Projet

Général

Profil

Tâche #13329

lenteur extreme au boot

Ajouté par Thierry Bertrand il y a plus de 8 ans. Mis à jour il y a environ 8 ans.

Statut:
Ne sera pas résolu
Priorité:
Normal
Assigné à:
-
Version cible:
-
Début:
21/01/2016
Echéance:
% réalisé:

0%

Temps estimé:
8.00 h
Temps passé:
Restant à faire (heures):
0.0

Description

L'eCDL met près d'une demi-heure à booter ...

boot.log Voir (5 ko) christophe guerinot, 07/10/2015 16:10

dmesg.txt Voir (51,3 ko) christophe guerinot, 07/10/2015 16:10

iptables-debug.log Voir (984 ko) christophe guerinot, 13/10/2015 10:25

boot.log.scribe (6,25 ko) christophe guerinot, 13/10/2015 13:20

dmesg.scribe (252 ko) christophe guerinot, 13/10/2015 13:20


Demandes liées

Lié à Distribution EOLE - Tâche #14005: reboot eCdl : Quand activer_cache_dns à 'oui' le boot prend 7 à 8 mn Fermé 21/09/2015

Révisions associées

Révision a662217c (diff)
Ajouté par christophe guerinot il y a plus de 8 ans

Ajout d'une variable creole 'activer_speedboot' (ref #13329 @2.0 )

  • suite à la suppression du paquet eole-ecdl-speedboot

Historique

#1 Mis à jour par Thierry Bertrand il y a plus de 8 ans

root@cdlpnesr-01:~# dmesg -T
[ven. oct.  2 05:03:47 2015] Initializing cgroup subsys cpuset
[ven. oct.  2 05:03:47 2015] Initializing cgroup subsys cpu
[ven. oct.  2 05:03:47 2015] Initializing cgroup subsys cpuacct
[ven. oct.  2 05:03:47 2015] Linux version 3.19.0-30-generic (buildd@lgw01-56) (gcc version 4.8.2 (Ubuntu 4.8.2-19ubuntu1) ) #33~14.04.1-Ubuntu SMP Tue Sep 22 09:27:00 UTC 2015 (Ubuntu 3.19.0-30.33~14.04.1-generic 3.19.8-ckt6)
[ven. oct.  2 05:03:47 2015] Command line: BOOT_IMAGE=/vmlinuz-3.19.0-30-generic root=/dev/mapper/ecdl--vg-root ro rootdelay=90 net.ifnames=1 biosdevname=0 quiet splash vt.handoff=7
[ven. oct.  2 05:03:47 2015] KERNEL supported cpus:
[ven. oct.  2 05:03:47 2015]   Intel GenuineIntel
[ven. oct.  2 05:03:47 2015]   AMD AuthenticAMD
[ven. oct.  2 05:03:47 2015]   Centaur CentaurHauls
[ven. oct.  2 05:03:47 2015] e820: BIOS-provided physical RAM map:
[ven. oct.  2 05:03:47 2015] BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable
[ven. oct.  2 05:03:47 2015] BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved
[ven. oct.  2 05:03:47 2015] BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved
[ven. oct.  2 05:03:47 2015] BIOS-e820: [mem 0x0000000000100000-0x000000001fffdfff] usable
[ven. oct.  2 05:03:47 2015] BIOS-e820: [mem 0x000000001fffe000-0x000000001fffffff] reserved
[ven. oct.  2 05:03:47 2015] BIOS-e820: [mem 0x00000000feffc000-0x00000000feffffff] reserved
[ven. oct.  2 05:03:47 2015] BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved
[ven. oct.  2 05:03:47 2015] NX (Execute Disable) protection: active
[ven. oct.  2 05:03:47 2015] SMBIOS 2.4 present.
[ven. oct.  2 05:03:47 2015] DMI: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
[ven. oct.  2 05:03:47 2015] Hypervisor detected: KVM
[ven. oct.  2 05:03:47 2015] e820: update [mem 0x00000000-0x00000fff] usable ==> reserved
[ven. oct.  2 05:03:47 2015] e820: remove [mem 0x000a0000-0x000fffff] usable
[ven. oct.  2 05:03:47 2015] AGP: No AGP bridge found
[ven. oct.  2 05:03:47 2015] e820: last_pfn = 0x1fffe max_arch_pfn = 0x400000000
[ven. oct.  2 05:03:47 2015] MTRR default type: write-back
[ven. oct.  2 05:03:47 2015] MTRR fixed ranges enabled:
[ven. oct.  2 05:03:47 2015]   00000-9FFFF write-back
[ven. oct.  2 05:03:47 2015]   A0000-BFFFF uncachable
[ven. oct.  2 05:03:47 2015]   C0000-FFFFF write-protect
[ven. oct.  2 05:03:47 2015] MTRR variable ranges enabled:
[ven. oct.  2 05:03:47 2015]   0 base 0080000000 mask FF80000000 uncachable
[ven. oct.  2 05:03:47 2015]   1 disabled
[ven. oct.  2 05:03:47 2015]   2 disabled
[ven. oct.  2 05:03:47 2015]   3 disabled
[ven. oct.  2 05:03:47 2015]   4 disabled
[ven. oct.  2 05:03:47 2015]   5 disabled
[ven. oct.  2 05:03:47 2015]   6 disabled
[ven. oct.  2 05:03:47 2015]   7 disabled
[ven. oct.  2 05:03:47 2015] PAT not supported by CPU.
[ven. oct.  2 05:03:47 2015] found SMP MP-table at [mem 0x000f0a10-0x000f0a1f] mapped at [ffff8800000f0a10]
[ven. oct.  2 05:03:47 2015] Scanning 1 areas for low memory corruption
[ven. oct.  2 05:03:47 2015] Base memory trampoline at [ffff880000099000] 99000 size 24576
[ven. oct.  2 05:03:47 2015] init_memory_mapping: [mem 0x00000000-0x000fffff]
[ven. oct.  2 05:03:47 2015]  [mem 0x00000000-0x000fffff] page 4k
[ven. oct.  2 05:03:47 2015] BRK [0x01fd4000, 0x01fd4fff] PGTABLE
[ven. oct.  2 05:03:47 2015] BRK [0x01fd5000, 0x01fd5fff] PGTABLE
[ven. oct.  2 05:03:47 2015] BRK [0x01fd6000, 0x01fd6fff] PGTABLE
[ven. oct.  2 05:03:47 2015] init_memory_mapping: [mem 0x1fc00000-0x1fdfffff]
[ven. oct.  2 05:03:47 2015]  [mem 0x1fc00000-0x1fdfffff] page 2M
[ven. oct.  2 05:03:47 2015] init_memory_mapping: [mem 0x00100000-0x1fbfffff]
[ven. oct.  2 05:03:47 2015]  [mem 0x00100000-0x001fffff] page 4k
[ven. oct.  2 05:03:47 2015]  [mem 0x00200000-0x1fbfffff] page 2M
[ven. oct.  2 05:03:47 2015] init_memory_mapping: [mem 0x1fe00000-0x1fffdfff]
[ven. oct.  2 05:03:47 2015]  [mem 0x1fe00000-0x1fffdfff] page 4k
[ven. oct.  2 05:03:47 2015] BRK [0x01fd7000, 0x01fd7fff] PGTABLE
[ven. oct.  2 05:03:47 2015] RAMDISK: [mem 0x1e0cc000-0x1f496fff]
[ven. oct.  2 05:03:47 2015] ACPI: Early table checksum verification disabled
[ven. oct.  2 05:03:47 2015] ACPI: RSDP 0x00000000000F0880 000014 (v00 BOCHS )
[ven. oct.  2 05:03:47 2015] ACPI: RSDT 0x000000001FFFFBC1 000034 (v01 BOCHS  BXPCRSDT 00000001 BXPC 00000001)
[ven. oct.  2 05:03:47 2015] ACPI: FACP 0x000000001FFFF1C0 000074 (v01 BOCHS  BXPCFACP 00000001 BXPC 00000001)
[ven. oct.  2 05:03:47 2015] ACPI: DSDT 0x000000001FFFE040 001180 (v01 BOCHS  BXPCDSDT 00000001 BXPC 00000001)
[ven. oct.  2 05:03:47 2015] ACPI: FACS 0x000000001FFFE000 000040
[ven. oct.  2 05:03:47 2015] ACPI: SSDT 0x000000001FFFF234 0008DD (v01 BOCHS  BXPCSSDT 00000001 BXPC 00000001)
[ven. oct.  2 05:03:47 2015] ACPI: APIC 0x000000001FFFFB11 000078 (v01 BOCHS  BXPCAPIC 00000001 BXPC 00000001)
[ven. oct.  2 05:03:47 2015] ACPI: HPET 0x000000001FFFFB89 000038 (v01 BOCHS  BXPCHPET 00000001 BXPC 00000001)
[ven. oct.  2 05:03:47 2015] ACPI: Local APIC address 0xfee00000
[ven. oct.  2 05:03:47 2015] No NUMA configuration found
[ven. oct.  2 05:03:47 2015] Faking a node at [mem 0x0000000000000000-0x000000001fffdfff]
[ven. oct.  2 05:03:47 2015] NODE_DATA(0) allocated [mem 0x1fff9000-0x1fffdfff]
[ven. oct.  2 05:03:47 2015] kvm-clock: Using msrs 4b564d01 and 4b564d00
[ven. oct.  2 05:03:47 2015] kvm-clock: cpu 0, msr 0:1fff5001, primary cpu clock
[ven. oct.  2 05:03:47 2015]  [ffffea0000000000-ffffea00007fffff] PMD -> [ffff88001d800000-ffff88001dffffff] on node 0
[ven. oct.  2 05:03:47 2015] Zone ranges:
[ven. oct.  2 05:03:47 2015]   DMA      [mem 0x00001000-0x00ffffff]
[ven. oct.  2 05:03:47 2015]   DMA32    [mem 0x01000000-0x1fffdfff]
[ven. oct.  2 05:03:47 2015]   Normal   empty
[ven. oct.  2 05:03:47 2015] Movable zone start for each node
[ven. oct.  2 05:03:47 2015] Early memory node ranges
[ven. oct.  2 05:03:47 2015]   node   0: [mem 0x00001000-0x0009efff]
[ven. oct.  2 05:03:47 2015]   node   0: [mem 0x00100000-0x1fffdfff]
[ven. oct.  2 05:03:47 2015] Initmem setup node 0 [mem 0x00001000-0x1fffdfff]
[ven. oct.  2 05:03:47 2015] On node 0 totalpages: 130972
[ven. oct.  2 05:03:47 2015]   DMA zone: 64 pages used for memmap
[ven. oct.  2 05:03:47 2015]   DMA zone: 21 pages reserved
[ven. oct.  2 05:03:47 2015]   DMA zone: 3998 pages, LIFO batch:0
[ven. oct.  2 05:03:47 2015]   DMA32 zone: 1984 pages used for memmap
[ven. oct.  2 05:03:47 2015]   DMA32 zone: 126974 pages, LIFO batch:31
[ven. oct.  2 05:03:47 2015] ACPI: PM-Timer IO Port: 0xb008
[ven. oct.  2 05:03:47 2015] ACPI: Local APIC address 0xfee00000
[ven. oct.  2 05:03:47 2015] ACPI: LAPIC (acpi_id[0x00] lapic_id[0x00] enabled)
[ven. oct.  2 05:03:47 2015] ACPI: LAPIC_NMI (acpi_id[0xff] dfl dfl lint[0x1])
[ven. oct.  2 05:03:47 2015] ACPI: IOAPIC (id[0x00] address[0xfec00000] gsi_base[0])
[ven. oct.  2 05:03:47 2015] IOAPIC[0]: apic_id 0, version 17, address 0xfec00000, GSI 0-23
[ven. oct.  2 05:03:47 2015] ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl)
[ven. oct.  2 05:03:47 2015] ACPI: INT_SRC_OVR (bus 0 bus_irq 5 global_irq 5 high level)
[ven. oct.  2 05:03:47 2015] ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level)
[ven. oct.  2 05:03:47 2015] ACPI: INT_SRC_OVR (bus 0 bus_irq 10 global_irq 10 high level)
[ven. oct.  2 05:03:47 2015] ACPI: INT_SRC_OVR (bus 0 bus_irq 11 global_irq 11 high level)
[ven. oct.  2 05:03:47 2015] ACPI: IRQ0 used by override.
[ven. oct.  2 05:03:47 2015] ACPI: IRQ5 used by override.
[ven. oct.  2 05:03:47 2015] ACPI: IRQ9 used by override.
[ven. oct.  2 05:03:47 2015] ACPI: IRQ10 used by override.
[ven. oct.  2 05:03:47 2015] ACPI: IRQ11 used by override.
[ven. oct.  2 05:03:47 2015] Using ACPI (MADT) for SMP configuration information
[ven. oct.  2 05:03:47 2015] ACPI: HPET id: 0x8086a201 base: 0xfed00000
[ven. oct.  2 05:03:47 2015] smpboot: Allowing 1 CPUs, 0 hotplug CPUs
[ven. oct.  2 05:03:47 2015] PM: Registered nosave memory: [mem 0x00000000-0x00000fff]
[ven. oct.  2 05:03:47 2015] PM: Registered nosave memory: [mem 0x0009f000-0x0009ffff]
[ven. oct.  2 05:03:47 2015] PM: Registered nosave memory: [mem 0x000a0000-0x000effff]
[ven. oct.  2 05:03:47 2015] PM: Registered nosave memory: [mem 0x000f0000-0x000fffff]
[ven. oct.  2 05:03:47 2015] e820: [mem 0x20000000-0xfeffbfff] available for PCI devices
[ven. oct.  2 05:03:47 2015] Booting paravirtualized kernel on KVM
[ven. oct.  2 05:03:47 2015] setup_percpu: NR_CPUS:256 nr_cpumask_bits:256 nr_cpu_ids:1 nr_node_ids:1
[ven. oct.  2 05:03:47 2015] PERCPU: Embedded 31 pages/cpu @ffff88001fc00000 s86144 r8192 d32640 u2097152
[ven. oct.  2 05:03:47 2015] pcpu-alloc: s86144 r8192 d32640 u2097152 alloc=1*2097152
[ven. oct.  2 05:03:47 2015] pcpu-alloc: [0] 0 
[ven. oct.  2 05:03:47 2015] KVM setup async PF for cpu 0
[ven. oct.  2 05:03:47 2015] kvm-stealtime: cpu 0, msr 1fc0e100
[ven. oct.  2 05:03:47 2015] Built 1 zonelists in Node order, mobility grouping on.  Total pages: 128903
[ven. oct.  2 05:03:47 2015] Policy zone: DMA32
[ven. oct.  2 05:03:47 2015] Kernel command line: BOOT_IMAGE=/vmlinuz-3.19.0-30-generic root=/dev/mapper/ecdl--vg-root ro rootdelay=90 net.ifnames=1 biosdevname=0 quiet splash vt.handoff=7
[ven. oct.  2 05:03:47 2015] PID hash table entries: 2048 (order: 2, 16384 bytes)
[ven. oct.  2 05:03:47 2015] AGP: Checking aperture...
[ven. oct.  2 05:03:47 2015] AGP: No AGP bridge found
[ven. oct.  2 05:03:47 2015] Calgary: detecting Calgary via BIOS EBDA area
[ven. oct.  2 05:03:47 2015] Calgary: Unable to locate Rio Grande table in EBDA - bailing!
[ven. oct.  2 05:03:47 2015] Memory: 478716K/523888K available (7920K kernel code, 1174K rwdata, 3756K rodata, 1408K init, 1292K bss, 45172K reserved, 0K cma-reserved)
[ven. oct.  2 05:03:47 2015] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=1, Nodes=1
[ven. oct.  2 05:03:47 2015] Hierarchical RCU implementation.
[ven. oct.  2 05:03:47 2015]     RCU dyntick-idle grace-period acceleration is enabled.
[ven. oct.  2 05:03:47 2015]     RCU restricting CPUs from NR_CPUS=256 to nr_cpu_ids=1.
[ven. oct.  2 05:03:47 2015] RCU: Adjusting geometry for rcu_fanout_leaf=16, nr_cpu_ids=1
[ven. oct.  2 05:03:47 2015] NR_IRQS:16640 nr_irqs:256 16
[ven. oct.  2 05:03:47 2015]     Offload RCU callbacks from all CPUs
[ven. oct.  2 05:03:47 2015]     Offload RCU callbacks from CPUs: 0.
[ven. oct.  2 05:03:47 2015] vt handoff: transparent VT on vt#7
[ven. oct.  2 05:03:47 2015] Console: colour dummy device 80x25
[ven. oct.  2 05:03:47 2015] console [tty0] enabled
[ven. oct.  2 05:03:47 2015] hpet clockevent registered
[ven. oct.  2 05:03:47 2015] tsc: Detected 2599.998 MHz processor
[ven. oct.  2 05:03:47 2015] Calibrating delay loop (skipped) preset value.. 5199.99 BogoMIPS (lpj=10399992)
[ven. oct.  2 05:03:47 2015] pid_max: default: 32768 minimum: 301
[ven. oct.  2 05:03:47 2015] ACPI: Core revision 20141107
[ven. oct.  2 05:03:47 2015] ACPI: All ACPI Tables successfully acquired
[ven. oct.  2 05:03:47 2015] Security Framework initialized
[ven. oct.  2 05:03:47 2015] AppArmor: AppArmor initialized
[ven. oct.  2 05:03:47 2015] Yama: becoming mindful.
[ven. oct.  2 05:03:47 2015] Dentry cache hash table entries: 65536 (order: 7, 524288 bytes)
[ven. oct.  2 05:03:47 2015] Inode-cache hash table entries: 32768 (order: 6, 262144 bytes)
[ven. oct.  2 05:03:47 2015] Mount-cache hash table entries: 1024 (order: 1, 8192 bytes)
[ven. oct.  2 05:03:47 2015] Mountpoint-cache hash table entries: 1024 (order: 1, 8192 bytes)
[ven. oct.  2 05:03:47 2015] Initializing cgroup subsys memory
[ven. oct.  2 05:03:47 2015] Initializing cgroup subsys devices
[ven. oct.  2 05:03:47 2015] Initializing cgroup subsys freezer
[ven. oct.  2 05:03:47 2015] Initializing cgroup subsys net_cls
[ven. oct.  2 05:03:47 2015] Initializing cgroup subsys blkio
[ven. oct.  2 05:03:47 2015] Initializing cgroup subsys perf_event
[ven. oct.  2 05:03:47 2015] Initializing cgroup subsys net_prio
[ven. oct.  2 05:03:47 2015] Initializing cgroup subsys hugetlb
[ven. oct.  2 05:03:47 2015] mce: CPU supports 10 MCE banks
[ven. oct.  2 05:03:47 2015] Last level iTLB entries: 4KB 0, 2MB 0, 4MB 0
[ven. oct.  2 05:03:47 2015] Last level dTLB entries: 4KB 0, 2MB 0, 4MB 0, 1GB 0
[ven. oct.  2 05:03:47 2015] Freeing SMP alternatives memory: 32K (ffffffff81e87000 - ffffffff81e8f000)
[ven. oct.  2 05:03:47 2015] ftrace: allocating 30022 entries in 118 pages
[ven. oct.  2 05:03:47 2015] Enabling x2apic
[ven. oct.  2 05:03:47 2015] Enabled x2apic
[ven. oct.  2 05:03:47 2015] Switched APIC routing to physical x2apic.
[ven. oct.  2 05:03:47 2015] ..TIMER: vector=0x30 apic1=0 pin1=2 apic2=-1 pin2=-1
[ven. oct.  2 05:03:47 2015] smpboot: CPU0: Intel QEMU Virtual CPU version 2.0.0 (fam: 06, model: 06, stepping: 03)
[ven. oct.  2 05:03:47 2015] Performance Events: Broken PMU hardware detected, using software events only.
[ven. oct.  2 05:03:47 2015] Failed to access perfctr msr (MSR c1 is 0)
[ven. oct.  2 05:03:47 2015] x86: Booted up 1 node, 1 CPUs
[ven. oct.  2 05:03:47 2015] smpboot: Total of 1 processors activated (5199.99 BogoMIPS)
[ven. oct.  2 05:03:47 2015] devtmpfs: initialized
[ven. oct.  2 05:03:47 2015] evm: security.selinux
[ven. oct.  2 05:03:47 2015] evm: security.SMACK64
[ven. oct.  2 05:03:47 2015] evm: security.SMACK64EXEC
[ven. oct.  2 05:03:47 2015] evm: security.SMACK64TRANSMUTE
[ven. oct.  2 05:03:47 2015] evm: security.SMACK64MMAP
[ven. oct.  2 05:03:47 2015] evm: security.ima
[ven. oct.  2 05:03:47 2015] evm: security.capability
[ven. oct.  2 05:03:47 2015] NMI watchdog: disabled (cpu0): hardware events not enabled
[ven. oct.  2 05:03:47 2015] pinctrl core: initialized pinctrl subsystem
[ven. oct.  2 05:03:47 2015] RTC time:  3:03:48, date: 10/02/15
[ven. oct.  2 05:03:47 2015] NET: Registered protocol family 16
[ven. oct.  2 05:03:47 2015] cpuidle: using governor ladder
[ven. oct.  2 05:03:47 2015] cpuidle: using governor menu
[ven. oct.  2 05:03:47 2015] ACPI: bus type PCI registered
[ven. oct.  2 05:03:47 2015] acpiphp: ACPI Hot Plug PCI Controller Driver version: 0.5
[ven. oct.  2 05:03:47 2015] PCI: Using configuration type 1 for base access
[ven. oct.  2 05:03:47 2015] ACPI: Added _OSI(Module Device)
[ven. oct.  2 05:03:47 2015] ACPI: Added _OSI(Processor Device)
[ven. oct.  2 05:03:47 2015] ACPI: Added _OSI(3.0 _SCP Extensions)
[ven. oct.  2 05:03:47 2015] ACPI: Added _OSI(Processor Aggregator Device)
[ven. oct.  2 05:03:47 2015] ACPI: Interpreter enabled
[ven. oct.  2 05:03:47 2015] ACPI Exception: AE_NOT_FOUND, While evaluating Sleep State [\_S1_] (20141107/hwxface-580)
[ven. oct.  2 05:03:47 2015] ACPI Exception: AE_NOT_FOUND, While evaluating Sleep State [\_S2_] (20141107/hwxface-580)
[ven. oct.  2 05:03:47 2015] ACPI: (supports S0 S3 S4 S5)
[ven. oct.  2 05:03:47 2015] ACPI: Using IOAPIC for interrupt routing
[ven. oct.  2 05:03:47 2015] PCI: Using host bridge windows from ACPI; if necessary, use "pci=nocrs" and report a bug
[ven. oct.  2 05:03:47 2015] ACPI: PCI Root Bridge [PCI0] (domain 0000 [bus 00-ff])
[ven. oct.  2 05:03:47 2015] acpi PNP0A03:00: _OSC: OS supports [ASPM ClockPM Segments MSI]
[ven. oct.  2 05:03:47 2015] acpi PNP0A03:00: _OSC failed (AE_NOT_FOUND); disabling ASPM
[ven. oct.  2 05:03:47 2015] acpi PNP0A03:00: fail to add MMCONFIG information, can't access extended PCI configuration space under this bridge.
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [3] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [4] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [5] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [6] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [7] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [8] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [9] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [10] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [11] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [12] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [13] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [14] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [15] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [16] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [17] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [18] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [19] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [20] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [21] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [22] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [23] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [24] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [25] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [26] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [27] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [28] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [29] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [30] registered
[ven. oct.  2 05:03:47 2015] acpiphp: Slot [31] registered
[ven. oct.  2 05:03:47 2015] PCI host bridge to bus 0000:00
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: root bus resource [bus 00-ff]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: root bus resource [io  0x0000-0x0cf7]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: root bus resource [io  0x0d00-0xadff]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: root bus resource [io  0xae0f-0xaeff]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: root bus resource [io  0xaf20-0xafdf]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: root bus resource [io  0xafe4-0xffff]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: root bus resource [mem 0x000a0000-0x000bffff]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: root bus resource [mem 0x20000000-0xfebfffff]
[ven. oct.  2 05:03:47 2015] pci 0000:00:00.0: [8086:1237] type 00 class 0x060000
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.0: [8086:7000] type 00 class 0x060100
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.1: [8086:7010] type 00 class 0x010180
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.1: reg 0x20: [io  0xc0a0-0xc0af]
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.1: legacy IDE quirk: reg 0x10: [io  0x01f0-0x01f7]
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.1: legacy IDE quirk: reg 0x14: [io  0x03f6]
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.1: legacy IDE quirk: reg 0x18: [io  0x0170-0x0177]
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.1: legacy IDE quirk: reg 0x1c: [io  0x0376]
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.2: [8086:7020] type 00 class 0x0c0300
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.2: reg 0x20: [io  0xc040-0xc05f]
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.3: [8086:7113] type 00 class 0x068000
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.3: quirk: [io  0xb000-0xb03f] claimed by PIIX4 ACPI
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.3: quirk: [io  0xb100-0xb10f] claimed by PIIX4 SMB
[ven. oct.  2 05:03:47 2015] pci 0000:00:02.0: [1234:1111] type 00 class 0x030000
[ven. oct.  2 05:03:47 2015] pci 0000:00:02.0: reg 0x10: [mem 0xfd000000-0xfdffffff pref]
[ven. oct.  2 05:03:47 2015] pci 0000:00:02.0: reg 0x18: [mem 0xfebd0000-0xfebd0fff]
[ven. oct.  2 05:03:47 2015] pci 0000:00:02.0: reg 0x30: [mem 0xfebc0000-0xfebcffff pref]
[ven. oct.  2 05:03:47 2015] pci 0000:00:03.0: [1af4:1000] type 00 class 0x020000
[ven. oct.  2 05:03:47 2015] pci 0000:00:03.0: reg 0x10: [io  0xc060-0xc07f]
[ven. oct.  2 05:03:47 2015] pci 0000:00:03.0: reg 0x14: [mem 0xfebd1000-0xfebd1fff]
[ven. oct.  2 05:03:47 2015] pci 0000:00:03.0: reg 0x30: [mem 0xfeb80000-0xfebbffff pref]
[ven. oct.  2 05:03:47 2015] pci 0000:00:04.0: [1af4:1001] type 00 class 0x010000
[ven. oct.  2 05:03:47 2015] pci 0000:00:04.0: reg 0x10: [io  0xc000-0xc03f]
[ven. oct.  2 05:03:47 2015] pci 0000:00:04.0: reg 0x14: [mem 0xfebd2000-0xfebd2fff]
[ven. oct.  2 05:03:47 2015] pci 0000:00:05.0: [1af4:1002] type 00 class 0x00ff00
[ven. oct.  2 05:03:47 2015] pci 0000:00:05.0: reg 0x10: [io  0xc080-0xc09f]
[ven. oct.  2 05:03:47 2015] ACPI: PCI Interrupt Link [LNKA] (IRQs 5 *10 11)
[ven. oct.  2 05:03:47 2015] ACPI: PCI Interrupt Link [LNKB] (IRQs 5 *10 11)
[ven. oct.  2 05:03:47 2015] ACPI: PCI Interrupt Link [LNKC] (IRQs 5 10 *11)
[ven. oct.  2 05:03:47 2015] ACPI: PCI Interrupt Link [LNKD] (IRQs 5 10 *11)
[ven. oct.  2 05:03:47 2015] ACPI: PCI Interrupt Link [LNKS] (IRQs *9)
[ven. oct.  2 05:03:47 2015] ACPI: Enabled 16 GPEs in block 00 to 0F
[ven. oct.  2 05:03:47 2015] vgaarb: setting as boot device: PCI:0000:00:02.0
[ven. oct.  2 05:03:47 2015] vgaarb: device added: PCI:0000:00:02.0,decodes=io+mem,owns=io+mem,locks=none
[ven. oct.  2 05:03:47 2015] vgaarb: loaded
[ven. oct.  2 05:03:47 2015] vgaarb: bridge control possible 0000:00:02.0
[ven. oct.  2 05:03:47 2015] SCSI subsystem initialized
[ven. oct.  2 05:03:47 2015] libata version 3.00 loaded.
[ven. oct.  2 05:03:47 2015] ACPI: bus type USB registered
[ven. oct.  2 05:03:47 2015] usbcore: registered new interface driver usbfs
[ven. oct.  2 05:03:47 2015] usbcore: registered new interface driver hub
[ven. oct.  2 05:03:47 2015] usbcore: registered new device driver usb
[ven. oct.  2 05:03:47 2015] PCI: Using ACPI for IRQ routing
[ven. oct.  2 05:03:47 2015] PCI: pci_cache_line_size set to 64 bytes
[ven. oct.  2 05:03:47 2015] e820: reserve RAM buffer [mem 0x0009fc00-0x0009ffff]
[ven. oct.  2 05:03:47 2015] e820: reserve RAM buffer [mem 0x1fffe000-0x1fffffff]
[ven. oct.  2 05:03:47 2015] NetLabel: Initializing
[ven. oct.  2 05:03:47 2015] NetLabel:  domain hash size = 128
[ven. oct.  2 05:03:47 2015] NetLabel:  protocols = UNLABELED CIPSOv4
[ven. oct.  2 05:03:47 2015] NetLabel:  unlabeled traffic allowed by default
[ven. oct.  2 05:03:47 2015] HPET: 3 timers in total, 0 timers will be used for per-cpu timer
[ven. oct.  2 05:03:47 2015] hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0
[ven. oct.  2 05:03:47 2015] hpet0: 3 comparators, 64-bit 100.000000 MHz counter
[ven. oct.  2 05:03:47 2015] Switched to clocksource kvm-clock
[ven. oct.  2 05:03:47 2015] AppArmor: AppArmor Filesystem Enabled
[ven. oct.  2 05:03:47 2015] pnp: PnP ACPI init
[ven. oct.  2 05:03:47 2015] pnp 00:00: Plug and Play ACPI device, IDs PNP0b00 (active)
[ven. oct.  2 05:03:47 2015] pnp 00:01: Plug and Play ACPI device, IDs PNP0303 (active)
[ven. oct.  2 05:03:47 2015] pnp 00:02: Plug and Play ACPI device, IDs PNP0f13 (active)
[ven. oct.  2 05:03:47 2015] pnp 00:03: [dma 2]
[ven. oct.  2 05:03:47 2015] pnp 00:03: Plug and Play ACPI device, IDs PNP0700 (active)
[ven. oct.  2 05:03:47 2015] pnp: PnP ACPI: found 4 devices
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: resource 4 [io  0x0000-0x0cf7]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: resource 5 [io  0x0d00-0xadff]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: resource 6 [io  0xae0f-0xaeff]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: resource 7 [io  0xaf20-0xafdf]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: resource 8 [io  0xafe4-0xffff]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: resource 9 [mem 0x000a0000-0x000bffff]
[ven. oct.  2 05:03:47 2015] pci_bus 0000:00: resource 10 [mem 0x20000000-0xfebfffff]
[ven. oct.  2 05:03:47 2015] NET: Registered protocol family 2
[ven. oct.  2 05:03:47 2015] TCP established hash table entries: 4096 (order: 3, 32768 bytes)
[ven. oct.  2 05:03:47 2015] TCP bind hash table entries: 4096 (order: 4, 65536 bytes)
[ven. oct.  2 05:03:47 2015] TCP: Hash tables configured (established 4096 bind 4096)
[ven. oct.  2 05:03:47 2015] TCP: reno registered
[ven. oct.  2 05:03:47 2015] UDP hash table entries: 256 (order: 1, 8192 bytes)
[ven. oct.  2 05:03:47 2015] UDP-Lite hash table entries: 256 (order: 1, 8192 bytes)
[ven. oct.  2 05:03:47 2015] NET: Registered protocol family 1
[ven. oct.  2 05:03:47 2015] pci 0000:00:00.0: Limiting direct PCI/PCI transfers
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.0: PIIX3: Enabling Passive Release
[ven. oct.  2 05:03:47 2015] pci 0000:00:01.0: Activating ISA DMA hang workarounds
[ven. oct.  2 05:03:47 2015] ACPI: PCI Interrupt Link [LNKD] enabled at IRQ 11
[ven. oct.  2 05:03:47 2015] pci 0000:00:02.0: Video device with shadowed ROM
[ven. oct.  2 05:03:47 2015] PCI: CLS 0 bytes, default 64
[ven. oct.  2 05:03:47 2015] Trying to unpack rootfs image as initramfs...
[ven. oct.  2 05:03:47 2015] Freeing initrd memory: 20268K (ffff88001e0cc000 - ffff88001f497000)
[ven. oct.  2 05:03:47 2015] microcode: CPU0 sig=0x663, pf=0x1, revision=0x1
[ven. oct.  2 05:03:47 2015] microcode: Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co.uk>, Peter Oruba
[ven. oct.  2 05:03:47 2015] Scanning for low memory corruption every 60 seconds
[ven. oct.  2 05:03:47 2015] futex hash table entries: 256 (order: 2, 16384 bytes)
[ven. oct.  2 05:03:47 2015] Initialise system trusted keyring
[ven. oct.  2 05:03:47 2015] audit: initializing netlink subsys (disabled)
[ven. oct.  2 05:03:47 2015] audit: type=2000 audit(1443764992.470:1): initialized
[ven. oct.  2 05:03:47 2015] HugeTLB registered 2 MB page size, pre-allocated 0 pages
[ven. oct.  2 05:03:47 2015] zpool: loaded
[ven. oct.  2 05:03:47 2015] zbud: loaded
[ven. oct.  2 05:03:47 2015] VFS: Disk quotas dquot_6.5.2
[ven. oct.  2 05:03:47 2015] VFS: Dquot-cache hash table entries: 512 (order 0, 4096 bytes)
[ven. oct.  2 05:03:47 2015] fuse init (API version 7.23)
[ven. oct.  2 05:03:47 2015] Key type big_key registered
[ven. oct.  2 05:03:47 2015] Key type asymmetric registered
[ven. oct.  2 05:03:47 2015] Asymmetric key parser 'x509' registered
[ven. oct.  2 05:03:47 2015] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 252)
[ven. oct.  2 05:03:47 2015] io scheduler noop registered
[ven. oct.  2 05:03:47 2015] io scheduler deadline registered (default)
[ven. oct.  2 05:03:47 2015] io scheduler cfq registered
[ven. oct.  2 05:03:47 2015] pci_hotplug: PCI Hot Plug PCI Core version: 0.5
[ven. oct.  2 05:03:47 2015] pciehp: PCI Express Hot Plug Controller Driver version: 0.4
[ven. oct.  2 05:03:47 2015] efifb: probing for efifb
[ven. oct.  2 05:03:47 2015] efifb: framebuffer at 0xfd000000, mapped to 0xffffc90000100000, using 1408k, total 1408k
[ven. oct.  2 05:03:47 2015] efifb: mode is 800x600x24, linelength=2400, pages=1
[ven. oct.  2 05:03:47 2015] efifb: scrolling: redraw
[ven. oct.  2 05:03:47 2015] efifb: Truecolor: size=0:8:8:8, shift=0:16:8:0
[ven. oct.  2 05:03:47 2015] Console: switching to colour frame buffer device 100x37
[ven. oct.  2 05:03:47 2015] fb0: EFI VGA frame buffer device
[ven. oct.  2 05:03:47 2015] intel_idle: does not run on family 6 model 6
[ven. oct.  2 05:03:47 2015] input: Power Button as /devices/LNXSYSTM:00/LNXPWRBN:00/input/input0
[ven. oct.  2 05:03:47 2015] ACPI: Power Button [PWRF]
[ven. oct.  2 05:03:47 2015] GHES: HEST is not enabled!
[ven. oct.  2 05:03:47 2015] ACPI: PCI Interrupt Link [LNKC] enabled at IRQ 10
[ven. oct.  2 05:03:47 2015] ACPI: PCI Interrupt Link [LNKA] enabled at IRQ 10
[ven. oct.  2 05:03:47 2015] Serial: 8250/16550 driver, 32 ports, IRQ sharing enabled
[ven. oct.  2 05:03:47 2015] Linux agpgart interface v0.103
[ven. oct.  2 05:03:47 2015] brd: module loaded
[ven. oct.  2 05:03:47 2015] loop: module loaded
[ven. oct.  2 05:03:47 2015]  vda: vda1 vda2 < vda5 >
[ven. oct.  2 05:03:47 2015] ata_piix 0000:00:01.1: version 2.13
[ven. oct.  2 05:03:47 2015] scsi host0: ata_piix
[ven. oct.  2 05:03:47 2015] scsi host1: ata_piix
[ven. oct.  2 05:03:47 2015] ata1: PATA max MWDMA2 cmd 0x1f0 ctl 0x3f6 bmdma 0xc0a0 irq 14
[ven. oct.  2 05:03:47 2015] ata2: PATA max MWDMA2 cmd 0x170 ctl 0x376 bmdma 0xc0a8 irq 15
[ven. oct.  2 05:03:47 2015] libphy: Fixed MDIO Bus: probed
[ven. oct.  2 05:03:47 2015] tun: Universal TUN/TAP device driver, 1.6
[ven. oct.  2 05:03:47 2015] tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
[ven. oct.  2 05:03:47 2015] PPP generic driver version 2.4.2
[ven. oct.  2 05:03:47 2015] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
[ven. oct.  2 05:03:47 2015] ehci-pci: EHCI PCI platform driver
[ven. oct.  2 05:03:47 2015] ehci-platform: EHCI generic platform driver
[ven. oct.  2 05:03:47 2015] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
[ven. oct.  2 05:03:47 2015] ohci-pci: OHCI PCI platform driver
[ven. oct.  2 05:03:47 2015] ohci-platform: OHCI generic platform driver
[ven. oct.  2 05:03:47 2015] uhci_hcd: USB Universal Host Controller Interface driver
[ven. oct.  2 05:03:47 2015] uhci_hcd 0000:00:01.2: UHCI Host Controller
[ven. oct.  2 05:03:47 2015] uhci_hcd 0000:00:01.2: new USB bus registered, assigned bus number 1
[ven. oct.  2 05:03:47 2015] uhci_hcd 0000:00:01.2: detected 2 ports
[ven. oct.  2 05:03:47 2015] uhci_hcd 0000:00:01.2: irq 11, io base 0x0000c040
[ven. oct.  2 05:03:47 2015] usb usb1: New USB device found, idVendor=1d6b, idProduct=0001
[ven. oct.  2 05:03:47 2015] usb usb1: New USB device strings: Mfr=3, Product=2, SerialNumber=1
[ven. oct.  2 05:03:47 2015] usb usb1: Product: UHCI Host Controller
[ven. oct.  2 05:03:47 2015] usb usb1: Manufacturer: Linux 3.19.0-30-generic uhci_hcd
[ven. oct.  2 05:03:47 2015] usb usb1: SerialNumber: 0000:00:01.2
[ven. oct.  2 05:03:47 2015] hub 1-0:1.0: USB hub found
[ven. oct.  2 05:03:47 2015] hub 1-0:1.0: 2 ports detected
[ven. oct.  2 05:03:47 2015] i8042: PNP: PS/2 Controller [PNP0303:KBD,PNP0f13:MOU] at 0x60,0x64 irq 1,12
[ven. oct.  2 05:03:47 2015] serio: i8042 KBD port at 0x60,0x64 irq 1
[ven. oct.  2 05:03:47 2015] serio: i8042 AUX port at 0x60,0x64 irq 12
[ven. oct.  2 05:03:47 2015] mousedev: PS/2 mouse device common for all mice
[ven. oct.  2 05:03:47 2015] input: AT Translated Set 2 keyboard as /devices/platform/i8042/serio0/input/input1
[ven. oct.  2 05:03:47 2015] rtc_cmos 00:00: RTC can wake from S4
[ven. oct.  2 05:03:47 2015] rtc_cmos 00:00: rtc core: registered rtc_cmos as rtc0
[ven. oct.  2 05:03:47 2015] rtc_cmos 00:00: alarms up to one day, 114 bytes nvram, hpet irqs
[ven. oct.  2 05:03:47 2015] i2c /dev entries driver
[ven. oct.  2 05:03:47 2015] device-mapper: uevent: version 1.0.3
[ven. oct.  2 05:03:47 2015] device-mapper: ioctl: 4.29.0-ioctl (2014-10-28) initialised: dm-devel@redhat.com
[ven. oct.  2 05:03:47 2015] ledtrig-cpu: registered to indicate activity on CPUs
[ven. oct.  2 05:03:47 2015] PCCT header not found.
[ven. oct.  2 05:03:47 2015] ACPI PCC probe failed.
[ven. oct.  2 05:03:47 2015] TCP: cubic registered
[ven. oct.  2 05:03:47 2015] NET: Registered protocol family 10
[ven. oct.  2 05:03:47 2015] NET: Registered protocol family 17
[ven. oct.  2 05:03:47 2015] Key type dns_resolver registered
[ven. oct.  2 05:03:47 2015] Loading compiled-in X.509 certificates
[ven. oct.  2 05:03:47 2015] Loaded X.509 cert 'Magrathea: Glacier signing key: 48a35745535d8d6f341b30c63c3aa38578743d0d'
[ven. oct.  2 05:03:47 2015] registered taskstats version 1
[ven. oct.  2 05:03:47 2015] Key type trusted registered
[ven. oct.  2 05:03:47 2015] Key type encrypted registered
[ven. oct.  2 05:03:47 2015] AppArmor: AppArmor sha1 policy hashing enabled
[ven. oct.  2 05:03:47 2015] ima: No TPM chip found, activating TPM-bypass!
[ven. oct.  2 05:03:47 2015] evm: HMAC attrs: 0x1
[ven. oct.  2 05:03:47 2015]   Magic number: 3:3:57
[ven. oct.  2 05:03:47 2015] rtc_cmos 00:00: setting system clock to 2015-10-02 03:03:48 UTC (1443755028)
[ven. oct.  2 05:03:47 2015] BIOS EDD facility v0.16 2004-Jun-25, 0 devices found
[ven. oct.  2 05:03:47 2015] EDD information not available.
[ven. oct.  2 05:03:47 2015] PM: Hibernation image not present or could not be loaded.
[ven. oct.  2 05:03:47 2015] ata1.01: NODEV after polling detection
[ven. oct.  2 05:03:47 2015] ata1.00: ATAPI: QEMU DVD-ROM, 2.0.0, max UDMA/100
[ven. oct.  2 05:03:47 2015] ata1.00: configured for MWDMA2
[ven. oct.  2 05:03:47 2015] scsi 0:0:0:0: CD-ROM            QEMU     QEMU DVD-ROM     2.0. PQ: 0 ANSI: 5
[ven. oct.  2 05:03:47 2015] sr 0:0:0:0: [sr0] scsi3-mmc drive: 4x/4x cd/rw xa/form2 tray
[ven. oct.  2 05:03:47 2015] cdrom: Uniform CD-ROM driver Revision: 3.20
[ven. oct.  2 05:03:47 2015] sr 0:0:0:0: Attached scsi CD-ROM sr0
[ven. oct.  2 05:03:47 2015] sr 0:0:0:0: Attached scsi generic sg0 type 5
[ven. oct.  2 05:03:47 2015] Freeing unused kernel memory: 1408K (ffffffff81d27000 - ffffffff81e87000)
[ven. oct.  2 05:03:47 2015] Write protecting the kernel read-only data: 12288k
[ven. oct.  2 05:03:47 2015] Freeing unused kernel memory: 260K (ffff8800017bf000 - ffff880001800000)
[ven. oct.  2 05:03:47 2015] Freeing unused kernel memory: 340K (ffff880001bab000 - ffff880001c00000)
[ven. oct.  2 05:03:47 2015] systemd-udevd[100]: starting version 204
[ven. oct.  2 05:03:47 2015] FDC 0 is a S82078B
[ven. oct.  2 05:03:47 2015] usb 1-1: new full-speed USB device number 2 using uhci_hcd
[ven. oct.  2 05:03:47 2015] random: lvm urandom read with 13 bits of entropy available
[ven. oct.  2 05:03:47 2015] usb 1-1: New USB device found, idVendor=0627, idProduct=0001
[ven. oct.  2 05:03:47 2015] usb 1-1: New USB device strings: Mfr=1, Product=3, SerialNumber=5
[ven. oct.  2 05:03:47 2015] usb 1-1: Product: QEMU USB Tablet
[ven. oct.  2 05:03:47 2015] usb 1-1: Manufacturer: QEMU
[ven. oct.  2 05:03:47 2015] usb 1-1: SerialNumber: 42
[ven. oct.  2 05:03:47 2015] hidraw: raw HID events driver (C) Jiri Kosina
[ven. oct.  2 05:03:47 2015] EXT4-fs (dm-0): mounted filesystem with ordered data mode. Opts: (null)
[ven. oct.  2 05:03:47 2015] usbcore: registered new interface driver usbhid
[ven. oct.  2 05:03:47 2015] usbhid: USB HID core driver
[ven. oct.  2 05:03:47 2015] input: QEMU QEMU USB Tablet as /devices/pci0000:00/0000:00:01.2/usb1/1-1/1-1:1.0/0003:0627:0001.0001/input/input4
[ven. oct.  2 05:03:47 2015] hid-generic 0003:0627:0001.0001: input,hidraw0: USB HID v0.01 Pointer [QEMU QEMU USB Tablet] on usb-0000:00:01.2-1/input0
[ven. oct.  2 05:03:48 2015] init: plymouth-upstart-bridge main process (169) terminated with status 1
[ven. oct.  2 05:03:48 2015] init: plymouth-upstart-bridge main process ended, respawning
[ven. oct.  2 05:03:48 2015] init: plymouth-upstart-bridge main process (180) terminated with status 1
[ven. oct.  2 05:03:48 2015] init: plymouth-upstart-bridge main process ended, respawning
[ven. oct.  2 05:03:48 2015] tsc: Refined TSC clocksource calibration: 2599.933 MHz
[ven. oct.  2 05:03:48 2015] Adding 524284k swap on /dev/mapper/ecdl--vg-swap_1.  Priority:-1 extents:1 across:524284k FS
[ven. oct.  2 05:03:48 2015] systemd-udevd[258]: starting version 204
[ven. oct.  2 05:03:48 2015] input: ImExPS/2 Generic Explorer Mouse as /devices/platform/i8042/serio1/input/input3
[ven. oct.  2 05:03:48 2015] EXT4-fs (dm-0): re-mounted. Opts: acl,errors=remount-ro,grpquota,user_xattr,usrquota
[ven. oct.  2 05:03:48 2015] lp: driver loaded but no devices found
[ven. oct.  2 05:03:49 2015] EXT4-fs (vda1): mounting ext2 file system using the ext4 subsystem
[ven. oct.  2 05:03:49 2015] EXT4-fs (vda1): mounted filesystem without journal. Opts: (null)
[ven. oct.  2 05:03:49 2015] piix4_smbus 0000:00:01.3: SMBus Host Controller at 0xb100, revision 0
[ven. oct.  2 05:03:49 2015] audit: type=1400 audit(1443755030.557:2): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/sbin/dhclient" pid=410 comm="apparmor_parser" 
[ven. oct.  2 05:03:49 2015] audit: type=1400 audit(1443755030.557:3): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=410 comm="apparmor_parser" 
[ven. oct.  2 05:03:49 2015] audit: type=1400 audit(1443755030.557:4): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=410 comm="apparmor_parser" 
[ven. oct.  2 05:03:49 2015] audit: type=1400 audit(1443755030.565:5): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=410 comm="apparmor_parser" 
[ven. oct.  2 05:03:49 2015] audit: type=1400 audit(1443755030.565:6): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=410 comm="apparmor_parser" 
[ven. oct.  2 05:03:49 2015] audit: type=1400 audit(1443755030.565:7): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=410 comm="apparmor_parser" 
[ven. oct.  2 05:03:49 2015] ppdev: user-space parallel port driver
[ven. oct.  2 05:03:49 2015] audit: type=1400 audit(1443755030.673:8): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/sbin/dhclient" pid=444 comm="apparmor_parser" 
[ven. oct.  2 05:03:49 2015] audit: type=1400 audit(1443755030.673:9): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=444 comm="apparmor_parser" 
[ven. oct.  2 05:03:49 2015] audit: type=1400 audit(1443755030.673:10): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=444 comm="apparmor_parser" 
[ven. oct.  2 05:03:50 2015] ip_tables: (C) 2000-2006 Netfilter Core Team
[ven. oct.  2 05:03:50 2015] init: samba-ad-dc main process (566) terminated with status 1
[ven. oct.  2 05:03:50 2015] nf_conntrack version 0.5.0 (3914 buckets, 15656 max)
[ven. oct.  2 05:03:50 2015] Netfilter messages via NETLINK v0.30.
[ven. oct.  2 05:03:50 2015] ip_set: protocol 6
[ven. oct.  2 05:03:57 2015] init: failsafe main process (525) killed by TERM signal
[ven. oct.  2 05:04:58 2015] audit_printk_skb: 36 callbacks suppressed
[ven. oct.  2 05:04:58 2015] audit: type=1400 audit(1443755099.477:23): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/sbin/dhclient" pid=968 comm="apparmor_parser" 
[ven. oct.  2 05:04:58 2015] audit: type=1400 audit(1443755099.477:24): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=968 comm="apparmor_parser" 
[ven. oct.  2 05:04:58 2015] audit: type=1400 audit(1443755099.477:25): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=968 comm="apparmor_parser" 
[ven. oct.  2 05:04:58 2015] audit: type=1400 audit(1443755099.477:26): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=968 comm="apparmor_parser" 
[ven. oct.  2 05:04:58 2015] audit: type=1400 audit(1443755099.477:27): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=968 comm="apparmor_parser" 
[ven. oct.  2 05:04:58 2015] audit: type=1400 audit(1443755099.477:28): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=968 comm="apparmor_parser" 
[ven. oct.  2 05:04:58 2015] audit: type=1400 audit(1443755099.661:29): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/bin/freshclam" pid=969 comm="apparmor_parser" 
[ven. oct.  2 05:04:58 2015] audit: type=1400 audit(1443755099.809:30): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/sbin/clamd" pid=970 comm="apparmor_parser" 
[ven. oct.  2 05:04:58 2015] audit: type=1400 audit(1443755099.809:31): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/sbin/named" pid=971 comm="apparmor_parser" 
[ven. oct.  2 05:04:58 2015] audit: type=1400 audit(1443755099.813:32): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/sbin/ntpd" pid=972 comm="apparmor_parser" 
[ven. oct.  2 05:05:09 2015] random: nonblocking pool is initialized
[ven. oct.  2 05:05:18 2015] audit_printk_skb: 6 callbacks suppressed
[ven. oct.  2 05:05:18 2015] audit: type=1400 audit(1443755119.465:35): apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/run/samba/nmbd/unexpected" pid=948 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
[ven. oct.  2 05:05:18 2015] audit: type=1400 audit(1443755119.717:36): apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/run/samba/winbindd/pipe" pid=948 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
[ven. oct.  2 05:05:40 2015] audit: type=1400 audit(1443755141.733:37): apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/run/samba/nmbd/unexpected" pid=1031 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
[ven. oct.  2 05:12:00 2015] atkbd serio0: Unknown key pressed (translated set 2, code 0x0 on isa0060/serio0).
[ven. oct.  2 05:12:00 2015] atkbd serio0: Use 'setkeycodes 00 <keycode>' to make it known.
[ven. oct.  2 05:12:00 2015] atkbd serio0: Unknown key released (translated set 2, code 0x0 on isa0060/serio0).
[ven. oct.  2 05:12:00 2015] atkbd serio0: Use 'setkeycodes 00 <keycode>' to make it known.
[ven. oct.  2 05:13:09 2015] audit: type=1400 audit(1443755590.725:38): apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/run/samba/nmbd/unexpected" pid=1259 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
[ven. oct.  2 05:13:09 2015] audit: type=1400 audit(1443755590.977:39): apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/run/samba/winbindd/pipe" pid=1259 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
[ven. oct.  2 05:13:31 2015] audit: type=1400 audit(1443755612.993:40): apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/run/samba/nmbd/unexpected" pid=1264 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
[ven. oct.  2 05:14:54 2015] audit: type=1400 audit(1443755695.317:41): apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/run/samba/nmbd/unexpected" pid=1264 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
[ven. oct.  2 05:17:16 2015] audit: type=1400 audit(1443755837.697:42): apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/run/samba/nmbd/unexpected" pid=1264 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
[ven. oct.  2 05:19:14 2015] audit: type=1400 audit(1443755955.933:43): apparmor="DENIED" operation="connect" profile="/usr/bin/freshclam" name="/run/samba/nmbd/unexpected" pid=1302 comm="freshclam" requested_mask="wr" denied_mask="wr" fsuid=107 ouid=0
[ven. oct.  2 05:20:40 2015] audit: type=1400 audit(1443756041.249:44): apparmor="DENIED" operation="connect" profile="/usr/bin/freshclam" name="/run/samba/nmbd/unexpected" pid=1302 comm="freshclam" requested_mask="wr" denied_mask="wr" fsuid=107 ouid=0
[ven. oct.  2 05:21:39 2015] audit: type=1400 audit(1443756100.189:45): apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/run/samba/nmbd/unexpected" pid=1264 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
[ven. oct.  2 05:22:05 2015] audit: type=1400 audit(1443756126.565:46): apparmor="DENIED" operation="connect" profile="/usr/bin/freshclam" name="/run/samba/nmbd/unexpected" pid=1302 comm="freshclam" requested_mask="wr" denied_mask="wr" fsuid=107 ouid=0
[ven. oct.  2 05:23:30 2015] audit: type=1400 audit(1443756211.881:47): apparmor="DENIED" operation="connect" profile="/usr/bin/freshclam" name="/run/samba/nmbd/unexpected" pid=1302 comm="freshclam" requested_mask="wr" denied_mask="wr" fsuid=107 ouid=0
[ven. oct.  2 05:24:56 2015] audit: type=1400 audit(1443756297.197:48): apparmor="DENIED" operation="connect" profile="/usr/bin/freshclam" name="/run/samba/nmbd/unexpected" pid=1302 comm="freshclam" requested_mask="wr" denied_mask="wr" fsuid=107 ouid=0
[ven. oct.  2 05:25:16 2015] audit: type=1400 audit(1443756317.477:49): apparmor="DENIED" operation="connect" profile="/usr/sbin/slapd" name="/run/samba/winbindd/pipe" pid=1740 comm="slapd" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
[ven. oct.  2 05:26:16 2015] audit: type=1400 audit(1443756377.513:50): apparmor="DENIED" operation="connect" profile="/usr/bin/freshclam" name="/run/samba/nmbd/unexpected" pid=1302 comm="freshclam" requested_mask="wr" denied_mask="wr" fsuid=107 ouid=0
[ven. oct.  2 05:30:01 2015] audit: type=1400 audit(1443756602.909:51): apparmor="DENIED" operation="connect" profile="/usr/sbin/ntpd" name="/run/samba/nmbd/unexpected" pid=1264 comm="ntpd" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
[ven. oct.  2 05:42:04 2015] init: plymouth-upstart-bridge main process ended, respawning

#2 Mis à jour par Emmanuel IHRY il y a plus de 8 ans

  • Assigné à mis à Benjamin Bohard

#3 Mis à jour par Emmanuel IHRY il y a plus de 8 ans

  • Statut changé de Nouveau à En cours

#4 Mis à jour par Emmanuel IHRY il y a plus de 8 ans

  • Restant à faire (heures) changé de 8.0 à 4.0

Après analyse, l'origine du pb a été localisé en deux temps :
- en enlevant dans nsswitch.conf la référence à windbind pour "group", le boot se passe correctement
- en conservant la configuration d'origine nsswitch.conf (ldap + winbind), l'ecdl boot en 25 secondes et est opérationnel à condition d'ouvrir le FW

--> Suite à donner : voir quelle règle IP table pose problème ou laquelle àjouter

#5 Mis à jour par christophe guerinot il y a plus de 8 ans

quelques bribes d'éléments

- lors du démarrage du serveur, les services samba sont lancés lors du montage des systèmes de fichiers et du démarrage des services réseau

il semble que le service samba-ad-dc ne se lance pas

dans /var/log/boot.log

 * Starting SMB/CIFS File and Active Directory ServerESC[94G[ESC[31mfailESC[39;49m]

autre élément
après lecture de la sortie 'dmesg'

si un certain nombre de services, sur lesquels le boot prennait du temps, sont supprimés au démarrage (ntpd, lancement de ntpdate, slapd, vnstat ainsi que samba-ad-dc) et que le démarrage du service winbind est placé lors de l'exécution du démarrage des services dans /etc/rc2.d/

après le lancement de bastion avec /etc/rc2.d/S95winbind

le serveur boot normalement mais le service winbind n'arrive pas se lancer

voir la demande #13352 sur l'eSbl

l'eSbl n'ayant pas les paquets linss-ldap ou libnss-ldapd d'installés, il semblerait qu'il y est un dysfonctionnement entre bastion et l'installation du paquet libnss-winbind

je joins les sorties '/var/log/boot.log=' et '/dmesg'

#6 Mis à jour par Emmanuel IHRY il y a plus de 8 ans

  • Tâche parente changé de #13012 à #13463

#7 Mis à jour par Daniel Dehennin il y a plus de 8 ans

Il faudrait vérifier le contenu du fichier /usr/lib/eole/forteresse.sh.

#8 Mis à jour par Daniel Dehennin il y a plus de 8 ans

Daniel Dehennin a écrit :

Il faudrait vérifier le contenu du fichier /usr/lib/eole/forteresse.sh.

Tester avec le script suivant pour avoir des LOG:

#!/bin/sh

#------------------------------------------------------------------------
# forteresse.sh - Put the current server in fortress mode
# Everything is rejected except SSH for authorized networks
#
# Copyright © 2014 Pôle de compétences EOLE <eole@ac-dijon.fr>
#
# License CeCILL:
#  * in french: http://www.cecill.info/licences/Licence_CeCILL_V2-fr.html
#  * in english http://www.cecill.info/licences/Licence_CeCILL_V2-en.html

# Define LSB log_* functions.
# Depend on lsb-base (>= 3.2-14) to ensure that this file is present
# and status_of_proc is working.
. /lib/lsb/init-functions

FIREWALL_ENABLED=false

# Check if parameter is current interface
# If ${IFACE} is undef then match all interfaces
is_iface() {
    [  -z "${IFACE}" -o "${IFACE}" = "${1}" ]
}

forteresse_start() {
    if [ -n "${IFACE}" -a "${MODE}" != 'start' ]
    then
        # From if-down script
        exit 0
    fi

    if [ -n "${IFACE}" -a  "${FIREWALL_ENABLED}" = 'false' ]
    then
        # From if-up script with firewall disabled
        log_warning_msg "Pare-feu désactivé, mode forteresse inactif." 
        exit 0
    fi

    if [ -n "${IFACE}" -a "$(runlevel)" != "unknown" ]
    then
        # From if-up script in non booting mode
        exit 0
    fi

    # Either from ifup with firewall enabled or direct call
    if is_iface "lo" 
    then
        log_begin_msg "Réinitialisation du pare-feu" 
        ## Reinitialisation des chaines
        /sbin/iptables -F
        /sbin/iptables -t nat -F
        ## on vide les regles utilisateurs
        /sbin/iptables -t nat -X
        /sbin/iptables -X
        ## mise en place de la politique par defaut
        /sbin/iptables -P INPUT DROP
        /sbin/iptables -A INPUT -j LOG --log-prefix "INPUT LOG: " 
        /sbin/iptables -P OUTPUT ACCEPT
        /sbin/iptables -A OUTPUT -j LOG --log-prefix "OUTPUT LOG: " 
        /sbin/iptables -P FORWARD DROP
        /sbin/iptables -A FORWARD -j LOG --log-prefix "FORWARD LOG: " 
        ## lo ok
        /sbin/iptables -A INPUT -i lo -j ACCEPT
        #Supprime les set ipset
        if [ $(command -v ipset) ]
        then
            ipset -n list | while read setname; do
                ipset flush "$setname";
                ipset destroy "$setname";
            done
        fi
    fi

    if is_iface "eth0" 
    then
        log_begin_msg "Activation du mode forteresse sur eth0" 
        /sbin/iptables -A INPUT -i eth0 -p tcp --syn -s 0/0 --dport ssh -m state --state NEW -j ACCEPT
        /sbin/iptables -A INPUT -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
    fi

    if is_iface "eth0" 
    then
        # Manage LXC if any
        if [ -x /usr/share/eole/bastion/data/90-lxc_rules ]
        then
            /usr/share/eole/bastion/data/90-lxc_rules
        fi
    fi
}

#9 Mis à jour par christophe guerinot il y a plus de 8 ans

quelques questionnements

- dans les dicos 20_fichier-primaire.xml (et 21_fichier-membre.xml) le service winbind n'est pas lancé avec la directive method='upstart'. Est-ce que cela peut avoir un impact ?

- un service (/etc/init.d/samba-ad-dc) qui semble plutôt dédié au fonctionnement du contrôleur en mode 'AD' est lancé au démarrage . Est-ce que cela peut avoir également un impact ? De même la variable 'activer_ad_smb' pourrait être définie en mode 'AD' est-ce que cela pourrait être également utile avec un fonctionnement s'appuyant sur le service winbind ?

#10 Mis à jour par christophe guerinot il y a plus de 8 ans

remontées des log

#11 Mis à jour par christophe guerinot il y a plus de 8 ans

test à partir d'un scribe

avec activer_winbind à 'oui' le boot est plus rapide que sur l'ecdl mais prend quand même 9 mn

- procédure mise en oeuvre sur le scribe

installation à partir de l'iso eole-2.5.1b1-alternate-amd64.iso

à l'installation, de base

root@scribe25-164:~# dpkg -l|grep libnss
ii  libnss-ldap:amd64                    264-2.2ubuntu4.14.04.1              amd64        NSS module for using LDAP as a naming service
ii  libnss-winbind:amd64                 2:4.1.6+dfsg-1ubuntu2.14.04.9       amd64        Samba nameservice integration plugins
(...)

root@scribe25-164:~# dpkg -l|grep libpam
(...)
ii  libpam-ldap:amd64                    184-8.5ubuntu3                      amd64        Pluggable Authentication Module for LDAP
(...)
ii  libpam-systemd:amd64                 204-5ubuntu20.14                    amd64        system and service manager - PAM module
ii  libpam-winbind:amd64                 2:4.1.6+dfsg-1ubuntu2.14.04.9       amd64        Windows domain authentication integration plugin
(...)

désinstallation des paquets 'à la hussarde'

~# dpkg --purge --force-depends libnss-ldap

~# rm -rf /var/lib/libnss-ldap

~# dpkg --purge --force-depends libpam-ldap


lors de la désinstallation du paquet 'libpam-ldap' réponse 'oui' sur la reconfiguration des fichiers pam common-*

récupération des paquets libpam-ldapd_0.8.13-3ubuntu1_amd64.deb , nslcd_0.8.13-3ubuntu1_amd64.deb et libnss-ldapd_0.8.13-3ubuntu1_amd64.deb sur le serveur

installation des paquets libxxx-ldapd

# dpkg -i --force-depends libpam-ldapd_0.8.13-3ubuntu1_amd64.deb

# dpkg -i --force-depends nslcd_0.8.13-3ubuntu1_amd64.deb

# dpkg -i --force-depends libnss-ldapd_0.8.13-3ubuntu1_amd64.deb

lors de l'installation du paquet 'libnss-ldapd' conserver group passwd shadow

dans le doute relancer l'instanciation si le serveur a déjà été instancié

~# instance

le scribe a l'air fonctionnel et redémarre normalement

Configuration avec l'ajout du service winbind

rendre le paramétrage de activer_winbind accessible en désactivant la ligne suivante

root@scribe25-164:~# cat /usr/share/eole/creole/dicos/29_scribehorus.xml|grep winbind
            <!-- <variable name='activer_winbind' redefine='True' hidden='True' /> -->
root@scribe25-164:~#

~# CreoleSet activer_winbind oui

~# reconfigure

le boot est alors anormalement long (environ 9mn sur ma vm)

je joins boot.log et un bout de dmesg (les remontées iptables-debug.log suite à adaptation du fichier '/usr/lib/eole/forteresse.sh' font 18Mo, le fichier n'est donc pas joint, mais il y a quelques trace du coup dans les retours via dmesg)

#12 Mis à jour par christophe guerinot il y a plus de 8 ans

lors de l'arrêt de serveur, l'exécution du script suivant permet de contourner le problème au redémarrage du serveur

#!/bin/sh

CreoleSet activer_firewall non

CreoleCat -t hosts.allow -o /etc/hosts.allow
CreoleCat -t hosts.deny -o /etc/hosts.deny
CreoleCat -t forteresse.sh -o /usr/lib/eole/forteresse.sh
CreoleCat -t 50-nat_rules -o /usr/share/eole/bastion/data/50-nat_rules

exit 0

au démarrage il faut remettre d'aplomb les fichiers avant le démarrage du service bastion

via les commandes

CreoleSet activer_firewall oui

CreoleCat -t hosts.allow -o /etc/hosts.allow
CreoleCat -t hosts.deny -o /etc/hosts.deny
CreoleCat -t forteresse.sh -o /usr/lib/eole/forteresse.sh
CreoleCat -t 50-nat_rules -o /usr/share/eole/bastion/data/50-nat_rules

#13 Mis à jour par christophe guerinot il y a plus de 8 ans

sur l'ecdl il ne semble pas pas que le blocage soit lié aux fichiers '/etc/hosts.allow', 'etc/hosts.deny' et '/usr/share/eole/bastion/50-nat_rules'

seul le contenu de la variable 'activer_firewall' qui doit être à 'non' et la templétisation du fichier '/usr/lib/eole/forteresse.sh' suffit à contourner les problèmes de boot

~# diff forteresse.sh.sansfirewall forteresse.sh.avecfirewall 
18c18
< FIREWALL_ENABLED=false
---
> FIREWALL_ENABLED=true
75c75
<         /sbin/iptables -A INPUT -i eth0 -p tcp --syn -s 0/0 --dport ssh -m state --state NEW -j ACCEPT
---
>         /sbin/iptables -A INPUT -i eth0 -p tcp --syn -s 0.0.0.0/0.0.0.0 --dport ssh -m state --state NEW -j ACCEPT

la solution de contournement consiste à

(1) à l'arrêt du serveur

exécuter les deux commandes

CreoleSet activer_firewall non
CreoleCat -t forteresse.sh -o /usr/lib/eole/forteresse.sh

(2) lors de la phase de redémarrage des services

repositionner la variable 'activer_firewall' à 'oui' et retemplétiser le fichier '/usr/lib/eole/forteresse.sh'

afin que le pare-feu soit fonctionnel suite au démarrage du serveur

#14 Mis à jour par christophe guerinot il y a plus de 8 ans

plusieurs problèmes sont susceptibles de jouer lors la lenteur au boot
soit suite à l'utilisation du paquet libnss-winbind, soit un comportement inhérent à l'ecdl depuis l'origine du projet)

(1) lié à l'installation du paquet libnss-winbind

si l'ecdl est configuré en mode secours 'local' (ecdl_bascule_ldap -l) , le comportement du scribe (avec libnss-ldapd + activer_winbind à 'oui') et de l'ecdl est identique
à quelques secondes près le boot prend un peu plus de 8 mn

petite différence: le scribe continue d'avoir le même comportement au boot malgrés le fait de passer activer_firewall à 'non'

piste à voir ??? si on regarde le comportement du script 'forteresse.sh'

- sur l'ecdl le script s'exécute une première fois lors du montage des partitions (moyennant une astuce fournie par Daniel pour générer des traces le script est exécuté avant la mise à jour des fichiers /home/aquota.group /home/aquota.user)
puis le script est à nouveau exécuté deux autres fois au boot

- sur le scribe le script n'est exécuté qu'une seule fois, avant la mise à jour des fichiers /home/aquota.group /home/aquota.user et ensuite le serveur rame pendant 8mn

(2) lié au comportement inherent à l'ecdl et du fait d'utiliser libnss-ldapd et des paquets samba mouture samba4

2a - si l'ecdl est configuré avec un accès au ldap central (ecdl_bascule_ldap -c) et que l'on active le pare-feu (activer_firewall à 'oui'), au 8 mn lié au problème précédent s'ajoute un temps de boot de 40 - 50 mn supplémentaires du fait que la base ldap n'est pas sur le serveur (Daniel suspecte un pb dns) - si le pb précédent est réglé celui-ci devrait pouvoir l'être également ... ou pas :(
2b - si on change malencontreusement l'@IP du controleur , et que l'adresse n'est pas autorisée à accéder au ldap centralisé la configuration de l'ecdl dès ses premières versions présente des lenteurs au boot
en version1 , il suffisait d'avoir sous la main un cache pour les groupes '/var/cache/nscd/group' pour contourner le pb même si le service nscd n'était pas lancé
il aurait fallu surement configurer nss/ldap (/etc/ldap.conf) pour régler le pb, mais le cas ne se posait que dans le cas où l'ecdl avait une mauvaise adresse IP !

#15 Mis à jour par Emmanuel IHRY il y a plus de 8 ans

  • Tâche parente changé de #13463 à #13770

#16 Mis à jour par christophe guerinot il y a plus de 8 ans

La solution de contournement consistant à désactiver le pare-feu lors du reboot ne fonctionne pas dans le cas où 'activer_cache_dns' est à 'oui'.

Puisque de toute façon il est nécessaire de relancer le service winbind après le redémarrage du serveur pour pouvoir récupérer les comptes et groupes d'éventuel(s) domaine(s) approuvé(s) ( voir #14019 ), la solution de contournement la plus simple reste de désactiver le lancement du service winbind lors du boot ( voir #14005 )

#17 Mis à jour par Thierry Bertrand il y a plus de 8 ans

  • Assigné à changé de Benjamin Bohard à christophe guerinot
  • Tâche parente changé de #13770 à #14160

#18 Mis à jour par Emmanuel IHRY il y a plus de 8 ans

  • Tâche parente changé de #14160 à #14134

#19 Mis à jour par christophe guerinot il y a plus de 8 ans

Le problème de fond : le service winbind génère un dysfonctionnement au démarrage d'un serveur eole si le paquet libnss-winbind est installé (le paquet libnss-winbind est indispensable pour récupérer les comptes des domaines approuvés)

Les solutions de contournement fonctionnent sur l'eCdl (désactivation du lancement du service winbind lors du démarrage / redémarrage du serveur), le traitement de la demande pourrait être basculé dans 'boîte à idée' sachant que le problème ne concerne pour le moment pas les autres modules eole (le module scribe n'utilise pas winbind).

En eole 2.6 (controleurs AD) le problème ne devrait pas se poser.

#20 Mis à jour par Emmanuel IHRY il y a plus de 8 ans

  • Tâche parente changé de #14134 à #14487

#21 Mis à jour par Emmanuel IHRY il y a plus de 8 ans

  • Catégorie mis à Version majeure

déplacé dans bac à idé

#22 Mis à jour par Emmanuel IHRY il y a plus de 8 ans

  • Début changé de 21/09/2015 à 21/01/2016
  • Tâche parente #14487 supprimé

#23 Mis à jour par Thierry Bertrand il y a environ 8 ans

  • Statut changé de En cours à Ne sera pas résolu
  • Assigné à christophe guerinot supprimé
  • Version cible sprint 2016 01-03 - Equipe PNE-SR supprimé
  • Restant à faire (heures) changé de 4.0 à 0.0

incompatibilité de winbind.

EN pas impactée, possibilité de contournement en 2.5

Pb de fond, firewall & dns

Formats disponibles : Atom PDF