Gentoo Archives: gentoo-gwn

From: Ulrich Plate <plate@g.o>
To: gentoo-gwn@l.g.o
Subject: [gentoo-gwn] Gentoo Weekly Newsletter 9 January 2006
Date: Mon, 09 Jan 2006 00:24:15
Message-Id: 20060109010258.53d634aa.plate@gentoo.org
1 ---------------------------------------------------------------------------
2 Gentoo Weekly Newsletter
3 http://www.gentoo.org/news/en/gwn/current.xml
4 This is the Gentoo Weekly Newsletter for the week of 9 January 2005.
5 ---------------------------------------------------------------------------
6
7 ==============
8 1. Gentoo news
9 ==============
10
11 FOSDEM coming up: Europe's main Gentoo event
12 --------------------------------------------
13
14 Thirty developers have already confirmed their attendance at next month's
15 FOSDEM[1], Europe's largest open-source conference and the most important
16 event in the European Gentoo calendar, to be held in Brussels. Last year
17 saw the first "dev room" reservation for Gentoo, an entire day and lecture
18 hall completely devoted to Gentoo use and development, with an embedded
19 Gentoo developers-only meeting that initiated the metastructure changes
20 implemented over the last year. FOSDEM 2006 again opens on the last
21 weekend of February, Saturday 25 and Sunday 26, with the Gentoo dev room
22 on the second day and a preliminary schedule already in place. If you plan
23 on attending FOSDEM and need help in finding accomodation in Brussels,
24 please contact Patrick Lauer[2] who coordinates this year's Gentoo
25 presence at FOSDEM. Especially if you want to fill one of the last
26 remaining time slots and grace the dev room with a Gentoo presentation!
27 1. http://www.fosdem.org
28 2. patrick@g.o
29
30
31 Lithuanian translators needed
32 -----------------------------
33
34 A small team around Ernestas Liubarskij[3] has recently started
35 translating the Gentoo documentation into the Lithuanian language (ISO
36 code: lt). They need many more contributors to help with this effort, so
37 if you can read English, write Lithuanian, and would like to join the
38 team, please contact Ernestas directly.
39 3. e.liubarskij@×××××.com
40
41 ========================
42 2. Developer of the week
43 ========================
44
45 "I'm an open-source guy with an open mind" -- Andrea Barisani
46 -------------------------------------------------------------
47
48 Figure 2.1: Andrea Barisani a.k.a. lcars
49 http://www.gentoo.org/images/gwn/20060109_lcars.jpg
50
51 Andrea Barisani[4] hails from the beautiful Italian city of Trieste. While
52 still trying to finish his degree in physics, he also runs a company -
53 InversePath[5] - together with fellow Gentoo developer Rob Holland[6].
54 4. lcars@g.o
55 5. http://www.inversepath.com
56 6. tigger@g.o
57
58 During his first year at the university, Andrea discovered his interest in
59 system administration and security. At the university, he deployed one of
60 the earliest documented production Gentoo servers. From bugreports and
61 patches he became more and more involved with Gentoo. The Gentoo
62 environment still exists at the University, along with
63 rsync1.it.gentoo.org and lists.gentoo.org, both managed by Andrea. Other
64 Gentoo duties include the LDAP setup, general infrastructure work,
65 managing the mailing lists and being the security liaison for the
66 Infrastructure project. Upstream mlmmj (the mailinglist software) benefits
67 from many patches Andrea created while adapting and bugfixing the package
68 to make it work for Gentoo. Additionally many LDAP-related packages,
69 sendmail, ftester (firewall testing tool) and tenshi (log analyzer) are
70 among the packages he maintains.
71
72 Andrea has deployed Gentoo on a wide range of systems whenever appropriate
73 -- firewalls, clusters, generic servers... Amazingly the "KDE or GNOME?"
74 question draws a blank from him -- Andrea is a text-mode addict, powered
75 by ssh, screen, mutt, vim and subversion. Only in rare cases does X even
76 get started, and then only for firefox or Openoffice. He manages 50
77 workstations and six servers at the university, among other things, which
78 more than compensates for the comparatively modest machine park of only a
79 few generic x86 computers he keeps at home.
80
81 Andrea is not strictly bound to Linux, as he says, "the world is big and
82 we have good software for many different things" -- while Linux usually
83 has the most features it often lacks the consistency of the BSD projects,
84 so he uses whatever works best. "You can see the benefits of a more
85 controlled bazaar in BSD, and you can see the benefits of a huge bazaar in
86 GNU|Whatever/Linux distros," he states.
87
88 Some people may remember the "rsync compromise" some time ago when an
89 exploit in the rsync code was abused to take over servers -- Andrea was
90 one of the first to fully diagnose the exploit. This exploit also showed
91 the power of open-source development -- within 36 hours the bugs were
92 fixed and a new rsync release was out. An interview about that incident
93 can be found in Harvard Business Review[7], a short biography of Andrea
94 and more personal info are available at the InversePath website[8] and the
95 speakers pages[9] of last year's PacSec conference in Yokohama that Andrea
96 attended.
97 7. http://hbswk.hbs.edu/item.jhtml?id=4928&t=technology
98 8. http://www.inversepath.com/staff.html
99 9. http://pacsec.jp/speakers.html?LANG=ENGLISH
100
101 =========================
102 3. Heard in the community
103 =========================
104
105 gentoo-dev
106 ----------
107
108 Textrels in packages policy
109
110 Mark Loeser[10] started a nice technical discussion about textrels.
111 Portage does warn about textrels as they can lead to performance and
112 security problems - a comprehensive explanation on the how and why of that
113 can be found in this thread.
114 10. halcy0n@g.o
115
116 * Textrels in packages policy [11]
117 11. http://thread.gmane.org/gmane.linux.gentoo.devel/33992
118
119 GLEP 42 (news) round six
120
121 The discussion about portage news reporting which has been going on for a
122 few weeks now gets iterated once more in the hope of reaching a workable
123 solution.
124
125 * GLEP 42 (news) round six [12]
126 12. http://thread.gmane.org/gmane.linux.gentoo.devel/34149
127
128 Viability of other SCM/version control systems for big repo's
129
130 While CVS is mature and quite stable it doesn't offer all the features of
131 newer version control systems. Some people have experimented with
132 migrating the gentoo-x86 repository (which won't happen in the near future
133 due to logistical and administrative issues). Donnie Berkholz[13] asks for
134 experiences with alternatives, especially with performance and scalability
135 in mind.
136 13. spyderous@g.o
137
138 * Viability of other SCM/version control systems for big repo's [14]
139 14. http://thread.gmane.org/gmane.linux.gentoo.devel/34187
140
141 gentoo-server
142 -------------
143
144 Roadrunner's server project update
145
146 Ricardo Loureiro wrote a follow-up to his initial PDF document mentioned
147 in the 12 December 2005 edition of the GWN[15]. This new document talks
148 about the initial design layout of the mysql database required to store
149 package information. It goes into great detail as to data types, and
150 displays more progress towards the project goals.
151 15.
152 http://www.gentoo.org/news/en/gwn/20051212-newsletter.xml#doc_chap3_sect3
153
154 * Gentoo-server, take 2[16]
155 16. http://thread.gmane.org/gmane.linux.gentoo.server/3373
156
157 =======================
158 4. Gentoo international
159 =======================
160
161 Italy: Yet another Gentoo derivative
162 ------------------------------------
163
164 Proclaiming to allow you to install Gentoo Linux on your computer in a
165 matter of minutes, the RR4 and RR64 Linux DVDs you can get from Fabio
166 Erculiani[17] differ from Gentoo in few ways, most importantly a default
167 kernel with Reiser4 enabled that is certain to send shivers down the
168 spines of many Gentoo developers who certainly wouldn't want to see your
169 bug reports about this anywhere near the official Gentoo bugzilla. The
170 RR4/64 project is still a remarkable effort, since it's a live system
171 complete with both KDE and Gnome that boots directly from the DVD. The
172 third beta 64-bit version of RR just came out on 26 December, sort of a
173 late Christmas present from Fabio to his fellow Italians, with
174 international users equally invited to give it a spin.
175 17.
176 http://www.lxnaydesign.net/index.php?option=com_content&task=view&id=16&Ite
177 mid=27
178
179 ======================
180 5. Gentoo in the press
181 ======================
182
183 Asteria (December 2005)
184 -----------------------
185
186 Jon Hood, a developer working for Asteria Solutions Group, Inc.[18] takes
187 the current beta version of the Gentoo Installer[19] for a test drive
188 around the block, and appears quite satisfied[20] with the result, calls
189 it a "wonderful step in the right direction for the Gentoo distribution,"
190 and is particularly delighted because "people aren't supposed to actually
191 USE testing software and have it WORK, but that's exactly what happened."
192 His review includes a pretty little slideshow[21] documenting every step
193 of the installation process when done via the GUI installer, very
194 interesting for everybody who's never seen it at work.
195 18. http://www.asteriasgi.com
196 19. http://www.gentoo.org/proj/en/releng/installer/
197 20. http://www2.asteriasgi.com/review/
198 21. http://www2.asteriasgi.com/review/slideshow.html
199
200 =========================
201 6. Gentoo developer moves
202 =========================
203
204 Moves
205 -----
206
207 The following developers recently left the Gentoo project:
208
209 * None this week
210
211 Adds
212 ----
213
214 The following developers recently joined the Gentoo project:
215
216 * Peter Volkov (pva) - netmon
217 * Gunnar Wrobel (wrobel) - web apps
218
219 Changes
220 -------
221
222 The following developers recently changed roles within the Gentoo project:
223
224 * Sven Vermeulen (swift) - resigned as Gentoo Documentation Project (GDP)
225 lead
226 * Xavier Neys (neysx) - took over the GDP lead role from swift
227
228 ==================
229 7. Gentoo Security
230 ==================
231
232 CenterICQ: Multiple vulnerabilities
233 -----------------------------------
234
235 CenterICQ is vulnerable to a Denial of Service issue, and also potentially
236 to the execution of arbitrary code through an included vulnerable ktools
237 library.
238
239 For more information, please see the GLSA Announcement[22]
240 22. http://www.gentoo.org/security/en/glsa/glsa-200512-11.xml
241
242 Mantis: Multiple vulnerabilities
243 --------------------------------
244
245 Mantis is affected by multiple vulnerabilities ranging from file upload
246 and SQL injection to cross-site scripting and HTTP response splitting.
247
248 For more information, please see the GLSA Announcement[23]
249 23. http://www.gentoo.org/security/en/glsa/glsa-200512-12.xml
250
251 Dropbear: Privilege escalation
252 ------------------------------
253
254 A buffer overflow in Dropbear could allow authenticated users to execute
255 arbitrary code as the root user.
256
257 For more information, please see the GLSA Announcement[24]
258 24. http://www.gentoo.org/security/en/glsa/glsa-200512-13.xml
259
260 NBD Tools: Buffer overflow in NBD server
261 ----------------------------------------
262
263 The NBD server is vulnerable to a buffer overflow that may result in the
264 execution of arbitrary code.
265
266 For more information, please see the GLSA Announcement[25]
267 25. http://www.gentoo.org/security/en/glsa/glsa-200512-14.xml
268
269 rssh: Privilege escalation
270 --------------------------
271
272 Local users could gain root privileges by chrooting into arbitrary
273 directories.
274
275 For more information, please see the GLSA Announcement[26]
276 26. http://www.gentoo.org/security/en/glsa/glsa-200512-15.xml
277
278 OpenMotif, AMD64 x86 emulation X libraries: Buffer overflows in libUil
279 library
280 -------
281
282 Two buffer overflows have been discovered in libUil, part of the OpenMotif
283 toolkit, that can potentially lead to the execution of arbitrary code.
284
285 For more information, please see the GLSA Announcement[27]
286 27. http://www.gentoo.org/security/en/glsa/glsa-200512-16.xml
287
288 scponly: Multiple privilege escalation issues
289 ---------------------------------------------
290
291 Local users can exploit an scponly flaw to gain root privileges, and
292 scponly restricted users can use another vulnerability to evade shell
293 restrictions.
294
295 For more information, please see the GLSA Announcement[28]
296 28. http://www.gentoo.org/security/en/glsa/glsa-200512-17.xml
297
298 XnView: Privilege escalation
299 ----------------------------
300
301 XnView may search for shared libraries in an untrusted location,
302 potentially allowing local users to execute arbitrary code with the
303 privileges of another user.
304
305 For more information, please see the GLSA Announcement[29]
306 29. http://www.gentoo.org/security/en/glsa/glsa-200512-18.xml
307
308 pinentry: Local privilege escalation
309 ------------------------------------
310
311 pinentry is vulnerable to privilege escalation.
312
313 For more information, please see the GLSA Announcement[30]
314 30. http://www.gentoo.org/security/en/glsa/glsa-200601-01.xml
315
316 KPdf, KWord: Multiple overflows in included Xpdf code
317 -----------------------------------------------------
318
319 KPdf and KWord both include vulnerable Xpdf code to handle PDF files,
320 making them vulnerable to the execution of arbitrary code.
321
322 For more information, please see the GLSA Announcement[31]
323 31. http://www.gentoo.org/security/en/glsa/glsa-200601-02.xml
324
325 HylaFAX: Multiple vulnerabilities
326 ---------------------------------
327
328 HylaFAX is vulnerable to arbitrary code execution and unauthorized access
329 vulnerabilities.
330
331 For more information, please see the GLSA Announcement[32]
332 32. http://www.gentoo.org/security/en/glsa/glsa-200601-03.xml
333
334 VMware Workstation: Vulnerability in NAT networking
335 ---------------------------------------------------
336
337 VMware guest operating systems can execute arbitrary code with elevated
338 privileges on the host operating system through a flaw in NAT networking.
339
340 For more information, please see the GLSA Announcement[33]
341 33. http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml
342
343 ===========
344 8. Bugzilla
345 ===========
346
347 Statistics
348 ----------
349
350 The Gentoo community uses Bugzilla (bugs.gentoo.org[34]) to record and
351 track bugs, notifications, suggestions and other interactions with the
352 development team. Between 18 December 2005 and 08 January 2006, activity
353 on the site has resulted in:
354 34. http://bugs.gentoo.org
355
356 * 2338 new bugs during this period
357 * 1184 bugs closed or resolved during this period
358 * 84 previously closed bugs were reopened this period
359
360 Of the 9097 currently open bugs: 78 are labeled 'blocker', 173 are labeled
361 'critical', and 498 are labeled 'major'.
362
363 Closed bug rankings
364 -------------------
365
366 The developers and teams who have closed the most bugs during this period
367 are:
368
369 * Gentoo Games[35], with 37 closed bugs[36]
370 * Java team[37], with 36 closed bugs[38]
371 * Gentoo Linux Gnome Desktop Team[39], with 33 closed bugs[40]
372 * Gentoo Security[41], with 32 closed bugs[42]
373 * AMD64 Porting Team[43], with 32 closed bugs[44]
374 * Portage team[45], with 31 closed bugs[46]
375 * Gentoo's Team for Core System packages[47], with 31 closed bugs[48]
376 * Docs Team[49], with 28 closed bugs[50]
377 35. games@g.o
378 36.
379 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-12-18&chfieldto=2006-01-08&resolution=FIXED&assigned_to=games@g.o
380 37. java@g.o
381 38.
382 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-12-18&chfieldto=2006-01-08&resolution=FIXED&assigned_to=java@g.o
383 39. gnome@g.o
384 40.
385 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-12-18&chfieldto=2006-01-08&resolution=FIXED&assigned_to=gnome@g.o
386 41. security@g.o
387 42.
388 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-12-18&chfieldto=2006-01-08&resolution=FIXED&assigned_to=security@g.o
389 43. amd64@g.o
390 44.
391 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-12-18&chfieldto=2006-01-08&resolution=FIXED&assigned_to=amd64@g.o
392 45. dev-portage@g.o
393 46.
394 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-12-18&chfieldto=2006-01-08&resolution=FIXED&assigned_to=dev-portage@g.o
395 47. base-system@g.o
396 48.
397 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-12-18&chfieldto=2006-01-08&resolution=FIXED&assigned_to=base-system@g.o
398 49. docs-team@g.o
399 50.
400 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-12-18&chfieldto=2006-01-08&resolution=FIXED&assigned_to=docs-team@g.o
401
402 New bug rankings
403 ----------------
404
405 The developers and teams who have been assigned the most new bugs during
406 this period are:
407
408 * Default Assignee for New Packages[51], with 102 new bugs[52]
409 * AMD64 Porting Team[53], with 73 new bugs[54]
410 * Default Assignee for Orphaned Packages[55], with 35 new bugs[56]
411 * Gentoo Sound Team[57], with 33 new bugs[58]
412 * media-video herd[59], with 29 new bugs[60]
413 * Gentoo Games[61], with 20 new bugs[62]
414 * Gentoo Kernel Bug Wranglers and Kernel Maintainers[63], with 17 new
415 bugs[64]
416 * Gentoo net-im Herd[65], with 16 new bugs[66]
417 51. maintainer-wanted@g.o
418 52.
419 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-12-18&chfieldto=2006-01-08&assigned_to=maintainer-wanted@g.o
420 53. amd64@g.o
421 54.
422 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-12-18&chfieldto=2006-01-08&assigned_to=amd64@g.o
423 55. maintainer-needed@g.o
424 56.
425 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-12-18&chfieldto=2006-01-08&assigned_to=maintainer-needed@g.o
426 57. sound@g.o
427 58.
428 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-12-18&chfieldto=2006-01-08&assigned_to=sound@g.o
429 59. media-video@g.o
430 60.
431 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-12-18&chfieldto=2006-01-08&assigned_to=media-video@g.o
432 61. games@g.o
433 62.
434 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-12-18&chfieldto=2006-01-08&assigned_to=games@g.o
435 63. kernel@g.o
436 64.
437 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-12-18&chfieldto=2006-01-08&assigned_to=kernel@g.o
438 65. net-im@g.o
439 66.
440 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-12-18&chfieldto=2006-01-08&assigned_to=net-im@g.o
441
442 ===============
443 9. GWN feedback
444 ===============
445
446 Please send us your feedback[67] and help make the GWN better.
447 67. gwn-feedback@g.o
448
449 ================================
450 10. GWN subscription information
451 ================================
452
453 To subscribe to the Gentoo Weekly Newsletter, send a blank email to
454 gentoo-gwn+subscribe@g.o.
455
456 To unsubscribe to the Gentoo Weekly Newsletter, send a blank email to
457 gentoo-gwn+unsubscribe@g.o from the email address you are
458 subscribed under.
459
460 ===================
461 11. Other languages
462 ===================
463
464 The Gentoo Weekly Newsletter is also available in the following languages:
465
466 * Danish[68]
467 * Dutch[69]
468 * English[70]
469 * German[71]
470 * French[72]
471 * Korean[73]
472 * Japanese[74]
473 * Italian[75]
474 * Polish[76]
475 * Portuguese (Brazil)[77]
476 * Portuguese (Portugal)[78]
477 * Russian[79]
478 * Spanish[80]
479 * Turkish[81]
480 68. http://www.gentoo.org/news/da/gwn/gwn.xml
481 69. http://www.gentoo.org/news/nl/gwn/gwn.xml
482 70. http://www.gentoo.org/news/en/gwn/gwn.xml
483 71. http://www.gentoo.org/news/de/gwn/gwn.xml
484 72. http://www.gentoo.org/news/fr/gwn/gwn.xml
485 73. http://www.gentoo.org/news/ko/gwn/gwn.xml
486 74. http://www.gentoo.org/news/ja/gwn/gwn.xml
487 75. http://www.gentoo.org/news/it/gwn/gwn.xml
488 76. http://www.gentoo.org/news/pl/gwn/gwn.xml
489 77. http://www.gentoo.org/news/pt_br/gwn/gwn.xml
490 78. http://www.gentoo.org/news/pt/gwn/gwn.xml
491 79. http://www.gentoo.org/news/ru/gwn/gwn.xml
492 80. http://www.gentoo.org/news/es/gwn/gwn.xml
493 81. http://www.gentoo.org/news/tr/gwn/gwn.xml
494
495 Ulrich Plate <plate@g.o> - Editor
496 Patrick Lauer <patrick@g.o> - Author
497 Chris White <chriswhite@g.o> - Author
498
499 --
500 gentoo-gwn@g.o mailing list