Re: -fPIE and stuff

2012-01-30 Thread Simon McVittie
On 29/01/12 23:25, Russ Allbery wrote: > For PIE, the main practical problem with PIE is that PIE and PIC conflict, > so you can't just add -fPIE to the compiler flags of a package that builds > both executables and libraries. I investigated this for D-Bus (which builds a security-sensitive daemon

Re: Linux 3.2 in wheezy

2012-01-30 Thread Holger Levsen
Hi Marco, thanks for these infos! On Montag, 30. Januar 2012, Marco d'Itri wrote: > Let's start with this: in its current form, it is not designed to > protect the host system from an untrusted root user in a guest. > So far lxc is nice for testing, but not much more. > http://blog.bofh.it/debian

Bug#657957: ITP: starlink-libast -- Handle World Coordinate Systems in Astronomy

2012-01-30 Thread Ole Streicher
Package: wnpp Severity: wishlist Owner: Ole Streicher X-Debbugs-Cc: debian-devel@lists.debian.org, debian-scie...@lists.debian.org * Package name: starlink-libast Version : 6.0.1 Upstream Author : David Berry, R.F. Warren-Smith * URL : www.starlink.ac.uk/ast * License

Re: alioth is down (again)

2012-01-30 Thread Francesco Namuri
Il Dom, 29 Gennaio 2012 20:53, Andrew Starr-Bochicchio ha scritto: > On Sun, Jan 29, 2012 at 3:13 PM, Martin Zobel-Helas > wrote: >> Hi, >> >> On Sun Jan 29, 2012 at 20:40:57 +0100, Poison Bit wrote: >>> On Sun, Jan 29, 2012 at 2:15 PM, Stephen Gran wrote: >>>   Second, a suggestion or some brai

Re: Linux 3.2 in wheezy

2012-01-30 Thread Yves-Alexis Perez
(adding few CC:s to keep track on the bug) On dim., 2012-01-29 at 21:26 +, Ben Hutchings wrote: > On Sun, 2012-01-29 at 20:57 +0100, Yves-Alexis Perez wrote: > > On dim., 2012-01-29 at 18:22 +, Ben Hutchings wrote: > > > Featuresets > > > --- > > > > > > The only featureset provid

Re: Linux 3.2 in wheezy

2012-01-30 Thread Marco d'Itri
On Jan 30, Holger Levsen wrote: > > http://blog.bofh.it/debian/id_413 > would you mind filing a bug about this?! Refering to your blog post is nice, Yes, since the upstream maintainers do not consider this to be a bug. -- ciao, Marco signature.asc Description: Digital signature

Re: Linux 3.2 in wheezy

2012-01-30 Thread Bernd Zeimetz
On 01/30/2012 01:44 AM, Adam Borowski wrote: [...] > * how to ensure good isolation while still being able to do useful work? > The point of vserver is that even root inside a VM shouldn't be able to > affect the host, on lxc you keep hurting the host by accident. Messing > with capabiliti

pkgdiff

2012-01-30 Thread Andrey Ponomarenko
Hello list, A new tool for package maintainers has been released today: pkgdiff [1] - a tool for analyzing changes in Linux software packages (DEB, RPM, TAR.GZ, etc). The output of the tool is an HTML report like this [2]. Usage is simple: pkgdiff -old OLD.deb -new NEW.deb [1] http://pk

Re: pkgdiff

2012-01-30 Thread Daniel Martí
That sounds great! Thanks for the info. Andrey Ponomarenko wrote: >Hello list, > >A new tool for package maintainers has been released today: pkgdiff [1] > >- a tool for analyzing changes in Linux software packages (DEB, RPM, >TAR.GZ, etc). The output of the tool is an HTML report like this [2]

Re: pkgdiff

2012-01-30 Thread Andrey Rahmatullin
On Mon, Jan 30, 2012 at 03:08:03PM +0400, Andrey Ponomarenko wrote: > Hello list, > > A new tool for package maintainers has been released today: pkgdiff > [1] - a tool for analyzing changes in Linux software packages (DEB, > RPM, TAR.GZ, etc). The output of the tool is an HTML report like > this

Re: Bug#653813: ITP: edgar -- The Legend of Edgar platform game

2012-01-30 Thread Guus Sliepen
On Fri, Jan 27, 2012 at 06:58:26PM +, Richard Sweeney wrote: > > >If "current" license is GPL and someone make a fork based on that your > >license change in the future will not have an impact on the fork. > >A "release" has no value when regarding what license the work is > >available as. >

Bug#657967: O: prelink -- ELF prelinking utility to speed up dynamic linking

2012-01-30 Thread Igor Borski
Package: wnpp Severity: normal I intend to orphan the prelink package. Package maintainer is Andrés Roldán He is unreachable both through email and BTS. Package version is way behind upstream (last upload 2009, upstream updated 2011-10-12) The package description is: The prelink package contai

Bug#657968: ITP: lua-lgi -- Lua binding to GObject based libraries

2012-01-30 Thread Enrico Tassi
Package: wnpp Severity: wishlist Owner: Enrico Tassi * Package name: lua-lgi Version : 0.4 Upstream Author : Pavel Holejsovsky * URL : https://github.com/pavouk/lgi * License : MIT/X Programming Lang: C, Lua Description : Lua binding to GObject base

Re: pkgdiff

2012-01-30 Thread Andrey Ponomarenko
Andrey Rahmatullin wrote: On Mon, Jan 30, 2012 at 03:08:03PM +0400, Andrey Ponomarenko wrote: Hello list, A new tool for package maintainers has been released today: pkgdiff [1] - a tool for analyzing changes in Linux software packages (DEB, RPM, TAR.GZ, etc). The output of the tool is an HTML

undangan pelatihan : TEKNIK PEMBUATAN PAKAN IKAN (PELET)

2012-01-30 Thread MITRA Agro
PELATIHAN TEKNIK PEMBUATAN PAKAN IKAN (PELET) Tanggal 26 Februari 2012 , Bogor Dunia usaha perikanan semakin dituntut untuk dapat memanfaatan lahan secara optimal sehingga produktivitas lahan dapat ditingkatkan semaksimal mungkin. Sejalan dengan intensifikasi lahan maka ketersediaan pa

Re: Linux 3.2 in wheezy

2012-01-30 Thread Brad Spengler
> Indeed. Brad, I'm not sure if you received the initial mail, so if you > have any comment??? It looks like there were quite a few messages I wasn't involved in ;) Regarding minimizing the patchset, we do that already where we see opportunities to do so. We used to carry a large constifying

Bug#657974: ITP: olena -- C++ Image Processing Platform

2012-01-30 Thread Guillaume Lazzara
Package: wnpp Severity: wishlist Owner: Guillaume Lazzara * Package name: olena Version : 2.0-1 Upstream Author : Olena Team * URL : http://olena.lrde.epita.fr * License : GPLv2 Programming Lang: C++ Description : C++ Image Processing Platform. It prov

Re: Linux 3.2 in wheezy

2012-01-30 Thread Ben Hutchings
On Mon, 2012-01-30 at 11:05 +0100, Yves-Alexis Perez wrote: > (adding few CC:s to keep track on the bug) > > On dim., 2012-01-29 at 21:26 +, Ben Hutchings wrote: > > On Sun, 2012-01-29 at 20:57 +0100, Yves-Alexis Perez wrote: > > > On dim., 2012-01-29 at 18:22 +, Ben Hutchings wrote: > > >

Re: -fPIE and stuff

2012-01-30 Thread James Cloos
> "RA" == Russ Allbery writes: RA> That's the main reason why I'm not sure prelinking is worth it; I'll RA> take the speed hit from using non-prelinked binaries in exchange for RA> verifiable checksums. The last time prelinking came up on the Gentoo lists, those who had done some benchmarkin

Re: Linux 3.2 in wheezy

2012-01-30 Thread Peter Samuelson
[Brad Spengler] > Frankly it makes more sense for me to offer .debs myself than to deal > with a bureaucracy and non-standard kernel in Debian. It contains > who-knows-what extra code, and I doubt anyone looked at any of it to > see if it allows for some way to leak information I prevent against

Re: -fPIE and stuff

2012-01-30 Thread Russ Allbery
Simon McVittie writes: > I investigated this for D-Bus (which builds a security-sensitive daemon, > dbus-daemon, and a library, libdbus). It turns out that libtool is > clever enough to replace -fPIE with -fPIC -DPIC when compiling objects > that will go in a shared library, and omit -pie when li

Re: alioth is down (again)

2012-01-30 Thread Julien Cristau
On Mon, Jan 30, 2012 at 10:42:48 +0800, Paul Wise wrote: > I guess DSA would welcome a patch adding machine-parsable output and > status information to this: > > https://db.debian.org/machines.cgi > > I guess the devscripts maintainers would also welcome a script to read > the resulting info and

Proposed mass bug-filing/NMUing: perl 4 libraries

2012-01-30 Thread Dominic Hargreaves
I would like to try and ensure that wheezy releases without any packages which use the deprecated perl 4 libraries without depending on the separate libperl4-corelibs-perl package. You can see more details, and a list of packages, at

Re: Bug#605090: Linux 3.2 in wheezy

2012-01-30 Thread Yves-Alexis Perez
On lun., 2012-01-30 at 14:08 +, Ben Hutchings wrote: > On Mon, 2012-01-30 at 11:05 +0100, Yves-Alexis Perez wrote: > > (adding few CC:s to keep track on the bug) > > > > On dim., 2012-01-29 at 21:26 +, Ben Hutchings wrote: > > > On Sun, 2012-01-29 at 20:57 +0100, Yves-Alexis Perez wrote: >

Re: alioth is down (again)

2012-01-30 Thread Paul Wise
On Tue, Jan 31, 2012 at 2:58 AM, Julien Cristau wrote: > Like ldapsearch(1)?  That kind of already exists... More like a frontend to ldapsearch that doesn't require people to know about LDAP, about the Debian schema, nor ldapsearch itself. -- bye, pabs http://wiki.debian.org/PaulWise -- To U