Gentoo Archives: gentoo-gwn

From: Yuji Kosugi <carlos@g.o>
To: gentoo-gwn@l.g.o
Subject: [gentoo-gwn] Gentoo Weekly Newsletter - Volume 3, Issue 28
Date: Tue, 13 Jul 2004 14:01:32
Message-Id: 20040713135825.GA3277@sparda.dyndns.org
1 ---------------------------------------------------------------------------
2 Gentoo Weekly Newsletter
3 http://www.gentoo.org/news/en/gwn/current.xml
4 This is the Gentoo Weekly Newsletter for the week of July 12th, 2004.
5 ---------------------------------------------------------------------------
6
7 ==============
8 1. Gentoo News
9 ==============
10
11 Portage update.
12 ---------------
13
14 Portage 2.0.51 continues to be in internal testing. Now in version
15 2.0.51_pre13 and masked, it's nearing readiness for ~arch. We'd like to
16 cover some changes to Portage that users will notice if they pick up the
17 currently masked 2.0.51_pre13, or a later ~arch masked or stable version.
18 First of all, due to changes in the Portage cache, users will notice
19 corruption messages when performing rsync updates, which will go away when
20 the cache is altered in a few weeks. At this point however, versions of
21 Portage prior to 2.0.50-r7 will start having problems because they won't
22 be able to handle the new cache. As always, users are recommended to read
23 the messages from emerge rsync and update Portage whenever a new stable
24 version is available.
25
26 Also, in the new version /var/cache/edb/virtuals is going to become
27 obsolete: Portage will calculate the virtuals based on packages installed
28 in the database. Once users upgrade to 2.0.51 the file will be obsolete
29 and there will be no need to save it. Also, /var/cache/edb/world will be
30 moving to the FHS-compliant state directory, /var/lib/portage.
31
32 For more information, read Nicholas Jones[1]'s announcement[2] on
33 gentoo-dev.
34
35 1. carpaski@g.o
36 2. http://article.gmane.org/gmane.linux.gentoo.devel/19521
37
38 ==================
39 2. Gentoo Security
40 ==================
41
42 XFree86, X.org: XDM ignores requestPort setting
43 -----------------------------------------------
44
45 XDM will open TCP sockets for its chooser, even if the
46 DisplayManager.requestPort setting is set to 0. This may allow authorized
47 users to access a machine remotely via X, even if the administrator has
48 configured XDM to refuse such connections.
49
50 For more information, please see the GLSA Announcement[3]
51
52 3. http://www.gentoo.org/security/en/glsa/glsa-200407-05.xml
53
54 libpng: Buffer overflow on row buffers
55 --------------------------------------
56
57 libpng contains a buffer overflow vulnerability potentially allowing an
58 attacker to perform a Denial of Service attack or even execute arbitrary
59 code.
60
61 For more information, please see the GLSA Announcement[4]
62
63 4. http://www.gentoo.org/security/en/glsa/glsa-200407-06.xml
64
65 Shorewall : Insecure temp file handling
66 ---------------------------------------
67
68 Shorewall contains a bug in the code handling the creation of temporary
69 files and directories. This can allow a non-root user to overwrite
70 arbitrary system files.
71
72 For more information, please see the GLSA Announcement[5]
73
74 5. http://www.gentoo.org/security/en/glsa/glsa-200407-07.xml
75
76 Ethereal: Multiple security problems
77 ------------------------------------
78
79 Multiple vulnerabilities including one buffer overflow exist in Ethereal,
80 which may allow an attacker to run arbitrary code or crash the program.
81
82 For more information, please see the GLSA Announcement[6]
83
84 6. http://www.gentoo.org/security/en/glsa/glsa-200407-08.xml
85
86 MoinMoin: Group ACL bypass
87 --------------------------
88
89 MoinMoin contains a bug allowing a user to bypass group ACLs (Access
90 Control Lists).
91
92 For more information, please see the GLSA Announcement[7]
93
94 7. http://www.gentoo.org/security/en/glsa/glsa-200407-09.xml
95
96 =================================
97 3. Featured Developer of the Week
98 =================================
99
100 Featured Developer is on hiatus this week.
101
102 =========================
103 4. Heard in the Community
104 =========================
105
106 Web Forums
107 ----------
108
109 New nvidia Drivers With Support for 2.6 Kernel
110
111 Both the Kernel & Hardware and the Gamers & Players forums have threads
112 about the new nvidia drivers that have been issued little over a week ago.
113 The 4k stacksize problem with 2.6 kernels appears to have been solved, and
114 the new drivers feature a configuration utility people seem to be quite
115 pleased with:
116
117 * New nVIDIA driver Version: 1.0-6106[8](Kernel & Hardware)
118 * nVidia Drivers 6106[9](Gamers & Players)
119 8. http://forums.gentoo.org/viewtopic.php?t=192634
120 9. http://forums.gentoo.org/viewtopic.php?t=192485
121
122
123 gentoo-user
124 -----------
125
126 Useful Install Tips
127
128 Not to be left behind the forums, the some folks started their own Useful
129 Install Tips[10] thread on gentoo-user this week.
130
131 10. http://thread.gmane.org/gmane.linux.gentoo.user/88339
132
133 Migrating to 2.6
134
135 Still haven't made the switch? The Changing to 2.6[11] thread may be a
136 good place to start!
137
138 11. http://thread.gmane.org/gmane.linux.gentoo.user/87980
139
140 =======================
141 5. Gentoo International
142 =======================
143
144 Gentoo International is on hiatus this week.
145
146 ===========
147 6. Bugzilla
148 ===========
149
150 Summary
151 -------
152
153 * Statistics
154 * Closed Bug Ranking
155 * New Bug Rankings
156
157 Statistics
158 ----------
159
160 The Gentoo community uses Bugzilla (bugs.gentoo.org[12]) to record and
161 track bugs, notifications, suggestions and other interactions with the
162 development team. Between 03 July 2004 and 09 July 2004, activity on the
163 site has resulted in:
164
165 12. http://bugs.gentoo.org
166
167 * 576 new bugs during this period
168 * 356 bugs closed or resolved during this period
169 * 26 previously closed bugs were reopened this period
170
171 Of the 6736 currently open bugs: 138 are labeled 'blocker', 179 are
172 labeled 'critical', and 528 are labeled 'major'.
173
174 Closed Bug Rankings
175 -------------------
176
177 The developers and teams who have closed the most bugs during this period
178 are:
179
180 * AMD64 Porting Team[13], with 44 closed bugs[14]
181 * Desktop Miscellaneous Team[15], with 17 closed bugs[16]
182 * Jeremy Huddleston[17], with 13 closed bugs[18]
183 * Netmon Herd[19], with 12 closed bugs[20]
184 * Net-Mail Packages[21], with 12 closed bugs[22]
185 * Gentoo KDE team[23], with 12 closed bugs[24]
186 13. amd64@g.o
187 14.
188 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch
189 field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX
190 ED&assigned_to=amd64@g.o
191 15. desktop-misc@g.o
192 16.
193 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch
194 field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX
195 ED&assigned_to=desktop-misc@g.o
196 17. eradicator@g.o
197 18.
198 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch
199 field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX
200 ED&assigned_to=eradicator@g.o
201 19. netmon@g.o
202 20.
203 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch
204 field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX
205 ED&assigned_to=netmon@g.o
206 21. net-mail@g.o
207 22.
208 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch
209 field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX
210 ED&assigned_to=net-mail@g.o
211 23. kde@g.o
212 24.
213 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch
214 field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX
215 ED&assigned_to=kde@g.o
216
217
218 New Bug Rankings
219 ----------------
220
221 The developers and teams who have been assigned the most new bugs during
222 this period are:
223
224 * Gentoo Linux Gnome Desktop Team[25], with 21 new bugs[26]
225 * Media-Video Herd[27], with 13 new bugs[28]
226 * AMD64 Porting Team[29], with 12 new bugs[30]
227 * Mozilla Gentoo Team[31], with 11 new bugs[32]
228 * Gentoo X-windows Packagers[33], with 10 new bugs[34]
229 * Gentoo's Team for Core System Packages[35], with 10 new bugs[36]
230 25. gnome@g.o
231 26.
232 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
233 tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07
234 -09&assigned_to=gnome@g.o
235 27. media-video@g.o
236 28.
237 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
238 tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07
239 -09&assigned_to=media-video@g.o
240 29. amd64@g.o
241 30.
242 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
243 tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07
244 -09&assigned_to=amd64@g.o
245 31. mozilla@g.o
246 32.
247 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
248 tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07
249 -09&assigned_to=mozilla@g.o
250 33. xfree@g.o
251 34.
252 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
253 tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07
254 -09&assigned_to=xfree@g.o
255 35. base-system@g.o
256 36.
257 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
258 tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07
259 -09&assigned_to=base-system@g.o
260
261
262 ==================
263 7. Tips and Tricks
264 ==================
265
266 Using 'make' for backups
267 ------------------------
268
269 Thanks to Lars Weiler[37] for providing this week's tip.
270
271 37. pylon@g.o
272
273 Usualy make from sys-devel/make is known as a tool for compiling
274 applications. But it could also be used to provide often used commands so
275 that they can be accessed easily.
276
277 Quite everybody wants to do backups. This could be done by packing them
278 with tar. For instance, we want to pack the ~/Mail folder and name the
279 file with a date:
280
281 ---------------------------------------------------------------------------
282 | Code Listing 7.1: |
283 | tar ~/Mail with date included |
284 ---------------------------------------------------------------------------
285 | |
286 |$ tar cvjf ~/Backups/Mail-`date +%F`.tar.bz2 ~/Mail |
287 | |
288 ---------------------------------------------------------------------------
289
290 After that we copy that file (and possibly more) to another computer by
291 using rsync and delete all the files in ~/Backups afterwards:
292
293 ---------------------------------------------------------------------------
294 | Code Listing 7.2: |
295 | Copy backup-file to another computer with rsync |
296 ---------------------------------------------------------------------------
297 | |
298 |$ rsync -avute ssh ~/Backups/ user@othermachine:~/Backups/ |
299 |% rm ~/Backups/* |
300 | |
301 ---------------------------------------------------------------------------
302
303 And now comes the clue with make. After a week you already forgot the
304 commands. Why not store them in a Makefile located in the home-directory,
305 so that you only have to call make backup?
306
307 Inside the Makefile (beware of the uppercased 'M') we provide two targets
308 for the commands, so that we can call them separately, e.g. if you only
309 want to copy the files. The first target backup will only call the other
310 targets in the given order:
311
312 ---------------------------------------------------------------------------
313 | Code Listing 7.3: |
314 | Sample Makefile for backups |
315 ---------------------------------------------------------------------------
316 | |
317 |backup: compress \ |
318 | copy |
319 | |
320 |compress: |
321 | tar cvjf ~/Backups/Mail-`date +%F`.tar.bz2 ~/Mail |
322 | |
323 |copy: |
324 | rsync -avute ssh ~/Backups/ user@othermachine:~/Backups/ |
325 | rm ~/Backups/* |
326 | |
327 ---------------------------------------------------------------------------
328
329 Now we can call make backup in the home directory and the ~/Mail-folder
330 will be compressed and copied to the other computer. The
331 restore-command-set will be your homework ;-)
332
333 Of course, there is a wide use for batched processes with Makefiles. Think
334 about all the things you ever wanted to have scripted with easy usability.
335 You can find more instructions in the info make pages.
336
337 ===========================
338 8. Moves, Adds, and Changes
339 ===========================
340
341 Moves
342 -----
343
344 The following developers recently left the Gentoo team:
345
346 * None this week
347
348 Adds
349 ----
350
351 The following developers recently joined the Gentoo Linux team:
352
353 * None this week
354
355 Changes
356 -------
357
358 The following developers recently changed roles within the Gentoo Linux
359 project:
360
361 * None this week
362
363 ====================
364 9. Contribute to GWN
365 ====================
366
367 Interested in contributing to the Gentoo Weekly Newsletter? Send us an
368 email[38].
369
370 38. gwn-feedback@g.o
371
372 ================
373 10. GWN Feedback
374 ================
375
376 Please send us your feedback[39] and help make the GWN better.
377
378 39. gwn-feedback@g.o
379
380 ================================
381 11. GWN Subscription Information
382 ================================
383
384 To subscribe to the Gentoo Weekly Newsletter, send a blank email to
385 gentoo-gwn-subscribe@g.o.
386
387 To unsubscribe to the Gentoo Weekly Newsletter, send a blank email to
388 gentoo-gwn-unsubscribe@g.o from the email address you are
389 subscribed under.
390
391 ===================
392 12. Other Languages
393 ===================
394
395 The Gentoo Weekly Newsletter is also available in the following languages:
396
397 * Danish[40]
398 * Dutch[41]
399 * English[42]
400 * German[43]
401 * French[44]
402 * Japanese[45]
403 * Italian[46]
404 * Polish[47]
405 * Portuguese (Brazil)[48]
406 * Portuguese (Portugal)[49]
407 * Russian[50]
408 * Spanish[51]
409 * Turkish[52]
410 40. http://www.gentoo.org/news/da/gwn/gwn.xml
411 41. http://www.gentoo.org/news/be/gwn/gwn.xml
412 42. http://www.gentoo.org/news/en/gwn/gwn.xml
413 43. http://www.gentoo.org/news/de/gwn/gwn.xml
414 44. http://www.gentoo.org/news/fr/gwn/gwn.xml
415 45. http://www.gentoo.org/news/ja/gwn/gwn.xml
416 46. http://www.gentoo.org/news/it/gwn/gwn.xml
417 47. http://www.gentoo.org/news/pl/gwn/gwn.xml
418 48. http://www.gentoo.org/news/br/gwn/gwn.xml
419 49. http://www.gentoo.org/news/pt/gwn/gwn.xml
420 50. http://www.gentoo.org/news/ru/gwn/gwn.xml
421 51. http://www.gentoo.org/news/es/gwn/gwn.xml
422 52. http://www.gentoo.org/news/tr/gwn/gwn.xml
423
424
425 Yuji Carlos Kosugi <carlos@g.o> - Editor
426 AJ Armstrong <aja@g.o> - Contributor
427 Brian Downey <bdowney@×××××××××××.net> - Contributor
428 Kurt Lieber <klieber@g.o> - Contributor
429 David Narayan <david@×××××××.net> - Contributor
430 Ulrich Plate <plate@g.o> - Contributor
431 Sven Vermeulen <swift@g.o> - Contributor
432 Simon Holm Thagersen <simon@××××××.net> - Danish Translation
433 Jesper Brodersen <broeman@g.o> - Danish Translation
434 Arne Mejlholm <aaby@g.o> - Danish Translation
435 Hendrik Eeckhaut <Hendrik.Eeckhaut@×××××.be> - Dutch Translation
436 Jorn Eilander <sephiroth@××××××××.nl> - Dutch Translation
437 Bernard Kerckenaere <bernieke@××××××××.com> - Dutch Translation
438 Peter ter Borg <peter@××××××.nl> - Dutch Translation
439 Jochen Maes <linux@××××.be> - Dutch Translation
440 Roderick Goessen <rgoessen@××××.nl> - Dutch Translation
441 Gerard van den Berg <gerard@××××××.net> - Dutch Translation
442 Matthieu Montaudouin <mat@××××××××.com> - French Translation
443 Xavier Neys <neysx@g.o> - French Translation
444 Martin Prieto <riverdale@×××××××××.org> - French Translation
445 Antoine Raillon <cabec2@××××××.net> - French Translation
446 Sebastien Cevey <seb@×××××.net> - French Translation
447 Jean-Christophe Choisy <mabouya@××××××××××××.org> - French Translation
448 Thomas Raschbacher <lordvan@g.o> - German Translation
449 Steffen Lassahn <madeagle@g.o> - German Translation
450 Matthias F. Brandstetter <haim@g.o> - German Translation
451 Lukas Domagala <Cyrik@g.o> - German Translation
452 Tobias Scherbaum <dertobi123@g.o> - German Translation
453 Daniel Gerholdt <Sputnik1969@g.o> - German Translation
454 Marc Herren <dj-submerge@g.o> - German Translation
455 Tobias Matzat <SirSeoman@g.o> - German Translation
456 Marco Mascherpa <mush@××××××.net> - Italian Translation
457 Claudio Merloni <paper@×××××××.it> - Italian Translation
458 Stefano Lucidi <stefano.lucidi@×××××××××××××.org> - Italian Translation
459 Katuyuki Konno <katuyuki@××××××××.jp> - Japanese Translation
460 Hiroyuki Takeda <hiro@××××××××××××××.jp> - Japanese Translation
461 Masato Hatakeyama <hatake@×××××××××××.jp> - Japanese Translation
462 Shigehiro Idani <datam@×××××××.jp> - Japanese Translation
463 Masayoshi Nakamura <masayang@×××××××××.com> - Japanese Translation
464 Tomoyuki Sakurai <web-gentoo-doc-jp@××××××××××××.nu> - Japanese Translation
465 Lukasz Strzygowski <lucass@××××××.pl> - Polish Translation
466 Karol Goralski <gooroo@××××××.pl> - Polish Translation
467 Atila "Jedi" Bohlke Vasconcelos <bohlke@×××××××××.br> - Portuguese
468 (Brazil) Translation
469 Eduardo Belloti <dudu@××××××××.net> - Portuguese (Brazil) Translation
470 Jo??o Rafael Moraes Nicola <joaoraf@×××××××××.br> - Portuguese (Brazil)
471 Translation
472 Marcelo Gon??alves de Azambuja <mgazambuja@×××××××××.br> - Portuguese
473 (Brazil) Translation
474 Otavio Rodolfo Piske <angusy@××××××××.org> - Portuguese (Brazil)
475 Translation
476 Pablo N. Hess -- NatuNobilis <natunobilis@××××××××.org> - Portuguese
477 (Brazil) Translation
478 Pedro de Medeiros <pzilla@××××××××.br> - Portuguese (Brazil) Translation
479 Ventura Barbeiro <venturasbarbeiro@××××××.br> - Portuguese (Brazil)
480 Translation
481 Bruno Ferreira <blueroom@××××××××××××.net> - Portuguese (Portugal)
482 Translation
483 Gustavo Felisberto <humpback@××××××××××.net> - Portuguese (Portugal)
484 Translation
485 Jos?? Costa <jose_costa@×××××××.pt> - Portuguese (Portugal) Translation
486 Luis Medina <metalgodin@×××××××××.org> - Portuguese (Portugal) Translation
487 Ricardo Loureiro <rjlouro@×××××××.org> - Portuguese (Portugal) Translation
488 Aleksandr Martyncev <amncorp@××.ru> - Russian Translator
489 Sergey Galkin <gals_home@××××.ru> - Russian Translator
490 Sergey Kuleshov <svyatogor@g.o> - Russian Translator
491 Alex Spirin <asp13@××××.ru> - Russian Translator
492 Denis Zaletov <dzaletov@×××××××.ru> - Russian Translator
493 Guillermo Juarez <guillermo.juarez@××××××××××.es> - Spanish Translation
494 Fernando J. Pereda <ferdy@××××××.org> - Spanish Translation
495 Juan Diego Guti??rrez Gallardo <andy@××××××.com> - Spanish Translation
496 Nicolas Silva <nsilva@××××××.edu> - Spanish Translation
497 Aycan Irican <aycan@××××××××.tr> - Turkish Translation
498 Bugra Cakir <bugra@×××××××××.com> - Turkish Translation
499 Cagil Seker <cagils@××××××××××.tr> - Turkish Translation
500 Emre Kazdagli <emre@××××××××.tr> - Turkish Translation
501 Evrim Ulu <evrim@××××××××.tr> - Turkish Translation
502 Gursel Kaynak <gurcell@××××××××.tr> - Turkish Translation