Wednesday, July 26, 2006

Sweet Irony

I’ve just released HAL 0.5.7.1 “Unmaintained piece of crap” and all vendors should upgrade as Linux kernels later than 2.6.17 will break HAL 0.5.7 (e.g. HAL will break in hardware detection, not the kernel). It should be a smooth upgrade and credit goes to Kay Sievers for the patches.




Reflection
Introspection


Just a few hours after my last entry, Jonathan Corbet of LWN found me at OLS and said it wasn’t LWN badmouthing HAL, he was just reporting what was going on at the kernel summit. So, sorry if I made it sound like it was LWN’s fault, it wasn’t, I do believe in free press and LWN is just an awesome resource. Oh, I just find the whole “unmaintained piece of crap” thing slightly amusing (hence the release name for 0.5.7.1) - the community around HAL is alive and well even though I’m not presently around doing HAL stuff as much as I like.

Thursday, July 20, 2006

Linux Symposium

I appear to be in Ontario, Canada. More specifically I’m in Ottawa though hours last night was spent at a bar in Quebec.



In Logan's terminal 3
In Logan’s terminal 3 enroute to OLS


Yesterday, Kay and I gave a talk on Dynamic Device Handling on the Modern Desktop and I think it was well received. Yeay!


Oh, and I’ve even got to say that hal-device-manager (the small python GTK+ app for viewing the hal device objects and their properties) was an “unmaintained piece of crap” alluding in a funny way to the recent LWN article badmouthing HAL. Some people in the audience laughed. Lots of excellent questions too. Good times.


I’ve uploaded the slides from mine and Kay’s talk here. Enjoy.

Thursday, July 13, 2006

PulseAudio and GNOME

Talked briefly to Monty yesterday about PulseAudio and how it would fit into GNOME. Here are some notes, I may be way off, but I thought it would be good to blog them anyway.



Monty!
Monty making an elaborate point about mixing stuff



  • Multiple Soundcard Configuration: The gstreamer sink for PulseAudio should use the same gconf settings as for the gstreamer-hal-gconf sink as discussed here. Then we would be able to reuse the same dialog which would be nice. I have no idea whether this is feasible, desirable or possible in the context of PulseAudio.. But I thought I’d mentioned it anyway, it makes sense to me and… IIRC, a number of applications such as Totem and Ekiga is moving to selecting outputs (using gstreamer) based on whether they output “Sound Events”, “Music or Movies” or “Audio/Video conferencing”.

  • Power Savings: To be honest, I’m not sure whether PulseAudio runs as a system daemon or in the desktop session or whether it’s configurable (sorry, haven’t done my homework). But surely, to me, it needs to run in the desktop session. It should talk to gnome-power-manager, via D-BUS, and keep track of whether the user “prefers power savings over performance” (yes, this is a user preference which defaults to on when running on battery and off when on AC).
    So if “prefers power savings over performance” is enabled as a desktop session wide setting (or if it changes state - it’s a live variable so need to listen to D-BUS signals from g-p-m), PulseAudio should close the file descriptor to files in /dev/audio when there is silence so the kernel drivers can put the sound card(s) to sleep. Not only that, if the sound card is used only for output it should open with O_RDONLY so parts of the sound card can be powered down. Specifically for projects such as OLPC this is important and Jaya Kumar already done the kernel side of this.
    Sure, when the sound card is turned on again there is a slight pop, but users for which this is the end of the world… they can tweak the setting in g-p-m or perhaps use a specific PulseAudio setting to override. But by default, PulseAudio should ask g-p-m so we can suspend sound cards on battery when not used. It’s about saving energy.. think of the kids, Der GrĂ¼ne Punkt, EnergyStar and all that! :-)



In other news, Mitra got a Macbook and she seems thrilled about it so far. Also, I didn’t know that Mitra’s mom have been in outer space.

Thursday, July 6, 2006

GUADEC recap

Got back from GUADEC and Spain on Sunday. Nice conference; I liked the touch with seven days instead of three even though it was a bit exhausting in the end. I’ve also got sick around Saturday so spent that day in bed in my hotel room before traveling back Sunday. As a result of all this, I’m way behind on mail so to those who I owe a reply, hang in there, I’ll get back to you eventually.



Robert and Joey in what could be a movie poster


Robert and Joey as batshit insane movie stars?



I’ve now uploaded the slides from my talk (ODP, PDF).



Bummed out
Taking a break from the action at the Fluendo party


I enjoyed the 4th of July fireworks from my balcony in Somerville, MA overlooking Boston



Zeppelin?
Zeppelin just after dropping it’s payload on Boston, MA?


All my GUADEC pictures are available here.

Monday, June 26, 2006

At GUADEC

Made it to Spain on Friday, surprisingly Delta brought me there at 7:45am as scheduled. Spent Friday walking around Barcelona with Kay and his girlfriend. Nice but a bit exhausting given we were out until 8pm. Made it to Vilanova late Friday night and, hours later, was surrounded by nice people and cold beer. Good times. Fell asleep around 1-2am.


I can’t believe noone else at GUADEC blogged about this guy at the registration desk:



GUADEC registration desk


“Pick me up”



I haven’t blogged for quite some time, should get back in the game. Despite that lots of things have happened in work, HAL, PolicyKit and also RL that I will need to report at some time. Now to get some lunch and see some talks!

Sunday, April 2, 2006

System Configuration

So once again the topic of system configuration and Elektra (aka LinuxRegistry) has come up on fedora-devel-list and since I know most people even on the list don’t keep up because of the sheer volume, I’m going to use my blog to link to my response.



WCC2006-20060401-032
Denmark vs. Japan at WCC 2006 - EOS 20D and 70-200mm f/2.8 lens @ ISO 400


It shouldn’t be a surprise to people knowing me that I consider myself a UNIX hater. In fact, this whole thread on f-d-l made me realize that the with regards to system configuration you really only want two things: session-wide and site-wide configuration. Maybe it’s time to open a CafePress store and pimp shirts and stickers with the mottos a’la # rm -rf /etc. Seriously.


Received my MacBook Pro last week and I’m psyched. Now to get Fedora installed :-) .

Tuesday, March 7, 2006

System-wide Lockdown and Usability

I wrote some time ago about how most modern Linux distributions deals with with granting unprivileged users additional privileges when they are logged in at the console. Stuff like allowing them to access removable disks, power down the system and so forth - Project Utopia stuff, that whole story.


While this is great for the home user, stuff Just Works, it’s not always ideal in more controlled environments such as call centers, university settings, Internet Cafes or print kiosks. Also, working for a distributor I’m also sometimes personally on the receiving end of rude people who wants this too. I don’t disagree much really. Yes, it makes sense to easily lock down what the operating system allows a user in front of it to do. Even to the point where it is totally unusable. Notably this is required for EAL style certifications of systems. Yes, Sarbanes-Oxley requires it too, and yes, some companies (search for the word ‘epoxy’ in that link) disable the USB ports of their employees computers.



Boat on reflecting water
Copenhagen, Denmark - December 2005


I wrote some notes about how to fix this in what I consider a sane way. Sane here includes allowing a system administrator or home user to override this in a way that just works, e.g. pop up a dialog asking for auth to gain privileges to carry out the operation. Mocking around with configuration files in /etc does not qualify - do not pass start, do not collect $200 - put up a GUI dialog instead; it’s 2006 for crying out loud :-)


Anyho, so I did this policy library and started to integrate it with gnome-mount. Sure, this example is kinda lame and the UI is still totally wrong. But it illustrates the point well. The sysadmin didn’t allow the user to override file system permissions on an advanced file system and we give the user the ability to correct it - there are lots of more interesting use-cases than this. And we need do need lockdown, otherwise all the Michal Jaegermann and Alan Cox’s of the world won’t let us put it in a general purpose operating system. Which is fair enough. Oh, before someone cries the root password is evil; whether we ask for the super user password, users own password or something different for auth should just be up to the OS vendor. It’s a boring implementation detail. It’s also fine by me to have a gconf key to hide these dialogs; that might be sometime a sysadmin in an enterprise setting would do. I think Clark even suggested once to put a button “Send request to sysadmin to enable feature” too. Whatever :-)



Eiffel Portal
Paris, France - January 2006


Whilst implementing this I researched various graphical su helpers including consolehelper / usermode that we ship in Fedora. They all suffer from the same set of problems most notably that they allow to run X applications as root. So, I guess for HAL I’ll be rolling my own just like everyone else :-) . Read on please.


No, seriously, I strongly believe the idea of even allowing X applications to run as root is a dead end from day one. With the su helper I plan for PolicyKit (which is a project I’ve spun off HAL containing said policy bits), your application will at most be elevated to an unprivileged “system user”. The trick here is that HAL allows this unprivileged user to invoke D-BUS methods normal unprivileged console users wouldn’t be allowed to invoke. To get to this “system user”, the desktop user will have to auth (root password, own password, whatever) and will thus be presented with a dialog even (optionally) offering the one-time-pain option by granting this privilege to the desktop and/or other users forever (or until the sysadmin changes it).



Looks like a wall of gold
Boston, MA - December 2005


The reason I’m spinning it off HAL is that it makes sense for the rest of the desktop bits (not only GNOME) to adopt the same architectural pattern; for example gnome-system-monitor could use this to renice processes.. g-s-m will simply provide a service on the system bus that runs as root and exports a method called Renice(). A PolicyKit policy file provides a list of uid and gid for who is allowed for this. Now, g-s-m will try to invoke Renice() but might get the PermissionDeniedByPolicy exception back. If this is the case, simply bring up said dialog, enter password, optionally grant this privilege to one or more users and, bingo, you’re done.


I plan to provide a PolicyKit-gnome library for these dialogs, e.g. password prompting and policy editing. Mostly because this is what I need for the HAL (and Fedora I guess), but I think it makes sense for GNOME too to consider this architectural pattern.


Yea yea, long boring blog post about admin stuff and it’s not even about cool bling stuff!. I hope at least that the admins love me :-)