Re: F40 Change Proposal: Unified Kernel Support Phase Two (System-Wide)

2023-12-06 Thread Daniel P . Berrangé
On Tue, Dec 05, 2023 at 04:14:00PM -0500, Neal Gompa wrote: > On Tue, Dec 5, 2023 at 3:47 PM Aoife Moloney wrote: > > > > This document represents a proposed Change. As part of the Changes > > process, proposals are publicly announced in order to receive > > community feedback. This proposal will

[Test-Announce] Fedora 40 Rawhide 20231206.n.0 nightly compose nominated for testing

2023-12-06 Thread rawhide
Announcing the creation of a new nightly release validation test event for Fedora 40 Rawhide 20231206.n.0. Please help run some tests for this nightly compose if you have time. For more information on nightly release validation testing, see: https://fedoraproject.org/wiki

Non-responsive maintainer check for Samuel P (survient)

2023-12-06 Thread Ondřej Holý
Hi, this email is part of the non-responsive maintainer policy for the wsdd package: https://bugzilla.redhat.com/show_bug.cgi?id=2253133 It would be nice to update the package to the latest upstream: https://bugzilla.redhat.com/show_bug.cgi?id=2175523 I proposed a pull request for it two months

Re: F40 Change Proposal: Unified Kernel Support Phase Two (System-Wide)

2023-12-06 Thread Gerd Hoffmann
On Tue, Dec 05, 2023 at 03:01:04PM -0600, Chris Adams wrote: > Once upon a time, Aoife Moloney said: > > * UKIs need this to find the root filesystem without root=... on the > > kernel command line. > > How does this work in system with more than one Linux install? Or any > more-complicated disk

Re: Obsoleting zlib in Fedora Rawhide

2023-12-06 Thread Miro Hrončok
On 06. 12. 23 0:09, Yaakov Selkowitz wrote: Except that it's not 100% compatible, since all those packages aren't building/working with zlib-ng-compat. At a minimum, you should be able to show that everything zlib-dependent successfully rebuilds with this, and since you've already identified som

Re: F40 Change Proposal: Unified Kernel Support Phase Two (System-Wide)

2023-12-06 Thread Gerd Hoffmann
Hi, > What is the point of using shim in this path? We're not having UKIs > signed by Microsoft, and unless the Linux kernel knows how to call > shim for certificates, I don't see how this is supposed to be useful > for the Microsoft->Fedora->OS boot chain. Booting without shim.efi would work

Change of cronie and crontabs CIS compliance

2023-12-06 Thread Ondrej Pohorelsky
Hi everyone, For F40 I would like to change file permissions of few files that are provided by cronie and crontabs and swap deny list for allow list. I'm not really sure if I should make a change proposal. I figured I'll send an email first and see the feedback. The driving force of this change i

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Michael J Gruber
Am Mi., 6. Dez. 2023 um 11:17 Uhr schrieb Ondrej Pohorelsky < opoho...@redhat.com>: > Hi everyone, > > For F40 I would like to change file permissions of few files that are > provided by cronie and crontabs and swap deny list for allow list. I'm not > really sure if I should make a change proposal

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Ondrej Pohorelsky
On Wed, Dec 6, 2023 at 11:26 AM Michael J Gruber wrote: > Hi there, > > what is the impact of these changes: > - Do default installs work the same way as before? > - Do existing setups (crontabs) keep working? > > If yes then I'd consider the permission changes to be fixes, or at least > standard

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Michael J Gruber
Am Mi., 6. Dez. 2023 um 12:09 Uhr schrieb Ondrej Pohorelsky < opoho...@redhat.com>: > > > On Wed, Dec 6, 2023 at 11:26 AM Michael J Gruber > wrote: > >> Hi there, >> >> what is the impact of these changes: >> - Do default installs work the same way as before? >> - Do existing setups (crontabs) ke

Fedora rawhide compose report: 20231206.n.0 changes

2023-12-06 Thread Fedora Rawhide Report
OLD: Fedora-Rawhide-20231205.n.1 NEW: Fedora-Rawhide-20231206.n.0 = SUMMARY = Added images:2 Dropped images: 7 Added packages: 3 Dropped packages:18 Upgraded packages: 67 Downgraded packages: 0 Size of added packages: 5.42 MiB Size of dropped packages

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Fabio Valentini
On Wed, Dec 6, 2023 at 11:17 AM Ondrej Pohorelsky wrote: > > Hi everyone, > > For F40 I would like to change file permissions of few files that are > provided by cronie and crontabs and swap deny list for allow list. I'm not > really sure if I should make a change proposal. I figured I'll send a

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Ondrej Pohorelsky
On Wed, Dec 6, 2023 at 12:32 PM Michael J Gruber wrote: > > Thanks, that sounds like the typical things to expect during an upgrade. > We typically don't even have release notes mentioning this, but it would be > nice, since it's even a "plus" for F40 (compliance, hardening). > > Does that mean m

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Daniel P . Berrangé
On Wed, Dec 06, 2023 at 12:39:02PM +0100, Fabio Valentini wrote: > On Wed, Dec 6, 2023 at 11:17 AM Ondrej Pohorelsky wrote: > > > > Hi everyone, > > > > For F40 I would like to change file permissions of few files that are > > provided by cronie and crontabs and swap deny list for allow list. I'm

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Ondrej Pohorelsky
On Wed, Dec 6, 2023 at 12:39 PM Fabio Valentini wrote: > On Wed, Dec 6, 2023 at 11:17 AM Ondrej Pohorelsky > wrote: > > > > Hi everyone, > > > > For F40 I would like to change file permissions of few files that are > provided by cronie and crontabs and swap deny list for allow list. I'm not > re

Orphaned packages looking for new maintainers

2023-12-06 Thread Miro Hrončok
The following packages are orphaned and will be retired when they are orphaned for six weeks, unless someone adopts them. If you know for sure that the package should be retired, please do so now with a proper reason: https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life Note: If

Copr builds are stuck at package signing

2023-12-06 Thread František Šumšal
Hey, Thanks to Packit I noticed that a lot of our jobs are running longer than usual, and a quick glance at the Copr task queue[0] tells me there's something fishy going on. I opened a couple of jobs[1][2][3] and all of them seem to be stuck in the same step - signing the build RPMs: builder-

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Tom Hughes via devel
On 06/12/2023 11:08, Ondrej Pohorelsky wrote: The only difference is that if you have populated the cron.deny list, after update it gets saved as .rpmsave and cron.allow is created. If the cron.deny is blank, it will get replaced. Also, if you had cron.allow populated before, it will stay this

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Daniel P . Berrangé
On Wed, Dec 06, 2023 at 11:53:26AM +, Tom Hughes via devel wrote: > On 06/12/2023 11:08, Ondrej Pohorelsky wrote: > > > The only difference is that if you have populated the cron.deny list, > > after update it gets saved as .rpmsave and cron.allow is created. > > If the cron.deny is blank, it

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Stephen Smoogen
On Wed, 6 Dec 2023 at 06:49, Ondrej Pohorelsky wrote: > > > On Wed, Dec 6, 2023 at 12:39 PM Fabio Valentini > wrote: > >> On Wed, Dec 6, 2023 at 11:17 AM Ondrej Pohorelsky >> wrote: >> > >> > Hi everyone, >> > >> > For F40 I would like to change file permissions of few files that are >> provide

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Daniel P . Berrangé
On Wed, Dec 06, 2023 at 11:16:44AM +0100, Ondrej Pohorelsky wrote: > Hi everyone, > > For F40 I would like to change file permissions of few files that are > provided by cronie and crontabs and swap deny list for allow list. I'm not > really sure if I should make a change proposal. I figured I'll

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Nikos Mavrogiannopoulos
On Wed, Dec 6, 2023 at 1:19 PM Daniel P. Berrangé wrote: > > On Wed, Dec 06, 2023 at 11:16:44AM +0100, Ondrej Pohorelsky wrote: > > Hi everyone, > > > > For F40 I would like to change file permissions of few files that are > > provided by cronie and crontabs and swap deny list for allow list. I'm

Re: Obsoleting zlib in Fedora Rawhide

2023-12-06 Thread Tulio Magno Quites Machado Filho
Yaakov Selkowitz writes: > Except that it's not 100% compatible, since all those packages aren't > building/working with zlib-ng-compat. At a minimum, you should be able > to show that everything zlib-dependent successfully rebuilds with this, I'm afraid I was not clear enough. Packages built w

Re: F40 Change Proposal: Unified Kernel Support Phase Two (System-Wide)

2023-12-06 Thread Neal Gompa
On Wed, Dec 6, 2023 at 5:15 AM Gerd Hoffmann wrote: > > Hi, > > > What is the point of using shim in this path? We're not having UKIs > > signed by Microsoft, and unless the Linux kernel knows how to call > > shim for certificates, I don't see how this is supposed to be useful > > for the Micros

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Ondrej Pohorelsky
On Wed, Dec 6, 2023 at 1:02 PM Daniel P. Berrangé wrote: > On Wed, Dec 06, 2023 at 11:53:26AM +, Tom Hughes via devel wrote: > > On 06/12/2023 11:08, Ondrej Pohorelsky wrote: > > > > > The only difference is that if you have populated the cron.deny list, > > > after update it gets saved as .r

Re: Change of cronie and crontabs CIS compliance

2023-12-06 Thread Ondrej Pohorelsky
On Wed, Dec 6, 2023 at 1:19 PM Daniel P. Berrangé wrote: > On Wed, Dec 06, 2023 at 11:16:44AM +0100, Ondrej Pohorelsky wrote: > > Hi everyone, > > > > For F40 I would like to change file permissions of few files that are > > provided by cronie and crontabs and swap deny list for allow list. I'm >

Re: F40 Change Proposal: Unified Kernel Support Phase Two (System-Wide)

2023-12-06 Thread Gerd Hoffmann
Hi, > Does that mean that the Linux EFI boot code knows how to call back to > shim to get the certificates instead of reading the firmware directly? No. The linux efi stub doesn't need that. shim.efi does: (a) Set efi variables, where the linux kernel can read the certificates from.

Re: Copr builds are stuck at package signing

2023-12-06 Thread Miroslav Suchý
Dne 06. 12. 23 v 12:52 František Šumšal napsal(a): Hey, Thanks to Packit I noticed that a lot of our jobs are running longer than usual, and a quick glance at the Copr task queue[0] tells me there's something fishy going on. I opened a couple of jobs[1][2][3] and all of ... Looks like the last

Re: Obsoleting zlib in Fedora Rawhide

2023-12-06 Thread Daniel Alley
> Except that it's not 100% compatible, since all those packages aren't > building/working with zlib-ng-compat. At a minimum, you should be able > to show that everything zlib-dependent successfully rebuilds with this, > and since you've already identified some that don't, IMO they should be > fix

Re: F40 Change Proposal: Unified Kernel Support Phase Two (System-Wide)

2023-12-06 Thread Vitaly Kuznetsov
Gerd Hoffmann writes: > Hi, > >> Does that mean that the Linux EFI boot code knows how to call back to >> shim to get the certificates instead of reading the firmware directly? > > No. The linux efi stub doesn't need that. > > shim.efi does: > > (a) Set efi variables, where the linux kernel

Re: F40 Change Proposal: Unified Kernel Support Phase Two (System-Wide)

2023-12-06 Thread Luca Boccassi
> Gerd Hoffmann this AFAIU means that we also need shim in the boot chain if we want to > support these addons. Only if you want to use certs in MOK to verify them, otherwise it's not necessary. The protocol is just LoadImage which every firmware also provides and checks against DB. --

Fedora CoreOS Meeting Minutes 2023-12-06

2023-12-06 Thread Dusty Mabe
Text Log: https://meetbot.fedoraproject.org/meeting-1_matrix_fedoraproject-org/2023-12-06/fedora-coreos-meeting.2023-12-06-16.31.log.txt HTML Log: https://meetbot.fedoraproject.org/meeting-1_matrix_fedoraproject-org/2023-12-06/fedora-coreos-meeting.2023-12-06-16.31.log.html Text Minutes: https:/

Re: Synching user database from Fedora IPA to pagure

2023-12-06 Thread Pierre-Yves Chibon
On Tue, Nov 28, 2023 at 10:13:35AM +, Mattia Verga via devel wrote: > I'd like to start writing a script to synch users/groups from Fedora IPA > to pagure.io and src.fp.o: both pagure.io and src.fp.o logins are based > on Fedora accounts, but the Pagure user database is only updated when a >

SoPlex and SCIP review swaps

2023-12-06 Thread Jerry James
Kevin Kofler noted about a year ago [1] that new versions of the solvers SoPlex [2] and SCIP [3] were released under free software licenses. Over the last year, I've been working little by little on building them in a COPR [4] and rebuilding various Fedora packages with SoPlex and SCIP support. I

Re: Update on the Modern C initiative

2023-12-06 Thread Kevin Kofler via devel
Florian Weimer wrote: > Although the critical type size mismatch happens on 32-bit architectures > and Windows only. Problems like these are the reason why I don't think > the Clang approach of restricting to incompatible-function-pointer-types > only makes much sense. Uhm, yeah, there are certai

Re: Review swaps for deps needed for conda update

2023-12-06 Thread Orion Poplawski
On 12/2/23 19:32, Orion Poplawski wrote: I have a number of packages needing review that are required for the latest round of updates to the conda package manager: https://bugzilla.redhat.com/buglist.cgi?bug_id=2025802&bug_id_type=anddependson&format=tvp&list_id=13378412# I'm particularly exci