Gentoo Weekly Newsletter - Volume 3, Issue 28
Yuji Kosugi <[email protected]> Tue, 13 Jul 2004 22:58:25 +0900
| Newsgroups | gmane.linux.gentoo.weekly-news |
|---|---|
| Message-ID | <[email protected]> |
--------------------------------------------------------------------------- Gentoo Weekly Newsletter http://www.gentoo.org/news/en/gwn/current.xml This is the Gentoo Weekly Newsletter for the week of July 12th, 2004. --------------------------------------------------------------------------- ============== 1. Gentoo News ============== Portage update. --------------- Portage 2.0.51 continues to be in internal testing. Now in version 2.0.51_pre13 and masked, it's nearing readiness for ~arch. We'd like to cover some changes to Portage that users will notice if they pick up the currently masked 2.0.51_pre13, or a later ~arch masked or stable version. First of all, due to changes in the Portage cache, users will notice corruption messages when performing rsync updates, which will go away when the cache is altered in a few weeks. At this point however, versions of Portage prior to 2.0.50-r7 will start having problems because they won't be able to handle the new cache. As always, users are recommended to read the messages from emerge rsync and update Portage whenever a new stable version is available. Also, in the new version /var/cache/edb/virtuals is going to become obsolete: Portage will calculate the virtuals based on packages installed in the database. Once users upgrade to 2.0.51 the file will be obsolete and there will be no need to save it. Also, /var/cache/edb/world will be moving to the FHS-compliant state directory, /var/lib/portage. For more information, read Nicholas Jones[1]'s announcement[2] on gentoo-dev. 1. [email protected] 2. http://article.gmane.org/gmane.linux.gentoo.devel/19521 ================== 2. Gentoo Security ================== XFree86, X.org: XDM ignores requestPort setting ----------------------------------------------- XDM will open TCP sockets for its chooser, even if the DisplayManager.requestPort setting is set to 0. This may allow authorized users to access a machine remotely via X, even if the administrator has configured XDM to refuse such connections. For more information, please see the GLSA Announcement[3] 3. http://www.gentoo.org/security/en/glsa/glsa-200407-05.xml libpng: Buffer overflow on row buffers -------------------------------------- libpng contains a buffer overflow vulnerability potentially allowing an attacker to perform a Denial of Service attack or even execute arbitrary code. For more information, please see the GLSA Announcement[4] 4. http://www.gentoo.org/security/en/glsa/glsa-200407-06.xml Shorewall : Insecure temp file handling --------------------------------------- Shorewall contains a bug in the code handling the creation of temporary files and directories. This can allow a non-root user to overwrite arbitrary system files. For more information, please see the GLSA Announcement[5] 5. http://www.gentoo.org/security/en/glsa/glsa-200407-07.xml Ethereal: Multiple security problems ------------------------------------ Multiple vulnerabilities including one buffer overflow exist in Ethereal, which may allow an attacker to run arbitrary code or crash the program. For more information, please see the GLSA Announcement[6] 6. http://www.gentoo.org/security/en/glsa/glsa-200407-08.xml MoinMoin: Group ACL bypass -------------------------- MoinMoin contains a bug allowing a user to bypass group ACLs (Access Control Lists). For more information, please see the GLSA Announcement[7] 7. http://www.gentoo.org/security/en/glsa/glsa-200407-09.xml ================================= 3. Featured Developer of the Week ================================= Featured Developer is on hiatus this week. ========================= 4. Heard in the Community ========================= Web Forums ---------- New nvidia Drivers With Support for 2.6 Kernel Both the Kernel & Hardware and the Gamers & Players forums have threads about the new nvidia drivers that have been issued little over a week ago. The 4k stacksize problem with 2.6 kernels appears to have been solved, and the new drivers feature a configuration utility people seem to be quite pleased with: * New nVIDIA driver Version: 1.0-6106[8](Kernel & Hardware) * nVidia Drivers 6106[9](Gamers & Players) 8. http://forums.gentoo.org/viewtopic.php?t=192634 9. http://forums.gentoo.org/viewtopic.php?t=192485 gentoo-user ----------- Useful Install Tips Not to be left behind the forums, the some folks started their own Useful Install Tips[10] thread on gentoo-user this week. 10. http://thread.gmane.org/gmane.linux.gentoo.user/88339 Migrating to 2.6 Still haven't made the switch? The Changing to 2.6[11] thread may be a good place to start! 11. http://thread.gmane.org/gmane.linux.gentoo.user/87980 ======================= 5. Gentoo International ======================= Gentoo International is on hiatus this week. =========== 6. Bugzilla =========== Summary ------- * Statistics * Closed Bug Ranking * New Bug Rankings Statistics ---------- The Gentoo community uses Bugzilla (bugs.gentoo.org[12]) to record and track bugs, notifications, suggestions and other interactions with the development team. Between 03 July 2004 and 09 July 2004, activity on the site has resulted in: 12. http://bugs.gentoo.org * 576 new bugs during this period * 356 bugs closed or resolved during this period * 26 previously closed bugs were reopened this period Of the 6736 currently open bugs: 138 are labeled 'blocker', 179 are labeled 'critical', and 528 are labeled 'major'. Closed Bug Rankings ------------------- The developers and teams who have closed the most bugs during this period are: * AMD64 Porting Team[13], with 44 closed bugs[14] * Desktop Miscellaneous Team[15], with 17 closed bugs[16] * Jeremy Huddleston[17], with 13 closed bugs[18] * Netmon Herd[19], with 12 closed bugs[20] * Net-Mail Packages[21], with 12 closed bugs[22] * Gentoo KDE team[23], with 12 closed bugs[24] 13. [email protected] 14. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX ED&[email protected] 15. [email protected] 16. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX ED&[email protected] 17. [email protected] 18. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX ED&[email protected] 19. [email protected] 20. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX ED&[email protected] 21. [email protected] 22. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX ED&[email protected] 23. [email protected] 24. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch field=bug_status&chfieldfrom=2004-07-03&chfieldto=2004-07-09&resolution=FIX ED&[email protected] New Bug Rankings ---------------- The developers and teams who have been assigned the most new bugs during this period are: * Gentoo Linux Gnome Desktop Team[25], with 21 new bugs[26] * Media-Video Herd[27], with 13 new bugs[28] * AMD64 Porting Team[29], with 12 new bugs[30] * Mozilla Gentoo Team[31], with 11 new bugs[32] * Gentoo X-windows Packagers[33], with 10 new bugs[34] * Gentoo's Team for Core System Packages[35], with 10 new bugs[36] 25. [email protected] 26. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07 -09&[email protected] 27. [email protected] 28. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07 -09&[email protected] 29. [email protected] 30. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07 -09&[email protected] 31. [email protected] 32. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07 -09&[email protected] 33. [email protected] 34. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07 -09&[email protected] 35. [email protected] 36. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-07-03&chfieldto=2004-07 -09&[email protected] ================== 7. Tips and Tricks ================== Using 'make' for backups ------------------------ Thanks to Lars Weiler[37] for providing this week's tip. 37. [email protected] Usualy make from sys-devel/make is known as a tool for compiling applications. But it could also be used to provide often used commands so that they can be accessed easily. Quite everybody wants to do backups. This could be done by packing them with tar. For instance, we want to pack the ~/Mail folder and name the file with a date: --------------------------------------------------------------------------- | Code Listing 7.1: | | tar ~/Mail with date included | --------------------------------------------------------------------------- | | |$ tar cvjf ~/Backups/Mail-`date +%F`.tar.bz2 ~/Mail | | | --------------------------------------------------------------------------- After that we copy that file (and possibly more) to another computer by using rsync and delete all the files in ~/Backups afterwards: --------------------------------------------------------------------------- | Code Listing 7.2: | | Copy backup-file to another computer with rsync | --------------------------------------------------------------------------- | | |$ rsync -avute ssh ~/Backups/ user@othermachine:~/Backups/ | |% rm ~/Backups/* | | | --------------------------------------------------------------------------- And now comes the clue with make. After a week you already forgot the commands. Why not store them in a Makefile located in the home-directory, so that you only have to call make backup? Inside the Makefile (beware of the uppercased 'M') we provide two targets for the commands, so that we can call them separately, e.g. if you only want to copy the files. The first target backup will only call the other targets in the given order: --------------------------------------------------------------------------- | Code Listing 7.3: | | Sample Makefile for backups | --------------------------------------------------------------------------- | | |backup: compress \ | | copy | | | |compress: | | tar cvjf ~/Backups/Mail-`date +%F`.tar.bz2 ~/Mail | | | |copy: | | rsync -avute ssh ~/Backups/ user@othermachine:~/Backups/ | | rm ~/Backups/* | | | --------------------------------------------------------------------------- Now we can call make backup in the home directory and the ~/Mail-folder will be compressed and copied to the other computer. The restore-command-set will be your homework ;-) Of course, there is a wide use for batched processes with Makefiles. Think about all the things you ever wanted to have scripted with easy usability. You can find more instructions in the info make pages. =========================== 8. Moves, Adds, and Changes =========================== Moves ----- The following developers recently left the Gentoo team: * None this week Adds ---- The following developers recently joined the Gentoo Linux team: * None this week Changes ------- The following developers recently changed roles within the Gentoo Linux project: * None this week ==================== 9. Contribute to GWN ==================== Interested in contributing to the Gentoo Weekly Newsletter? Send us an email[38]. 38. [email protected] ================ 10. GWN Feedback ================ Please send us your feedback[39] and help make the GWN better. 39. [email protected] ================================ 11. GWN Subscription Information ================================ To subscribe to the Gentoo Weekly Newsletter, send a blank email to [email protected]. To unsubscribe to the Gentoo Weekly Newsletter, send a blank email to [email protected] from the email address you are subscribed under. =================== 12. Other Languages =================== The Gentoo Weekly Newsletter is also available in the following languages: * Danish[40] * Dutch[41] * English[42] * German[43] * French[44] * Japanese[45] * Italian[46] * Polish[47] * Portuguese (Brazil)[48] * Portuguese (Portugal)[49] * Russian[50] * Spanish[51] * Turkish[52] 40. http://www.gentoo.org/news/da/gwn/gwn.xml 41. http://www.gentoo.org/news/be/gwn/gwn.xml 42. http://www.gentoo.org/news/en/gwn/gwn.xml 43. http://www.gentoo.org/news/de/gwn/gwn.xml 44. http://www.gentoo.org/news/fr/gwn/gwn.xml 45. http://www.gentoo.org/news/ja/gwn/gwn.xml 46. http://www.gentoo.org/news/it/gwn/gwn.xml 47. http://www.gentoo.org/news/pl/gwn/gwn.xml 48. http://www.gentoo.org/news/br/gwn/gwn.xml 49. http://www.gentoo.org/news/pt/gwn/gwn.xml 50. http://www.gentoo.org/news/ru/gwn/gwn.xml 51. http://www.gentoo.org/news/es/gwn/gwn.xml 52. http://www.gentoo.org/news/tr/gwn/gwn.xml Yuji Carlos Kosugi <[email protected]> - Editor AJ Armstrong <[email protected]> - Contributor Brian Downey <[email protected]> - Contributor Kurt Lieber <[email protected]> - Contributor David Narayan <[email protected]> - Contributor Ulrich Plate <[email protected]> - Contributor Sven Vermeulen <[email protected]> - Contributor Simon Holm Thagersen <[email protected]> - Danish Translation Jesper Brodersen <[email protected]> - Danish Translation Arne Mejlholm <[email protected]> - Danish Translation Hendrik Eeckhaut <[email protected]> - Dutch Translation Jorn Eilander <[email protected]> - Dutch Translation Bernard Kerckenaere <[email protected]> - Dutch Translation Peter ter Borg <[email protected]> - Dutch Translation Jochen Maes <[email protected]> - Dutch Translation Roderick Goessen <[email protected]> - Dutch Translation Gerard van den Berg <[email protected]> - Dutch Translation Matthieu Montaudouin <[email protected]> - French Translation Xavier Neys <[email protected]> - French Translation Martin Prieto <[email protected]> - French Translation Antoine Raillon <[email protected]> - French Translation Sebastien Cevey <[email protected]> - French Translation Jean-Christophe Choisy <[email protected]> - French Translation Thomas Raschbacher <[email protected]> - German Translation Steffen Lassahn <[email protected]> - German Translation Matthias F. Brandstetter <[email protected]> - German Translation Lukas Domagala <[email protected]> - German Translation Tobias Scherbaum <[email protected]> - German Translation Daniel Gerholdt <[email protected]> - German Translation Marc Herren <[email protected]> - German Translation Tobias Matzat <[email protected]> - German Translation Marco Mascherpa <[email protected]> - Italian Translation Claudio Merloni <[email protected]> - Italian Translation Stefano Lucidi <[email protected]> - Italian Translation Katuyuki Konno <[email protected]> - Japanese Translation Hiroyuki Takeda <[email protected]> - Japanese Translation Masato Hatakeyama <[email protected]> - Japanese Translation Shigehiro Idani <[email protected]> - Japanese Translation Masayoshi Nakamura <[email protected]> - Japanese Translation Tomoyuki Sakurai <[email protected]> - Japanese Translation Lukasz Strzygowski <[email protected]> - Polish Translation Karol Goralski <[email protected]> - Polish Translation Atila "Jedi" Bohlke Vasconcelos <[email protected]> - Portuguese (Brazil) Translation Eduardo Belloti <[email protected]> - Portuguese (Brazil) Translation Jo??o Rafael Moraes Nicola <[email protected]> - Portuguese (Brazil) Translation Marcelo Gon??alves de Azambuja <[email protected]> - Portuguese (Brazil) Translation Otavio Rodolfo Piske <[email protected]> - Portuguese (Brazil) Translation Pablo N. Hess -- NatuNobilis <[email protected]> - Portuguese (Brazil) Translation Pedro de Medeiros <[email protected]> - Portuguese (Brazil) Translation Ventura Barbeiro <[email protected]> - Portuguese (Brazil) Translation Bruno Ferreira <[email protected]> - Portuguese (Portugal) Translation Gustavo Felisberto <[email protected]> - Portuguese (Portugal) Translation Jos?? Costa <[email protected]> - Portuguese (Portugal) Translation Luis Medina <[email protected]> - Portuguese (Portugal) Translation Ricardo Loureiro <[email protected]> - Portuguese (Portugal) Translation Aleksandr Martyncev <[email protected]> - Russian Translator Sergey Galkin <[email protected]> - Russian Translator Sergey Kuleshov <[email protected]> - Russian Translator Alex Spirin <[email protected]> - Russian Translator Denis Zaletov <[email protected]> - Russian Translator Guillermo Juarez <[email protected]> - Spanish Translation Fernando J. Pereda <[email protected]> - Spanish Translation Juan Diego Guti??rrez Gallardo <[email protected]> - Spanish Translation Nicolas Silva <[email protected]> - Spanish Translation Aycan Irican <[email protected]> - Turkish Translation Bugra Cakir <[email protected]> - Turkish Translation Cagil Seker <[email protected]> - Turkish Translation Emre Kazdagli <[email protected]> - Turkish Translation Evrim Ulu <[email protected]> - Turkish Translation Gursel Kaynak <[email protected]> - Turkish Translation
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFA8+qB9QP4LZPv56cRAuKbAJ4ljNAcdRHiiimOqsyxhHJVqId0+wCfX/1E UAihyiyL1IXBnFdancq0H9E= =2aqQ -----END PGP SIGNATURE-----