Debian Weekly News - June 6th, 2006

Welcome to this year's 23rd issue of DWN, the weekly newsletter for
the Debian community. Enrico Zini [1]reported that he has increased
the performance of [2]debtags by improving the [3]tagcoll library.
Krzysztof Klincewicz [4]analysed 500 most active projects on
[5]SourceForge and concluded that only little innovation happens in
these projects.

Trustability of the Web of Trust. During the recent [6]Debian
Conference Martin Krafft [7]conducted a keysigning [8]experiment to
raise questions about the Debian web of trust. This web consists of
signatures between GnuPG keys, which verify that the signer has reason
to believe that the key's owner is really the person who they claims
to be. However, the signer does not confirm the validity of a
government-issued form of identification, which is not possible given
the wide variety of identification to be found at an international
event with 140 participants.

Security Support for Woody ending. The Debian Project [9]announced
that more than one year after the release of Debian GNU/Linux 3.1
alias 'sarge' the security [10]support for the old stable distribution
3.0 will be terminated at the end of June 2006. Debian GNU/Linux 3.0
alias 'woody' has been released nearly four years ago on July 19th

Improving Debian's Publicity. Andreas Barth [11]noted that there were
somewhat suboptimal news in the press about Debian in the past. It
seems that journalists did pick up postings which were primarily
targeted at Debian developers and wrote articles about with misleading
information. Andreas wondered how to improve this situation, probably
by offering direct phone contact to our developers for the

Debian Conference 6: Hot, spicy and working hard. Robin Miller
[12]reported that this year's [13]Debconf brought close to 300 Debian
developers, package maintainers, and other interested parties to
Mexico. A lot of work was aimed at making Debian more user-friendly.
Holger Levsen and several others shot high definition video of most
DebConf6 presentations which will be available on the
[14]meetings-archive server soon.

Automatic Debian Installation with Pre-Seeding. Carla Schroder
[15]explained how to generate a quick 'n' dirty preseed configuration
file for replicating a Debian installation, and how to perform a
minimal custom installation with a USB stick. She continued to
[16]explain how to start a network installation with either a new USB
stick or an old CD-ROM, or an even more antique 3.5" diskette.

Debian IRC moves to OFTC. The Debian project [17]announced that it has
moved the irc.debian.org alias to the [18]Open and Free Technology
Community (OFTC). This move was done in recognition of many
discussions taking place there already. OFTC is also a sister
organisation of Debian, as both are supported and represented by
[19]Software in the Public Interest, Inc. The Debian project has been
using the [20]Freenode IRC network for many years.

Failed Release Architecture Qualification. Andreas Barth [21]reported
about three architectures that were released with Debian [22]sarge
which currently do not meet the requirements for inclusion in
[23]etch. Some sub-architectures of [24]m68k still require the 2.2 or
2.4 kernel which are not supported anymore. The [25]s390 port lacks a
sufficient number of developers. The [26]sparc port lacks kernel
support. Help for these ports is highly appreciated.

New Debian Menu Structure. Bill Allombert [27]proposed a new Debian
menu structure devised by Linas Zvirblis. Several sections have been
renamed and a number of sub-sections have been created to reflect the
large number of new applications. Developers should check whether
their current menu files still fit into the new structure and adjust
the section if not.

Delivering Mails for System Users? Andreas Metzler [28]wondered if it
would be safe to reject any mail for system accounts based on the user
id unless it is redirected via /etc/aliases. Wouter Verhelst
[29]explained that other distributions start with a lower uid for real
users. Stephen Samuel [30]confirmed that this would cause problems in
a hybrid environment.

Debian Light Desktop. André Luiz Rodrigues Ferreira [31]started
working on a desktop meta package for desktop machines running old
hardware. He [32]received several improvements. Joey Hess would like
to [33]add this to [34]tasksel, so that the desktop task automatically
installs it if it detects a system that is not easily capable of
running KDE/GNOME.

Reforming the New-Maintainer Process. Marc Brockschmidt [35]proposed
to stiffen the requirements for prospective maintainers by adding a
second advocate and increasing the amount of packaging they must have
already accomplished in the past. This way the applicant is more into
Debian when they apply. He also suggested to separate upload
permissions, system accounts and voting rights which would mean a
reform of the Debian project.

Security Updates. You know the drill. Please make sure that you update
your systems if you have any of these packages installed.

 * DSA 1083: [36]motor -- Arbitrary code execution.
 * DSA 1084: [37]typespeed -- Arbitrary code execution.
 * DSA 1085: [38]lynx-cur -- Several vulnerabilities.
 * DSA 1086: [39]xmcd -- Denial of service.
 * DSA 1087: [40]postgresql -- Encoding vulnerabilities.
 * DSA 1088: [41]centericq -- Arbitrary code execution.
 * DSA 1089: [42]freeradius -- Arbitrary code execution.
 * DSA 1090: [43]spamassassin -- Arbitrary command execution.

New or Noteworthy Packages. The following packages were added to the
unstable Debian archive [44]recently or contain important updates.

 * [45]aspell-ar -- Arabic dictionary for aspell.
 * [46]emile -- The Early Mac Image LoadEr.
 * [47]flasm -- Assembler and disassembler for Flash (SWF) bytecode.
 * [48]gpiv -- Graphic User Interface program for Particle Image
 * [49]gpivtools -- Command line programs for Particle Image
 * [50]gvrng -- Interactive, introductory programming language.
 * [51]ifpgui -- QT based manager for iRiver iFP audio player.
 * [52]lingot -- Accurate and easy to use musical instrument tuner.
 * [53]lsparisc -- List all PA-RISC devices currently on system.
 * [54]memories -- Web-based photo sharing application.
 * [55]pyflakes -- Simple python source checker.
 * [56]rkward -- KDE frontend to the R statistics language.
 * [57]totem-mozilla -- Totem Mozilla plugin.
 * [58]ttf-thai-tlwg -- Thai fonts in TrueType format.
 * [59]weather-util -- Command-line tool to obtain weather conditions
   and forecasts.
 * [60]weechat-scripts -- Script collection for the WeeChat IRC
 * [61]xchat-guile -- Guile scripting plugin for XChat.
 * [62]xfonts-thai-poonlap -- Poonlap Veerathanabutr bitmap fonts for

Orphaned Packages. 2 packages were orphaned this week and require a
new maintainer. This makes a total of 292 orphaned packages. Many
thanks to the previous maintainers who contributed to the Free
Software community. Please see the [63]WNPP pages for the full list,
and please add a note to the bug report and retitle it to ITA: if you
plan to take over a package. To find out which orphaned packages are
installed on your system the wnpp-alert program from devscripts may be

 * [64]dmachinemon -- Network-wide monitoring suite for monitoring
   machine status. ([65]Bug#370081)
 * [66]gamix -- Graphical sound mixer for ALSA. ([67]Bug#370080)

Removed Packages. One package has been [68]removed from the Debian
archive during the past week:

 * gngeo -- NeoGeo emulator
   [69]Bug#354571: Request of QA, license problems, undistributable

