-
nahamu
has anyone seen an ancient SMB client stop being able to talk to our latest and seen "clnt <IP> no supported dialect" ?
-
richlowe
I think that might be on purpose when smb1 got turned off?
-
richlowe
but I have no idea for sure
-
nahamu
sounds legit.
-
richlowe
tsoome_, gwr, etc would know
-
nahamu
is it possible to turn smb1 back on, or is it just gone?
-
richlowe
jbk maybe
-
richlowe
I don't, sorry :\
-
nahamu
I'll go hunt for info on smb1 being turned down. thanks!
-
nahamu
-
fenix
→ FEATURE 14097: time to disable SMB1 by default (Closed) |
code.illumos.org/c/illumos-gate/+/1721
-
nahamu
Haha:
-
nahamu
> lease make sure a heads-up goes out when this commits. I know some home users enable SMB1 so their "smart" printer/scanner can send scans to the "network drive".
-
nahamu
It me.
-
nahamu
thanks for pointing me in the right direction, richlowe.
-
nahamu
... might be tricky to override on smartos...
-
nahamu
sharectl set -p min_protocol=1 smb
-
nahamu
can probably just do that on boot. gross, but should fix things for me for now.
-
nahamu
Seems to work. Need a better long-term solution...
-
nahamu
thanks again!
-
danmcd
nahamu: do you export from GZ?
-
danmcd
If you're sharing out of a zone that sharectl SHOULD stick.
-
tsoome_
nights are good, some things get sorted while I sleep:D
-
am11
gwr: just replied on gh 👋
-
nahamu
danmcd: yes, from gz. I need to learn to share from zones and reconfigure how everything is set up. Ideally only the single share for the printer should be set that way.
-
nahamu
and done. new zone created, just that one directory shared out with min_protocol=1.
-
jbk
nahamu: you may also want to use a delegated dataset for that (if not doing so already)
-
alanc
twitter.com/alanc/status/1806078511335223362 could be a privacy concern, for the small number of systems that have multiple users, with at least one who uses /usr/bin/spell
-
richlowe
oh, tmp files?
-
richlowe
I'm guessing the link isn't going to work in whatever this tty emacs chooses to open :)
-
alanc
not tmp. /var/adm/spellhist, where it records every word that isn't found in the dictionary from every user of /usr/bin/spell, along with their username & utmp info
-
jclulow
What a UNIX thing to do
-
richlowe
so the admin can amend the dictionary, of course
-
jclulow
or punish the poor of spelling
-
richlowe
an exciting covert channel, for the 80's
-
richlowe
as long as you never need to communicate a dictionary word
-
alanc
enabled by usr/src/pkg/manifests/SUNWcs.p5m listing mode=0666 for the spellhist file
-
richlowe
does it let you sneak things out of labels? :)
-
jclulow
steganography through cacography
-
richlowe
uuencode /top/secret | spell
-
jclulow
also just "dd if=/dev/urandom of=/var/adm/spellhist" jesus
-
alanc
only if your global zone admin has made the spellhist files in each labeled zone be hard links to each other (which I think is hard to do since normally each zone would have it's own filesystem)
-
jclulow
I assumed this was going to be some kind of setuid thing
-
jclulow
what an atrocious idea this was lol
-
alanc
sure, it's one of many ways that users can fill /var, especially if /var/tmp isn't a separate filesystem
-
jclulow
Definitely one I had no idea about though
-
jclulow
I feel like people can at least foresee /var/tmp as an avenue for shenanigans
-
richlowe
/var/tmp has been my enemy so many times
-
jclulow
/tmp too!
-
jclulow
Really users should just not have files
-
alanc
but yeah, our bug to fix it wasn't labeled "this is bad for privacy", but "we ship unmonitored, unrotated word-writable file that few people know about"
-
alanc
jclulow: just need to copy the systemd feature to delete /home then
-
jclulow
ha
-
alanc
(which admittedly makes sense for building temporary, throw-away container images, despite people hitting it on their long-lived Linux laptop installations)
-
richlowe
and I guess they don't have a giant home directory server to ever prompt them to worry about someone typing it down the wrong pipe.
-
jclulow
I think one of the core issues with the systemd folks is that their focus wanders (this week it's lets be a good laptop, next week it's let's replace all container platforms) and they only have one giant pile of confusingly named and split up programs and libraries in which to do it all
-
jclulow
Also they're abrasive and don't listen to people, I guess, is probably up there :P
-
jclulow
But other than that, Mrs Lincoln
-
alanc
they desperately want to have a unified kernel+userspace like illumos or BSD, but Linux doesn't do that, so systemd becomes the dumping ground for all the userspace stuff anyone wants to do
-
jclulow
Yeah
-
richlowe
I haven't managed to keep up with what's going on, I'm convinced booting userland is something everyone will always hate though, like issue tracking.
-
jclulow
richlowe: It isn't really confined to booting, these days, is amongst the litany of misdeeds
-
jclulow
It will be interesting to see the first time someone suggests that everything would be better if systemd reparented on top of fushcia or some other not linux
-
richlowe
all those GNU-slash jokes will get funnier
-
jclulow
true fact
-
jclulow
maybe systemd-libc will be the big giveaway
-
richlowe
I mean, ksh93 contains a C library...
-
jclulow
You might be surprised to discover I am also not a huge ksh93 fan haha
-
alanc
at least that's the only "mode=0666" found in a github search of the illumos-gate repo
-
richlowe
I once trawled through everything that was randomly +x