1 |
--------------------------------------------------------------------------- |
2 |
Gentoo Weekly Newsletter |
3 |
http://www.gentoo.org/news/en/gwn/current.xml |
4 |
This is the Gentoo Weekly Newsletter for the week of 24 April 2006. |
5 |
--------------------------------------------------------------------------- |
6 |
|
7 |
============== |
8 |
1. Gentoo news |
9 |
============== |
10 |
|
11 |
Major OpenLDAP upgrade ahead |
12 |
---------------------------- |
13 |
|
14 |
OpenLDAP Version 2.3 will be unmasked during this week. There are many new |
15 |
features and some incompatibilities: |
16 |
|
17 |
* The slurpd sync method has been deprecated in favour of syncrepl |
18 |
* Existing databases need to be manually upgraded or they may get |
19 |
trashed, instructions can be found in the ebuilds. |
20 |
* Although the libraries from 2.1 or 2.2 are kept if installed, a |
21 |
revdep-rebuild is highly recommended |
22 |
* The dbm backend has been deprecated and is already removed in new |
23 |
upstream version (2.4alpha), migrating to a different backend (bdb or hdb) |
24 |
is recommended. |
25 |
|
26 |
Subforums layout for forums.gentoo.org |
27 |
-------------------------------------- |
28 |
|
29 |
Subforums have been in use on forums.gentoo.org for a while now, but |
30 |
before creating further subforums we are looking to see if the layout |
31 |
could be improved. There are some alternative layout proposals and the |
32 |
forums team would like to get some input on what people prefer. A |
33 |
thread[1] showing some examples of possible implementations including a |
34 |
poll has been set up on the forums. Please take some time to review them, |
35 |
vote and/or comment on them. |
36 |
|
37 |
1. http://forums.gentoo.org/viewtopic-t-455911.html |
38 |
|
39 |
========================= |
40 |
2. Heard in the community |
41 |
========================= |
42 |
|
43 |
Web forums |
44 |
---------- |
45 |
|
46 |
Gentoo Forums Improvements |
47 |
|
48 |
Since the last upgrade of the Gentoo Forums announced in the GWN of the |
49 |
previous week, the internationalization of the Gentoo Forums continues, |
50 |
with even more languages translated, as well as many more parts that until |
51 |
now were in English. Apart from that, some security enhancements and |
52 |
restrictions have been incorporated into the current stable version of the |
53 |
Gentoo Forums. Finally, a very significant bug that was affecting the |
54 |
moderators was finally dispatched. You can see the full update log if you |
55 |
follow the appropiate link below. |
56 |
|
57 |
* Gentoo Forums Improvements[2] |
58 |
* Merging threads while others reply breaks[3] |
59 |
2. http://forums.gentoo.org/viewtopic-t-456404.html |
60 |
3. http://bugs.gentoo.org/128097 |
61 |
|
62 |
|
63 |
Is Gentoo more expensive than Red Hat? |
64 |
|
65 |
One of our users, drakkan[4], who has been a fellow Gentoo User for over |
66 |
two years, explains that he is afraid that it is more expensive to |
67 |
maintain Gentoo servers than Red Hat ones. Two important reasons are the |
68 |
constant need of recompilation of packages which takes some time, but also |
69 |
the change in configuration files. Find out more about this in the thread |
70 |
below. |
71 |
|
72 |
4. http://forums.gentoo.org/profile.php?mode=viewprofile&u=59756 |
73 |
|
74 |
* Is gentoo more expensive than red hat?[5] |
75 |
5. http://forums.gentoo.org/viewtopic.php?t=456081 |
76 |
|
77 |
|
78 |
Documentation, Tips & Tricks: Trackball configuration in modular xorg |
79 |
|
80 |
davidgurvich[6] has started a very nice tricks thread where he explains |
81 |
that there is no longer any need to use xmodmap with xorg-x11 7 to modify |
82 |
which buttons point where as there seems to be a new option for that |
83 |
within xorg.conf, "ButtonMapping". Get into the discussion and read more |
84 |
about this topic in the thread below. |
85 |
|
86 |
6. http://forums.gentoo.org/profile.php?mode=viewprofile&u=134507 |
87 |
|
88 |
* Trackball configuration in modular xorg[7] |
89 |
7. http://forums.gentoo.org/viewtopic.php?t=455793 |
90 |
|
91 |
|
92 |
gentoo-dev |
93 |
---------- |
94 |
|
95 |
Automatically killing invalid CFLAGS/warning about bad CFLAGS |
96 |
|
97 |
The AMD64 team has been testing an addition to the profile.bashrc that |
98 |
filters CFLAGS that are unrecognized by gcc. As it seems to work quite |
99 |
well it could be implemented globally to reduce the number of bugs and |
100 |
errors due to bad CFLAGS, potentially at the cost of flexibility. |
101 |
|
102 |
* automatically killing invalid CFLAGS/warning about bad CFLAGS [8] |
103 |
8. http://thread.gmane.org/gmane.linux.gentoo.devel/37376 |
104 |
|
105 |
|
106 |
Enroll users for testing packages |
107 |
|
108 |
In the quest for better testing of packages Eldad Zack[9] proposes to |
109 |
allow users to give more feedback on testing packages. The Arch Tester |
110 |
program tries to fill that niche, but it is still hard for users to get |
111 |
involved without spending too much of their time for Gentoo. |
112 |
|
113 |
9. eldad@g.o |
114 |
|
115 |
* enroll users for testing packages [10] |
116 |
10. http://thread.gmane.org/gmane.linux.gentoo.devel/37348 |
117 |
|
118 |
|
119 |
Gentoo theming during bootup |
120 |
|
121 |
In one of the bigger threads of the last weeks Donnie Berkholz[11] asks |
122 |
for some help in creating an easy-to-install Gentoo theme for bootup. From |
123 |
this start the thread goes into a heated debate on branding - should |
124 |
Gentoo offer things as they are shipped by upstream or patch them to have |
125 |
a Gentoo look? |
126 |
|
127 |
11. spyderous@g.o |
128 |
|
129 |
* Gentoo theming during bootup [12] |
130 |
12. http://thread.gmane.org/gmane.linux.gentoo.devel/37238 |
131 |
|
132 |
|
133 |
====================== |
134 |
3. Gentoo in the press |
135 |
====================== |
136 |
|
137 |
Gentoo Wiki (23 April 2006) |
138 |
--------------------------- |
139 |
|
140 |
Steve Dibb has written a nice Howto on dynamic DNS to point to a host |
141 |
residing anywhere on a DSL or other access line with changing IP |
142 |
addresses. Hosted on the inofficial Gentoo Wiki, the article[13] goes into |
143 |
great detail explaining the entire process, from registering a domain name |
144 |
to using the services of a dynamic domain name resolver -- EveryDNS in his |
145 |
example -- to follow an ISP's dynamic IP address allocation. |
146 |
|
147 |
13. http://gentoo-wiki.com/HOWTO_Dynamic_DNS_with_EveryDNS |
148 |
|
149 |
========================= |
150 |
4. Gentoo developer moves |
151 |
========================= |
152 |
|
153 |
Moves |
154 |
----- |
155 |
|
156 |
The following developers recently left the Gentoo project: |
157 |
|
158 |
* None this week |
159 |
|
160 |
Adds |
161 |
---- |
162 |
|
163 |
The following developers recently joined the Gentoo project: |
164 |
|
165 |
* Thilo Bangert (bangert) - net-mail herd |
166 |
|
167 |
Changes |
168 |
------- |
169 |
|
170 |
The following developers recently changed roles within the Gentoo project: |
171 |
|
172 |
* Denis Dupeyron (calchan) - joined the embedded herd |
173 |
|
174 |
================== |
175 |
5. Gentoo Security |
176 |
================== |
177 |
|
178 |
libapreq2: Denial of Service vulnerability |
179 |
------------------------------------------ |
180 |
|
181 |
A vulnerability has been reported in libapreq2 which could lead to a |
182 |
Denial of Service. |
183 |
|
184 |
For more information, please see the GLSA Announcement[14] |
185 |
|
186 |
14. http://www.gentoo.org/security/en/glsa/glsa-200604-08.xml |
187 |
|
188 |
Cyrus-SASL: DIGEST-MD5 Pre-Authentication Denial of Service |
189 |
----------------------------------------------------------- |
190 |
|
191 |
Cyrus-SASL contains a vulnerability in the DIGEST-MD5 process that could |
192 |
lead to a Denial of Service. |
193 |
|
194 |
For more information, please see the GLSA Announcement[15] |
195 |
|
196 |
15. http://www.gentoo.org/security/en/glsa/glsa-200604-09.xml |
197 |
|
198 |
zgv, xzgv: Heap overflow |
199 |
------------------------ |
200 |
|
201 |
xzgv and zgv attempt to decode JPEG images within the CMYK/YCCK colour |
202 |
space incorrectly, potentially resulting in the execution of arbitrary |
203 |
code. |
204 |
|
205 |
For more information, please see the GLSA Announcement[16] |
206 |
|
207 |
16. http://www.gentoo.org/security/en/glsa/glsa-200604-10.xml |
208 |
|
209 |
Crossfire server: Denial of Service and potential arbitrary code execution |
210 |
-------------------------------------------------------------------------- |
211 |
|
212 |
The Crossfire game server is vulnerable to a Denial of Service and |
213 |
potentially to the execution of arbitrary code. |
214 |
|
215 |
For more information, please see the GLSA Announcement[17] |
216 |
|
217 |
17. http://www.gentoo.org/security/en/glsa/glsa-200604-11.xml |
218 |
|
219 |
Mozilla Firefox: Multiple vulnerabilities |
220 |
----------------------------------------- |
221 |
|
222 |
Several vulnerabilities in Mozilla Firefox allow attacks ranging from |
223 |
execution of script code with elevated privileges to information leaks. |
224 |
|
225 |
For more information, please see the GLSA Announcement[18] |
226 |
|
227 |
18. http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml |
228 |
|
229 |
fbida: Insecure temporary file creation |
230 |
--------------------------------------- |
231 |
|
232 |
fbida is vulnerable to linking attacks, potentially allowing a local user |
233 |
to overwrite arbitrary files. |
234 |
|
235 |
For more information, please see the GLSA Announcement[19] |
236 |
|
237 |
19. http://www.gentoo.org/security/en/glsa/glsa-200604-13.xml |
238 |
|
239 |
Dia: Arbitrary code execution through XFig import |
240 |
------------------------------------------------- |
241 |
|
242 |
Buffer overflows in Dia's XFig import could allow remote attackers to |
243 |
execute arbitrary code. |
244 |
|
245 |
For more information, please see the GLSA Announcement[20] |
246 |
|
247 |
20. http://www.gentoo.org/security/en/glsa/glsa-200604-14.xml |
248 |
|
249 |
=========== |
250 |
6. Bugzilla |
251 |
=========== |
252 |
|
253 |
Statistics |
254 |
---------- |
255 |
|
256 |
The Gentoo community uses Bugzilla (bugs.gentoo.org[21]) to record and |
257 |
track bugs, notifications, suggestions and other interactions with the |
258 |
development team. Between 16 April 2006 and 23 April 2006, activity on the |
259 |
site has resulted in: |
260 |
|
261 |
21. http://bugs.gentoo.org |
262 |
|
263 |
* 799 new bugs during this period |
264 |
* 470 bugs closed or resolved during this period |
265 |
* 38 previously closed bugs were reopened this period |
266 |
|
267 |
Of the 9766 currently open bugs: 60 are labeled 'blocker', 144 are labeled |
268 |
'critical', and 520 are labeled 'major'. |
269 |
|
270 |
Closed bug rankings |
271 |
------------------- |
272 |
|
273 |
The developers and teams who have closed the most bugs during this period |
274 |
are: |
275 |
|
276 |
* Gentoo KDE team[22], with 26 closed bugs[23] |
277 |
* Gentoo's Team for Core System packages[24], with 23 closed bugs[25] |
278 |
* Gentoo Games[26], with 22 closed bugs[27] |
279 |
* Portage team[28], with 22 closed bugs[29] |
280 |
* media-video herd[30], with 18 closed bugs[31] |
281 |
* Gentoo Toolchain Maintainers[32], with 17 closed bugs[33] |
282 |
* Gentoo Linux Gnome Desktop Team[34], with 17 closed bugs[35] |
283 |
* Gentoo Security[36], with 16 closed bugs[37] |
284 |
22. kde@g.o |
285 |
23. |
286 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-04-16&chfieldto=2006-04-23&resolution=FIXED&assigned_to=kde@g.o |
287 |
24. base-system@g.o |
288 |
25. |
289 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-04-16&chfieldto=2006-04-23&resolution=FIXED&assigned_to=base-system@g.o |
290 |
26. games@g.o |
291 |
27. |
292 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-04-16&chfieldto=2006-04-23&resolution=FIXED&assigned_to=games@g.o |
293 |
28. dev-portage@g.o |
294 |
29. |
295 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-04-16&chfieldto=2006-04-23&resolution=FIXED&assigned_to=dev-portage@g.o |
296 |
30. media-video@g.o |
297 |
31. |
298 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-04-16&chfieldto=2006-04-23&resolution=FIXED&assigned_to=media-video@g.o |
299 |
32. toolchain@g.o |
300 |
33. |
301 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-04-16&chfieldto=2006-04-23&resolution=FIXED&assigned_to=toolchain@g.o |
302 |
34. gnome@g.o |
303 |
35. |
304 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-04-16&chfieldto=2006-04-23&resolution=FIXED&assigned_to=gnome@g.o |
305 |
36. security@g.o |
306 |
37. |
307 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2006-04-16&chfieldto=2006-04-23&resolution=FIXED&assigned_to=security@g.o |
308 |
|
309 |
|
310 |
New bug rankings |
311 |
---------------- |
312 |
|
313 |
The developers and teams who have been assigned the most new bugs during |
314 |
this period are: |
315 |
|
316 |
* Default Assignee for New Packages[38], with 27 new bugs[39] |
317 |
* AMD64 Project[40], with 12 new bugs[41] |
318 |
* Jon Hood[42], with 10 new bugs[43] |
319 |
* media-video herd[44], with 10 new bugs[45] |
320 |
* Default Assignee for Orphaned Packages[46], with 9 new bugs[47] |
321 |
* Gentoo KDE team[48], with 9 new bugs[49] |
322 |
* SpanKY[50], with 7 new bugs[51] |
323 |
* Gentoo Games[52], with 7 new bugs[53] |
324 |
38. maintainer-wanted@g.o |
325 |
39. |
326 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-04-16&chfieldto=2006-04-23&assigned_to=maintainer-wanted@g.o |
327 |
40. amd64@g.o |
328 |
41. |
329 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-04-16&chfieldto=2006-04-23&assigned_to=amd64@g.o |
330 |
42. squinky86@g.o |
331 |
43. |
332 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-04-16&chfieldto=2006-04-23&assigned_to=squinky86@g.o |
333 |
44. media-video@g.o |
334 |
45. |
335 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-04-16&chfieldto=2006-04-23&assigned_to=media-video@g.o |
336 |
46. maintainer-needed@g.o |
337 |
47. |
338 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-04-16&chfieldto=2006-04-23&assigned_to=maintainer-needed@g.o |
339 |
48. kde@g.o |
340 |
49. |
341 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-04-16&chfieldto=2006-04-23&assigned_to=kde@g.o |
342 |
50. vapier@g.o |
343 |
51. |
344 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-04-16&chfieldto=2006-04-23&assigned_to=vapier@g.o |
345 |
52. games@g.o |
346 |
53. |
347 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2006-04-16&chfieldto=2006-04-23&assigned_to=games@g.o |
348 |
|
349 |
|
350 |
=============== |
351 |
7. GWN feedback |
352 |
=============== |
353 |
|
354 |
Please send us your feedback[54] and help make the GWN better. |
355 |
|
356 |
54. gwn-feedback@g.o |
357 |
|
358 |
=============================== |
359 |
8. GWN subscription information |
360 |
=============================== |
361 |
|
362 |
To subscribe to the Gentoo Weekly Newsletter, send a blank e-mail to |
363 |
gentoo-gwn+subscribe@g.o. |
364 |
|
365 |
To unsubscribe to the Gentoo Weekly Newsletter, send a blank e-mail to |
366 |
gentoo-gwn+unsubscribe@g.o from the e-mail address you are |
367 |
subscribed under. |
368 |
|
369 |
================== |
370 |
9. Other languages |
371 |
================== |
372 |
|
373 |
The Gentoo Weekly Newsletter is also available in the following languages: |
374 |
|
375 |
* Danish[55] |
376 |
* Dutch[56] |
377 |
* English[57] |
378 |
* German[58] |
379 |
* French[59] |
380 |
* Korean[60] |
381 |
* Japanese[61] |
382 |
* Italian[62] |
383 |
* Polish[63] |
384 |
* Portuguese (Brazil)[64] |
385 |
* Portuguese (Portugal)[65] |
386 |
* Russian[66] |
387 |
* Spanish[67] |
388 |
* Turkish[68] |
389 |
55. http://www.gentoo.org/news/da/gwn/gwn.xml |
390 |
56. http://www.gentoo.org/news/nl/gwn/gwn.xml |
391 |
57. http://www.gentoo.org/news/en/gwn/gwn.xml |
392 |
58. http://www.gentoo.org/news/de/gwn/gwn.xml |
393 |
59. http://www.gentoo.org/news/fr/gwn/gwn.xml |
394 |
60. http://www.gentoo.org/news/ko/gwn/gwn.xml |
395 |
61. http://www.gentoo.org/news/ja/gwn/gwn.xml |
396 |
62. http://www.gentoo.org/news/it/gwn/gwn.xml |
397 |
63. http://www.gentoo.org/news/pl/gwn/gwn.xml |
398 |
64. http://www.gentoo.org/news/pt_br/gwn/gwn.xml |
399 |
65. http://www.gentoo.org/news/pt/gwn/gwn.xml |
400 |
66. http://www.gentoo.org/news/ru/gwn/gwn.xml |
401 |
67. http://www.gentoo.org/news/es/gwn/gwn.xml |
402 |
68. http://www.gentoo.org/news/tr/gwn/gwn.xml |
403 |
|
404 |
|
405 |
Ulrich Plate <plate@g.o> - Editor |
406 |
Ioannis Aslanidis <deathwing00@g.o> - Author |
407 |
Wernfried Haas <amne@g.o> - Author |
408 |
Patrick Lauer <patrick@g.o> - Author |
409 |
Markus Ullmann <jokey@g.o> - Author |
410 |
|
411 |
-- |
412 |
gentoo-gwn@g.o mailing list |