Re: Preventing account takeovers through expired domains

2022-02-19 Thread Björn Persson
efore the domain is released for registration. Let's just not make it so tight that a little unscheduled downtime can open an attack window. Björn Persson pgpqiv4u1U4Nr.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@li

Preventing account takeovers through expired domains (was: Do we have any policy for disabling inactive users)

2022-02-19 Thread Björn Persson
tep 6 cannot happen before step 3. That way the Fedora Project could reliably prevent this kind of attack. I hope this explanation is clear enough to be understood. In case of TL;DR, the short version is four posts upthread from here. So, does step 3 exist? Björn Persson pgpPIYU3U_oGq.pgp Descri

Re: Do we have any policy for disabling inactive users

2022-02-16 Thread Björn Persson
Vitaly Zaitsev via devel wrote: > On 15/02/2022 19:43, Björn Persson wrote: > > The packager would then be required to authenticate with their existing > > credentials – or prove their identity in some way that does not rely on > > ownership of the email address – and set a

Re: Do we have any policy for disabling inactive users

2022-02-15 Thread Björn Persson
ddress – and set a new email address in their account. Entering the old email address again would be allowed, in case they have recovered the domain, but they would have to prove that they can receive a confirmation message regardless of whether the new address is the same as the old a

Re: Do we have any policy for disabling inactive users

2022-02-11 Thread Björn Persson
Ben Cotton wrote: > I would support removing the 113 who don't exist in Koji. If they have been that way for a long time, I suppose. Don't cause additional hurdles for newcomers just because their first review takes a while. Björn Persson pgp11SGC3hJR2.pgp Description: OpenPGP dig

Re: Do we have any policy for disabling inactive users

2022-02-11 Thread Björn Persson
Thus an open Bugzilla ticket is no indication that the package is unmaintained. You need to check what version is actually in Rawhide. If the Bugzilla tickets should in fact not be left open, then they should be automatically closed just like they're automatically opened. Björn Persson

Re: gcc-12.0.0-0.4.fc36 in rawhide

2022-01-17 Thread Björn Persson
https://bugzilla.redhat.com/show_bug.cgi?id=2041667 Björn Persson pgpaayNBpxRq6.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of C

Re: New tool - license-validate

2021-12-27 Thread Björn Persson
Miroslav Suchý wrote: > $ license-validate-v'GPL or (MIT and BSD)' >     No terminal defined for 'G' at line 1 col 1 Approximately nobody will understand "No terminal defined for 'G'". Can the error message be improved? Björn Persson pgp5AIXhm

Re: new systemd in rawhide

2021-12-10 Thread Björn Persson
lse' > or similar, please make sure that you install those libraries too if > appropriate. Was "not" supposed to be "now"? Otherwise these statements don't make sense together. Björn Persson pgpz2V_ix2CZt.pgp Description: OpenPGP digital signatur __

Re: F36 Change: Make Rescue Mode Work With Locked Root (System-Wide Change proposal)

2021-12-09 Thread Björn Persson
oot entry for the rescue mode, then maybe Grub could be programmed to require a passphrase before it will boot that entry? Björn Persson pgp1LnefA7iK9.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fed

Re: F36 Change: Make Rescue Mode Work With Locked Root (System-Wide Change proposal)

2021-12-09 Thread Björn Persson
this case, Grub should also by default require root's or a wheel user's passphrase before boot parameters can be changed. That is consistent. Björn Persson pgpcT9reGtFmi.pgp Description: OpenPGP digital signatur ___ devel mailing list -- d

Re: F36 Change: Make Rescue Mode Work With Locked Root (System-Wide Change proposal)

2021-12-08 Thread Björn Persson
Chris Adams wrote: > Once upon a time, Björn Persson said: > > Chris Adams wrote: > > > If the admin has done one thing to lock down the system, then they can > > > do another (removing the sulogin --force addition). > > > > How do you propose to ens

Re: F36 Change: Make Rescue Mode Work With Locked Root (System-Wide Change proposal)

2021-12-07 Thread Björn Persson
in this new release of this particular distribution they need to run this special command to prevent boot problems from granting root access to whoever can type on the keyboard. Björn Persson pgpUpKi2TnP15.pgp Description: OpenPGP digital signatur __

Re: F36 Change: Enable fs-verity in RPM (System-Wide Change proposal)

2021-12-04 Thread Björn Persson
this change is authorized? Do I disable FS-verity for that specific file? Disable FS-verity globally? Add my own key to the kernel's keyring? Build and sign my own RPM package? What prevents an attacker from doing the same? Will files under /etc be covered, or will local configuration still be possi

Re: (Quite?) OT Question: Is still relevant Software RAID?

2021-12-02 Thread Björn Persson
and BTRFS, not clouds or devops. But the licensing situation makes ZFS painful, and BTRFS seems to take forever to mature, so it should be expected that many people will choose software RAID instead. Björn Persson pgpK9xoq79ydL.pgp Description: Ope

Re: Review request for oclock package (orphaned since F35)

2021-11-23 Thread Björn Persson
tarball. So don't do that. Björn Persson pgpuxCuE5BI4x.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https:

Re: F36 Change: Remove .la files from buildroot (Self-Contained Change proposal)

2021-11-01 Thread Björn Persson
the file's content, then I think the script should do that to verify that files with a ".la" suffix really are Libtool archives before deleting them. Björn Persson pgp2yAnXNNShR.pgp Description: OpenPGP digital signatur ___ d

Re: crypto-policies and a certain usage of SHA-1

2021-10-16 Thread Björn Persson
place the key every few hours or days. The Signature field is different every time though. Thus I'm not sure whether the attacker's time limit is the lifetime of the key (which Fedora can't control) or the TCP timeout. Björn Persson pgptnItUABZ9M.pgp

crypto-policies and a certain usage of SHA-1

2021-10-15 Thread Björn Persson
se anyone wants to test things themself. Björn Persson pgptX2bBu9PZE.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org

Re: Linux Plumbers Conference - Open Printing Micro Conference

2021-09-21 Thread Björn Persson
Zdenek Dohnal wrote: > the schedule for the first no-driver was proposed What is a no-driver? Björn Persson pgp8IziBk8gfn.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an em

Re: Specfile description and summary translations

2021-08-19 Thread Björn Persson
slations of RPM descriptions and summaries, which is sad, but in that case there certainly shouldn't be a "SHOULD" in the Review Guidelines. Björn Persson pgpCtFKpUoKUK.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel

Re: Systemd unit files installed into unowned directories

2021-08-05 Thread Björn Persson
is rather similar to /usr/share/bash-completion, /usr/share/man, /usr/share/info and various other directories that filesystem owns. Björn Persson pgpM1c3jmu0yS.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraprojec

Re: Why so long for EPEL-8?

2021-07-19 Thread Björn Persson
sy at the time. I don't know a convenient way to do that, so I end up installing updates when they show up in the updates repository. Björn Persson pgpvoA3f6hGTK.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fed

Re: Using "Open location" in GIMP causes a (sometimes) catastrophic crash

2021-06-19 Thread Björn Persson
might be caused > by limited system resources. From the provided error message it looks > like insufficient RAM/buffer size. Perhaps limiting the length of the error message could prevent overuse of system resources? I doubt anyone actually wants a super-wide alert window. Björn Persson pgp

Re: x86_64-v2 in Fedora

2021-06-16 Thread Björn Persson
vbe/&&/xsave/) > level = 3 > if (level == 3 && > /avx512f/&&/avx512bw/&&/avx512cd/&&/avx512dq/&&/avx512vl/) level = 4 > if (level > 0) { print "CPU supports x86-64-v" level; exit level + 1 } > exit 1 > }

Re: Preventing supply chain attacks via rekor

2021-06-11 Thread Björn Persson
less animation. Even the text that is right there in the HTML code is hidden. Instead it wants me to execute a bunch of Javascript from at least three different domains. When a website expects me to execute some unknown program before they'll even tell me who they are or what they

Re: When is pappl going to be good enough to replace cups?

2021-05-27 Thread Björn Persson
;. For any reasonable reading of the manual, "BrowseLocalProtocols none" should have the same effect as "Browsing No". It seems safest to turn off both, but I'm not at all sure whether that prevents network printers from showing up in my print dialogs. B

Re: When is pappl going to be good enough to replace cups?

2021-05-26 Thread Björn Persson
Solomon Peachy wrote: > On Wed, May 26, 2021 at 08:15:46PM +0200, Björn Persson wrote: > > And I always try to avoid using protocols that assume that the local > > link is secure. That's one of the reasons why my printer is connected by > > USB, and I would like to co

Re: When is pappl going to be good enough to replace cups?

2021-05-26 Thread Björn Persson
ected by USB, and I would like to continue to have that choice. Björn Persson pgp2GJIq_HFQB.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fed

Re: When is pappl going to be good enough to replace cups?

2021-05-26 Thread Björn Persson
printer name/identifier just > so they can capture a document *you* want to print, but if there's that > level of persistant hostile presence on your local network, you're > already completly screwed. I would be if I would use insecure protoco

Re: When is pappl going to be good enough to replace cups?

2021-05-25 Thread Björn Persson
printer and an auto-found printer, so I can continue to have my printer configured and know that I'm sending to that one? Do I need to explain, detail by detail, the errors in the reasoning "People don't print on untrusted networks. Therefore any network with a printer on it is trusted.

Re: When is pappl going to be good enough to replace cups?

2021-05-24 Thread Björn Persson
ices that trust the wifi network to protect them. Assuming that all the nodes on the local link are friendly is criminally naïve. Björn Persson pgpLHHjA7RfBz.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject

Re: When is pappl going to be good enough to replace cups?

2021-05-22 Thread Björn Persson
er how I will know whether I'm sending my sensitive document to my USB printer or to some impostor on a wifi network. I wish working software could just continue working. Obviously that's far too sane for this insane world. Björn Persson pgpN_tzgp_dVv.pgp Description: OpenPGP digital sig

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-11 Thread Björn Persson
using and updating /boot/grub2/grub.cfg, leaving /boot/efi/EFI/fedora/grub.cfg to go stale, and the upgrade replaced the file in use with the stale one. This would mean that different programs have different ideas about which grub.cfg is in use. See also https://bugzilla.redhat.com/show_bug.cgi?id=195

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-09 Thread Björn Persson
situations like this.) Then I ran "grub2-mkconfig -o /boot/grub2/grub.cfg" to get the boot working normally. Björn Persson pgpOIohB2HgVJ.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To u

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-08 Thread Björn Persson
should get, none of the outdated entries I actually see. Björn Persson pgpz23pXbFgYJ.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fed

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-08 Thread Björn Persson
ub.cfg That file contains the outdated menu entries I described. Is there a way to recreate it from the Dracut shell, or with the filesystem temporarily mounted on another Fedora 32 system? Björn Persson pgpwCgzgHgw6P.pgp Description: OpenPGP digital signatur _

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-08 Thread Björn Persson
Tomasz Torcz wrote: > Dnia Sat, May 08, 2021 at 02:51:31PM +0200, Björn Persson napisał(a): > > I used yum system-upgrade to upgrade from Fedora 32 to Fedora 34. Now > > Grub complains about not finding some theme files, and then displays a > > Missing theme files

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-08 Thread Björn Persson
Neal Gompa wrote: > On Sat, May 8, 2021 at 8:53 AM Björn Persson wrote: > > > > I used yum system-upgrade to upgrade from Fedora 32 to Fedora 34. Now > > Grub complains about not finding some theme files, and then displays a > > menu with two kernels from Fedora 29 and

Upgrade to Fedora 34 broke the boot menu.

2021-05-08 Thread Björn Persson
Which component in Bugzilla might be responsible for this mess? Björn Persson pgpbycvIEd1Uy.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraprojec

Re: F35 Change: CompilerPolicy Change (System-Wide Change proposal)

2021-04-23 Thread Björn Persson
, compiler, assembler, linker and whatever else may be involved. Björn Persson pgp_UDSFlTZ8_.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.f

Re: F35 Change: Debuginfod By Default (Self-Contained Change proposal)

2021-04-22 Thread Björn Persson
Frank Ch. Eigler wrote: > Björn Persson writes: > > And as you noted yourself, an attacker who can manipulate cached files > > client-side has already taken over the user account anyway. > > Yes and no, and so I must disagree with your "won't improve ... for

Re: F35 Change: Debuginfod By Default (Self-Contained Change proposal)

2021-04-22 Thread Björn Persson
eouts should not be happening any more. It is however a good illustration of how a network problem can destroy the user experience. Five minutes is a long wait. I'm glad that we now have this information. Björn Persson pgpaB8snU3QuR.pgp Description: OpenPGP digital signatur __

Re: F35 Change: Debuginfod By Default (Self-Contained Change proposal)

2021-04-21 Thread Björn Persson
/.var/app/org.gnome.Tetravex/cache/debuginfod_client/a2429c266188acc10181f6936915f35274bb4a38/debuginfo > Downloading separate debug info for /lib64/libcap.so.2... I was wondering what the user experience would be like in such a situation. Could you estimate how long you had to wait in tota

Re: F35 Change: Debuginfod By Default (Self-Contained Change proposal)

2021-04-21 Thread Björn Persson
Frank Ch. Eigler wrote: > Björn Persson writes: > > > · How is it verified that files received from debuginfo servers have not > > been tampered with? > > Following up further to this, we're planning to add optional client-side > hash-verification of

Re: F35 Change: Debuginfod By Default (Self-Contained Change proposal)

2021-04-10 Thread Björn Persson
how a network problem can impact the usability of debugging tools. Could it for example make GDB hang for a minute every time it encounters a new source filename? Finally, if somebody doesn't like the answers to the above questions, then they'll want to know how to disable the feature.

License changes in Gnatcoll packages

2021-04-09 Thread Björn Persson
GPLv3+ with exceptions. gnatcoll-gmp, gnatcoll-readline and gnatcoll-xref are still GPLv3+. Björn Persson pgpuCeu2ODDUt.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to

Re: F35 Change proposal: RPM 4.17 (System-Wide Change proposal)

2021-04-07 Thread Björn Persson
/886 I think that's a good idea. If it gets implemented, then we can remove check-rpaths from the Ada spec files – but there might be other similar usecases where something runs in %check to check files in the buildroot, which would break if %check would be moved before %install. Björn Persson

Re: Fedora Account Migration & Production Deployment Update: COMPLETE!

2021-03-28 Thread Björn Persson
ing that a word like "Jamaica" is useful as a password – if it's checked server-side that the two passwords are not similar – but it's not two-factor authentication if both passwords are stored in the same password manager. I'm not going to speculate on how you mean that &qu

Re: Fedora Account Migration & Production Deployment Update: COMPLETE!

2021-03-27 Thread Björn Persson
That turns the "security question" into a backup passphrase. If you want people to do this, then it's better to ask them to make up a passphrase. Björn Persson pgpE8zuWQSxko.pgp Description: OpenPGP digital signatur ___ devel mailing list -- d

Re: Fedora Account Migration & Production Deployment Update: COMPLETE!

2021-03-27 Thread Björn Persson
done in the login session, then successful attacks will be less frequent, because then the attacker first needs the victim's passphrase. Side-channel authentication is a design flaw none the less. There's no point to having a second factor if it's so weak that the security depends mos

Re: Fedora Account Migration & Production Deployment Update: COMPLETE!

2021-03-26 Thread Björn Persson
your password, so it doesn't > really play nice with password managers. Such kludges shouldn't be exposed in user interfaces if it can be avoided. A web interface should be able to receive two strings in two separate fields, and concatenate them if the backend requires that. Björn Perss

Re: OpenSSH SHA-1 deprecation, developing FAQ, etc

2021-03-12 Thread Björn Persson
e release notes seem to use "signature scheme" and "signature algorithm" interchangeably, and the manual uses "host key algorithms" and "key types" when it seems to actually be talking about signature schemes. Björn Persson pgpueXa4thwTm.pgp Description: OpenPG

Re: F35 Change: "Fedora Linux" in /etc/os-release

2021-03-10 Thread Björn Persson
/apache2, /etc/apache2, apache2.service and so on. That's a real nuisance. Working with both Debian and CentOS I always have trouble remembering whether it's /etc/apache2 or /etc/httpd, and apache2.service or httpd.service. Both have apachectl though, not httpctl. Björn Persson pgpM4

Re: F35 Change: "Fedora Linux" in /etc/os-release

2021-03-10 Thread Björn Persson
a CoreOS, not Fedora Linux" makes no sense either, because Fedora CoreOS would be a subset of Fedora Linux if I understand you correctly. Björn Persson pgp4m8hB5HQ1s.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedo

Re: F35 Change: "Fedora Linux" in /etc/os-release

2021-03-10 Thread Björn Persson
Fedora is a software distribution. It contains Linux, many GNU components, RPM, MariaDB, Libreoffice and lots of other things, but its name is "Fedora". Or call it "Fedora Software Distribution" or anything else that doesn't single out any of the components. That approac

Re: F35 Change: "Fedora Linux" in /etc/os-release

2021-03-10 Thread Björn Persson
ething like "Fedora Family", because it's a number of closely related distributions which are suitable for use at home? Or something like "Fedora Flow", alluding to frequent releases and a steady stream of updates? Björn Persson pgpQIZfjHla23.pgp Description: OpenPGP digit

Re: python noarch packaging vs pip install

2021-03-08 Thread Björn Persson
-a-week/ https://arstechnica.com/information-technology/2021/02/supply-chain-attack-that-fooled-apple-and-microsoft-is-attracting-copycats/ Björn Persson pgplQo4tEGPPu.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproje

Re: Fedora's GPG key in DNS(SEC)

2021-03-08 Thread Björn Persson
ess is trusted. You state that the DNS server isn't necessarily in the same domain as the repository, so it's not as simple as comparing the domain names. Could you explain how the email address is validated? Björn Persson pgpKpG3Y0YPHa.pgp Descript

Re: F34 gdm login prompt goes crazy when a fingerprint reader with no enrolled prints is present

2021-03-08 Thread Björn Persson
Matthew Miller wrote: > On Sun, Mar 07, 2021 at 10:26:50AM +0100, Björn Persson wrote: > > > It can, but most people don't have a good setup for even local mail > > > delivery. Out of the box, we don't really do anything useful. > > It wouldn't tak

Re: F34 gdm login prompt goes crazy when a fingerprint reader with no enrolled prints is present

2021-03-07 Thread Björn Persson
x27;s a kernel thread called "edac-poller", so I don't know whether the runtime overhead is any lower. Björn Persson pgpxIV_q_B1uk.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedorapro

Re: F34 gdm login prompt goes crazy when a fingerprint reader with no enrolled prints is present

2021-03-07 Thread Björn Persson
ariety of MUAs can pick up the emails from /var/spool/mail. But I guess those who want fewer daemons won't be happy to see Postfix added just for a chance to be warned about an imminent breakdown. Björn Persson pgpK7UBRzp74e.pgp Description: OpenPGP digital signatur

Re: Bodhi client prompting for a password

2021-03-03 Thread Björn Persson
use different methods for > authenticating with your FAS account. > > koji uses kerberos, bodhi uses OpenID over HTTP, dist-git uses SSH ... It wouldn't be a user interface problem if they'd all fetch the passcode from the same keyring. Then the user wouldn't need to know h

Re: Fedora's GPG key in DNS(SEC)

2021-02-12 Thread Björn Persson
he sha256sum step.) According to the manual, GnuPG can look up keys in DNS in various ways, but it tries only Web Key Directory by default. I think therefore that the greatest advantage of publishing the keys in DNS is that it can help with verifying installation images, but it might be even

Re: Jami (formerly Ring) P2P softphone packaging?

2021-02-02 Thread Björn Persson
ly > does voice and IM could that provide a way forward? If that would remove the dependency on FFMPEG, then I suppose that would work around that problem at least. You could also try packaging Jami in RPM Fusion, if FFMPEG is the only obstacle. Björn Persson pgp2kmhXTqIh7.pgp Description: Op

Re: Schedule for Wednesday's FESCo Meeting (2021-01-13)

2021-01-13 Thread Björn Persson
or agreeing on a meeting time across borders. Björn Persson pgpVdptJ6P7EG.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Cond

Re: Stale proven packagers

2020-12-26 Thread Björn Persson
kens are better where security requirements are higher, like in two-factor authentication. Requiring biometrics is effectively the same as prohibiting stronger authentication methods, which is a stupid thing to do. Björn Persson pgpUh0Z_Vy5p9.pgp Description: OpenPGP digital signatur

Re: Nothing provides libgnat-10.so()(64bit)

2020-12-08 Thread Björn Persson
Miro Hrončok wrote: > On 12/8/20 10:26 AM, Björn Persson wrote: > > This time I got eight separate Bugzilla issues, which all essentially > > just served as notification that GCC has been upgraded, and each one > > needs to be closed manually. That's manageable as lon

Re: Nothing provides libgnat-10.so()(64bit)

2020-12-08 Thread Björn Persson
one of my packages is unbuildable (and it's not just because its dependencies haven't been rebuilt yet), notify me and I'll look into it. For that purpose a bug report in Bugzilla is appropriate. Björn Persson pgpBqSuNykGKA.pgp Description: OpenPGP digital signatur __

Re: Fedora 34 Change: ntp replacement (Self-Contained Change)

2020-12-03 Thread Björn Persson
hould at worst refuse to run. If it does anything worse than that, then I think that's a serious defect that needs to be fixed. > == User Experience == > For most users of `ntp` the experience is not expected to change > significantly. Or rather: For most users their only experience w

Re: Package review sum-ump

2020-11-24 Thread Björn Persson
reviewer, it's probably best to close the older one as duplicate. Next time you write to the list, don't reply to a random unrelated message. Use the reply button only when you're actually replying to something. Björn Persson pgpvqQxcz9TqU.pgp Description:

Re: Rawhide build failure on strange archs

2020-11-07 Thread Björn Persson
instead of overflow. Björn Persson pgpkFWYt_eIDv.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Cond

Re: Fedora Security Team

2020-11-04 Thread Björn Persson
ese issues. Of course, the real solution would be decent code quality upstream, so that security fixes would be rare, not come in heaps. Björn Persson pgpNFhNBPaTcI.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproj

Re: Retiring ntp

2020-11-02 Thread Björn Persson
I see only two. > I'm not sure how many users of ntp are there. As a replacement, we > could package ntpsec. Judging only from their own website, it seems that switching to NTPsec would be a great improvement. I'll have to investigate whether I can migrate all my usec

Re: F34 Change proposal: DNS Over TLS (System-Wide Change)

2020-10-08 Thread Björn Persson
ould have chosen to "deal with" the problem then, if they cared about DNSsec. You Michael replied to Florian and called DNSsec-aware clients "a quite specialized use-case", so you can't claim that you were unaware of the issue. "It's too late" rings holl

Re: fedpkg push - traceback - and a PR created?

2020-10-04 Thread Björn Persson
Sérgio Basto wrote: > On Sun, 2020-10-04 at 21:39 +0200, Björn Persson wrote: > > Adam Williamson wrote: > > > On Sun, 2020-10-04 at 12:31 +0200, Vitaly Zaitsev via devel wrote: > > > > On 04.10.2020 12:04, Barry Scott wrote: > > > > > Why is a

Re: fedpkg push - traceback - and a PR created?

2020-10-04 Thread Björn Persson
e a pull-request", it would be better if it said "You can create a pull-request here:". Björn Persson pgpyFM46RxEdz.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscri

Re: This is bad, was Re: Fedora 33 System-Wide Change proposal: systemd-resolved

2020-09-30 Thread Björn Persson
d.service > # mv /etc/resolv.conf.orig-with-nm /etc/resolv.conf > # systemctl restart NetworkManager.service So there's no need to revert any changes to /etc/nsswitch.conf? I've seen some discussion about that file in relation to systemd-resolved. It seemed far from easy to understand ho

Re: This is bad, was Re: Fedora 33 System-Wide Change proposal: systemd-resolved

2020-09-30 Thread Björn Persson
Neal Gompa wrote: > On Tue, Sep 29, 2020 at 7:48 AM Björn Persson wrote: > > > > Lennart Poettering wrote: > > > On Mo, 28.09.20 22:54, Björn Persson (Bjorn@rombobjörn.se) wrote: > > > > > > > It can work in company-scope if the company has c

Re: This is bad, was Re: Fedora 33 System-Wide Change proposal: systemd-resolved

2020-09-29 Thread Björn Persson
Lennart Poettering wrote: > On Mo, 28.09.20 22:54, Björn Persson (Bjorn@rombobjörn.se) wrote: > > > It can work in company-scope if the company has competent network > > admins. My local DNS server at home resolves local hostnames to private > > IPv4 addresses in the 192.

Re: This is bad, was Re: Fedora 33 System-Wide Change proposal: systemd-resolved

2020-09-28 Thread Björn Persson
I don't mind "losing" LLMNR, MDNS and synthetic records, which never existed in DNS to begin with. It would however be good to have the split DNS feature, and I see no reason why that wouldn't work with DNSsec. Of course, whether a DO query gets a useful response

Re: This is bad, was Re: Fedora 33 System-Wide Change proposal: systemd-resolved

2020-09-28 Thread Björn Persson
lly qualified domain name. Now people are saying in this thread that systemd-resolved treats both as local names and doesn't even try to look them up in DNS. So does systemd-resolved comply with this standard or not? Björn Persson pgpR1LBeVrXuG.pgp Description: OpenPGP digital sig

Re: btrfs / booting alternative OS versions from subvolumes

2020-09-19 Thread Björn Persson
des that it has been upgraded, and automatically converts the files to the new format. Then you reboot into another OS with an older version of the program, which doesn't understand the new format. Björn Persson pgpa6uCnwWouC.pgp Description: OpenPGP digital

Re: F33 update stuck for past 6 days in request for testing->stable

2020-09-12 Thread Björn Persson
ng list? Kevin's wording is perfect. It just needs to be visible in the web interface, with the words "Beta freeze" as a link. Björn Persson pgpfEuTuG6xiz.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedor

Re: [Test-Announce] Re: Fedora 33 Beta Go/No-Go and Release Readiness meetings

2020-09-11 Thread Björn Persson
; Sounds like a good change, which should be made for DNS as well. So where is a global pool of volunteer-provided DNS resolvers similar to pool.ntp.org? I've never heard of one, and I suspect it's not advisable to do that with DNS. Björn Persson pgpOgqC0Qs2k_.pgp

Re: The Future of the Java Stack (also regarding ELN and RHEL)

2020-09-09 Thread Björn Persson
program updates, and so on and so forth? And then manually check a bunch of individual upstream websites for updates to programs that aren't in those language-specific repositories either? No way! I run "yum update" and get *all* the updates for my system. Björn Persson pgpmHQ

Re: What is the real value of Release and %changelog metadata?

2020-08-23 Thread Björn Persson
p field always present, with the value 0 when not in use. Yet another option is to put the minorbump after the buildtag. I'd say this is technically manageable, but there is some risk that packagers would do minorbumps wrong by mistake. Björn Persson pgpFWv2VjPrhd.pgp Descripti

Re: What is the real value of Release and %changelog metadata?

2020-08-18 Thread Björn Persson
st}%{?buildtag}" > > Can I ask why this wouldn't be: > > Release: 1%{?buildtag}%{?dist} > > ? Putting the buildtag after the disttag makes it possible to change how the buildtag is generated in a future Fedora release without breaking upgrade paths. B

Re: What is the real value of Release and %changelog metadata?

2020-08-16 Thread Björn Persson
way, one or more of the current parts of the Version and Release fields should be updated. For a rebuild, when the source code hasn't changed, the spec wouldn't need to change either, and only the buildtag would set the rebuilt package apart from the previous one. Björn Persson

Re: What is the real value of Release and %changelog metadata?

2020-08-13 Thread Björn Persson
og. > Side question: Is it really useful to put "Rebuilt for > https://fedoraproject.org/wiki/Fedora_XX_Mass_Rebuild"; into changelogs? I don't see any use for those entries. There is already a build timestamp in the package metadata. Björn Persson pgpMsq9P1nJQE.p

Re: Coin4 build failure

2020-08-07 Thread Björn Persson
interpretation is that they want you to choose a source of randomness by defining one of those macros, so can you get the build system to pass -DXML_DEV_URANDOM to g++? Björn Persson pgpPcZvc6LN8c.pgp Description: OpenPGP digital signatur ___ devel

Re: Can we do away with release and changelog bumping?

2020-07-06 Thread Björn Persson
rrently it sits deployed in staging koji, > so you can give it a test-drive :-) What will the release value be when a package that uses autorel is built with fedpkg local? Or fedpkg mockbuild? Björn Persson pgpbSFrl37n3U.pgp Description: OpenPG

Re: Can we do away with release and changelog bumping?

2020-07-06 Thread Björn Persson
Florian Weimer wrote: > * Björn Persson: > > > The macro could be defined like this for example: > > > > %buildtag .%(date +%%s) > > Using time for synchronization is always a bit iffy. Well, if somebody manages to build a package twice within a second, usi

Re: Can we do away with release and changelog bumping?

2020-07-05 Thread Björn Persson
Nicolas Mailhot via devel wrote: > Le dimanche 05 juillet 2020 à 17:46 +0200, Björn Persson a écrit : > > It seems that several problems would just disappear if a rebuild > > would generate a unique package ID without a Git commit. > > That’s exacly what the change does.

Can we do away with release and changelog bumping? (was: RPM-level auto release and changelog bumping - Fedora 33 System-Wide Change proposal)

2020-07-05 Thread Björn Persson
, ignoring the buildtag. The buildtag would distinguish between different builds of the same version-release. What flaws can you all find in this idea? Björn Persson pgpIGk2i3K6iH.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@l

Re: use of 'date' in rpm .spec %define concats add'l str chars?

2020-07-03 Thread Björn Persson
PGNet Dev wrote: > %define _build_timestamp %( date +%Y%m%d_%H%M%S ) Percent signs that are not to be interpreted as RPM syntax need to be doubled. Write this as: %define _build_timestamp %(date +%%Y%%m%%d_%%H%%M%%S) Björn Persson pgpSR1gksDcHm.pgp Description: OpenPGP digi

Re: Is allowed in certain cases to override default Fedora compiler flags?

2020-07-02 Thread Björn Persson
it should be done by tweaking the code to silence the compiler warning for that call only. Disabling -Wunused-result for the whole program is not a good idea. Björn Persson pgpmAzjiNZ85n.pgp Description: OpenPGP digital signatur ___ devel mailing list -- deve

Re: Is allowed in certain cases to override default Fedora compiler flags?

2020-07-02 Thread Björn Persson
ood reason". As I understand it, Sergio's question is whether this case is a good reason. In my opinion, incorrect use of snprintf and write are bad reasons for overriding the compiler flags. It's better to fix the actual problem than to silence the alarm. Björn

Re: Is allowed in certain cases to override default Fedora compiler flags?

2020-07-02 Thread Björn Persson
ey find that burdensome, then that's because they made a bad choice of programming language. Björn Persson pgp7dztvU6yd2.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email

Re: [Fedora-packaging] Re: RPM-level auto release and changelog bumping - Fedora 33 System-Wide Change proposal

2020-07-02 Thread Björn Persson
key/value file will be committed to Git from inside Koji? Do the Koji builders have write access to Git? > commit the new build event timestamp in > the detached changelog file at %build time %build is executed once per arch, on different builders, so which builder's timestamp get

<    1   2   3   4   5   6   7   >