Debian Weekly News - April 6th, 2004

Debian Weekly News - April 6th, 2004

Welcome to this year's 14th issue of DWN, the weekly newsletter for
the Debian community. Manoj Srivastava sent out the [1]final call for
votes on the project leader [2]election and revealed that 351 of the
908 developers have already voted. Andreas Schuldei is still
[3]looking for ideas for talks for the upcoming [4]Debian

Support for Hotplug in Debian. Joey Hess [5]noticed that support for
hotplugged devices is an area where Debian could lead and excel in
integration, but the [6]libgphoto2-2 package states that the provided
scripts are not meant to be used by default. He complained that there
seems to be little desire to work on these scripts and instead wait
for other distributions to do fairly useful things by default when USB
devices are plugged in.

Snapshot Archive is now searchable for Packages. Fumitoshi Ukai
[7]announced that he has implemented a new function on
[8]snapshot.debian.net to search for packages. This is sure to help
many people in searching for old versions of a particular package from
the huge archive. He has also created a shortcut URL of the form
http://snapshot.debian.net/package/<packagename>. Domenico Andreoli
and Branden Robinson thanked him for this great job as well as Martin
Schulze who suggested he implement such this feature.

Debian Host Naming Scheme. After Lars Wirzenius [9]wondered if no-one
else cares about choosing names for computers with care, comments and
revelations by [10]Wouter Verhelst, [11]Joshua Kwan, [12]Scott James
Remnant, [13]Tollef Fog Heen and [14]Jesus Climent, a Debian admin
[15]explained the [16]naming scheme used for debian.org hosts. Most of
them are named after ancient baroque or classical composers, with a
number of exceptions.

RPM orphaned and not free anymore? Joey Hess [17]orphaned [18]rpm
since the newest version depends on the non-free elfutils library.
This makes it impossible for Joey to update the package. Not being
able to include rpm in Debian could have far reaching consequences -
from problems with the LSB to increased difficulty to run other
distributions software on Debian and vice-versa.

Debian Security Advisories CVE-compatible. The Debian project
[19]announced that [20]Debian Security Advisories have been declared
[21]CVE-compatible at the RSA Conference 2004, in San Francisco,
February 24th, 2004. The project also believes that it is extremely
important to provide users with additional information related to
security issues that affect the Debian distribution.

Custom Debian Distributions. Andreas Tille [22]announced a [23]paper
he wrote about [24]custom Debian distributions, the techniques used
and the goals behind them. This is an implicit call for participation
for all those people inside and outside the Debian project. Custom
Debian distributions try to provide a solution for special groups of
target users with different skills and interests.

Getting newer Kernels in stable. Andrew Pollock [25]wanted to know if
it would be possible to get newer kernel packages in stable Debian
releases, since he is concerned about Debian installation issues. The
stable release manager [26]explained that new versions are not
possible since too much can break. Instead he encouraged people to
maintain additional repositories with updated kernel packages.

April Fools Pranks. The community released a couple of April fools
pranks, of which we're listing some. Pascal Hakim sent in a
[27]document covering improvements for Debian releases. Pablo
Lorenzzoni became [28]illuminated and wanted to switch to a
proprietary operating system. The Internet Society determined the
[29]requirements for the Omniscience Protocol (RFC 3751). Symlink
[30]reported (German only) about a guy who wanted to file a
class-action law against the Free Software Foundation. Finally, the
[31]defacement of their own website by the grsecurity devlopers was a
bit awkward and scared quite some people.

Additional Links to Translations. Nobuhiro Imai [32]wondered if he was
permitted to add additional links to translations of Debian web pages.
In these cases the original page links to an external resource and its
Japanese translation is located somewhere else. Gerfried Fuchs
[33]explained that this would be appreciated and helpful, and he
already have added such links to German translations. He also noted
that one should not have to change anything if the other website has
enabled [34]content negotiation as well.

Proposed l10n Framework. Jure Cuhalev [35]proposed a new scheme for
Debian localisation work (l10n), where all translation teams would use
an Alioth project that would serve as a common gateway. The advantage
of such a system is that it is less work for maintainers and
translators to update their translations, as it is now for the
[36]debian-installer already. However, Denis Barbier [37]explained
that this should be handled with care, since packages have to be
synchronised and the maintainer could have used different

Bugtracking System moved. The bug tracking system was moved from
master to spohr but master kept a regularly updated copy. This has
been moved to merkel, due to disk space issues on master. Colin Watson
[38]asked other developers to move their related scripts to merkel.
The mirror is updated every fifteen minutes.

Zope Maintenance in Debian. There has been a [39]discussion about
removing Zope from testing. Jonas Meurer instead [40]encouraged other
developers to start forming a maintenance group since it may require
more maintainer activity than most other packages. David Coe [41]added
that the current maintainers were always willing to accept good
patches and non-maintainer uploads.

Indirect Donation from Redmond. A particular advertisement in the
current issue of the German [42]Linux Magazin magazine, created and
paid by a Redmond-based company, did not only cause a [43]discussion
(German only) on whether a GNU/Linux oriented magazine should accept
such an advertisement but also a large [44]donation to the Debian

Probing for Operating Systems. Joey Hess [45]reported that he was
working together with Joshua Kwan to work on probing for other
operating systems. This will be used by the [46]debian-installer to
create the boot configuration which should be able to boot other
operating systems as well.

Security Updates. You know the drill. Please make sure that you update
your systems if you have any of these packages installed.

 * [47]Linux 2.4.17 (hppa) -- Local root exploits.
 * [48]interchange -- Information leak.
 * [49]fte -- Buffer overflows.
 * [50]oftpd -- Denial of service.
 * [51]squid -- ACL bypass.
 * [52]Linux 2.4.18 (hppa) -- Local root exploits.
 * [53]heimdal -- Cross-realm vulnerability.
 * [54]xine-ui -- Insecure temporary file creation.

New or Noteworthy Packages. The following packages were added to the
unstable Debian archive [55]recently or contain important updates.

 * [56]bjam -- Software build tool.
 * [57]bnfc -- Compiler front-end generator based on Labelled BNF.
 * [58]brutefir -- Software convolution engine.
 * [59]cecilia -- Graphic user interface for CSound.
 * [60]charmap -- Character map for GNUstep.
 * [61]cups-pdf -- PDF Writer backend for CUPS.
 * [62]cvs2svn -- Convert a CVS repository to a subversion
 * [63]debian-installer-manual -- Debian installation manual.
 * [64]horgand -- JACK capable organ synthesizer.
 * [65]imapproxy -- IMAP protocol proxy.
 * [66]kazehakase -- Gecko based web browser using GTK.
 * [67]kurush -- Easy to use personal finance manager.
 * [68]mpeg3-utils -- MPEG streams decoding library.
 * [69]pal -- Command-line calendar program that can keep track of
 * [70]po4a -- Tools for helping translation of documentation.
 * [71]poe -- Vorbis comment editor.
 * [72]postgresql-plruby -- Ruby procedural language for PostgreSQL.
 * [73]rdeliver -- Fully functioning mail filter with RubyFilter.
 * [74]sipsak -- SIP Swiss army knife.
 * [75]specimen -- MIDI controllable audio sampler for GNU/Linux
 * [76]stepbill -- Get rid of those nasty Wingdows viruses.
 * [77]supybot -- Robust and user friendly Python IRC bot.
 * [78]uim -- Simple, secure, and flexible input method collection
   and library.
 * [79]websieve -- Web based Cyrus IMAP user admin client.

