Re: Fedora 37: Add kernel parameters that help prevent local exploits

2022-05-23 Thread Demi Marie Obenour
On 5/23/22 14:50, Steve Grubb wrote: > Hello, > > On Wednesday, May 18, 2022 11:15:16 PM EDT Hellosway Here via devel wrote: >> Add `slab_nomerge init_on_alloc=1 init_on_free=1 page_alloc.shuffle=1 >> pti=on randomize_kstack_offset=on vsyscall=none ` as default kernel >> command line arguments. Th

Re: Fedora 37: Add kernel parameters that help prevent local exploits

2022-05-23 Thread Glorious Hellosway via devel
This thread was accidentally reposted, please reply to this one https://lists.fedorahosted.org/archives/list/devel@lists.fedoraproject.org/thread/YJ4HKHMLBGCSXZ3S3NSTSARTJNAG7NXC/ . I think it would be useful is there was a centralized CLI and GUI intyerface for these, but it doesn't exist yet.

Fedora-IoT-36-20220523.0 compose check report

2022-05-23 Thread Fedora compose checker
No missing expected images. Failed openQA tests: 2/15 (x86_64), 3/15 (aarch64) Old failures (same test failed in Fedora-IoT-36-20220520.0): ID: 1276950 Test: x86_64 IoT-dvd_ostree-iso iot_zezere_server@uefi URL: https://openqa.fedoraproject.org/tests/1276950 ID: 1276957 Test: x86_64 IoT-

Re: F37 proposal: Enhance Persian Font Support (Self-Contained Change proposal)

2022-05-23 Thread Sebastian Crane
As something of a typography enthusiast, I'm very much in support of this. For English, the consistent fonts on Fedora Workstation make a noticeable and positive effect on the general aesthetic, so anything that can widen that benefit would be advantageous. I did notice that the 'How to Test' sect

Re: F37 proposal: Build all JDKs in Fedora against in-tree libraries and with static stdc++lib (System-Wide Change proposal)

2022-05-23 Thread Guido Aulisi
Hi, > Il giorno 10 mag 2022, alle ore 15:29, Ben Cotton ha > scritto: > > https://fedoraproject.org/wiki/Changes/JdkInTreeLibsAndStdclibStatic > > This document represents a proposed Change. As part of the Changes > process, proposals are publicly announced in order to receive > community feed

Re: Fedora 37: Add kernel parameters that help prevent local exploits

2022-05-23 Thread Steve Grubb
Hello, On Wednesday, May 18, 2022 11:15:16 PM EDT Hellosway Here via devel wrote: > Add `slab_nomerge init_on_alloc=1 init_on_free=1 page_alloc.shuffle=1 > pti=on randomize_kstack_offset=on vsyscall=none ` as default kernel > command line arguments. This can help prevent local exploits by making i

Re: F37 proposal: Build all JDKs in Fedora against in-tree libraries and with static stdc++lib (System-Wide Change proposal)

2022-05-23 Thread Kevin Fenzi
So, just replying here since this is a nice monster of a thread. ;( First, just to clear up some previous coments, shim does build against the oldest stable Fedora in koji and then is manually tagged into newer ones. This is not at all a good process. It only gets a bodhi update for the one relea

Re: F37 proposal: Enhance Persian Font Support (Self-Contained Change proposal)

2022-05-23 Thread Michael Catanzaro
On Mon, May 23 2022 at 11:54:30 AM -0400, Ben Cotton wrote: Default Persian font will be changed automatically on upgrades. Good, but how will you achieve this? We finally noticed that noto fonts don't get installed when upgrading F35 -> F36 and should avoid making the same mistake again. ..

Re: F36 release retrospective

2022-05-23 Thread Ben Cotton
As a reminder, the F36 release retrospective survey is open through 27 May: https://fedoraproject.limequery.com/36 It should only take a few moments of your time. No matter how you participated in the development and release of F36, I'd like your input. (Remember, this is about the process of prod

F37 proposal: Enhance Persian Font Support (Self-Contained Change proposal)

2022-05-23 Thread Ben Cotton
https://fedoraproject.org/wiki/Changes/EnhancePersianFontSupport This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the Fedora Engineering Steerin

Some docs repos are moving to GitLab

2022-05-23 Thread Ben Cotton
On behalf of the Docs team, I want to share that we'll be moving the repos that the Docs team maintains to GitLab. Note that this does not require any other teams to move their repos. For more details, see our Community Blog post: https://communityblog.fedoraproject.org/some-docs-repos-are-moving-t

Fedora-Rawhide-20220523.n.0 compose check report

2022-05-23 Thread Fedora compose checker
Missing expected images: Minimal raw-xz armhfp Compose FAILS proposed Rawhide gating check! 5 of 43 required tests failed, 1 result missing openQA tests matching unsatisfied gating requirements shown with **GATING** below Failed openQA tests: 46/231 (x86_64), 30/152 (aarch64) New failures (sam

Re: F37 Proposal: Strong crypto settings: phase 3, forewarning 1/2 (System-Wide Change proposal)

2022-05-23 Thread Ian Pilcher
On 5/2/22 08:56, Ian Pilcher wrote: IMO, there's a rather desperate need to be able to override the system- wide policy for individual processes, maybe via some sort of wrapper around one of the containerization technologies. Just FYI, I managed to bang out a proof of concept of a "wrapper" tha

Re: Heads up: openjpeg2-2.5.0 and gdal-3.5.0 coming to rawhide

2022-05-23 Thread Mamoru TASAKA
Sandro Mani wrote on 2022/05/23 3:39: Hi - gazebo fails to build due to "cannot convert 'ALCdevice*' to 'ALCdevice_struct*' in assignment", which looks like an openal-soft-1.21 incompatibility. Possibly updating gazebo from the currently packaged v10.1.0 to current upstream version 11.10.2 mi

Fedora rawhide compose report: 20220523.n.0 changes

2022-05-23 Thread Fedora Rawhide Report
OLD: Fedora-Rawhide-20220522.n.0 NEW: Fedora-Rawhide-20220523.n.0 = SUMMARY = Added images:0 Dropped images: 1 Added packages: 0 Dropped packages:2 Upgraded packages: 204 Downgraded packages: 0 Size of added packages: 0 B Size of dropped packages:17.58

Fedora-Cloud-34-20220523.0 compose check report

2022-05-23 Thread Fedora compose checker
No missing expected images. Soft failed openQA tests: 1/8 (x86_64), 1/8 (aarch64) (Tests completed, but using a workaround for a known bug) Old soft failures (same test soft failed in Fedora-Cloud-34-20220522.0): ID: 1276382 Test: x86_64 Cloud_Base-qcow2-qcow2 cloud_autocloud URL: https://op

Re: How much free space in /var is required for upgrades?

2022-05-23 Thread Panu Matilainen
On 5/16/22 13:39, Panu Matilainen wrote: On 5/13/22 21:54, Jason L Tibbitts III wrote: So I went to do a dnf system-upgrade from F35 to F36 on a test machine, as part of my usual testing.  In the middle of the process, it appears that /var filled up and that left the system in an unfortunate sta

Re: grub2 BIOS booting iso and code

2022-05-23 Thread Thomas Schmitt
Hi, another experiment proposal for Dominik 'Rathann' Mierzejewski: Zeroize the GPT of a copy of boot-grub2-f36.iso and adjust MBR partition 1. Do this in bash for the $'\x...' gestures: # Create the playground cp boot-grub2-f36.iso test.iso # Zeroize the main GPT dd if=/dev/zero bs=1 s

Re: What happened to umask?

2022-05-23 Thread Pavel Zhukov
Owen Taylor writes: > For years, Red Hat Linux / Fedora systems have had a umask of 0002 for > regular users as part of the "user private group" scheme [*]. Basically the > idea is that > you can set a directory group-sticky and use it as a common work area for a > group of users. > > A chang