin a cron job [16:57]
staticsafenope [16:57]
i wonder what the spikes are then
staticsafemore e-mail [16:57]
mercutioahh pflogsumm
wow you hardly have any rejections
my rejection rather is like 10x my received or something
heh what'st htat SASL LOGIn thing
someone trying to brute force you?
staticsafeyea noticed
not unusual
mercutiooh actually my rejection rate went down a lot
still higher than yours
staticsafeas you can see, its my mailing list e-mail, so not a lot of spam [17:00]
mercutiodate received delivered deferred bounced rejected
Apr 28 2013 957 675 109 7 9105
Apr 29 2013 1611 1116 199 20 5606
Apr 30 2013 3762 2557 175 1 1580
staticsafeactually 0 spam from non-list sources [17:01]
mercutioit's kind of ireregular it seems [17:01]
staticsafemy reject count is unusual, its actually just greylisting [17:02]
i use zen.spamhaus.org
staticsafewhich im thinking of disabling [17:02]
mercutioi don't greylist anymore
it's too annoying when you're waiting for a mail
staticsafeyea i use postscreen with zen.spamhaus.org and some other black lists [17:02]
mercutiooh so it just doesn't reach postfix [17:02]
postscreen is <3
mercutiobut yeah, i dunno why apr 28 was so bad
and apr30 good
it won't do much harm, it's just one of those things i occassionally notice
i imagine peoelpe without zen.spamhaus.org get a lot more spam?
zen kills a lot of stuff
mercutioit's annoying how wasteful of resources mailing lists are
but as ssd's get cheaper etc i suppose people are likely to care less and less
staticsafeamavisd-new takes care of the rest [17:05]
mercutioi'm using amavis too
and dkimproxy
staticsafeI use opendkim for DKIM checking and signing [17:06]
mercutioand dcc, and razor, and pyzor etc.
i used to use dspam
staticsafeI was thinking of dspam but meh [17:06]
mercutioi'm actually still getting some phishing coming through
i dunno dspam started going wrong
and amavis can't feed it anymore
it expires tokens
so if you stop feeding it stuff it goes weird
i think that was it
staticsafeyea possibly [17:07]
mercutioit's obvious phishing stuff though
i dunno how to block it easily though
57444 N May 04 Kiwibank ( 254) Kiwibank internet banking customer support
51094 O Mar 11 ASB Bank ( 73) Hello ASB Customer
57338 O May 02 ASB Bank Limite ( 132) Irregular Activity On Your Account.
staticsafei actually surprisingly little spam on even my main accounts
mercutiobank phishing seems popular
and fedex
and paypal
i'm not even using kiwibank or asb bank though
the real problem is that lots of bank email looks like spam too
with html and crap
staticsafeheh [17:10]
mercutiosent from weird remote mail servers [17:10]
staticsafemy bank sends me 1 e-mail per month [17:10]
mercutiohmm so does mine
saying i should pay my credit card
staticsafeheh [17:11]
mercutioit's even using domainkeys
and not coming from a dodgy looking server
staticsafeyea banks usually do
I know Paypal uses it for sure
mercutiolots don't use spf still
my one is now at least
but it's ~all
oh wow way more are since i last checked
staticsafei do -all on most of my domains [17:12]
mercutiohey the other two are using -all
why can't my bank!
wow only one bank i checked so far has no spf
the all the rest have -all except my bank
staticsafehah [17:13]
mercutiook 2 don't have
anz and bnz
hangon maybe anz isn't a bank
staticsaferbc.com. 300 IN TXT "v=spf1 mx ip4: ip4: -all" [17:13]
mercutiooh it is it just sucks at google [17:13]
staticsafe:) [17:13]
mercutiothat your bank? nice [17:14]
staticsafeyea [17:14]
mercutiocarribbean? [17:14]
staticsafenope, royal bank of canada [17:14]
mercutioyeh it asked me what country i am in [17:14]
staticsafethey are international yea [17:15]
mercutiodo tehy use windows or linux? [17:15]
staticsafeno idea [17:15]
mercutiocurk tells me that they don't tell me what web server they run
and all their pages say .html :/
staticsafethe online banking stuff is a CGI app [17:16]
so probably unix
maybe solaris or aix or something
i'm always hesitant when i see aspx on a bank
maybe shouldn't worry so much
staticsafeheh [17:19]
mercutiothey may write their passwords down on paper and throw them in the trash for all i know
actually i haven't heard much in the way of bank security issues
ok i better go to supermarket before storm starts
ideas1New to bsd... which bsd is recommended to be used a webserver openbsd or freebsd? [17:50]
easymacEither one.
FreeBSD is probably easier for a newbie to get started though.
ideas1Damn a friend just bought me a absolute openbsd 2nd edition... [17:51]
easymacThen just use that.
It's not *that* different.
ideas1But i got the impression openbsd was more for routing [17:52]
easymacIt does routing very well, but it does serving very well too
FreeBSD is meant more for serving, though, yes.
ideas1Im a little confused coming from linux. [17:55]
easymacLinux is retarded. [17:55]
ideas1hahahha ouch i have like 6 servers at work alll rhel [17:56]
easymacI'm sorry that you pay for the ability to use free software.
ideas1lol the hostility [17:56]
easymacI gotta go eat dinner :) Good luck. FYI #FreeBSDHelp on EFNet is good.
I'm kidding around, but I do hate Linux.
ideas1ok cool thank you [17:57]
ideas1thank you [17:57]
phluxso I did some more customizing to i3's bar: http://www.phluxbox.com/img/air8ai.png
For the wireless network, it colors the essid based on the connection quality, and it does the same for battery percentage based on where it's at :)
but that's kind of cool
your color scheme reeminds me of solarized
hmmm where it says mpd arist song name do you find it's often difficult with long artists / song names
or does it up more space to the left
awyeahWell, I'm doing it. I'm going back to hosting my own e-mail. Lord help me. [19:08]
dkim, spf, domainkeys, amavis, dspam, spamassassin
so many complications :)
good luck
Well... I'm just getting dspam set up now, looks like it includes vlamav.
I do need to get the SPF records in
mercutioi use clamav from amavisd-new
i don't find clamav hits much
but hitting anything is better than nothing
awyeahtrue [19:10]
phluxmercutio: it uses up more space to the left
mercutio: it just depends on how long the artist/song is. If you don't want it to do that, though, you can use ${scroll 15 $mpd_artist - $mpd_title}
but I wasn't really a fan of how it scrolled
mercutiooh cool [19:47]
.... (idle for 19mn)
awyeahYeah. dspam is sucky to set up. [23:42]

