Gentoo Archives: gentoo-gwn

From: Lars Weiler <pylon@g.o>
To: gentoo-gwn@l.g.o
Subject: [gentoo-gwn] Gentoo Weekly Newsletter 7 November 2005
Date: Mon, 07 Nov 2005 00:22:32
Message-Id: 20051107000049.GF20632@celeborn.wh-og.hs-niederrhein.de
1 ---------------------------------------------------------------------------
2 Gentoo Weekly Newsletter
3 http://www.gentoo.org/news/en/gwn/current.xml
4 This is the Gentoo Weekly Newsletter for the week of 7 November 2005.
5 ---------------------------------------------------------------------------
6
7 ==============
8 1. Gentoo news
9 ==============
10
11 New GLEP to manage important update information
12 -----------------------------------------------
13
14 One of the longest-standing discussions between Gentoo developers and
15 users centers around the little einfo warnings that are being displayed
16 briefly whenever you emerge a package that contains crucial additional
17 information on how to upgrade things, and what configuration files to
18 watch out for. They're important, very much so, but in essence useful only
19 to those who watch a compilation scroll past their screens, and despite
20 several earlier efforts have never been made to stick around other places
21 in Portage to be consulted later, at leisure, after a lengthy update of
22 several packages at once. Now Ciaran McCreesh[1] has set out for yet
23 another attempt at solving this problem: He is the author of a formal
24 proposal[2] for an automatic distribution system for critical news that is
25 to complement existing Gentoo information channels (Forums,
26 gentoo-announce mailing list, website and the GWN), but aims to be part of
27 Portage itself in order to get pushed out to Gentoo users without them
28 having to pull anything in.
29
30 1. ciaranm@g.o
31 2. http://www.gentoo.org/proj/en/glep/glep-0042.html
32
33 ===============
34 2. User stories
35 ===============
36
37 Interview with Jacob Lindberg, a Linux Specialist for Brenntag Nordic
38 ---------------------------------------------------------------------
39
40 Figure 2.1: Jacob Lindberg, Linux Specialist for Brenntag Nordic
41 http://www.gentoo.org/images/gwn/20051107_jacob.jpg
42
43 Who are you and where do you work?
44
45 I'm Jacob Lindberg, 30 years old working as a Linux Specialist for
46 Brenntag Nordic in Denmark since March 2004. I recently got married, have
47 no kids, but a dog and 2 blue-russian cats, Phoebe and Joey, named after
48 Friends (the comedy).
49
50 Brenntag Nordic has offices and plants in Denmark, Sweden, Norway and
51 Finland and is a part of the Brenntag Group. They consolidated a lot of
52 their servers[3] to Linux in 2003. Unfortunately the cost of external
53 consultants was very high, services went down from time to time, and the
54 consultants didn't have the knowledge to fix the various problems. The
55 solutions were based on SuSE. As an old FreeBSD man, I don't like anything
56 in binaries. I want my stuff from source and configurable. And as a lot of
57 other Linux guys I have been through the hell of RPM dependencies. No
58 more! This is why way back Gentoo caught my attention, and it has never
59 left it since.
60
61 3. http://www-306.ibm.com/software/success/cssdb.nsf/CS/DNSD-5QJENP
62
63 Where do you use Gentoo? What did it replace?
64
65 We have no Linux servers not running Gentoo, so it's everywhere that's
66 possible. We got the following services from Gentoo:
67
68 * Samba, doing PDC, fileserver and Image server
69 * Squid, doing proxy and filtering
70 * Postfix and spamassassin, scanning all incoming and outgoing emails
71 * Bind9, running our dns internally and externally
72 * IPtables, running as firewall between our datacenter and our 10
73 locations (clients)
74 * rsync, doing our Gentoo mirror
75 * proftpd and tftp, doing images for Cisco equipment and such
76 * Backup server
77 * Log server
78
79 Why do you use POWER4/5 machines?
80
81 Our iSeries machines are running SAP and Lotus Notes in the OS400
82 environment. The rest are Linux LPARs (logical partitions). In the new
83 year we will exchange the 870 with an 570 (i5), so everything is changed
84 to POWER5. The future plan is after changing to POWER5 we have a lot more
85 power and are able to supply more services. The reason for using IBM
86 hardware is that it's rock stable – and we have the opportunity to run
87 things directly from the OS400 also.
88
89 It's not easy to get something running on fairly non-documented
90 architecture (iSeries on PPC64) which was the situation back in early
91 2004. I started out with a pSeries LiveCD which didn't work at all. After
92 some tricks, and some help from the community I managed to get a nws
93 working which contained the LiveCD, and a kernel in the IFS. Now I could
94 boot Gentoo. This was done on my old 270 (RS/6000 processor as far as I
95 remember). This was quickly adapted to the 825 (POWER4) and 870 (POWER4).
96 Today the 2005.0 and 2005.1 LiveCD are working on the i5 machines, but
97 still not on the 825 and 870 machine.
98
99 The difference between x86 and PPC64 is mostly when installing and
100 configuring, especially the kernel. All your environment has to be
101 configured correctly for the PPC64 to work also. When working inside
102 Gentoo you don't see any big difference except uname returns another
103 architecture. This is because of the way Gentoo works.
104
105 Where does Gentoo need improvement?
106
107 I'm applying to become a member of the PPC64 developer team. In this way,
108 I can be a part of the improvement. I think the GLEP webpage[4] shows some
109 nice features for the future.
110
111 4. http://glep.gentoo.org
112
113 What are your experiences with the Gentoo community?
114
115 It's amazing how many people are contributing to the community. This is
116 why I want to do it also. But my experience is that it's hard to find a
117 problem which can't be solved with the help from the community. So it's
118 very positive.
119
120 =========================
121 3. Heard in the community
122 =========================
123
124 gentoo-dev
125 ----------
126
127 Getting important updates to users
128
129 One of the largest threads of the last week split into four subthreads.
130 The heated discussion revolved around a central problem that has not
131 received the needed attention for a long time: How do you make sure that
132 users get important information about updates, changes etc.? We have the
133 gentoo.org website, an RSS feed, the GWN, emerge messages etc. - but there
134 is no central authorative sources for updates. The GLEP proposals by Chris
135 White[5] and Ciaran McCreesh[6] drifted away into a very heated dicsussion
136 (a flamewar one might say) about XML and other things.
137
138 5. chriswhite@g.o
139 6. ciaranm@g.o
140
141 * Getting important updates to users[7]
142 * GLEP 42 (Was: Getting Important Updates To Users) [8]
143 * GLEP ??: Critical News Reporting [9]
144 * GLEP 42 "Critical News Reporting" Round Two [10]
145 7. http://thread.gmane.org/gmane.linux.gentoo.devel/32380
146 8. http://thread.gmane.org/gmane.linux.gentoo.devel/32427
147 9. http://thread.gmane.org/gmane.linux.gentoo.devel/32438
148 10. http://thread.gmane.org/gmane.linux.gentoo.devel/32657
149
150
151 Proposed changes to base profile for Gentoo/ALT
152
153 Diego Pettenò[11] offers some patches to the profiles so that the base
154 profile is more generic and some linux-specific things are moved away from
155 the "base" profile to "default-linux". This is another step on the way to
156 integrate Gentoo/BSD.
157
158 11. flameeyes@g.o
159
160 * Proposed changes to base profile for Gentoo/ALT [12]
161 12. http://thread.gmane.org/gmane.linux.gentoo.devel/32507
162
163
164 =======================
165 4. Gentoo international
166 =======================
167
168 Italy: GeCHI conference in November
169 -----------------------------------
170
171 26 November 2005 is going to be the date for the 5th time that Italy's
172 open-source movement organizes a national Linux Day, and the 3rd time that
173 this Italy-wide event is a chance for the ever-growing Italian Gentoo
174 users community to prepare for some evangelism of their own. This year the
175 3rd national meeting called Gentoo Day will be organized in collaboration
176 with the VELug[13] (Venice Free Software Users Group). Thanks to the
177 support of the local authorities, the location of this year's meeting will
178 be Villa Franchin, Viale Garibaldi 155 (quartiere Carpenedo-Bissuola), in
179 the city of Mestre, near Venice.
180
181 13. http://www.velug.it
182
183 Gentooists active in the Gentoo Channel Italia[14] (GeCHI) framework will
184 present some talks about different topics starting from an "Introduction
185 to Gentoo", to "Gentoo Linux Installer" to "Having fun with Gentoo" ending
186 with "Gimp: From 0 to Dalì". There will be the possibility to buy some new
187 cool gadgets, like the world-famous GeCHI T-Shirt or some stickers and
188 posters.
189
190 14. http://www.gechi.it
191
192 Don't miss this chance to meet and mingle with other Italian Gentoo users
193 and developers! If you want to join the GeCHI in this endeavour check this
194 Forum thread[15] and the GeCHI's own forum[16] (both links in Italian)."
195
196 15. http://forums.gentoo.org/viewtopic-p-2853724.html
197 16. http://www.gechi.it/forums/viewtopic.php?p=1632
198
199 Japan: GentooJP receives Andrea Barisani
200 ----------------------------------------
201
202 The GentooJP crowd[17] will play cicerone to visiting Gentoo developer
203 Andrea Barisani[18] with a nite-seeing tour of the more indigenous back
204 alleys of Tokyo's Shibuya district, on the schedule for Sunday, 13
205 November 2005. Andrea is in town for a presentation at the PacSec
206 conference[19], and if you would like to join the outing, make sure you're
207 at the Hachiko statue in front of Shibuya station by 18:30 hours.
208
209 17. http://www.gentoo.gr.jp
210 18. lcars@g.o
211 19. http://www.gentoo.org/news/en/gwn/20051003-newsletter.xml#doc_chap2_sect2
212
213 Note: Confirm your participation by sending a short note to the
214 gentoojp-misc@××××××××××××.jp mailing list, please.
215
216 ======================
217 5. Gentoo in the press
218 ======================
219
220 Desktop Linux (4 November 2005)
221 -------------------------------
222
223 A new book from O'Reilly, the Linux Desktop Pocket Reference[20], provides
224 a concise overview of the "five most popular distributions" listed in
225 alphabetical order, Gentoo after Fedora, and followed by Mandriva, SUSE
226 and Ubuntu. Author David Brickner tries to cut through the undergrowth of
227 too much information that he finds "hard to sift through it all, to know
228 what is accurate and what is up-to-date," and which he identifies as the
229 "biggest obstacle to faster adoption of Linux on the desktop." Chapter 1
230 containing a comparison of the five distributions is available as a PDF
231 sample document[21], and provides a particularly enthusiastic assessment
232 of Gentoo's main assets: Portage and the documentation.
233
234 20. http://www.desktoplinux.com/news/NS6574473318.html
235 21. http://www.oreilly.com/catalog/linuxdesktoppr/chapter/ch01.pdf
236
237 =========================
238 6. Gentoo developer moves
239 =========================
240
241 Moves
242 -----
243
244 The following developers recently left the Gentoo project:
245
246 * None this week
247
248 Adds
249 ----
250
251 The following developers recently joined the Gentoo project:
252
253 * Markus Dittrich (markusle) - app-sci
254 * Michael Cummings (mcummings - reinstalled after leaving two months ago) - perl
255 * Alexey Chumakov (achumakov) - Russian translation
256
257 Changes
258 -------
259
260 The following developers recently changed roles within the Gentoo project:
261
262 * None this week
263
264 ==================
265 7. Gentoo Security
266 ==================
267
268 libgda: Format string vulnerabilities
269 -------------------------------------
270
271 Two format string vulnerabilities in libgda may lead to the execution of
272 arbitrary code.
273
274 For more information, please see the GLSA Announcement[22]
275
276 22. http://www.gentoo.org/security/en/glsa/glsa-200511-01.xml
277
278 QDBM, ImageMagick, GDAL: RUNPATH issues
279 ---------------------------------------
280
281 Multiple packages suffer from RUNPATH issues that may allow users in the
282 "portage" group to escalate privileges.
283
284 For more information, please see the GLSA Announcement[23]
285
286 23. http://www.gentoo.org/security/en/glsa/glsa-200511-02.xml
287
288 giflib: Multiple vulnerabilities
289 --------------------------------
290
291 giflib may dereference NULL or write out of bounds when processing
292 malformed images, potentially resulting in Denial of Service or arbitrary
293 code execution.
294
295 For more information, please see the GLSA Announcement[24]
296
297 24. http://www.gentoo.org/security/en/glsa/glsa-200511-03.xml
298
299 libgda: Format string vulnerabilities
300 -------------------------------------
301
302 Two format string vulnerabilities in libgda may lead to the execution of
303 arbitrary code.
304
305 For more information, please see the GLSA Announcement[25]
306
307 25. http://www.gentoo.org/security/en/glsa/glsa-200511-01.xml
308
309 QDBM, ImageMagick, GDAL: RUNPATH issues
310 ---------------------------------------
311
312 Multiple packages suffer from RUNPATH issues that may allow users in the
313 "portage" group to escalate privileges.
314
315 For more information, please see the GLSA Announcement[26]
316
317 26. http://www.gentoo.org/security/en/glsa/glsa-200511-02.xml
318
319 giflib: Multiple vulnerabilities
320 --------------------------------
321
322 giflib may dereference NULL or write out of bounds when processing
323 malformed images, potentially resulting in Denial of Service or arbitrary
324 code execution.
325
326 For more information, please see the GLSA Announcement[27]
327
328 27. http://www.gentoo.org/security/en/glsa/glsa-200511-03.xml
329
330 ClamAV: Multiple vulnerabilities
331 --------------------------------
332
333 ClamAV has many security flaws which make it vulnerable to remote
334 execution of arbitrary code and a Denial of Service.
335
336 For more information, please see the GLSA Announcement[28]
337
338 28. http://www.gentoo.org/security/en/glsa/glsa-200511-04.xml
339
340 GNUMP3d: Directory traversal and XSS vulnerabilities
341 ----------------------------------------------------
342
343 GNUMP3d is vulnerable to directory traversal and cross-site scripting
344 attacks that may result in information disclosure or the compromise of a
345 browser.
346
347 For more information, please see the GLSA Announcement[29]
348
349 29. http://www.gentoo.org/security/en/glsa/glsa-200511-05.xml
350
351 fetchmail: Password exposure in fetchmailconf
352 ---------------------------------------------
353
354 fetchmailconf fails to properly handle file permissions, temporarily
355 exposing sensitive information to other local users.
356
357 For more information, please see the GLSA Announcement[30]
358
359 30. http://www.gentoo.org/security/en/glsa/glsa-200511-06.xml
360
361 OpenVPN: Multiple vulnerabilities
362 ---------------------------------
363
364 The OpenVPN client is potentially vulnerable to the execution of arbitrary
365 code and the OpenVPN server is vulnerable to a Denial of Service issue.
366
367 For more information, please see the GLSA Announcement[31]
368
369 31. http://www.gentoo.org/security/en/glsa/glsa-200511-07.xml
370
371 ===========
372 8. Bugzilla
373 ===========
374
375 Statistics
376 ----------
377
378 The Gentoo community uses Bugzilla (bugs.gentoo.org[32]) to record and
379 track bugs, notifications, suggestions and other interactions with the
380 development team. Between 29 October 2005 and 05 November 2005, activity
381 on the site has resulted in:
382
383 32. http://bugs.gentoo.org
384
385 * 756 new bugs during this period
386 * 437 bugs closed or resolved during this period
387 * 36 previously closed bugs were reopened this period
388
389 Of the 8861 currently open bugs: 99 are labeled 'blocker', 191 are labeled
390 'critical', and 552 are labeled 'major'.
391
392 Closed bug rankings
393 -------------------
394
395 The developers and teams who have closed the most bugs during this period
396 are:
397
398 * Gentoo for Mac OS X[33], with 52 closed bugs[34]
399 * Gentoo Sound Team[35], with 18 closed bugs[36]
400 * media-gfx herd[37], with 14 closed bugs[38]
401 * Gentoo Developers for the x86 Architecture[39], with 12 closed bugs[40]
402
403 * Gentoo Linux Gnome Desktop Team[41], with 12 closed bugs[42]
404 * Gentoo Games[43], with 12 closed bugs[44]
405 * Gentoo Security[45], with 11 closed bugs[46]
406 * Python Gentoo Team[47], with 11 closed bugs[48]
407 33. ppc-macos@g.o
408 34. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-10-29&chfieldto=2005-11-05&resolution=FIXED&assigned_to=ppc-macos@g.o
409 35. sound@g.o
410 36. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-10-29&chfieldto=2005-11-05&resolution=FIXED&assigned_to=sound@g.o
411 37. graphics@g.o
412 38. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-10-29&chfieldto=2005-11-05&resolution=FIXED&assigned_to=graphics@g.o
413 39. x86@g.o
414 40. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-10-29&chfieldto=2005-11-05&resolution=FIXED&assigned_to=x86@g.o
415 41. gnome@g.o
416 42. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-10-29&chfieldto=2005-11-05&resolution=FIXED&assigned_to=gnome@g.o
417 43. games@g.o
418 44. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-10-29&chfieldto=2005-11-05&resolution=FIXED&assigned_to=games@g.o
419 45. security@g.o
420 46. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-10-29&chfieldto=2005-11-05&resolution=FIXED&assigned_to=security@g.o
421 47. python@g.o
422 48. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&chfield=bug_status&chfieldfrom=2005-10-29&chfieldto=2005-11-05&resolution=FIXED&assigned_to=python@g.o
423
424
425 New bug rankings
426 ----------------
427
428 The developers and teams who have been assigned the most new bugs during
429 this period are:
430
431 * Default Assignee for New Packages[49], with 36 new bugs[50]
432 * GNOME Office[51], with 33 new bugs[52]
433 * Luis Medinas[53], with 24 new bugs[54]
434 * Default Assignee for Orphaned Packages[55], with 10 new bugs[56]
435 * X11 External Driver Maintainers[57], with 9 new bugs[58]
436 * Gentoo Sound Team[59], with 8 new bugs[60]
437 * Mobile Herd[61], with 8 new bugs[62]
438 * Gentoo Science Related Packages[63], with 7 new bugs[64]
439 49. maintainer-wanted@g.o
440 50. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-10-29&chfieldto=2005-11-05&assigned_to=maintainer-wanted@g.o
441 51. gnome-office@g.o
442 52. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-10-29&chfieldto=2005-11-05&assigned_to=gnome-office@g.o
443 53. metalgod@g.o
444 54. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-10-29&chfieldto=2005-11-05&assigned_to=metalgod@g.o
445 55. maintainer-needed@g.o
446 56. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-10-29&chfieldto=2005-11-05&assigned_to=maintainer-needed@g.o
447 57. x11-drivers@g.o
448 58. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-10-29&chfieldto=2005-11-05&assigned_to=x11-drivers@g.o
449 59. sound@g.o
450 60. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-10-29&chfieldto=2005-11-05&assigned_to=sound@g.o
451 61. mobile@g.o
452 62. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-10-29&chfieldto=2005-11-05&assigned_to=mobile@g.o
453 63. sci@g.o
454 64. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2005-10-29&chfieldto=2005-11-05&assigned_to=sci@g.o
455
456
457 ===============
458 9. GWN feedback
459 ===============
460
461 Please send us your feedback[65] and help make the GWN better.
462
463 65. gwn-feedback@g.o
464
465 ================================
466 10. GWN subscription information
467 ================================
468
469 To subscribe to the Gentoo Weekly Newsletter, send a blank email to
470 gentoo-gwn+subscribe@g.o.
471
472 To unsubscribe to the Gentoo Weekly Newsletter, send a blank email to
473 gentoo-gwn+unsubscribe@g.o from the email address you are
474 subscribed under.
475
476 ===================
477 11. Other languages
478 ===================
479
480 The Gentoo Weekly Newsletter is also available in the following languages:
481
482 * Danish[66]
483 * Dutch[67]
484 * English[68]
485 * German[69]
486 * French[70]
487 * Korean[71]
488 * Japanese[72]
489 * Italian[73]
490 * Polish[74]
491 * Portuguese (Brazil)[75]
492 * Portuguese (Portugal)[76]
493 * Russian[77]
494 * Spanish[78]
495 * Turkish[79]
496 66. http://www.gentoo.org/news/da/gwn/gwn.xml
497 67. http://www.gentoo.org/news/nl/gwn/gwn.xml
498 68. http://www.gentoo.org/news/en/gwn/gwn.xml
499 69. http://www.gentoo.org/news/de/gwn/gwn.xml
500 70. http://www.gentoo.org/news/fr/gwn/gwn.xml
501 71. http://www.gentoo.org/news/ko/gwn/gwn.xml
502 72. http://www.gentoo.org/news/ja/gwn/gwn.xml
503 73. http://www.gentoo.org/news/it/gwn/gwn.xml
504 74. http://www.gentoo.org/news/pl/gwn/gwn.xml
505 75. http://www.gentoo.org/news/pt_br/gwn/gwn.xml
506 76. http://www.gentoo.org/news/pt/gwn/gwn.xml
507 77. http://www.gentoo.org/news/ru/gwn/gwn.xml
508 78. http://www.gentoo.org/news/es/gwn/gwn.xml
509 79. http://www.gentoo.org/news/tr/gwn/gwn.xml
510
511
512 Ulrich Plate <plate@g.o> - Editor
513 Patrick Lauer <patrick@g.o> - Author
514 Andrea Perotti <deadhead@×××××.it> - Author
515
516 --
517 gentoo-gwn@g.o mailing list