Re: [suse-sles-e] SLES10 sux (== /bin/su) - broken??

From: Alexei_Roudnev (Alexei_Roudnev_at_exigengroup.com)
Date: Thu Mar 22 2007 - 19:35:11 CET


Message-ID: <0c3601c76cb0$d318a4c0$6f31a8c0@sjc.exigengroup.com>
From: "Alexei_Roudnev" <Alexei_Roudnev@exigengroup.com>
Date: Thu, 22 Mar 2007 11:35:11 -0700
Subject: Re: [suse-sles-e] SLES10 sux (== /bin/su) - broken??

1) sux change is not documented in SUSe (about systemuser=1 option). Guess
what 99% users will do - they will run

xhost + (on their desk)
export DISPLAY=...

so no security at all. Excellent change and no documentation (except in
Google -:)).

2) iSCSI+hotplug mount do work in SIMPLE cases only. Take a NetApp with 2
interfaces and configure it. in SLES9 + Cisco iSCSI, all you need to do is
to allow multiport, then iSCSI discover all ports, connects to one of your
choice and reconnects to another in case of problems, so providing
redundancy. In SLES10 you have the only chance of using Multipath (as in
RHEL4). When you run multipath, hotplug dont work for some reason. Moreover,
becasue of multipath you can't use convenient target names in disk names
anymore, so you try to use lvm and found, that lvm is not aligned not with
iSCSI not with hotplug and not with multipath.

In contrast:
- in SLES9 lvm is not aligned with iSCSI too (btw, why - it's pretty simple
to cal it again in netfs) but you have convenioent and readabla disk names
in disk/by-id and disk/by-path and disks (LUN's) see lun resize on the
filer. So you have both choices of
 * simple add lvm (hack of course but a simple one)
 * use convenient disk names from /dev/disk/*

- in RHEL4, you have not a choice except multipath, BUT multipath is well
aligned with lvm. When system see _netdev, it runs lvm scan once again and
mount _netdev disks.

As a result, iSCSI is unusable without a few hacks in SLES10, in contrast to
both SLES9 (no hacks required) and RHEL4 (no hacks required).

As I said - one workaround is fine, 2 workarounds are still good, ..., 10
workarounds == time to think, I already hit a problem with yast2->nfs in
SLES10, problem with NFS and oracle compatibility (not identified yet, so I
can't count it on SLES10, but I was not able to use NFS to get access from
standby to the bacups, which looks really weird), problem with YOU
(yast2->YOU is absent so you must go and make it al manually)... 5 or 6
workarounds already... Did not try OCFSv2 on SLES10 yet, btw...

Overall system quality is dropping down, and here is a problem. Esp. quality
of yast and quality of new Linux kernel adoptation in areas not covered by
desktop usage pattern (iSCSI, lvm, NFS).

In this particular cases:
- sux must be documented including this option, in manual and RELASE NOTES.
- hotplug + udev must be documented and tested in work with multipath + lvm.
- netfs should exist as an option (there are MANY and MANY cases when I dont
want and can nt use hotplug. OCFSv2 is simplerst one - what if I don't want
to mount it from ocfsv2 startup but whant to treat it as a network mount?)
- iSCSI documentation in SLES10 is not adequate.
- yast2... SuSe have 2 choices:
  * everyone in SuSe MUST use yast2 all the time. So that if we see
'yast2->software startup time == 2 minutes (I can show it to you) then
developres feel pain and fix it;
OR
  * yast2 will be dead in a few years.

----- Original Message -----
From: "Anders Norrbring" <lists@norrbring.se>
To: <suse-sles-e@suse.com>
Sent: Thursday, March 22, 2007 6:43 AM
Subject: Re: [suse-sles-e] SLES10 sux (== /bin/su) - broken??

> Marcus Meissner skrev:
>
> >>> - netfs service dropped and never replaced by something else (hotplug
mentioned but don't work properly and is not documented), so no stanard way
to mount network-related disks without a hack (the easierst hack is to put
netfs back -:));
> >> What is netfs? I never even heard of it before.
>
> Mounting network volumes via udev works just fine, no need at all for
> the old netfs, I've been using udev for quite some time to mount a iSCSI
> volume, and it haven't failed on me once.
>
> --
>
> Anders Norrbring
> Norrbring Consulting
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: suse-sles-e-unsubscribe@suse.com
> For additional commands, e-mail: suse-sles-e-help@suse.com
>
>

---------------------------------------------------------------------
To unsubscribe, e-mail: suse-sles-e-unsubscribe@suse.com
For additional commands, e-mail: suse-sles-e-help@suse.com



This archive was generated by hypermail 2.1.7 : Thu Mar 22 2007 - 21:40:55 CET