Re: armhf port, repo and simple image available

2010-08-07 Thread Konstantinos Margaritis
On Wednesday 04 August 2010 19:23:51 Konstantinos Margaritis wrote: > Yup, and doxygen fails. In fact I am amazed that this actually builds on > other platforms properly, it appears that it build-deps on libqt4-dev, but > Makefile.doxywizard is configured for qt3: I patched doxygen to use qmake

Re: Bug#592115: apt seems to somehow use ~/.gnupg dir when checking package integrity which might be used for security attacks

2010-08-07 Thread Julian Andres Klode
reassign 592115 dpkg thanks On Sa, 2010-08-07 at 18:17 +0200, Christoph Anton Mitterer wrote: > Package: apt > Version: 0.7.20.2+lenny2 > Severity: grave > Tags: security > Justification: user security hole > > Hi. > > I found out some strange issue, which IMO might be used for security attacks

Re: armhf port, repo and simple image available

2010-08-07 Thread Konstantinos Margaritis
On Wednesday 04 August 2010 17:01:18 Konstantinos Margaritis wrote: > 11. klibc: I modified the source to tune for armv7-a but it still fails to > build: http://paste.debian.net/82212/ (which as I found, used to occur with > klibc in ubuntu, LP: #534281). This probably has to do with my older > ve

Fwd: debdiff for v3 source packages with multiple tarballs?

2010-08-07 Thread Matthias Klose
sorry, hit autocomplete for the recipient too early ... Original Message Subject: debdiff for v3 source packages with multiple tarballs? Resent-Date: Sat, 7 Aug 2010 17:12:17 + (UTC) Resent-From: debian-de...@lists.debian.org Date: Sat, 07 Aug 2010 18:56:26 +0200 From: Matt

Re: Bug#592115: apt seems to somehow use ~/.gnupg dir when checking package integrity which might be used for security attacks

2010-08-07 Thread Christoph Anton Mitterer
On Sat, 2010-08-07 at 21:27 +0200, Julian Andres Klode wrote: > As everyone should know, dpkg unpacks the source packages and verifies > them using gpg. APT knows that the package is secure, because the source > is secure. Ah I've missed that this is from the debsig, and not from checking the integ

Re: Fwd: debdiff for v3 source packages with multiple tarballs?

2010-08-07 Thread Raphael Hertzog
Hi, On Sat, 07 Aug 2010, Matthias Klose wrote: > and debdiff isn't able anymore to show a meaningful diff. Is there any way to > decouple the name of the tarball and the directory name where the tarball is > unpacked? No. > Or is there a way to create a more meaningful diff? Yes. See the --mov