kentonv changed the topic of #sandstorm to: Welcome to #sandstorm: home of all things Say hi! | Have a question but no one is here? Try asking in the discussion group: | Public logs at
Kbuzz has joined #sandstorm
Kbuzz has quit [Ping timeout: 248 seconds]
Kbuzz has joined #sandstorm
<kentonv> this Intel hardware bug thing sure is exciting
<TimMc> Oh, which one?
<mokomull> I kind of wanted to screw around with it and see what I can figure out, but people smarter than me will be publishing in a couple days anyway, it seems.
<kentonv> Linux seems to be implementing a huge change to fundamental memory management in a huge hurry
<kentonv> it's estimated to reduce overall performance by ~5%, yet it's being rushed out and backported as we speak
<kentonv> ... and it's only going to be enabled for Intel CPUs, non AMD.
<mokomull> and merged in like an rc5 or rc6 IIRC
<kentonv> connecting the dots, it looks like Intel CPUs have a bug that lets an unprivileged process read arbitrary physical memory through the kernel memory mappings (which are supposed to be inaccessible in user mode)
<kentonv> so the solution is to actually switch page tables when switching between user and kernel modes
<kentonv> so that the kernel is not even mapped in user mode
<kentonv> if you have users you don't trust on your Sandstorm server, you're gonna want to update the kernel as soon as the updates become available from your distro
<kentonv> unfortunately the sandbox can't protect you from this one
<kentonv> (that is, if you have users you don't trust whom you've permitted to install their own apps -- probably not very common for self-hosted servers)
jemc has quit [Ping timeout: 240 seconds]
<mokomull> hm, looks like it's backported to 4.14 so far, but not older. Kind of a fiddly bit to backport...
<kentonv> they're working on it.
<mokomull> I assume as much.
<mokomull> I'd just gone googling around to see what the status was :)
harish_ has quit [Ping timeout: 248 seconds]
isd has joined #sandstorm
TimMc has quit [Ping timeout: 260 seconds]
TimMc has joined #sandstorm
<kentonv> mokomull, it looks like 4.4 and 4.9 may have received the patchset (or at least part of it) today
<TimMc> Ahhh, this thing, I'd heard some mutterings about it.
<TimMc> "Major kernel changes written in a hurry" makes me nervous; I hope the cure is not worse than the disease.
<kentonv> well, you could always go buy an AMD processor if you want to avoid the whole thing...
harish_ has joined #sandstorm
harish_ has quit [Ping timeout: 272 seconds]
isd has quit [Quit: Leaving.]
harish_ has joined #sandstorm
jemc has joined #sandstorm
TimMc has quit [Ping timeout: 240 seconds]
TimMc has joined #sandstorm
NoGo has joined #sandstorm
NoGo has quit [Client Quit]
NoGoGoats has joined #sandstorm
<NoGoGoats> hello!
isd has joined #sandstorm
<kentonv> hi
<Kbuzz> allo
<NoGoGoats> I'm trying to get started with sandstorm. I can't seem to connect to the server via the URL. Does anybody have a moment to help me troubleshoot?
<NoGoGoats> Been working on this for number of hours and have been utilizing as a guide
<kentonv> ok. First, did you choose to use
<NoGoGoats> yes, and Whois reports are correct public IP address from my server
<kentonv> ok. Where is your server physically? E.g. in a cloud hosting service, or in your house, or... ?
<NoGoGoats> an in-house server. Ports on the router are open to the local IP of the server 443, 80, 6080, 30025
<NoGoGoats> The only thing special is it Virtualized through proxmox
Kbuzz has quit [Remote host closed the connection]
<kentonv> if you try to visit the *internal* IP of the server on port 80 or 443, does it respond? (presumably with an error due to wrong hostname)
rolig has quit [Ping timeout: 256 seconds]
<NoGoGoats> I'll double check and AFK
pie_ has quit [Ping timeout: 248 seconds]
rolig has joined #sandstorm
<NoGoGoats> okay I'm back
<NoGoGoats> Local IP goes to "Sandstorm static publishing needs further configuration (or wrong URL)"
<NoGoGoats> so I believe it does respond
<NoGoGoats> @kentonv
<NoGoGoats> @kentonv
<NoGoGoats> kentonv
<NoGoGoats> @kentonv thanks for helping me out on this.
<kentonv> ok, so it seems the problem is that your router isn't routing the public IP to the internal one
<kentonv> NoGoGoats, many home routers have a problem where they won't correctly route a connection addressed to the public IP if the connection comes from the internal network. So it may be that you only can't see your server from your own network, but if you tried to access it from outside, you'd see it.
<NoGoGoats> that's my guesstimate as well. That's where sandstorm is Virtualized Via proxmox.but that is reachable via a dedicated internal IP address which my router is using for port forwarding. For instance I can SSH fine using the same internal IP for the VM.
<kentonv> maybe try accessing the sandcats domain from your phone, with wifi turned off, and see if it gets through
<NoGoGoats> okay I'll give it a shot I'll try it on my cell phone.
<kentonv> :)
<NoGoGoats> it looks like that did the trick. I bet clearing out my browser cash will resolve this issue.
<NoGoGoats> if it wasn't a routing problem because I tried it with Wi-Fi enabled first. :) thanks so much for your help!
NoGoGoats has quit [Quit: - A hand crafted IRC client]
NoGoGoats has joined #sandstorm
NoGoGoats has quit [Client Quit]
isd has quit [Quit: Leaving.]
TimMc has quit [Ping timeout: 248 seconds]
TimMc has joined #sandstorm
harish_ has quit [Ping timeout: 256 seconds]
TimMc has quit [Ping timeout: 248 seconds]
TimMc has joined #sandstorm
n8a has quit [Ping timeout: 265 seconds]
n8a has joined #sandstorm
n8a has quit [Ping timeout: 252 seconds]
n8a has joined #sandstorm
gambatte1 has quit [Ping timeout: 248 seconds]
gambatte has quit [Ping timeout: 240 seconds]
gambatte2 has quit [Ping timeout: 255 seconds]
gambatte has joined #sandstorm
gambatte1 has joined #sandstorm
TimMc has quit [Ping timeout: 272 seconds]
TimMc has joined #sandstorm
gambatte2 has joined #sandstorm
Telesight has joined #sandstorm
jemc has quit [Ping timeout: 268 seconds]
harish_ has joined #sandstorm
ccx^xmpp has left #sandstorm ["Disconnected: Replaced by new connection"]
ccx^xmpp has joined #sandstorm
<logicfish> hi, i can't get this to work - when i enter-grain there's no permisions to view files under /var/lib
n8a has quit [Ping timeout: 252 seconds]
n8a has joined #sandstorm
TimMc has quit [Ping timeout: 248 seconds]
TimMc has joined #sandstorm
pie_ has joined #sandstorm
ccx^xmpp has left #sandstorm ["Disconnected: Replaced by new connection"]
ccx^xmpp has joined #sandstorm
pie_ has quit [Ping timeout: 240 seconds]
TimMc has quit [Ping timeout: 265 seconds]
TimMc has joined #sandstorm
pie_ has joined #sandstorm
aundro has joined #sandstorm
aundro has left #sandstorm [#sandstorm]
guido has quit [Ping timeout: 268 seconds]
guido has joined #sandstorm
jemc has joined #sandstorm
jemc has quit [Ping timeout: 240 seconds]
TimMc has quit [Ping timeout: 248 seconds]
TimMc has joined #sandstorm
isd has joined #sandstorm
Kbuzz has joined #sandstorm
Kbuzz has quit [Ping timeout: 264 seconds]
isd has quit [Quit: Leaving.]
xet7 has joined #sandstorm
isd has joined #sandstorm
jemc has joined #sandstorm
TimMc has quit [Ping timeout: 240 seconds]
TimMc has joined #sandstorm
samba_ has joined #sandstorm
jemc has quit [Quit: WeeChat 1.9]
jemc has joined #sandstorm
TimMc has quit [Ping timeout: 264 seconds]
samba_ has quit [Ping timeout: 260 seconds]
TimMc has joined #sandstorm
samba_ has joined #sandstorm
Telesight has quit [Remote host closed the connection]
samba_ has quit [Ping timeout: 248 seconds]
isd has quit [Quit: Leaving.]
samba_ has joined #sandstorm
samba_ has quit [Quit: WeeChat 2.0.1]
isd has joined #sandstorm
samba_ has joined #sandstorm
samba_ has quit [Quit: WeeChat 2.0.1]
samba_ has joined #sandstorm
TimMc has quit [Ping timeout: 256 seconds]
TimMc has joined #sandstorm