Debian Project News - October 8th, 2008
---------------------------------------------------------------------------
Debian Project News
http://www.debian.org/News/project/2008/12/
Debian Project News - October 8th, 2008
---------------------------------------------------------------------------
Welcome to this year's 12th issue of DPN, the newsletter for the Debian
community.
Some of the topics covered in this issue include:
* Bits from the DPL
* What you can do for Lenny
* 500,000th bug reported
* ... and much more.
Bits from the DPL
Steve McIntyre sent out another [1]"Bits from the DPL" mail. His first
topic was the recently finished eighth Debian Conference in Argentina.
Even though many developers and contributors could not travel there he
considered it to be a successful conference. He especially thanked the
video team, who "did an [2]amazing job this year making most of the
sessions available via stream as well as forwarding questions via
Internet Relay Chat." Steve is already looking forward to next year's
Debian Conference, which will take place in the Junta Extremadura in
Spain.
1: http://lists.debian.org/debian-devel-announce/2008/09/msg00009.html
2: http://wiki.debconf.org/wiki/DebConf8/Videoteam/Thanks
He then summarized the results of this year's [3]Google Summer of
Code, a project in which students work on specific free software
projects and get paid by Google. Debian got thirteen project slots.
Eleven of these projects were completed successfully (sadly, the rest
had to drop out due to unforeseen problems).
3: http://wiki.debian.org/SummerOfCode2008
Steve closed with a short summary about the upcoming stable release
"Lenny". Preparations for a release candidate of the debian-installer
are on their way and the release notes are taking shape. But there are
still a lot of release critical bugs left to be fixed.
What you can do for "Lenny"
Unfortunatly, Debian GNU/Linux 5.0 "Lenny" hasn't been released yet.
Alexander Reichle-Schmehl [4]briefly explained the problems and listed
some open issues which need to resolved before Lenny can be released.
He points out that even a "simple user" (meaning "everyone") can help.
4: http://lists.debian.org/debian-devel-announce/2008/10/msg00000.html
While most release blockers and release goals have been dealt with --
including transitions to newer compilers, libraries and other tools --
the development has reached its final phase, where the last release
critical bugs need to be fixed, upgrade tests need to be performed and
the release notes need to be written. Alexander gave a brief overview
on how to perform upgrade tests, which he later [5]updated in his
blog, also showed other ways to help such as writing and translating
the release notes.
5: http://blog.schmehl.info/Debian/releasing-lenny
He then [6]categorized the remaining bugs, while Lucas Nussbaum
created a detailed list of the [7]bugs still remaining.
6: http://blog.schmehl.info/Debian/releasing-lenny-2
7: http://lists.debian.org/debian-devel/2008/10/msg00072.html
In related news, Franklin Piat [8]had created a [9]list of things
users could do in the long term to help test Debian.
8: http://lists.debian.org/debian-devel/2008/10/msg00043.html
9: http://wiki.debian.org/TestDebian
500,000th bug reported
Christian Perrier [10]noted that the 500,000th [11]bug has been
reported to Debian's bug tracking sytem. In it, Nobuhiro Iwamatsu
requested a feature for the common debian build system, a tool used to
create Debian packages, and even provided a patch.
10: http://www.perrier.eu.org/weblog/2008/09/24#bug-500000-now
11: http://bugs.debian.org/500000
Lucas Nussbaum [12]graciously provided some statistics. From these
500,000 bugs, nearly 410,000 have already been solved.
12: ttp://www.lucas-nussbaum.net/blog/?p=312
Christian also noted that the vitality of the Debian Bug Tracking
system is an indicator of the vitality of development in Debian (the
current bug report rate is about 60,000 bugs per year for a total of
24,000 packages in the distribution, only 2.5 bugs per year, per
package).
Thus, Debian developers are proud that they have had 500,000 occasions
to interact with their users. Of course, they are also proud that
410,000 of thesve already closed 410,000 of these bugs and and only 250
of the remaining bugs are release critical for the upcoming Debian
lenny release.
Valid-Until field in Release files
While the current archive structure prevents injection of malicious
packages through a digital trust path (e.g. at a "bad mirror"), it
still has a small flaw. A potential attacker could use outdated release
information to force people to use an outdated mirror, leaving out the
latest security updates. To address this problem, Jörg Jaspert [13]has
added a "valid until" field to the release information. APT (or another
package manager) can then check if the data available on the mirror is
up to date. Work has already begun to integrate this feature into the
apt package manager and tools based upon it; however, [14]some
questions remain unresolved.
13: http://blog.ganneff.de/blog/2008/09/23/valid-until-field-in-release-f.html
14: http://bugs.debian.org/499897
Choosing a language during NAS installations
Martin Michlmayr [15]reported that due to changes of the internal
structure of the debian-installer, it is now it is now possible to
choose the language (and the resulting system) for installations on NAS
machines. Installations on headless NAS devices are typically done
remotely via SSH and up until now, the network had been started after
the language had already been chosen, thus the ability to choose a
language interactively was completely disabled for such devices. Due to
changes in the component responsible for choosing the locale, this
feature can now be enabled for these kinds of devices.
15: http://www.cyrius.com/journal/debian/nas-localechooser
m68k moved to debian-ports
After missing release criteria for both Etch and Lenny, the m68k port
made the switch from using the wanna-build instance on Debian
infrastructure to the one on [16]Debian-Ports. This is a necessary step
before m68k can be removed from the Debian archive. [17]Buildd.Net
still supports the m68k architecture and has already adopted the
change. The m68k port was one of two official ports in the first Debian
release, Debian 2.0 (the other being i386).
16: http://www.debian-ports.org/
17: http://unstable.buildd.net/index-m68k.html
Other news
Christian Perrier [18]released the final number of languages which will
be supported in the debian-installer of the upcoming release.
All-in-all 63 languages will be supported, which is 5 more than in the
current release.
18: http://www.perrier.eu.org/weblog/2008/09/21#di-freeze-lenny-final
A long term goal, the move from documentation in /usr/doc to
/usr/share/doc as recommended in the Filesystem hierarchy standard, has
finally been [19]completed.
19: http://bugs.debian.org/322762#1225
Christian Perrier [20]also noted that the team working on apt, the core
package manager of Debian and Debian-based distributions, is lacking
manpower and in need of help.
20: http://www.perrier.eu.org/weblog/2008/09/30#apt-maintenance
Linux Kongress 2008
From Thursday the 9th of October to Friday the 10th of October, the
Debian Project will participate with a booth at the Linux-Kongress 2008
in Hamburg, Germany. Please see the respective [21]events page for
further details.
21: http://www.debian.org/events/2008/1009-linuxkongress
Technical Dutch Open Source Event 2008
From Saturday the 25th of October to Sunday the 26th of October, the
Debian Project will participate with a booth at the Technical Dutch
Open Source Event (T-DOSE) in Eindhoven, Netherlands. Please see the
respective [22]events page for further details.
22: http://www.debian.org/events/2008/1025-t-dose
New Developers
6 applicants [23]have been [24]accepted as Debian Developers since the
prior issue of the Debian Project News. Please welcome Tobias Grimm,
Chris Lamb, Manuel Prinz, Patrick Schoenfeld, Sandro Tosi, Jan Wagner
and Barry deFreese in our project!
23: http://lists.debian.org/debian-newmaint/2008/09/msg00059.html
24: http://lists.debian.org/debian-newmaint/2008/09/msg00029.html
Important Debian Security Advisories
Debian's Security Team recently released advisories for these packages
(among others): [25]openssh, [26]twiki, [27]phpmyadmin, [28]horde3,
[29]mplayer, [30]lighttpd, [31]squid and [32]php5. Please read them
carefully and take the proper measures.
25: http://www.debian.org/security/2008/dsa-1638
26: http://www.debian.org/security/2008/dsa-1639
27: http://www.debian.org/security/2008/dsa-1641
28: http://www.debian.org/security/2008/dsa-1642
29: http://www.debian.org/security/2008/dsa-1644
30: http://www.debian.org/security/2008/dsa-1645
31: http://www.debian.org/security/2008/dsa-1646
32: http://www.debian.org/security/2008/dsa-1647
Please note that these are a selection of the more important security
advisories of the last two weeks. If you need to be kept up to date
about security advisories released by the Debian Security Team, please
subscribe to the [33]security mailing list for announcements.
33: http://lists.debian.org/debian-security-announce/
New and noteworthy packages
The following packages were added to the unstable Debian archive
recently ([34]among others):
* [35]9mount-dbg -- plan9 filesystem (v9fs) user mount utilities
(debug)
* [36]acpitool-dbg -- command line ACPI client (debug)
* [37]amule-emc -- list ed2k links inside emulecollection files
* [38]dosfstools-dbg -- utilities for making and checking MS-DOS FAT
filesystems (debug)
* [39]gameclock -- a simple chess clock to track time in real life
games
* [40]gnupg-pkcs11-scd-dbg -- GnuPG smart-card daemon with PKCS#11
support (debug)
* [41]jags -- Just Another Gibbs Sampler for Bayesian MCMC simulation
* [42]libfwbuilder8 -- Firewall Builder API library
* [43]libfwbuilder8-dbg -- Firewall Builder API library (debugging
version)
* [44]libgammu4 -- Mobile phone management library
* [45]libgammu4-dbg -- Mobile phone management library - debugger
symbols
* [46]netdiscover-dbg -- active/passive network address scanner using
arp requests (debug)
* [47]poedit-dbg -- gettext catalog editor (debug)
* [48]python-crack -- transitional package from python-crack to
python-cracklib
* [49]python-django-registration -- A user-registration application
for Django
* [50]qt4-qmake -- Qt 4 qmake Makefile generator tool
* [51]rawstudio-dbg -- open source raw-image converter (debug)
* [52]ttf-linux-libertine -- The Linux Libertine family of free fonts
* [53]twiki-ldapcontrib -- LDAP services for TWiki
* [54]tworld-data -- Chip's Challenge Game Engine Emulation
34: http://packages.debian.org/unstable/main/newpkg
35: http://packages.debian.org/unstable/main/9mount-dbg
36: http://packages.debian.org/unstable/main/acpitool-dbg
37: http://packages.debian.org/unstable/main/amule-emc
38: http://packages.debian.org/unstable/main/dosfstools-dbg
39: http://packages.debian.org/unstable/main/gameclock
40: http://packages.debian.org/unstable/main/gnupg-pkcs11-scd-dbg
41: http://packages.debian.org/unstable/main/jags
42: http://packages.debian.org/unstable/main/libfwbuilder8
43: http://packages.debian.org/unstable/main/libfwbuilder8-dbg
44: http://packages.debian.org/unstable/main/libgammu4
45: http://packages.debian.org/unstable/main/libgammu4-dbg
46: http://packages.debian.org/unstable/main/netdiscover-dbg
47: http://packages.debian.org/unstable/main/poedit-dbg
48: http://packages.debian.org/unstable/main/python-crack
49: http://packages.debian.org/unstable/main/python-django-registration
50: http://packages.debian.org/unstable/main/qt4-qmake
51: http://packages.debian.org/unstable/main/rawstudio-dbg
52: http://packages.debian.org/unstable/main/ttf-linux-libertine
53: http://packages.debian.org/unstable/main/twiki-ldapcontrib
54: http://packages.debian.org/unstable/main/tworld-data
[55]ddclient (an utility to get access to home servers despite having a
dynamic IP), [56]FlameRobin (a GUI to Administer Firebird/Interbase SQL
servers) and [57]logstalgia (a pong-like apache log viewer) where
presented by Debian Package of the Day.
55: http://debaday.debian.net/2008/09/28/ddclient-getting-access-to-home-servers-despite-having-a-dynamic-ip/
56: http://debaday.debian.net/2008/09/21/flamerobin-a-gui-to-administer-firebirdinterbase-sql-servers/
57: http://debaday.debian.net/2008/10/05/logstalgia-pong-like-apache-log-viewer/
Work-needing packages
Currently 444 packages are orphaned and 125 packages are up for
adoption. Please take a look at [58]the [59]recent [60]reports to see
if there are packages you are interested in or view the complete list
of [61]packages which need your help.
58: http://lists.debian.org/debian-devel/2008/09/msg00574.html
59: http://lists.debian.org/debian-devel/2008/09/msg00714.html
60: http://lists.debian.org/debian-devel/2008/10/msg00020.html
61: http://www.debian.org/devel/wnpp/help_requested
Want to continue reading DPN?
Please help us create this newsletter. We still need more volunteer
writers to watch the Debian community and report about what is going
on. Please see the [62]contributing page to find out how to help. We're
looking forward to receiving your mail at
[63]debian-publicity@lists.debian.org.
62: http://wiki.debian.org/ProjectNews/HowToContribute
63: mailto:debian-publicity@lists.debian.org
This issue of Debian Project News was edited by Ari Pollak, Ingo
Juergensmann, Christian Perrier and Alexander Reichle-Schmehl.
Reply to: