Sunday, January 07, 2024
support@conference.yunohost.org
January
Mon Tue Wed Thu Fri Sat Sun
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19 20
21
22
23
24
25
26
27
28
29
30
31
       
             

[08:58:06] <Avatar for Norbert> >> <@gamaaim:matrix.org> How to solve this problem in this case?
>
> Here is the solution that was given in the post, but it seems that Aleks (he/him/il/lui) totally forgot about it
>
>> We should probably include a fix upstream but in the meantime a clean solution I believe should be to run :
>>
>> systemctl edit yunohost-api
>>
>> You will enter a mode where you can edit an (initially empty) file
>>
>> In this file, add the following :
>>
>> [Service]
>> EnvironmentFile=/etc/environment
>>
>> You can save with Ctrl+X (it will ask confirmation, just press Y and Enter)
>>
>> Then run systemctl restart yunohost-api
>>
>> Not tested but that should do the trick …
>
> The simplest would be to integrate the possibility of using a proxy in yunohost webmin as suggested by the last comment on the forum

[10:51:01] <Ilario> Bonjour! j'ai un petit souci avec les courriels, cad je les recois mais quand je cherche d'en envoyer il s'affiche un message du tipe "not send" et le courriel ne sort pas. Le diagnostique ne signale rien de anormale. Avez vous une idée? merci bcp
[11:59:15] <tufek> Ilario: un coup de yunohost tools diagnosis et vérifier que ton FAI ne bloque pas le port 25?
[12:02:34] <Ilario> Merci le diagnostic donne tout bon comme mail, la chose drôle c'est que il marchait tout avant que je ferme la porte 22 et je configure une nouvelle porte pour ssh. En plus je ne reçoit plus les mail du diagnostic automatique.
[12:04:34] <tufek> Et tu as mis ssh sur quel port du coup? :) tu es chez quel FAI?
[13:59:34] <Ilario> Le fai c'est Eolo, le port c'est le même numéro des pompiers !
[14:20:56] <Ilario> Une nouveauté, depuis mon portable /e/ et k9, après avoir accepté la conf proposé relativement à des certificats, j'arrive à envoyer.
[15:43:57] <Chatpitaine Caverne> Merci beaucoup la commu pour la mise à disposition de Peertube V6.0.2🎉
[16:47:37] <clawfire> Hey there. Hope you all have a good weekend. I have a depreciation notice when I'm looking for update from YNH GUI (probably the same from CLI to be fair)

> W: http://forge.yunohost.org/debian/dists/bullseye/InRelease: Key is stored in legacy trusted.gpg keyring (/etc/apt/trusted.gpg), see the DEPRECATION section in apt-key(8) for details.

Any idea if I need to do something ?
[16:48:28] <clawfire> Hey there. Hope you all have a good weekend. I have a depreciation notice when I'm looking for update from YNH GUI (probably the same from CLI to be fair)

> W: http://forge.yunohost.org/debian/dists/bullseye/InRelease: Key is stored in legacy trusted.gpg keyring (/etc/apt/trusted.gpg), see the DEPRECATION section in apt-key(8) for details.

Any idea if I need to do something ?

My source.list look like this:
```
sources.list:deb http://mirrors.gandi.net/debian bullseye main
sources.list:deb-src http://mirrors.gandi.net/debian bullseye main
sources.list:deb http://security.debian.org/debian-security bullseye-security main
sources.list:deb-src http://security.debian.org/debian-security bullseye-security main
sources.list:deb http://mirrors.gandi.net/debian bullseye-updates main
sources.list:deb-src http://mirrors.gandi.net/debian bullseye-updates main
sources.list.d/extra_php_version.list:deb https://packages.sury.org/php/ bookworm main
sources.list.d/tailscale.list:deb https://pkgs.tailscale.com/stable/debian bullseye main
sources.list.d/yunohost.list:deb http://forge.yunohost.org/debian/ bullseye stable
```
[16:55:54] <shadowstorm1> Hello, I encounter an error importing files in trilium
[16:55:55] <shadowstorm1> https://aria.im/_matrix/media/v1/download/matrix.org/uPAmkCqXnzBCohAuHRApNjGw
[16:56:17] <clawfire> > <@clawfire:matrix.org> Hey there. Hope you all have a good weekend. I have a depreciation notice when I'm looking for update from YNH GUI (probably the same from CLI to be fair)
>
> > W: http://forge.yunohost.org/debian/dists/bullseye/InRelease: Key is stored in legacy trusted.gpg keyring (/etc/apt/trusted.gpg), see the DEPRECATION section in apt-key(8) for details.
>
> Any idea if I need to do something ?
>
> My source.list look like this:
> ```
> sources.list:deb http://mirrors.gandi.net/debian bullseye main
> sources.list:deb-src http://mirrors.gandi.net/debian bullseye main
> sources.list:deb http://security.debian.org/debian-security bullseye-security main
> sources.list:deb-src http://security.debian.org/debian-security bullseye-security main
> sources.list:deb http://mirrors.gandi.net/debian bullseye-updates main
> sources.list:deb-src http://mirrors.gandi.net/debian bullseye-updates main
> sources.list.d/extra_php_version.list:deb https://packages.sury.org/php/ bookworm main
> sources.list.d/tailscale.list:deb https://pkgs.tailscale.com/stable/debian bullseye main
> sources.list.d/yunohost.list:deb http://forge.yunohost.org/debian/ bullseye stable
> ```

Answering my own issue, but could be interesting for others: https://itsfoss.com/key-is-stored-in-legacy-trusted-gpg/ explains how to do it pretty well.
[16:58:36] <shadowstorm1> This error importing files into trilium does not occur on flatpak or other server-based trilium installations, but only with trilium installations from yunohost
[17:00:11] <shadowstorm1> I use the latest version of trilium which is offered by yunohost, I use the default configuration, but downloading attachments does not work
[17:05:00] <tituspijean> shadowstorm1: can you share the trilium and nginx service logs right after triggering the error?
[17:07:12] <tituspijean> use the yunopaste buttons.
[17:09:35] <shadowstorm1> The yunopaste button doesn't seem to work for me 🤔
[17:09:35] <tituspijean> how so?
[17:10:28] <shadowstorm1> When I press it, nothing happens, it doesn't generate a link
[17:12:39] <shadowstorm1> Can I capture logs directly from the terminal with termbin?
[17:15:19] <shadowstorm1> Here are the trilium logs https://termbin.com/z3cj
[17:23:21] <shadowstorm1> I have disconnected and connected several times but the yunopaste button still does not work
[17:43:46] <tituspijean> to be fixed with https://github.com/YunoHost-Apps/trilium_ynh/pull/60
[17:46:22] <shadowstorm1> > <@titus:pijean.ovh> to be fixed with https://github.com/YunoHost-Apps/trilium_ynh/pull/60

Was it a permissions issue?
[17:52:33] <Chatpitaine Caverne> shadowstorm1: you can see the modification in the nginx config here : https://github.com/YunoHost-Apps/trilium_ynh/pull/60/commits/bd7bf9946facb5e3dbd22d9d344b9b2db0802fe2
[17:53:41] <shadowstorm1> > <@chatpitaine:cirkau.art> shadowstorm1: you can see the modification in the nginx config here : https://github.com/YunoHost-Apps/trilium_ynh/pull/60/commits/bd7bf9946facb5e3dbd22d9d344b9b2db0802fe2

Okay, so it was definitely a yunohost bug. Glad to have helped identify a bug
[17:55:57] <tituspijean> for more information: https://yunohost.org/en/contribute
[17:59:01] <shadowstorm1> > <@titus:pijean.ovh> for more information: https://yunohost.org/en/contribute

It's complicated to contribute to yunohost if you're having fun blocking IP addresses. These are undemocratic methods and close to dictatorship ^^
[18:00:11] <tituspijean> c'est tout ce que je voulais savoir, merci
[18:02:24] <shadowstorm1> C'était aussi ce que je voulais savoir. Donc vous utilisez bien des backdoor dans yunohost pour capturer les IP ?
Car dans les logs que j'ai partagé il n'y avait aucun fragment d'adresse IP !
[18:03:20] <tituspijean> oui tout à fait. on a pu rentrer dans ton routeur et mettre à jour le firmware de ton linky avec un logiciel maison.
[18:03:45] <tituspijean> ou plus sérieusement, t'as qu'à nous laisser en paix.
[20:11:45] <laguill13> Bonsoir,
J'ai installé l'application code.
Je n'arrive pas accéder aux fichiers de configuration de mes autres applicaions. Il faut autoriser des paramètres pour éditer les fichiers de config ?
[20:32:34] <alcapurrias [she/her]> Hello, I can't renew my Let's Encrypt certificates. They all come back with a 403 error. Here are the logs: https://paste.yunohost.org/raw/ovohobicuw
[20:38:40] <Aleks (he/him/il/lui)> hmm are you in a special context like a reverse proxy maybe ? Do you have anything specific installed on that domain ?
[20:39:30] <Aleks (he/him/il/lui)> or could it be that you manually tweaked the nginx config or unix permissions maybe ?
[20:40:25] <alcapurrias [she/her]> None of my domains are renewing, they all have the same error. I don't do anything special, I don't know any programming things
[20:46:21] <Aleks (he/him/il/lui)> hmokay, in that case if you have access to command line (for example via SSH), I would suggest sharing the result of `sudo namei -l /var/www/.well-known/acme-challenge-public/` to see if there's any permission issue for some reason
[20:50:41] <Aleks (he/him/il/lui)> should display something like https://paste.yunohost.org/raw/cuwohajoqe
[20:52:23] <alcapurrias [she/her]> Yes I can do that, one moment
[20:54:05] <alcapurrias [she/her]> Ooh okay mine are showing differently:

f: /var/www/.well-known/acme-challenge-public/
drwxr-xr-x root root /
drwxr-xr-x root root var
drwxrwxr-x root root www
drwxrwxr-x root root .well-known
drw-r-x--- root www-data acme-challenge-public
[20:54:30] <Aleks (he/him/il/lui)> hmmmokay dunno how that happened ...
[20:54:56] <Aleks (he/him/il/lui)> maybe some app you installed recently that tweaks stuff idk ...
[20:55:48] <Aleks (he/him/il/lui)> anyway this is not a big deal to fix (though still would be nice to understand), you can probably run `chmod 755 /var/www/.well-known/acme-challenge-public/` and retry the cert install
[21:02:15] <alcapurrias [she/her]> Unfortunately it's still doing the same thing. The first namei command has the same output too
[21:03:34] <Aleks (he/him/il/lui)> uuuh wut
[21:04:24] <Aleks (he/him/il/lui)> or maybe you're not root and need to add sudo ?
[21:04:25] <Aleks (he/him/il/lui)> `sudo chmod 755 /var/www/.well-known/acme-challenge-public/` ?
[21:11:18] <alcapurrias [she/her]> I did have it on root but I just tried with sudo too. Same thing. If I were to install fresh and restore from a backup, I'm guessing that it will still have these broken permissions right?
[21:13:45] <alcapurrias [she/her]> Oh wait the output did change:

f: /var/www/.well-known/acme-challenge-public/
drwxr-xr-x root root /
drwxr-xr-x root root var
drwxr-xr-x root root www
drwxrwxr-x root root .well-known
drwxr-xr-x root www-data acme-challenge-public
[21:16:10] <@err404:matrix.numericore.com> take care about execution bit
[23:08:40] <alcapurrias [she/her]> I did a fresh install of Yunohost and just restored the apps, everything is fine now