Re: Bug#752450: ftp.debian.org: please consider to strongly tighten the validity period of Release files

2014-10-29 Thread Russell Stuart
On Thu, 2014-10-30 at 01:40 -0400, Michael Gilbert wrote: > There are also end-of-life announcements, which maybe the > debian-security-support package now addresses in a somewhat automated > fashion. I wasn't aware of that. Thanks. > Anyway, it is entirely understandable that reading can be har

Re: Bug#752450: ftp.debian.org: please consider to strongly tighten the validity period of Release files

2014-10-29 Thread Michael Gilbert
On Thu, Oct 30, 2014 at 1:12 AM, Russell Stuart wrote: > On Wed, 2014-10-29 at 21:58 -0700, Russ Allbery wrote: >> Also, this means that you completely miss security advisories that *don't* >> involve changing a package in the archive, like "this thing is a disaster, >> so we're pulling it from the

Re: Bug#752450: ftp.debian.org: please consider to strongly tighten the validity period of Release files

2014-10-29 Thread Michael Gilbert
On Thu, Oct 30, 2014 at 12:09 AM, Christoph Anton Mitterer wrote: > On Wed, 2014-10-29 at 19:39 -0700, Russ Allbery wrote: >> Packages appearing on mirrors is not how we notify Debian users of >> security updates. We do that by issuing a security advisory. > Aha,... well... sounds like nitpicking,

Re: Bug#752450: ftp.debian.org: please consider to strongly tighten the validity period of Release files

2014-10-29 Thread Russ Allbery
Russell Stuart writes: > If it is so that much of a disaster that it warrants pulling a package > from stable, surely a little more notification than an email to a list > most people don't monitor would be warranted? See, for example, DSA-2819. Or, on a different front, DSA-2907, which was rath

Re: Bug#752450: ftp.debian.org: please consider to strongly tighten the validity period of Release files

2014-10-29 Thread Russell Stuart
On Wed, 2014-10-29 at 21:58 -0700, Russ Allbery wrote: > Also, this means that you completely miss security advisories that *don't* > involve changing a package in the archive, like "this thing is a disaster, > so we're pulling it from the archive entirely and suggest you stop using > it." If it i

Re: Bug#752450: ftp.debian.org: please consider to strongly tighten the validity period of Release files

2014-10-29 Thread Russ Allbery
Christoph Anton Mitterer writes: > Even apart from the above problems, I doubt that mail is the appropriate > mean for many admins to get notified about security upgrades. If you don't read the mail, you're going to miss some really vital information, like packages that we are no longer supporti

Re: Bug#752450: ftp.debian.org: please consider to strongly tighten the validity period of Release files

2014-10-29 Thread Russ Allbery
Russell Stuart writes: > If there are two "ways" and one requires a human and the other is > completely automatic, all other things being equal for me the "right" > way is the automated one. I know my limitations - not being > conscientious when doing manual repetitive labour is one of them. Th

Re: Bug#752450: ftp.debian.org: please consider to strongly tighten the validity period of Release files

2014-10-29 Thread Christoph Anton Mitterer
Hey Russ. On Wed, 2014-10-29 at 19:39 -0700, Russ Allbery wrote: > Packages appearing on mirrors is not how we notify Debian users of > security updates. We do that by issuing a security advisory. Aha,... well... sounds like nitpicking,... I guess the least of the users have subscribed the respe

Re: Bug#752450: ftp.debian.org: please consider to strongly tighten the validity period of Release files

2014-10-29 Thread Russell Stuart
On Wed, 2014-10-29 at 19:39 -0700, Russ Allbery wrote: > But we shouldn't confuse that with the right way to check > for security updates for Debian systems. People who > care about security updates need to be subscribed to > debian-security-announce and reading the DSAs. If there are two "ways"

Re: dgit and git-dpm

2014-10-29 Thread Charles Plessy
Le Wed, Oct 29, 2014 at 04:09:03PM -0500, Jose-Luis Rivas a écrit : > On 29/10/14, 07:44pm, Thorsten Glaser wrote: > > > > This is a dangerous habit to get into – I’d prefer users of even > > dgit, no matter how good it may be, to not rely on that. This is > > a social issue, not a technical one.

Re: building against Clang (was: Legitimate exercise of...)

2014-10-29 Thread Adam Borowski
On Wed, Oct 29, 2014 at 05:02:11PM +0100, Jonas Smedegaard wrote: > Quoting Russ Allbery (2014-10-28 17:20:02) at debian-vote@l.d.o > > For the compiler, all of Debian is built with GCC, but some teams do > > test builds with Clang and report bugs, which most maintainers merge > > and some don't.

Re: Bug#752450: ftp.debian.org: please consider to strongly tighten the validity period of Release files

2014-10-29 Thread Russ Allbery
Christoph Anton Mitterer writes: > Anyway this should demonstrate quite practical, how fast attackers are > these days and that severely reducing the validity times doesn't just > help against some completely unreal attack vectors. > Even if the security team is as fast as above, then a victim m

Re: building against Clang (was: Legitimate exercise of...)

2014-10-29 Thread Henrique de Moraes Holschuh
On Wed, 29 Oct 2014, Jonas Smedegaard wrote: > Speaking of which: Is it Policy or just habit to use GCC over Clang? gcc still generates better machine code than clang in the *general* case for C source (I don't know about the rest). There is no policy to use gcc: if your program builds better usi

Re: What is the policy on audio group? and, proposal of a new group for the jack audio server

2014-10-29 Thread Ralf Jung
Hi, > Marco d'Itri: >> On Oct 27, Tobias Frost wrote: >> > Ok, so you are for removing audio group from user default groups? Eventually, yes. >>> Did you mean "maybe" or "for sure, someone" > > s/someone/sometime/ > >> No. >> > Then what *did* you mean? Well, probably the correct Engl

Bug#767299: ITP: librscode -- library implementing a Reed-Solomon error correction algorithm

2014-10-29 Thread Christian Kastner
Package: wnpp Severity: wishlist Owner: Christian Kastner * Package name: librscode Version : 1.3 Upstream Author : Henry Minsky * URL : http://rscode.sourceforge.net * License : GPL-3+ Programming Lang: C Description : library implementing a Reed-Solo

Bug#767298: ITP: python-cachetools -- extensible memoizing collections and decorators

2014-10-29 Thread Christian Kastner
Package: wnpp Severity: wishlist Owner: Christian Kastner * Package name: python-cachetools Version : 0.6.0 Upstream Author : Thomas Kremmer * URL : https://github.com/tkem/cachetools * License : Expat Programming Lang: Python Description : extensible m

Re: Bug#752450: ftp.debian.org: please consider to strongly tighten the validity period of Release files

2014-10-29 Thread Christoph Anton Mitterer
Hey Henrique, et al. I've had lost my interest a bit, since it feels like fighting windmills... but one month has passed and it's perhaps a good time to revisit this. On Mon, 2014-09-29 at 08:08 -0300, Henrique de Moraes Holschuh wrote: > On Mon, 29 Sep 2014, Christoph Anton Mitterer wrote: > >

Re: dgit and git-dpm

2014-10-29 Thread Jose-Luis Rivas
On 29/10/14, 07:44pm, Thorsten Glaser wrote: > Ian Jackson dixit: > > [ NMU ] > >A dgit user should be able to do this without reading the debdiff: > > This is a dangerous habit to get into – I’d prefer users of even > dgit, no matter how good it may be, to not rely on that. This is > a social is

Re: dgit and git-dpm

2014-10-29 Thread Thorsten Glaser
Ian Jackson dixit: [ NMU ] >A dgit user should be able to do this without reading the debdiff: This is a dangerous habit to get into – I’d prefer users of even dgit, no matter how good it may be, to not rely on that. This is a social issue, not a technical one. bye, //mirabilos -- „Cool, /usr/s

Re: Doxygen and embedded jquery problem, how to solve?

2014-10-29 Thread Bastien ROUCARIES
On Wed, Oct 29, 2014 at 5:48 PM, Scott Kitterman wrote: > On Wednesday, October 29, 2014 17:44:11 Cyril Brulebois wrote: >> Scott Kitterman (2014-10-29): >> > Would another option be to use "built-using" the doxygen version in >> > question. Since effectively this is embedded code from the doxyg

Re: building against Clang (was: Legitimate exercise of...)

2014-10-29 Thread Matthias Urlichs
Hi, Jonas Smedegaard: > Speaking of which: Is it Policy or just habit to use GCC over Clang? > Well, when Debian was started, clang didn't even exist – also, for a long time it wasn't compatible with quite a few GCCisms in our sources and/or rules files. -- -- Matthias Urlichs -- To UNSUBSCR

Re: Doxygen and embedded jquery problem, how to solve?

2014-10-29 Thread Scott Kitterman
On Wednesday, October 29, 2014 17:44:11 Cyril Brulebois wrote: > Scott Kitterman (2014-10-29): > > Would another option be to use "built-using" the doxygen version in > > question. Since effectively this is embedded code from the doxygen > > package if I understand it correctly. Using doxygen to

Re: building against Clang

2014-10-29 Thread Sylvestre Ledru
On 29/10/2014 17:02, Jonas Smedegaard wrote: > Quoting Russ Allbery (2014-10-28 17:20:02) at debian-vote@l.d.o >> For the compiler, all of Debian is built with GCC, but some teams do >> test builds with Clang and report bugs, which most maintainers merge >> and some don't. > > Speaking of which:

Re: Doxygen and embedded jquery problem, how to solve?

2014-10-29 Thread Cyril Brulebois
Scott Kitterman (2014-10-29): > Would another option be to use "built-using" the doxygen version in > question. Since effectively this is embedded code from the doxygen > package if I understand it correctly. Using doxygen to regenerate > things is the preferred form of modification and all the

Re: Doxygen and embedded jquery problem, how to solve?

2014-10-29 Thread Scott Kitterman
On Wednesday, October 29, 2014 15:59:44 Jonas Smedegaard wrote: > Quoting Gianfranco Costamagna (2014-10-29 15:18:30) > > > >For the source package I believe you should either... > > [...] > > > the documentation is usually regenerated into debian, not ship with > > the source code > > Silly me

Re: building against Clang (was: Legitimate exercise of...)

2014-10-29 Thread Gert Wollny
On Wed, 2014-10-29 at 17:02 +0100, Jonas Smedegaard wrote: > doxygen (and a very few others) links against libclang1-3.5 > "where available" according to the changelog, ... > libllvm3.5 is also used for another few, including mesa. It's not so much a question whether these packages are compiled

Re: building against Clang (was: Legitimate exercise of...)

2014-10-29 Thread Mathieu Malaterre
On Wed, Oct 29, 2014 at 5:02 PM, Jonas Smedegaard wrote: > Quoting Russ Allbery (2014-10-28 17:20:02) at debian-vote@l.d.o >> For the compiler, all of Debian is built with GCC, but some teams do >> test builds with Clang and report bugs, which most maintainers merge >> and some don't. > > Speaking

Re: building against Clang

2014-10-29 Thread Russ Allbery
Jonas Smedegaard writes: > Quoting Russ Allbery (2014-10-28 17:20:02) at debian-vote@l.d.o >> For the compiler, all of Debian is built with GCC, but some teams do >> test builds with Clang and report bugs, which most maintainers merge >> and some don't. > Speaking of which: Is it Policy or just

Re: building against Clang (was: Legitimate exercise of...)

2014-10-29 Thread Jonas Smedegaard
Quoting Russ Allbery (2014-10-28 17:20:02) at debian-vote@l.d.o > For the compiler, all of Debian is built with GCC, but some teams do > test builds with Clang and report bugs, which most maintainers merge > and some don't. Speaking of which: Is it Policy or just habit to use GCC over Clang? I

Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)

2014-10-29 Thread Barry Warsaw
On Oct 29, 2014, at 01:47 PM, Ian Jackson wrote: >I got the impression that sbuild is winning over pbuilder BICBW. Especially now that bug #607228 has been fixed! Cheers, -Barry signature.asc Description: PGP signature

Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)

2014-10-29 Thread Osamu Aoki
Hi, On Wed, Oct 29, 2014 at 11:54:41AM -0200, Antonio Terceiro wrote: > On Wed, Oct 29, 2014 at 02:32:04PM +0100, Guido Günther wrote: > > On Wed, Oct 29, 2014 at 12:06:59PM +, Ian Jackson wrote: > > > Dimitri John Ledkov writes ("Re: dgit and git-dpm (was Re: > > > Standardizing the layout o

Re: Doxygen and embedded jquery problem, how to solve?

2014-10-29 Thread Gianfranco Costamagna
Hi Paul, >This is the place in which I remind people javascript-common with >multiple versions of jQuery would reduce maintainer burden and avoid >filling the archive with tons of binaries if someone has a spare few hours. this can fix the problem about symlinking a javascript version that gets

Re: Doxygen and embedded jquery problem, how to solve?

2014-10-29 Thread Gianfranco Costamagna
>IMO the proper solution is for Debian packaging of doxygen to untangle >jQuery from extensions, depend on + symlink the jQuery part, provide the >extensions as a shared package, and patch doxygen code to generate >docuementation referencing each separately instead of the entangled one. >...b

Bug#767246: ITP: pyapi-gitlab -- Python wrapper for the GitLab API

2014-10-29 Thread Benjamin Drung
Package: wnpp Severity: wishlist Owner: Benjamin Drung * Package name: pyapi-gitlab Version : 6.2.3 Upstream Author : Itxaka Serrano Garcia * URL : https://github.com/Itxaka/pyapi-gitlab * License : GPL-3 Programming Lang: Python Description : Python w

Re: Doxygen and embedded jquery problem, how to solve?

2014-10-29 Thread Paul Tagliamonte
On Wed, Oct 29, 2014 at 03:59:44PM +0100, Jonas Smedegaard wrote: > IMO the proper solution is for Debian packaging of doxygen to untangle > jQuery from extensions, depend on + symlink the jQuery part, provide the > extensions as a shared package, and patch doxygen code to generate > docuementat

Re: Doxygen and embedded jquery problem, how to solve?

2014-10-29 Thread Jonas Smedegaard
Quoting Gianfranco Costamagna (2014-10-29 15:18:30) > >For the source package I believe you should either... [...] > the documentation is usually regenerated into debian, not ship with > the source code Silly me, you are right, off course. >>For the [binary] package I believe you should either.

Re: Doxygen and embedded jquery problem, how to solve?

2014-10-29 Thread Gianfranco Costamagna
Dear Jonas, >For the source package I believe you should either... >a) ensure that the code is truly the code that it claims to be >(filename "jquery-1.2.3" quite arguably is not adequate ensurance >that it contains unaltered version 1.2.3 of jQuery). >This can be difficult to ensure

Re: Doxygen and embedded jquery problem, how to solve?

2014-10-29 Thread Jonas Smedegaard
Hi Gianfranco, Quoting Gianfranco Costamagna (2014-10-29 13:41:30) > I'm stuck with this jquery problem, and I don't know the best solution > for it. > > Doxygen creates and embeds a patched jquery version (why they don't > extend jquery in another file or rename it to avoid clashes is obscure

Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)

2014-10-29 Thread Antonio Terceiro
On Wed, Oct 29, 2014 at 02:32:04PM +0100, Guido Günther wrote: > On Wed, Oct 29, 2014 at 12:06:59PM +, Ian Jackson wrote: > > Dimitri John Ledkov writes ("Re: dgit and git-dpm (was Re: Standardizing > > the layout of git packaging repositories)"): > > > dpkg-source removes it, by default, for

Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)

2014-10-29 Thread Ian Jackson
Guido Günther writes ("Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)"): > I do wonder if we should switch to using git-pbuilder by default and > rather offer to invoke 'git-pbuilder create' in case we don't find a > proper base.cow for it. I got the impress

Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)

2014-10-29 Thread Ian Jackson
Simon McVittie writes ("Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)"): > On 29/10/14 12:08, Ian Jackson wrote: > > The contents of the default ignore > > list is in dpkg-source, but it is not enabled unless the caller says > > -I. git-buildpackage passes

Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)

2014-10-29 Thread Guido Günther
On Wed, Oct 29, 2014 at 12:06:59PM +, Ian Jackson wrote: > Dimitri John Ledkov writes ("Re: dgit and git-dpm (was Re: Standardizing the > layout of git packaging repositories)"): > > dpkg-source removes it, by default, for 3.0 based formats as it's part > > of the default ignore list. > > (or

Re: dgit and git-dpm

2014-10-29 Thread Ian Jackson
Thorsten Glaser writes ("Re: dgit and git-dpm"): > On Wed, 29 Oct 2014, Ian Jackson wrote: > > maintainers of other tools. It does seem to me to imply that using > > git-buildpackage to do an NMU is risky, because: > > Yes, it is – anything other than the standard Debian tool > (dpkg-buildpackage

Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)

2014-10-29 Thread Simon McVittie
On 29/10/14 12:08, Ian Jackson wrote: > The contents of the default ignore > list is in dpkg-source, but it is not enabled unless the caller says > -I. git-buildpackage passes -I. To be completely clear (because I misread it twice in a row), you mean that it is not enabled unless the caller uses

Re: dgit and git-dpm

2014-10-29 Thread Thorsten Glaser
On Wed, 29 Oct 2014, Ian Jackson wrote: > maintainers of other tools. It does seem to me to imply that using > git-buildpackage to do an NMU is risky, because: Yes, it is – anything other than the standard Debian tool (dpkg-buildpackage) is. > If some user of git-buildpackage (without dgit) tri

Doxygen and embedded jquery problem, how to solve?

2014-10-29 Thread Gianfranco Costamagna
Hi dear Debian Developers and Maintainers, I'm stuck with this jquery problem, and I don't know the best solution for it. Doxygen creates and embeds a patched jquery version (why they don't extend jquery in another file or rename it to avoid clashes is obscure to me), then symlink can result i

Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)

2014-10-29 Thread Ian Jackson
[resending because my MUA failed to mangle the headers] Dimitri John Ledkov writes ("Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)"): > dpkg-source removes it, by default, for 3.0 based formats as it's part > of the default ignore list. > (or rather ignores

Re: Where to upload official OpenStack Debian images?

2014-10-29 Thread Thomas Goirand
On 10/29/2014 12:54 AM, Steve McIntyre wrote: > On Wed, Oct 22, 2014 at 03:58:04PM +0200, Juerg Haefliger wrote: >> Hi, >> >> On Sat, Jul 19, 2014 at 10:12 AM, Thomas Goirand wrote: >>> >>> On 07/18/2014 07:49 PM, Steve McIntyre wrote: > [2] I contacted Steve McIntyre privately about it, but h

Re: dgit and git-dpm (was Re: Standardizing the layout of git packaging repositories)

2014-10-29 Thread Dimitri John Ledkov
On 29 October 2014 05:39, Guido Günther wrote: > On Tue, Oct 28, 2014 at 07:17:49PM +, Ian Jackson wrote: >> Brian May writes ("Re: Standardizing the layout of git packaging >> repositories"): >> > However, with git-dpm, no branch is ever destroyed. Every branch is always >> > merged into the

Auto moto gume zimska ponuda

2014-10-29 Thread Zimske Gume
Postovani, ovim putem zelimo da Vam ponudimo asortiman zimskih guma putem nase veleprodaje - zastupnici smo za SAVU, DUNLOP, GY i mogucnost ugradnje istih u nasem servisu. Servis se nalazi u ulici Jovanke Radakovic 25i ( od Bogoslovije ka Mirijevu na samom glavnom putu). Uz ponudu pneumatika za