Showing posts with label sysadmin. Show all posts
Showing posts with label sysadmin. Show all posts

Friday, August 29, 2025

Building ffmpeg 8.0 with MP3 support on macOS Sequoia on Silicon

So the other day I needed to strip the audio out of an mp4 and turn it into an mp3.  It's a long story that goes on to involve OpenAI Whisper making a transcription that I could feed into DeepL for translation and finally outputting it as an SRT file.  "Hey, I could just write a Python script to do that."

But first, I'd need to shave a yak.

You see, the slam-dunk tool for doing something like this is ffmpeg.  The only problem is that you can't just download ffmpeg from the macOS app store.  You can get it from homebrew, but if you're going to trust some janky package off the internet, well, you might as well go all-in and build it from source.  At least then you know what's in it.

What's not in it is a few necessary libraries.  I'd need one to handle the MP3 encoding.  And for that I'd need pkg-config.  And at least I already had Xcode and its command-line utilities installed, so that yak was already shaved.  Here's what I ran on the command-line to get it all working.

Step 1, build and install pkg-config on a Silicon Mac:

As of this writing, the latest version is 0.29.2.  You should probably pop over to the releases site in a browser and see what the current version is.  But here's what works for 0.29.2.

cd /tmp
curl -OL https://pkg-config.freedesktop.org/releases/pkg-config-0.29.2.tar.gz
tar -xzf pkg-config-0.29.2.tar.gz
cd pkg-config-0.29.2
CFLAGS="-Wno-int-conversion" CXXFLAGS="-Wno-int-conversion" \
  ./configure --with-internal-glib
make
sudo make install
pkg-config --version  # should return 0.29.2
cd ..

Step 2, build and install LAME (for MP3 support)

As of this writing, LAME is version 3.100, so that's what I used.  Go double-check there's not a newer one.

curl -OL https://sourceforge.net/projects/lame/files/lame/3.100/lame-3.100.tar.gz
tar -xzf lame-3.100.tar.gz
cd lame-3.100
sed -i -e "/lame_init_old/d" include/libmp3lame.sym
./configure
make
sudo make install
lame --version  # Should say 3.100
cd ..

Step 3, build and install H.264 support (optional, but I wanted it)

This will grab the latest no matter what.

git clone https://code.videolan.org/videolan/x264.git
cd x264
./configure --enable-static
make
sudo make install
h264 --version  # Should show a version and that you just built it
cd ..

Step 4, build and install ffmpeg (finally)

They'd just released version 8 so that's what I went with.  As before, check my version numbers against whatever's current and modify these commands as appropriate.

curl -OL https://ffmpeg.org/releases/ffmpeg-8.0.tar.gz
tar -xzf ffmpeg-8.0.tar.gz
cd ffmpeg-8.0
./configure --prefix=/usr/local --enable-gpl \
  --enable-nonfree --enable-libmp3lame --enable-libx264 \
  --enable-shared
make
sudo make install
ffmpeg  # Should show version and usage information
cd ..

Step 5, try it out

My original goal was to strip the audio out of an mp4 and have an mp3 as the result.  Here's an ffmpeg command that does that, assuming you have a file called test-clip.mp4 in the current working directory and want to produce a file called test-clip.mp3.

ffmpeg -i test-clip.mp4 -vn -codec:a libmp3lame  test-clip.mp3

Works on my laptop! (tm)

Hopefully this saves someone some time.  If you try this on your own Sequoia system on Silicon and find you have to change anything, please let me know!

Sunday, August 30, 2020

Running Kali 2020.3 on an original GPD Pocket

I recently needed to dust off my wifi skills, and to keep a low profile, I use my GPD Pocket laptop.  My install of Kali was old, so I decided to see if I could load Kali 2020.3 on it.  After much searching and futzing about, it turns out almost everything works right out of the box.  You need a couple files, some settings, and a trick with the installer.  I also found the archlinux wiki page on GPD really useful, oddly enough.
  • Run the text-mode installer.
  • When you're asked to load the brcm files from a USB drive, say "no."
  • It will successfully find all the APs around you, so select yours.
  • But, it *won't* be able to negotiate WPA2 without the missing files.
  • Tell it you're using an open wifi network.
  • Let this fail.  (If you'd told it WPA2 it it would be in a loop of failing and re-asking you the PSK.)
  • Now, select the option to continue without a network connection.
  • Install and reboot.
  • Log in to your new system.
  • (If your screen is rotated, click to the Kali logo, pick Settings, then Display, and set Rotation to "Right.")
  • Put a copy of this brcmfmac4356-pcie.gpd-win-pocket.txt file on a USB drive.  (Kali can read FAT.)
  • Write a copy into /lib/firmware/brcm/brcmfmac4356-pcie.gpd-win-pocket.txt on Kali.
  • Reboot.  (I know, I know, I could use modprobe.)
  • Log in to your system.
  • Click the Kali icon, choose Settings, then Advanced Network Configuration.
  • Double-click your SSID.
  • Go to the Wi-Fi Security tab.
  • Update your settings to reflect that you use WPA, and provide a password.
  • Save

You'll also need to tweak the touchscreen configuration, which doesn't know it is rotated, yet.

  • Edit /usr/share/X11/ xorg.conf.d/40-libinput.conf
  • Inside the "InputClass" stanza for "libinput touchscreen" add this:
  • Option "CalibrationMatrix" "0 1 0 -1 0 1 0 0 1"
  • Restart

Tuesday, September 19, 2017

Build a Puppet 5 Master on CentOS 7 -- Hella Quickstyle

Want get going with Puppet 5, but you're in some sort of an insane hurry?  Let me walk you through a "hella quickstyle" install of a Puppet 5 master on CentOS 7.  Starting with a completely new, base CentOS 7 system, here's what to do, as root.

Install the Master

I'll be using Puppet Labs' own yum repositories for the install.  The repository definition can be installed by grabbing an RPM.

  rpm -Uvh https://yum.puppetlabs.com/puppet5/puppet5-release-el-7.noarch.rpm

Now it's a piece of cake to install the puppetserver package and its dependencies.

  yum -y install puppetserver

The default configuration has the master's JVM start with a 2 gb heap size.  That's way more than I need.  (Your mileage will vary.)  Let's bring that size down.

  sed -i -e 's/-Xms2g -Xmx2g/-Xms128m -Xmx512m/' /etc/sysconfig/puppetserver

Now I can start up the Puppet server.

  systemctl start puppetserver

If you like, make a symlink to the puppet binary in /usr/local/bin.

  ln -s /opt/puppetlabs/puppet/bin/puppet /usr/local/bin/puppet

The package adds configuration for the master, but not the agent, so I'll add a stanza telling the agent to fetch catalogs from itself.

  cat >> /etc/puppetlabs/puppet/puppet.conf <<EOF
  [agent]
    server = `hostname -f`
  EOF

Now the agent should be able to run.

  puppet agent --test

Finally, I'm going to tell firewalld to allow TCP connections to port 8140, so that other nodes can request catalogs from my master.

  cat > /etc/firewalld/services/puppetmaster.xml <<EOF
  <?xml version="1.0" encoding="utf-8"?>
    <service>
      <short>puppetmaster</short>
      <description>Puppet Master</description>
      <port protocol="tcp" port="8140"/>
    </service>
  EOF

  firewall-cmd --permanent --add-service=puppetmaster   # may take two tries
  firewall-cmd --reload

Add PuppetDB

Next, I'll use Puppet to install and configure PuppetDB.  First, I need to install a module.  I'm not going to use r10k to manage the modules I need, but in the real world, you probably would.  I'm just going to use the Puppet Module Tool to throw it directly into the production code environment.

  puppet module install puppetlabs-puppetdb

Now I classify my master with puppetdb classes.  I'm going to add a node definition for my master to the site.pp manifest.  (And I'll add a default node, for the future.)  When I declare the puppetdb class, I'll tune my memory requirements down, and tell it not to manage my firewall.

  cat >> /etc/puppetlabs/code/environments/production/manifests/site.pp <<EOF
  node '`hostname -f`' {
    # Install and configure PuppetDB
    class { 'puppetdb':
      java_args => { '-Xms' => '128m', '-Xmx' => '256m' },
      manage_firewall => false,
    }
    # And configure the master to use PuppetDB
    include puppetdb::master::config
  }

  node default {
    notify { 'Default node definition ... no classification found!':}
  }
  EOF

Let's make sure it's working.  First, do an agent run, which should make the master submit a report to the PuppetDB.

  puppet agent --test

And now try a (convoluted) curl request straight into the local PuppetDB, to list nodes that are classified with the "Puppetdb" class.  Note: if you adapt and re-use this later, make sure to run it from the master.

  curl -X GET \
    --tlsv1 \
    --stderr /dev/null \
    --data-urlencode "query=[\"and\",[\"=\",\"type\",\"Class\"],[\"=\",\"title\",\"Puppetdb\"]]" \
    --cert   $(puppet config print hostcert) \
    --key    $(puppet config print hostprivkey) \
    --cacert $(puppet config print localcacert) \
    https://`hostname f`:8081/pdb/query/v4/resources | python -m json.tool

Add Agent Nodes

For quick reference, here are the steps to add just the Puppet agent to a node.  All you need to do is add a yum repo, install the puppet-agent package, aim it at your new master, and run.  Make sure  to replace FQDN_OF_YOUR_MASTER in the example below.

  rpm -Uvh https://yum.puppetlabs.com/puppet5/puppet5-release-el-7.noarch.rpm
  yum -y install puppet-agent
  cat >> /etc/puppetlabs/puppet/puppet.conf <<EOF
  [agent]
    server = FQDN_OF_YOUR_MASTER
  EOF
  puppet agent --test --waitforcert 10

Future Direction

These instructions use the Puppet module tool to install the puppetdb module.  That throws it directly into /etc/puppetlabs/code/environments/production/modules.  Most production-grade Puppet masters use 'r10k' to manage the modules that they need, automatically pulling them from version control or the forge, rather than adding them by hand.  The documentation for r10k is here.

Wednesday, July 8, 2015

Changing VMware Fusion DHCP Lease Times

At any one time, I've got a dozen or so virtual machines that I might want to boot a subset of.  Monday and Tuesday I might need one bunch, but Wednesday through Friday another.  VMware Fusion's default lease time is a day, which means frequently those early-week machines are assigned IPs that the later-in-the-week machines were previously using.  Flip-flop batches and they collide.

Well, you can change the default and maximum lease times that Fusion gives out to guests by using the `vmnet-cfgcli` command.  It's pretty easy, and you do it on a per-vmnet basis.  To query the current values, for example on the NAT vmnet8 device, goes like this:


  sudo /Applications/VMware\ Fusion.app/Contents/Library/vmnet-cfgcli getdhcpparam vmnet8 defleasetime
  sudo /Applications/VMware\ Fusion.app/Contents/Library/vmnet-cfgcli getdhcpparam vmnet8 maxleasetime

And you set the values, again with an example on the NAT network, like this:

  sudo /Applications/VMware\ Fusion.app/Contents/Library/vmnet-cfgcli setdhcpparam vmnet8 defleasetime <seconds>
  sudo /Applications/VMware\ Fusion.app/Contents/Library/vmnet-cfgcli setdhcpparam vmnet8 maxleasetime <seconds>

Restart VMware Fusion and you're all set.  Machines requesting a new lease will now receive one with the updated settings.  By the way, a week is 604800 seconds.

Thursday, April 9, 2015

Build a Puppet Master on CentOS 7 -- Hella Quick-Style

I build Puppet environments all the time, which means I need to set up Puppet Masters all the time.  Here's what I do to get a Master running on CentOS 7 "hella quick-style."

Build a CentOS 7 machine and set its hostname. I'm going to call mine "kermit.localdomain."

hostnamectl set-hostname kermit.localdomain

Then add the official PuppetLabs yum repo to the system's sources.

rpm -ivh http://yum.puppetlabs.com/puppetlabs-release-el-7.noarch.rpm

Now yum can install the Puppet Master for you.

yum -y install puppet-server

The easiest way to generate the Master's SSL keypair and self-sign its certificate is to just start up the Master in the foreground and then control-C out of it once it's done the SSL bits. (There must be a more elegant way to do this.)

puppet master --verbose --no-daemonize
[Ctrl-C]

Aim the Master's own Agent at itself. The last stanza in a stock Puppet install's puppet.conf is the [agent] section, so we can get away with just appending to it. (Again, using "kermit" in this example.)

echo 'server = kermit.localdomain' >> /etc/puppet/puppet.conf

Add a [master] stanza to the puppet.conf file. On a stock install, it's safe to just append to the file.

cat >> /etc/puppet/puppet.conf <<EOF
[master]
    environmentpath = \$confdir/environments
    basemodulepath = /etc/puppet/modules
    reports = store,log
EOF


The Master won't start without a production environment, so make an empty one.

mkdir -p /etc/puppet/environments/production/{modules,manifests}
echo 'node default {}' > /etc/puppet/environments/production/manifests/site.pp

Copy the package-supplied Hiera configuration file to a place where the Master can find it. Later, you'll likely need to update the 'datadir' and your hierarchy, but for now the stock one is fine.

cp /etc/hiera.yaml /etc/puppet/hiera.yaml

Set up firewalld with a rule for Puppet traffic on port 8140.

cat > /etc/firewalld/services/puppetmaster.xml <<EOF
<?xml version="1.0" encoding="utf-8"?>
  <service>
    <short>puppetmaster</short>
    <description>Puppet Master</description>
    <port protocol="tcp" port="8140"/>
  </service>
EOF

Tell firewalld to use the rule.

firewall-cmd --permanent --add-service=puppetmaster   # may take two tries
firewall-cmd --reload

And finally, start up the pieces.

puppet resource service puppetmaster ensure=running enable=true
puppet resource service puppet ensure=running enable=true

That's it! If you have to troubleshoot, tail /var/log/messages for clues. Remember, you can kick off Puppet runs manually with `puppet agent -t` to see what's going on during a run.

Saturday, June 30, 2012

Apple's Missing "Insert" Key

The extended Apple keyboard lacks an "insert" key.  If you're running Windows in a virtual machine, there are some apps where that key would be very useful.  Well, it turns out that a Windows virtual machine sees your keyboard a little differently than MacOS does.  Press the "clear" button, and you're actually toggling the "numlock" setting.  Once out of numlock mode, pressing the zero key is actually hitting the "insert" key.

The Storage Admin's DIY SFP Stylus

Check it out, the little rubber end-caps that come on some fibre SFPs are detected by a capacitative display!  It's only some of them.  We went through a pile at work and found that about one in five was able to impersonate a finger.  Dunno why it works, but it opens up some great possibilities for a DIY stylus.  (Maybe the rubber is doped with an EMF-blocking material.)

The discovery was pretty funny.  I was installing SFPs and tossed a bunch of the end-caps on my powered-on iPad for safe keeping.  The tablet went nutz from all the multitouches.

Saturday, January 14, 2012

Updating AD DNS from Mac OS X or Linux

I've got a Mac in an AD environment with DHCP.  All the Windows machines end up with the right DNS in the domain.  Mine doesn't, so my command prompt always has someone else's PTR.  The AD admins set me up so the DC will honor my DNS updates without auth.  (Thanks guys!)  In this example, my machine is tron.sub.domain.com at 192.168.0.42.  Here's how I use nsupdate interactively, one command at a time, in a terminal, to restore reality:
  nsupdate
  > update delete tron.sub.domain.com A
  > send
  > update delete 42.0.168.192.in-addr.arpa PTR
  > send
  > update add tron.sub.domain.com 86400 IN A 192.168.0.42
  > send
  > update add 42.0.168.192.in-addr.arpa. 86400 IN PTR tron.sub.domain.com.
  > send
  > quit
nsupdate will take commands from a file or stdin, so one-liners and scripts are easy.  If you need to use auth, look at the -y or -k flag.  If your domain's SOA isn't quite aiming your client at the right server, the "server" command lets you specify where to send updates.  If your AD admins aren't as accommodating as mine, try buying them a beer.

Wednesday, January 11, 2012

Flipping Vertical Scrolling Behavior in X Windows

I've grown used to Mac OS "natural scrolling" on my trackpad.  So when I recently set up a few ubuntu netbooks, for a quick lab experiment, I wanted to have their trackpads behave the same.  It's actually pretty simple to tell X windows to flip 'em.

Short story, on a completely stock ubuntu, (and should work for anything) this will flip your scrolling:
  • open a terminal
  • run `echo "pointer =  1 2 3 5 4 6 7 8 9 10 11 12" >> ~/.Xmodmap`
  • logout of your X windows session.
  • log back in.
  • ta-da.
Long story, since the days of the dinosaurs, X Windows has been really nice about letting you remap your mouse keys .. southpaws would frequently swap their left and right buttons.  The `xmodmap` command provides an interface for this stuff.  Try `man xmodmap` and `xmodmap -help` for more details.  The above instructions just append a custom button setting to the rc file that xmodmap evaluates at log in.

Up and down scroll are considered physical buttons 4 and 5, respectively.  The "pointer = " statement above has 4 and 5 swapped.  Simple as that.

Use `xmodmap -pp` to display your current button mappings, and `xmodmap -e "pointer = default"` to reset to normal.  If you want to suss out where all of your buttons are, launch `xev` to see what events X is handling .. look for the ButtonPress event and note the "button" attribute.

Wednesday, December 28, 2011

Arduino Ethernet is Alive

I've attached two LEDs, a dial, a light sensor, and a passive infrared motion detector to the Arduino Ethernet.  I've got it running a telnet server and a web server.  I can telnet to the little guy and instruct it to turn the LEDs on or off.  Or point a web browser at it, to see the current status of lights and sensors.  It tries to return JSON, but my structure might not be entirely clean.  Also, it's behind a few layers of NAT, so not yet publicly available.  (Soon!)

It's all stand-alone, which is pretty kewl.  Give it a connection and a few volts -- it'll happily start up and begin sensing things and controlling its lights.  You can imagine keeping these in a data center, with DHCP and a dynamic DNS client.  Plug it in, it reports its IP to you and awaits queries about the environment, or commands for the LEDs.  (Or reads sensors and sets LEDs by its own logic, while it waits for a human.)

The whole thing -- board, power adapter, cable, sensors, lights -- is well under a hundred bucks!

Download my kludgey arduino code and my chaotic fritzing layout, if you like. (Remember, it's a weekend project -- it doesn't have to be pretty.)

Wednesday, December 14, 2011

Typing a Backtick ` in iOS

  • tap the .?123 key
  • press and hold the single quote '
  • backtick is in the ensuing pop-up

Saturday, November 5, 2011

The Sysadmin's Wiki and the Advertising Executive's Rolodex

I've been pondering this a little, but I'm not sure where it belongs.  It's in my blog backlog, though, so here it lives.  I worked in advertising for a short while and noticed some fun quirks of the industry.  ("Worked" in the industry?  Hah!  Actually, I was answering phones.)

You see, executives had a rolodex on their desk, that they protected like a vital organ.  And it *was* a vital organ -- the contacts in there were "theirs," and made the executive uniquely valuable.  When an executive quit, or was fired, the first thing they did was grab their rolodex.  Only then would they make sure they had trivialities such as car keys or their wallet.

Sysadmins have an analogue ... our wiki pages.  But they're typically hosted on an internal company server, readable by the rest of the team.  And then, some sysadmins refuse to post information to the wiki, guarding it like their "rolodex."  They don't say as much, but you know which ones are trying to stay valuable by not spreading tribal knowledge.

How similar are these?  Sysadmins and ad-people have mostly opposite attitudes towards the information that makes them valuable, but the analogy itself might hold water.  Has there been a change in the advertising field, as companies have moved to shared, server-based customer relationship systems that the corporation owns?  I wouldn't dream of hoarding my information, and I think *that* makes me uniquely valuable ... so am I "right" or just used to having the corporation "own" my information?  I wonder.

Thursday, November 3, 2011

Installing Puppet on Centos 5 directly from Puppet Labs

photo: wikimedia commons : User:Liftarn
If you want the latest stable release of puppet on a Centos 5 machine, you can get it from Puppet Labs' own yum repo.  Other "usual" add-on repos (epel, fedora, e.g.) can lag by as much as one minor version.  Puppet Labs tries to keep the version in their repo as stable as possible, according to the Puppet professional services guy sitting across from me, today.  (Hi, Carl!)

First, download an rpm to add the puppet labs yum repos.  Then download an rpm to add the EPEL repo.  Puppet requires a couple sneaky ruby pieces, and EPEL has 'em.  (ruby-shadow and ruby-augeas, fyi)

  cd /tmp
  wget http://yum.puppetlabs.com/el/5/products/x86_64/puppetlabs-release-5-1.noarch.rpm
  sudo rpm -Uvh puppetlabs-release-5-1.noarch.rpm
  wget http://download.fedora.redhat.com/pub/epel/5/x86_64/epel-release-5-4.noarch.rpm
  sudo rpm -Uvh epel-release-5-4.noarch.rpm
  yum repolist  # just to see that they actually installed

Both repo definitions enable their main binary repos, for a normal `yum install` command, so there's no need to add flags to enable them.  Source repos and testing versions are disabled, but can be enabled if you have some nutty reason to do it.

You should now be able to `yum install` the puppet client and/or server -- with all the dependencies being available.

  yum install puppet # for a client
  yum install puppet puppet-server # to include the server pieces, as well.
  # actually, pupper-server just adds an init script
  # and some scripts that pretend to be things like puppetmasterd

Ta da!

Tuesday, September 6, 2011

Restoring Wifi on a Vaio Updated to Ubuntu 11.10


  • You were running Ubuntu with a 2.6 kernel, say 10.10 or 11.04
  • You let (or asked) update-manager to upgrade you to 11.10
  • Now it doesn't even think you *have* a wifi interface.
I'll bet, like me, you'd previously told the 2.6 kernels to ignore the realtek 2xxx kernel modules, because it was causing an unfortunate mess.  And you did it scattergun style, blacklisting a bunch of them all will he, nill he, until it worked.  The shotgun method is a lovely, time-honored tradition .. you just gotta undo your work now that you're on a 3.0 kernel.

  • `sudo vi /etc/modprobe.d/blacklist.conf`
  • Find all of your "blacklist rt2something" lines and comment them out.
    • If they're not there, check other files in modprobe.d
  • Restart your cute little netbook.
  • If that was the problem, on login, it'll connect to wifi as usual.
That was all it took for me to get my just-updated system back on the intarwebs.  Mine's a Vaio M111AX, but I think Sony used the same chips for other models.  If you really did a number on your module configuration for the 2.6 kernel, a clean install of Ubuntu 11.10 (Obsequious Ostrich) might be your best bet.  But hopefully this did the trick!

Friday, September 2, 2011

Gunnar Computer Glasses - Review

"Do those things work?"  Half the department has now asked me about my new Gunnar Digital Performance Eyewear.  "Yeah, they actually seem to," is my reply, "borrow 'em for a day!"  But it seems like people are willing to take my word(s) for it, with a few asking for a real review.

The story starts while I'd been enjoying some really gnarly eye strain.  Like, "I promised myself I wouldn't cry," strain.  You can look out the window and touch-type, part of the time, but it wasn't enough.  I needed to do something before people started to wonder why I got so sad in meetings.

So there I was at a conference in Las Vegas, wandering the vendor village, and Gunnar had a booth.  You've probably done the same calculation ... the idea of reducing eyestrain is great, and the glasses look nice, and you can try them on and stare at a screen for a minute or two ... but you just don't know if they'll do anything after a whole day of use.  Am I right?  And you don't know whether the yellow tint is going to get annoying.  And your cow orkers might laugh at you.  You just don't know, standing there for five minutes.  You need a real scientific experiment.

Well, this being Las Vegas, I decided to take a gamble.  If I played casino games, I'd be out at least a hundred bucks by now, I figured .. and with nothing to show for it, either.

So now it's been a couple weeks, and I suppose there's the possibility that my seasonal allergies just happened to completely disappear when I put these things on, but I think my little bet has actually payed off.

See if you can borrow someone else's pair for a day .. but I think it's reasonable to take a chance and get yourself a set.  If it doesn't work out, you can always sell them to one of the people who inevitably asks you "Do those things work?"

Wednesday, July 20, 2011

Should Corporate IT embrace its inner Ma Bell?

Okay, bear with me here.  I was thinking about this on the ride home, and I could be on to something, or I could have just inhaled too much exhaust.  Is "Corporate IT" (with capital letters) reaching a point where it looks more like Ma Bell than a helpful and innovative organization?  That's not a bad thing.  Look what happened when Ma Bell got shaken up.

Remember the old days, when you got your phone service in one-size-fits-all "service offering?" (Put down the ITIL book, I'm using it derogatorily.)  The phone company actually owned the wiring in your house, and you rented the handset from them.  (Kids, skip down a paragraph or two.)  And that made perfect sense!  Their product was intended to connect people, not just run a stupid network.  And who the hell wanted to manage their own infrastructure in the house, anyways?  Seriously, what do I care about my stupid phone service?

And then along comes the Sports Illustrated Football Phone.  (Kids, skip another paragraph.)  It just looks so awesome on TV and it's free fer chrissakes and it's a nice way to show your friends just how enthusiastic you are about ritualized, non-lethal battle games.  That guy in the ad looks so chummy and smart!  You must have one.  But it's a piece of junk and it breaks. So you call the phone company and they natter on at you about how it's an unsupported device and who do you think you are, a phone technician, this is very serious stuff.

You could write a book about this, so I'm sure someone has.  If not, get me a ghost writer and I'll supply the technical angle.  (Sadly, Tim O'Reilly does not read my blog.)

But it was really making me think.  Do we need to just relax, put a few sandbags in the right places, and begin to define our basic offering as merely running a line to the MPOE?  Do we charge extra for inside wiring work, but offer an "inside wiring plan," for folks who never want to bother with it?  If you get tired of your answering machine breaking tapes all the time (Kids, skip another sentence.) you'll see the value in paying extra for voicemail.  If you want to run a call center, we'll happily give you a T1 ... but arranging to de-mux it and install a PBX is up to you.

It sure beats the current state .. where we continue to offer services that are somewhat appealing to end-users, and mostly manageable at scale for IT, but kinda leave both of us a little unsatisfied.  They said I can keep the awesome football phone even if I choose not to subscribe!  Why are you making me use this hideous, heavy, putty-colored thing!?

Maybe it's time for Corporate IT to learn to stop worrying and love the football phone.

Thursday, July 14, 2011

Repurposed NetApp Filer Grill

I saved an old NetApp FAS960 faceplate from the e-waste pile.  There's an arduino glued into the back, and LEDs run to the original spots on the filer's grill.  I added a photo resistor on the top left corner -- so waving your hand over it causes a measurable drop in light level, letting it be a sort of gestural input.  (Sort of.)

The initial application was as a timer for backup tape acclimation.  When you bring new tapes into the datacenter, you'd wave over the photo resistor, resetting the clock, and then in two hours it'll illuminate the blue LED, and in six hours it does the green LED ... indicating that the tapes are adjusted to the datacenter environment.  That works fine, but I'm still not sure what it wants to be when it grows up.

Frackin' Toasters.

Saturday, July 9, 2011

Fixing Multiple Characters Typed in a vSphere Console on a Linux Guest

You know the problem .. you're in the vSphere client, you've got a console open on a linux guest, and sometimes when you type a character, you get multiples of it typed in the console.  Yeah, try logging in like that.

Briefly, the problem is that it thinks you're holding down the keys (lag adds time between key-down and key-up events) so it repeats the letter you're "holding down."  You can disable key repeating for this guest's console by changing how long a key must be down before it's repeated.  There's a handy post that explains editing the .vmx file .. but I prefer to do it in the vSphere client:

  • Pop into the vSphere client and "Shut Down Guest"  (I know, sorry.)
  • Click to "Edit Settings"
  • Select the "Options" tab.
  • In the list, under "Advanced," click "General"
  • Over on the right, click the "Configuration Parameters..." button.
  • Click the "Add Row" button.
  • Make the new variable's name "keyboard.typematicMinDelay" and the value "2000000"
  • Boot it back up.

Now you can login as "root," instead of "rrrroooooott."

Sunday, April 17, 2011

Fixing Bluetooth Pairing Problems in Windows on Bootcamp

You're running Bootcamp to dual-boot your Mac.  You're able to pair a bluetooth device on the MacOS X side of the house, but you can't subsequently get the device to pair in Windows.  Short story: you've gotta unpair it in MacOS, then pair it in Windows, and finally go back and re-pair it in MacOS.

  • Bootcamp into MacOS X.
  • Use System Preferences > Bluetooth to unpair the device.
  • Bootcamp into Windows
  • Use Control Panel (different sub-tool per version) to pair with the device.
  • Bootcamp back into MaxOS X.
  • Use System Preferences > Bluetooth to pair with the device again.
  • It otter work in both environments, now.
Long story:  I think that basically, the device is getting confused because it's been paired with "a computer" just fine, and sees no point in re-pairing with the same computer.  I could be totally wrong.  But that'd mean that the MacOS side of things is just being especially clever, seeing that Windows is already paired, and re-using those connection credentials.  Basically, I'll bet the Mac is pretending to be the existing paired Windows sytem .. while Windows has no idea it needs to share.  That's my story and I'm sticking to it.

Hopefully this helps someone else.  There are a bunch of discussions about this, scattered across the web, that detail the drop-pair-repair method.  But half of them are those stupid sites that've scraped someone else's content and plastered it with ads and premium-membership scams.  Honestly, I wish there was a Google preference I could set that'd just ignore those bozos every time I search.

I wonder how you'd determine that a site is scraped content with ads and membership offers.  If you just used domain name, they'd go and register new domains all the time to dodge the blacklisting.  Perhaps some sort of "deprecate sites with more than X ads" heuristic.  If anyone's got an idea, I'd love to hear it.

Tuesday, March 1, 2011

Mark Masterson (CSC) at OSCON

I'm continuing the trend on my lunch-time videos, watching more O'Reilly stuff, and today was Mark Masterson's presentation at OSCON.  He does a really interesting job of breaking down how enterprises balance the adoption of new technologies with risk avoidance.  The upshot, to me, was that risk calculations are based on the probability of failure, times the cost of failure -- so if you can't reduce the probability of failure, virtualization can certainly reduce the cost of failure.  I hadn't seen it put so simply, before.  Very interesting!  (BTW, here is Shanley Kane's post, that he references which I enjoyed.)