Gentoo Archives: gentoo-gwn

From: Chris Gianelloni <wolf31o2@g.o>
To: gentoo-gwn@l.g.o
Subject: [gentoo-gwn] Gentoo Weekly Newsletter 11 September 2006
Date: Mon, 18 Sep 2006 13:50:19
Message-Id: 1158582535.9786.2.camel@inertia.twi-31o2.org
1 ---------------------------------------------------------------------------
2 Gentoo Weekly Newsletter
3 http://www.gentoo.org/news/en/gwn/current.xml
4 This is the Gentoo Weekly Newsletter for the week of 11 September 2006.
5 ---------------------------------------------------------------------------
6
7 ==============
8 1. Gentoo news
9 ==============
10
11 New Gentoo Council elected
12 --------------------------
13
14 The Gentoo Council[1] is the elected governing body of Gentoo and decides
15 on global issues and policies that affect multiple projects in Gentoo. It
16 also serves as an appeal court for disciplinary decisions. The Council
17 members are elected for a year and must hold monthly public meetings.
18
19 1. http://www.gentoo.org/proj/en/council/
20
21 The new council for the coming year has been elected. The polls were open
22 for a one-month voting period, to allow all developers a chance to vote on
23 their elected representatives. The winners of this year's council vote are
24 as follows:
25
26 * Diego Pettenò (Flameeyes)
27 * Mike Doty (KingTaco)
28 * Danny van Dyk (Kugelfang)
29 * Bryan Østergaard (kloeri)
30 * Robin H. Johnson (robbat2)
31 * Mike Frysinger (vapier)
32 * Chris Gianelloni (wolf31o2)
33
34 Of the new council, only Mike Frysinger is returning for another tour. The
35 GWN staff wishes to congratulate all of the new council members and wishes
36 them a productive year.
37
38 Donation from Cloanto: Amiga Forever CD
39 ---------------------------------------
40
41 This week, Gentoo received a donation of the Amiga Forever CD[2] from
42 Cloanto. The Amiga[3] is the family of personal computers developed
43 initially by Amiga Corporation and later by Commodore International. These
44 computers had great success due to their graphics and sound, which were
45 far ahead of their time. Therefore, Amiga received its nickname, the
46 ultimate games machine. These computers are in the past, but fortunately,
47 the power of modern PC hardware has made it possible to emulate Amiga
48 software and games. Gentoo provides two Amiga emulators app-emulation/uae
49 and app-emulation/e-uae. However, to make full use of these programs, one
50 must have access to an image of the Amiga Kickstart ROM. To properly
51 maintain these packages, access to the Amiga Kickstart ROM is required for
52 Gentoo developers.
53
54 2. http://amigaforever.com
55 3. http://en.wikipedia.org/wiki/Amiga
56
57 The Amiga Forever CD is the award-winning Amiga preservation, emulation,
58 and support package, made by Cloanto, Amiga developers since 1986. Cloanto
59 has made this CD available to all Gentoo developers to aid in the
60 maintenance of the Amiga emulation programs.
61
62 Gentoo would like to thank Cloanto for this generous donation.
63
64 Monolithic X no longer supported
65 --------------------------------
66
67 Developer Donnie Berkholz[4] wrote to the gentoo-dev mailing list about
68 the discontinuation of support for the monolithic X ebuilds. This means
69 there will be no more fixes added to the monolithic packages, including no
70 more security fixes. Package maintainers will begin removing dependencies
71 for the monolithic ebuilds from their packages. Donnie hopes to move the
72 monolithic X ebuilds into an overlay soon.
73
74 4. dberkholz@g.o
75
76 Users still using the old monolithic ebuilds should upgrade to modular X
77 using the Migrating to Modular X HOWTO[5] instructions.
78
79 5. http://www.gentoo.org/proj/en/desktop/x/x11/modular-x-howto.xml
80
81 ========================
82 2. Developer of the week
83 ========================
84
85 "Gentoo, it's what all the cool kids are doing." -Joshua Nichols
86 ----------------------------------------------------------------
87
88 Figure 2.1: Joshua Nichols, aka nichoj
89 http://www.gentoo.org/images/gwn/20060911_nichoj.jpg
90
91 Developer Joshua Nichols, aka nichoj, resides in Boston, MA - known for
92 their baked beans and tea parties... OK, one in particular. He graduated
93 last spring from Rensselaer Polytechnic Institute with a dual degree in
94 Computer Science and Psychology. At 23, Josh shares an apartment with
95 three friends and one phantom roommate. They have no pets, but Josh
96 considers himself a dog lover and hopes to have a German Shepard when he
97 has more time and a bigger place.
98
99 Josh works for Banta Corporation, a print and supply chain management
100 company, not that anyone knows what that means. His office develops web
101 applications, both internal and external. Josh works with a team
102 developing modular web applications, primarily with Java and J2EE (like
103 Eclipse, Tomcat, Spring, JDO, web services, etc).
104
105 Nichoj claims some fairly canon interests as far as geekery goes. He
106 enjoys reading, mostly sci-fi and fantasy, and some occassional technical
107 reference, for a bit of light reading. He also really enjoys watching
108 Adult Swim, but don't we all? When Josh manages to get out of the house,
109 it may be for some rollerblading or hackey sack, but will inadvertently
110 end up like many Boston festivities... having a few drinks with friends at
111 one of the many Boston drinking establishments.
112
113 Josh started using Gentoo back in his freshmen year at college. He had
114 been a Linux user for years but found that hand configuring things quickly
115 became hard to maintain and discovered that using Gentoo helped him
116 maintain his computer the way he wanted. About a year ago, Josh decided
117 that he wanted to be more involved with open source software. He started
118 attending the LUG's, actively reporting bugs, and helping people on IRC.
119 He was becoming rather proficient with Java, and was quickly recruited by
120 karltk. Josh's current role with Gentoo is one that he rather enjoys, as
121 the Java Project Lead.
122
123 Perhaps the Gentoo achievement Josh is most proud of is his contribution
124 to the new Java system, which was released a few months ago. While it was
125 mostly developed by the time Josh joined the team, they did quickly
126 realize that all of their 400+ Java packages would have to be updated.
127 Josh is very proud to have contributed to the planning and execution, as
128 well as working through the inevitable rough edges upon rolling it to the
129 ~arch masses. Of noteworthy mention, Josh received his first 'hate mail'
130 while working on this project; he must have been doing something right.
131 ;-)
132
133 Josh's primary desktop is an AMD64 box, sporting an X2 4400+, 4GB of RAM,
134 and a 7800GT connected to a 24" LCD. He also has two Dell x86 laptops, an
135 Athlon XP file server, and a G5 desktop for some PPC goodness. His first
136 apps launched? Compiz and CGWD of course, shortly followed by GAIM,
137 Firefox, and Thunderbird.
138
139 Josh's parting words were that of wisdom: "It may be obvious, but you
140 should enjoy what you do. This can be both applied to work within open
141 source projects or with a job. If you're doing something you can't enjoy,
142 or even worse, hate, well, that's bad mmmkay. It'll make your hair grey
143 prematurely, and you might even poke your own eyes out in frustration. I
144 don't know about you, but I like having both eyes. But seriously, I feel
145 fortunate to be able to thoroughly enjoy both my work for Gentoo and my day
146 job."
147
148 =========================
149 3. Heard in the community
150 =========================
151
152 forums
153 ------
154
155 A graphical program for creating ebuilds
156
157 A suggestion to create a graphical program, an IDE of sorts for the
158 purpose of creating ebuilds has been proposed on the forums. Those in
159 favor claim that a program could substantially reduce the effort in
160 writing ebuilds from scratch, as it will ask the user for the information
161 required. Those against the idea cite that the complexity of options in
162 ebuilds would make such a program impossible to create without limiting
163 the options or providing an ill-thought out interface. Whether you support
164 the idea or not, this is not the first time such a program has been
165 proposed. Efforts in the past were made by Pythonhead, a Gentoo developer,
166 in the now stagnant Abeni package.
167
168 * https://forums.gentoo.org/viewtopic-t-496403.html
169 * http://abeni.sourceforge.net/
170
171 =======================
172 4. Gentoo International
173 =======================
174
175 Australia: Software Freedom Day, Canberra
176 -----------------------------------------
177
178 Canberra Software Freedom Day[6], on the 9th of September, was an event
179 talking about software freedom, encouraging people to give Linux a go and
180 handing out Gentoo, Ubuntu[7], and TheOpenCD[8]. After the event, 48
181 people have a new Gentoo Linux 2006.1 x86 LiveCD, and 23 have a 2006.1
182 amd64 LiveCD.
183
184 6. http://www.softwarefreedomday.org/
185 7. http://www.ubuntu.com/
186 8. http://www.theopencd.org/
187
188 Figure 4.1: The Software Freedom Day team
189 http://www.gentoo.org/images/gwn/20060911_sfd.jpg
190
191 Note: Left to Right: Rainer Klein, Neill Cox, Daniel Black (dragonheart),
192 Brian Bishop, Pascal Klein, David Symons, and Evan Leybourn -- Missing:
193 Steve Walsh, Troy Newell
194
195 All participants had a lot of fun meeting interesting people watching the
196 Elephants Dream[9] production. People were interested in alternatives to
197 avoid spyware/viruses, making their old PC hardware useful again as
198 backup/storage servers and making old laptops usable again.
199
200 9. http://orange.blender.org/
201
202 ======================
203 5. Gentoo in the press
204 ======================
205
206 LinuxPlanet (7 Sep)
207 -------------------
208
209 This week, LinuxPlanet covers Sectoo[10], a security-focused distribution
210 based on Gentoo Linux. Sectoo is a LiveCD-based distribution designed to
211 aid in penetration testing, and also to be a useful toolbox for network
212 administrators interested in securing their own networks.
213
214 10. http://www.sectoo.org/
215
216 * Sectoo--A Live Look at Gentoo[11]
217 11. http://www.linuxplanet.com/linuxplanet/reviews/6307/1/
218
219
220 =========================
221 6. Gentoo developer moves
222 =========================
223
224 Moves
225 -----
226
227 The following developers recently left the Gentoo project:
228
229 * none this week
230
231 Adds
232 ----
233
234 The following developers recently joined the Gentoo project:
235
236 * Javier Villavicencio (The_Paya) Gentoo/FreeBSD
237 * Mike Kelly (pioto) creandus/GLEP27/vim
238 * Vlastimil Babka (Caster) Java
239
240 Changes
241 -------
242
243 The following developers recently changed roles within the Gentoo project:
244
245 * Krzysiek Pawlik (nelchael) joined PPC/Java
246 * Jorge Manuel B. S. Vicetto (jmbsvicetto) joined UserRel
247
248 ==================
249 7. Gentoo security
250 ==================
251
252 Streamripper: Multiple remote buffer overflows
253 ----------------------------------------------
254
255 Streamripper is vulnerable to multiple remote buffer overflows, leading to
256 the execution of arbitrary code.
257
258 For more information, please see the GLSA Announcement[12]
259
260 12. http://www.gentoo.org/security/en/glsa/glsa-200609-01.xml
261
262 GTetrinet: Remote code execution
263 --------------------------------
264
265 GTetrinet is vulnerable to a remote buffer overflow, potentially leading
266 to arbitrary code execution.
267
268 For more information, please see the GLSA Announcement[13]
269
270 13. http://www.gentoo.org/security/en/glsa/glsa-200609-02.xml
271
272 OpenTTD: Remote Denial of Service
273 ---------------------------------
274
275 The OpenTTD server is vulnerable to a remote Denial of Service.
276
277 For more information, please see the GLSA Announcement[14]
278
279 14. http://www.gentoo.org/security/en/glsa/glsa-200609-03.xml
280
281 LibXfont: Multiple integer overflows
282 ------------------------------------
283
284 A buffer overflow was discovered in the PCF font parser, potentially
285 resulting in the execution of arbitrary code.
286
287 For more information, please see the GLSA Announcement[15]
288
289 15. http://www.gentoo.org/security/en/glsa/glsa-200609-04.xml
290
291 OpenSSL, AMD64 x86 emulation base libraries: RSA signature forgery
292 ------------------------------------------------------------------
293
294 OpenSSL fails to properly validate PKCS #1 v1.5 signatures.
295
296 For more information, please see the GLSA Announcement[16]
297
298 16. http://www.gentoo.org/security/en/glsa/glsa-200609-05.xml
299
300 ===========
301 8. Bugzilla
302 ===========
303
304 Summary
305 -------
306
307 * Statistics
308 * Closed bug ranking
309 * New bug rankings
310
311 Statistics
312 ----------
313
314 The Gentoo community uses Bugzilla (bugs.gentoo.org[17]) to record and
315 track bugs, notifications, suggestions and other interactions with the
316 development team. Between 03 September 2006 and 10 September 2006,
317 activity on the site has resulted in:
318
319 17. http://bugs.gentoo.org
320
321 * 929 new bugs during this period
322 * 565 bugs closed or resolved during this period
323 * 38 previously closed bugs were reopened this period
324
325 Of the 11040 currently open bugs: 38 are labeled 'blocker', 124 are
326 labeled 'critical', and 530 are labeled 'major'.
327
328 Closed bug rankings
329 -------------------
330
331 The developers and teams who have closed the most bugs during this period
332 are:
333
334 * Gentoo's Team for Core System packages[18], with 31 closed bugs[19]
335 * Gentoo Linux Gnome Desktop Team[20], with 26 closed bugs[21]
336 * AMD64 Project[22], with 25 closed bugs[23]
337 * Gentoo Games[24], with 20 closed bugs[25]
338 * Gentoo Security[26], with 18 closed bugs[27]
339 * mips team[28], with 18 closed bugs[29]
340 * Java team[30], with 18 closed bugs[31]
341 * Gentoo X-windows packagers[32], with 13 closed bugs[33]
342 18. base-system@g.o
343 19.
344 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-09-03&chfieldto=2006-09-10&resolution=FIXED&assigned_to=base-system@g.o
345 20. gnome@g.o
346 21.
347 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-09-03&chfieldto=2006-09-10&resolution=FIXED&assigned_to=gnome@g.o
348 22. amd64@g.o
349 23.
350 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-09-03&chfieldto=2006-09-10&resolution=FIXED&assigned_to=amd64@g.o
351 24. games@g.o
352 25.
353 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-09-03&chfieldto=2006-09-10&resolution=FIXED&assigned_to=games@g.o
354 26. security@g.o
355 27.
356 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-09-03&chfieldto=2006-09-10&resolution=FIXED&assigned_to=security@g.o
357 28. mips@g.o
358 29.
359 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-09-03&chfieldto=2006-09-10&resolution=FIXED&assigned_to=mips@g.o
360 30. java@g.o
361 31.
362 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-09-03&chfieldto=2006-09-10&resolution=FIXED&assigned_to=java@g.o
363 32. x11@g.o
364 33.
365 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-09-03&chfieldto=2006-09-10&resolution=FIXED&assigned_to=x11@g.o
366
367
368 New bug rankings
369 ----------------
370
371 The developers and teams who have been assigned the most new bugs during
372 this period are:
373
374 * Default Assignee for New Packages[34], with 42 new bugs[35]
375 * Gentoo Sound Team[36], with 15 new bugs[37]
376 * AMD64 Project[38], with 15 new bugs[39]
377 * Default Assignee for Orphaned Packages[40], with 14 new bugs[41]
378 * Gentoo KDE team[42], with 9 new bugs[43]
379 * Gentoo net-im Herd[44], with 8 new bugs[45]
380 * Java team[46], with 8 new bugs[47]
381 * Robin Johnson[48], with 6 new bugs[49]
382 34. maintainer-wanted@g.o
383 35.
384 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-09-03&chfieldto=2006-09-10&assigned_to=maintainer-wanted@g.o
385 36. sound@g.o
386 37.
387 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-09-03&chfieldto=2006-09-10&assigned_to=sound@g.o
388 38. amd64@g.o
389 39.
390 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-09-03&chfieldto=2006-09-10&assigned_to=amd64@g.o
391 40. maintainer-needed@g.o
392 41.
393 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-09-03&chfieldto=2006-09-10&assigned_to=maintainer-needed@g.o
394 42. kde@g.o
395 43.
396 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-09-03&chfieldto=2006-09-10&assigned_to=kde@g.o
397 44. net-im@g.o
398 45.
399 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-09-03&chfieldto=2006-09-10&assigned_to=net-im@g.o
400 46. java@g.o
401 47.
402 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-09-03&chfieldto=2006-09-10&assigned_to=java@g.o
403 48. robbat2@g.o
404 49.
405 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-09-03&chfieldto=2006-09-10&assigned_to=robbat2@g.o
406
407
408 ===============
409 9. GWN feedback
410 ===============
411
412 Please send us your feedback[50] and help make the GWN better.
413
414 50. gwn-feedback@g.o
415
416 ================================
417 10. GWN subscription information
418 ================================
419
420 To subscribe to the Gentoo Weekly Newsletter, send a blank e-mail to
421 gentoo-gwn+subscribe@g.o.
422
423 To unsubscribe to the Gentoo Weekly Newsletter, send a blank e-mail to
424 gentoo-gwn+unsubscribe@g.o from the e-mail address you are
425 subscribed under.
426
427 ===================
428 11. Other languages
429 ===================
430
431 The Gentoo Weekly Newsletter is also available in the following languages:
432
433 * Chinese (Simplified)[51]
434 * Danish[52]
435 * Dutch[53]
436 * English[54]
437 * German[55]
438 * Greek[56]
439 * French[57]
440 * Korean[58]
441 * Japanese[59]
442 * Italian[60]
443 * Polish[61]
444 * Portuguese (Brazil)[62]
445 * Portuguese (Portugal)[63]
446 * Russian[64]
447 * Spanish[65]
448 51. http://www.gentoo.org/news/zh_cn/gwn/gwn.xml
449 52. http://www.gentoo.org/news/da/gwn/gwn.xml
450 53. http://www.gentoo.org/news/nl/gwn/gwn.xml
451 54. http://www.gentoo.org/news/en/gwn/gwn.xml
452 55. http://www.gentoo.org/news/de/gwn/gwn.xml
453 56. http://www.gentoo.org/news/el/gwn/gwn.xml
454 57. http://www.gentoo.org/news/fr/gwn/gwn.xml
455 58. http://www.gentoo.org/news/ko/gwn/gwn.xml
456 59. http://www.gentoo.org/news/ja/gwn/gwn.xml
457 60. http://www.gentoo.org/news/it/gwn/gwn.xml
458 61. http://www.gentoo.org/news/pl/gwn/gwn.xml
459 62. http://www.gentoo.org/news/pt_br/gwn/gwn.xml
460 63. http://www.gentoo.org/news/pt/gwn/gwn.xml
461 64. http://www.gentoo.org/news/ru/gwn/gwn.xml
462 65. http://www.gentoo.org/news/es/gwn/gwn.xml
463
464
465 Ulrich Plate <plate@g.o> - Editor
466 Mark Kowarsky <mark_alec@g.o> - Author
467 Daniel Black <dragonheart@g.o> - Author
468 Peter Volkov <pva@g.o> - Author
469 Chrissy Fullam <musikc@×××××××.net> - Author
470 Chris Gianelloni <wolf31o2@g.o> - Author
471
472
473
474 --
475 gentoo-gwn@g.o mailing list