Re: Considerations for lilo removal

2008-06-16 Thread Florian Weimer
* William Pitcock: I am wondering if it is a good idea to remove lilo entirely. At the moment, lilo has been pulled from testing, and the code is in a shape where a grave bug (bug #479607) is unlikely fixable without severe refactoring of the codebase. BTW, the bug report lacks this

Re: ssl security desaster

2008-05-27 Thread Florian Weimer
* Florian Weimer: Well, you can send me the key in private if you want. Let's see if I can factor it. 8-) I got the key from Patrik, but it's not contained in my blacklist. We couldn't find a dowkd version that flagged the key as weak, nor could we definitely confirm that the very same key

Re: Large data packages in the archive

2008-05-27 Thread Florian Weimer
* Joerg Jaspert: Any comments? In the long term, I'd like to see a better CDN, so that such considerations would magically disappear. Timeframe for this? I expect it to be ready within 2 weeks. Oooh. For a production-quality CDN, 2 years seem more reasonable. I don't know the reason for

Re: ssl security desaster

2008-05-17 Thread Florian Weimer
* Thibaut Paumard: Actually, I seem to remember that the issue of critical packages being maintained by only one person have been pointed out here several times already this year (although I don't remember the particular threads). Certainly, such packages needs a better QA than the rest.

Re: ssl problems: gpg affected?

2008-05-15 Thread Florian Weimer
* Michal Čihař: GnuPG does not use OpenSSL, so it should be safe. But generally it could be possible to use same key for both GnuPG and OpenSSL and then you would have a problem. There is no benefit from doing that, so this is highly unlikely. It requires manual key conversion, too. -- To

Re: Using sgid binaries to defend against LD_PRELOAD/ptrace()

2008-04-27 Thread Florian Weimer
* Josselin Mouette: Given that it seems unlikely that we obtain another solution, should we start right now with that stuff? I think it's a bit foolish to abuse SGID bits to take away permissions. This kind of restriction is essentially a configuration option, and applying it to the wrong

Accepted pperl 0.25-5 (source amd64)

2008-04-27 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.8 Date: Sun, 27 Apr 2008 11:31:52 +0200 Source: pperl Binary: pperl Architecture: source amd64 Version: 0.25-5 Distribution: unstable Urgency: medium Maintainer: Florian Weimer [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED

Accepted pperl 0.25-4 (source amd64)

2008-04-27 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.8 Date: Sun, 27 Apr 2008 10:49:34 +0200 Source: pperl Binary: pperl Architecture: source amd64 Version: 0.25-4 Distribution: unstable Urgency: low Maintainer: Florian Weimer [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED

Re: Reviewing http://wiki.debian.org/ArchitectureSpecificsMemo

2008-04-26 Thread Florian Weimer
* Bernd Eckenfels: In article [EMAIL PROTECTED] you wrote: sizeof(char) == 1 I just removed them for this reason. Maybe we need to specify CHAR_BITS instead? Too much Java programming? 8-) POSIX requires CHAR_BITS to be 8 these days. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED]

Accepted debfoster 2.7-1 (source amd64)

2008-04-19 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.8 Date: Sat, 19 Apr 2008 17:14:49 +0200 Source: debfoster Binary: debfoster Architecture: source amd64 Version: 2.7-1 Distribution: unstable Urgency: low Maintainer: debfoster Maintainer Team [EMAIL PROTECTED] Changed-By: Florian Weimer

Re: exim, local resolver, host name lookups and IPv6

2008-04-11 Thread Florian Weimer
* Mike Hommey: The main question to be able to answer your question correctly is: what does it need these information for ? It needs to know all of its own host names in order to recognize local mail. At least I think this is the motivation; obviously, using reverse lookup to gather this data

Re: exim, local resolver, host name lookups and IPv6

2008-04-11 Thread Florian Weimer
* Bernhard R. Link: I think the main problem is that Debian is by default setting up those ipv6 stuff into the interface even when you are in an pure ipv4 environment. That way exim4 cannot do anything to avoid ipv6 stuff and evil things like this can happen. Yes, I agree this is a problem,

Re: Version numbering for security uploads of native packages

2008-03-16 Thread Florian Weimer
* Adam D. Barratt: Currently, debchange will produce a version number of X-0.1 in such cases which suffers from the problem described above. It has been suggested that either one of +s1 / +sec1 / +security1 or release1 should be used to avoid the issue. For stable and oldstable, we need

Re: Status of dependency based boot sequencing release goal 2008-03

2008-03-16 Thread Florian Weimer
* Petter Reinholdtsen: Here is a small update on the release goal of converting the Debian boot sequening to use dynamic and dependency based ordering instead of hardcoded sequence numbers. The latest status information is available from URL:

Re: Bits from the Security Team

2008-03-13 Thread Florian Weimer
* Guido Günther: Hi Moritz, On Sun, Mar 09, 2008 at 11:05:11PM +0100, Moritz Muehlenhoff wrote: The Security Team is now using Request Tracker to coordinate work and our RT processes have already been refined a lot. If you're a package maintainer working towards a security update, you're

Re: dpkg with triggers support (again)

2008-03-13 Thread Florian Weimer
* John Goerzen: Some of the official, published GIT trees are constantly rebased. Apparently, the rule is not set in stone. Which ones? The pu and (less often) the next branches in the main GIT repository. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe.

Re: dpkg with triggers support (again)

2008-03-12 Thread Florian Weimer
* John Goerzen: What is it that people don't get from git-rebase(1)? When you rebase a branch, you are changing its history in a way that will cause problems for anyone who already has a copy of the branch in their repository and tries to pull updates from you. You

Accepted xml2rfc 1.33.dfsg-1 (source all)

2008-03-09 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sun, 09 Mar 2008 09:13:27 +0100 Source: xml2rfc Binary: xml2rfc Architecture: source all Version: 1.33.dfsg-1 Distribution: unstable Urgency: low Maintainer: Florian Weimer [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL

Re: How to cope with patches sanely

2008-03-01 Thread Florian Weimer
* martin f. krafft: also sprach Manoj Srivastava [EMAIL PROTECTED] [2008.02.29.2153 +0100]: 3) I propose ./debian/branches/{TopicA,TopicB,TopicC}.diff.gz files. Each diff, applied to the orig.tar.gz , shall recreate for the interested user the corresponding branch in my

Re: How to cope with patches sanely

2008-03-01 Thread Florian Weimer
* martin f. krafft: also sprach Florian Weimer [EMAIL PROTECTED] [2008.03.01.1334 +0100]: The nice thing about Manoj's proposal that we (as in the security team, for instance) need not care if the Debian maintainer thinks that upstream needs pristine topic branches, an integration branch

Re: How to cope with patches sanely

2008-02-29 Thread Florian Weimer
* Ben Finney: It's no security risk to unpack a tarball, apply a patch to it via GNU 'patch', and examine the result. History should tell you that this is not true. 8-) I can even understand people who state that GNU tar should never be used to uncompress tarballs from untrusted sources, and

Re: How to cope with patches sanely

2008-02-29 Thread Florian Weimer
* Manoj Srivastava: But there is no such linearization, not in the way that quilt et al do it. The state of such integration is not maintained in the feature branches; it is in the history of the integration branch. As each feature branch was created or developed, if there were

Re: Bug#468183: Unsupported?

2008-02-29 Thread Florian Weimer
* Thorsten Schmale: I created an updated description. Please see below. One thing i forgot to mention earlier was the feature of logging the http requests directly to a mysql-database. I'm not quite sure, but I think this feature is not supported by most other webservers. We've already got

Re: Google Summer of Code 2008

2008-02-29 Thread Florian Weimer
* Lucas Nussbaum: I have had a problem with the way GSOC was handled in Debian in the past years. Me too, but I've seen exactly the opposite: someone was funded who wasn't really active in the area of the project where he worked on, and didn't use existing interfaces etc. to implement his

Re: How to cope with patches sanely

2008-02-29 Thread Florian Weimer
* Manoj Srivastava: Now, a lot of what I need is already present. 1) the orig.tar.gz represents the upstream branch, exactly. 2) the diff.gz + orig.tar.gz represents the integration branch, exactly. So the missing thing is the topic branches. 3) I propose

Re: Bug#468183: ITP: monkey -- small webserver based on the HTTP/1.1 protocol

2008-02-29 Thread Florian Weimer
* Sebastian Krause: I like Debian *because* there are so many choices in the main repository and I don't have to worry if a package is actually well-supported when I install it, Sorry, you are kidding yourself if you actually believe that. Software and packaging quality vary greatly across

Re: binary vs real debian packages

2008-02-29 Thread Florian Weimer
* William Francis: I've built a few debian binary style packages [1] but the maintainer of my local repository is asking that I have all the proper debian files, like the .dsc, .orig, .diff, .changes, etc so some how he can sleep better at night or something. He likes dupload for putting

Accepted libwant-perl 0.18-1 (source amd64)

2008-02-27 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Wed, 27 Feb 2008 20:36:32 +0100 Source: libwant-perl Binary: libwant-perl Architecture: source amd64 Version: 0.18-1 Distribution: unstable Urgency: low Maintainer: Florian Weimer [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL

Re: dash bug which is affecting release goal

2008-02-24 Thread Florian Weimer
* William Pitcock: On Sun, 2008-02-24 at 14:00 +, Ian Jackson wrote: John H. Robinson, IV writes (Re: dash bug which is affecting release goal): Pierre Habouzit wrote: echo() { /bin/echo $@ } echo() { /bin/echo ${1+$@}; } I believe you mean. Why ?! Because stand-alone

Re: Debian mirror CDN had launched.

2008-02-18 Thread Florian Weimer
* ARAKI Yasuhiro: Do you like cdn.debian.net's idea and implementation? Sorry if I sound like a broken record. What kind of software do you use? Is this just DNS-Balance plus a handful of scripts? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact

Re: dash bug which is affecting release goal

2008-02-11 Thread Florian Weimer
* Andreas Bombe: How many million person-hours does it really need to substitute #!/bin/sh by #!/bin/bash once per script? That's even easily scriptable, and I don't see the need for any amount of reviewing and testing for such simple a bug fix. /bin/sh behaves differently than /bin/bash,

Accepted doscan 0.3.1-3 (source amd64)

2008-02-02 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sat, 02 Feb 2008 12:32:44 +0100 Source: doscan Binary: doscan Architecture: source amd64 Version: 0.3.1-3 Distribution: unstable Urgency: low Maintainer: Florian Weimer [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED

Accepted scponly 4.6-1.2 (source amd64)

2008-01-22 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Tue, 22 Jan 2008 20:24:09 +0100 Source: scponly Binary: scponly Architecture: source amd64 Version: 4.6-1.2 Distribution: unstable Urgency: high Maintainer: Thomas Wana [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED

Re: Editing the sources in debian/rules clean

2008-01-01 Thread Florian Weimer
* Miriam Ruiz: 2007/12/26, Florian Weimer [EMAIL PROTECTED]: This the issue, but I think it could be more widespread. It turns out that the package in question (tar) was last uploaded before the autotools were finalized for etch, so the copying is not a no-op in this particular case (but I

Editing the sources in debian/rules clean

2007-12-26 Thread Florian Weimer
It has come to my attention that a number of packages edit source files (i.e. non-generated files in the source directory tree) in the clean target of debian/rules. Policy is mostly silent on this issue. There's a requirement that build, clean is a no-op, but dpkg-buildpackage actually executes

Re: Editing the sources in debian/rules clean

2007-12-26 Thread Florian Weimer
* Petter Reinholdtsen: [Florian Weimer] It has come to my attention that a number of packages edit source files (i.e. non-generated files in the source directory tree) in the clean target of debian/rules. Do you have any example packages to mention? I've seen some updating of the config

Re: Bug#457318: ITP: qmail -- a secure, reliable, efficient, simple message transfer agent

2007-12-24 Thread Florian Weimer
* Turbo Fredriksson: (and claims that this makes Qmail wide open for spams is rubish - it's only if/when configured incorrectly that this becomes a problem) How can you configure DJB qmail so that it rejects mail for non-existing local mailboxes at SMTP dialog time? -- To UNSUBSCRIBE, email

Re: MTA comparison (postfix, exim4, ...)

2007-11-23 Thread Florian Weimer
* Miles Bader: Postfix has a reputation for being faster and more secure than exim. Nowadays, the Postfix code base is larger than the Exim code base. Why is it worth worrying about, though? Are the difference between exim and postfix really great enough to matter for typical use?!?

Re: MTA comparison (postfix, exim4, ...)

2007-11-23 Thread Florian Weimer
* Henrique de Moraes Holschuh: On Fri, 23 Nov 2007, Florian Weimer wrote: Personally, what made me stick to Exim so far is the ability to configure retry behavior on a per-domain basis. One of my mail servers Postfix does that too. You direct the domains to a different transport

Re: gcc compilation error with abs() affects sarge, etch, lenny, sid

2007-11-22 Thread Florian Weimer
* Nikita V. Youshchenko: I think this should be fixed in stable as well. And probably even in oldstable. Miscompilation is BAD thing ... In practice, long-standing compiler bugs have very little practical impact, otherwise they wouldn't be long-standing. We've fixed similar bugs in GCC

Re: Early adopters of symbol based dependencies needed

2007-11-21 Thread Florian Weimer
* Joey Hess: Performance penalty of PIC code due to register pressure, I guess. I seem to remember it was a threading issue, but I didn't manage to track down an explanation. Well, Perl should use __thread anyway, so it's unlikely that the issue is still present. -- To UNSUBSCRIBE, email

Re: What to do when the LaTeX sources are missing, but an XML equivalent was rewritten from scratch ?

2007-11-19 Thread Florian Weimer
* Norbert Preining: What if upstream ships a pdf AND the source, but the generation of the pdf relies on not-available fonts. I would still ship this pdf into my Debian package out of the following reasons: The embedded fonts are still restricted, so it has to go into non-free (perhaps

Re: What to do when the LaTeX sources are missing, but an XML equivalent was rewritten from scratch ?

2007-11-19 Thread Florian Weimer
* Norbert Preining: On Mo, 19 Nov 2007, Florian Weimer wrote: The embedded fonts are still restricted, so it has to go into non-free These fonts are not the full fonts, but sub-setted. Otherwise type companies would NEVER allow any distribution of pdfs with their fonts. But they do

Re: What to do when the LaTeX sources are missing, but an XML equivalent was rewritten from scratch ?

2007-11-19 Thread Florian Weimer
* Norbert Preining: On Mo, 19 Nov 2007, Florian Weimer wrote: These fonts are not the full fonts, but sub-setted. Otherwise type companies would NEVER allow any distribution of pdfs with their fonts. But they do. But this doesn't mean that you are allowed to extract those subsets, put

Re: MTA comparison (postfix, exim4, ...)

2007-11-17 Thread Florian Weimer
* MJ Ray: I believe http://www.postfix.org/ADDRESS_VERIFICATION_README.html details the facility you're looking for. I don't believe it does. I don't want to verify the recipient address - I want to try delivering the redirected mail and avoid being left holding the baby if the destination

Re: ries.debian.org AKA ftp-master.debian.org - hardware problems

2007-11-11 Thread Florian Weimer
* Joerg Jaspert: you may have noticed that around yesterday evening (UTC) ries.debian.org AKA ftp-master.debian.org has problems. The exact cause and possible solutions for this are currently investigated by the admins, a first problem guess is troubles with the harddiscs. It seems that

Re: buildds: Authentication warning overridden.

2007-11-11 Thread Florian Weimer
* Michael Banck: Assuming that compromised mirrors get quickly identified by people using signatures, and buildd packages having to be uploaded directly, the amount of compromised packages this way is probably small, so they can be rebuilt using packages from another mirror, after the build

Re: buildds: Authentication warning overridden.

2007-11-11 Thread Florian Weimer
* Wouter Verhelst: That's inevitable because http://incoming.debian.org is not signed; The update frequency of that repository (which is available only to buildd hosts by IP and/or password protection) makes that impossible -- or at least that's what I understood; you may want to check with

Re: Bug#449317: ITP: zekr-quran-translations-ur -- Zekr Quran Urdu translations

2007-11-05 Thread Florian Weimer
* brian m. carlson: Urdu - Pakistan Urdu. Authors: - Maulana Shah Imam Ahmed Raza Khan (kanzul_iman.zip). According to Wikipedia, the translator died in 1921, which means that his translation occurred prior to 1923. In this case, the translation is in the public domain in the United

Re: Bits from the Security Team

2007-10-31 Thread Florian Weimer
* Francesco P. Lovergine: On Tue, Oct 30, 2007 at 09:04:12PM +0100, Moritz Muehlenhoff wrote: Embedded code copies Wouldn't be the case to add a suitable control field, as proposed in a previous thread for that case? For various reasons, we need something that can be

Accepted db4.5 4.5.20-10 (source all amd64)

2007-10-22 Thread Florian Weimer
-10 Distribution: unstable Urgency: low Maintainer: Debian Berkeley DB Maintainers [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED] Description: db4.5-doc - Berkeley v4.5 Database Documentation [html] db4.5-util - Berkeley v4.5 Database Utilities libdb4.5 - Berkeley v4.5

Accepted db4.5 4.5.20-11 (source all amd64)

2007-10-22 Thread Florian Weimer
-11 Distribution: unstable Urgency: low Maintainer: Debian Berkeley DB Maintainers [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED] Description: db4.5-doc - Berkeley v4.5 Database Documentation [html] db4.5-util - Berkeley v4.5 Database Utilities libdb4.5 - Berkeley v4.5

Re: Bug#445866: ITP: perforce -- closed source revision control system

2007-10-10 Thread Florian Weimer
* Pierre Habouzit: (I don't know anything about Perforce. Perhaps it's really dangerous software. But perhaps it's just non-free.) OTOH I'm always reluctant to see new things enter non-free when there is perfectly suitable alternatives. I mean git, hg, bzr, or even the horrible svn can

Re: seeking: Ian Jackson

2007-10-10 Thread Florian Weimer
RFC 1123 contains this requirement: 5.2.2 Canonicalization: RFC-821 Section 3.1 The domain names that a Sender-SMTP sends in MAIL and RCPT commands MUST have been canonicalized, i.e., they must be fully-qualified principal names or domain literals, not

Re: seeking: Ian Jackson

2007-10-10 Thread Florian Weimer
* martin f. krafft: also sprach Florian Weimer [EMAIL PROTECTED] [2007.10.10.1145 +0100]: RFC 1123 contains this requirement: 5.2.2 Canonicalization: RFC-821 Section 3.1 The domain names that a Sender-SMTP sends in MAIL and RCPT commands MUST have been

Re: Bug#445866: ITP: perforce -- closed source revision control system

2007-10-08 Thread Florian Weimer
* Pierre Habouzit: How about people use it? There's plenty of installations of perforce; s/perforce/windows/ and the sentence is still true ;) The Windows copyright is pretty restrictive AFAIK. If it weren't, I'm certain we hould ship things like Virtualbox VMs in non-free because there

Accepted db4.4 4.4.20-11 (source all amd64)

2007-10-07 Thread Florian Weimer
Maintainer: Debian Berkeley DB Maintainers [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED] Description: db4.4-doc - Berkeley v4.4 Database Documentation [html] db4.4-util - Berkeley v4.4 Database Utilities libdb4.4 - Berkeley v4.4 Database Libraries [runtime] libdb4.4++ - Berkeley v4.4

Accepted db4.5 4.5.20-9 (source all amd64)

2007-10-07 Thread Florian Weimer
-9 Distribution: unstable Urgency: high Maintainer: Debian Berkeley DB Maintainers [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED] Description: db4.5-doc - Berkeley v4.5 Database Documentation [html] db4.5-util - Berkeley v4.5 Database Utilities libdb4.5 - Berkeley v4.5

Accepted db4.3 4.3.29-11 (source all amd64)

2007-10-06 Thread Florian Weimer
Maintainer: Debian Berkeley DB Maintainers [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED] Description: db4.3-doc - Berkeley v4.3 Database Documentation [html] db4.3-util - Berkeley v4.3 Database Utilities libdb4.3 - Berkeley v4.3 Database Libraries [runtime] libdb4.3++-dev

Re: How to detect if inside a buildd chroot

2007-09-25 Thread Florian Weimer
* Reinhard Tartler: - libxine1 only depends on libraries, that it really needs. This leaves users that don't install the recommended packages in the situation, that they cannot play their mp3/ogg/etc files. I guess this will be a non-issue as soon as apt-get installs recommends by

Re: New 'maint' facet for Debtags

2007-09-17 Thread Florian Weimer
* Enrico Zini: Below is an example vocabulary for it, with annotations on how to autogenerate the tag information. I'd like to run some discussion on it for a week or so, then proceed to implementation. Something that indicates security support by upstream, the maintainer and the security

Accepted db4.4 4.4.20-10 (source all amd64)

2007-09-14 Thread Florian Weimer
: Debian Berkeley DB Maintainers [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED] Description: db4.4-doc - Berkeley v4.4 Database Documentation [html] db4.4-util - Berkeley v4.4 Database Utilities libdb4.4 - Berkeley v4.4 Database Libraries [runtime] libdb4.4++ - Berkeley v4.4

Accepted db4.2 4.2.52+dfsg-4 (source amd64)

2007-09-14 Thread Florian Weimer
: Debian Berkeley DB Maintainers [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED] Description: db4.2-util - Berkeley v4.2 Database Utilities libdb4.2 - Berkeley v4.2 Database Libraries [runtime] libdb4.2++-dev - Berkeley v4.2 Database Libraries for C++ [development] libdb4.2++c2

Accepted db4.3 4.3.29-10 (source all amd64)

2007-09-14 Thread Florian Weimer
Maintainer: Debian Berkeley DB Maintainers [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED] Description: db4.3-doc - Berkeley v4.3 Database Documentation [html] db4.3-util - Berkeley v4.3 Database Utilities libdb4.3 - Berkeley v4.3 Database Libraries [runtime] libdb4.3++-dev - Berkeley

Accepted junit4 4.3.1-2 (source all)

2007-09-10 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Mon, 03 Sep 2007 08:14:52 +0200 Source: junit4 Binary: junit4 Architecture: source all Version: 4.3.1-2 Distribution: unstable Urgency: low Maintainer: Florian Weimer [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED

Accepted debsecan 0.4.10 (source all)

2007-09-02 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sun, 02 Sep 2007 17:27:52 +0200 Source: debsecan Binary: debsecan Architecture: source all Version: 0.4.10 Distribution: unstable Urgency: low Maintainer: Florian Weimer [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED

Re: many packages FTBFS, if $TAPE is set

2007-08-28 Thread Florian Weimer
* Bastian Blank: On Tue, Aug 28, 2007 at 09:39:47AM -0700, John H. Robinson, IV wrote: I assume you mean to make the documentation match the behaivour. At least. Rememer it is a Tape ARchival program. | -f, --file [HOSTNAME:]F | use archive file or device F (default -, meaning

Re: Bug#435884: ITP: rsyslog -- enhanced multi-threaded syslogd

2007-08-07 Thread Florian Weimer
* Hamish Moffatt: Also does rsyslog guarantee that messages are logged in the order they are sent? The kernel does not guarantee that SOCK_DGRAM sockets preserve order, even if the packets are sent from a single process/host. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

Re: Bug#435884: ITP: rsyslog -- enhanced multi-threaded syslogd

2007-08-07 Thread Florian Weimer
* Pierre Habouzit: On Mon, Aug 06, 2007 at 08:15:58AM +1000, Hamish Moffatt wrote: On Sun, Aug 05, 2007 at 10:25:34PM +0200, SZALAY Attila wrote: And I think that the real question is that there is place in Debian for a multithread/process system logging daemon (against the singlethread

Re: making debian/copyright machine-interpretable

2007-08-05 Thread Florian Weimer
* Sam Hocevar: On Sat, Aug 04, 2007, Florian Weimer wrote: It's probably better to use a separate file. If there's a syntax error, you can't be sure if the file is in the old format, or if its a genuine error. But the information must be in debian/copyright. Why? I don't think

Re: Bug#435884: ITP: rsyslog -- enhanced multi-threaded syslogd

2007-08-04 Thread Florian Weimer
* Bastian Blank: On Sat, Aug 04, 2007 at 01:44:14AM -0400, Roberto C. Sánchez wrote: As the target user for this sort of package is a sysadmin type, I would saw it is an important enough detail that it should be in the short description. But only in the relation: multi-threaded == bad. You

Re: Packaging a difficult project

2007-08-03 Thread Florian Weimer
* Steve Langasek: Hmm, I would question whether this is something we'd want to include in the Debian archive as-is; I think we already have way too many gcc packages being carried around with our releases and that we need to try to make this number go down, not add more copies of the gcc

Bug#433954: RFP: softflowd -- Flow-based network traffic analyser

2007-07-20 Thread Florian Weimer
or summarised within softflowd itself. -- Florian Weimer[EMAIL PROTECTED] BFK edv-consulting GmbH http://www.bfk.de/ Kriegsstraße 100 tel: +49-721-96201-1 D-76133 Karlsruhe fax: +49-721-96201-99

Re: Porting from OpenSSL to GnuTLS

2007-06-27 Thread Florian Weimer
* Bruno Costacurta: I might start thinking about porting an x509 application from OpenSSL to GnuTLS (Gnu Transport Layer Security) and so looking about feedbacks, experiences ..etc.. about such porting, libraries ..etc.. What kind of level of X.509 support do you need? Is chasing

Accepted cook 2.29-1 (source all amd64)

2007-06-27 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sun, 18 Mar 2007 16:09:34 +0100 Source: cook Binary: cook cook-doc cook-rsh Architecture: source amd64 all Version: 2.29-1 Distribution: unstable Urgency: low Maintainer: Florian Weimer [EMAIL PROTECTED] Changed-By: Florian Weimer

Re: Best practices for cron jobs?

2007-06-13 Thread Florian Weimer
* Duncan Findlay: I imagine it would be relatively simple to have the postinst generate a random time during the day for a cron script to run, but this doesn't work with anacron -- many users would never get updates. debsecan creates a cron entry which is run hourly, at a random minute, and

Re: Bug#422423: ITP: libtool-cvs -- Generic library support script - CVS snapshot

2007-05-07 Thread Florian Weimer
* Mike Hommey: Why not package this as libtool and upload to experimental ? It would be impossible to build-depend on it. This may or may not be a good thing. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Accepted stringtemplate 3.0-1 (source all)

2007-05-07 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sun, 22 Apr 2007 14:46:17 +0200 Source: stringtemplate Binary: libstringtemplate-java Architecture: source all Version: 3.0-1 Distribution: unstable Urgency: low Maintainer: Florian Weimer [EMAIL PROTECTED] Changed-By: Florian Weimer

Bug#420793: ITP: junit4 -- JUnit regression test framework for Java

2007-04-24 Thread Florian Weimer
Package: wnpp Severity: wishlist Owner: Florian Weimer [EMAIL PROTECTED] * Package name: junit4 Version : 4.3.1 Upstream Author : Erich Gamma, Kent Beck * URL : http://www.junit.org/ * License : CPL Programming Lang: Java Description : JUnit regression

Re: Mandatory -dbg packages for libraries?

2007-04-22 Thread Florian Weimer
* Neil Williams: Apart from those limitations, is there a *technical* reason why -dbg packages should not be available? GCC's debugging information at -O2 will continue to worsen (in part as a result of -O2 getting better). Hence, -dbg libraries would need to be compiled with different

Re: Xorg 7.2

2007-04-22 Thread Florian Weimer
* Steve Langasek: unstable doesn't mean it's ok to upload packages with known bugs that render the system unusable to many users and drives them away from using unstable because they're using non-free software and that shouldn't matter to us. The consequences of breaking Java for most users

Re: How to bet back to a sane version number?

2007-04-17 Thread Florian Weimer
* Hamish Moffatt: FWIW you can experiment quite easily using dpkg --compare-versions x lt y echo Yes Interestingly, 4.22.. is considered higher than 4.22.3. I'm not sure if this is good advice though :-) It's also a good idea to check against APT's implementation when playing with strange

Re: How to bet back to a sane version number?

2007-04-17 Thread Florian Weimer
* Florent Rougon: This function doesn't return anything (well, actually, it returns the object None). The correct version is: def compare(a, b): return apt_pkg.VersionCompare(a, b) Yes, indeed, sorry about that. Too much Perl lately. Thanks for explaining the multi-way compare, too.

Re: How to bet back to a sane version number?

2007-04-17 Thread Florian Weimer
* Margarita Manterola: Other posibilities: ~$ dpkg --compare-versions 4.22.3-1 lt 4.22_-3.1 echo Yes Yes Keep in mind that dpkg does not check for the validity of version numbers. _ is in fact forbidden, and I believe there is a check in dak that enforces that. (The list of permitted

Re: The number of etch installations is rocketing...

2007-04-13 Thread Florian Weimer
* Ron Johnson: On 04/12/07 15:14, Florian Weimer wrote: * Ron Johnson: On 04/12/07 14:32, Kurt Roeckx wrote: [snip] You can also see this by looking at /proc/cpuinfo looking for lm in flags. Does lahf_lm count? The file should also list lm earlier on the same line. Oh well, I guess

Re: The number of etch installations is rocketing...

2007-04-12 Thread Florian Weimer
* Ron Johnson: On 04/12/07 14:32, Kurt Roeckx wrote: [snip] You can also see this by looking at /proc/cpuinfo looking for lm in flags. Does lahf_lm count? The file should also list lm earlier on the same line. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

Not-so-mass bug filing for the patented IDEA algorithm

2007-04-10 Thread Florian Weimer
I plan to file a couple of bugs (not too many, probably a dozen) on packages which contain implementations of the patented IDEA algorithm -- because the presence of that code makes them non-free. As far as I know, no program in Debian actually uses this code, it's just inherited from upstream

Re: Not-so-mass bug filing for the patented IDEA algorithm

2007-04-10 Thread Florian Weimer
* Pierre Habouzit: On Tue, Apr 10, 2007 at 09:09:23AM +0200, Florian Weimer wrote: I plan to file a couple of bugs (not too many, probably a dozen) on packages which contain implementations of the patented IDEA algorithm -- because the presence of that code makes them non-free. because

Re: Not-so-mass bug filing for the patented IDEA algorithm

2007-04-10 Thread Florian Weimer
* Neil Williams: Which are the offending libraries? Botan, Crypto++, BouncyCastle, a few Perl-related packages. Is this mass-bug-filing intended to be against the applications that link against the libraries or just the offending libraries themselves? Just the libraries. Debian's crypto

Re: Not-so-mass bug filing for the patented IDEA algorithm

2007-04-10 Thread Florian Weimer
* Kurt Roeckx: As far as I understand, they have been disabled because at that time, it seems we only cared about using those, not about distributing them. Disabling it and telling users the reason in the package documentation is sufficient, I guess. Is there consensus that we shouldn't ship

Accepted debsecan 0.4.8 (source all)

2007-04-09 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Mon, 9 Apr 2007 11:46:19 +0200 Source: debsecan Binary: debsecan Architecture: source all Version: 0.4.8 Distribution: unstable Urgency: high Maintainer: Florian Weimer [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED

Accepted debsecan 0.4.9 (source all)

2007-04-09 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Tue, 10 Apr 2007 07:16:24 +0200 Source: debsecan Binary: debsecan Architecture: source all Version: 0.4.9 Distribution: unstable Urgency: high Maintainer: Florian Weimer [EMAIL PROTECTED] Changed-By: Florian Weimer [EMAIL PROTECTED

Re: MySql broken on older 486 and other cpuid less CPUs. Does this qualify as RC?

2007-04-05 Thread Florian Weimer
* Lennart Sorensen: So does it seem fair to raise the severity to flag mysql as release critical for etch since it does affect any program that links in libmysql running on any x86 without cpuid support? Document it in the release notes, please. It's not worth risking stability for the

Re: Modifying /etc/apt/sources.list in postinst ; determining the suite in postinst

2007-04-03 Thread Florian Weimer
* Neil Williams: Finally, if this is done in postinst, presumably the changes will have to be removed in postrm or can dpkg be persuaded to do this for me? (Could I ship a sources.list file in the package and move the previous one to sources.dpkg-old?) There is /etc/apt/sources.list.d.

Alerts for uploads to stable-proposed-updates and tpu

2007-04-01 Thread Florian Weimer
Is there some kind of mailing list I can subscribe to, to receive alerts when someone uploads a package to stable-proposed-updates or testing-propposed-updates? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Alerts for uploads to stable-proposed-updates and tpu

2007-04-01 Thread Florian Weimer
* Andreas Barth: For t-p-u, [EMAIL PROTECTED] Ah, thanks. Pretty obvious in retrospect. For proposed-updates, I fear the mails are only sent upon approval, but I'm not sure (it would be debian-changes@lists.debian.org). Mail after approval is good enough for my purposes, thanks. -- To

Re: Slow package database

2007-03-31 Thread Florian Weimer
* Adam Borowski: On Fri, Mar 30, 2007 at 08:57:03PM +0200, Loïc Minier wrote: Indeed it accounts for some part of the problem; after I cloned and replaced my /var/lib/dpkg/info tree with the copy, the figure dropped from 22 seconds to 15 seconds. It's not that. It's

Re: Slow package database

2007-03-30 Thread Florian Weimer
* Christoph Haas: What might be the cause? Is there some fragmentation effect? It's probably ext3's directory hashing. It tries to access the files in /var/lib/dpkg/info in hash order, which leads to essentially random disk I/O. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Re: More stuff the installer does which isn't done on upgrade

2007-03-26 Thread Florian Weimer
* Nathanael Nerode: While on new installs it looks like this: -- # This is a list of hotpluggable network interfaces. # They will be activated automatically by the hotplug subsystem. And, as discussed before, this doesn't work reliably on all systems. 8-( -- To UNSUBSCRIBE, email

Re: Ethernet interface numbering in etch

2007-03-26 Thread Florian Weimer
* Russ Allbery: There's actually some stuff in udev or some related package to deal with this, but I can't ever seem to find it when I need it. I think this is actually a documentation bug more than a functionality bug; we just need a better guide on how to do it. You can, somehow, assign

<    1   2   3   4   5   6   7   8   9   >