Re: F36 Change: Make Rescue Mode Work With Locked Root (System-Wide Change proposal)

2021-12-07 Thread Björn Persson
in this new release of this particular distribution they need to run this special command to prevent boot problems from granting root access to whoever can type on the keyboard. Björn Persson pgpUpKi2TnP15.pgp Description: OpenPGP digital signatur __

Re: F36 Change: Make Rescue Mode Work With Locked Root (System-Wide Change proposal)

2021-12-08 Thread Björn Persson
Chris Adams wrote: > Once upon a time, Björn Persson said: > > Chris Adams wrote: > > > If the admin has done one thing to lock down the system, then they can > > > do another (removing the sulogin --force addition). > > > > How do you propose to ens

Re: F36 Change: Make Rescue Mode Work With Locked Root (System-Wide Change proposal)

2021-12-09 Thread Björn Persson
this case, Grub should also by default require root's or a wheel user's passphrase before boot parameters can be changed. That is consistent. Björn Persson pgpcT9reGtFmi.pgp Description: OpenPGP digital signatur ___ devel mailing list -- d

Re: F36 Change: Make Rescue Mode Work With Locked Root (System-Wide Change proposal)

2021-12-09 Thread Björn Persson
oot entry for the rescue mode, then maybe Grub could be programmed to require a passphrase before it will boot that entry? Björn Persson pgp1LnefA7iK9.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fed

Re: new systemd in rawhide

2021-12-10 Thread Björn Persson
lse' > or similar, please make sure that you install those libraries too if > appropriate. Was "not" supposed to be "now"? Otherwise these statements don't make sense together. Björn Persson pgpz2V_ix2CZt.pgp Description: OpenPGP digital signatur __

Re: New tool - license-validate

2021-12-27 Thread Björn Persson
Miroslav Suchý wrote: > $ license-validate-v'GPL or (MIT and BSD)' >     No terminal defined for 'G' at line 1 col 1 Approximately nobody will understand "No terminal defined for 'G'". Can the error message be improved? Björn Persson pgp5AIXhm

Re: gcc-12.0.0-0.4.fc36 in rawhide

2022-01-17 Thread Björn Persson
https://bugzilla.redhat.com/show_bug.cgi?id=2041667 Björn Persson pgpaayNBpxRq6.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of C

Re: Do we have any policy for disabling inactive users

2022-02-11 Thread Björn Persson
Thus an open Bugzilla ticket is no indication that the package is unmaintained. You need to check what version is actually in Rawhide. If the Bugzilla tickets should in fact not be left open, then they should be automatically closed just like they're automatically opened. Björn Persson

Re: Do we have any policy for disabling inactive users

2022-02-11 Thread Björn Persson
Ben Cotton wrote: > I would support removing the 113 who don't exist in Koji. If they have been that way for a long time, I suppose. Don't cause additional hurdles for newcomers just because their first review takes a while. Björn Persson pgp11SGC3hJR2.pgp Description: OpenPGP dig

Re: Do we have any policy for disabling inactive users

2022-02-15 Thread Björn Persson
ddress – and set a new email address in their account. Entering the old email address again would be allowed, in case they have recovered the domain, but they would have to prove that they can receive a confirmation message regardless of whether the new address is the same as the old a

Re: Do we have any policy for disabling inactive users

2022-02-16 Thread Björn Persson
Vitaly Zaitsev via devel wrote: > On 15/02/2022 19:43, Björn Persson wrote: > > The packager would then be required to authenticate with their existing > > credentials – or prove their identity in some way that does not rely on > > ownership of the email address – and set a

Preventing account takeovers through expired domains (was: Do we have any policy for disabling inactive users)

2022-02-19 Thread Björn Persson
tep 6 cannot happen before step 3. That way the Fedora Project could reliably prevent this kind of attack. I hope this explanation is clear enough to be understood. In case of TL;DR, the short version is four posts upthread from here. So, does step 3 exist? Björn Persson pgpPIYU3U_oGq.pgp Descri

Re: Preventing account takeovers through expired domains

2022-02-19 Thread Björn Persson
efore the domain is released for registration. Let's just not make it so tight that a little unscheduled downtime can open an attack window. Björn Persson pgpqiv4u1U4Nr.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@li

Re: Preventing account takeovers through expired domains

2022-02-20 Thread Björn Persson
Mattia Verga via devel wrote: > Il 19/02/22 19:38, Björn Persson ha scritto: > > Zbigniew Jędrzejewski-Szmek wrote: > >> I think it'd be better to check the status weekly and only require > >> account reconfirmation if the quarantine status is detected ⌊N / 7 -

2FA (was: Preventing account takeovers through expired domains)

2022-02-20 Thread Björn Persson
Demi Marie Obenour wrote: > Security keys are the only form of 2fa that is immune to > phishing attacks. U2F and FIDO2 are said to be immune to phishing. HOTP, TOTP and various proprietary challenge-respone protocols are not immune. Björn Persson pgp_7IhtLa4JI.pgp Description: OpenPGP d

2FA (was: Preventing account takeovers through expired domains)

2022-02-21 Thread Björn Persson
instead of retyping. (Still not as good as U2F of course.) Björn Persson pgpxs9kMwtLFb.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fe

Re: F37 Change: Curl-minimal as default (System-Wide Change proposal)

2022-02-22 Thread Björn Persson
curl-minimal suited only for programs that only communicate with a predefined set of servers in ASCII-only domains. Any program that accepts user-provided URLs will need curl-full to be able to handle arbitrary domain names, even if the program speaks only HTTPS, HTTP and FTP. Björn Persson pgp4a

Re: F37 Change: Curl-minimal as default (System-Wide Change proposal)

2022-02-23 Thread Björn Persson
people will start using it? Guess what – everybody else is also waiting for everybody else. This is the same deadlock that hampers IPv6, encrypted email and many other things. Everybody's waiting for everybody else to move first. Björn Persson pgp90R61gv1GJ.pgp Description: OpenPGP digital

Re: F37 Change: Curl-minimal as default (System-Wide Change proposal)

2022-02-23 Thread Björn Persson
would impact me if I had a private mirror, but I don't. For downloading files from a command line, my habit is to use Wget, so I guess I'm dodging that bullet. Björn Persson pgpBhrzmDJc5Y.pgp Description: OpenPGP digital signatur ___

Re: F37 Change: Curl-minimal as default (System-Wide Change proposal)

2022-02-24 Thread Björn Persson
Kamil Dudka wrote: > There seems to be demand for libcurl with IDN support on minimal Fedora > installations, so I created a pull request to enable it in libcurl-minimal: > > https://src.fedoraproject.org/rpms/curl/pull-request/13 Thank you. Björn Persson pgp2ZEu96gtIM.pgp

Re: Linux Plumbers Conference - Open Printing Micro Conference

2021-09-21 Thread Björn Persson
Zdenek Dohnal wrote: > the schedule for the first no-driver was proposed What is a no-driver? Björn Persson pgp8IziBk8gfn.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an em

crypto-policies and a certain usage of SHA-1

2021-10-15 Thread Björn Persson
se anyone wants to test things themself. Björn Persson pgptX2bBu9PZE.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org

Re: crypto-policies and a certain usage of SHA-1

2021-10-16 Thread Björn Persson
place the key every few hours or days. The Signature field is different every time though. Thus I'm not sure whether the attacker's time limit is the lifetime of the key (which Fedora can't control) or the TCP timeout. Björn Persson pgptnItUABZ9M.pgp

Re: F36 Change: Remove .la files from buildroot (Self-Contained Change proposal)

2021-11-01 Thread Björn Persson
the file's content, then I think the script should do that to verify that files with a ".la" suffix really are Libtool archives before deleting them. Björn Persson pgp2yAnXNNShR.pgp Description: OpenPGP digital signatur ___ d

Re: Review request for oclock package (orphaned since F35)

2021-11-23 Thread Björn Persson
tarball. So don't do that. Björn Persson pgpuxCuE5BI4x.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https:

Re: (Quite?) OT Question: Is still relevant Software RAID?

2021-12-02 Thread Björn Persson
and BTRFS, not clouds or devops. But the licensing situation makes ZFS painful, and BTRFS seems to take forever to mature, so it should be expected that many people will choose software RAID instead. Björn Persson pgpK9xoq79ydL.pgp Description: Ope

Re: F36 Change: Enable fs-verity in RPM (System-Wide Change proposal)

2021-12-04 Thread Björn Persson
this change is authorized? Do I disable FS-verity for that specific file? Disable FS-verity globally? Add my own key to the kernel's keyring? Build and sign my own RPM package? What prevents an attacker from doing the same? Will files under /etc be covered, or will local configuration still be possi

Re: script to run after hotspot authentication?

2018-04-24 Thread Björn Persson
Paul Wouters wrote: > So I guess the problem that is used is > /usr/libexec/gnome-shell-portal-helper Writing "problem" instead of "program" seems quite appropriate, given the quality of most software in the world. Björn Persson pgpC0reNedOSb.pgp Description

Re: Fedora 28 Final status is GO

2018-04-27 Thread Björn Persson
In Fedora "guidelines" usually means "strict regulations". :-Þ Björn Persson pgphM5zEOKLsN.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org

Re: Prioritizing ~/.local/bin over /usr/bin on the PATH

2018-05-07 Thread Björn Persson
another consequence of not designing a programming language with enough forethought to make future versions backward-compatible. I suppose we'll get rid of it some day when all Sphinx plugins have been ported to Python 3. Björn Persson pgpGS9jbFl0wQ.pgp Description: OpenPGP digital signatu

Re: "invalid path: ~/.fedora-server-ca.cert"

2018-05-11 Thread Björn Persson
ture, and shouldn't be expected to work if the pathname isn't processed by a shell. Unless Fedpkg promises shell-like expansion features, that pathname truly is invalid. I don't know why you didn't have this problem earlier. Perhaps it worked by accident before because a shell wa

Re: Hiding the grub menu by default on single OS installs

2018-05-31 Thread Björn Persson
der as simple and straightforward as possible to minimize the risk of problems. I would hate to run into some bug that renders the system unusable, and then find that I can't do anything about it because a separate bug causes Grub to not display the boot menu. Björn Persson pgpn63RGL_xa

Re: Prioritizing ~/.local/bin over /usr/bin on the PATH

2018-06-15 Thread Björn Persson
h > such POC already _has_. Please post your proof of concept so that people can discuss some actual code instead of vague and unsubstantiated claims. Don't forget that if your proof of concept can be modified to either overwrite or append to ~/.bashrc, then it's irreleva

Re: Prioritizing ~/.local/bin over /usr/bin on the PATH

2018-06-16 Thread Björn Persson
Tomasz Kłoczko wrote: > On Fri, 15 Jun 2018 at 23:21, Björn Persson wrote: > [..] > > Don't forget that if your proof of concept can be modified to either > > overwrite or append to ~/.bashrc, then it's irrelevant to this debate. > > before ~/.bashrc is execu

Re: Prioritizing ~/.local/bin over /usr/bin on the PATH

2018-06-16 Thread Björn Persson
really* sick of all the security by handwaving that's going on in this thread. Could everybody please discuss *relevant* attack scenarios, instead of scenarios that begin with the attacker already having so much access that the value of PATH doesn't matter? Bj

Re: Prioritizing ~/.local/bin over /usr/bin on the PATH

2018-06-17 Thread Björn Persson
Tomasz Kłoczko wrote: > Just please add /usr/local/bin/id text file with content: > > #!/bin/sh > echo "No one expects The Spanish Inquisition!" > exec /usr/bin/id $* I can't: bash: /usr/local/bin/id: Permission denied Björn Persson pgpmM0qMeoYoJ.pgp Descrip

Re: Prioritizing ~/.local/bin over /usr/bin on the PATH

2018-06-18 Thread Björn Persson
t holds water. I jumped into this debate because I couldn't stomach all the "It's insecure because handwaving." and "It's insecure because I've said so several times.". Björn Persson pgpJCfL1Me0sp.pgp Description: OpenPGP digital signatur __

Re: Prioritizing ~/.local/bin over /usr/bin on the PATH

2018-06-18 Thread Björn Persson
Nico Kadel-Garcia wrote: > On Sat, Jun 16, 2018 at 11:38 AM, Björn Persson wrote: > > Nico Kadel-Garcia wrote: > >> On Fri, Jun 15, 2018 at 12:55 PM, Till Maas wrote: > >> > So the assumption is to have a super sophisticated browser exploit for > >>

Re: Prioritizing ~/.local/bin over /usr/bin on the PATH

2018-06-22 Thread Björn Persson
updates (except that one which will > remove ~/.local/bin/ from the $PATH) would be able to stop damage ones > done. > > Would you consider now classify such change as serious vulnerability > introduction? If you state a falsehood again and again it will eventually become true? Bjö

Re: Prioritizing ~/.local/bin over /usr/bin on the PATH

2018-06-22 Thread Björn Persson
't likely to break something unrelated. That's one reason why I'm not convinced that this change is a good idea. It obviously has nothing to do with security though. It's a matter of safety, which is different from security. Björn Persson pgpNNmJlUq98I.pgp Descr

Re: Prioritizing ~/.local/bin over /usr/bin on the PATH

2018-06-24 Thread Björn Persson
Till Maas wrote: > On Fri, Jun 22, 2018 at 07:24:54PM +0200, Björn Persson wrote: > > Till Maas wrote: > > > I do not see any reason why a user would put something in ~/bin that > > > would mask something in /usr/bin except to actually mask the binary. It > &

Re: F29 Self Contained Change: Deprecate YUM 3

2018-06-27 Thread Björn Persson
> Remove yum (v3) and all related packages from Fedora. > > > > > > == Detailed description == > > Remove packages from the distribution > > IMHO deprecate != remove, but rather mark for removal in some next release. > > Should the change be called differently

Re: Schedule for Wednesday's FESCo Meeting (2021-01-13)

2021-01-13 Thread Björn Persson
or agreeing on a meeting time across borders. Björn Persson pgpVdptJ6P7EG.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Cond

Re: Jami (formerly Ring) P2P softphone packaging?

2021-02-02 Thread Björn Persson
ly > does voice and IM could that provide a way forward? If that would remove the dependency on FFMPEG, then I suppose that would work around that problem at least. You could also try packaging Jami in RPM Fusion, if FFMPEG is the only obstacle. Björn Persson pgp2kmhXTqIh7.pgp Description: Op

Re: Fedora's GPG key in DNS(SEC)

2021-02-12 Thread Björn Persson
he sha256sum step.) According to the manual, GnuPG can look up keys in DNS in various ways, but it tries only Web Key Directory by default. I think therefore that the greatest advantage of publishing the keys in DNS is that it can help with verifying installation images, but it might be even

Re: Bodhi client prompting for a password

2021-03-03 Thread Björn Persson
use different methods for > authenticating with your FAS account. > > koji uses kerberos, bodhi uses OpenID over HTTP, dist-git uses SSH ... It wouldn't be a user interface problem if they'd all fetch the passcode from the same keyring. Then the user wouldn't need to know h

Re: F34 gdm login prompt goes crazy when a fingerprint reader with no enrolled prints is present

2021-03-07 Thread Björn Persson
ariety of MUAs can pick up the emails from /var/spool/mail. But I guess those who want fewer daemons won't be happy to see Postfix added just for a chance to be warned about an imminent breakdown. Björn Persson pgpK7UBRzp74e.pgp Description: OpenPGP digital signatur

Re: F34 gdm login prompt goes crazy when a fingerprint reader with no enrolled prints is present

2021-03-07 Thread Björn Persson
x27;s a kernel thread called "edac-poller", so I don't know whether the runtime overhead is any lower. Björn Persson pgpxIV_q_B1uk.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedorapro

Re: F34 gdm login prompt goes crazy when a fingerprint reader with no enrolled prints is present

2021-03-08 Thread Björn Persson
Matthew Miller wrote: > On Sun, Mar 07, 2021 at 10:26:50AM +0100, Björn Persson wrote: > > > It can, but most people don't have a good setup for even local mail > > > delivery. Out of the box, we don't really do anything useful. > > It wouldn't tak

Re: Fedora's GPG key in DNS(SEC)

2021-03-08 Thread Björn Persson
ess is trusted. You state that the DNS server isn't necessarily in the same domain as the repository, so it's not as simple as comparing the domain names. Could you explain how the email address is validated? Björn Persson pgpKpG3Y0YPHa.pgp Descript

Re: python noarch packaging vs pip install

2021-03-08 Thread Björn Persson
-a-week/ https://arstechnica.com/information-technology/2021/02/supply-chain-attack-that-fooled-apple-and-microsoft-is-attracting-copycats/ Björn Persson pgplQo4tEGPPu.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproje

Re: F35 Change: "Fedora Linux" in /etc/os-release

2021-03-10 Thread Björn Persson
ething like "Fedora Family", because it's a number of closely related distributions which are suitable for use at home? Or something like "Fedora Flow", alluding to frequent releases and a steady stream of updates? Björn Persson pgpQIZfjHla23.pgp Description: OpenPGP digit

Re: F35 Change: "Fedora Linux" in /etc/os-release

2021-03-10 Thread Björn Persson
Fedora is a software distribution. It contains Linux, many GNU components, RPM, MariaDB, Libreoffice and lots of other things, but its name is "Fedora". Or call it "Fedora Software Distribution" or anything else that doesn't single out any of the components. That approac

Re: F35 Change: "Fedora Linux" in /etc/os-release

2021-03-10 Thread Björn Persson
a CoreOS, not Fedora Linux" makes no sense either, because Fedora CoreOS would be a subset of Fedora Linux if I understand you correctly. Björn Persson pgp4m8hB5HQ1s.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedo

Re: F35 Change: "Fedora Linux" in /etc/os-release

2021-03-10 Thread Björn Persson
/apache2, /etc/apache2, apache2.service and so on. That's a real nuisance. Working with both Debian and CentOS I always have trouble remembering whether it's /etc/apache2 or /etc/httpd, and apache2.service or httpd.service. Both have apachectl though, not httpctl. Björn Persson pgpM4

Re: OpenSSH SHA-1 deprecation, developing FAQ, etc

2021-03-12 Thread Björn Persson
e release notes seem to use "signature scheme" and "signature algorithm" interchangeably, and the manual uses "host key algorithms" and "key types" when it seems to actually be talking about signature schemes. Björn Persson pgpueXa4thwTm.pgp Description: OpenPG

Re: Fedora Account Migration & Production Deployment Update: COMPLETE!

2021-03-26 Thread Björn Persson
your password, so it doesn't > really play nice with password managers. Such kludges shouldn't be exposed in user interfaces if it can be avoided. A web interface should be able to receive two strings in two separate fields, and concatenate them if the backend requires that. Björn Perss

Re: Fedora Account Migration & Production Deployment Update: COMPLETE!

2021-03-27 Thread Björn Persson
done in the login session, then successful attacks will be less frequent, because then the attacker first needs the victim's passphrase. Side-channel authentication is a design flaw none the less. There's no point to having a second factor if it's so weak that the security depends mos

Re: Fedora Account Migration & Production Deployment Update: COMPLETE!

2021-03-27 Thread Björn Persson
That turns the "security question" into a backup passphrase. If you want people to do this, then it's better to ask them to make up a passphrase. Björn Persson pgpE8zuWQSxko.pgp Description: OpenPGP digital signatur ___ devel mailing list -- d

Re: Fedora Account Migration & Production Deployment Update: COMPLETE!

2021-03-28 Thread Björn Persson
ing that a word like "Jamaica" is useful as a password – if it's checked server-side that the two passwords are not similar – but it's not two-factor authentication if both passwords are stored in the same password manager. I'm not going to speculate on how you mean that &qu

Re: F35 Change proposal: RPM 4.17 (System-Wide Change proposal)

2021-04-07 Thread Björn Persson
/886 I think that's a good idea. If it gets implemented, then we can remove check-rpaths from the Ada spec files – but there might be other similar usecases where something runs in %check to check files in the buildroot, which would break if %check would be moved before %install. Björn Persson

License changes in Gnatcoll packages

2021-04-09 Thread Björn Persson
GPLv3+ with exceptions. gnatcoll-gmp, gnatcoll-readline and gnatcoll-xref are still GPLv3+. Björn Persson pgpuCeu2ODDUt.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to

Re: F35 Change: Debuginfod By Default (Self-Contained Change proposal)

2021-04-10 Thread Björn Persson
how a network problem can impact the usability of debugging tools. Could it for example make GDB hang for a minute every time it encounters a new source filename? Finally, if somebody doesn't like the answers to the above questions, then they'll want to know how to disable the feature.

Re: F35 Change: Debuginfod By Default (Self-Contained Change proposal)

2021-04-21 Thread Björn Persson
Frank Ch. Eigler wrote: > Björn Persson writes: > > > · How is it verified that files received from debuginfo servers have not > > been tampered with? > > Following up further to this, we're planning to add optional client-side > hash-verification of

Re: F35 Change: Debuginfod By Default (Self-Contained Change proposal)

2021-04-21 Thread Björn Persson
/.var/app/org.gnome.Tetravex/cache/debuginfod_client/a2429c266188acc10181f6936915f35274bb4a38/debuginfo > Downloading separate debug info for /lib64/libcap.so.2... I was wondering what the user experience would be like in such a situation. Could you estimate how long you had to wait in tota

Re: F35 Change: Debuginfod By Default (Self-Contained Change proposal)

2021-04-22 Thread Björn Persson
eouts should not be happening any more. It is however a good illustration of how a network problem can destroy the user experience. Five minutes is a long wait. I'm glad that we now have this information. Björn Persson pgpaB8snU3QuR.pgp Description: OpenPGP digital signatur __

Re: F35 Change: Debuginfod By Default (Self-Contained Change proposal)

2021-04-22 Thread Björn Persson
Frank Ch. Eigler wrote: > Björn Persson writes: > > And as you noted yourself, an attacker who can manipulate cached files > > client-side has already taken over the user account anyway. > > Yes and no, and so I must disagree with your "won't improve ... for

Re: F35 Change: CompilerPolicy Change (System-Wide Change proposal)

2021-04-23 Thread Björn Persson
, compiler, assembler, linker and whatever else may be involved. Björn Persson pgp_UDSFlTZ8_.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.f

Upgrade to Fedora 34 broke the boot menu.

2021-05-08 Thread Björn Persson
Which component in Bugzilla might be responsible for this mess? Björn Persson pgpbycvIEd1Uy.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraprojec

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-08 Thread Björn Persson
Neal Gompa wrote: > On Sat, May 8, 2021 at 8:53 AM Björn Persson wrote: > > > > I used yum system-upgrade to upgrade from Fedora 32 to Fedora 34. Now > > Grub complains about not finding some theme files, and then displays a > > menu with two kernels from Fedora 29 and

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-08 Thread Björn Persson
Tomasz Torcz wrote: > Dnia Sat, May 08, 2021 at 02:51:31PM +0200, Björn Persson napisał(a): > > I used yum system-upgrade to upgrade from Fedora 32 to Fedora 34. Now > > Grub complains about not finding some theme files, and then displays a > > Missing theme files

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-08 Thread Björn Persson
ub.cfg That file contains the outdated menu entries I described. Is there a way to recreate it from the Dracut shell, or with the filesystem temporarily mounted on another Fedora 32 system? Björn Persson pgpwCgzgHgw6P.pgp Description: OpenPGP digital signatur _

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-08 Thread Björn Persson
should get, none of the outdated entries I actually see. Björn Persson pgpz23pXbFgYJ.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fed

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-09 Thread Björn Persson
situations like this.) Then I ran "grub2-mkconfig -o /boot/grub2/grub.cfg" to get the boot working normally. Björn Persson pgpOIohB2HgVJ.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To u

Re: Upgrade to Fedora 34 broke the boot menu.

2021-05-11 Thread Björn Persson
using and updating /boot/grub2/grub.cfg, leaving /boot/efi/EFI/fedora/grub.cfg to go stale, and the upgrade replaced the file in use with the stale one. This would mean that different programs have different ideas about which grub.cfg is in use. See also https://bugzilla.redhat.com/show_bug.cgi?id=195

Re: When is pappl going to be good enough to replace cups?

2021-05-22 Thread Björn Persson
er how I will know whether I'm sending my sensitive document to my USB printer or to some impostor on a wifi network. I wish working software could just continue working. Obviously that's far too sane for this insane world. Björn Persson pgpN_tzgp_dVv.pgp Description: OpenPGP digital sig

Re: When is pappl going to be good enough to replace cups?

2021-05-24 Thread Björn Persson
ices that trust the wifi network to protect them. Assuming that all the nodes on the local link are friendly is criminally naïve. Björn Persson pgpLHHjA7RfBz.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject

Re: When is pappl going to be good enough to replace cups?

2021-05-25 Thread Björn Persson
printer and an auto-found printer, so I can continue to have my printer configured and know that I'm sending to that one? Do I need to explain, detail by detail, the errors in the reasoning "People don't print on untrusted networks. Therefore any network with a printer on it is trusted.

Re: When is pappl going to be good enough to replace cups?

2021-05-26 Thread Björn Persson
printer name/identifier just > so they can capture a document *you* want to print, but if there's that > level of persistant hostile presence on your local network, you're > already completly screwed. I would be if I would use insecure protoco

Re: When is pappl going to be good enough to replace cups?

2021-05-26 Thread Björn Persson
ected by USB, and I would like to continue to have that choice. Björn Persson pgp2GJIq_HFQB.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fed

Re: When is pappl going to be good enough to replace cups?

2021-05-26 Thread Björn Persson
Solomon Peachy wrote: > On Wed, May 26, 2021 at 08:15:46PM +0200, Björn Persson wrote: > > And I always try to avoid using protocols that assume that the local > > link is secure. That's one of the reasons why my printer is connected by > > USB, and I would like to co

Re: When is pappl going to be good enough to replace cups?

2021-05-27 Thread Björn Persson
;. For any reasonable reading of the manual, "BrowseLocalProtocols none" should have the same effect as "Browsing No". It seems safest to turn off both, but I'm not at all sure whether that prevents network printers from showing up in my print dialogs. B

Re: Landing a larger-than-release change (distrusting SHA-1 signatures)

2022-03-15 Thread Björn Persson
d around by temporarily adding "SHA1" to /etc/crypto-policies/back-ends/nss.config. Björn Persson pgpQmPo25Lqfu.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send

Re: F37 Change: Deprecate Legacy BIOS (System-Wide Change proposal)

2022-04-06 Thread Björn Persson
o Fedora. I use this laptop to develop and test performance measurement tools. It handles build jobs, testsuites and virtual machines just fine. The days when a three-year-old computer was too slow to be useful are long gone. Björn Persson pgp52J6uYF2PH.pgp Description: Ope

Re: F37 Change: Deprecate Legacy BIOS (System-Wide Change proposal)

2022-04-06 Thread Björn Persson
7;s still dangerous to let known security holes accumulate. Björn Persson pgpzXxjDRbutY.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.

Re: GNOME Online Accounts "Fedora" - Pre-authentication failed

2022-04-08 Thread Björn Persson
er's brain is the other factor. In that case a TOTP seed stored in a Yubikey becomes a third factor. Björn Persson pgpBJJfbjJHPN.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsu

Re: GNOME Online Accounts "Fedora" - Pre-authentication failed

2022-04-08 Thread Björn Persson
that requires authentication, if the previous ticket has expired. Don't ask for authentication just for the sake of renewing a ticket when the user is doing something else. That would teach users dangerous habits. Björn Persson pgpkW8N6aTay3.pgp Description: OpenP

Re: Would it be useful to have a video call to discuss the "Deprecate Legacy BIOS" Change proposal?

2022-04-15 Thread Björn Persson
up with the software's demands, but that takes much longer than ten years nowadays. Björn Persson pgpZ7ENGcIhpJ.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-

Re: Would it be useful to have a video call to discuss the "Deprecate Legacy BIOS" Change proposal?

2022-04-15 Thread Björn Persson
way, the forum post is an example of a user who is dissatisfied with UEFI for some reason, and wants to boot in BIOS mode instead. Dropping BIOS-boot support from Fedora would presumably not make that person any happier. Björn Persson pgpTOibEFEGtI.pgp Description: OpenPGP digital signatur ___

Re: verifying signature for a package

2022-04-17 Thread Björn Persson
rson who signed the Xfontsel tarball. Once you have the key, remember to pass all three parameters to gpgverify: --keyring, --signature and --data. Björn Persson pgpcFSmHuVaks.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@list

Re: verifying signature for a package

2022-04-17 Thread Björn Persson
t be confusing. Björn Persson pgpTL5tFH4atr.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fed

Re: Change proposal: make Change proposals more obvious

2022-04-28 Thread Björn Persson
m-Wide Change proposal)" Once you write "proposal", the word "change" becomes rather redundant. What proposal doesn't propose any kind of change? If somebody doesn't want to change anything, they won't write a proposal. Björn Persson pgp8oC

Re: Preventing supply chain attacks via rekor

2021-06-11 Thread Björn Persson
less animation. Even the text that is right there in the HTML code is hidden. Instead it wants me to execute a bunch of Javascript from at least three different domains. When a website expects me to execute some unknown program before they'll even tell me who they are or what they

Re: x86_64-v2 in Fedora

2021-06-16 Thread Björn Persson
vbe/&&/xsave/) > level = 3 > if (level == 3 && > /avx512f/&&/avx512bw/&&/avx512cd/&&/avx512dq/&&/avx512vl/) level = 4 > if (level > 0) { print "CPU supports x86-64-v" level; exit level + 1 } > exit 1 > }

Re: Using "Open location" in GIMP causes a (sometimes) catastrophic crash

2021-06-19 Thread Björn Persson
might be caused > by limited system resources. From the provided error message it looks > like insufficient RAM/buffer size. Perhaps limiting the length of the error message could prevent overuse of system resources? I doubt anyone actually wants a super-wide alert window. Björn Persson pgp

Re: Why so long for EPEL-8?

2021-07-19 Thread Björn Persson
sy at the time. I don't know a convenient way to do that, so I end up installing updates when they show up in the updates repository. Björn Persson pgpvoA3f6hGTK.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fed

Re: Systemd unit files installed into unowned directories

2021-08-05 Thread Björn Persson
is rather similar to /usr/share/bash-completion, /usr/share/man, /usr/share/info and various other directories that filesystem owns. Björn Persson pgpM1c3jmu0yS.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel@lists.fedoraprojec

Re: Specfile description and summary translations

2021-08-19 Thread Björn Persson
slations of RPM descriptions and summaries, which is sad, but in that case there certainly shouldn't be a "SHOULD" in the Review Guidelines. Björn Persson pgpCtFKpUoKUK.pgp Description: OpenPGP digital signatur ___ devel mailing list -- devel

Re: Fedora 42: The Answer to Life, The Universe and Everything

2024-11-04 Thread Björn Persson
Daniel P. Berrangé wrote: > We would need to get legal clearance to use "Adams" I presume. We could choose something less likely to cause legal trouble, such as "Deep Thought", "Life, The Universe and Everything", "The Answer", "Arthur Dent&quo

Re: FYI Koji 1.35 changed how side tag newRepo works

2024-11-03 Thread Björn Persson
Kevin Fenzi wrote: > On Mon, Oct 28, 2024 at 06:42:28PM +0100, Björn Persson wrote: > > In the case of --wait-repo it would make sense to request and await a > > refresh after the build, to guarantee that when the koji command exits > > successfully the repo includes the newly

<    2   3   4   5   6   7   8   >