Debian Weekly News - January 6th, 2004

Debian Weekly News - January 6th, 2004

Welcome to this year's first issue of DWN, the weekly newsletter for
the Debian community. Debian Weekly News enters its fifth year, since
on January 4th 1999, Joey Hess released the first issue. Richard
Stallman [1]wrote that he quit MIT 20 years ago to create a free
operating system, a variation of which is used by thousands of people
today. Merry Christmas to those celebrating the Orthodox Christmas on
the 7th of January.

 1. http://www.newsforge.com/article.pl?sid=04/01/05/1146229

Coordination in Free Software Projects. Giampaolo Garzarelli and
Roberto Galoppini wrote a [2]paper about the coordination in modular
organizations and used the Debian project as example. The paper
asserts that the production process is hierarchical notwithstanding
the modular (nearly decomposable) architecture of software.

 2. http://opensource.mit.edu/papers/garzarelligaloppini.pdf

History of the Social Contract. Raul Miller [3]explained that
historically the [4]Debian Free Software Guidelines were about
distributing software and not writing software because, originally,
Debian was not supposed to be about writing software, but about
pulling together a coherent distribution based on what's already out

 3. http://lists.debian.org/debian-vote-0401/msg00002.html
 4. http://www.debian.org/social_contract#guidelines

Using Kernel Header Files. Ben Armstrong [5]noticed that source code
doesn't compile well on non-i386 architectures due to the use of
kernel include files. Ben Collins [6]advised that kernel headers are
not meant for userspace programs. John Hasler [7]suggested to include
only the required definitions from the kernel header file into the

 5. http://lists.debian.org/debian-devel-0312/msg02272.html
 6. http://lists.debian.org/debian-devel-0312/msg02273.html
 7. http://lists.debian.org/debian-devel-0312/msg02282.html

Planet Debian. Scott James Remnant [8]announced [9]Planet Debian
which is a collection of recent blog entries by Debian developers and
affiliated people. It reads RSS feeds of about 30 people and works
similar to [10]Planet GNOME.

 8. http://lists.debian.org/debian-devel-announce-0401/msg00001.html
 9. http://people.debian.org/~keybuk/planetdebian/
 10. http://planet.gnome.org/

Another non-free Proposal. Anthony DeRobertis [11]formulated another
proposal to remove non-free software from Debian archives with the
sarge release. This time a rationale is prepended and helps
understanding the issue.

 11. http://lists.debian.org/debian-vote-0401/msg00062.html

Debian R Policy. Dirk Eddelbüttel [12]released a draft for a suggested
policy for R packages within Debian. In the six years that Debian
members are maintaining R for Debian, the total number of R related
packages has grown to a full thirty. This draft is a timely concern
since R-based archives such as [13]CRAN and [14]BioConductor are
experiencing enormous growth in the number of their packages. More and
more of these may eventually be turned into Debian packages.

 12. http://lists.debian.org/debian-devel-0312/msg02332.html
 13. http://cran.r-project.org/
 14. http://www.bioconductor.org/

License Adjustment Letter. Roland Stigge [15]reported about the
willingness of the current maintainer and the former author of
latex2html to alter its license. This is a requirement before the
package can go back into main. However, this may need an agreement
from [16]Leeds University which is attached to the mail. Roland seeks

 15. http://lists.debian.org/debian-legal-0401/msg00016.html
 16. http://www.leeds.ac.uk/

APT-Howto Redesign. Gustavo Noronha Silva [17]thought about rewriting
the [18]APT Howto for sarge. The main focus should be what new sarge
users want to know, not necessarily unstable users. He also want to
emphasise the use of aptitude instead of plain apt-get.

 17. http://lists.debian.org/debian-doc-0312/msg00024.html
 18. http://www.debian.org/doc/manuals/apt-howto/

Debian-Installer Beta 2. Joey Hess [19]announced that debian-installer
in the Debian archive has been branched for beta 2 for the i386
architecture. The udebs and installation images have been copied to
testing and changes necessary to get ports working for beta 2 can be
propagated into testing as well. At this stage, the MIPS port is
tentatively scheduled for January 17th release, and the IA-64 port for
January 12th. The PowerPC port appears close to done, but no date has
been set yet.

 19. http://lists.debian.org/debian-boot-0401/msg00269.html

XFS Support in Debian-Installer. Steve Langasek [20]announced that
after several iterations, XFS-enabled debian-installer netinst
[21]images are now available for download. Testing of this
(unsanctioned, unofficial) image is welcome, including testing by
anyone not specifically interested in using XFS. The default image on
the disk (typing linux at the boot prompt instead of xfs) should in
all ways behave like the regular daily images.

 20. http://lists.debian.org/debian-boot-0401/msg00218.html
 21. http://people.debian.org/~vorlon/d-i/xfs/sarge-i386-xfs-netinst.iso

Debian-based Distributions Compared. Barry Smith [22]posted his fifth
and final article reviewing Debian-based commercial distributions in a
Small Office / Home Office (SOHO) environment. The article reviews
Xandros 2.0 Deluxe, and compares it to the distributions previously
reviewed: [23]Lindows 4.0, [24]Lindows 4.5, [25]Libranet, and

 22. http://www.osnews.com/story.php?news_id=5564
 23. http://www.osnews.com/story.php?news_id=5238
 24. http://www.osnews.com/story.php?news_id=5495
 25. http://www.osnews.com/story.php?news_id=5274
 26. http://www.osnews.com/story.php?news_id=5348

Partial GNOME Freeze. Jordi Mallach [27]asked Debian GNOME maintainers
to freeze all packages that are associated with meta-gnome2 packages.
He listed 13 packages that bear one or more problems. Each of them is
a reason to keep meta-gnome2 out of the testing distribution, which is
required for proper GNOME in sarge.

 27. http://lists.debian.org/debian-gtk-gnome-0401/msg00017.html

Security Updates. You know the drill. Please make sure that you update
your systems if you have any of these packages installed.

 * [28]lftp -- Arbitrary code execution.
 * [29]ethereal -- Several vulnerabilities.
 * [30]screen -- Group utmp exploit.
 * [31]bind -- Denial of service.
 * [32]libnids -- Buffer overflow.
 * [33]mpg321 -- Format string vulnerability.
 * [34]nd -- Buffer overflows.
 * [35]Linux 2.4.18 -- Local root exploit.

 28. http://www.debian.org/security/2004/dsa-406
 29. http://www.debian.org/security/2004/dsa-407
 30. http://www.debian.org/security/2004/dsa-408
 31. http://www.debian.org/security/2004/dsa-409
 32. http://www.debian.org/security/2004/dsa-410
 33. http://www.debian.org/security/2004/dsa-411
 34. http://www.debian.org/security/2004/dsa-412
 35. http://www.debian.org/security/2004/dsa-413

Reply to: