Re: Bits from the Security Team

2014-03-06 Thread Jakub Wilk
* Moritz Muehlenhoff , 2014-03-05, 20:03: * Since Wheezy the Linux kernel features a security mechanism which nullifies many symlink attacks (fs.protected_symlinks). For the lazy, documentation of protected_symlinks: When the value in this file is 0, no restrictions are placed on following sy

Re: RSA vs ECDSA (Was: Bits from keyring-maint: Pushing keyring updates. Let us bury your old 1024D key!)

2014-03-06 Thread Helmut Grohne
On Tue, Mar 04, 2014 at 02:33:23PM -0600, Gunnar Wolf wrote: > Umh, I feel I have to answer this message, but I clearly don't have > enough information to do so in an authoritative way¹. AIUI, ECDSA has > not been shown to be *stronger* than RSA ??? RSA works based on modulus > operations, ECDSA on

Bug#740946: ITP: libsub-recursive-perl -- anonymous memory leak free recursive subroutines

2014-03-06 Thread Peter Roberts
Package: wnpp Severity: wishlist Owner: Peter Roberts * Package name: libsub-recursive-perl Version : 0.03 Upstream Author : Johan Lodin * URL : https://metacpan.org/release/Sub-Recursive * License : GPL Programming Lang: Perl Description : anonymous m

debian/copyright: how extensive ...

2014-03-06 Thread Osamu Aoki
Hi, While refining my debmake command and sponsoring libkkc package as my test case, I came to questions on practical aspect of debian/copyright file. How far we need to document in debian/copyright for auto-generated and what to do with files with explicit text. I want to know this to re

Re: Bits from the Security Team

2014-03-06 Thread Guido Günther
Hi Jakub, On Wed, Mar 05, 2014 at 10:33:23PM +0100, Jakub Wilk wrote: > * Guido Günther , 2014-03-05, 20:54: [..snip..] > >I looked at the docs and as I read them this would affect uid 0 as > >well. > > Luckily this is not the case. :) root can see other users' /proc > entries just fine. Perhaps

Idea for apt-get : getting source code instead getting binaries

2014-03-06 Thread Solal Rastier
Hello! I've an idea for a new apt-get package style : Developer side : -The developer create a ./install script in the source code. -The install script executes all commands necessary for install the software. Also, it getting dependancies, etc. -The developer create a tarball (.tar.bzip2) and re

Re: Bug#740946: ITP: libsub-recursive-perl -- anonymous memory leak free recursive subroutines

2014-03-06 Thread Thibaut Paumard
Le 06/03/2014 15:32, Peter Roberts a écrit : > Description : anonymous memory leak free recursive subroutines Hi, I suggest using hyphens and comas in the short title: "anonymous, memory-leak-free, recursive subroutines". Initially I thought you were packaging a free package for leaking mem

Re: debian/copyright: how extensive ...

2014-03-06 Thread Lars Wirzenius
On Fri, Mar 07, 2014 at 12:12:10AM +0900, Osamu Aoki wrote: > There is no DEP-5 rules on what to do. For example the followings are I hasten to point out, just in case it's still unclear to anyone, that DEP-5 (now copyright-format/1.0) does not, in any way, affect what files can or can't be exclu

Re: Idea for apt-get : getting source code instead getting binaries

2014-03-06 Thread Liang Suilong
There is a tool named as apt-build. It should be satisfied for your need. Sent From My Heart My Page: http://www.liangsuilong.info On Thu, Mar 6, 2014 at 11:33 PM, Solal Rastier wrote: > Hello! I've an idea for a new apt-get package style : > > Developer side : > -The developer create a ./ins

Re: Idea for apt-get : getting source code instead getting binaries

2014-03-06 Thread Matt Zagrabelny
On Thu, Mar 6, 2014 at 9:33 AM, Solal Rastier wrote: > Hello! I've an idea for a new apt-get package style : > > Developer side : > -The developer create a ./install script in the source code. > -The install script executes all commands necessary for install the software. > Also, it getting depen

Re: Bug#740946: ITP: libsub-recursive-perl -- anonymous memory leak free recursive subroutines

2014-03-06 Thread Dominique Dumont
On Thursday 06 March 2014 14:32:00 Peter Roberts wrote: > * License : GPL Note that the upstream license in same as Perl [1] All the best [1] https://metacpan.org/pod/Sub::Recursive#COPYRIGHT -- https://github.com/dod38fr/ -o- http://search.cpan.org/~ddumont/ http://ddumont.wordpres

Re: Idea for apt-get : getting source code instead getting binaries

2014-03-06 Thread Paul Tagliamonte
On Thu, Mar 06, 2014 at 04:33:50PM +0100, Solal Rastier wrote: > Hello! I've an idea for a new apt-get package style : > > Developer side : > -The developer create a ./install script in the source code. > -The install script executes all commands necessary for install the software. > Also, it get

Bug#740957: ITP: libjs-jquery-coolfieldset -- jQuery Plugin for creating collapsible fieldset

2014-03-06 Thread Francois-Regis Vuillemin
Package: wnpp Severity: wishlist Owner: "Francois-Regis Vuillemin" * Package name: libjs-jquery-coolfieldset Version : 1.0.0 Upstream Author : Luc Ky * URL : http://w3shaman.com/article/jquery-plugin-collapsible- fieldset * License : GPL Programming Lang: j

Re: RSA vs ECDSA (Was: Bits from keyring-maint: Pushing keyring updates. Let us bury your old 1024D key!)

2014-03-06 Thread Ian Jackson
Helmut Grohne writes ("Re: RSA vs ECDSA (Was: Bits from keyring-maint: Pushing keyring updates. Let us bury your old 1024D key!)"): > ECDSA is a DSA algorithm and therefore relies on the creation of secure > random numbers. It has this problem, that if you happen to choose the > same number for tw

Using docker for Debian packaging work ?

2014-03-06 Thread Olivier Berger
Hi. I've been investigating the use of Docker containers on Debian (resulting in the creation of a few wiki pages [0]), and intend to use them more for Debian related tasks. Btw, thanks a lot for the packaging of docker and other guides already available around (I tried to collect what I spotted i

Re: Idea for apt-get : getting source code instead getting binaries

2014-03-06 Thread John Paul Adrian Glaubitz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 03/06/2014 05:01 PM, Paul Tagliamonte wrote: > Script to do this attached; can I have my GSoC money now? :) Comic Book Guy: I'm interested in upgrading my 28.8k modem to a fibre-optic T1 line. Will you be able to provide

Re: Using docker for Debian packaging work ?

2014-03-06 Thread Paul Tagliamonte
I'd be interested in a few things - a Debian index which I can trust (images) - I'm keen to help add OpenPGP to Docker upstream. I'd also love it if dbuilder (or whatever) could tag layers with build-deps installed (tagging something like foobar:1.2.3-1), so that building the package wouldn't have

Re: Idea for apt-get : getting source code instead getting binaries

2014-03-06 Thread Paul Tagliamonte
On Thu, Mar 06, 2014 at 06:58:41PM +0100, John Paul Adrian Glaubitz wrote: > On 03/06/2014 05:01 PM, Paul Tagliamonte wrote: > > Script to do this attached; can I have my GSoC money now? :) > > Homer: Can I have some money now? BTW; just for context, I thought this message was to a soc-coordinati

Re: Idea for apt-get : getting source code instead getting binaries

2014-03-06 Thread Octavio Alvarez
On 03/06/2014 07:33 AM, Solal Rastier wrote: > Hello! I've an idea for a new apt-get package style : > > Developer side : > -The developer create a ./install script in the source code. > -The install script executes all commands necessary for install the software. > Also, it getting dependancies,

Bike Week Starts Here at Space Coast Harley-Davidson!

2014-03-06 Thread Space Coast Harley-Davidson
View this message in a browser. http://archives.subscribermail.com/msg/e06249d1cc5c4fa4a8bceb6f30de375e.htm To view this message in a browser. Copy and Paste the following URL in your web address bar: http://www.spacecoastharley.com/default.asp?page=e-blast

Re: debian/copyright: how extensive ...

2014-03-06 Thread Joerg Jaspert
On 13507 March 1977, Osamu Aoki wrote: > When FTP master rejected previous upload rightfully, he had interesting > message: [...] > He was not asking to list auto-generated files with permissive licenses. [...] > (These all are autotools generated special exception ones with slightly > different w

Work-needing packages report for Mar 7, 2014

2014-03-06 Thread wnpp
The following is a listing of packages for which help has been requested through the WNPP (Work-Needing and Prospective Packages) system in the last week. Total number of orphaned packages: 561 (new: 5) Total number of packages offered up for adoption: 142 (new: 5) Total number of packages request