Sure, glad to help out with the docs.
I tested adjusting UFW with KDE firewall settings application to allow incoming SSH connections but found out that making changes through there gives "Please restart plasma firewall, the backend disconnected." error banner when trying to add or remove rules.
Adding and modifying rules in command line works fine however eg. `sudo ufw allow ssh`. Not sure if it's MX23 related or Debian 12/KDE issue, but thought to note it here.
Code: Select all
[CODE]Snapshot created on: 20230610_0900
System:
Kernel: 6.2.14-1-liquorix-amd64 arch: x86_64 bits: 64 compiler: gcc v: 12.2.0 parameters: audit=0
intel_pstate=disable hpet=disable rcupdate.rcu_expedited=1
BOOT_IMAGE=/vmlinuz-6.2.14-1-liquorix-amd64 root=UUID=<filter> ro
quiet splash
Desktop: KDE Plasma v: 5.27.5 wm: kwin_x11 vt: 7 dm: SDDM Distro: MX-23_x64 Libretto June 10
2023 base: Debian GNU/Linux 12 (bookworm)
Machine:
Type: Laptop System: LENOVO product: 20HMS2Q900 v: ThinkPad X270 serial: <superuser required>
Chassis: type: 10 serial: <superuser required>
Mobo: LENOVO model: 20HMS2Q900 serial: <superuser required> UEFI: LENOVO v: R0IET67W (1.45 )
date: 02/22/2022
Battery:
ID-1: BAT0 charge: 14.5 Wh (79.7%) condition: 18.2/23.2 Wh (78.7%) volts: 11.9 min: 11.1
model: SANYO 45N1773 type: Li-ion serial: <filter> status: not charging cycles: 135
ID-2: BAT1 charge: 18.6 Wh (96.9%) condition: 19.2/23.5 Wh (81.8%) volts: 12.0 min: 11.4
model: LGC 45N1127 type: Li-ion serial: <filter> status: discharging cycles: 302
CPU:
Info: model: Intel Core i7-7600U bits: 64 type: MT MCP arch: Amber/Kaby Lake note: check
gen: core 7 level: v3 note: check built: 2017 process: Intel 14nm family: 6 model-id: 0x8E (142)
stepping: 9 microcode: 0xF2
Topology: cpus: 1x cores: 2 tpc: 2 threads: 4 smt: enabled cache: L1: 128 KiB
desc: d-2x32 KiB; i-2x32 KiB L2: 512 KiB desc: 2x256 KiB L3: 4 MiB desc: 1x4 MiB
Speed (MHz): avg: 650 high: 900 min/max: 400/2801 boost: enabled scaling: driver: acpi-cpufreq
governor: ondemand cores: 1: 900 2: 900 3: 400 4: 400 bogomips: 23199
Flags: avx avx2 ht lm nx pae sse sse2 sse3 sse4_1 sse4_2 ssse3 vmx
Vulnerabilities:
Type: itlb_multihit status: KVM: VMX disabled
Type: l1tf mitigation: PTE Inversion; VMX: conditional cache flushes, SMT vulnerable
Type: mds mitigation: Clear CPU buffers; SMT vulnerable
Type: meltdown mitigation: PTI
Type: mmio_stale_data mitigation: Clear CPU buffers; SMT vulnerable
Type: retbleed mitigation: IBRS
Type: spec_store_bypass mitigation: Speculative Store Bypass disabled via prctl
Type: spectre_v1 mitigation: usercopy/swapgs barriers and __user pointer sanitization
Type: spectre_v2 mitigation: IBRS, IBPB: conditional, STIBP: conditional, RSB filling,
PBRSB-eIBRS: Not affected
Type: srbds mitigation: Microcode
Type: tsx_async_abort mitigation: TSX disabled
Graphics:
Device-1: Intel HD Graphics 620 vendor: Lenovo driver: i915 v: kernel arch: Gen-9.5
process: Intel 14nm built: 2016-20 ports: active: eDP-1 empty: DP-1, DP-2, HDMI-A-1, HDMI-A-2
bus-ID: 00:02.0 chip-ID: 8086:5916 class-ID: 0300
Device-2: Lite-On Integrated Camera type: USB driver: uvcvideo bus-ID: 1-8:3 chip-ID: 04ca:7066
class-ID: 0e02
Display: x11 server: X.Org v: 1.21.1.7 compositor: kwin_x11 driver: X: loaded: modesetting
unloaded: fbdev,vesa dri: iris gpu: i915 display-ID: :0 screens: 1
Screen-1: 0 s-res: 1920x1080 s-dpi: 96 s-size: 508x285mm (20.00x11.22") s-diag: 582mm (22.93")
Monitor-1: eDP-1 model: AU Optronics 0x106d built: 2017 res: 1920x1080 hz: 60 dpi: 177
gamma: 1.2 size: 276x155mm (10.87x6.1") diag: 317mm (12.5") ratio: 16:9 modes: 1920x1080
API: OpenGL v: 4.6 Mesa 22.3.6 renderer: Mesa Intel HD Graphics 620 (KBL GT2)
direct-render: Yes
Audio:
Device-1: Intel Sunrise Point-LP HD Audio vendor: Lenovo driver: snd_hda_intel v: kernel
alternate: snd_soc_skl, snd_soc_avs, snd_sof_pci_intel_skl bus-ID: 00:1f.3 chip-ID: 8086:9d71
class-ID: 0403
API: ALSA v: k6.2.14-1-liquorix-amd64 status: kernel-api tools: alsamixer,amixer
Server-1: PipeWire v: 0.3.65 status: active with: 1: pipewire-pulse status: active
2: wireplumber status: active 3: pipewire-alsa type: plugin 4: pw-jack type: plugin
tools: pactl,pw-cat,pw-cli,wpctl
Network:
Device-1: Intel Ethernet I219-LM vendor: Lenovo driver: e1000e v: kernel port: N/A
bus-ID: 00:1f.6 chip-ID: 8086:15d7 class-ID: 0200
IF: eth0 state: down mac: <filter>
Device-2: Intel Wireless 8265 / 8275 driver: iwlwifi v: kernel modules: wl pcie: gen: 1
speed: 2.5 GT/s lanes: 1 bus-ID: 03:00.0 chip-ID: 8086:24fd class-ID: 0280
IF: wlan0 state: up mac: <filter>
IF-ID-1: br-b710255e22d6 state: down mac: <filter>
IF-ID-2: br-fc7751ca2413 state: down mac: <filter>
IF-ID-3: docker0 state: down mac: <filter>
Bluetooth:
Device-1: Intel Bluetooth wireless interface type: USB driver: btusb v: 0.8 bus-ID: 1-7:2
chip-ID: 8087:0a2b class-ID: e001
Report: hciconfig ID: hci0 rfk-id: 4 state: up address: <filter> bt-v: 2.1 lmp-v: 4.2
sub-v: 100 hci-v: 4.2 rev: 100
Info: acl-mtu: 1021:4 sco-mtu: 96:6 link-policy: rswitch hold sniff
link-mode: peripheral accept service-classes: rendering, capturing, object transfer, audio,
telephony
Drives:
Local Storage: total: 476.94 GiB used: 26.96 GiB (5.7%)
SMART Message: Unable to run smartctl. Root privileges required.
ID-1: /dev/nvme0n1 maj-min: 259:0 vendor: Samsung model: MZVLB512HAJQ-000L7 size: 476.94 GiB
block-size: physical: 512 B logical: 512 B speed: 31.6 Gb/s lanes: 4 type: SSD serial: <filter>
rev: 5L2QEXA7 temp: 32.9 C scheme: GPT
Partition:
ID-1: / raw-size: 124.98 GiB size: 122.46 GiB (97.98%) used: 26.82 GiB (21.9%) fs: ext4
dev: /dev/dm-0 maj-min: 253:0 mapped: root.fsm
ID-2: /boot raw-size: 500 MiB size: 458.3 MiB (91.67%) used: 87.1 MiB (19.0%) fs: ext4
dev: /dev/nvme0n1p6 maj-min: 259:6
ID-3: /boot/efi raw-size: 100 MiB size: 96 MiB (96.00%) used: 50.2 MiB (52.3%) fs: vfat
dev: /dev/nvme0n1p2 maj-min: 259:2
Swap:
Kernel: swappiness: 15 (default 60) cache-pressure: 100 (default)
ID-1: swap-1 type: partition size: 16.1 GiB used: 0 KiB (0.0%) priority: -2 dev: /dev/dm-1
maj-min: 253:1 mapped: swap
Sensors:
System Temperatures: cpu: 53.0 C pch: 50.5 C mobo: N/A
Fan Speeds (RPM): fan-1: 3060
Repos:
Packages: 2820 pm: dpkg pkgs: 2811 libs: 1552 tools: apt,apt-get,aptitude,nala pm: rpm pkgs: 0
pm: flatpak pkgs: 9
Active apt repos in: /etc/apt/sources.list
1: deb http://ppa.launchpad.net/uunicorn/open-fprintd/ubuntu kinetic main
2: deb-src http://ppa.launchpad.net/uunicorn/open-fprintd/ubuntu kinetic main
No active apt repos in: /etc/apt/sources.list.d/debian-stable-updates.list
Active apt repos in: /etc/apt/sources.list.d/debian.list
1: deb http://deb.debian.org/debian bookworm main contrib non-free non-free-firmware
2: deb-src http://deb.debian.org/debian bookworm main contrib non-free
Active apt repos in: /etc/apt/sources.list.d/docker.list
1: deb [arch=amd64 signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/debian bookworm stable
Active apt repos in: /etc/apt/sources.list.d/mx.list
1: deb http://ftp.acc.umu.se/mirror/mxlinux.org/packages/mx/repo/ bookworm main non-free
2: deb http://ftp.acc.umu.se/mirror/mxlinux.org/packages/mx/repo/ bookworm ahs
Info:
Processes: 228 Uptime: 2h 29m wakeups: 6 Memory: 15.37 GiB used: 3.13 GiB (20.4%) Init: SysVinit
v: 3.06 runlevel: 5 default: graphical tool: systemctl Compilers: gcc: 12.2.0 alt: 12
Client: shell wrapper v: 5.2.15-release inxi: 3.3.26
Boot Mode: UEFI
EDIT: Oops, I had the Liquorix kernel running, will try without it also...
EDIT2: Yes, problem with the default kernel also.
Screenshot_20230610_160357_mx23-beta1-kde-firewall-bug.jpg
Code: Select all
Kernel: 6.1.0-9-amd64 [6.1.27-1] arch: x86_64 bits: 64 compiler: gcc v: 12.2.0
parameters: BOOT_IMAGE=/vmlinuz-6.1.0-9-amd64 root=UUID=<filter> ro
quiet splash
I was trying the Liquorix 6.2 kernel for the new "retbleed=stuff" kernel parameter which would speed up Skylake Intel systems a bit but seemed they don't support it at the moment
https://github.com/zen-kernel/zen-kernel/issues/300.
You do not have the required permissions to view the files attached to this post.