Re: Hardening flags?

2012-06-13 Thread Dr. Markus Waldeck
  are there any plans to enable hardening flags in:
  - x11-xkb-utils
  - xinit
  - xauth
  - xfonts-utils
  - ...
  ?
  
 Not particularly.

http://wiki.debian.org/ReleaseGoals/SecurityHardeningBuildFlags

ReleaseGoals
SecurityHardeningBuildFlags

Security Hardening Build Flags

Goal description

This goal is to update as many packages as possible to use security hardening 
build flags via dpkg-buildflags. These flags enable various protections against 
security issues such as stack smashing, predictable locations of values in 
memory, etc. 

Thanks!

Markus

-- 
NEU: FreePhone 3-fach-Flat mit kostenlosem Smartphone!  

Jetzt informieren: http://mobile.1und1.de/?ac=OM.PW.PW003K20328T7073a


-- 
To UNSUBSCRIBE, email to debian-x-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/20120613063933.6...@gmx.net



Hardening flags?

2012-06-12 Thread Dr. Markus Waldeck
Dear Debian X Strike Force,

are there any plans to enable hardening flags in:
- x11-xkb-utils
- xinit
- xauth
- xfonts-utils
- ...
?

Thanks!

Dr. Markus Waldeck

-- 
Empfehlen Sie GMX DSL Ihren Freunden und Bekannten und wir
belohnen Sie mit bis zu 50,- Euro! https://freundschaftswerbung.gmx.de


-- 
To UNSUBSCRIBE, email to debian-x-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/20120612182006.286...@gmx.net



Bug#378811: Fixed in xterm (268-1) unstable

2011-02-13 Thread Dr. Markus Waldeck
xterm (268-1) unstable; urgency=low
...

  [ Julien Cristau ]
  * Update copy of XTerm FAQ to revision 1.167 (dated 2010/11/25)

/usr/share/doc/xterm/xterm.faq.gz and /usr/share/doc/xterm/xterm.faq.html:

Here is a resource file which I tested with xterm-88c, xterm-149 and xterm-158, 
using $TERM set to xterm-debian:

! $Id: xterm.faq.html,v 1.167 2010/11/25 14:10:03 tom Exp $
! Settings to make xterm-88c work as expected for Debian.
...
-- 
Empfehlen Sie GMX DSL Ihren Freunden und Bekannten und wir
belohnen Sie mit bis zu 50,- Euro! https://freundschaftswerbung.gmx.de




-- 
To UNSUBSCRIBE, email to debian-x-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/20110213182210.260...@gmx.net



Bug#511231: Fatal X server error after upgrade to 2.4.3+git+20090105+a8c5480-1

2009-01-08 Thread Dr. Markus Waldeck

Package: libdrm-intel1
Version: 2.4.3+git+20090105+a8c5480-1
Justification: renders package unusable
Severity: grave

After the upgrade from 2.4.1+git+20081116+930c0e7-1 to
2.4.3+git+20090105+a8c5480-1 it was not possible to start X

The end of the Xorg.0.log:

Backtrace:
0: /usr/bin/X11/X(xorg_backtrace+0x3b) [0x812f0fb]
1: /usr/bin/X11/X(xf86SigHandler+0x51) [0x80c1c71]
2: [0xb80b4400]
3: /usr/lib/xorg/modules/drivers//intel_drv.so(I830Sync+0x54) [0xb7b3f4f4]
4: /usr/lib/xorg/modules/drivers//intel_drv.so [0xb7b68f0a]
5: /usr/lib/xorg/modules//libexa.so(exaWaitSync+0x65) [0xb7a20415]
6: /usr/lib/xorg/modules/drivers//intel_drv.so(i830WaitSync+0xb7) [0xb7b4ee67]
7: /usr/lib/xorg/modules/drivers//intel_drv.so [0xb7b459b4]
8: /usr/bin/X11/X(xf86CrtcSetMode+0x13b) [0x80eb3ab]
9: /usr/bin/X11/X(xf86SetDesiredModes+0x1af) [0x80ebbff]
10: /usr/lib/xorg/modules/drivers//intel_drv.so [0xb7b4f436]
11: /usr/lib/xorg/modules/drivers//intel_drv.so [0xb7b50d48]
12: /usr/bin/X11/X(AddScreen+0x19f) [0x8070a9f]
13: /usr/bin/X11/X(InitOutput+0x206) [0x80a91b6]
14: /usr/bin/X11/X(main+0x279) [0x8071239]
15: /lib/i686/cmov/libc.so.6(__libc_start_main+0xe5) [0xb7cdc775]
16: /usr/bin/X11/X(FontFileCompleteXLFD+0x20d) [0x8070821]

Fatal server error:
Caught signal 11.  Server aborting


FatalError re-entered, aborting
I830EmitFlush: BEGIN_BATCH called without closing ADVANCE_BATCH


After the downgrade to 2.4.1+git+20081116+930c0e7-1 it is possblie to start X.

-- System Information:
Debian Release: 5.0
Architecture: i386 (i686)

Versions of packages libdrm-intel1 depends on:
ii  libc6   2.9-0exp1GNU C Library: Shared libraries
ii  libdrm2 2.4.3+git+20090105+a8c5480-1 Userspace interface to kernel rend

Installed X packages:
ii  xserver-common2:1.5.3-1 common files used by various X servers
ii  xserver-xorg  1:7.4~4   the X.Org X server
ii  xserver-xorg-core 2:1.5.3-1 Xorg X server - core server
ii  xserver-xorg-video-intel  2:2.5.1-1 X.Org X server -- Intel i8xx, i9xx 
display driver

-- 
Sensationsangebot verlängert: GMX FreeDSL - Telefonanschluss + DSL 
für nur 16,37 Euro/mtl.!* http://dsl.gmx.de/?ac=OM.AD.PD003K1308T4569a


Xorg.0.log
Description: Binary data


Bug#491732: Better check in /var/lib/dpkg/info/xdm.postinst

2008-07-21 Thread Dr. Markus Waldeck

Package: xdm
Version: 1:1.1.8-2
Severity: wishlist

Some daemons like apache and cupsd check in their postinst scripts
(/var/lib/dpkg/info/apache2.2-common.postinst,
/var/lib/dpkg/info/cups.postinst) whether the corresponding script in
/etc/init.d is executable.
Only if the script is execuptable update-rc.d is run.
In the other case the creation of the links in /etc/rc*.d is
considered as undesired.

I made patch:

--- /var/lib/dpkg/info/xdm.postinst 2008-07-21 19:46:07.0 +
+++ /var/lib/dpkg/info/xdm.postinst.patched 2008-07-21 19:45:59.0 
+
@@ -1010,7 +1010,7 @@
 # stdout, which can confuse debconf.
 db_stop

-if [ -e /etc/init.d/xdm ]; then
+if [ -x /etc/init.d/xdm ]; then
   update-rc.d xdm defaults 99 01
 fi

-- 
GMX startet ShortView.de. Hier findest Du Leute mit Deinen Interessen!
Jetzt dabei sein: http://www.shortview.de/[EMAIL PROTECTED]



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#468777: man xorg.conf should mention DynamicClocks

2008-03-01 Thread Dr. Markus Waldeck

Package: xserver-xorg-core
Version: 2:1.4.1~git20080131-1
Severity: normal

I found a description of DynamicClocks on
http://www.x.org/wiki/DynamicClocks.

It should be part of xorg.conf.

-- 
GMX startet ShortView.de. Hier findest Du Leute mit Deinen Interessen!
Jetzt dabei sein: http://www.shortview.de/[EMAIL PROTECTED]



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#468777: man xorg.conf should mention DynamicClocks

2008-03-01 Thread Dr. Markus Waldeck
 Isn't this radeon specific? 

If this is the case the problem is solved!

Thanks


-- 
Psst! Geheimtipp: Online Games kostenlos spielen bei den GMX Free Games! 
http://games.entertainment.web.de/de/entertainment/games/free



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#458432: xterm does not display Unicode glyphs beyond \uFFFF

2008-01-01 Thread Dr. Markus Waldeck
 I might have noticed this earlier, but was unfamiliar
 with fonts using codes past 0x.

The oldest known script is sumerian cuneiform.
I searched for free fonts and found George Douros fonts
which were included in Debian after an wnpp.

Fortunately the fonts use Unicode encoding
which I prefer since I studied in Japan.
According to wikipedia (http://en.wikipedia.org/wiki/Unicode_cuneiform)
sumerian cuneiform are included since Unicode 5.0.

 but TrueType fonts use a different interface, which apparently
 does not have the same limitation (that's how xfd is able to display
 the font).  

Is it possibe to use this functionality in xterm?

-- 
GMX FreeMail: 1 GB Postfach, 5 E-Mail-Adressen, 10 Free SMS.
Alle Infos und kostenlose Anmeldung: http://www.gmx.net/de/go/freemail



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#443892: x11-utils: luit can't find locale aliases

2007-12-31 Thread Dr. Markus Waldeck
I also wasted my time with this bug!

 From: Brice Goglin [EMAIL PROTECTED]
 To: [EMAIL PROTECTED]
 Subject: Re: Bug#443892: x11-utils: luit can't find locale aliases
 Date: Tue, 25 Sep 2007 19:12:36 +0200

 tags 443892 +fixed-upstream
 thank you

This is nothing at all worth
until a new package is available!

Dr. Markus Waldeck

-- 
GMX FreeMail: 1 GB Postfach, 5 E-Mail-Adressen, 10 Free SMS.
Alle Infos und kostenlose Anmeldung: http://www.gmx.net/de/go/freemail



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#458432: xterm does not display Unicode glyphs beyond \uFFFF

2007-12-31 Thread Dr. Markus Waldeck

Package: xterm
Version: 229-1
Severity: normal

I tested the fonts in the package ttf-ancient-fonts.
The work fine with openoffice and eclipse.

But if I start an xterm with -fa Akkadian only glyphs
below \u are displayed.

Is this a limitation in xterm?


-- 
Der GMX SmartSurfer hilft bis zu 70% Ihrer Onlinekosten zu sparen! 
Ideal für Modem und ISDN: http://www.gmx.net/de/go/smartsurfer



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#458432: xterm does not display Unicode glyphs beyond \uFFFF

2007-12-31 Thread Dr. Markus Waldeck
 yes.  TrueType fonts might not have this limitation, but bitmap
 fonts have only the XDrawString16 interface to write characters.
 xterm is translating codes outside 0-0x to the replacement
 character.
 
 (I should investigate this further - thanks for the reminder)

Thank you for the answer!

Unfortunately there is no XDrawString32 :-(

-- 
Der GMX SmartSurfer hilft bis zu 70% Ihrer Onlinekosten zu sparen! 
Ideal für Modem und ISDN: http://www.gmx.net/de/go/smartsurfer



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#438196: xdm 1.1.6-3

2007-11-20 Thread Dr. Markus Waldeck

 I tried many times to stop/restart xdm 1:1.6-3 and I don't have this
 problem anymore.
 Do you confirm?

The problem disappeared as mentioned on Fri, 17 Aug 2007 09:14:05 +0200.

Thanks!



-- 
Ist Ihr Browser Vista-kompatibel? Jetzt die neuesten 
Browser-Versionen downloaden: http://www.gmx.net/de/go/browser



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#438196: Bug #438196: xdm does not create /var/run/xdm.pid

2007-08-17 Thread Dr. Markus Waldeck

Hi,

as mentioned before I noticed some problems with xdm 1.1.5-1.

An other problem was reported in bugreport #438200.

Julien Cristau made very fast a new build (1:1.1.5-2).
This resolved #438200.

Unfortunately I did not check for #438196 
so I noticed few minutes ago that it seams 
that the /var/run/xdm.pid problem disappeared.

Markus

-- 
Pt! Schon vom neuen GMX MultiMessenger gehört?
Der kanns mit allen: http://www.gmx.net/de/go/multimessenger


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#438196: Bug #438196: xdm does not create /var/run/xdm.pid

2007-08-17 Thread Dr. Markus Waldeck
 There are very few changes in 1.1.5-2, so it's unlikely that the xdm.pid
 problem was fixed there. Did you reproduce the problem multiple times
 with 1.1.5-1? Or is it possible that it occurred only at the first
 restart (or only multiple times until you rebooted or so)?

As a chemist I learned a magic word which is called reproducibility :-).

I updated on wednesday and noticed the problem after booting on thursday 
morning. The problem persisted two reboots.

After each boot /etc/init.d/xdm start was issued several times 
followed by stopping with pkill xdm and checking with ps.


-- 
GMX FreeMail: 1 GB Postfach, 5 E-Mail-Adressen, 10 Free SMS.
Alle Infos und kostenlose Anmeldung: http://www.gmx.net/de/go/freemail


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#438196: xdm does not create /var/run/xdm.pid

2007-08-16 Thread Dr. Markus Waldeck

Package: xdm
Version: 1:1.1.5-1
Severity: important

It noticed some problems with xdm 1.1.5-1.

One problem is that a start via /etc/init.d/xdm does not create the
PIDFILE /var/run/xdm.pid.

So it is not possible to stop the xdm with /etc/init.d/xdm:

# /etc/init.d/xdm stop
Stopping X display manager: xdm not running (/var/run/xdm.pid not
found).

-- 
Pt! Schon vom neuen GMX MultiMessenger gehört?
Der kanns mit allen: http://www.gmx.net/de/go/multimessenger


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#438200: xlogin*background: black does not longer work

2007-08-16 Thread Dr. Markus Waldeck

Package: xdm
Version: 1:1.1.5-1
Severity: normal

It noticed some problems with xdm 1.1.5-1.

A further problem is that it was possible to suppress
the login screen at all. This is useful if you travel
often with plane and train and you want to avoid
the presentation of your username on your laptop.

In previous versions I used xlogin*background: black
to achieve this goal. In the current version does this 
configuration not work.

-- 
GMX FreeMail: 1 GB Postfach, 5 E-Mail-Adressen, 10 Free SMS.
Alle Infos und kostenlose Anmeldung: http://www.gmx.net/de/go/freemail


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#438196: xdm does not create /var/run/xdm.pid

2007-08-16 Thread Dr. Markus Waldeck
Hi,

thanks for your immediate answer!

 We have multiple bug reports [1] about problems related to xdm
 startup/exit/pidfile, I guess we need to cleanup some mess here...

I checked the bug reports

 #270393 == PIDFILE removal problem
 #343386 == PIDFILE removal problem, maybe permission problem
 #334461 == ?
 #372114 == accidental removal
 #382037 == no PIDFILE generated (?)
 #398917 == incompatible xdm locations

It seems that every new release introduces new bugs!

Fortunately I had few problems on my machine
but I could understand that pkgsrc (NetBSD, DragonFly, ...)
dropped the xdm package.

I tested gdm and kdm as an alternative but I use icewm
and so I consider xdm as the maximal acceptable overhead.

Maybe is should return to startx :-(

Markus


-- 
Ist Ihr Browser Vista-kompatibel? Jetzt die neuesten 
Browser-Versionen downloaden: http://www.gmx.net/de/go/browser


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]