Gentoo Archives: gentoo-gwn

From: Ulrich Plate <plate@g.o>
To: gentoo-gwn@××××××××××××.org
Subject: [gentoo-gwn] Gentoo Weekly Newsletter 28 February 2005
Date: Tue, 01 Mar 2005 00:52:59
Message-Id: 20050301020015.0a3216b6.plate@gentoo.org
1 ---------------------------------------------------------------------------
2 Gentoo Weekly Newsletter
3 http://www.gentoo.org/news/en/gwn/current.xml
4 This is the Gentoo Weekly Newsletter for the week of 28 February 2005.
5 ---------------------------------------------------------------------------
6
7 ==============
8 1. Gentoo News
9 ==============
10
11 First European Gentoo developer meeting
12 ---------------------------------------
13
14 Twentythree Gentoo developers from the European Union, Norway, Switzerland
15 and the U.S.attended the first official Gentoo developer meeting organized
16 in Brussels, borrowing the location and the occasion from the FOSDEM event
17 held last weekend. For two hours on Sunday morning, the Gentoo DevRoom in
18 one of the historic buildings of Université Libre de Bruxelles was
19 reserved for the internal meeting that for the first time brought together
20 people who have been working as a team for months or years, but had never
21 met in person. After a short round of introductions, the discussion
22 quickly centered on structural issues of Gentoo development. When
23 infrastructure provisioning and development was done by just a handful of
24 key persons, it was usually sufficient to holler requests into their
25 general direction, and they'd get the job done. Today, with a headcount of
26 over 350 developers and a great diversity of needs and ambitions, the
27 Brussel meeting unanimously suggested renovating the project's internal
28 structure, to reflect changes in its scope, to make active developers feel
29 better represented, and to prepare the ground for future scalability. The
30 result of the discussion will be drafted as a proposal to submit to
31 Gentoo's project managers and developers at large.
32
33 Figure 1.1: First Pan-European Gentoo developer meeting
34 http://www.gentoo.org/images/gwn/20050228_fosdem-devs.jpg
35
36 Note: Standing, from left to right: cryos, foser, tantive, pYrania, ian,
37 jaevorsz, koon, SeJo, pvdabeel, hansmi, lu_zero. Sitting in front: beejay,
38 luckyduck, plate, Pylon, zypher, Ferdy, BaSS, karltk, tove, bonsaikitten,
39 Kugelfang, KingTaco. Invisibly present (helping out at the booth): stkn.
40
41 FOSDEM 2005 expo and conference
42 -------------------------------
43
44 Gentoo's presence at the biggest open-source developer meeting in Europe
45 for the third year in a row was an outstanding experience for everyone who
46 attended. At an estimated 3500 participants, FOSDEM has outgrown its old
47 target audience of just developers from Benelux countries, and an
48 impressive line-up of presenters attracts open-source developers from all
49 over Europe and beyond to come to Brussels each year. Learning from
50 previous experience prevented the toilets from overflowing and sandwiches
51 from being sold out before everyone was fed, and with speakers like Alan
52 Cox and Richard Stallman in the main track and dozens of projects --
53 including Gentoo -- organizing their own developer rooms, the three
54 buildings entirely occupied by FOSDEM 2005 were buzzing with activity for
55 both days of the conference.
56
57 The DevRoom booked for the duration of the entire conference was densely
58 packed with Gentoo users and others interested in the twelve presentations
59 held by the Gentoo developers. Attendance fluctuated between a few dozen
60 and 80 people sitting and standing around the room, and the range of
61 topics covered general descriptions of the Gentoo project as well as
62 highly technical papers on specific development. Portage and Java
63 development were at the center of the attention, but even more exotic
64 presentations like the GNAP work of Thierry Carrez[1] in the embedded
65 space attracted highly focussed crowds. Most DevRoom presentations are
66 available for download from a central repository[2]. Outside of the
67 DevRoom, Damien Krotkine[3] held a "lightning talk" about his libconf
68 project[4] (the base for Gentoo's USE flag editor GUI profuse, among other
69 things), and last but not least, Marius Mauch[5] had the honour of
70 addressing the larger main track audience with his presentation of
71 Gentoo's Portage system.
72 1. koon@g.o
73 2. http://www.gentoo.org/proj/en/pr/docs/presentation-listing.xml
74 3. dams@g.o
75 4. http://www.libconf.net/
76 5. genone@g.o
77
78 Figure 1.1: Jochen Maes giving the keynote speech at the Gentoo DevRoom
79 http://www.gentoo.org/images/gwn/20050228_fosdem-keynote.jpg
80
81 Detached from the DevRoom in a separate building, Gentoo had a
82 double-sized booth in the hallway, located between the Mozilla table
83 celebrating the first anniversary of Firefox, and a project for converting
84 inexpensive Korean Gameboy clones ("Gamepark"[6]) into fully-fledged
85 Linux-PDAs. On display at the Gentoo stand were four of Genesi's
86 PegasosPPC Open Desktop Workstations (two of them demoing the new Cube
87 LiveCD for PPC[7]), several x86 and PPC notebooks, and TGL's exotic
88 Kuro-Box[8] running as an MP3 streaming server. Visitors were jostling
89 through the narrow hallway, stopping for a chat with the Gentooists on
90 duty, grabbing stickers or sweets (from a box labeled "/dev/snack"), or to
91 buy T-shirts and other Gentoo paraphernalia.
92 6. http://www.gp32linux.com/
93 7.
94 http://www.gentoo.org/news/en/gwn/20050131-newsletter.xml#doc_chap1_sect3
95 8. http://www.gentoo.org/news/en/gwn/20050221-newsletter.xml#doc_chap2
96
97 Figure 1.2: Busy hours at the Gentoo booth
98 http://www.gentoo.org/images/gwn/20050228_fosdem-booth.jpg
99
100 The inofficial, yet popular "Fizzlewizzle" releases collated by Tobias
101 Scherbaum[9], were completely sold out within a few hours. Special FOSDEM
102 editions of Gentoo Linux CDs have become a tradition of their own, but
103 this year's "Fizzlewizzle" was available for the first time on both LiveCD
104 and -DVDs. The ISOs had been updated with the latest Portage snapshot just
105 three days before FOSDEM opened its gates, spin in a default English
106 environment as opposed to earlier German localizations, and contain a full
107 KDE 3.3 installation that can be run directly from the media, without
108 installing on harddisk first. The DVD encompasses 2.2GB worth of sources
109 on top of the usual CD image contents, and both images continue to be
110 available via bittorrent[10], for x86 or PPC, along with the Cube LiveCD
111 for PPC.
112 9. dertobi123@g.o
113 10. http://tracker.netdomination.org
114
115 Figure 1.3: Brussels landmark monument, the Atomium, on Gentoo's FOSDEM
116 edition LiveDVD cover
117 http://www.gentoo.org/images/gwn/20050228_fosdem-dvd.jpg
118
119 Note: Artwork by Christian Hartmann, download the full-size cover art for
120 printing DVD and CD labels, for PPC and x86.
121
122 FOSDEM's famous quantum singularity, first spotted by Daniel Robbins
123 during his visit to the 2003 conference and rediscovered on the floor of
124 Brussel's youth hostel last year, had migrated to one of Europe's most
125 famous techno clubs, Fuse, where a group of Gentoo developers claims to
126 have seen it hovering over the dance floor on Saturday night.
127
128 Apache unmasked
129 ---------------
130
131 The Gentoo Apache Team has unmasked package updates that have been in the
132 works for a while. Thanks to additional help from developers who joined
133 the team over the past few months, the announcement many Apache users have
134 been waiting for could finally be made last Sunday. Some of the major
135 changes include:
136
137 * New configuration and configuration locations to more closely match
138 upstream and reduce confusion for users coming from other distributions.
139 * Modules now use a centralized eclass that builds, installs, and
140 displays standard information on enabling the module. This allows easier
141 maintenance of existing modules, and allows us to more rapidly develop
142 ebuilds for modules that are not yet in the tree.
143 * Expanded USE flags to customize your apache installation now let you
144 choose multiple MPMs to build and make it easy to switch between them.
145 * A new gentoo-webroot that will eventually provide a gentoo-themed
146 icon-set, error documents, and default website. This has been put in its
147 own package, and includes a USE-flag to not install the gentoo-webroot
148 into /var/www/localhost - useful if you put your own website there.
149 * And much more, including many bug fixes.
150
151 When upgrading Apache, necessary steps will include merging customizations
152 in /etc/apache2/httpd.conf and updating all currently used modules to
153 revisions that support the new eclass. Detailed documentation[11] is
154 available, and if you have any questions or problems during migration,
155 talk to the Apache team on #gentoo-apache at irc.freenode.net or via the
156 mailing list, gentoo-web-user@g.o.
157 11. http://dev.gentoo.org/~vericgar/doc/apache-package-refresh.html
158
159 New Gentoo/FreeBSD documentation available
160 ------------------------------------------
161
162 Since our recent article[12] about the Gentoo/FreeBSD project in the GWN's
163 Future Zone, Gentoo developer Michael Kohl[13] has taken over maintenance
164 of the related documentation. The new document[14] is based on Aaron
165 Walker's original installation instructions, and contains lots of
166 contributions by Gentoo/FreeBSD project lead Otavio R. Piske[15].
167 12. http://www.gentoo.org/news/en/gwn/20050207-newsletter.xml
168 13. citizen428@g.o
169 14. http://dev.gentoo.org/~citizen428/doc/gentoo-freebsd.html
170 15. angusyoung@g.o
171
172 ==================
173 2. Gentoo security
174 ==================
175
176 PuTTY: Remote code execution
177 ----------------------------
178
179 PuTTY was found to contain vulnerabilities that can allow a malicious SFTP
180 server to execute arbitrary code on unsuspecting PSCP and PSFTP clients.
181
182 For more information, please see the GLSA Announcement[16]
183 16. http://www.gentoo.org/security/en/glsa/glsa-200502-28.xml
184
185 Cyrus IMAP Server: Multiple overflow vulnerabilities
186 ----------------------------------------------------
187
188 The Cyrus IMAP Server is affected by several overflow vulnerabilities
189 which could potentially lead to the remote execution of arbitrary code.
190
191 For more information, please see the GLSA Announcement[17]
192 17. http://www.gentoo.org/security/en/glsa/glsa-200502-29.xml
193
194 cmd5checkpw: Local password leak vulnerability
195 ----------------------------------------------
196
197 cmd5checkpw contains a flaw allowing local users to access other users
198 cmd5checkpw passwords.
199
200 For more information, please see the GLSA Announcement[18]
201 18. http://www.gentoo.org/security/en/glsa/glsa-200502-30.xml
202
203 uim: Privilege escalation vulnerability
204 ---------------------------------------
205
206 Under certain conditions, applications linked against uim suffer from a
207 privilege escalation vulnerability.
208
209 For more information, please see the GLSA Announcement[19]
210 19. http://www.gentoo.org/security/en/glsa/glsa-200502-31.xml
211
212 UnAce: Buffer overflow and directory traversal vulnerabilities
213 --------------------------------------------------------------
214
215 UnAce is vulnerable to several buffer overflow and directory traversal
216 attacks.
217
218 For more information, please see the GLSA Announcement[20]
219 20. http://www.gentoo.org/security/en/glsa/glsa-200502-32.xml
220
221 =========================
222 3. Heard in the community
223 =========================
224
225 gentoo-catalyst
226 ---------------
227
228 Catalyst vs Knoppix Confusion
229
230 This week a user asked if Catalyst can be used to build a Knoppix-like
231 LiveCD based on Gentoo Linux. General consensus was that the tool isn't
232 really there yet, but improvements are under way to enhance its
233 functionality into this direction. Robert Paskowitz[21] pointed out a
234 Catalyst-made LiveCD, Caster[22], that provides a good example of what's
235 already possible today.
236 21. rpaskowitz@×××××××××.ca
237 22. http://zaheer.merali.org/mediawiki/index.php/Caster
238
239 Note: Until popular mailing list archives like Gmane pick up the
240 gentoo-catalyst mailing list, Michael Kohl keeps a regularly updated
241 archive in a temporary home at his developer webspace.
242
243 * Catalyst vs Knoppix Confusion[23]
244 23.
245 http://dev.gentoo.org/~citizen428/hypermail/gentoo-catalyst/0502/0233.html
246
247 ======================
248 4. Gentoo in the press
249 ======================
250
251 eWeek (28 February 2005)
252 ------------------------
253
254 ZiffDavis analyst Jason Brooks summarizes eWeek Lab's evaluation[24] of
255 Gentoo Linux for enterprise use. The article opens stating that "Gentoo
256 Linux has quickly grown into one of the world's most popular Linux
257 distributions", and "the system's source code-based software installation
258 mechanism makes (it) a good fit for testing the latest versions of key
259 open-source software components." However, "its reputation as a
260 bleeding-edge distribution (...) has so far dimmed its prospects for
261 enterprise adoption." and Brooks therefore "hesitates to recommend" Gentoo
262 for wide adoption in production environments. The article walks through
263 some basic pros and cons of source-based distributions, and finds a few
264 potential problems in all-free Linux distributions as opposed to
265 commercial vendors, but when testing the installation of VMWare as an
266 example for non-free software packages, the author readily acknowledges
267 that "Gentoo makes the process of obtaining the software more elegant than
268 any other Linux distribution we've tested."
269 24. http://www.eweek.com/article2/0,1759,1770228,00.asp
270
271 OSdir.com (22 February 2005)
272 ----------------------------
273
274 O'Reilly's online magazine on operating systems finds unusually harsh
275 words for Linux distributor RedHat's attitude of the past. In the article
276 titled "Best of Linux World Coverage: The Redhat Mistake"[25], Gentoo is
277 mentioned as stepping in "where they messed up" by "abandoning their
278 'freebie' Redhat version two years ago to focus exclusively on their
279 enterprise 'pay up big time' version," a move that was "not exactly the
280 wisest thing to do," says OSdir.com's managing editor Steve Mallett.
281 25. http://www.osdir.com/Article4265.phtml
282
283 ZDNet (18 February 2005)
284 ------------------------
285
286 In a similar article[26] about RedHat's "misstep in its relations with
287 technology enthusiasts" and the plan to "rectify the situation with a more
288 aggressive Fedora project," CNET author Stephen Shankland observes that
289 "Red Hat has ample competition. Projects such as Gentoo lure hard-core
290 Linux programmers, while Sun Microsystems is trying to build its own
291 community of programmers around its OpenSolaris project."
292 26. http://news.zdnet.com/2100-3513_22-5582945.html?tag=nl.e539
293
294 ===========
295 5. Bugzilla
296 ===========
297
298 Summary
299 -------
300
301 * Statistics
302 * Closed bug ranking
303 * New bug rankings
304
305 Statistics
306 ----------
307
308 The Gentoo community uses Bugzilla (bugs.gentoo.org[27]) to record and
309 track bugs, notifications, suggestions and other interactions with the
310 development team. Between 20 February 2005 and 27 February 2005, activity
311 on the site has resulted in:
312 27. http://bugs.gentoo.org
313
314 * 789 new bugs during this period
315 * 443 bugs closed or resolved during this period
316 * 33 previously closed bugs were reopened this period
317
318 Of the 8054 currently open bugs: 100 are labeled 'blocker', 233 are
319 labeled 'critical', and 595 are labeled 'major'.
320
321 Closed bug rankings
322 -------------------
323
324 The developers and teams who have closed the most bugs during this period
325 are:
326
327 * AMD64 Porting Team[28], with 49 closed bugs[29]
328 * Gentoo Games[30], with 24 closed bugs[31]
329 * Mozilla Gentoo Team[32], with 17 closed bugs[33]
330 * Gentoo Web Proxy Developers[34], with 15 closed bugs[35]
331 * PAM Gentoo Team[36], with 15 closed bugs[37]
332 * so[38], with 14 closed bugs[39]
333 * Netmon Herd[40], with 14 closed bugs[41]
334 * Gentoo KDE team[42], with 13 closed bugs[43]
335 28. amd64@g.o
336 29.
337 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-02-20&chfieldto=2005-02-27&resolution=FIXED&assigned_to=amd64@g.o
338 30. games@g.o
339 31.
340 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-02-20&chfieldto=2005-02-27&resolution=FIXED&assigned_to=games@g.o
341 32. mozilla@g.o
342 33.
343 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-02-20&chfieldto=2005-02-27&resolution=FIXED&assigned_to=mozilla@g.o
344 34. www-proxy@g.o
345 35.
346 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-02-20&chfieldto=2005-02-27&resolution=FIXED&assigned_to=www-proxy@g.o
347 36. pam-bugs@g.o
348 37.
349 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-02-20&chfieldto=2005-02-27&resolution=FIXED&assigned_to=pam-bugs@g.o
350 38. so@g.o
351 39.
352 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-02-20&chfieldto=2005-02-27&resolution=FIXED&assigned_to=so@g.o
353 40. netmon@g.o
354 41.
355 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-02-20&chfieldto=2005-02-27&resolution=FIXED&assigned_to=netmon@g.o
356 42. kde@g.o
357 43.
358 http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-02-20&chfieldto=2005-02-27&resolution=FIXED&assigned_to=kde@g.o
359
360 New bug rankings
361 ----------------
362
363 The developers and teams who have been assigned the most new bugs during
364 this period are:
365
366 * Gentoo Sound Team[44], with 36 new bugs[45]
367 * AMD64 Porting Team[46], with 21 new bugs[47]
368 * Gentoo Science Related Packages[48], with 16 new bugs[49]
369 * Gentoo Linux Gnome Desktop Team[50], with 16 new bugs[51]
370 * Gentoo X-windows packagers[52], with 14 new bugs[53]
371 * Gentoo's Team for Core System packages[54], with 14 new bugs[55]
372 * Gentoo Games[56], with 13 new bugs[57]
373 * PHP Bugs[58], with 12 new bugs[59]
374 44. sound@g.o
375 45.
376 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-02-20&chfieldto=2005-02-27&assigned_to=sound@g.o
377 46. amd64@g.o
378 47.
379 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-02-20&chfieldto=2005-02-27&assigned_to=amd64@g.o
380 48. sci@g.o
381 49.
382 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-02-20&chfieldto=2005-02-27&assigned_to=sci@g.o
383 50. gnome@g.o
384 51.
385 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-02-20&chfieldto=2005-02-27&assigned_to=gnome@g.o
386 52. x11@g.o
387 53.
388 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-02-20&chfieldto=2005-02-27&assigned_to=x11@g.o
389 54. base-system@g.o
390 55.
391 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-02-20&chfieldto=2005-02-27&assigned_to=base-system@g.o
392 56. games@g.o
393 57.
394 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-02-20&chfieldto=2005-02-27&assigned_to=games@g.o
395 58. php-bugs@g.o
396 59.
397 http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-02-20&chfieldto=2005-02-27&assigned_to=php-bugs@g.o
398
399 ===========================
400 6. Moves, adds, and changes
401 ===========================
402
403 Moves
404 -----
405
406 The following developers recently left the Gentoo team:
407
408 * None this week
409
410 Adds
411 ----
412
413 The following developers recently joined the Gentoo Linux team:
414
415 * Alex Howells (Astinus) - AMD64
416 * Elfyn McBratney (beu) - Apache
417
418 Changes
419 -------
420
421 The following developers recently changed roles within the Gentoo Linux
422 project:
423
424 * Lance Albertson (ramereth) - New operational lead for the
425 infrastructure project
426
427 ====================
428 7. Contribute to GWN
429 ====================
430
431 Interested in contributing to the Gentoo Weekly Newsletter? Send us an
432 email[60].
433 60. gwn-feedback@g.o
434
435 ===============
436 8. GWN feedback
437 ===============
438
439 Please send us your feedback[61] and help make the GWN better.
440 61. gwn-feedback@g.o
441
442 ===============================
443 9. GWN subscription information
444 ===============================
445
446 To subscribe to the Gentoo Weekly Newsletter, send a blank email to
447 gentoo-gwn-subscribe@g.o.
448
449 To unsubscribe to the Gentoo Weekly Newsletter, send a blank email to
450 gentoo-gwn-unsubscribe@g.o from the email address you are
451 subscribed under.
452
453 ===================
454 10. Other languages
455 ===================
456
457 The Gentoo Weekly Newsletter is also available in the following languages:
458
459 * Danish[62]
460 * Dutch[63]
461 * English[64]
462 * German[65]
463 * french[66]
464 * japanese[67]
465 * italian[68]
466 * polish[69]
467 * portuguese (brazil)[70]
468 * portuguese (portugal)[71]
469 * russian[72]
470 * spanish[73]
471 * turkish[74]
472 62. http://www.gentoo.org/news/da/gwn/gwn.xml
473 63. http://www.gentoo.org/news/nl/gwn/gwn.xml
474 64. http://www.gentoo.org/news/en/gwn/gwn.xml
475 65. http://www.gentoo.org/news/de/gwn/gwn.xml
476 66. http://www.gentoo.org/news/fr/gwn/gwn.xml
477 67. http://www.gentoo.org/news/ja/gwn/gwn.xml
478 68. http://www.gentoo.org/news/it/gwn/gwn.xml
479 69. http://www.gentoo.org/news/pl/gwn/gwn.xml
480 70. http://www.gentoo.org/news/pt_br/gwn/gwn.xml
481 71. http://www.gentoo.org/news/pt/gwn/gwn.xml
482 72. http://www.gentoo.org/news/ru/gwn/gwn.xml
483 73. http://www.gentoo.org/news/es/gwn/gwn.xml
484 74. http://www.gentoo.org/news/tr/gwn/gwn.xml
485
486 Ulrich Plate <plate@g.o> - Editor
487 Michael Kohl <citizen428@g.o> - Author
488 Michael Stewart <vericgar@g.o> - Author
489
490 --
491 gentoo-gwn@g.o mailing list