Re: A Look In the Mirror: Attacks on Package Managers

2010-06-06 Thread Josselin Mouette
Le dimanche 06 juin 2010 à 14:50 +0900, Ansgar Burchardt a écrit : > The Release file in the repository has now a Valid-Until field that > invalidates the repository after some time without updates. This can be > used to detect a mirror provided outdated packages. > > I am not sure whether APT che

Re: A Look In the Mirror: Attacks on Package Managers

2010-06-06 Thread Florian Weimer
* Fernando Lemos: > 1. Man-in-the-middle attacks between clients and security update servers > 2. Denial-of-service attacks to the security updates infrastructure > 3. No trusted servers for security updates for testing and unstable > > Using HTTPS for the security update infrastructure could solv

Re: A Look In the Mirror: Attacks on Package Managers

2010-06-06 Thread Peter Palfrader
On Sun, 06 Jun 2010, Florian Weimer wrote: > You'd have to fetch the root metadata from a trusted server over > something like HTTPS (that is, something with authentication and a > challange-response component built in). That wouldn't be a stupid design at all. It would also allow that root meta

Re: how to help end-users to increase the life-time of their SSDs

2010-06-06 Thread Christoph Anton Mitterer
On Sun, 2010-06-06 at 10:28 +0400, Michael Tokarev wrote: > > - optionally /var/tmp as tmpfs > Not an answer to your original question, just a not-so-random observation. > /var/tmp is declared by LFS as "temporary storage that persists across > reboots". It wont be this way if it's on tmpfs obviou

Bug#584760: ITP: ibus-table-others -- provide various tables that beyond Chinese for IBus-Table

2010-06-06 Thread Asias He
Package: wnpp Severity: wishlist Owner: Asias He * Package name: ibus-table-others Version : 1.3.0.20100528 * URL : http://code.google.com/p/ibus/ * License : GPLv3 Programming Lang: Python Description : provide various tables that beyond Chinese for IBu

enquiry about linux debian

2010-06-06 Thread Bassam Hadi. Al-Dogash
Good day I am Bassam hadi from saudi arabia,Riyadh capital city. I have bachelor in information technolgy. I prefered linux OS as I can review IT courses from daily usage. I have ubuntu & debian distributions , and I want to know is (universities -*.iso filetypes) Contact me t

Re: Permission to NMU gcc-mingw32

2010-06-06 Thread Bill Allombert
On Sun, Jun 06, 2010 at 11:53:08AM +, Ove Kaaven wrote: > The lack of a suitable (i.e. non-buggy) mingw32 cross-compiler has blocked > Wine updates for half a year now. Both the mingw32 package (gcc 4.2.1) and > the gcc-mingw32 package (gcc 4.4.2) have a bug which was fixed in upstream > gcc 4.

Bug#584769: ITP: clustershell -- An event-based python library to execute commands on local or distant cluster nodes in parallel

2010-06-06 Thread stephan gorget
Package: wnpp Severity: wishlist Owner: stephan gorget * Package name: clustershell Version : 1.2.83 Upstream Author : Stephane Thiell * URL : https://sourceforge.net/projects/clustershell/ * License : CeCILL Programming Lang: Python Description : An

status of circulars dependencies in unstable

2010-06-06 Thread Bill Allombert
Dear developers, Today circular dependencies in unstable reached an all-time low. Here the list of current circular dependencies: * libc6 libgcc1 * perl perl-modules * debconf debconf-english debconf-i18n * abuse abuse-frabs abuse-lib * ghostscript gs-common * python-imaging python-imaging-tk * o

Re: Re (2): lilo removal in squeeze / new lilo upstream

2010-06-06 Thread Joachim Wiedorn
Russell Coker wrote on 2010-06-05 22:30: > On Wed, 26 May 2010, Stephen Powell wrote: > > You're missing the point. The main selling point to management > > is that Linux is free. If they have to buy new backup software > > in order to accommodate Linux' backup requirements, that will > > kill

Re: A Look In the Mirror: Attacks on Package Managers

2010-06-06 Thread Joey Hess
Josselin Mouette wrote: > It does. If you don’t re-run “apt-get update”, the signature will be > considered invalid. j...@gnu:~/tmp/apt-0.7.26~exp5>grep -i Valid-Until -r . zsh: exit 2 grep -i Valid-Until -r . What'm I missing? -- see shy jo signature.asc Description: Digital signature

Re: status of circulars dependencies in unstable

2010-06-06 Thread Petter Reinholdtsen
[Bill Allombert] > Dear developers, > Today circular dependencies in unstable reached an all-time low. Very good to hear. If only we could get it down to zero, piuparts would be able to test all the packages and a more deterministic package installation order would be ensured. :) Happy hacking,

Re: A Look In the Mirror: Attacks on Package Managers

2010-06-06 Thread Fernando Lemos
On Sun, Jun 6, 2010 at 5:31 AM, Florian Weimer wrote: > * Fernando Lemos: > >> 1. Man-in-the-middle attacks between clients and security update servers >> 2. Denial-of-service attacks to the security updates infrastructure >> 3. No trusted servers for security updates for testing and unstable >> >

Re: status of circulars dependencies in unstable

2010-06-06 Thread Josselin Mouette
Le dimanche 06 juin 2010 à 18:06 +0200, Petter Reinholdtsen a écrit : > [Bill Allombert] > > Dear developers, > > Today circular dependencies in unstable reached an all-time low. > > Very good to hear. If only we could get it down to zero, piuparts > would be able to test all the packages and a m

Re: status of circulars dependencies in unstable

2010-06-06 Thread Eugene V. Lyubimkin
--=20 Eugene V. Lyubimkin aka JackYF, JID: jackyf.devel(maildog)gmail.com C++/Perl developer, Debian Developer signature.asc Description: OpenPGP digital signature

Re: status of circulars dependencies in unstable

2010-06-06 Thread Neil Williams
On Sun, 06 Jun 2010 18:29:01 +0200 Josselin Mouette wrote: > Le dimanche 06 juin 2010 à 18:06 +0200, Petter Reinholdtsen a écrit : > > [Bill Allombert] > > > Dear developers, > > > Today circular dependencies in unstable reached an all-time low. > > > > Very good to hear. If only we could get i

Re: A Look In the Mirror: Attacks on Package Managers

2010-06-06 Thread David Kalnischkies
2010/6/6 Joey Hess : > Josselin Mouette wrote: >> It does. If you don’t re-run “apt-get update”, the signature will be >> considered invalid. > > j...@gnu:~/tmp/apt-0.7.26~exp5>grep -i Valid-Until -r . > zsh: exit 2     grep -i Valid-Until -r . > > What'm I missing? Nothing - or at least I didn't

Re: status of circulars dependencies in unstable

2010-06-06 Thread Rene Engelhard
Hi, On Sun, Jun 06, 2010 at 06:29:01PM +0200, Josselin Mouette wrote: > Le dimanche 06 juin 2010 à 18:06 +0200, Petter Reinholdtsen a écrit : > > [Bill Allombert] > > > Dear developers, > > > Today circular dependencies in unstable reached an all-time low. > > > > Very good to hear. If only we c

Re: A Look In the Mirror: Attacks on Package Managers

2010-06-06 Thread Fernando Lemos
On Sun, Jun 6, 2010 at 1:34 PM, David Kalnischkies wrote: > In regards to APT i will have a look later how to implement it, > hints regarding a good error message are welcomed > as i can currently only thing about stuff like: >> > W: http://debian.example.org squeeze Release: The Validation da

Re: Improving in-place upgrades of Ada packages from Lenny to Squeeze

2010-06-06 Thread David Kalnischkies
(better late than never) 2010/6/1 Jacob Sparre Andersen : > David Kalnischkies wrote: >> 2010/5/31 Ludovic Brenta : >>> Question 2: if I add Breaks: to a -dev package, which ones of Conflicts: >>> and Replaces: should I also specify? (currently, both are specified; the new >>> packages replace alm

Re: Improving in-place upgrades of Ada packages from Lenny to Squeeze

2010-06-06 Thread David Kalnischkies
(better late than never) 2010/6/3 Ludovic Brenta : > Jacob Sparre Andersen writes: >> David Kalnischkies wrote: >>> With the break you can force the update of old-libs, which >>> could depend in their new version on the new-libs. > > OK, I just tried that (in a local repository).  Having gnat brea

Re: status of circulars dependencies in unstable

2010-06-06 Thread Neil Williams
On Sun, 6 Jun 2010 18:53:04 +0200 Rene Engelhard wrote: > On Sun, Jun 06, 2010 at 06:29:01PM +0200, Josselin Mouette wrote: > > Le dimanche 06 juin 2010 à 18:06 +0200, Petter Reinholdtsen a > > écrit : > > > [Bill Allombert] > > > > Dear developers, > > > > Today circular dependencies in unstable

Re: status of circulars dependencies in unstable

2010-06-06 Thread Rene Engelhard
Hi, On Sun, Jun 06, 2010 at 06:15:41PM +0100, Neil Williams wrote: > The bug report doesn't explain why this needs to be a Depends: either - > it could be a Recommends AFAICT. To quote the report, "which for some > stuff needs" - the definition of a Recommends in my book. If "some stuff" in t

Re: Re (2): lilo removal in squeeze / new lilo upstream

2010-06-06 Thread Stephen Powell
On Sun, 06 Jun 2010 09:39:59 -0400 (EDT), Joachim Wiedorn wrote: > > I see that more people than thought still want to have or need LiLO. Now > I have decided to start and reanimate the upstream development. Everyone > is invited to join in this development. I'm working on LiLO version 23. > >

Re: status of circulars dependencies in unstable

2010-06-06 Thread Neil Williams
On Sun, 6 Jun 2010 19:18:19 +0200 Rene Engelhard wrote: > On Sun, Jun 06, 2010 at 06:15:41PM +0100, Neil Williams wrote: > > The bug report doesn't explain why this needs to be a Depends: > > either - it could be a Recommends AFAICT. To quote the report, > > "which for some stuff needs" - the

Re: status of circulars dependencies in unstable

2010-06-06 Thread Josselin Mouette
Le dimanche 06 juin 2010 à 18:53 +0200, Rene Engelhard a écrit : > No. Besides that I think it would be bad to forbid correct dependencies it > would break some subpolicies. (I have the cli-uno-bridge <-> > libuno-cppuhelper1.0-cil > one in mind, see #495748). This is a very classical case of cir

Re: Improving in-place upgrades of Ada packages from Lenny to Squeeze

2010-06-06 Thread David Kalnischkies
2010/6/6 Ludovic Brenta : > Package: gnat > Architecture: any > Depends: gnat-4.4 (>= 4.4.2-1) > Recommends: ada-reference-manual, gnat-gps > Breaks: libadasockets-dev (<= 1.8.6-2), libasis-dev, libaunit-dev, >  libaws-dev, libflorist-dev, libgnademysql-dev, libgnadeodbc-dev, >  libgnadepostgresql-

Re: status of circulars dependencies in unstable

2010-06-06 Thread Steve Langasek
On Sun, Jun 06, 2010 at 06:29:01PM +0200, Josselin Mouette wrote: > Le dimanche 06 juin 2010 à 18:06 +0200, Petter Reinholdtsen a écrit : > > [Bill Allombert] > > > Dear developers, > > > Today circular dependencies in unstable reached an all-time low. > > > > Very good to hear. If only we could

Re: Improving in-place upgrades of Ada packages from Lenny to Squeeze

2010-06-06 Thread Ludovic Brenta
David Kalnischkies writes: > 2010/6/6 Ludovic Brenta : >> Package: gnat >> Architecture: any >> Depends: gnat-4.4 (>= 4.4.2-1) >> Recommends: ada-reference-manual, gnat-gps >> Breaks: libadasockets-dev (<= 1.8.6-2), libasis-dev, libaunit-dev, >>  libaws-dev, libflorist-dev, libgnademysql-dev, libgn

Re: Re (2): lilo removal in squeeze / new lilo upstream

2010-06-06 Thread William Pitcock
Hi, - "Joachim Wiedorn" wrote: > Russell Coker wrote on 2010-06-05 22:30: > > > On Wed, 26 May 2010, Stephen Powell wrote: > > > You're missing the point. The main selling point to management > > > is that Linux is free. If they have to buy new backup software > > > in order to accommod

Re: Re (2): lilo removal in squeeze / new lilo upstream

2010-06-06 Thread Stephen Powell
On: Sun, 06 Jun 2010 17:44:05 -0400 (EDT), William Pitcock wrote: > "Joachim Wiedorn" wrote: >> I see that more people than thought still want to have or need LiLO. >> Now I have decided to start and reanimate the upstream development. >> Everyone is invited to join in this development. I'm worki