Debian Weekly News - June 13th, 2006

Welcome to this year's 24th issue of DWN, the weekly newsletter for
the Debian community. Jeff Licquia [1]stated that the last tests he
ran would have been acceptable for passing the [2]Linux Standard Base
3.0. OSDir put up a [3]screenshot tour of the second beta release of
the [4]installer for Debian [5]etch.

Debian CGL registration. Troy Heber [6]reported that Debian GNU/Linux
3.1 has been [7]registered against OSDL's CGL 2.0.2 specification as
a Carrier Grade Linux (CGL) [8]distribution by HP. Since Debian does
not meet the [9]requirements with 100 % an analysis will show where
it falls and help correct this for future releases. Ideally this would
result in a [10]fully integrated Custom Debian Distribution.

GNOME 1 Packages in Debian. Nathanael Nerode [11]wondered what to do
with the remaining GNOME 1 packages that are in the archive. With the
new [12]GnuCash based on GTK2 entering [13]testing it is finally
possible to minimise the number of these library packages that are no
longer supported by upstream as they were only used by the old GnuCash

Graphical Reportbug. Philipp Kern [14]reported that he is in the
process of programming a graphical frontend to the [15]reportbug tool.
The goal is to give even unexperienced users the chance to report bugs
and wishes to developers. Philipp's project is part of Debian's
[16]participation of this year's [17]Summer of Code from Google.

Debian is not a SuperMarket. Joey Hess [18]coined the term supermarket
for Debian as a resource of packages when he was talking about fears
that Debian could degrade into a collection of not well integrated
software while many people use derivates that would simply use this
pool. He [19]explained that Debian is not only about packaging but
also about integrating and making it the best distribution.

Valid Shells for System Accounts? Uwe Hermann [20]wondered which
system users should get a valid shell and which shouldn't. Colin
Watson [21]explained that it's a long-term [22]goal to disable the
shell for some system users after checking on a case-by-case basis.
Javier Fernández-Sanguino Peña [23]added disabling recommendations and
provided information on using nologin as shell.

Sailing with Debian. Members of the Austrian [24]InnoC association
have [25]won the first [26]Microtransat challenge for autonomous
sailing vessels in Toulouse. Their [27]boat is a conventional model
sailing vessel enhanced with a fan-less Mini-ITX computer running
Debian GNU/Linux at 600 MHz with 1 GB flash memory and a number of

Interview with the DPL. Thomas Schönhoff published an [28]interview he
conducted with Anthony Towns, the current Debian project [29]leader,
and his deputy Steve McIntyre. The questions cover stable updates,
personal visions, relationship with derivatives, support for stable
releases and integrating Hurd, BSD and SELinux.

Changing the Optimisation for compiled Packages. Rogério Brito
[30]wondered about the feasibility of compiling some packages with the
optimisation -Os instead of -O2. Thiemo Seufer [31]explained that for
some CPUs either optimisation may be better while it isn't for the
other. Gabor Gombas [32]added that using -Os on a large scale may
discover new and interesting compiler bugs.

Changed Location for CGI Scripts. Alexis Sukrieh [33]pointed out that
[34]lintian claimed that CGI scripts should be installed in
/usr/lib/cgi-lib instead of /usr/lib/cgi-bin. Joey Hess [35]added that
this was discussed in 2003 but support for it has been dropped
afterwards. Steve Langasek [36]reported that this requirement has been
reverted in more recent policy.

Security Updates. You know the drill. Please make sure that you update
your systems if you have any of these packages installed.

 * DSA 1091: [37]tiff -- Arbitrary code execution.
 * DSA 1092: [38]mysql-dfsg-4.1 -- SQL injection.
 * DSA 1093: [39]xine-lib -- Denial of service.
 * DSA 1094: [40]gforge -- Cross-site scripting.
 * DSA 1095: [41]freetype -- Several vulnerabilities.
 * DSA 1096: [42]webcalendar -- Arbitrary code execution.

New or Noteworthy Packages. The following packages were added to the
unstable Debian archive [43]recently or contain important updates.

 * [44]balazar -- 3D adventure and role-playing game.
 * [45]cdck -- Verifies the quality of written CDs/DVDs.
 * [46]crasm -- Cross assembler for 6800/6801/6803/6502/65C02/Z80.
 * [47]debdelta -- Diff and patch utilities which works with Debian
 * [48]easypg -- Yet another GnuPG interface for Emacs.
 * [49]filler -- Simple game where two players try to capture half
   the board.
 * [50]fusesmb -- Filesystem client based on the SMB file transfer
 * [51]gopchop -- Fast, lossless cuts-only editor for MPEG2 video
 * [52]kiax -- IAX VoIP softphone.
 * [53]monsterz -- Arcade puzzle game.
 * [54]mrb -- Manage incremental data snapshots with make/rsync.
 * [55]nethogs -- Net top tool grouping bandwidth per process.
 * [56]pekwm -- Fast & Light WindowManager.
 * [57]qgit -- Qt application for viewing GIT trees.
 * [58]sgf2dg -- Creates TeX files from Go game records.
 * [59]simba -- Next generation mirroring tool.
 * [60]supertuxkart -- Kart racing game.
 * [61]websimba -- Web interface for simba.
 * [62]zabbix-agent -- Software for monitoring of your networks --

Orphaned Packages. 1 package was orphaned this week and requires a new
maintainer. This makes a total of 291 orphaned packages. Many thanks
to the previous maintainers who contributed to the Free Software
community. Please see the [63]WNPP pages for the full list, and please
add a note to the bug report and retitle it to ITA: if you plan to
take over a package. To find out which orphaned packages are installed
on your system the wnpp-alert program from devscripts may be helpful.

 * [64]vtun -- Virtual Tunnel over TCP/IP Networks. ([65]Bug#373134)

Removed Packages. 1 package has been [66]removed from the Debian
archive during the past week:

 * prebaseconfig -- Finish the installation and reboot (udeb)
   [67]Bug#370209: Request of maintainer, superseded by

This issue of Debian Weekly News was edited by Mohammed Adnène
Trojette, Sebastian Feltel and Martin 'Joey' Schulze.

