Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Jakub Jelinek
On Wed, Apr 03, 2013 at 01:53:27AM +0200, Reindl Harald wrote: > > A prelinked module reduces time spent in ld-linux, and increases sharing > > of pages (which reduces time spent in kernel duplicating copy-on-write > > pages.) > > The savings are *visible* when invoking an interactive GUI program

Re: CANCELED: Wednesday's FESCo Meeting (2012-04-03)

2013-04-02 Thread Dhiru Kholia
On Tue, Apr 2, 2013 at 11:34 PM, Stephen Gallagher wrote: > There are currently no tickets in the FESCo Trac instance that require > discussion tomorrow. After discussion with several other FESCo members > in #fedora-devel, we agreed to cancel this week's meeting unless > something urgent comes up

[Test-Announce] 2013-04-03 @ 16:00 UTC - F19 Alpha Blocker Bug Review #4

2013-04-02 Thread Tim Flink
# F19 Alpha Blocker Review meeting #4 # Date: 2013-04-03 # Time: 16:00 UTC (12:00 EDT, 09:00 PDT) # Location: #fedora-blocker-review on irc.freenode.net The first alpha blocker review meeting after the freeze has started - exciting times :) We'll be running through the alpha blockers and freeze e

Re: How do *you* use Fedora?

2013-04-02 Thread John5342
On 2 Apr 2013 20:48, "Pete Travis" wrote: > > Hello, > > The docs team has begun assembling release notes for Fedora 19, and I've been thinking over hardware requirements. > > Historically, we have cited the CPU, storage, and especially memory requirements for the default installation - a basic GN

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Reindl Harald
Am 03.04.2013 01:50, schrieb John Reiser: >> It does rather seem like we should consider just killing it [prelink], at >> least by default. > > Prelinking shortens the time between execve() and first useful output in theory > A prelinked module reduces time spent in ld-linux, and increases shar

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Kevin Fenzi
On Tue, 02 Apr 2013 16:50:33 -0700 John Reiser wrote: > > It does rather seem like we should consider just killing it > > [prelink], at least by default. > > Prelinking shortens the time between execve() and first useful output. > A prelinked module reduces time spent in ld-linux, and increases

Re: How do *you* use Fedora?

2013-04-02 Thread Matthew Miller
On Tue, Apr 02, 2013 at 03:28:21PM -0700, Adam Williamson wrote: > >>I'm considering system specs at this point, but establishing the roles > >>deployed might aid in targeting more comprehensive documentation. Beyond a > >>basic desktop, what use cases would you like to see us represent? > >Cloud g

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread John Reiser
> It does rather seem like we should consider just killing it [prelink], at > least by default. Prelinking shortens the time between execve() and first useful output. A prelinked module reduces time spent in ld-linux, and increases sharing of pages (which reduces time spent in kernel duplicating

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Stephen Smoogen
On Tue, 2 Apr 2013, Adam Williamson wrote: Date: Tue, 02 Apr 2013 15:18:55 -0700 From: Adam Williamson Reply-To: Development discussions related to Fedora To: devel@lists.fedoraproject.org Subject: Re: Expanding the list of "Hardened Packages" On 31/03/13 08:11 AM, Richard W.M. Jones wrot

GSoC

2013-04-02 Thread Ruben Guerra Marin
Hi all, My name is Ruben Guerra (biker on Freenode) and I have been a Fedora ambassador for a year, but I am also a student, and I would like to participate on the GSoC working for Fedora. I know python (and also I have knowledge of the django framework), java, C, assembly and some PHP. I also kno

Re: package, package2, package3 naming-with-version exploit

2013-04-02 Thread James Antill
On Tue, 2013-04-02 at 14:16 +, Petr Pisar wrote: > On 2013-04-02, seth vidal wrote: > > On Tue, 2 Apr 2013 13:27:43 + (UTC) > > Petr Pisar wrote: > >> > >> Misusing names does not allow all of that. > > > > misusing? Is this, again, another metaphor? Please speak plainly. What > > do you

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Reindl Harald
Am 03.04.2013 00:18, schrieb Adam Williamson: > On 31/03/13 08:11 AM, Richard W.M. Jones wrote: > >> However prelink does reduce the effectiveness of ASLR (a bit). See >> http://lwn.net/Articles/341440/ and follow-up conversation. > > Ignoring the silly stuff, it does seem that this is Yet Ano

Re: How do *you* use Fedora?

2013-04-02 Thread Adam Williamson
On 02/04/13 02:26 PM, Matthew Miller wrote: On Tue, Apr 02, 2013 at 01:47:48PM -0600, Pete Travis wrote: I'm considering system specs at this point, but establishing the roles deployed might aid in targeting more comprehensive documentation. Beyond a basic desktop, what use cases would you like

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Adam Williamson
On 31/03/13 08:11 AM, Richard W.M. Jones wrote: However prelink does reduce the effectiveness of ASLR (a bit). See http://lwn.net/Articles/341440/ and follow-up conversation. Ignoring the silly stuff, it does seem that this is Yet Another Reason Prelink Is Bad, and we seem to keep bumping up

Re: How do *you* use Fedora?

2013-04-02 Thread Matthew Miller
On Tue, Apr 02, 2013 at 01:47:48PM -0600, Pete Travis wrote: > I'm considering system specs at this point, but establishing the roles > deployed might aid in targeting more comprehensive documentation. Beyond a > basic desktop, what use cases would you like to see us represent? Cloud guest, please

Re: Using Fedora for Gnome development...

2013-04-02 Thread Darryl L. Pierce
On Tue, Apr 02, 2013 at 03:50:26PM -0400, Colin Walters wrote: > On Tue, 2013-04-02 at 15:31 -0400, Darryl L. Pierce wrote: > > > When python3 is installed then, with both projects, Cmake finds Python > > 3. > > This seems like either a bug in Cmake or your project (not sure which) - > if it's p

Re: How do *you* use Fedora?

2013-04-02 Thread DJ Delorie
I'm WAY out on the bell curve... I have two PCs. One of them, the one I sit in front of, has four monitors (on one Radeon HD card), video capture and playback, digital and analog audio (digital goes to a surround system receiver, analog to gaming headphones), an SSD plus a dual-3Tb raid1 all in

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Steve Grubb
On Saturday, March 30, 2013 08:54:30 AM Dhiru Kholia wrote: > On Fri, Mar 29, 2013 at 10:43 PM, Richard W.M. Jones wrote: > > On Fri, Mar 29, 2013 at 10:08:37PM +0530, Dhiru Kholia wrote: > > > 1. Hardening flags should be turned on (by default) for all packages > > > which are at comparatively m

Re: Using Fedora for Gnome development...

2013-04-02 Thread Colin Walters
On Tue, 2013-04-02 at 15:31 -0400, Darryl L. Pierce wrote: > When python3 is installed then, with both projects, Cmake finds Python > 3. This seems like either a bug in Cmake or your project (not sure which) - if it's possible to explicitly specify that you want Python 2, then you should be doin

How do *you* use Fedora?

2013-04-02 Thread Pete Travis
Hello, The docs team has begun assembling release notes for Fedora 19, and I've been thinking over hardware requirements. Historically, we have cited the CPU, storage, and especially memory requirements for the default installation - a basic GNOME desktop. I'd like to reexamine that practice, wi

Re: Using Fedora for Gnome development...

2013-04-02 Thread Darryl L. Pierce
On Tue, Apr 02, 2013 at 09:28:12PM +0800, Mathieu Bridon wrote: > You can perfectly well have Python 2 and 3 coexisting on the same > Fedora, and use either in your projects. > > The packages are made to be installed in parallel, and there > shouldn't be any conflicts. > > Many people are develop

Re: XFS and trim

2013-04-02 Thread Eric Sandeen
On 4/2/13 9:26 AM, Steven Haigh wrote: > On 03/04/13 01:08, Eric Sandeen wrote: snip >> I wonder if we should add something to the remount path to printk >> when a non-remountable option is encountered; I might look into >> that, otherwise it's a little surprising (although semi-obvious >> when t

CANCELED: Wednesday's FESCo Meeting (2012-04-03)

2013-04-02 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 There are currently no tickets in the FESCo Trac instance that require discussion tomorrow. After discussion with several other FESCo members in #fedora-devel, we agreed to cancel this week's meeting unless something urgent comes up. If you feel that

[Test-Announce] Fedora 19 Alpha Change freeze

2013-04-02 Thread Kamil Paral
- Forwarded Message - From: "Dennis Gilmore" To: devel-annou...@lists.fedoraproject.org Sent: Tuesday, April 2, 2013 4:40:41 AM Subject: Fedora 19 Alpha Change freeze Hi all, as the Fedora 19 schedule[1] states the Alpha change freeze is upon us. As we are now at the change freeze bodhi

Re: XFS and trim

2013-04-02 Thread Steven Haigh
On 03/04/13 01:46, Eric Sandeen wrote: BTW Steven - we often recommend against runtime trim, and suggest fstrim instead, for performance reasons. Just something to maybe keep in mind and experiment with. Thats ok - this isn't for a high-performance system - this is just me messing around on

Re: XFS and trim

2013-04-02 Thread Ric Wheeler
On 04/02/2013 10:26 AM, Steven Haigh wrote: On 03/04/13 01:08, Eric Sandeen wrote: On 4/1/13 5:26 PM, Steven Haigh wrote: On 04/02/2013 12:19 AM, Josef Bacik wrote: On Sat, Mar 30, 2013 at 9:38 PM, Steven Haigh wrote: Hi all, Firstly, Please CC me into replies as I'm not subscribed to this

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread John Reiser
>> $ gcc -m32 -fPIE -O -S foo.c >> $ cat foo.s # edited for brevity >> foo: # 25 bytes; about 15 cycles (incl. 3*3 cycles data cache fetch >> latency) >> call__x86.get_pc_thunk.cx >> addl$_GLOBAL_OFFSET_TABLE_, %ecx >> movl4(%esp), %eax >> movla@GOT(%ecx), %e

[Bug 947489] New: Please revert the "unbundling" of "inc::Module::Install", at least when bootstrapping

2013-04-02 Thread bugzilla
Product: Fedora https://bugzilla.redhat.com/show_bug.cgi?id=947489 Bug ID: 947489 Summary: Please revert the "unbundling" of "inc::Module::Install", at least when bootstrapping Product: Fedora Version: rawhide Component: per

Re: XFS and trim

2013-04-02 Thread Eric Sandeen
On 4/2/13 9:30 AM, Ric Wheeler wrote: > On 04/02/2013 10:26 AM, Steven Haigh wrote: >> On 03/04/13 01:08, Eric Sandeen wrote: >>> On 4/1/13 5:26 PM, Steven Haigh wrote: On 04/02/2013 12:19 AM, Josef Bacik wrote: > On Sat, Mar 30, 2013 at 9:38 PM, Steven Haigh wrote: >> Hi all, >>

ARM "Secret Docoder Ring" Wiki Page

2013-04-02 Thread Paul Whalen
Good day all, At FUDCon we discussed the creation of a 'Secret Decoder Ring' document that would help those new to the ARM world to quickly become familiar with the ongoing work and ease the process of jumping in. A draft of the document has been posted: https://fedoraproject.org/wiki/Archi

Re: XFS and trim

2013-04-02 Thread Steven Haigh
On 03/04/13 01:08, Eric Sandeen wrote: On 4/1/13 5:26 PM, Steven Haigh wrote: On 04/02/2013 12:19 AM, Josef Bacik wrote: On Sat, Mar 30, 2013 at 9:38 PM, Steven Haigh wrote: Hi all, Firstly, Please CC me into replies as I'm not subscribed to this list. I'm trying to confirm that Fedora 18 h

Re: package, package2, package3 naming-with-version exploit

2013-04-02 Thread seth vidal
On Tue, 2 Apr 2013 14:16:31 + (UTC) Petr Pisar wrote: > On 2013-04-02, seth vidal wrote: > > On Tue, 2 Apr 2013 13:27:43 + (UTC) > > Petr Pisar wrote: > >> > >> Misusing names does not allow all of that. > > > > misusing? Is this, again, another metaphor? Please speak plainly. > > What

Re: package, package2, package3 naming-with-version exploit

2013-04-02 Thread seth vidal
On Tue, 2 Apr 2013 14:02:46 + (UTC) Petr Pisar wrote: > Or maybe there are APIs 3.8, 3.9, and 4.0 and we want to express (3.8 > or 3.9), but poor RPM does not handle `or'? After reading these and other comments from you, Petr, it seems to me you are not interested in making things better, yo

Re: package, package2, package3 naming-with-version exploit

2013-04-02 Thread Petr Pisar
On 2013-04-02, seth vidal wrote: > On Tue, 2 Apr 2013 13:27:43 + (UTC) > Petr Pisar wrote: >> >> Misusing names does not allow all of that. > > misusing? Is this, again, another metaphor? Please speak plainly. What > do you mean here? Where is the misuse? > foo1, foo2, foo3 -- there is no or

Re: XFS and trim

2013-04-02 Thread Eric Sandeen
On 4/1/13 5:26 PM, Steven Haigh wrote: > On 04/02/2013 12:19 AM, Josef Bacik wrote: >> On Sat, Mar 30, 2013 at 9:38 PM, Steven Haigh wrote: >>> Hi all, >>> >>> Firstly, Please CC me into replies as I'm not subscribed to this list. >>> >>> I'm trying to confirm that Fedora 18 has enabled trim for X

Orphaning maven-pmd-plugin

2013-04-02 Thread Tomas Radej
Hi, I am orphaning maven-pmd-plugin due to serious hardships when updating, and I don't really need it. It is buildrequired by: ehcache-parent-0:2.3-4.fc19.src ehcache-sizeof-agent-0:1.0.1-4.fc19.src maven-license-plugin-0:1.8.0-13.fc19.src quartz-0:2.1.2-7.fc19.src resteasy-0:2.3.2-9.fc18.src

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Richard W.M. Jones
On Tue, Apr 02, 2013 at 07:15:29PM +0530, Dhiru Kholia wrote: > On Tue, Apr 2, 2013 at 6:36 PM, Richard W.M. Jones wrote: > > On Tue, Apr 02, 2013 at 05:51:42PM +0530, Dhiru Kholia wrote: > >> http://dl.dropbox.com/u/1522424/probable-violations-F19.xls > > > > That shows: > > > > > > > > Can you

Re: package, package2, package3 naming-with-version exploit

2013-04-02 Thread Petr Pisar
On 2013-03-29, Miloslav Trmač wrote: > On Fri, Mar 29, 2013 at 3:01 PM, Petr Pisar wrote: >> On 2013-03-29, Tomas Mraz wrote: >> Basically yes. It's call for semantically separeted API identifier. Now >> you have NEVRA string: >> >> Where we have API? Nowhere because Fedora assumes only one vers

[SOLVED] fedpkg upload errors

2013-04-02 Thread Alexey I. Froloff
Hi, When I tried to run fedpkg upload I got error: Could not execute new_sources: Lookaside failure: (60, "Peer's certificate issuer has been marked as not trusted by the user.") This is how I solved it: certutil -d sql:$HOME/.pki/nssdb -A -i \ $HOME/.fedora-server-ca.cert -n 'Fedora Project

Re: package, package2, package3 naming-with-version exploit

2013-04-02 Thread seth vidal
On Tue, 2 Apr 2013 13:27:43 + (UTC) Petr Pisar wrote: > On 2013-03-29, seth vidal wrote: > >> > >> What's Architecture good for? To allow multilib. To install more > >> instances of the same version. And yum ignores Architecture on > >> purpose. But don't tell anybody that. Otherwise he cou

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Dhiru Kholia
On Tue, Apr 2, 2013 at 6:36 PM, Richard W.M. Jones wrote: > On Tue, Apr 02, 2013 at 05:51:42PM +0530, Dhiru Kholia wrote: >> http://dl.dropbox.com/u/1522424/probable-violations-F19.xls > > That shows: > > > > Can you use a non-proprietary format please. > http://dl.dropbox.com/u/1522424/probable

Re: rawhide report: 20130330 changes

2013-04-02 Thread Vít Ondruch
Dne 30.3.2013 20:02, Kevin Fenzi napsal(a): There's a number of ruby ones. I'm not sure what to do with these. The abi is hard coded, so it would be easy to change and rebuild, but I have no idea if the packages work correctly with the new ruby. Ruby sig folks: Anyone working on these? [aeolus

Re: Using Fedora for Gnome development...

2013-04-02 Thread Mathieu Bridon
On Tuesday, April 02, 2013 08:25 PM, Darryl L. Pierce wrote: On Mon, Apr 01, 2013 at 04:56:34PM -0400, Colin Walters wrote: On Mon, 2013-04-01 at 16:26 -0400, Darryl L. Pierce wrote: When I ran this (which is where I ran into problems) jhbuild installs python3 and its dependencies, which is wh

Re: package, package2, package3 naming-with-version exploit

2013-04-02 Thread Petr Pisar
On 2013-03-29, seth vidal wrote: > On Fri, 29 Mar 2013 14:01:29 + (UTC) > Petr Pisar wrote: > >> >> What's Architecture good for? To allow multilib. To install more >> instances of the same version. And yum ignores Architecture on >> purpose. But don't tell anybody that. Otherwise he could n

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Dhiru Kholia
On Tue, Apr 2, 2013 at 6:36 PM, Richard W.M. Jones wrote: > On Tue, Apr 02, 2013 at 05:51:42PM +0530, Dhiru Kholia wrote: >> http://dl.dropbox.com/u/1522424/probable-violations-F19.xls > > That shows: > > > > Can you use a non-proprietary format please. > Can you try "wget http://dl.dropbox.com/

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Richard W.M. Jones
On Tue, Apr 02, 2013 at 05:51:42PM +0530, Dhiru Kholia wrote: > http://dl.dropbox.com/u/1522424/probable-violations-F19.xls That shows: ^Q^Z^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@>^@^C^@ ^@^F^@^@^@^@^@^@^@^@^@^@^@^F^@^@^@^B^@^@^@^@^@^@^@^P^@^@^@^@^@^@^@^@^@^@^B^@^@^B^@^@^B^@^@^B^@^@^B^@^@^B^@^@ Can yo

F-19 Branched report: 20130402 changes

2013-04-02 Thread Fedora Branched Report
Compose started at Tue Apr 2 09:15:19 UTC 2013 Broken deps for x86_64 -- [aeolus-conductor] aeolus-conductor-0.10.6-2.fc19.noarch requires ruby(abi) = 0:1.9.1 [alexandria] alexandria-0.6.9-4.fc19.noarch requires ruby(abi) >=

Re: Using Fedora for Gnome development...

2013-04-02 Thread Darryl L. Pierce
On Mon, Apr 01, 2013 at 04:56:34PM -0400, Colin Walters wrote: > On Mon, 2013-04-01 at 16:26 -0400, Darryl L. Pierce wrote: > > > When I ran this (which is where I ran into problems) jhbuild installs > > python3 and its dependencies, which is what's borking my day job > > development. > > That's

[Bug 926018] perl-DBI-1.625 is available

2013-04-02 Thread bugzilla
Product: Fedora https://bugzilla.redhat.com/show_bug.cgi?id=926018 Petr Šabata changed: What|Removed |Added Status|ASSIGNED|CLOSED Fixed In Version|

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread Dhiru Kholia
On 04/01/13 at 03:05pm, Dhiru Kholia wrote: > On 04/01/13 at 10:23am, Michael Scherer wrote: > > Le lundi 01 avril 2013 à 12:29 +0530, Dhiru Kholia a écrit : > > > It would be great to have some sort of automated method to find if > > > hardening criteria applies to a particular package. Ideas are

Re: dependency problem with my (first) RPM

2013-04-02 Thread Dario Faggioli
On lun, 2013-04-01 at 13:19 +0200, Miro Hrončok wrote: > Dne 1.4.2013 12:42, Michael Schwendt napsal(a): > > RPM's automatic Perl dependency generator isn't 100% and has found > > something like "use any" in a Perl module or source file. You either > > need to work around that by changing that text

Re: dependency problem with my (first) RPM

2013-04-02 Thread Dario Faggioli
On lun, 2013-04-01 at 12:14 +0200, Reindl Harald wrote: > > Am 01.04.2013 12:02, schrieb Miro Hrončok: > > Dne 1.4.2013 10:17, Dario Faggioli napsal(a): > >> I googled for this quite a bit, but I don't seem to be able to find > >> anything explaining how to make that "Requires: perl(any)" go > >>

Re: dependency problem with my (first) RPM

2013-04-02 Thread Dario Faggioli
On mar, 2013-04-02 at 08:32 +0800, Christopher Meng wrote: > %define _binaries_in_noarch_packages_terminate_build 0 ? > That didn't do anything... Perhaps because what I'm seeing is a `yum install' issue, rather than a `rpmbuild -ba' issue? Thanks anyway, Dario -- <> (Raistlin Majere) --

[Bug 946889] perl-Text-CSV_XS-0.97 is available

2013-04-02 Thread bugzilla
Product: Fedora https://bugzilla.redhat.com/show_bug.cgi?id=946889 Petr Šabata changed: What|Removed |Added Status|ASSIGNED|CLOSED Fixed In Version|

Re: package, package2, package3 naming-with-version exploit

2013-04-02 Thread Vít Ondruch
Dne 29.3.2013 22:49, Nicolas Mailhot napsal(a): This is what I am taking about: http://www.devconf.cz/slides/mls-pkgmgmt2.pdf http://www.youtube.com/watch?v=FNwNF19oFqM The most interesting parts of the presentation IMHO are : 1. the acknowledgement that sometimes, you really need operators su

Re: Expanding the list of "Hardened Packages"

2013-04-02 Thread David Howells
John Reiser wrote: > It's also easy to see the mechanism: > $ cat foo.c > extern int a[]; > > void foo(int j) { a[j]=j; } > $ gcc -m32 -fPIE -O -S foo.c > $ cat foo.s # edited for brevity > foo: # 25 bytes; about 15 cycles (incl. 3*3 cycles data cache fetch latency) > call__x86.get

[heads-up] st license change

2013-04-02 Thread Petr Šabata
Please note that with the 0.4 update (landing in rawhide and f19 now), st has switched from BSD to MIT license. [1] Petr [1] http://lists.suckless.org/dev/1303/15030.html pgpn_yaryx9lo.pgp Description: PGP signature -- devel mailing list devel@lists.fedoraproject.org https://admin.fedoraprojec

Re: any hope for logstash?

2013-04-02 Thread Vít Ondruch
Dne 30.3.2013 03:31, gil napsal(a): Il 30/03/2013 01:16, Carl Byington ha scritto: I am working on packaging logstash http://www.logstash.net/ but the build procedure described here https://github.com/logstash/logstash/wiki/ Building-and-running-logstash-from-source seems to be incompatible

[Test-Announce] OpenStack Test Day today (Tuesday)

2013-04-02 Thread Adam Williamson
It's Test Day time again today, folks. Sorry for the short notice - looks like everyone was expecting someone else to send the announcement mail... Today - 2013-04-02 - is OpenStack Test Day: https://fedoraproject.org/wiki/Test_Day:2013-04-02_OpenStack Please do come out and help us test the