Gentoo Archives: gentoo-gwn

From: Ulrich Plate <plate@g.o>
To: gentoo-gwn@l.g.o
Subject: [gentoo-gwn] Gentoo Weekly Newsletter 27 June 2005
Date: Mon, 27 Jun 2005 00:44:53
Message-Id: 20050627022915.2400dceb.plate@gentoo.org
1 ---------------------------------------------------------------------------
2 Gentoo Weekly Newsletter
3 http://www.gentoo.org/news/en/gwn/current.xml
4 This is the Gentoo Weekly Newsletter for the week of 27 June 2005.
5 ---------------------------------------------------------------------------
6
7 ==============
8 1. Gentoo News
9 ==============
10
11 Gentoo developer wins award for home entertainment system
12 ---------------------------------------------------------
13
14 Congratulations to Gentoo developer Pieter van den Abeele[1] who went to
15 the Freescale Technology Forum in Orlando, Florida -- and away with the
16 "Best of Show" award for his home media entertainment center based on a
17 hardware design prototype by Gentoo-sponsor Genesi's[2], the maker of the
18 Open Desktop Workstation[3]. Features worth highlighting include a
19 THX-certified 7.1 audio system, a 256M ATI graphics card, SATA hard disk
20 capacity measured in terabytes, full-screen video conferencing support
21 with Altivec optimized audio codecs, a dual TV tuner, Vacuum Fluorescent
22 Display for system messages, fast DVD writer, smartcard support to protect
23 recordings, for authentication and encryption, and infrared support so you
24 can run your media center from a remote control just like any old VCR.
25 More details about the show, including video and audio streams can be
26 found at Pieter's blogsite[4].
27
28 1. pvdabeel@g.o
29 2. http://www.genesi.lu
30 3. http://vendors.gentoo.org
31 4. http://metadistribution.org/blog/
32
33 Figure 1.1: Pieter and his award: Best of Show at the Freescale Technology
34 Forum
35 http://www.gentoo.org/images/gwn/20050627_award.jpg
36
37 Gentoo at the German LinuxTag 2005 in Karlsruhe
38 -----------------------------------------------
39
40 "Linux everywhere", the motto of this year's LinuxTag, held particularly
41 true again for the Gentoo team when PPC developer Lars Weiler[5] was once
42 again invited to install Gentoo Linux on a machine at the close-by HP
43 booth in the same exhibition hall. After a Quad-Opteron[6] installation,
44 Pylon this year bootstrapped Gentoo Linux on a sleek Dual Intel Itanium 2
45 server, featuring 1.6GHz processors, 4GB RAM and two 73GB
46 Ultra320-SCSI-Platten, of which 36GB were set aside for the Gentoo
47 installation. The machine had a gigabit network card, but no graphics or
48 input devices: serial console and later ssh were the only ways in. From a
49 chroot environment in an installed SuSE Linux, a flawless stage1
50 installation was done, including a 2.6.12 kernel that -- interestingly
51 enough -- needed almost no variation from the default config settings.
52 Trying for an ia64 install CD and a catalyst demonstration, fiddling
53 around with the elilo bootloader and some interesting observations kept
54 Lars busy and happy for a day.
55
56 5. pylon@g.o
57 6. news/en/gwn/20040628-newsletter.xml#doc_chap1
58
59 Figure 1.1: HP's Christian Franck, Gentoo developers Robin Johnson and
60 Lars Weiler hacking away
61 http://www.gentoo.org/images/gwn/20050627_itanium.png
62
63 While the total number of visitors to the LinuxTag was somewhat diminished
64 by the introduction of an entrance fee to be paid by all visitors, the
65 Gentoo booth was as popular as ever. Portability was indeed the main focus
66 of this year's Gentoo presence, with PPC, MIPS and x86 architectures on
67 display at the Gentoo stand, and another HPPA host in the same hall at the
68 Linux Portability stand - a 66MHz HP 735 running KDE 3.3.2... 60 T-Shirts
69 were sold, 15 developers and helpers from Germany took care of visitors at
70 the Gentoo booth, backed up by Robin Johnson[7] visiting from Canada.
71
72 7. robbat2@g.o
73
74 Figure 1.2: Still smiling on closing day: the Gentoo LinuxTag team 2005
75 http://www.gentoo.org/images/gwn/20050627_linuxtag.jpg
76
77 Note: Left to right: Stefan Knoblich (stkn), Marc Herren (dj-submerge),
78 Robin Johnson (robbat2),Lars Weiler (pylon), Michael Imhof (tantive),
79 Sebastian Müller (dakjo), Christian Hartmann (ian!), Markus Nigbur
80 (pyrania), Timo Antweiler (azze), Marc Hildebrand (zypher), Stefan
81 Schweizer (genstef)
82
83 After the show, the inofficial localized Gentoo XLiveCD that has become
84 sort of a traditional treat for visitors at IT fairs with a Gentoo
85 representation manned by the German NFP "Friends of Gentoo e.V." has been
86 made available. Everyone who couldn't buy one of the 120 CDs that went
87 over the table at the booth in Karlsruhe can now download the image from
88 the Fizzlewizzle server[8]or via Bittorrent[9]. x86 is uploaded, the PPC
89 version will follow in a bit.
90
91 8. http://fizzlewizzle.net
92 9. http://tracker.netdomination.org
93
94 Figure 1.3: Cover art by Christian Hartmann (ian!) for the Fizzlewizzle
95 Gentoo XLiveCD
96 http://www.gentoo.org/images/gwn/20050627_fizzlewizzle.jpg
97
98 Developer accounts on donated AMD64 machine now available
99 ---------------------------------------------------------
100
101 Several new development systems are being brought online this week! Named
102 pitr, dustball and poseidon,the bulk of the hardware was generously
103 donated by AMD last month[10]. Other donations from various developers and
104 the Gentoo Foundation have facilitated the purchase of parts essential to
105 setting up the boxes, including power supplies and hard disks.
106 Specifications for the three new machines are:
107
108 10. news/en/gwn/20050530-newsletter.xml
109
110 * poseidon.amd64.dev.gentoo.org: Dual Opteron 844, 4GB ECC/Registered
111 RAM, one 80GB HDD
112 * pitr.amd64.dev.gentoo.org: Dual Opteron 842, 2GB ECC/Registered RAM,
113 two 120GB drives
114 * dustpuppy.amd64.dev.gentoo.org: Dual Opteron 842, 1GB ECC/Registered
115 RAM, diskless node
116
117 Figure 1.1: Named after a character on userfriendly.org: Pitr in all its
118 glory
119 http://www.gentoo.org/images/gwn/20050627_amd64.png
120
121 Two of the systems will be deployed for Gentoo/AMD64 testing/development
122 activities, while the third is destined to become a dedicated release
123 engineering platform. Their deployment is neatly timed to coincide with
124 the release cycle for Gentoo 2005.1 - where their significant processing
125 power will contribute towards the construction of stages, hopefully
126 dramatically reducing catalyst build times!
127
128 =========================
129 2. Heard in the community
130 =========================
131
132 gentoo-dev
133 ----------
134
135 Splitting one source package into many binaries
136
137 Since most other Linux distros have split packages for binaries and
138 headers, why isn't this done in Gentoo? Where does it help and what
139 problems does it cause? Read on to find out
140
141 * ebuild splitting [11]
142 11. http://thread.gmane.org/gmane.linux.gentoo.devel/28954
143
144
145 Glibc, non-glibc and external libs
146
147 As Gentoo/BSD is maturing some problems with the handling of the different
148 libcs become more pronounced. How does one handle the extra libraries
149 needed on BSD systems to get all glibc function?
150
151 * Glibc, non-glibc and external libs [12]
152 12. http://thread.gmane.org/gmane.linux.gentoo.devel/28900
153
154
155 =======================
156 3. Gentoo International
157 =======================
158
159 Germany: Gentoo summer camp
160 ---------------------------
161
162 Bring a tent, enough beverages and food to last for two days, and join the
163 happy Gentoo campers at the first German Gentoo summer camp. From 13 to 14
164 August 2005, German and other European Gentooists are meeting on a
165 campsite in Wissen, close to Siegen and Koblenz in the Westerwald forest
166 region. Bring a laptop if you like, too, but the camp is mainly targeting
167 real life interaction: just for fun, for getting to know each other and
168 spending a nice weekend a la campagne. Computing -- if at all -- is going
169 to be limited to whatever is stored on the campers' disks, as there will
170 be no internet connectivity. Prices are very moderate at 5 EUR per night,
171 please register at organiser Slick's website[13] (link in German).
172
173 13. http://gentootreffen2005.deruwe.de/voranmeldung/
174
175 ======================
176 4. Gentoo in the press
177 ======================
178
179 eMediawire (24 June 2005)
180 -------------------------
181
182 Sumo Computer[14], known for their Gentoo-driven Kuro-Box[15], has now
183 taken an Asus Pundit-R Booksize Barebones system and added a 3.2 Ghz
184 Pentium 4 Prescott processor, a GB of memory, 400 GB worth of SATA disk
185 space and a DVD/CD-RW drive -- and again ships the small box with Gentoo
186 Linux preinstalled, says the press release[16] posted on eMediaWire.
187
188 14. http://www.sumocomputers.com
189 15. news/en/gwn/20050523-newsletter.xml#doc_chap6_sect2
190 16. http://www.emediawire.com/releases/2005/6/emw254188.htm
191
192 ===========================
193 5. Moves, adds, and changes
194 ===========================
195
196 Moves
197 -----
198
199 The following developers recently left the Gentoo team:
200
201 * None this week
202
203 Adds
204 ----
205
206 The following developers recently joined the Gentoo Linux team:
207
208 * Johannes Traub (_bambam) - PPC arch tester
209
210 Changes
211 -------
212
213 The following developers recently changed roles within the Gentoo Linux
214 project:
215
216 * Andrea Barisani (lcars) - Adds sendmail ebuild maintenance to his infra
217 duties
218
219 ==================
220 6. Gentoo security
221 ==================
222
223 cpio: Directory traversal vulnerability
224 ---------------------------------------
225
226 cpio contains a flaw which may allow a specially crafted cpio archive to
227 extract files to an arbitrary directory.
228
229 For more information, please see the GLSA Announcement[17]
230
231 17. http://www.gentoo.org/security/en/glsa/glsa-200506-16.xml
232
233 SpamAssassin 3, Vipul's Razor: Denial of Service vulnerability
234 --------------------------------------------------------------
235
236 SpamAssassin and Vipul's Razor are vulnerable to a Denial of Service
237 attack when handling certain malformed messages.
238
239 For more information, please see the GLSA Announcement[18]
240
241 18. http://www.gentoo.org/security/en/glsa/glsa-200506-17.xml
242
243 Tor: Information disclosure
244 ---------------------------
245
246 A flaw in Tor may allow the disclosure of arbitrary memory portions.
247
248 For more information, please see the GLSA Announcement[19]
249
250 19. http://www.gentoo.org/security/en/glsa/glsa-200506-18.xml
251
252 SquirrelMail: Several XSS vulnerabilities
253 -----------------------------------------
254
255 Squirrelmail is vulnerable to several cross-site scripting vulnerabilities
256 which could lead to a compromise of webmail accounts.
257
258 For more information, please see the GLSA Announcement[20]
259
260 20. http://www.gentoo.org/security/en/glsa/glsa-200506-19.xml
261
262 Cacti: Several vulnerabilities
263 ------------------------------
264
265 Cacti is vulnerable to several SQL injection and file inclusion
266 vulnerabilities.
267
268 For more information, please see the GLSA Announcement[21]
269
270 21. http://www.gentoo.org/security/en/glsa/glsa-200506-20.xml
271
272 Trac: File upload vulnerability
273 -------------------------------
274
275 Trac may allow remote attackers to upload files, possibly leading to the
276 execution of arbitrary code.
277
278 For more information, please see the GLSA Announcement[22]
279
280 22. http://www.gentoo.org/security/en/glsa/glsa-200506-21.xml
281
282 sudo: Arbitrary command execution
283 ---------------------------------
284
285 A vulnerability in sudo may allow local users to elevate privileges.
286
287 For more information, please see the GLSA Announcement[23]
288
289 23. http://www.gentoo.org/security/en/glsa/glsa-200506-22.xml
290
291 ===========
292 7. Bugzilla
293 ===========
294
295 Summary
296 -------
297
298 * Statistics
299 * Closed bug ranking
300 * New bug rankings
301
302 Statistics
303 ----------
304
305 The Gentoo community uses Bugzilla (bugs.gentoo.org[24]) to record and
306 track bugs, notifications, suggestions and other interactions with the
307 development team. Between 19 June 2005 and 26 June 2005, activity on the
308 site has resulted in:
309
310 24. http://bugs.gentoo.org
311
312 * 585 new bugs during this period
313 * 397 bugs closed or resolved during this period
314 * 18 previously closed bugs were reopened this period
315
316 Of the 8396 currently open bugs: 106 are labeled 'blocker', 208 are
317 labeled 'critical', and 597 are labeled 'major'.
318
319 Closed bug rankings
320 -------------------
321
322 The developers and teams who have closed the most bugs during this period
323 are:
324
325 * Jonathan Smith[25], with 38 closed bugs[26]
326 * Alastair Tse[27], with 26 closed bugs[28]
327 * AMD64 Porting Team[29], with 20 closed bugs[30]
328 * Gentoo Games[31], with 15 closed bugs[32]
329 * Jeremy Huddleston[33], with 14 closed bugs[34]
330 * Shyam Mani[35], with 12 closed bugs[36]
331 * Gentoo Security[37], with 11 closed bugs[38]
332 * Gentoo Linux Gnome Desktop Team[39], with 11 closed bugs[40]
333 25. smithj@g.o
334 26.
335 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-06-19&chfieldto=2005-06-26&resolution=FIXED&assigned_to=smithj@g.o
336 27. liquidx@g.o
337 28.
338 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-06-19&chfieldto=2005-06-26&resolution=FIXED&assigned_to=liquidx@g.o
339 29. amd64@g.o
340 30.
341 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-06-19&chfieldto=2005-06-26&resolution=FIXED&assigned_to=amd64@g.o
342 31. games@g.o
343 32.
344 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-06-19&chfieldto=2005-06-26&resolution=FIXED&assigned_to=games@g.o
345 33. eradicator@g.o
346 34.
347 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-06-19&chfieldto=2005-06-26&resolution=FIXED&assigned_to=eradicator@g.o
348 35. fox2mike@g.o
349 36.
350 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-06-19&chfieldto=2005-06-26&resolution=FIXED&assigned_to=fox2mike@g.o
351 37. security@g.o
352 38.
353 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-06-19&chfieldto=2005-06-26&resolution=FIXED&assigned_to=security@g.o
354 39. gnome@g.o
355 40.
356 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-06-19&chfieldto=2005-06-26&resolution=FIXED&assigned_to=gnome@g.o
357
358
359 New bug rankings
360 ----------------
361
362 The developers and teams who have been assigned the most new bugs during
363 this period are:
364
365 * Default Assignee for New Packages[41], with 64 new bugs[42]
366 * Jonathan Smith[43], with 12 new bugs[44]
367 * Gentoo Web Application Packages Maintainers[45], with 10 new bugs[46]
368 * Gentoo Linux Gnome Desktop Team[47], with 10 new bugs[48]
369 * AMD64 Porting Team[49], with 10 new bugs[50]
370 * Gentoo Sound Team[51], with 9 new bugs[52]
371 * Chris PeBenito[53], with 9 new bugs[54]
372 * Net-Mail Packages[55], with 8 new bugs[56]
373 41. maintainer-needed@g.o
374 42.
375 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-06-19&chfieldto=2005-06-26&assigned_to=maintainer-needed@g.o
376 43. smithj@g.o
377 44.
378 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-06-19&chfieldto=2005-06-26&assigned_to=smithj@g.o
379 45. web-apps@g.o
380 46.
381 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-06-19&chfieldto=2005-06-26&assigned_to=web-apps@g.o
382 47. gnome@g.o
383 48.
384 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-06-19&chfieldto=2005-06-26&assigned_to=gnome@g.o
385 49. amd64@g.o
386 50.
387 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-06-19&chfieldto=2005-06-26&assigned_to=amd64@g.o
388 51. sound@g.o
389 52.
390 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-06-19&chfieldto=2005-06-26&assigned_to=sound@g.o
391 53. pebenito@g.o
392 54.
393 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-06-19&chfieldto=2005-06-26&assigned_to=pebenito@g.o
394 55. net-mail@g.o
395 56.
396 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-06-19&chfieldto=2005-06-26&assigned_to=net-mail@g.o
397
398
399 ===============
400 8. GWN feedback
401 ===============
402
403 Please send us your feedback[57] and help make the GWN better.
404
405 57. gwn-feedback@g.o
406
407 ===============================
408 9. GWN subscription information
409 ===============================
410
411 To subscribe to the Gentoo Weekly Newsletter, send a blank email to
412 gentoo-gwn+subscribe@g.o.
413
414 To unsubscribe to the Gentoo Weekly Newsletter, send a blank email to
415 gentoo-gwn+unsubscribe@g.o from the email address you are
416 subscribed under.
417
418 ===================
419 10. Other languages
420 ===================
421
422 The Gentoo Weekly Newsletter is also available in the following languages:
423
424 * Danish[58]
425 * Dutch[59]
426 * English[60]
427 * German[61]
428 * French[62]
429 * Japanese[63]
430 * Italian[64]
431 * Polish[65]
432 * Portuguese (Brazil)[66]
433 * Portuguese (Portugal)[67]
434 * Russian[68]
435 * Spanish[69]
436 * Turkish[70]
437 58. http://www.gentoo.org/news/da/gwn/gwn.xml
438 59. http://www.gentoo.org/news/nl/gwn/gwn.xml
439 60. http://www.gentoo.org/news/en/gwn/gwn.xml
440 61. http://www.gentoo.org/news/de/gwn/gwn.xml
441 62. http://www.gentoo.org/news/fr/gwn/gwn.xml
442 63. http://www.gentoo.org/news/ja/gwn/gwn.xml
443 64. http://www.gentoo.org/news/it/gwn/gwn.xml
444 65. http://www.gentoo.org/news/pl/gwn/gwn.xml
445 66. http://www.gentoo.org/news/pt_br/gwn/gwn.xml
446 67. http://www.gentoo.org/news/pt/gwn/gwn.xml
447 68. http://www.gentoo.org/news/ru/gwn/gwn.xml
448 69. http://www.gentoo.org/news/es/gwn/gwn.xml
449 70. http://www.gentoo.org/news/tr/gwn/gwn.xml
450
451
452 Ulrich Plate <plate@g.o> - Editor
453 Alex Howells <astinus@g.o> - Author
454 Patrick Lauer <patrick@g.o> - Author
455 Lars Weiler <pylon@g.o> - Author
456
457 --
458 gentoo-gwn@g.o mailing list