Re: Re: Bug#493645: ITP: nostromo -- small, simple, fast and securehttpd

2008-08-25 Thread Franklin PIAT
> On Sun, 2008-08-03 at 21:09 +0100, Kai Hendry wrote: > > Package: wnpp > > Severity: wishlist > > > > * Package name: nostromo > > * URL : http://www.nazgul.ch/dev.html > > Programming Lang: C > > Description : small, simple, fast and secure httpd > [..] > As has been sa

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Christian Perrier
Quoting Steve Langasek ([EMAIL PROTECTED]): > This is far below the quality I expect from a mass bug filing that's been > reviewed by debian-devel. Mass bugfilings at RC severity need to be held to Even though I overread the thread when Dmitry posted his intent to -devel, I feel like there was

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Dmitry E. Oboukhov
NW> An attacker would be insane to select this example as a NW> vehicle. Attacker can use many ways (all variants from this list, for ex), one of its can work. Why you think that this variant is not work? -- . ''`. Dmitry E. Oboukhov : :’ : [EMAIL PROTECTED] `. `~’ GPGKey: 1024D / F8E26537 2006

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Thijs Kinkhorst
On Monday 25 August 2008 07:16, Christian Perrier wrote: > Quoting Steve Langasek ([EMAIL PROTECTED]): > > This is far below the quality I expect from a mass bug filing that's been > > reviewed by debian-devel. Mass bugfilings at RC severity need to be held > > to > > Even though I overread the th

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Thijs Kinkhorst
On Sunday 24 August 2008 22:00, Steve Langasek wrote: > Please take responsibility for providing the missing information to the > package maintainers, and for correcting the false positives that you've > filed. Yes, please. I think the only way the damage of this bad bug filing can be mitigated i

Re: RFA: The Debian Jr. project

2008-08-25 Thread Holger Levsen
Hi Ben, thanks for your work on Debian Jr. and for acknowledging that you don't have time/a heart for it anymore! On Thursday 07 August 2008 12:46, Ben Armstrong wrote: > The time has come for me to give up the [0]Debian Jr. project for > someone else to lead. While I still have a clear vision f

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Dmitry E. Oboukhov
TK>> Quoting Steve Langasek ([EMAIL PROTECTED]): TK>>> This is far below the quality I expect from a mass bug filing that's been TK>>> reviewed by debian-devel. Mass bugfilings at RC severity need to be held TK>>> to TK>> TK>> Even though I overread the thread when Dmitry posted his intent to TK>

oslec with zaptel and dahdi: dependency for external modules

2008-08-25 Thread Tzafrir Cohen
Basic question: how do I handle building external kernel modulesfrom different packages that depend on one another? (As for the workaround of getting either into mainline: tried, and doesn't work. At least not now) I have a module called "Mainmod" in package "mainmod-source", and it depends on co

Re: Re: Bug#493645: ITP: nostromo -- small, simple, fast and securehttpd

2008-08-25 Thread Tzafrir Cohen
On Mon, Aug 25, 2008 at 08:43:16AM +0200, Franklin PIAT wrote: > For those who needs to choose a (light) webserver, this page is meant to > gather pros and cons of each one : > http://wiki.debian.org/WebServers > > (Contributions are welcome.) Both boa and lighttpd require much more installed s

Re: RFA: The Debian Jr. project

2008-08-25 Thread Michael Schutte
On Mon, Aug 25, 2008 at 10:15:39AM +0200, Holger Levsen wrote: > > * Update the appearance of Debian Jr. > > * Incorporate the winning entry in the logo contest into Debian > > Jr. and the web site. > > Can you give a pointer to that logo please?! http://www.debianart.org/cchost/?ccm=/debia

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Neil Williams
On Mon, 2008-08-25 at 11:57 +0400, Dmitry E. Oboukhov wrote: > NW> An attacker would be insane to select this example as a > NW> vehicle. > > Attacker can use many ways (all variants from this list, for ex), one of > its can work. Why you think that this variant is not work? Because it is in the

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Neil Williams
On Mon, 2008-08-25 at 10:09 +0200, Thijs Kinkhorst wrote: > On Sunday 24 August 2008 22:00, Steve Langasek wrote: > > Please take responsibility for providing the missing information to the > > package maintainers, and for correcting the false positives that you've > > filed. > > Yes, please. I th

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Neil Williams
On Mon, 2008-08-25 at 10:09 +0200, Thijs Kinkhorst wrote: > On Sunday 24 August 2008 22:00, Steve Langasek wrote: > > Please take responsibility for providing the missing information to the > > package maintainers, and for correcting the false positives that you've > > filed. > > Yes, please. I th

Re: RFA: The Debian Jr. project

2008-08-25 Thread Ben Armstrong
On Mon, 25 Aug 2008 10:15:39 +0200 Holger Levsen <[EMAIL PROTECTED]> wrote: > thanks for your work on Debian Jr. and for acknowledging that you don't have > time/a heart for it anymore! Thanks. It's hard to let go, but it's really for the best if someone else will carry on. > Is that vision wri

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Charles Plessy
Le Mon, Aug 25, 2008 at 07:16:00AM +0200, Christian Perrier a écrit : > > - timing wrt the release > - timing wrt the "half of the developers are VAC" status we generally > have in August > - the obvious lack of preparation In addition, security issues should better be reported upstream first s

Re: RFA: The Debian Jr. project

2008-08-25 Thread Miriam Ruiz
2008/8/25 Ben Armstrong <[EMAIL PROTECTED]>: > While I would not have any problem with that if Edu cared for the > project and preserved the vision I described above, I have always > felt my own ideas for Jr had nothing to do with school and might indeed > by swallowed up by school concerns if we

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Dmitry E. Oboukhov
NW>>> An attacker would be insane to select this example as a NW>>> vehicle. NW>> NW>> Attacker can use many ways (all variants from this list, for ex), one of NW>> its can work. Why you think that this variant is not work? NW> Because it is in the documentation, not the script. Didn't you read t

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Martin Langhoff
On Mon, Aug 25, 2008 at 10:17 PM, Dmitry E. Oboukhov <[EMAIL PROTECTED]> wrote: > NW> Because it is in the documentation, not the script. Didn't you read the > NW> reply? It is not a route of attack, it is AN EXAMPLE in the > NW> documentation! > This script marked as executable. > User can start i

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Neil Williams
On Mon, 2008-08-25 at 14:17 +0400, Dmitry E. Oboukhov wrote: > NW>>> An attacker would be insane to select this example as a > NW>>> vehicle. > NW>> > NW>> Attacker can use many ways (all variants from this list, for ex), one of > NW>> its can work. Why you think that this variant is not work? >

Processed: this really should be checked by lintian

2008-08-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 161978 important Bug#161978: general: /usr/share as a symlink breaks EVERYTHING, but only sometimes Severity set to `important' from `important' > thanks Stopping processing here. Please contact me if you need assistance. Debian bug

Bug#161978: this really should be checked by lintian

2008-08-25 Thread Holger Levsen
severity 161978 important thanks Hi, downgrading severity, as this is about an old issue with tetex and because there is probably even a lintian check for this already. (Too lazy to confirm now, thus I'm also not reassigning the bug to lintian yet.) regards, Holger pgpmaN4blyB01.pgp

Bug#278246: marked as done (Cyrillic letters are displayed as double-width in most places)

2008-08-25 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 12:59:08 +0200 with message-id <[EMAIL PROTECTED]> and subject line closing has caused the Debian Bug report #278246, regarding Cyrillic letters are displayed as double-width in most places to be marked as done. This means that you claim that the problem has be

Bug#279983: marked as done (general: scsi emulated cdrom ide unit can't be correctly mounted first time)

2008-08-25 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 13:01:25 +0200 with message-id <[EMAIL PROTECTED]> and subject line closing has caused the Debian Bug report #279983, regarding general: scsi emulated cdrom ide unit can't be correctly mounted first time to be marked as done. This means that you claim that the

Bug#354654: marked as done (general: fat32 gets corrupted)

2008-08-25 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 13:04:14 +0200 with message-id <[EMAIL PROTECTED]> and subject line closing has caused the Debian Bug report #354654, regarding general: fat32 gets corrupted to be marked as done. This means that you claim that the problem has been dealt with. If this is not th

Bug#414938: status update?

2008-08-25 Thread Holger Levsen
severity 414938 normal thanks Hi Steven, downgrading as networking works for 99,9% of our users just fine :-) The bug smells a bit like 472680, have you been able to fix your network issues since then? regards, Holger pgpZZSq598vS7.pgp Description: PGP signature

Processed: status update?

2008-08-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 414938 normal Bug#414938: general: network connection issues, 90% connection slowdown Severity set to `normal' from `important' > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administr

Processed: reassign

2008-08-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign 484277 emdebian-tools Bug#484277: buildd.emdebian.org: RPATH issues Bug reassigned from package `general' to `emdebian-tools'. > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administra

Processed (with 1 errors): more info needed

2008-08-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 482994 normal Bug#482994: general: gnome applications fails to print with cups on remote printer, authorization request not fullfilled. Severity set to `normal' from `important' > tags 482994 +unreproducable Unknown tag/s: unreproducable. Rec

Bug#482994: more info needed

2008-08-25 Thread Holger Levsen
severity 482994 normal tags 482994 +unreproducable thanks Hi Federico, I very much believe that this bug is caused by a configuration problem on your side, as I can print from gnome applications to a local cups printer just fine. Can you please elaborate? Else I'll close this bug in a week. r

Processed: there is no spoon^wpatch

2008-08-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 128852 -patch Bug#128852: Ultra-newbie introductory documentation needed somewhere Tags were: patch Tags removed: patch > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (admini

Processed: Re: porters want to provide fixes, so...

2008-08-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 482921 -wontfix Bug#482921: please provide libc6-hppa64 and libc6-hppa64-dev packages Tags were: wontfix upstream Tags removed: wontfix > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system admin

Re: RFA: The Debian Jr. project

2008-08-25 Thread Miriam Ruiz
2008/8/25 Andreas Tille <[EMAIL PROTECTED]>: > Miriam, good luck at the revitalisation front! I'm willing to support > your effort by sharing experiences and technically with the DIS tools > (formerly known as CDD tools). Thanks a lot!! I will gladly take your word and be able to benefit from yo

Re: RFA: The Debian Jr. project

2008-08-25 Thread Andreas Tille
On Mon, 25 Aug 2008, Miriam Ruiz wrote: I have different plans for Debian Jr than those in from Debian-Edu if I was to adopt that project. It would be nice to talk about it. I'll try to find time to write a text on my view about the future of the Debian Jr Project as soon as I can. From my po

Processed: Re: Processed (with 1 errors): more info needed

2008-08-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 482994 +unreproducible Bug#482994: general: gnome applications fails to print with cups on remote printer, authorization request not fullfilled. There were no tags set. Tags added: unreproducible > thanks Stopping processing here. Please contact

Processed: any news on the lintian check?

2008-08-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 438885 important Bug#438885: Mass bug filing: must use invoke-rc.d Severity set to `important' from `serious' > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (administrato

Bug#132505: marked as done (debian status script(s))

2008-08-25 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 14:24:44 +0200 with message-id <[EMAIL PROTECTED]> and subject line the logwatch package implements this has caused the Debian Bug report #132505, regarding debian status script(s) to be marked as done. This means that you claim that the problem has been dealt

Bug#161978: this really should be checked by lintian

2008-08-25 Thread Adam D. Barratt
Hi, On Mon, August 25, 2008 11:56, Holger Levsen wrote: > downgrading severity, as this is about an old issue with tetex and because > there is probably even a lintian check for this already. (Too lazy to > confirm > now, thus I'm also not reassigning the bug to lintian yet.) As far as I can see,

Re: disappointed ... APT HowTo removed from sid

2008-08-25 Thread Osamu Aoki
Hi, On Thu, Aug 07, 2008 at 03:55:11PM +0200, Florian Rehnisch wrote: > Hi folks, > > I got the news that apt-howto* packages were removed from > sid (as they were from lenny before). Yes. Some basic apt features have been changed and apt-howto author admits it is not up-to-date. http://b

Bug#278246: marked as done (Cyrillic letters are displayed as double-width in most places)

2008-08-25 Thread Osamu Aoki
Hi, I agree to close this... > 278246: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278246 > From: Paul Pogonyshev <[EMAIL PROTECTED]> > Subject: Cyrillic letters are displayed as double-width in most places > To: [EMAIL PROTECTED] > Date: Mon, 25 Oct 2004 21:09:51 +0300 > > Package: generic

Re: Help supporting Debian on a Kurobox

2008-08-25 Thread RalfGesellensetter
Am Freitag 22 August 2008 schrieb =?iso-8859-1?Q?Rog=E9rio?= Brito: > I obviously want to run Debian on it so that I downloaded the powerpc > basedebs.tar from woody, a statically linked busybox (for chroot), > unpacked and manually installed these packages, upgraded to sarge and > now to etch. Thi

Bug#161978: marked as done (general: /usr/share as a symlink breaks EVERYTHING, but only sometimes)

2008-08-25 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 18:32:26 +0200 with message-id <[EMAIL PROTECTED]> and subject line checked by lintian already, thanks Adam! has caused the Debian Bug report #161978, regarding general: /usr/share as a symlink breaks EVERYTHING, but only sometimes to be marked as done. This

Re: Hardware compatibility test: draft proposal

2008-08-25 Thread Giacomo A. Catenazzi
Joe Smith wrote: > > "Giacomo Catenazzi" <[EMAIL PROTECTED]> wrote in message > news:[EMAIL PROTECTED] >> Wouter Verhelst wrote: >>> Hi, >>> >>> As I mentioned in my blog[1], I kindof like the suggestion that Bdale >> >> Yes, I find the talk very interesting. >> >>> So, after more than twelve hour

Re: Hardware compatibility test: draft proposal

2008-08-25 Thread Giacomo A. Catenazzi
Wouter Verhelst wrote: On Fri, Aug 22, 2008 at 12:55:34PM +0200, Giacomo Catenazzi wrote: Wouter Verhelst wrote: Hi, As I mentioned in my blog[1], I kindof like the suggestion that Bdale Yes, I find the talk very interesting. So, after more than twelve hours of boredom on an airplane and ha

Bug#78782: syslogs in debian

2008-08-25 Thread Michael Biebl
Holger Levsen wrote: > Hi Michael, > > as you know the state of the various syslogd implementations in Debian well, > could you please comment on, reassign and/or close #78782? ;-) > We nowadays have the virtual packages system-log-daemon and linux-kernel-log-daemon. The available syslog solut

Bug#78782: syslogs in debian

2008-08-25 Thread Török Edwin
On 2008-08-25 20:37, Michael Biebl wrote: Holger Levsen wrote: Hi Michael, as you know the state of the various syslogd implementations in Debian well, could you please comment on, reassign and/or close #78782? ;-) We nowadays have the virtual packages system-log-daemon and linux-

Bug#78782: syslogs in debian

2008-08-25 Thread Michael Biebl
Török Edwin wrote: > On 2008-08-25 20:37, Michael Biebl wrote: >> The current default syslog for Debian is rsyslog. >> > > I just installed using Debian lenny beta2 installer, and then did a > dist-upgrade to sid, my syslog is still > sysklogd (though apt-get install rsyslog shows no conflict

Bug#496560: ITP: libass -- library for SSA/ASS subtitles rendering

2008-08-25 Thread Christophe Mutricy
Package: wnpp Severity: wishlist Owner: Christophe Mutricy <[EMAIL PROTECTED]> * Package name: libass Version : 9.5.0 Upstream Author : Evgeniy Stepanov <[EMAIL PROTECTED] * URL : http://sourceforge.net/projects/libass * License : GPL v2 or later Programming

Bug#78782: marked as done (confusion among system log daemons)

2008-08-25 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 20:28:55 +0200 with message-id <[EMAIL PROTECTED]> and subject line Re: syslogs in debian has caused the Debian Bug report #78782, regarding confusion among system log daemons to be marked as done. This means that you claim that the problem has been dealt with.

Bug#496578: ITP: libmodule-inspector-perl -- An integrated API for inspecting Perl distributions

2008-08-25 Thread Damyan Ivanov
Package: wnpp Severity: wishlist Owner: Damyan Ivanov <[EMAIL PROTECTED]> * Package name: libmodule-inspector-perl Version : 1.05 Upstream Author : Adam Kennedy <[EMAIL PROTECTED]> * URL : http://search.cpan.org/dist/Module-Inspector/ * License : same as Perl (G

Bug#496586: ITP: numptyphysics -- crayon based physics puzzle game

2008-08-25 Thread Yaroslav Halchenko
Package: wnpp Severity: wishlist Owner: Yaroslav Halchenko <[EMAIL PROTECTED]> * Package name: numptyphysics Version : 0.3.0 Upstream Author : Tim Edmonds <[EMAIL PROTECTED]> * URL : http://numptyphysics.garage.maemo.org/ * License : GPL Programming Lang: C++

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Moritz Muehlenhoff
Christian Perrier wrote: >> This is far below the quality I expect from a mass bug filing that's been >> reviewed by debian-devel. Mass bugfilings at RC severity need to be held to > > Even though I overread the thread when Dmitry posted his intent to > -devel, I feel like there was *no* strong a

Re: Arch-dependent Depends

2008-08-25 Thread David Moreno
On Tue, 2008-06-24 at 10:55 +0200, Stefano Zacchiroli wrote: > Anyhow, we have to choose among: > 1) document and make the procedure work > 2) bug the packages which are using the undocumented procedure Seconded. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Tro

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Raphael Geissert
Charles Plessy wrote: > Le Mon, Aug 25, 2008 at 07:16:00AM +0200, Christian Perrier a écrit : >> >> - timing wrt the release >> - timing wrt the "half of the developers are VAC" status we generally >> have in August >> - the obvious lack of preparation > > In addition, security issues should b

[Suggestion] Reject Mail to ITP Bug

2008-08-25 Thread Kartik Mistry
Hi, I have seen that many packages are rejected from NEW [1] due to either licensing or poor packaging and we know the reasons [2] too. It will be very helpful if Rejection is also mailed to ITP (where it apply) so, that anyone can look at actual reason and fix problem (packaging, contacting upst

Re: [Suggestion] Reject Mail to ITP Bug

2008-08-25 Thread Paul Wise
On Tue, Aug 26, 2008 at 1:01 PM, Kartik Mistry <[EMAIL PROTECTED]> wrote: > I have seen that many packages are rejected from NEW [1] due to either > licensing or poor packaging and we know the reasons [2] too. > > It will be very helpful if Rejection is also mailed to ITP (where it > apply) so, th