[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Removing Packages in Slink for Debian 2.1



Okay, everybody...  It's that time again.  I've gone through the bug logs
and made my list of packages to keep/remove should they still have
release-critical (i.e. critical, grave, or important) bugs at ship time.

The following bugs are for packages I don't think we can ship 2.1 without:

apache-common     25990  apache-common: apache expects passwd.db but not dbmmanage [54]  (Johnie Ingram <johnie@debian.org>)
apache-ssl        26012  apache-ssl: usage of /tmp/ssl.log is a security hole [54]  (Christoph Martin <christoph.martin@uni-mainz.de>)
base-passwd       25882  various system users inherited my personal gid (100) ! [57]  (Galen Hazelwood <galenh@micron.net>)
bash              27661  bash handling of if/fi broken when &quot;sourced&quot; [0]  (Guy Maor <maor@debian.org>)
boot-floppies     26584  lomem install doesn't activate swap [34]  (Enrique Zanardi <sr1-boot-floppies@debian.org>)
boot-floppies     27061  boot-floppies' .bash_profile for root prompt for pkgsel is confusing [19]  (Enrique Zanardi <sr1-boot-floppies@debian.org>)
cron              26705  RedHat (possible) buffer overflow fixes [29]  (Steve Greenland <stevegr@master.debian.org>)
dpkg               1797  upgrade/downgrade dependency calculation problem [1075]  (Klee Dienes and Ian Jackson <dpkg-maint@chiark.greenend.org.uk>)
dpkg              17624  dpkg: installs regular dir when .deb contains symlink ! [257]  (Klee Dienes and Ian Jackson <dpkg-maint@chiark.greenend.org.uk>)
dpkg              20401  Problems updating bo -&gt; hamm [198]  (Klee Dienes and Ian Jackson <dpkg-maint@chiark.greenend.org.uk>)
dpkg              21182  dpkg: dpkg can go into an infinite loop with --force-configure-any [181]  (Klee Dienes and Ian Jackson <dpkg-maint@chiark.greenend.org.uk>)
dpkg              26880  dpkg: Creating XF86Config during install freezes VT [23]  (Klee Dienes and Ian Jackson <dpkg-maint@chiark.greenend.org.uk>)
dpkg-dev          25405  xpm: builds libc5 package on powerpc [70]  (Klee Dienes and Ian Jackson <dpkg-maint@chiark.greenend.org.uk>)
fakeroot          27794  fakeroot: fakeroot depends on missing library [0]  (joost witteveen <joostje@debian.org>)
fetchmail         23092  Security: fetchmail sends packets off site without explicit permission [133]  (Paul Haggart <phaggart@debian.org>)
ftp.debian.org    25761  ftp.debian.org: No standard naming convention for mirrors.. [59]  (Guy Maor <ftpmaster@debian.org>)
ftp.debian.org    26920  ftp.debian.org: package installation procedure problem [22]  (Guy Maor <ftpmaster@debian.org>)
ftp.debian.org    27381  libg++272-dev and libstdc++2.8-dev conflict, being both standard!! [11]  (Guy Maor <ftpmaster@debian.org>)
ftp.debian.org    27642  exim needs to be made standard, smail needs to be made optional [0]  (Guy Maor <ftpmaster@debian.org>)
gcc               26100  gcc: -dynamic is not default as it should be [50]  (Galen Hazelwood <galenh@micron.net>)
groff             27790  groff depends on missing libary. [0]  (Fabrizio Polacco <fpolacco@debian.org>)
libc6             26147  dlopen() corrupts heap, dlclose() reads free()'d memory [49]  (Dale Scheetz <dwarf@polaris.net>)
libc6             27314  libc6: wrong shlibs file [12]  (Dale Scheetz <dwarf@polaris.net>)
libc6             27334  libc6: breaks sendmail, probably problem in resolver [12]  (Dale Scheetz <dwarf@polaris.net>)
libc6             27403  libc6: fsck error occure after ldconfig [10]  (Dale Scheetz <dwarf@polaris.net>)
libc6-doc         26984  libc6-doc: info files problem. [21]  (Dale Scheetz <dwarf@polaris.net>)
libpam0g          27514  libpam moved without warning! [8]  (Klee Dienes <klee@debian.org>)
libreadlineg2     27762  libreadlineg2 links in old ncurses [0]  (Guy Maor <maor@debian.org>)
mount             27421  mount: fails to parse existing /etc/fstab [10]  (Vincent Renardias <vincent@waw.com>)
netstd            27789  netstd depends on libstdc++2.8 [0]  (Herbert Xu <herbert@debian.org>)
nis               26294  package is out of date; makedbm does not handle &quot;\&quot; extended lines longer than 120 characters [43]  (Miquel van Smoorenburg <miquels@cistron.nl>)
nonus.debian.org  18572  nonus.debian.org: remove des-solnet_1.03-5.deb [231]  (Sven Rudolph <sr1@inf.tu-dresden.de>)
nonus.debian.org  18785  nonus.debian.org: incoming backlog [225]  (Sven Rudolph <sr1@inf.tu-dresden.de>)
nonus.debian.org  18887  des-solnet: package description [222]  (Sven Rudolph <sr1@inf.tu-dresden.de>)
nonus.debian.org  20773  nonus.debian.org: please remove gnupg from frozen [190]  (Sven Rudolph <sr1@inf.tu-dresden.de>)
nonus.debian.org  21423  Dpkg-ftp can't handle alternative distributions [177]  (Sven Rudolph <sr1@inf.tu-dresden.de>)
nonus.debian.org  22287  nonus.debian.org with incorrect layout [157]  (Sven Rudolph <sr1@inf.tu-dresden.de>)
nonus.debian.org  23642  Packages [118]  (Sven Rudolph <sr1@inf.tu-dresden.de>)
nonus.debian.org  25198  nonus.debian.org: Packages don't exist [76]  (Sven Rudolph <sr1@inf.tu-dresden.de>)
perl              27604  Perl @INC needs /usr/lib/perl5 [7]  (Darren Stalder <torin@daft.com>)
perl              27738  perl: @INC does not contain /usr/lib/perl5 [0]  (Darren Stalder <torin@daft.com>)
sendmail          26106  sendmail postinst is not tolerant of warnings [50]  (Richard Nelson <cowboy@debian.org>)
slang1            27385  slang1: Still no source package [11]  (Chris Fearnley <cjf@netaxs.com>)
ssh               27415  ssh suddenly requires controlling tty [10]  (Philip Hands <phil@hands.com>)
svgalibg1         25878  svgalib: security hole [57]  (Andy Mortimer <andy.mortimer@poboxes.com>)
tetex-base        27895  tetex-base config problem [0]  (Christoph Martin <christoph.martin@uni-mainz.de>)
xemacs20-bin      25676  xemacs20-bin: GNUS: Insecure MIME extraction [62]  (James LewisMoss <dres@dimensional.com>)

If you feel otherwise, please let me know.  These bugs remaining open will
delay the release of Debian 2.1 (currently planned for the end of November).

The following are packages I feel we can remove:

ada-rm            27918  ada-rm: This large package should be architecture: all [0]  ()
apple2            27590  apple2: should be in contrib, not main [7]  (Tom Lear <tom@trap.mountain-view.ca.us>)
balsa             27726  balsa cannot be run [0]  (olet@debian.org (Ole J. Tetlie))
balsa             27894  balsa is linked against ancient version of gtk [0]  (olet@debian.org (Ole J. Tetlie))
cvs-pcl           22577  compile of pcl-cvs.el fails (cannot load &quot;cookie&quot;) [149]  (Tom Lees <tom@lpsg.demon.co.uk>)
dhcp-client-beta  18322  dhclient-script problem with &quot;EXPIRE&quot; [238]  (Rich Sahlender <rsahlen@debian.org>)
dhcp-client-beta  19767  dhcp-client-beta has no /usr/doc directory [211]  (Rich Sahlender <rsahlen@debian.org>)
freetype2-dev     27814  freetype2-dev: should not conflict with freetype1 [0]  (Anthony Fok <foka@debian.org>)
gnome-gnothello   27405  gnome-gnothello doesn't run here [10]  (James LewisMoss <dres@debian.org>)
gnus              25609  Gnus: prerm script failure make it impossible to upgrade/pruge  [64]  (Michael Alan Dorman <mdorman@debian.org>)
htdig             25412  htdig: htdig ignores config file stuff/absolute pathnames compiled in [70]  (Gergely Madarasz <gorgo@caesar.elte.hu>)
infocom           21478  infocom: Integrating infocom interpreters [175]  (Brian White <bcwhite@pobox.com>)
jdk1.1            27097  jdk1.1: error in installing jdk1.1: links are in a mess [18]  (Stephen Zander <gibreel@debian.org>)
jdk1.1            27330  jdk1.1: Files should be conffiles [12]  (Stephen Zander <gibreel@debian.org>)
jove              27219  jove: Jove wants /usr/tmp [14]  (Loic Prylli <lprylli@graville.fdn.fr>)
junkbuster        25258  junkbuster: junkbuster has security holes [74]  (Paul Haggart <phaggart@debian.org>)
kaffe             20980  kaffe: kaffe depends on jdk-common [186]  ()
kdebase           23655  kdebase includes /etc/X11/Xsession [118]  (Stephan Kulow <coolo@kde.org>)
kdebase           25903  kdebase doesn't include rights to distribute kvt [56]  (Stephan Kulow <coolo@kde.org>)
kdebase           25974  kvt creates ~/.kde with root as owner and insane permissions  [55]  (Stephan Kulow <coolo@kde.org>)
kdegraphics       25627  kdegraphics violates copyright [63]  (Stephan Kulow <coolo@kde.org>)
kdelibs0g         24643  kdebase: We have no licence to distribute KDE binaries when linked against Qt [90]  (Stephan Kulow <coolo@kde.org>)
kdemultimedia     25628  kmultimedia violates copyright law (and debian policy) [63]  (Stephan Kulow <coolo@kde.org>)
kdeutils          25630  kdeutils copyright problems [63]  (Stephan Kulow <coolo@kde.org>)
knfs              27250  knfs (remote root exploit) [14]  (Anders Hammarquist <iko@debian.org>)
libmagick4-dev    19332  libmagick: ldconfig-symlink-before-shlib-in-deb LI#67 [217]  (scott@debian.org (Scott K. Ellis))
libpgjava         27753  libpgjava: depends on jdk1.1-runtime, which is now included in jdk1.1 [0]  (Oliver Elphick <Oliver.Elphick@lfix.co.uk>)
lists-archives    26384  lists-archives: Missing conffiles [40]  (Johnie Ingram <johnie@debian.org>)
mozilla           27181  mozilla dumps core [15]  (Debian QA group <debian-qa@lists.debian.org>)
netatalk          25598  netalk: several problems (and the solution) [64]  (Joel Klecker <jk@espy.org>)
pcmcia-modules-2  27395  pcmcia-modules are totally broken out of the box [11]  (Brian Mays <brian@debian.org>)
pcmcia-source     26657  pcmcia-source: Needs this patch to work on 2.1.118+ kernels [32]  (Brian Mays <brian@debian.org>)
pil               27495  package pil should be python-pil [8]  (Matthias Klose <doko@debian.org>)
qftp              27791  qftp depends on missing libary. [0]  (edmonds@freewwweb.com (Robert S. Edmonds))
qps               16635  qps: qps seems to be statically linked with QT and is in the wrong section [281]  (Hanno Wagner <wagner@linux.de>)
rt                23583  rt: lacking copyright [120]  (Ender <ewigin@petra>)
secure-su         26827  secure-su breaks findutils (And who knows what else) [25]  (Guy Maor <maor@debian.org>)
smb2www           27641  perl 5.005-02 breaks smb2www [0]  (Craig Small <csmall@debian.org>)
strace            26065  strace confused about sigaction flags [51]  (Wichert Akkerman <wakkerma@debian.org>)
tkstep8.0         19255  Tkstep8.0 doesn't mention dependencies on tiff, jpeg and Xpm. [218]  (Federico Di Gregorio <fog@debian.org>)
vrwave            23436  vrwave should maybe go in contrib? [124]  (Javier Fernandez-Sanguino Pen~a <jfs@computer.org>)
xephem            19441  xephem-smotif: no-copyright-file LI#177 [217]  (Frank Jordan <f.jordan@uni-duisburg.de>)
xswallow          25932  Xswallow should be in contrib [55]  (Javier Fernandez-Sanguino Pen~a <jfs@computer.org>)
yagirc            24747  yagirc: Binary and Libs for yagirc stored in /bin and /lib [87]  (davidw@efn.org (David N. Welton))

Again, please let me know if you feel differently.  If I don't hear otherwise,
I'll be removing all of those packages in the list directly above to be
removed from slink during the freeze.

Note: the above lists are made directly from the bug logs.  I haven't
actually correlated them with the list of packages that actually exist.
If a package listed above has already been removed from the distribution,
don't worry about it.

People who wish to help prepare for the release of Debian 2.1 should take
a look at the bugs and see what they can do to resolve them.  Please contact
the maintainer before actually doing anything, though, so they can
coordinate your efforts with theirs and other volunteers.

Thanks!

                                          Brian
                                 ( bcwhite@verisim.com )

-------------------------------------------------------------------------------
Seize the moment!  Live now.  Make "now" always the most important time. -- JLP


Reply to: