[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Debian Weekly News - February 18th, 2003



---------------------------------------------------------------------------
Debian Weekly News
http://www.debian.org/News/weekly/2003/07/
Debian Weekly News - February 18th, 2003
---------------------------------------------------------------------------

Welcome to this year's seventh issue of DWN, the weekly newsletter for
the Debian community. In addition to the [1]FLOSS report sponsored by
the European Commission, researchers at Stanford University's
Institute for Economic Policy Research designed another [2]survey and
asked the community for its assistance. If you have ever wondered
whether (GNU/)Linux was the only new and [3]free operating system
recently begun, take a look at [4]ReactOS, which aims to implement a
free version of NT.

 1. http://www.infonomics.nl/FLOSS/report/
 2. http://www.stanford.edu/group/floss-us/
 3. http://www.gnu.org/copyleft/gpl.html
 4. http://www.reactos.com/

Debian Project Leader Elections. Manoj Srivastava [5]announced the
final day of the nomination period. The candidate [6]platforms shall
be published on February 15th and rebuttals shall be published on
February 21th. David B. Harris and Adam Heath have volunteered to
conduct the DPL debate on IRC, probably towards the end of the month.
So far, Moshe Zadka, Bdale Garbee, Martin Michlmayr and Branden
Robinson chose to [7]run.

 5. http://lists.debian.org/debian-vote-0302/msg00037.html
 6. http://www.debian.org/vote/2003/vote_0001
 7. http://lists.debian.org/debian-vote-0302/msg00051.html

Debian Keyring Analysis. Lars Wirzenius [8]analyzed the Debian
keyrings (GnuPG and PGP). This reveals that 769 keys are in a so
called strongly connected set, in which all keys are able to reach all
others (via bidirectional signatures). Unfortunately, his [9]research
also discloses that 487 are not part of a strong connected set. Peter
Palfrader mentioned the [10]trust analysis he is running on the Debian
Keyring.

 8. http://lists.debian.org/debian-project-0302/msg00001.html
 9. http://liw.iki.fi/liw/temp/keyring/
 10. http://people.debian.org/~weasel/weboftrust/

Timeserver Round Robin Project. Adrian von Bidder [11]asked people who
run a computer with a static IP address to run ntpd and offer it for
public use on the [12]time.fortytwo.ch DNS round robin. The reason for
this request is that some public time servers (as listed somewhere on
ntp.org) are having problems with too much traffic. Later he
[13]reported that he has received several positive answers, but none
from the admins of project machines which already run an NTP server.

 11. http://lists.debian.org/debian-project-0301/msg00048.html
 12. http://fortytwo.ch/time/
 13. http://lists.debian.org/debian-project-0302/msg00018.html

Why several Versions of BerkeleyDB? Will Lowe [14]wondered why Debian
distributes 4 versions of BerkeleyDB. This will result in integrity
problems when two different versions are indirectly linked into the
same process (e.g. through the chain Apache, mod_perl and
libberkeley-db-perl). Matthew Wilcox [15]explained that there are
binary file incompatibilities involved and that no tool to downgrade a
database is provided.

 14. http://lists.debian.org/debian-devel-0302/msg00736.html
 15. http://lists.debian.org/debian-devel-0302/msg00738.html

Removing mICQ from Debian? Martin Loschwitz [16]proposed to remove
[17]mICQ from Debian entirely since the upstream author has placed a
harmful and [18]obfuscated easter egg in the code, bypassing the
maintainer's testing. Anthony Towns [19]asked all maintainers to
review upstream changes before packaging code, Branden Robinson
already [20]reads every line of diff that gets applied to his XFree86
packages. Rüdiger Kuhlmann later [21]reported that the problems were
resolved and that the easter egg was replaced. Martin Loschwitz also
sent an [22]update.

 16. http://lists.debian.org/debian-devel-0302/msg00771.html
 17. http://packages.debian.org/micq
 18. http://lists.debian.org/debian-devel-0302/msg00774.html
 19. http://lists.debian.org/debian-devel-0302/msg00802.html
 20. http://lists.debian.org/debian-devel-0302/msg00850.html
 21. http://lists.debian.org/debian-devel-0302/msg01119.html
 22. http://lists.debian.org/debian-devel-0302/msg01125.html

Retitling ITPs Round Two. Bas Zoetekouw [23]announced the second round
of retitling Intent To Package (ITP) bug reports into Request For
Packaging (RFP). Earlier he [24]tried to contact the submitters but
for 143 packages his call was left unanswered. Luca De Vitis
[25]wondered if it wouldn't be more useful to close these bug reports
right away, since nobody has packaged the corresponding packages in
more than a year. It could mean that there is no one interested in
that package anymore.

 23. http://lists.debian.org/debian-qa-0302/msg00011.html
 24. http://lists.debian.org/debian-qa-0212/msg00064.html
 25. http://lists.debian.org/debian-qa-0302/msg00014.html

Best Practice Bug Closing through Changelogs. Joey Hess [26]reminded
developers that Changelog lines should only describe changes to the
content of the package. Developers should not use lines such as "*
This is not a bug - closes: #XXX" to close bugs. In these situations,
the bug should be closed by mailing a description to
XXX-done@bugs.debian.org. This issue has come up [27]before, but the
[28]Developer's Reference Manual now makes the proper procedure clear.

 26. http://lists.debian.org/debian-devel/2003/debian-devel-200302/msg00788.html
 27. http://lists.debian.org/debian-devel-0302/msg00039.html
 28. http://www.debian.org/doc/manuals/developers-reference/ch-pkgs.en.html#s-bug-handling

Debian featured in Case-Study. Colm MacCárthaigh and Colin Whittaker
presented a Debian-centric [29]paper on best practice for operating
system management at [30]SAGE-IE, the Irish Branch of the System
Administrators Guild. The paper highlights Debian's strong policy and
consistency, security and reliability, and illustrates how Debian is
an excellent choice for high-availability, low maintenance
applications.

 29. http://www.sage-ie.org/slides/case_study/
 30. http://www.sage-ie.org/

Results from the Security Survey. [31]Results were published from the
security [32]survey last year. The highlight (or rather worst
incident) is one person who maintains about 4000 potato machines that
he cannot easily upgrade. In general it seems that many Debian
administrators would rather like to stay with the old stable release
before upgrading to the new one -- for about one year after a new
stable version has been released. The security team will therefore try
to support potato until end of June 2003.

 31. http://lists.debian.org/debian-devel-announce-0302/msg00010.html
 32. http://lists.debian.org/debian-devel-announce-0211/msg00001.html

Debian project at Desktop Linux Summit. The Debian project
[33]announced its participation at the upcoming [34]Desktop Linux
Summit in San Diego next week. Regardless of [35]recent [36]withdraws
of companies and organisations from the Desktop Linux Summit, the
Debian project will maintain a booth in the exhibition area. Bdale
Garbee will also participate in a panel discussion about the future of
GNU/Linux on the Desktop.

 33. http://www.debian.org/News/2003/20030215
 34. http://www.debian.org/events/2003/0220-desktopsummit
 35. http://lwn.net/Articles/20312/
 36. http://lwn.net/Articles/20352/

Work on OpenLDAP 2.1. Alexey Chetroi wanted to [37]know if time is
being spent on packaging OpenLDAP 2.1 since the current version 2.0
has some problems with support for TLS connections. Roland
Bauerschmidt [38]revealed that a group of maintainers is working on
it, but the packages need more testing before they can upload
packages.

 37. http://lists.debian.org/debian-devel-0302/msg00919.html
 38. http://lists.debian.org/debian-devel-0302/msg00924.html

Maintaining Multilingual Documentation. Craig Sanders [39]noted that
an increasing number of large language-specific packages is entering
the Debian archives. He suggested that those packages would be
collected in a language-specific subdirectory of the /doc/ directory.
However, since he would like this to happen beneath the pool directory
instead of the (virtual) package section, it's rather unlikely to
happen.

 39. http://lists.debian.org/debian-devel-0302/msg01025.html

License or Copyright? Antoine Mathys [40]wondered what the real
difference between a license and a copyright is. Sean Perry
[41]clarified that the license is the document which states the
permissions granted or withheld. Branden Robinson further [42]stated
that a copyright is a legal concept that grants (negotiable) monopoly
privileges to authors to duplicate, modify, and distribute physical
forms of the "work".

 40. http://lists.debian.org/debian-legal-0302/msg00025.html
 41. http://lists.debian.org/debian-legal-0302/msg00029.html
 42. http://lists.debian.org/debian-legal-0302/msg00037.html

Debian Zaurus Update. Matt Zimmerman released an [43]update report
about Debian on handhelds in general and the Zaurus in particular. He
added a brief record of where we've been and where we stand on current
development. [44]Opie packages for example are coming along
wonderfully, and are progressing into Debian unstable. Phil Blundell
has further packaged some parts of [45]GPE for Debian, an X11- and
GTK-based desktop project.

 43. http://lists.debian.org/debian-handheld-0302/msg00044.html
 44. http://opie.handhelds.org/
 45. http://gpe.handhelds.org/

Security Updates. You know the drill. Please make sure that you update
your systems if you have any of these packages installed.

 * [46]w3mmee-ssl -- Cookie information leak.
 * [47]w3m -- Cookie information leak.

 46. http://www.debian.org/security/2003/dsa-250
 47. http://www.debian.org/security/2003/dsa-251

New or Noteworthy Packages. The following packages were added to the
unstable Debian archive recently or contain important updates.

 * [48]atlantik -- KDE client for monopd.
 * [49]ccze -- Roboust, modular log coloriser.
 * [50]kaboodle -- Embedded media player for KDE.
 * [51]kaudiocreator -- CD ripper and audio encoder frontend.
 * [52]kbounce -- Jezzball clone for the K Desktop Environment.
 * [53]kenolaba -- Enolaba board game for KDE.
 * [54]kfouleggs -- KDE clone of the Japanese PuyoPuy game.
 * [55]kile -- The KDE Integrated LaTeX Environment.
 * [56]klickety -- Clickomania-like game for KDE.
 * [57]klineakconfig -- KDE configurator for lineakd.
 * [58]kolf -- Minigolf game for KDE.
 * [59]ksocrat -- English/Russian and Russian/English Dictionary.
 * [60]megami -- Blackjack game for KDE.
 * [61]sip -- Python/C++ Bindings Generator.
 * [62]subproject-howto -- Debian Subproject HOWTO.
 * [63]w3c-dtd-xhtml -- W3C eXtensible HyperText Markup Language
   (XHTML) DTD.
 * [64]wflogs -- The modular firewall log analyzer of the WallFire
   project.

 48. http://packages.debian.org/unstable/games/atlantik.html
 49. http://packages.debian.org/unstable/utils/ccze.html
 50. http://packages.debian.org/unstable/sound/kaboodle.html
 51. http://packages.debian.org/unstable/sound/kaudiocreator.html
 52. http://packages.debian.org/unstable/games/kbounce.html
 53. http://packages.debian.org/unstable/games/kenolaba.html
 54. http://packages.debian.org/unstable/games/kfouleggs.html
 55. http://packages.debian.org/unstable/tex/kile.html
 56. http://packages.debian.org/unstable/games/klickety.html
 57. http://packages.debian.org/unstable/x11/klineakconfig.html
 58. http://packages.debian.org/unstable/games/kolf.html
 59. http://packages.debian.org/unstable/text/ksocrat.html
 60. http://packages.debian.org/unstable/games/megami.html
 61. http://packages.debian.org/unstable/devel/sip.html
 62. http://packages.debian.org/unstable/doc/subproject-howto.html
 63. http://packages.debian.org/unstable/text/w3c-dtd-xhtml.html
 64. http://packages.debian.org/unstable/admin/wflogs.html

Orphaned Packages. 1 package was orphaned this week and requires a new
maintainer. This makes a total of 158 orphaned packages. Many thanks
to the previous maintainer who contributed to the Free Software
community. Please see the [65]WNPP pages for the full list, and please
add a note to the bug report and retitle it to ITA: if you plan to
take over a package.

 65. http://www.debian.org/devel/wnpp/

 * [66]kernel-patch-ck -- Con Kolivas' patch to improve system
   responsiveness. ([67]Bug#181425)

 66. http://packages.debian.org/unstable/misc/kernel-patch-ck.html
 67. http://bugs.debian.org/181425

Want to continue reading DWN? Please help us create this newsletter.
Several people are submitting items already, but we are still in need
of volunteer writers who prepare items. Please see the
[68]contributing page to find out how to help. We're looking forward
to receiving your mail at [69]dwn@debian.org.

 68. http://www.debian.org/News/weekly/contributing
 69. mailto:dwn@debian.org



Reply to: