Re: Help bts-link be a more effective tool

2009-01-21 Thread Sandro Tosi
On Sun, Jan 18, 2009 at 11:20, Frank Küster wrote: > "Paul Wise" wrote: >> Debian TeX Maintainers >>texlive-bin > > One was a typo in the upstream address. The other one, Thanks for fixing this. > E: pkg=texlive-bin, bug=351672, msg=Does not deals dupes: > [http://sourceforge.net/tracker/

Re: Help bts-link be a more effective tool

2009-01-21 Thread Sandro Tosi
On Sun, Jan 18, 2009 at 10:12, Emilio Pozuelo Monfort wrote: >> E: pkg=update-manager, bug=415376, msg=Parse error: > [https://bugs.launchpad.net/update-manager/+bug/95168/] No product specified > but > bug affects multiple products > > That looks wrong to me. The error says "No product specified

Re: Help bts-link be a more effective tool

2009-01-21 Thread Sandro Tosi
On Sun, Jan 18, 2009 at 03:21, Raphael Geissert wrote: > Hi, > > Sandro Tosi wrote: > [...} >> In recent bts-link runs, we noticed some errors. The log is available >> at [2]: please take the time to give it a look, search for your >> packages and check the situation. There are errors in that log

Re: Help bts-link be a more effective tool

2009-01-19 Thread Bastien ROUCARIES
On Mon, Jan 19, 2009 at 10:50 AM, Bastien ROUCARIES wrote: >ll need I suppose cooperation from BTS itself but in a second > time. We need only two user tags by foreign distrib: > bts-link-foreign-xref-$distrib set to the foregin bugzilla entry > bts-link-foreign-status-$distrib magically set by b

Re: Tracing bugs between distro's bugtrackers - Was: Re: Help bts-link be a more effective tool

2009-01-19 Thread Bastien ROUCARIES
On Mon, Jan 19, 2009 at 10:46 AM, Olivier Berger wrote: > Le lundi 19 janvier 2009 à 07:12 +0100, Christian Perrier a écrit : >> Quoting Bastien ROUCARIES (roucaries.bast...@gmail.com): >> > >> > I really useful stuff will be to use user tag in order to crossref >> > another distrib bugzilla. For

Re: Tracing bugs between distro's bugtrackers - Was: Re: Help bts-link be a more effective tool

2009-01-19 Thread Bastien ROUCARIES
On Mon, Jan 19, 2009 at 10:36 AM, Olivier Berger wrote: > Hi. > > Le dimanche 18 janvier 2009 à 19:54 +0100, Bastien ROUCARIES a écrit : >> On Sat, Jan 17, 2009 at 8:36 PM, Sandro Tosi wrote: >> > Hello, >> >> > If you feel something is missing, should be fixed or enhanced, let >> > us[4] know; o

Re: Help bts-link be a more effective tool

2009-01-19 Thread Stefano Zacchiroli
On Mon, Jan 19, 2009 at 10:40:13AM +0100, Olivier Berger wrote: > Did you mean "The bts-link is polluted", above ? No, I did mean the PTS. I've no idea whether that is true also for bts-link :) -- Stefano Zacchiroli -o- PhD in Computer Science \ PostDoc @ Univ. Paris 7 z...@{upsilon.cc,pps.juss

Re: Tracing bugs between distro's bugtrackers - Was: Re: Help bts-link be a more effective tool

2009-01-19 Thread James Westby
On Mon, 2009-01-19 at 10:46 +0100, Olivier Berger wrote: > There would be some need for inter-distro work here, maybe... any ideas > on where to discuss that much welcome ;) distributi...@lists.freedesktop.org would be a good place to start. http://lists.freedesktop.org/mailman/listinfo/distribut

Re: Help bts-link be a more effective tool

2009-01-19 Thread Paul Wise
On Mon, Jan 19, 2009 at 7:46 PM, Stefano Zacchiroli wrote: > BTW, when that is done, please submit a wishlist bugreport on the PTS > requesting integration, *together* with a description of the parsing > rules of the error output of bts-link OR maybe a switch to a format > which can be parsed out

Re: Help bts-link be a more effective tool

2009-01-19 Thread Bastien ROUCARIES
On Mon, Jan 19, 2009 at 7:12 AM, Christian Perrier wrote: > Quoting Bastien ROUCARIES (roucaries.bast...@gmail.com): >> On Sat, Jan 17, 2009 at 8:36 PM, Sandro Tosi wrote: >> > Hello, >> >> > If you feel something is missing, should be fixed or enhanced, let >> > us[4] know; of course, patches ar

Tracing bugs between distro's bugtrackers - Was: Re: Help bts-link be a more effective tool

2009-01-19 Thread Olivier Berger
Hi. Le dimanche 18 janvier 2009 à 19:54 +0100, Bastien ROUCARIES a écrit : > On Sat, Jan 17, 2009 at 8:36 PM, Sandro Tosi wrote: > > Hello, > > > If you feel something is missing, should be fixed or enhanced, let > > us[4] know; of course, patches are welcome ;) (git repo at [5]). > > I really

Re: Tracing bugs between distro's bugtrackers - Was: Re: Help bts-link be a more effective tool

2009-01-19 Thread Olivier Berger
Le lundi 19 janvier 2009 à 07:12 +0100, Christian Perrier a écrit : > Quoting Bastien ROUCARIES (roucaries.bast...@gmail.com): > > > > I really useful stuff will be to use user tag in order to crossref > > another distrib bugzilla. For instance some bug are fixed on redhat > > like #506180 but not

Re: Help bts-link be a more effective tool

2009-01-19 Thread Olivier Berger
Le lundi 19 janvier 2009 à 09:46 +0100, Stefano Zacchiroli a écrit : > The PTS is being polluted by tons of micro-parsers for the output of > the tools it monitor, a convergence at least on the surface syntaxes > would be nice to ease future maintenance. > Did you mean "The bts-link is polluted"

Re: Help bts-link be a more effective tool

2009-01-19 Thread Stefano Zacchiroli
On Mon, Jan 19, 2009 at 09:17:06AM +0100, Raphael Hertzog wrote: > Before you decide to push out errors to maintainers via PTS (as I've seen > mentionned), you should really improve the tool so that the only remaining > errors are really user errors. BTW, when that is done, please submit a wishlis

Re: Help bts-link be a more effective tool

2009-01-19 Thread Raphael Hertzog
On Sat, 17 Jan 2009, Sandro Tosi wrote: > In recent bts-link runs, we noticed some errors. The log is available > at [2]: please take the time to give it a look, search for your > packages and check the situation. There are errors in that log that > might be ok, but others can refer to broken links

Re: Help bts-link be a more effective tool

2009-01-18 Thread Christian Perrier
Quoting Bastien ROUCARIES (roucaries.bast...@gmail.com): > On Sat, Jan 17, 2009 at 8:36 PM, Sandro Tosi wrote: > > Hello, > > > If you feel something is missing, should be fixed or enhanced, let > > us[4] know; of course, patches are welcome ;) (git repo at [5]). > > I really useful stuff will b

Re: Help bts-link be a more effective tool

2009-01-18 Thread Raphael Geissert
Ben Finney wrote: [...] > > Since the problem is not with the package itself, but with an external > service, I think this would be better in DEHS. > DEHS-provided information is displayed in the PTS as well, as it is up to the package maintainer(s) or collaborators to "fix" it (either on the De

Re: Help bts-link be a more effective tool

2009-01-18 Thread Bastien ROUCARIES
On Sat, Jan 17, 2009 at 8:36 PM, Sandro Tosi wrote: > Hello, > If you feel something is missing, should be fixed or enhanced, let > us[4] know; of course, patches are welcome ;) (git repo at [5]). I really useful stuff will be to use user tag in order to crossref another distrib bugzilla. For in

Re: Help bts-link be a more effective tool

2009-01-18 Thread Frank Küster
"Paul Wise" wrote: > Debian TeX Maintainers >texlive-bin One was a typo in the upstream address. The other one, E: pkg=texlive-bin, bug=351672, msg=Does not deals dupes: [http://sourceforge.net/tracker/index.php?func=detail&aid=1425283&group_id=23164&atid=377580] I do not understand. T

Re: Help bts-link be a more effective tool

2009-01-18 Thread Mikhail Gusarov
Twas brillig at 10:12:26 18.01.2009 UTC+01 when po...@ubuntu.com did gyre and gimble: >>mercurial EPM> Looks like they're not using Trac anymore... Yes, moved to roundup. -- -- To UNSUBSCRIBE, email to debian-devel-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? C

Re: Help bts-link be a more effective tool

2009-01-18 Thread Emilio Pozuelo Monfort
Paul Wise wrote: > On Sun, Jan 18, 2009 at 6:36 AM, Sandro Tosi wrote: > >> In recent bts-link runs, we noticed some errors. The log is available >> at [2]: please take the time to give it a look, search for your >> packages and check the situation. There are errors in that log that >> might be o

Re: Help bts-link be a more effective tool

2009-01-18 Thread Ben Finney
Raphael Geissert writes: > What about generating a nice report page and making the PTS warn > when bts-link had troubles handling forwarded bugs of a given > package. Good idea. Since the problem is not with the package itself, but with an external service, I think this would be better in DEHS.

Re: Help bts-link be a more effective tool

2009-01-17 Thread Raphael Geissert
Hi, Sandro Tosi wrote: [...} > In recent bts-link runs, we noticed some errors. The log is available > at [2]: please take the time to give it a look, search for your > packages and check the situation. There are errors in that log that > might be ok, but others can refer to broken links, no more

Re: Help bts-link be a more effective tool

2009-01-17 Thread Paul Wise
On Sun, Jan 18, 2009 at 6:36 AM, Sandro Tosi wrote: > In recent bts-link runs, we noticed some errors. The log is available > at [2]: please take the time to give it a look, search for your > packages and check the situation. There are errors in that log that > might be ok, but others can refer t

Help bts-link be a more effective tool

2009-01-17 Thread Sandro Tosi
Hello, as you might have seen (if you use the forwarded BTS feature) we have a tool, called bts-link[1], that help us track upstream bugs situation, tagging Debian bugs accordingly. In recent bts-link runs, we noticed some errors. The log is available at [2]: please take the time to give it a

Re: Help needed with the GPG Key Signing Coordination page

2009-01-07 Thread Patrick Schoenfeld
rk (since > you will have to exchange emails with requesters and dd's). Besides that, > there are from time to time people calling in for help since they cannot > find a dd to sign their key. This doesn't happen very often, maybe 3 to 5 > times a year at most. It such a case yo

Re: Help needed with the GPG Key Signing Coordination page

2009-01-06 Thread David Watson
* Luk Claes (l...@debian.org) wrote: > Hi > > Ralf Treinen and I are looking for help with the GPG Key Signing > Coordination page. > > The GPG key signing coordination page at http://nm.debian.org/gpg.php > is primarily aimed at prospective contributors to find existing De

Re: Help needed with the GPG Key Signing Coordination page

2009-01-05 Thread Ralf Treinen
e now looking for one or two > > additional people to help out. The tasks to be performed are described > > at > > http://svn.debian.org/wsvn/nm/trunk/doc/gpg-coord/README?op=file&rev=0&sc=0 > > Could you tell how much time / week (or whatever scale is sensible) t

Re: Help needed with the GPG Key Signing Coordination page

2009-01-05 Thread Patrick Schoenfeld
Hi, On Mon, Jan 05, 2009 at 08:40:03PM +0100, Luk Claes wrote: > Ralf Treinen and I are looking for help with the GPG Key Signing > Coordination page. I'm quiet interested in helping out a bit, but for now undecided. > Ralf Treinen and I have been taking care of this page the last

Help needed with the GPG Key Signing Coordination page

2009-01-05 Thread Luk Claes
Hi Ralf Treinen and I are looking for help with the GPG Key Signing Coordination page. The GPG key signing coordination page at http://nm.debian.org/gpg.php is primarily aimed at prospective contributors to find existing Debian developers who can sign their key for the ID part of the NM

Re: [Pkg-fonts-devel] [libmagick9] Help needed defoma

2008-12-23 Thread Paul Wise
On Wed, Dec 24, 2008 at 12:06 AM, Bastien ROUCARIES wrote: > Imagemagick does use a static list of police. This could lead to problem and > user have already send bug report. > Could be possible to help us implementing a defoma script for imagemagick? It would be far far better to

[libmagick9] Help needed defoma

2008-12-23 Thread Bastien ROUCARIES
Tags: help Hi, Imagemagick does use a static list of police. This could lead to problem and user have already send bug report. Could be possible to help us implementing a defoma script for imagemagick? Regards Bastien -- To UNSUBSCRIBE, email to debian-devel-requ...@lists.debian.org with a

Re: Help needed for #377468

2008-12-20 Thread Alexander Sack
On Sat, Dec 20, 2008 at 03:50:21PM +0100, Bastien ROUCARIES wrote: > Hi! > > I would like to ask for some help for the bug #377468, if possible, > please. Particularly from a mozilla-plugin wizard. > > The problem is that djvulibre in upstream is not linked against a particu

Re: Help needed for #377468

2008-12-20 Thread roucaries bastien
On Sat, Dec 20, 2008 at 4:22 PM, Thomas Viehmann wrote: > Bastien ROUCARIES wrote: >> I would like to ask for some help for the bug #377468, if possible, >> please. Particularly from a mozilla-plugin wizard. > > Just having made this choice w.r.t. to nsdejavu and pthread

Re: Help needed for #377468

2008-12-20 Thread Thomas Viehmann
[dropped even more CCs] roucaries bastien wrote: > It seems other plugins have the same problem. Should I open bug report? Well, that depends a bit: a) some of the symbols in your list (NS_*) might be from stuff that can reasonably be expected to always linked into things loading the plugins

Re: Help needed for #377468

2008-12-20 Thread Thomas Viehmann
Bastien ROUCARIES wrote: > I would like to ask for some help for the bug #377468, if possible, > please. Particularly from a mozilla-plugin wizard. > The problem is that djvulibre in upstream is not linked against a particular > libXt > in order to adapt against differen

Help needed for #377468

2008-12-20 Thread Bastien ROUCARIES
Hi! I would like to ask for some help for the bug #377468, if possible, please. Particularly from a mozilla-plugin wizard. The problem is that djvulibre in upstream is not linked against a particular libXt in order to adapt against different libXt version depending of the browser used. The

Bug#508443: Info received (Help for #508443)

2008-12-15 Thread Debian Bug Tracking System
Thank you for the additional information you have supplied regarding this Bug report. This is an automatically generated reply to let you know your message has been received. Your message is being forwarded to the package maintainers and other interested parties for their attention; they will re

Help for #508443

2008-12-15 Thread Nelson A. de Oliveira
Hi! I would like to ask for some help for the bug #508443, if possible, please. The problem is that I don't have a sparc machine (I have access to the developer accessible ones, like smetana.debian.org, but I just can't get an imagemagick package built with the debug symbols nor

Re: Can we help the release by proposing package removals?

2008-12-02 Thread Christian Perrier
Quoting Charles Plessy ([EMAIL PROTECTED]): > Would it help the release team if people who want to help would file properly > argumented requests of removal for such packages? This would clear the RC > radar > and focus energy on the packages without which Debian can not consider

Re: Can we help the release by proposing package removals?

2008-12-02 Thread Cyril Brulebois
Charles Plessy <[EMAIL PROTECTED]> (03/12/2008): > [blablabla for the actual question:] > Subject: Re: Can we help the release by proposing package removals? Look at debian-release@, that's already being done. Mraw, KiBi. signature.asc Description: Digital signature

Can we help the release by proposing package removals?

2008-12-02 Thread Charles Plessy
ly be supplied through backports.debian.org if there were users requesting it and developers willing to contribute time on a mid-term basis. Would it help the release team if people who want to help would file properly argumented requests of removal for such packages? This would clear the RC radar and

Please help solve #504721

2008-11-29 Thread Jurij Smakov
Bcc: debian-devel Hi, We have recently recognized that serial console detection in the installer is not working as expected, which resulted in RC bug http://bugs.debian.org/504721. If you have access to a machine through serial console, please provide debugging information which can help

Bug#505209: ITP: yagtd -- utility to help organize your to-do lists

2008-11-10 Thread Max Vozeler
Description : utility to help organize your to-do lists yagtd is a very simple utility designed to make the management of your to-do list quick and easy. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#502770: ITP: setroubleshoot-plugins -- Tool to help troubleshoot SELinux problems (plugins)

2008-10-19 Thread Pierre Chifflier
Python Description : Tool to help troubleshoot SELinux problems (plugins) Tools to help diagnose SELinux problems. When AVC messages are generated an alert can be generated that will give information about the problem and help track its resolution. Alerts can be configured to user preference. The same

Re: help, error with debian/tmp

2008-10-04 Thread Neil Williams
On Sun, 5 Oct 2008 01:47:52 +0400 ivan <[EMAIL PROTECTED]> wrote: > Hello all > > Please, help me, what i do wrong? Try the [EMAIL PROTECTED] instead. -- Neil Williams = http://www.data-freedom.org/ http://www.nosoftwarepatents.com/ http://www.linux

help, error with debian/tmp

2008-10-04 Thread ivan
Hello all Please, help me, what i do wrong? I try build debian package, but see error: [EMAIL PROTECTED]:/data/soft/pkg/astral/libastral-0.4% dpkg-buildpackage ... install -s libastral.so /data/soft/pkg/astral/libastral-0.4/debian/tmp/usr/lib/ install: указанная цель `/data/soft/pkg/astral

Re: Run "guest CPUs" under Linux? I need your help

2008-09-11 Thread Gunnar Wolf
Craig Small dijo [Fri, Sep 12, 2008 at 12:26:41PM +1000]: > Hello, > I'm the Debian maintainer for procps, which is the package that gives > you things like ps,killall and top. The latest version of procps now > handles all 7 cpu numbers, so all is well? > > Actually no, since kernel 2.6.24 the

Run "guest CPUs" under Linux? I need your help

2008-09-11 Thread Craig Small
Hello, I'm the Debian maintainer for procps, which is the package that gives you things like ps,killall and top. The latest version of procps now handles all 7 cpu numbers, so all is well? Actually no, since kernel 2.6.24 there is a 9th CPU field! It's called a guest field and is the amount of

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-09-07 Thread Javier Fernández-Sanguino Peña
On Tue, Aug 12, 2008 at 03:52:14PM -0700, John H. Robinson, IV wrote: > As mktemp and tempfile are both essential[2], they can be relied upon. Essential in Debian, not in other systems. > Is there any scenario where using mktemp or tempfile fails, and sing > $TMPDIR succeeds? Scripts that are wr

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-08-28 Thread Michelle Konzack
Hi *, a little bit late, but since I am currently working in germany... Am 2008-08-11 17:31:51, schrieb Sam Morris: > A while ago, the use of libpam-tmpdir was suggested in order to mitigate > some of these attacks. It would be nice to see it in use by default, some > day. > > Obviously there

Re: [Help] Problem with blitz++ package (debian lenny, amd64). (fwd)

2008-08-27 Thread Raphael Geissert
Hi Andreas, Andreas Tille wrote: > Hi, > > via Google I have seen that the same problem was reported (and solved, > but I have no idea how to obtain the patch) in archlinux: > > http://bbs.archlinux.org/viewtopic.php?pid=404588 > I didn't see anything useful, but here are the files: http

[Help] Problem with blitz++ package (debian lenny, amd64). (fwd)

2008-08-27 Thread Andreas Tille
Hi, via Google I have seen that the same problem was reported (and solved, but I have no idea how to obtain the patch) in archlinux: http://bbs.archlinux.org/viewtopic.php?pid=404588 The user who reported the problem found out that the following workaround solves the problem on his machine:

[Help] Re: feh: alpha blending (e.g., thumbnail under pointer hilite) not working

2008-08-27 Thread Andreas Tille
. I'm a little bit suspicious about the fact that you wrote the problem would not occure when using the old 4.3.0.dfsg.1-1 version of "xserver-xfree86". I admit I'm not very educated in X server programming and thus I would like to ask for help here on Debian devel list whet

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Raphael Geissert
Charles Plessy wrote: > Le Mon, Aug 25, 2008 at 07:16:00AM +0200, Christian Perrier a écrit : >> >> - timing wrt the release >> - timing wrt the "half of the developers are VAC" status we generally >> have in August >> - the obvious lack of preparation > > In addition, security issues should b

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Moritz Muehlenhoff
Christian Perrier wrote: >> This is far below the quality I expect from a mass bug filing that's been >> reviewed by debian-devel. Mass bugfilings at RC severity need to be held to > > Even though I overread the thread when Dmitry posted his intent to > -devel, I feel like there was *no* strong a

Re: Help supporting Debian on a Kurobox

2008-08-25 Thread RalfGesellensetter
now to etch. This system image is already tarred and available for > others to see, if necessary. Hi Brito, interesting hardware. Do you know http://www.harunana.jp/apache2-default/index.php?Debian%EF%BC%9Awoody%E2%86%92sarge%E5%8C%96 ? Maybe you can get help there. Regards Ralf -- To UNS

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Neil Williams
On Mon, 2008-08-25 at 14:17 +0400, Dmitry E. Oboukhov wrote: > NW>>> An attacker would be insane to select this example as a > NW>>> vehicle. > NW>> > NW>> Attacker can use many ways (all variants from this list, for ex), one of > NW>> its can work. Why you think that this variant is not work? >

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Martin Langhoff
On Mon, Aug 25, 2008 at 10:17 PM, Dmitry E. Oboukhov <[EMAIL PROTECTED]> wrote: > NW> Because it is in the documentation, not the script. Didn't you read the > NW> reply? It is not a route of attack, it is AN EXAMPLE in the > NW> documentation! > This script marked as executable. > User can start i

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Dmitry E. Oboukhov
NW>>> An attacker would be insane to select this example as a NW>>> vehicle. NW>> NW>> Attacker can use many ways (all variants from this list, for ex), one of NW>> its can work. Why you think that this variant is not work? NW> Because it is in the documentation, not the script. Didn't you read t

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Charles Plessy
Le Mon, Aug 25, 2008 at 07:16:00AM +0200, Christian Perrier a écrit : > > - timing wrt the release > - timing wrt the "half of the developers are VAC" status we generally > have in August > - the obvious lack of preparation In addition, security issues should better be reported upstream first s

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Neil Williams
On Mon, 2008-08-25 at 10:09 +0200, Thijs Kinkhorst wrote: > On Sunday 24 August 2008 22:00, Steve Langasek wrote: > > Please take responsibility for providing the missing information to the > > package maintainers, and for correcting the false positives that you've > > filed. > > Yes, please. I th

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Neil Williams
On Mon, 2008-08-25 at 10:09 +0200, Thijs Kinkhorst wrote: > On Sunday 24 August 2008 22:00, Steve Langasek wrote: > > Please take responsibility for providing the missing information to the > > package maintainers, and for correcting the false positives that you've > > filed. > > Yes, please. I th

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Neil Williams
On Mon, 2008-08-25 at 11:57 +0400, Dmitry E. Oboukhov wrote: > NW> An attacker would be insane to select this example as a > NW> vehicle. > > Attacker can use many ways (all variants from this list, for ex), one of > its can work. Why you think that this variant is not work? Because it is in the

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Dmitry E. Oboukhov
TK>> Quoting Steve Langasek ([EMAIL PROTECTED]): TK>>> This is far below the quality I expect from a mass bug filing that's been TK>>> reviewed by debian-devel. Mass bugfilings at RC severity need to be held TK>>> to TK>> TK>> Even though I overread the thread when Dmitry posted his intent to TK>

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Thijs Kinkhorst
On Sunday 24 August 2008 22:00, Steve Langasek wrote: > Please take responsibility for providing the missing information to the > package maintainers, and for correcting the false positives that you've > filed. Yes, please. I think the only way the damage of this bad bug filing can be mitigated i

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Thijs Kinkhorst
On Monday 25 August 2008 07:16, Christian Perrier wrote: > Quoting Steve Langasek ([EMAIL PROTECTED]): > > This is far below the quality I expect from a mass bug filing that's been > > reviewed by debian-devel. Mass bugfilings at RC severity need to be held > > to > > Even though I overread the th

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Dmitry E. Oboukhov
NW> An attacker would be insane to select this example as a NW> vehicle. Attacker can use many ways (all variants from this list, for ex), one of its can work. Why you think that this variant is not work? -- . ''`. Dmitry E. Oboukhov : :’ : [EMAIL PROTECTED] `. `~’ GPGKey: 1024D / F8E26537 2006

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-25 Thread Christian Perrier
Quoting Steve Langasek ([EMAIL PROTECTED]): > This is far below the quality I expect from a mass bug filing that's been > reviewed by debian-devel. Mass bugfilings at RC severity need to be held to Even though I overread the thread when Dmitry posted his intent to -devel, I feel like there was

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
On Sun, Aug 24, 2008 at 06:44:57PM -0700, Russ Allbery wrote: > Steve Langasek <[EMAIL PROTECTED]> writes: > > The example *is* wrong - the example given is never safe to run, because > > the only way to verify beforehand that /tmp/zenity is not a symlink to > > something more important is by firs

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Peter Samuelson
[Neil Williams] > $ pilot-qof -x data.xml --invoice-city -t 2006-11-08 | dfxml-invoice - \ > | zenity --text-info --title="2006-11-08" - > > 2. Unnecessarily complicated for documentation (the need for '\' is, > IMHO, an indication that the command is too long). Not to disagree with your real t

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Russ Allbery
Steve Langasek <[EMAIL PROTECTED]> writes: > The example *is* wrong - the example given is never safe to run, because > the only way to verify beforehand that /tmp/zenity is not a symlink to > something more important is by first explicitly *creating* your file > funder /tmp (non-destructively), t

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Bernd Eckenfels
In article <[EMAIL PROTECTED]> you wrote: > Yes, a race condition could happen and yes, there could be all sorts of > complicated ways of handling temp files and passing back the name of the > file but examples have to be simple and clear, not obfuscated by > problems unrelated to the nature of the

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Neil Williams
On Sun, 2008-08-24 at 13:30 -0700, Steve Langasek wrote: > On Sun, Aug 24, 2008 at 08:28:32PM +0100, Neil Williams wrote: > > =head1 > > A more complex example using 'zenity' - a Gnome dialog generator. > > > $ pilot-qof -x data.xml --invoice-city -t 2006-11-08 | dfxml-invoice - > > > /tmp/zenity

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
On Sun, Aug 24, 2008 at 08:28:32PM +0100, Neil Williams wrote: > > For example if a script uses in its work a temp file which is created > > in /tmp directory, then every user can create symlink with the same > > name in this directory in order to destroy or rewrite some system > > or user

Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
On Sun, Aug 24, 2008 at 10:05:30PM +0400, Dmitry E. Oboukhov wrote: > Package: initramfs-tools > Severity: grave > This message about the error concerns a few packages at once. I've > tested all the packages (for Lenny) on my Debian mirror. All scripts > of packages (marked as executable) we

Re: Bug#496429: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Neil Williams
s a few times). Why make the example unnecessarily complicated? All it needed to show was that the redirect needs to create a file which zenity can then read. > This list is created with the help of script. This list is sorted by > hand. Howewer in some cases mistake is possible. You'

Re: Help supporting Debian on a Kurobox

2008-08-22 Thread Luca Capello
Hi Rogério! Please don't Cc: me, I read the debian-devel list. On Fri, 22 Aug 2008 17:11:45 +0200, Rogério Brito wrote: > On Aug 22 2008, Sven Luther wrote: >> 1) U-boot is able to boot a uimage. > > Right, but how does one generate this uImage? Will it be side-by-side > of a normal kernel imag

Re: Help supporting Debian on a Kurobox

2008-08-22 Thread Rogério Brito
attach a serial console, but this > involves some soldering on the board. Search the web for instructions on > how to do this. I don't even know if the kernel has serial support compiled in. I will check this. > > Right, but the current heartbeat daemon seems to be independent of

Re: Help supporting Debian on a Kurobox

2008-08-22 Thread Rogério Brito
ge. Some init > > scripts also seem to be needed. > > Ok, but that is *AFTER* you have booted the kernel, right ? So, the > first order of things is to add generation fo a uboot uImage out of the > debian klernel, and maybe you need to enable Right, but the current heartbeat daemon

Re: Help supporting Debian on a Kurobox

2008-08-22 Thread Rogério Brito
Hi, Guennadi. Thanks for your answer. On Aug 22 2008, Guennadi Liakhovetski wrote: > Hi, > > ask on #linkstationwiki on FreeNode, or talk on > http://www.nas-central.org/ forums, or post to > [EMAIL PROTECTED] (might need to subscribe). Visiting the site, it seems that some people there seem t

Re: Help supporting Debian on a Kurobox

2008-08-22 Thread Rogério Brito
Hi, Sven. On Aug 22 2008, Sven Luther wrote: > On Fri, Aug 22, 2008 at 09:14:04AM -0300, Rogério Brito wrote: > > Since this is my first incursion into the embedded arena, I would welcome > > any help (and, BTW, learn and collaborate with the emdebian project with my &

Re: Help supporting Debian on a Kurobox

2008-08-22 Thread Guennadi Liakhovetski
and NewWorld PowerMacs). > > * There seems to be some daemons (heartbeat daemons) and utilities that > need special attention (read: packaging) and that are not yet available > in Debian (or outdated), together with corresponding initscripts. > > Since this is my first incursion into

Help supporting Debian on a Kurobox

2008-08-22 Thread Rogério Brito
e any help (and, BTW, learn and collaborate with the emdebian project with my own packages). It seems to me that a special kernel should be compiled, that special devices should be created (apparently, the current udev/kernels don't create the necessary devices needed so that the device doesn&#x

Re: Newby packager need help during his training ;)

2008-08-20 Thread Laurent Guignard
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 sean finney a écrit : > hiya, > > On Wednesday 20 August 2008 03:40:41 pm Laurent Guignard wrote: >> I just began to build a package. I read some tutorial and I have a small >> question : > > in addition to the other suggestions, it should be pointed

Re: Newby packager need help during his training ;)

2008-08-20 Thread sean finney
hiya, On Wednesday 20 August 2008 03:40:41 pm Laurent Guignard wrote: > I just began to build a package. I read some tutorial and I have a small > question : in addition to the other suggestions, it should be pointed out that a more appropriate (and possibly more helpful) mailing list for this t

Re: Newby packager need help during his training ;)

2008-08-20 Thread Andreas Bombe
On Wed, Aug 20, 2008 at 03:40:41PM +0200, Laurent Guignard wrote: > How to update configuration files stored in local users home directory > with these contained in package and save the previous configuration > files somewhere in the filesystem hierarchy ? You don't do that at all. The contents o

Re: Newby packager need help during his training ;)

2008-08-20 Thread Neil Williams
On Wed, 2008-08-20 at 15:40 +0200, Laurent Guignard wrote: > I just began to build a package. I read some tutorial and I have a small > question : > How to update configuration files stored in local users home directory Generally, packages don't do that - it is up to the runtime program to handle

Newby packager need help during his training ;)

2008-08-20 Thread Laurent Guignard
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello, I just began to build a package. I read some tutorial and I have a small question : How to update configuration files stored in local users home directory with these contained in package and save the previous configuration files somewhere in th

Re: Bug#495705: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-08-19 Thread Russ Allbery
"Dmitry E. Oboukhov" <[EMAIL PROTECTED]> writes: > Package: lintian > Tags: patch, security > Severity: wishlist > > Hello, lintan maintainers! > please, see full discussion in -devel: > http://lists.debian.org/debian-devel/2008/08/msg00271.html > for example, see the bug > http://bugs.d

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-08-19 Thread Dmitry E. Oboukhov
Package: lintian Tags: patch, security Severity: wishlist Hello, lintan maintainers! please, see full discussion in -devel: http://lists.debian.org/debian-devel/2008/08/msg00271.html for example, see the bug http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494648 (if attacker m

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-08-16 Thread Vincent Danjean
Brian May wrote: > Ivan Jager wrote: >> qemu-make-debian-root will continue running even if mkdir failed. > Dmitry said the script has -e set - if so the script will not continue > running if mkdir failed (unless it somehow overrides the -e check, e.g. > mkdir /tmp/file || true). You must take car

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-08-15 Thread Brian May
Ivan Jager wrote: qemu-make-debian-root will continue running even if mkdir failed. Dmitry said the script has -e set - if so the script will not continue running if mkdir failed (unless it somehow overrides the -e check, e.g. mkdir /tmp/file || true). Also, assuming qemu-make-debian-root is

Bug#495026: ITP: chessclock -- a simple chess clock to help track time in real life games

2008-08-13 Thread The Anarcat
Lang: Python Description : a simple chess clock to help track time in real life games This is a fairly simple application designed to track the time spent thinking by the players during a chess game. Various ways of tracking time are supported, with only "countdown" (aka "blitz&

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-08-13 Thread Dmitry E. Oboukhov
Report of sid: http://uvw.ru/report.sid.txt -- ... mpd is off . ''`. Dmitry E. Oboukhov : :’ : [EMAIL PROTECTED] `. `~’ GPGKey: 1024D / F8E26537 2006-11-21 `- 1B23 D4F8 8EC0 D902 0555 E438 AB8C 00CF F8E2 6537 signature.asc Description: Digital signature

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-08-13 Thread Ivan Jager
On Wed, 13 Aug 2008, Brian May wrote: Dmitry E. Oboukhov wrote: qemu makes mount the directory /tmp/mount.$$. Attacker creates many symlinks /tmp/dir.\d+ -> /etc and if qemu (/usr/sbin/qemu-make-debian-root) starts then /etc goes out from root directory tree. The result: system is unusable. I

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-08-13 Thread Bjørn Mork
"Dmitry E. Oboukhov" <[EMAIL PROTECTED]> writes: > On 18:42 Wed 13 Aug , Brian May wrote: >> Dmitry E. Oboukhov wrote: >>> qemu makes mount the directory /tmp/mount.$$. Attacker creates many >>> symlinks /tmp/dir.\d+ -> /etc and if qemu >>> (/usr/sbin/qemu-make-debian-root) starts then /etc goe

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-08-13 Thread Dmitry E. Oboukhov
On 18:42 Wed 13 Aug , Brian May wrote: > Dmitry E. Oboukhov wrote: >> qemu makes mount the directory /tmp/mount.$$. Attacker creates many >> symlinks /tmp/dir.\d+ -> /etc and if qemu >> (/usr/sbin/qemu-make-debian-root) starts then /etc goes >> out from root directory tree. The result: system i

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-08-13 Thread Brian May
Dmitry E. Oboukhov wrote: qemu makes mount the directory /tmp/mount.$$. Attacker creates many symlinks /tmp/dir.\d+ -> /etc and if qemu (/usr/sbin/qemu-make-debian-root) starts then /etc goes out from root directory tree. The result: system is unusable. I might be dense, but I don't get this.

Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages

2008-08-12 Thread Dmitry E. Oboukhov
Some people wrote to me: your script is bad, it detects qemu, but qemu is bugfree. ok, looking qemu: qemu makes mount the directory /tmp/mount.$$. Attacker creates many symlinks /tmp/dir.\d+ -> /etc and if qemu (/usr/sbin/qemu-make-debian-root) starts then /etc goes out from root directory tree.

<    6   7   8   9   10   11   12   13   14   15   >