Gentoo Archives: gentoo-gwn

From: Ulrich Plate <plate@g.o>
To: gentoo-gwn@l.g.o
Subject: [gentoo-gwn] Gentoo Weekly Newsletter 18 October 2004
Date: Sun, 17 Oct 2004 23:14:56
Message-Id: 20041018010659.0cb41682.plate@gentoo.org
1 ---------------------------------------------------------------------------
2 Gentoo Weekly Newsletter
3 http://www.gentoo.org/news/en/gwn/current.xml
4 This is the Gentoo Weekly Newsletter for the week of 18 October 2004.
5 ---------------------------------------------------------------------------
6
7 ==============
8 1. Gentoo News
9 ==============
10
11 2004.3 release coming your way: LiveCD test builds for x86 and PPC
12 avalable soon
13 -------------
14
15 Watch out for beta versions of the upcoming 2004.3 LiveCDs this week: Both
16 x86 and PPC architectures are on the brink of releasing previews, and will
17 eagerly await bug reports at Gentoo's bugzilla as soon as the test builds
18 hit the mirrors. Comments from testers are highly welcome before marking
19 the respective architectures ready for release.
20
21 New lead translator for Japanese GWN
22 ------------------------------------
23
24 The GWN extends its gratitude to a long-time contributor, Japanese lead
25 translator Katsuyuki Konno who is leaving the team this month, to be
26 followed by Tomoyuki Sakurai[1]. The Japanese version of the GWN has been
27 in existence from the fourth issue of the English language publication,
28 and it hasn't skipped a single issue ever since then, making Japanese one
29 of the first and most reliable of the various alternative GWN languages.
30 1. cherry@××××××××××××.nu
31
32 ==================
33 2. Gentoo security
34 ==================
35
36 LessTif: Integer and stack overflows in libXpm
37 ----------------------------------------------
38
39 Multiple vulnerabilities have been discovered in libXpm, which is included
40 in LessTif, that can potentially lead to remote code execution.
41
42 For more information, please see the GLSA Announcement[2]
43 2. http://www.gentoo.org/security/en/glsa/glsa-200410-09.xml
44
45 gettext: Insecure temporary file handling
46 -----------------------------------------
47
48 The gettext utility is vulnerable to symlink attacks, potentially allowing
49 a local user to overwrite or change permissions on arbitrary files with
50 the rights of the user running gettext, which could be the root user.
51
52 For more information, please see the GLSA Announcement[3]
53 3. http://www.gentoo.org/security/en/glsa/glsa-200410-10.xml
54
55 tiff: Buffer overflows in image decoding
56 ----------------------------------------
57
58 Multiple heap-based overflows have been found in the tiff library image
59 decoding routines, potentially allowing to execute arbitrary code with the
60 rights of the user viewing a malicious image.
61
62 For more information, please see the GLSA Announcement[4]
63 4. http://www.gentoo.org/security/en/glsa/glsa-200410-11.xml
64
65 WordPress: HTTP response splitting and XSS vulnerabilities
66 ----------------------------------------------------------
67
68 WordPress contains HTTP response splitting and cross-site scripting
69 vulnerabilities.
70
71 For more information, please see the GLSA Announcement[5]
72 5. http://www.gentoo.org/security/en/glsa/glsa-200410-12.xml
73
74 BNC: Input validation flaw
75 --------------------------
76
77 BNC contains an input validation flaw which might allow a remote attacker
78 to issue arbitrary IRC related commands.
79
80 For more information, please see the GLSA Announcement[6]
81 6. http://www.gentoo.org/security/en/glsa/glsa-200410-13.xml
82
83 =========================
84 3. Heard in the community
85 =========================
86
87 Web forums
88 ----------
89
90 KDE and GPG
91
92 Security comes at a price: When packages supposedly collaborating with
93 each other for providing GnuPG and S/MIME support in the KDE mail client
94 are being updated without coordination upstream, things may occasionally
95 break:
96
97 * KDEPIM 3.3.1 failing on gpgme[7]
98 7. http://forums.gentoo.org/viewtopic.php?t=236628
99
100 gentoo-user
101 -----------
102
103 KDE and broken DNS
104
105 Several Gentooers noticed that after upgrading glibc on their systems, DNS
106 sporadically quit working inside KDE. One helpful poster provided a link
107 back to KDE's bugzilla that had a bug report specifically for Gentoo, but
108 it had no solution. So what is the culprit? When doing large system
109 upgrades such as perl, glibc, etc. you should be sure to do a
110 revdep-rebuild[8] to help solve issues like the above. It's not a magic
111 fix for everything, but it can certainly reduce hair-pulling for strange
112 events like these.
113 8. http://www.gentoo.org/doc/en/gentoolkit.xml#doc_chap5
114
115 * kooky kde behaviour[9]
116 9. http://thread.gmane.org/gmane.linux.gentoo.user/102980
117
118 Resuming emerge on a notebook
119
120 Many people have an issue with long running emerges on their notebooks:
121 Between work and home they have to cancel and completely restart the
122 compilation of some larger packages.
123
124 * How to restart an emerge[10]
125 10. http://thread.gmane.org/gmane.linux.gentoo.user/103221
126
127 Filesystem automounter
128
129 Having trouble getting autofs to work on your Gentoo system? Here's a
130 thread discussing alternative program recommendations for mounting
131 filesystems.
132
133 * autofs, supermount, submount... which is best for Gentoo?[11]
134 11. http://article.gmane.org/gmane.linux.gentoo.user/103026
135
136 gentoo-dev
137 ----------
138
139 xorg-x11-6.8.0-r1 ready to go stable on all archs
140
141 Donnie Berkholz[12] announced that xorg-x11-6.8.0-r1 is ready to go stable
142 on x86 and asked all arch maintainers to follow shortly thereafter, unless
143 there is a good reason not to mark it stable. Reason for this is to have
144 marked it stable before the portage snapshot for the 2004.3 release will
145 be taken.
146 12. spyderous@g.o
147
148 * xorg-x11-6.8.0-r1 ready to go stable on all archs[13]
149 13. http://thread.gmane.org/gmane.linux.gentoo.devel/22006
150
151 init script optimizations?
152
153 Discussions about more or less dangerous optimizations to speed up the
154 boot sequence.
155
156 * init script optimizations?[14]
157 14. http://thread.gmane.org/gmane.linux.gentoo.devel/22100
158
159 HPPA dev box is now online at OSU
160
161 Mike Frysinger[15] got his HPPA development-box set up on OSU where it is
162 accessible for every Gentoo developer who need to test ebuilds on HPPA.
163 15. vapier@g.o
164
165 * HPPA dev box is now online at OSU[16]
166 16. http://thread.gmane.org/gmane.linux.gentoo.devel/22107
167
168 rsync speed and space taken
169
170 Discussions about the size of the Gentoo portage tree.
171
172 * rsync speed and space taken[17]
173 17. http://thread.gmane.org/gmane.linux.gentoo.devel/21962
174
175 Support for UTF-8 in the console
176
177 Mike Frysinger was looking for feedback from people using UTF-8 fonts and
178 keymaps in the console, and asked them to test a new patch.
179
180 * support for UTF8 in console[18]
181 18. http://thread.gmane.org/gmane.linux.gentoo.devel/22173
182
183 GLEP23 - Updates and call for further discussion
184
185 GLEP 23 deals with Portage and how it handles the ACCEPT_LICENSE clause:
186
187 * GLEP23 - Updates and call for further discussion[19]
188 19. http://thread.gmane.org/gmane.linux.gentoo.devel/22173
189
190 =======================
191 4. Gentoo International
192 =======================
193
194 Germany: Munich Gentoo Linux User Group Event
195 ---------------------------------------------
196
197 Last Saturday, 15 October, MGLUG's Gentooistas[20] and other Linux users
198 from Munich's general LUG[21] (celebrating its 10th anniversary this year)
199 and neighboring Erding LUG[22] had organized a joint event with "Berkeley
200 in Munich"[23], the local BSD community. Labeled "First Open-source
201 Infotainment Day", the organisers had brought together speakers exploring
202 the structural differences between Linux and FreeBSD, introducing TeX
203 desktop publishing, and other topics. One presentation was dedicated to
204 "Gentoo Linux from an ISP's viewpoint", and installations of both Gentoo
205 Linux and FreeBSD were offered during the event, too. The meeting started
206 early and continued over lunch at the premises of a Munich-based job
207 training center[24], and a few impressions of the event can be viewed at
208 the MGLUG's photo gallery[25].
209 20. http://www.mglug.de
210 21. http://www.muc-lug.de
211 22. http://www.lug-erding.de
212 23. http://www.berklix.org/bim
213 24. http://www.bfipeters.de/
214 25. http://www.mglug.de/gallery/aktivitaeten
215
216 Figure 4.1: Gentoo Linux users and friends in Munich
217 http://www.gentoo.org/images/gwn/20041018-mglug.jpg
218
219 Italy: To Smau or not to Smau
220 -----------------------------
221
222 It has a reputation for being the largest and most important IT fair in
223 Italy, but some Italian Gentooists seem to be skeptical about its
224 usefulness. Nevertheless, a few Gechi[26] members are openly thinking of
225 attending the Smau this year[27], held at the Milano trade fair ground
226 from Thursday 21 October to Monday 25 October 2004. Never mind that
227 weighing the pros and cons at this thread in the Gentoo forums[28] only
228 has "half-naked dancers" on the plus-side of the balance sheet - you'll
229 still be able to meet one or the other Gentooist among the almost 400,000
230 visitors expected at the event.
231 26. http://www.gechi.it
232 27. http://www.smau.it/smau2004/english/docs/exhibition_what.php
233 28. http://forums.gentoo.org/viewtopic.php?t=233447
234
235 ======================
236 5. Gentoo in the press
237 ======================
238
239 The Age (12 October 2004)
240 -------------------------
241
242 In a rather disturbingly titled article in Australia's leading newspaper
243 for the Victoria district[29], "Microsoft scores well on security
244 analysis", the Victorian open-source activist Con Zymaris did his best to
245 convince author Rob O'Neill of the virtue of open-source security
246 advisories, but wasn't entirely successful. If getting shot as a messenger
247 of security flaws really is a considerable risk down under, Gentoo may
248 want to stand less tall, but in reality, of course, having the highest
249 number of security advisories of all open-source projects and commercial
250 vendors is not bad at all.
251 29.
252 http://www.theage.com.au/articles/2004/10/11/1097406487760.html?oneclick=true
253
254 ZDNet (12 October 2004)
255 -----------------------
256
257 David Berlind at ZDnet props Linux against Mac OS X[30] in his quest for
258 the future ruler of the desktop: "Today, even the most reputable and
259 recommended distributions of desktop Linux, such as Gentoo and Xandros,
260 are not the no-brainers that OS X and Windows--in that order--are."
261 Interestingly enough, he seems quite confident that Linux will eventually
262 be persistent enough for popular acceptance as a desktop OS: "However,
263 it’s only a matter of time before desktop Linux follows precisely the same
264 path as server Linux did when it worked its way from the pockets of early
265 adopters and risk takers into gaining the widespread affection of server
266 administrators."
267 30. http://news.zdnet.com/2100-9590_22-5406365.html
268
269 Central Command, Inc. (press release 13 October 2004)
270 ------------------------------------------------------
271
272 Gentoo figures as one of the supported distributions in a press release by
273 Central Command, Inc.[31], a privately held company in Ohio providing
274 anti-virus software that is going to be offered as a server-side
275 application bundled with the services of Outblaze Ltd., a global provider
276 of hosted email headquartered in Hong Kong.
277 31. http://www.centralcommand.com/13102004.html
278
279 ===========
280 6. Bugzilla
281 ===========
282
283 Summary
284 -------
285
286 * Statistics
287 * Closed bug ranking
288 * New bug rankings
289
290 Statistics
291 ----------
292
293 The Gentoo community uses Bugzilla (bugs.gentoo.org[32]) to record and
294 track bugs, notifications, suggestions and other interactions with the
295 development team. Between 10 October 2004 and 16 October 2004, activity on
296 the site has resulted in:
297 32. http://bugs.gentoo.org
298
299 * 796 new bugs during this period
300 * 310 bugs closed or resolved during this period
301 * 38 previously closed bugs were reopened this period
302
303 Of the 7252 currently open bugs: 124 are labeled 'blocker', 245 are
304 labeled 'critical', and 525 are labeled 'major'.
305
306 Closed bug rankings
307 -------------------
308
309 The developers and teams who have closed the most bugs during this period
310 are:
311
312 * Gentoo's Team for Core System packages[33], with 28 closed bugs[34]
313 * Gentoo X-windows packagers[35], with 17 closed bugs[36]
314 * Java team[37], with 16 closed bugs[38]
315 * Gentoo Games[39], with 14 closed bugs[40]
316 * AMD64 Porting Team[41], with 11 closed bugs[42]
317 * osx porters[43], with 10 closed bugs[44]
318 * Gentoo KDE team[45], with 10 closed bugs[46]
319 * Gentoo Linux Gnome Desktop Team[47], with 10 closed bugs[48]
320 33. base-system@g.o
321 34.
322 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2004-10-10&chfieldto=2004-10-16&resolution=FIXED&assigned_to=base-system@g.o
323 35. x11@g.o
324 36.
325 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2004-10-10&chfieldto=2004-10-16&resolution=FIXED&assigned_to=x11@g.o
326 37. java@g.o
327 38.
328 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2004-10-10&chfieldto=2004-10-16&resolution=FIXED&assigned_to=java@g.o
329 39. games@g.o
330 40.
331 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2004-10-10&chfieldto=2004-10-16&resolution=FIXED&assigned_to=games@g.o
332 41. amd64@g.o
333 42.
334 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2004-10-10&chfieldto=2004-10-16&resolution=FIXED&assigned_to=amd64@g.o
335 43. osx@g.o
336 44.
337 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2004-10-10&chfieldto=2004-10-16&resolution=FIXED&assigned_to=osx@g.o
338 45. kde@g.o
339 46.
340 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2004-10-10&chfieldto=2004-10-16&resolution=FIXED&assigned_to=kde@g.o
341 47. gnome@g.o
342 48.
343 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2004-10-10&chfieldto=2004-10-16&resolution=FIXED&assigned_to=gnome@g.o
344
345 New bug rankings
346 ----------------
347
348 The developers and teams who have been assigned the most new bugs during
349 this period are:
350
351 * Gentoo Linux Gnome Desktop Team[49], with 27 new bugs[50]
352 * Java team[51], with 25 new bugs[52]
353 * Gentoo Toolchain Maintainers[53], with 24 new bugs[54]
354 * Gentoo's Team for Core System packages[55], with 23 new bugs[56]
355 * osx porters[57], with 19 new bugs[58]
356 * AMD64 Porting Team[59], with 18 new bugs[60]
357 * Gentoo X-windows packagers[61], with 17 new bugs[62]
358 * Gentoo Kernel Bug Wranglers and Kernel Maintainers[63], with 15 new
359 bugs[64]
360 49. gnome@g.o
361 50.
362 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-10-10&chfieldto=2004-10-16&assigned_to=gnome@g.o
363 51. java@g.o
364 52.
365 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-10-10&chfieldto=2004-10-16&assigned_to=java@g.o
366 53. toolchain@g.o
367 54.
368 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-10-10&chfieldto=2004-10-16&assigned_to=toolchain@g.o
369 55. base-system@g.o
370 56.
371 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-10-10&chfieldto=2004-10-16&assigned_to=base-system@g.o
372 57. osx@g.o
373 58.
374 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-10-10&chfieldto=2004-10-16&assigned_to=osx@g.o
375 59. amd64@g.o
376 60.
377 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-10-10&chfieldto=2004-10-16&assigned_to=amd64@g.o
378 61. x11@g.o
379 62.
380 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-10-10&chfieldto=2004-10-16&assigned_to=x11@g.o
381 63. kernel@g.o
382 64.
383 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-10-10&chfieldto=2004-10-16&assigned_to=kernel@g.o
384
385 ==================
386 7. Tips and Tricks
387 ==================
388
389 Gentoo Initscripts
390 ------------------
391
392 This week we will have a look at some nice to know things about
393 initscripts that every sysadmin and user should at least have heard of
394 once.
395
396 By installing and administering your installation of Gentoo Linux you will
397 have learned about how to add services to a specific runlevel, and how to
398 start and stop those services.
399
400 But most users are not aware of some other nifty functions in the Gentoo
401 initscripts that have the potential for making their lives easier in
402 administering their Gentoo boxes.
403
404 Q: What to do if I can’t stop a service? What if the processes were killed
405 but my system thinks they are still running?
406
407 A: Execute /etc/init.d/<service> zap to reset the status of the service.
408
409
410 Q: How do I figure out if a service is running or not?
411
412 A: /etc/init.d/<service> status will tell you the current status of the
413 given service.
414
415
416 Q: And while we're at it, how can I see all services running?
417
418 A: rc-status lists all services that have been started and their current
419 status.
420
421
422 Q: How to restart a service?
423
424 A: /etc/init.d/<service> restart restarts the service.
425
426
427 Q: How do I find out what other services have to be started when I want to
428 use <service>?
429
430 A: /etc/init.d/<service> ineed will give you a list of services that need
431 to be running before this service can be started.
432
433
434 Q: Which services need/depend on this <service>?
435
436 A: /etc/init.d/<service> needsme lists all services that depend on the
437 service given.
438
439 For further information on how runlevels work in Gentoo Linux please take
440 a look at the Initscript guide[65] that is part of the Gentoo System
441 Documentation.
442 65. http://www.gentoo.org/doc/en/handbook/handbook-x86.xml?part=2&chap=5
443
444 ===========================
445 8. Moves, adds, and changes
446 ===========================
447
448 Moves
449 -----
450
451 The following developers recently left the Gentoo team:
452
453 * None this week
454
455 Adds
456 ----
457
458 The following developers recently joined the Gentoo Linux team:
459
460 * None this week
461
462 Changes
463 -------
464
465 The following developers recently changed roles within the Gentoo Linux
466 project:
467
468 * None this week
469
470 ====================
471 9. Contribute to GWN
472 ====================
473
474 Interested in contributing to the Gentoo Weekly Newsletter? Send us an
475 email[66].
476 66. gwn-feedback@g.o
477
478 ================
479 10. GWN feedback
480 ================
481
482 Please send us your feedback[67] and help make the GWN better.
483 67. gwn-feedback@g.o
484
485 ================================
486 11. GWN subscription information
487 ================================
488
489 To subscribe to the Gentoo Weekly Newsletter, send a blank email to
490 gentoo-gwn-subscribe@g.o.
491
492 To unsubscribe to the Gentoo Weekly Newsletter, send a blank email to
493 gentoo-gwn-unsubscribe@g.o from the email address you are
494 subscribed under.
495
496 ===================
497 12. Other languages
498 ===================
499
500 The Gentoo Weekly Newsletter is also available in the following languages:
501
502 * Danish[68]
503 * Dutch[69]
504 * English[70]
505 * German[71]
506 * French[72]
507 * Japanese[73]
508 * Italian[74]
509 * Polish[75]
510 * Portuguese (Brazil)[76]
511 * Portuguese (Portugal)[77]
512 * Russian[78]
513 * Spanish[79]
514 * Turkish[80]
515 68. http://www.gentoo.org/news/da/gwn/gwn.xml
516 69. http://www.gentoo.org/news/be/gwn/gwn.xml
517 70. http://www.gentoo.org/news/en/gwn/gwn.xml
518 71. http://www.gentoo.org/news/de/gwn/gwn.xml
519 72. http://www.gentoo.org/news/fr/gwn/gwn.xml
520 73. http://www.gentoo.org/news/ja/gwn/gwn.xml
521 74. http://www.gentoo.org/news/it/gwn/gwn.xml
522 75. http://www.gentoo.org/news/pl/gwn/gwn.xml
523 76. http://www.gentoo.org/news/br/gwn/gwn.xml
524 77. http://www.gentoo.org/news/pt/gwn/gwn.xml
525 78. http://www.gentoo.org/news/ru/gwn/gwn.xml
526 79. http://www.gentoo.org/news/es/gwn/gwn.xml
527 80. http://www.gentoo.org/news/tr/gwn/gwn.xml
528
529 Ulrich Plate <plate@g.o> - Editor
530 Brian Downey <bdowney@×××××××××××.net> - Author
531 Marc Hildebrand <zypher@g.o> - Author
532 Patrick Lauer <patrick@g.o> - Author
533 Emmet Wagle <ewagle@×××××.com> - Author
534
535
536 --
537 gentoo-gwn@g.o mailing list