Gentoo Weekly Newsletter - Volume 3, Issue 24

Yuji Kosugi <[email protected]> Tue, 15 Jun 2004 21:14:46 +0900
Newsgroups gmane.linux.gentoo.weekly-news
Message-ID <[email protected]>
---------------------------------------------------------------------------
Gentoo Weekly Newsletter
http://www.gentoo.org/news/en/gwn/current.xml
This is the Gentoo Weekly Newsletter for the week of May 31st, 2004.
---------------------------------------------------------------------------
 
==============
1. Gentoo News
==============
  
Gentoo Not-For-Profit Paperwork complete
----------------------------------------
  
The paperwork for the Gentoo Not-For-Profit entity was approved by the 
State of New Mexico today. This means that as of today, the Gentoo 
Foundation is an official Not-For-Profit Corporation in the United States. 
The process of becoming a Federally-recognized not-for-profit entity, 
which will take about six months for approval, can now begin. Sven 
Vermeulen has been tasked with drafting a charter for the newly approved 
Gentoo Foundation. Assets of Gentoo Technologies, Inc. such as the 
gentoo.org domain, can now be transferred to the Gentoo Foundation. We're 
glad to see all the hard work that has been put into this process giving 
some positive results and would like to thank Daniel Robbins[1] and all of 
the trustees for their hard work. 

 1. [email protected]
    
Ways to get involved: Introducing [email protected]
------------------------------------------------------------
  
Developer Stuart Herbert[2] has created a new bugzilla user 
([email protected]), to which he is assigning all bugs about new 
packages. Some of these bugs are requests for ebuilds. Some of the bugs 
include ebuilds that need testing (and maybe fixing). 

 2. [email protected]
 
If you want to get involved with Gentoo, and can spare the time, this 
would be a great way - especially if you know any of the packages 
involved. This will free up some time for the developers to concentrate on 
real bugs reported against packages already in Portage. 
 
If you want to be notified when new bugs are added to the webapps-request 
list, you can setup a watch in your Bugzilla account. Simply go to this 
page[3] and in the "Users to watch:" box, type in 
'[email protected]'. 

 3. http://bugs.gentoo.org/userprefs.cgi?tab=email
    
==================
2. Gentoo Security
==================
  
Mailman: Member password disclosure vulnerability
-------------------------------------------------
  
Mailman contains a bug allowing 3rd parties to retrieve member passwords. 
 
For more information, please see the GLSA Announcement[4] 

 4. http://www.gentoo.org/security/en/glsa/glsa-200406-04.xml
    
Apache: Buffer overflow in mod_ssl
----------------------------------
  
A bug in mod_ssl may allow a remote attacker to execute remote code when 
Apache is configured a certain way. 
 
For more information, please see the GLSA Announcement[5] 

 5. http://www.gentoo.org/security/en/glsa/glsa-200406-05.xml
    
CVS: additional DoS and arbitrary code execution vulnerabilities
----------------------------------------------------------------
  
Several serious new vulnerabilities have been found in CVS, which may 
allow an attacker to remotely compromise a CVS server. 
 
For more information, please see the GLSA Announcement[6] 

 6. http://www.gentoo.org/security/en/glsa/glsa-200406-06.xml
    
Subversion: Remote heap overflow
--------------------------------
  
Subversion is vulnerable to a remote Denial of Service that may be 
exploitable to execute arbitrary code on the server running svnserve. 
 
For more information, please see the GLSA Announcement[7] 

 7. http://www.gentoo.org/security/en/glsa/glsa-200406-07.xml
    
=========================
3. Heard in the Community
=========================
  
Web Forums
----------
  
Linux Memory Management 
 
A concise and very useful tutorial about memory management in Linux has 
made its way into the Documentation, Tips & Tricks section, paying special 
attention to things peculiar in 2.6 kernels: 
 
 * Linux Memory Management or 'Why is there no free RAM?'[8] 
 8. http://forums.gentoo.org/viewtopic.php?t=175419
    
gentoo-user
-----------
  
Deadlocking Kernels 
 
A vulnerability that apparently affects all x86 2.4 and 2.6 series kernels 
was shared on gentoo-user  here[9] with exploit code in tow. 

 9. http://article.gmane.org/gmane.linux.gentoo.user/84302
 
The GWN and RSS 
 
This[10] thread covered reading the GWN via an RSS feed, as well as 
preferred applications to do so. 

 10. http://article.gmane.org/gmane.linux.gentoo.user/84115
    
=======================
4. Gentoo International
=======================
   
Germany: LPI 101 Certification in German at the LinuxTag in Karlsruhe 
 
The German branch of the Linux Professional Institute[11] has announced 
that they will offer certification in German for the first time at the 
LinuxTag in Karlsruhe[12] this year. For 30 Euros, visitors to the fair 
(and some of the German devs at the Gentoo booth are known to go as well) 
can sit for the LPI 101 in German or English, or the LPI 201 in English 
only, on 24 to 26 June 2004. Details here.[13].

 11. http://www.lpi-german.de
 12. http://www.linuxtag.de
 13. http://www.lpi-german.de/presse/20040609.html
    
===========
5. Bugzilla
===========
  
Summary
-------
  
 * Statistics 
 * Closed Bug Ranking 
 * New Bug Rankings 
    
Statistics
----------
  
The Gentoo community uses Bugzilla (bugs.gentoo.org[14]) to record and 
track bugs, notifications, suggestions and other interactions with the 
development team. Between 04 June 2004 and 10 June 2004, activity on the 
site has resulted in: 

 14. http://bugs.gentoo.org
 
 * 537 new bugs during this period 
 * 305 bugs closed or resolved during this period 
 * 14 previously closed bugs were reopened this period 
 
Of the 6461 currently open bugs: 131 are labeled 'blocker', 189 are 
labeled 'critical', and 524 are labeled 'major'. 
    
Closed Bug Rankings
-------------------
  
The developers and teams who have closed the most bugs during this period 
are: 
 
 * Gentoo Games[15], with 18 closed bugs[16]  
 * Gentoo's Team for Core System packages[17], with 12 closed bugs[18]  
 * Net-Mail Packages[19], with 11 closed bugs[20]  
 * Thomas Raschbacher[21], with 9 closed bugs[22]  
 * Gentoo KDE team[23], with 8 closed bugs[24]  
 15. [email protected]
 16. 
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch
field=bug_status&chfieldfrom=2004-06-04&chfieldto=2004-06-10&resolution=FIX
ED&[email protected]
 17. [email protected]
 18. 
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch
field=bug_status&chfieldfrom=2004-06-04&chfieldto=2004-06-10&resolution=FIX
ED&[email protected]
 19. [email protected]
 20. 
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch
field=bug_status&chfieldfrom=2004-06-04&chfieldto=2004-06-10&resolution=FIX
ED&[email protected]
 21. [email protected]
 22. 
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch
field=bug_status&chfieldfrom=2004-06-04&chfieldto=2004-06-10&resolution=FIX
ED&[email protected]
 23. [email protected]
 24. 
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch
field=bug_status&chfieldfrom=2004-06-04&chfieldto=2004-06-10&resolution=FIX
ED&[email protected]

New Bug Rankings
----------------
  
The developers and teams who have been assigned the most new bugs during 
this period are: 
 
 * Gentoo Toolchain Maintainers[25], with 19 new bugs[26]  
 * Gentoo Linux Gnome Desktop Team[27], with 17 new bugs[28]  
 * AMD64 Porting Team[29], with 16 new bugs[30]  
 * Gentoo Web Application Packages Maintainers[31], with 12 new bugs[32]  
 * Gentoo Perl Devs[33], with 12 new bugs[34]  
 * Gentoo KDE team[35], with 12 new bugs[36]  
 25. [email protected]
 26. 
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-06-04&chfieldto=2004-06
-10&[email protected]
 27. [email protected]
 28. 
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-06-04&chfieldto=2004-06
-10&[email protected]
 29. [email protected]
 30. 
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-06-04&chfieldto=2004-06
-10&[email protected]
 31. [email protected]
 32. 
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-06-04&chfieldto=2004-06
-10&[email protected]
 33. [email protected]
 34. 
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-06-04&chfieldto=2004-06
-10&[email protected]
 35. [email protected]
 36. 
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s
tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-06-04&chfieldto=2004-06
-10&[email protected]
    
==================
6. Tips and Tricks
==================
   
Protecting files with noclobber
 
This tip is for people who have ever hosed important files by using > when 
they meant to use >>. Add the following line to .bashrc: set -o noclobber. 
The noclobber option prevents you from overwriting existing files with the 
> operator.
 
---------------------------------------------------------------------------
| Code Listing 6.1:                                                       |
|-------------------------------------------------------------------------|
|                                                                         |
|% program > file2                                                        |
|bash: file2: cannot overwrite existing file                              |
---------------------------------------------------------------------------
 
In some cases you may really want to overwrite the file. In this case, 
instead of turning noclobber off, you can use >| to force the file to be 
written.
 
---------------------------------------------------------------------------
| Code Listing 6.2:                                                       |
|-------------------------------------------------------------------------|
|                                                                         |
|% program >| file2                                                       |
---------------------------------------------------------------------------
    
===========================
7. Moves, Adds, and Changes
===========================
  
Moves
-----
  
The following developers recently left the Gentoo team:
 
 * None this week 
    
Adds
----
  
The following developers recently joined the Gentoo Linux team:
 
 * None this week 
    
Changes
-------
  
The following developers recently changed roles within the Gentoo Linux 
project:
 
 * None this week 
    
====================
8. Contribute to GWN
====================
   
Interested in contributing to the Gentoo Weekly Newsletter? Send us an 
email[37].

 37. [email protected]
    
===============
9. GWN Feedback
===============
   
Please send us your feedback[38] and help make the GWN better.

 38. [email protected]
    
================================
10. GWN Subscription Information
================================
   
To subscribe to the Gentoo Weekly Newsletter, send a blank email to 
[email protected].
 
To unsubscribe to the Gentoo Weekly Newsletter, send a blank email to 
[email protected] from the email address you are 
subscribed under.
    
===================
11. Other Languages
===================
   
The Gentoo Weekly Newsletter is also available in the following languages:
 
 * Danish[39] 
 * Dutch[40] 
 * English[41] 
 * German[42] 
 * French[43] 
 * Japanese[44] 
 * Italian[45] 
 * Polish[46] 
 * Portuguese (Brazil)[47] 
 * Portuguese (Portugal)[48] 
 * Russian[49] 
 * Spanish[50] 
 * Turkish[51] 
 39. http://www.gentoo.org/news/da/gwn/gwn.xml
 40. http://www.gentoo.org/news/be/gwn/gwn.xml
 41. http://www.gentoo.org/news/en/gwn/gwn.xml
 42. http://www.gentoo.org/news/de/gwn/gwn.xml
 43. http://www.gentoo.org/news/fr/gwn/gwn.xml
 44. http://www.gentoo.org/news/ja/gwn/gwn.xml
 45. http://www.gentoo.org/news/it/gwn/gwn.xml
 46. http://www.gentoo.org/news/pl/gwn/gwn.xml
 47. http://www.gentoo.org/news/br/gwn/gwn.xml
 48. http://www.gentoo.org/news/pt/gwn/gwn.xml
 49. http://www.gentoo.org/news/ru/gwn/gwn.xml
 50. http://www.gentoo.org/news/es/gwn/gwn.xml
 51. http://www.gentoo.org/news/tr/gwn/gwn.xml

Yuji Carlos Kosugi <[email protected]> - Editor
AJ Armstrong <[email protected]> - Contributor
Brian Downey <[email protected]> - Contributor
Kurt Lieber <[email protected]> - Contributor
David Narayan <[email protected]> - Contributor
Ulrich Plate <[email protected]> - Contributor
Sven Vermeulen <[email protected]> - Contributor
Simon Holm Thagersen <[email protected]> - Danish Translation
Jesper Brodersen <[email protected]> - Danish Translation
Arne Mejlholm <[email protected]> - Danish Translation
Hendrik Eeckhaut <[email protected]> - Dutch Translation
Jorn Eilander <[email protected]> - Dutch Translation
Bernard Kerckenaere <[email protected]> - Dutch Translation
Peter ter Borg <[email protected]> - Dutch Translation
Jochen Maes <[email protected]> - Dutch Translation
Roderick Goessen <[email protected]> - Dutch Translation
Gerard van den Berg <[email protected]> - Dutch Translation
Matthieu Montaudouin <[email protected]> - French Translation
Xavier Neys <[email protected]> - French Translation
Martin Prieto <[email protected]> - French Translation
Antoine Raillon <[email protected]> - French Translation
Sebastien Cevey <[email protected]> - French Translation
Jean-Christophe Choisy <[email protected]> - French Translation
Thomas Raschbacher <[email protected]> - German Translation
Steffen Lassahn <[email protected]> - German Translation
Matthias F. Brandstetter <[email protected]> - German Translation
Lukas Domagala <[email protected]> - German Translation
Tobias Scherbaum <[email protected]> - German Translation
Daniel Gerholdt <[email protected]> - German Translation
Marc Herren <[email protected]> - German Translation
Tobias Matzat <[email protected]> - German Translation
Marco Mascherpa <[email protected]> - Italian Translation
Claudio Merloni <[email protected]> - Italian Translation
Stefano Lucidi <[email protected]> - Italian Translation
Katuyuki Konno <[email protected]> - Japanese Translation
Hiroyuki Takeda <[email protected]> - Japanese Translation
Masato Hatakeyama <[email protected]> - Japanese Translation
Masayoshi Nakamura <[email protected]> - Japanese Translation
Yasunori Fukudome <[email protected]> - Japanese Translation
Tomoyuki Sakurai <[email protected]> - Japanese Translation
Lukasz Strzygowski <[email protected]> - Polish Translation
Karol Goralski <[email protected]> - Polish Translation
Atila "Jedi" Bohlke Vasconcelos <[email protected]> - Portuguese 
(Brazil) Translation
Eduardo Belloti <[email protected]> - Portuguese (Brazil) Translation
Jo??o Rafael Moraes Nicola <[email protected]> - Portuguese (Brazil) 
Translation
Marcelo Gon??alves de Azambuja <[email protected]> - Portuguese 
(Brazil) Translation
Otavio Rodolfo Piske <[email protected]> - Portuguese (Brazil) 
Translation
Pablo N. Hess -- NatuNobilis <[email protected]> - Portuguese 
(Brazil) Translation
Pedro de Medeiros <[email protected]> - Portuguese (Brazil) Translation
Ventura Barbeiro <[email protected]> - Portuguese (Brazil) 
Translation
Bruno Ferreira <[email protected]> - Portuguese (Portugal) 
Translation
Gustavo Felisberto <[email protected]> - Portuguese (Portugal) 
Translation
Jos?? Costa <[email protected]> - Portuguese (Portugal) Translation
Luis Medina <[email protected]> - Portuguese (Portugal) Translation
Ricardo Loureiro <[email protected]> - Portuguese (Portugal) Translation
Aleksandr Martyncev <[email protected]> - Russian Translator
Sergey Galkin <[email protected]> - Russian Translator
Sergey Kuleshov <[email protected]> - Russian Translator
Alex Spirin <[email protected]> - Russian Translator
Denis Zaletov <[email protected]> - Russian Translator
Lanark <[email protected]> - Spanish Translation
Fernando J. Pereda <[email protected]> - Spanish Translation
Lluis Peinado Cifuentes <[email protected]> - Spanish Translation
Zephryn Xirdal T <[email protected]> - Spanish Translation
Guillermo Juarez <[email protected]> - Spanish Translation
Jes??s Garc??a Crespo <[email protected]> - Spanish Translation
Carlos Castillo <[email protected]> - Spanish Translation
Julio Castillo <[email protected]> - Spanish Translation
Sergio G??mez <[email protected]> - Spanish Translation
Aycan Irican <[email protected]> - Turkish Translation
Bugra Cakir <[email protected]> - Turkish Translation
Cagil Seker <[email protected]> - Turkish Translation
Emre Kazdagli <[email protected]> - Turkish Translation
Evrim Ulu <[email protected]> - Turkish Translation
Gursel Kaynak <[email protected]> - Turkish Translation
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFAzug29QP4LZPv56cRAqStAJ0Wd8ZSEtwPPEo25fxgsz6QHw6ZjwCeLSC7
gRPs0xmBMM5FVGlUauugWrU=
=sa1H
-----END PGP SIGNATURE-----