LWN.net Weekly Edition for January 17, 2008
Making code reviews easier with Review Board
Reviewing code is a thankless, but very important, task for any software project. For free software projects, the "many eyes make all bugs shallow" aphorism only works if the eyes actually focus on the code in question. Review Board is a web-based application that helps reviewers examine the code, while making it easier for a developer to track those reviews.
Borne out of frustration with the process of code reviews at VMware, Review Board has made a great deal of progress since being released last May. The idea behind it is to centralize all of the pieces that need to come together for a review: code diffs, screenshots of UI functionality, comments by other developers, etc. On many projects, reviews are handled by email, but that can be difficult to use; various pieces of the puzzle are spread around in multiple messages and locations.
Often a reviewer needs to see more context than a simple email diff provides or wants to comment on a related section of code that is not contained in the diff; each requires a reviewer to do more work. In a complicated set of changes, ensuring that the developer and any other reviewers can follow what code the comments pertain to can also be difficult. It is these kinds of problems that Review Board is meant to solve.
Review Board presents a side-by-side diff view, shown at right, with lots of extras, many of which will be familiar to users of other graphical diff tools. Changed lines are highlighted in different colors based on whether they are additions, deletions, or changes. Changes on a particular line are highlighted in a slightly darker color so that they can be distinguished more easily as well. The numbered tabs along the left edge provide a link to a reviewer's comments about that section of the code. This is where Review Board shows that it is much more than just a diff viewer.
Using AJAX techniques, Review Board allows a reviewer to interact very naturally with the code. They can highlight a certain section, which will pop up a text widget that records comments associated with that section of code. When other reviewers or the developer read those comments, the code snippet is included, with a link back to the code in the diff view. Each of these comments can then be commented upon which allows for a conversation about the code to develop.
It is not just code that can be annotated; screenshots of application functionality or bugs can be attached to reviews, as well. Sections of the screenshot can be highlighted and commented upon, as shown at left. This feature is an excellent example of where a web-based tool can shine; doing the same task in text-based email would be painful. Not all projects need it, but those that do will find it quite useful as anyone who has spent time trying to describe a UI problem in email will attest.
Inter-diffs is another useful feature that Review Board provides. Often in the code review process, several revisions of the original patch are made. It can be tedious to wade through a large diff, most of which has been uncontroversial (or resolved earlier) to get to the changes in the area of interest. Review Board has the ability to see changes between any two revisions of the patch, which should reduce much of the hassle.
Another thing that Review Board does is to assist in managing code reviews. When a developer posts something for review, various reviewers can be notified via email. Review Board keeps track of that information, presenting users with a "dashboard" view of their pending reviews, both those they submitted and those that others have asked them to do. This high-level overview is the first screen the user sees when they log on to the system, shown at right. This makes keeping track of work that needs to be done – or who to prod to get a review moving again – much easier.
Currently, Review Board best supports the Subversion and Perforce version control systems (VCS), but support for others, including distributed VCS Mercurial and git, are being actively developed and are usable in their current states. Released under an MIT license, Review Board is written in Python, using the Django web framework. Development is hosted at Google Code; the developers, unsurprisingly, uses the software for internal code reviews.
Other systems to assist in the code review process do exist. Codestriker is a Perl based web application that has similar aspirations to Review Board. Also of interest is Python founder Guido van Rossum's first project at Google: a code review system he calls "Mondrian". It is closely tied to Google proprietary code, though, so it seems unlikely to be released as free software – though it might make an appearance as a tool for Google Code projects to use.
Code reviews are very powerful, but generally painful to perform; any
tool that claims that "Code reviews are fun again!
...almost.
", as Review Board does, will be welcomed by many. It
will be interesting to see whether a code review tracker becomes a standard
part of newer free software projects. Over the last few years, we have
seen the rise of distributed VCS, bug trackers, and wikis to assist in
distributed development. Will Review Board – or something like it
– be the next tool to be added?
SAMP?
A few articles making predictions for 2008 had put an initial public offering by MySQL on their list. The company had clearly been heading in that direction for a while; sales were growing, venture capital was coming in, etc. In the end, though, the MySQL IPO seems destined not to happen - Sun Microsystems got there first. The deal is structured as a full acquisition - Sun will pay about $800 million for all outstanding shares of MySQL stock. In addition, about $200 million in options will be covered, so, overall, this is a billion-dollar deal. Not bad for a company which is based on free software.Sun is making the right noises about how this deal will work. There is no talk of taking MySQL proprietary or changing its license. MySQL will continue to be supported on all platforms, and not just Solaris. A series of grants will be made to help university researchers advance the state of the art in database management systems. There is a lot of talk about continuing to support "the community," though details are (perhaps necessarily) scarce. CEO Jonathan Schwartz says that Sun will be working to improve "the rest of the LAMP" stack, though he says nothing about the "L" (for Linux) part.
Chances are that this deal will be a good thing for MySQL users. Sun is clearly making MySQL an important part of its overall strategy (in these days, one does not toss $1 billion toward unimportant objectives) and can be expected to continue - or accelerate - development of the system. Sun's free software orientation is strong enough that the chances of parts or all of MySQL going proprietary seem small. Indeed, nothing in Sun's releases says anything about MySQL's commercial licensing business; the emphasis appears to be strongly on support and services. So MySQL might just become even more open than it is now.
Sun appears to be positioning itself to compete strongly with Oracle. Both companies are working hard to be able to offer the entire software stack to their customers. So Oracle's push into the Linux distribution business and Sun's database venture are both aimed at having the same story for their sales staff to tell: we, in some way, own and control all of the software you are looking to run. No problems with incompatibilities, finger-pointing, etc. As an added bonus, Sun will happily sell you the hardware you need too. Do expect an increase in efforts aimed at moving MySQL users away from the (Oracle-owned) InnoDB engine, though.
For Sun to sell that story, though, it will to have continue to push Solaris hard as an alternative to Linux. Either that, or the company will eventually find itself shopping for a Linux distributor of its own. Either way, it seems likely that competitive pressures for operating systems (and higher layers) sales and support are set to increase, especially in the high-performance web server area. Red Hat, whose PostgreSQL-based database offering appears to have fallen below the radar, may find itself scrambling for a response.
Sun makes a big point of being able to sell the entire package, and there is some truth to that. Processors, storage, systems software, database software, programming languages, office suites, and more can all be had from one company. What remains to be seen is whether this is really what customers want. There is a lot of value in being able to integrate components from multiple sources and not being dependent on a single vendor. Your editor, who managed a transition from being an all-DEC shop to an all-Sun shop some twenty years ago, is not convinced that those days are worth going back to.
Ten-year timeline, part 2: the bubble days
Last week, we began a multi-part series looking at the soon-to-be ten years of LWN. At the end of that episode, we were coming to the realization that the training business was, perhaps, not going to perform quite as well as our spreadsheets had suggested it might. It turns out that spreadsheets created with free software can be just as deceptive as those done with proprietary programs - who would have ever guessed? So we decided to look into whether it might be possible to make some sort of deal with some other company - preferably one with some money - to keep the show going.Just how one might go about looking for such a deal is not immediately obvious - especially if you're a bunch of technical people who have no clue about how corporate acquisitions are done. Somehow, hanging an "Acquire Us!" sign on the front page did not quite seem like the right way to go. After some thought, we decided that the best approach might be to just quietly slip the word to a few people that we might be open to offers, then sit back and see what happened. As it turned out, that was all we needed to do. Much of the following story has never been told - but all of the non-disclosure agreements have run out by now, so this seems like the right time.
Meanwhile, things were happening at a furious pace in the Linux community.
- August 26, 1999: Red Hat
and Caldera get around to year-2000 compliance. The 2.3.15 patch is
"huge", touching all of 600 files (2.6.24 currently has changes to
over 10,000 files). The first
Ottawa Linux Symposium concludes.
- September 2, 1999: Sun
buys StarDivision, but uses its "community source license" for the
code. Red Hat shuts down "Red Hat Linux" vendors on Amazon.
- September 9, 1999: SCO
(old SCO, mind you, not the current company) trashes Linux in Europe.
Bruce Perens worries that Sun may be trying to grab control of the
Linux desktop through its acquisition of StarDivision. Disruptive
changes in the "stable" 2.2 kernel upset users.
- September 16, 1999: the 2.3 kernel goes into "feature freeze," with Linus predicting a release by the end of the year. He neglected to specify which year, though. Cobalt networks files to go public. LinuxOne - a company nobody had ever heard of - files to go public. Andover.net (the company which had bought Slashdot) files to go public. The first ext3 filesystem patches are released.
The 2.3 feature freeze is instructive - 2.4.0 was not released until January, 2001 - 16 months after this "freeze" went into effect. Over the next months we'll see plenty of reasons for the delay in the 2.4.0 release; Linus was famously not a great release manager. But releases which failed to arrive were the norm back in those days. Free software was much like proprietary software in that regard. One has to look back to realize just how much better we have gotten at getting software releases out in a reasonable period of time.
The IPO filings were beginning to pile up - much to your editor's chagrin. Actually reading those things is a painful chore, and we felt that we needed to examine all of them. The relative newcomers out there may be wondering who that LinuxOne company is. So were we, at the time. LinuxOne materialized out of thin air, slapped its name onto a copy of Red Hat Linux, and called itself a Linux company. They clearly hoped to get in on the general mania and make a bunch of money before people caught on - they nearly achieved it, too.
- September 30, 1999: Caldera spinoff Lineo gets going - remember Embedix and Embrowser? Red Hat drops LWN news from its web site.
Lineo got spun out of Caldera for a couple of apparent reasons: (1) to isolate the DR-DOS lawsuit which was being pursued against Microsoft, and (2) to try to double the number of public offerings. The first objective was achieved, and the suit was ultimately successful. In the end, though, Lineo still failed to get off the ground.
- October 7, 1999: Sun
announces that it will be releasing the Solaris source code. The
OpenBSD project grabs the last freely-licensed version of ssh and
starts the OpenSSH project.
- October 14, 1999: TurboLinux gets a big chunk of venture money. SCO (old SCO) buys a chunk of the Linux Mall. Crypto export rules in the U.S. begin to soften. The devfs discussion continues. SGI, VA Linux, and O'Reilly launch a commercialized version of the Debian distribution. VA Linux files for its IPO.
Old-timers will remember the Linux Mall - that was the place, once upon a time, where we bought our Linux CDs (and stuffed penguins too). Yes, we actually bought Linux on CD and waited for it to show up via mail, though it may seem a little strange now. The Linux Mall, and its founder Mark Bolzern, were fixtures in the early days of Linux. As Linux grew and bandwidth increased, though, the Linux Mall was having a bit of a hard time of it. The name was famous, though, and the site got a lot of traffic, so companies interested in getting into the Linux hype were interested in it.
It may be getting a bit ahead of the story, but this is as good a place as any to let it be known that one of the things that the Linux Mall wanted to do with its new-found wealth was to acquire a media outlet like LWN. It was part of the bigger plan of creating a full-featured e-commerce "mall" centered around Linux. We considered the offer long and hard, but, in the end, declined it. Just as well: the Linux Mall missed the IPO boat and got folded into EBIZ, which, in turn, eventually went bankrupt. Had we taken that path, there would be no LWN now.
- October 21, 1999:
LinuxToday is acquired by Internet.com; co-founder Dave Whitinger leaves
the building. ATI announces that it will be releasing 3D programming
information for its video adapters - the good news here is that it's
finally getting around to doing that.
- November 4, 1999: DVD
encryption is cracked and DeCSS is released. The Y2K-related
"windowing" patent threatens the kernel. Burn all GIFs day. The
kernel gets past the longstanding 1GB limit on installed memory. Slackware 7 (the
successor to Slackware 4) is released. The non-profit Red Hat Center
for Open Source launches - and is never heard from again.
- November 11, 1999: Cobalt
network goes public, shares begin trading at $130.
- November 18, 1999: The Linux Business Expo is held as part of the once-famous COMDEX event. Red Hat acquires Cygnus. BitKeeper is said to be getting closer to release. Mozilla hits milestone 11 and is said to be getting closer to release. Advogato.org launches.
LWN has only rarely operated booths at conferences, but we did have one at the Comdex Linux Business Expo. For the curious, here's a picture from the event featuring LWN editor Rebecca Sobol. That week's LWN edition was produced from that booth after the floor closed, under the watchful eye of security guards who didn't think we should be there. Your editor remembers it as one of the coldest experiences of his life. During the show, we subjected to constant, highly-amplified screaming obnoxiousness from the large booth being run by LinuxToday - the acquisition, it seemed, had put that site onto a rather less dignified path.
The other thing LWN was doing at this event was talking with potential suitors. One of those was a company called Atipa, which was operating a large booth of its own. Atipa was a VA-style Linux box vendor with a grand plan for a Linux portal site which would, eventually, be the place people went for Linux information. They thought that LWN would make a good addition to that portal, and were pushing hard to make a deal.
We met a few times with Atipa's CEO, a charismatic man who told a good story. The company, he said, was going to outdo even the coming VA Linux IPO, which was already clearly going to be big. Along the way he was going to pick up companies like Applix and open-source the ApplixWare office suite - something which would have been nice at the time. He stated flat out that he was soon to be a billionaire, and that we could share in that bonanza. It was quite the tale, but we tended to walk out of these meetings believing every word of it.
With some distance, though, the glow always faded. We wondered why our visit to the company's headquarters revealed a building almost devoid of people. The magic "profit happens here" step in their plans seemed less inevitable when looked at later. In the end, we did not take this deal. Thereafter, we received (unverifiable) word that Atipa's investors started asking some harder questions and found that, perhaps, they, too, had allowed themselves to be charmed more than they should have. Atipa rather abruptly found a new CEO, the IPO never happened, and investors, presumably, lost their money.
Also at the Linux Business Expo, we met with some representatives from O'Reilly. They were getting the O'Reilly network off the ground, and thought that LWN might make a good addition to it. They eventually offered us a deal (which looked more like a traditional angel investment than an acquisition) and a network affiliation which would have given us a portion of the revenue from the ads they sold. Your editor, who has a lot of respect for the people at O'Reilly, has always had a bit of regret at turning down this offer. It was an opportunity to get business advice from some very smart people. But it would almost certainly have been fatal to LWN once the advertising market fell apart.
Meanwhile, the acquisition of Cygnus by Red Hat led to a fair amount of online worrying about whether Red Hat was set to take over Linux by virtue of employing a number of GCC developers. Such fears look a little silly now, but they seemed real then.
- December 9, 1999:
Andover.net goes public. The kernel gets NUMA support (during a
feature freeze, remember).
Sun announces a Linux Java release, rolling over the "Blackdown" team
which had been working on this release for years.
- December 12, 1999: VA Linux goes public, setting the record for the largest first-day gain in NASDAQ history. Eric Raymond gets rich and lets us all know about it. The non-free BitKeeper license is revealed. LinuxCare acquires the Puffin Group and gets another $32 million. The Linux Capital Group launches; it starts by funding Progeny Linux. Companies send out "we use Linux" press releases in an attempt to make their stock price go up.
The VA IPO was not just the peak of the Linux bubble - it could well be the peak of the dotcom bubble as a whole. It was not possible to watch that stock rise to well over $300 a share on the first day and not be overwhelmed by a sense of unreality. Still, it seemed like no more than what Linux deserved, and people somehow expected it to continue.
- January 6, 2000: Linux
survives Y2K. Red Hat buys Hell's Kitchen Software, does nothing with
it. VA Linux launches the SourceForge site.
- January 13, 2000: Caldera
Systems (later to become SCO) files for its IPO. The kernel gets a
new block driver API and 32-bit UIDs - still during the feature freeze.
- January 20, 2000: LinuxCare files for its IPO. Linus Torvalds shuts down the sale of a number of Linux-related domain names. Secure Computing Corporation announces that it will be developing (what becomes) SELinux. Enoch becomes Gentoo Linux. TurboLinux completes another funding round.
Once upon a time, Caldera Systems was supposed to be among the biggest winners in the distribution sector - they had the business connections and the distribution channels. "Linux for business" got the company far enough to do an IPO, but not much beyond that. This is, of course, the company which eventually became the SCO Group.
Caldera was well overshadowed by LinuxCare, though. The distribution business always looked like a hard one to maintain over the long term - that is why Red Hat was trying to be a web portal company. Services were going to be the real gold mine, and LinuxCare was going to be at the top of the Linux support industry. The company got money from left and right (a funding round produced offers of ten times the target amount) and hired a long list of well-known Linux hackers.
Need we say that LWN's editors paid a visit to LinuxCare during this time? It was a hard time for LinuxCare to discuss acquisitions, since the IPO process was already underway, but discuss they did. So we went to the famous San Francisco headquarters. Your editor's memories from that day are strong. LinuxCare was filled with hundreds of people who all believed they were on the way toward an IPO that would exceed even VA Linux; suffice to say they were happy about the prospect. Meanwhile, though, a couple hundred of them were all working in a single not-very-large room called "the barn"; it resembled, more than anything else, a school lunchroom filled with long tables. Everybody worked on a laptop because there was no room in their tiny piece of table space for anything else. They all complained about having colds. It looked awful.
LinuxCare's negotiator was an ex-fighter jet pilot who retained the "top gun" attitude. When valuations were discussed, we were told that offering LinuxCare's pre-IPO shares at $50-60 each was being generous to us. Issues like editorial control were not really even on the table. In the end, we turned this deal down, but with a feeling like we were throwing a winning lottery ticket in the trash. Of course, subsequent events showed that we need not have worried about this particular missed opportunity.
- February 10, 2000: Real-time Linux turns out to be patented. VA Linux acquires Andover.Net. The KDE project moves to SourceForge. Atipa acquires Enhanced Software Technologies. The Linux Fund announces that it will be filing for an IPO.
The Andover.Net acquisition was announced at LinuxWorld in New York - LWN was there, of course. The initial deal included a massive pile of cash to be handed to Andover.Net's shareholders, but people questioned that handout to the extent that it eventually went away. Andover.Net's owners had to content themselves mostly with VA Linux shares, which, already, were worth considerably less than they had been on IPO day. In the end, Andover.Net turned out to be a good buy for VA Linux, once it became clear that the Linux-installed computer business was harder than it had looked.
We were approached by a VA executive at LinuxWorld to see if we were interested in maybe being acquired sometime. By then, though, we had so many offers that we couldn't really give them all serious consideration. So we did not pursue that opportunity.
But, at this event, we did talk with some representatives from ZDNet, who were also looking for a Linux site to buy. The offer they made was, by far, the most generous of any. By some reckoning, we should have taken it. Certainly it would have come out better than most of the other options we had. But ZDNet would have exercised more editorial control than we would have liked, and, being already a public company, it didn't offer that IPO "pop" that we somehow thought was our due. So we ended up not taking that path.
- February 17, 2000: devfs
is merged into the mainline kernel. Also merged is the "softnet" core
networking rework. Remember, the kernel is in a feature freeze.
- February 24, 2000: Eazel is founded with the goal of improving Linux usability.
To your editor, Eazel never made sense from the beginning. There was, truly, no revenue model. Indeed, it seemed like a scam designed to draw venture money for the purpose of writing Nautilus. To that extent it succeeded, but the investors cannot have been happy in the end.
- March 2, 2000: Atipa
announces $30 million in investments.
- March 23, 2000: Caldera
Systems goes public; its share price merely doubles. The planned date
for LinuxCare's IPO passes with no offering.
- April 4, 2000: Linuxcare's IPO is pushed back to April 24 - or so they say. EBIZ acquires longtime Linux CD distributor InfoMagic. Atipa Linux Solutions acquires DCG Computer Corp. Sendmail Inc. gets $35 million in funding.
This was the point where LWN announced that it had been acquired by a company called Tucows. We had, in fact, been talking with them for some months, and had made the decision in February. It took some time, though, for the lawyers to hammer out the final agreement. In the end, we were probably exceedingly lucky: market conditions were going downhill in a hurry by this point and, had the negotiations stretched out much longer, Tucows might have started looking for reasons to back out of the deal.
Or maybe not. We went with Tucows for a number of reasons, but at the top of the list was that they were clearly smart and decent people who, while arguably being carried away by the bubble like the rest of us, clearly had a functioning business underneath it all. Their acquisition of LWN never yielded the benefits they were looking for, but the people at Tucows always treated us well and we still count them as friends. Perhaps we were smart, or perhaps we were just very lucky, but, in retrospect, we came out of a complex, high-stakes process having made what was probably the best possible decision.
The Tucows acquisition made it possible for LWN editors Rebecca Sobol and Forrest Cook to join as regular staff members. It also positioned us within a safe harbor for the dotcom crash, which was already in progress. But the story of those years will be the subject of next week's installment.
Security
A kernel security hole
Security holes can sneak into code in surprising ways, even in highly scrutinized codebases. Perhaps even more surprising is how long they can persist in something as popular as the Linux kernel before someone notices. The release of stable kernels 2.6.22.16 and 2.6.23.14 this week are instructive for both of those reasons.
The bug that led to the releases is fixed by a two line patch, but might be exploitable to cause filesystem corruption. If it were a bug in a driver for an obscure piece of hardware, with relatively few users, it might have been less eye opening, but it was in the Virtual File System (VFS) layer of the kernel. VFS is the abstraction that allows all kernel filesystems to be used identically regardless of their underlying implementation. The open() system call is used to open any file on any type of filesystem; VFS is what makes that work.
In fact it is the open() path that is affected by the bug. Due to a faulty test, the bug allows directories to be opened for writing, which is generally a recipe for disaster. It could also allow a file on a read-only filesystem to be opened for writing – depending on the underlying filesystem implementation, that could lead to corruption. In both cases, they are only locally exploitable.
The bug was introduced in a change to support NFS in October of 2005 – more than two years ago; all kernels since 2.6.15 are affected. The change was aimed at making NFSv4 open calls be atomic (because an open is really a lookup followed by an open), but also did some code reorganization that changed the semantics of a flag variable. That variable was being used to determine the access mode for directories and read-only filesystems, so that change subtly broke the tests.
Part of the problem is that the tests are in a function called may_open(), which takes two flag parameters:
int may_open(struct nameidata *nd, int acc_mode, int flag)
The incorrect code was using flag in the tests when it should have
been using acc_mode. Each of them is a bitmask of values that, on
first glance, might be easy to confuse – each is related to permissions.
The bit values for each have names like FMODE_WRITE and
MAY_WRITE, which would seem to have a fair amount of overlap. This
may explain why the problem was not spotted at the time it was introduced.
There may be no easy solution to this kind of problem – other than more scrutiny. Using different types, rather than plain int, for each flag might have helped, but since the tests were using the right kind of bit values for flag, that is a somewhat hard sell.
Something unpleasant to consider in all of this is that this may not be the first time this problem has been noticed. It may just have been the first time it was noticed by someone who reported it. Folks with a malicious intent are much less inclined to report bugs. This particular bug is not one that would be particularly useful to attackers, but we would do well to remember that fixing a two year old hole means that systems were vulnerable for all that time. It is not only the good guys who can read code.
New vulnerabilities
apache: several vulnerabilities
| Package(s): | apache | CVE #(s): | CVE-2007-5000 CVE-2007-6388 CVE-2008-0005 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | January 15, 2008 | Updated: | July 29, 2008 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | A flaw was found in the mod_imap module. On sites where mod_imap was
enabled and an imagemap file was publicly available, a cross-site scripting
attack was possible. (CVE-2007-5000)
A flaw was found in the mod_status module. On sites where mod_status was enabled and the status pages were publicly available, a cross-site scripting attack was possible. (CVE-2007-6388) A flaw was found in the mod_proxy_ftp module. On sites where mod_proxy_ftp was enabled and a forward proxy was configured, a cross-site scripting attack was possible against Web browsers which did not correctly derive the response character set following the rules in RFC 2616. (CVE-2008-0005) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
claws-mail: insecure temp file
| Package(s): | claws-mail | CVE #(s): | CVE-2007-6208 | ||||
| Created: | January 10, 2008 | Updated: | January 16, 2008 | ||||
| Description: | Claws Mail creates temp files in an insecure manner. This can be used by a local attacker to make a symlink attack, allowing files with the local user's privileges to be overwritten. | ||||||
| Alerts: |
| ||||||
drupal: multiple vulnerabilities
| Package(s): | drupal | CVE #(s): | |||||||||
| Created: | January 14, 2008 | Updated: | January 16, 2008 | ||||||||
| Description: | From the Fedora advisory: Update to 5.6, security fixes: DRUPAL-SA-2008-005 DRUPAL-SA-2008-006 DRUPAL-SA-2008-007see http://drupal.org/security for more information. | ||||||||||
| Alerts: |
| ||||||||||
fail2ban: denial of service
| Package(s): | fail2ban | CVE #(s): | CVE-2007-4321 | ||||
| Created: | January 10, 2008 | Updated: | January 16, 2008 | ||||
| Description: | From the Debian alert: Daniel B. Cid discovered that fail2ban, a tool to block IP addresses that cause login failures, is too liberal about parsing SSH log files, allowing an attacker to block any IP address. | ||||||
| Alerts: |
| ||||||
gforge: SQL injection
| Package(s): | gforge | CVE #(s): | CVE-2008-0173 | ||||
| Created: | January 14, 2008 | Updated: | January 16, 2008 | ||||
| Description: | From the Debian advisory: It was discovered that Gforge, a collaborative development tool, did not properly sanitise some CGI parameters, allowing SQL injection in scripts related to RSS exports. | ||||||
| Alerts: |
| ||||||
httpd: cross-site scripting, denial of service
| Package(s): | httpd | CVE #(s): | CVE-2007-6421 CVE-2007-6422 | ||||||||||||||||||||||||||||||||
| Created: | January 15, 2008 | Updated: | April 4, 2008 | ||||||||||||||||||||||||||||||||
| Description: | A flaw was found in the mod_proxy_balancer module. On sites where
mod_proxy_balancer was enabled, a cross-site scripting attack against an
authorized user was possible. (CVE-2007-6421)
A flaw was found in the mod_proxy_balancer module. On sites where mod_proxy_balancer was enabled, an authorized user could send a carefully crafted request that would cause the Apache child process handling that request to crash. This could lead to a denial of service if using a threaded Multi-Processing Module. (CVE-2007-6422) | ||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||
kernel: denial of service vulnerabilities
| Package(s): | kernel | CVE #(s): | CVE-2007-4133 CVE-2007-5093 | ||||||||||||||||||||||||||||||||||||||||||||
| Created: | January 12, 2008 | Updated: | November 20, 2008 | ||||||||||||||||||||||||||||||||||||||||||||
| Description: | The (1) hugetlb_vmtruncate_list and (2) hugetlb_vmtruncate functions
in fs/hugetlbfs/inode.c in the Linux kernel before 2.6.19-rc4 perform
certain prio_tree calculations using HPAGE_SIZE instead of PAGE_SIZE
units, which allows local users to cause a denial of service (panic)
via unspecified vectors.
The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 relies on user space to close the device, which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consumption in khubd) by not closing the device after the disconnect is invoked. NOTE: this rarely crosses privilege boundaries, unless the attacker can convince the victim to unplug the affected device. | ||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||
libxml2: denial of service
| Package(s): | libxml2 | CVE #(s): | CVE-2007-6284 | ||||||||||||||||||||||||||||||||||||
| Created: | January 11, 2008 | Updated: | January 31, 2008 | ||||||||||||||||||||||||||||||||||||
| Description: | A denial of service flaw was found in the way libxml2 processes certain content. If an application linked against libxml2 processes malformed XML content, it could cause the application to stop responding. | ||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||
moodle: cross-site scripting
| Package(s): | moodle | CVE #(s): | CVE-2008-0123 | ||||||||||||
| Created: | January 16, 2008 | Updated: | November 12, 2008 | ||||||||||||
| Description: | Moodle suffers from a cross-site scripting vulnerability which is only open during the install process. | ||||||||||||||
| Alerts: |
| ||||||||||||||
openafs: denial of service
| Package(s): | openafs | CVE #(s): | CVE-2007-6599 | ||||||||||||
| Created: | January 10, 2008 | Updated: | January 25, 2008 | ||||||||||||
| Description: | From the Gentoo advisory: Russ Allbery, Jeffrey Altman, Dan Hyde and Thomas Mueller discovered a race condition due to an improper handling of the clients callbacks lists. A remote attacker could construct cases which trigger the race condition, resulting in a server crash. | ||||||||||||||
| Alerts: |
| ||||||||||||||
paramiko: insecure random pool usage
| Package(s): | paramiko | CVE #(s): | CVE-2008-0299 | ||||||||||||
| Created: | January 16, 2008 | Updated: | March 4, 2008 | ||||||||||||
| Description: | Programs which keep more than one paramiko connection open may leak random pool information. | ||||||||||||||
| Alerts: |
| ||||||||||||||
R: buffer overflows
| Package(s): | R | CVE #(s): | |||||
| Created: | January 10, 2008 | Updated: | January 16, 2008 | ||||
| Description: | The R language has a copy of PCRE, that has a number of buffer overflow and memory corruption vulnerabilities. If an attacker creates specially crafted regular expressions, it may be possible to create a denial of service, execute arbitrary code or disclose unauthorized information. | ||||||
| Alerts: |
| ||||||
xfce4: multiple vulnerabilities
| Package(s): | xfce4 | CVE #(s): | CVE-2007-6531 CVE-2007-6532 | ||||
| Created: | January 10, 2008 | Updated: | January 16, 2008 | ||||
| Description: | From the Gentoo alert: Gregory Andersen reported that the Xfce4 panel does not correctly calculate memory boundaries, leading to a stack-based buffer overflow in the launcher_update_panel_entry() function (CVE-2007-6531). Daichi Kawahata reported libxfcegui4 did not copy provided values when creating "SessionClient" structs, possibly leading to access of freed memory areas (CVE-2007-6532). | ||||||
| Alerts: |
| ||||||
xine-lib: buffer overflow
| Package(s): | xine-lib | CVE #(s): | CVE-2008-0225 | ||||||||||||||||||||||||||||
| Created: | January 16, 2008 | Updated: | August 7, 2008 | ||||||||||||||||||||||||||||
| Description: | xine-lib contains a buffer overflow which could be exploited (via a specially-crafted stream) to execute arbitrary code; see this advisory for more information. | ||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||
Page editor: Jake Edge
Kernel development
Brief items
Kernel release status
The current 2.6 prepatch is 2.6.24-rc8, released by Linus on January 15. It contains a fair number of fixes but not much else. "So I'm pretty sure this is the last -rc, and the final 2.6.24 will probably be out next weekend or so. But in the meantime, let's give this a final shakedown, and see if we can fix any last regressions still." See the long-format changelog for the details.
As of this writing, a very small number of fixes has been merged post-rc8.
There have been no -mm releases over the last week.
The current stable 2.6 kernel is 2.6.23.14, released (along with 2.6.22.16) on January 14. These releases contain a single patch: a fix for the filesystem security vulnerability discussed on this week's Security Page.
For older kernels: 2.6.16.58 was released on January 16 with several fixes.
Kernel development news
Quote of the week
The common case -- a single syscall like open(2) -- would be a single byte bytecode, plus a couple VM register stores. The result is stored in another VM register.
But this format enables more complex cases, where userland programs can pass strings of syscalls into the kernel, and let them execute until some exceptional condition occurs. Results would be stored in VM registers (or userland addresses stored in VM registers...).
A better btrfs
Chris Mason has recently released Btrfs v0.10, which contains a number of interesting new features. In general, Btrfs has come a long way since LWN first wrote about it last June. Btrfs may, in some years, be the filesystem most of us are using - at least, for those of us who will still be using rotating storage then. So it bears watching.Btrfs, remember, is an entire new filesystem being developed by Chris Mason. It is a copy-on-write system which is capable of quickly creating snapshots of the state of the filesystem at any time. The snapshotting is so fast, in fact, that it is used as the Btrfs transactional mechanism, eliminating the need for a separate journal. It supports subvolumes - essentially the existence of multiple, independent filesystems on the same device. Btrfs is designed for speed, and also provides checksumming for all stored data.
Some kernel patches show up and quickly find their way into production use. For example, one year ago, nobody (outside of the -ck list, perhaps) was talking about fair scheduling; but, as of this writing, the CFS scheduler has been shipping for a few months. KVM also went from initial posting to merged over the course of about two kernel release cycles. Filesystems do not work that way, though. Filesystem developers tend to be a cautious, conservative bunch; those who aren't that way tend not to survive their first few encounters with users who have lost data. This is all a way of saying that, even though Btrfs is advancing quickly, one should not plan on using it in any sort of production role for a while yet. As if to drive that point home, Btrfs still crashes the system when the filesystem runs out of space. The v0.10 patch, like its predecessors, also changes the on-disk format.
The on-disk format change is one of the key features in this version of the Btrfs patch. The format now includes back references on almost all objects in the filesystem. As a result, it is now easy to answer questions like "to which file does this block belong?" Back references have a few uses, not the least of which is the addition of some redundant information which can be used to check the integrity of the filesystem. If a file claims to own a set of blocks which, in turn, claim to belong to a different file, then something is clearly wrong. Back references can also be used to quickly determine which files are affected when disk blocks turn bad.
Most users, however, will be more interested in another new feature which has been enabled by the existence of back references: online resizing. It is now possible to change the size of a Btrfs filesystem while it is mounted and busy - this includes shrinking the filesystem. If the Btrfs code has to give up some space, it can now quickly find the affected files and move the necessary blocks out of the way. So Btrfs should work nicely with the device mapper code, growing or shrinking filesystems as conditions require.
Another interesting feature in v0.10 is the associated in-place ext3 converter. It is now possible to non-destructively convert an existing ext3 filesystem to Btrfs - and to go back if need be. The converter works by stashing a copy of the ext3 metadata found at the beginning of the disk, then creating a parallel directory tree in the free space on the filesystem. So the entire ext3 filesystem remains on the disk, taking up some space but preserving a fallback should Btrfs not work out. The actual file data is shared between the two filesystems; since Btrfs does copy-on-write, the original ext3 filesystem remains even after the Btrfs filesystem has been changed. Switching to Btrfs forevermore is a simple matter of deleting the ext3 subvolume, recovering the extra disk space in the process.
Finally, the copy-on-write mechanism can be turned off now with a mount option. For certain types of workloads, copy-on-write just slows things down without providing any real advantages. Since (1) one of those workloads is relational database management, and (2) Chris works for Oracle, the only surprise here is that this option took as long as it did to arrive. If multiple snapshots reference a given file, though, copy-on-write is still performed; otherwise it would not be possible to keep the snapshots independent of each other.
For those who are curious about where Btrfs will go from here, Chris has posted a timeline describing what he plans to accomplish over the coming year. Next on the list would appear to be "storage pools," allowing a Btrfs filesystem to span multiple devices. Once that's in place, striping and mirroring will be implemented within the filesystem. Longer-term projects include per-directory snapshots, fine-grained locking (the filesystem currently uses a single, global lock), built-in incremental backup support, and online filesystem checking. Fixing that pesky out-of-space problem isn't on the list, but one assumes Chris has it in the back of his mind somewhere.
Unprivileged mounts
There are a number of filesystem-related patches aimed at the upcoming 2.6.25 merge window; one of those is the unprivileged mount patch by Miklos Szeredi. This patch enables an unprivileged user process to call the mount() system call and - in certain circumstances - have that call actually succeed. It could eventually lead to a situation where users have more flexibility to create their own environments and the setuid mount utility is no longer needed.This patch adds a new field (uid) to the vfsmount structure, allowing the kernel to keep track of the owner of a specific filesystem mount. The system administrator can give ownership of a specific mount to a user with the new MNT_SETUSER flag. A common pattern might be to bind-mount a user's home directory on top of itself, giving the user the ownership of that mount. Once that has been done, the user is allowed to freely mount other filesystems below that mount point - with a couple of conditions:
- There is a system-wide limit on the number of allowed user mounts;
once that limit is hit, no more unprivileged mounts will be allowed
until somebody unmounts something. The current patch has no provision
for per-user or per-group mount limits, but such a feature would not
be particularly hard to add should the need arise.
- The filesystem type must be marked as being safe for unprivileged mounts. Miklos notes that a filesystem must go through "a thorough audit" before this flag can be set with any confidence. The patch, as posted, marks the fuse filesystem (which allows for the creation of filesystems implemented in user space) as being safe; fuse was designed for this mode of operation in the first place. Bind mounts are also allowed, with some additional conditions.
If the system allows the mount, the flags allowing for setuid and device files will be forcibly cleared - unless the user has the requisite capabilities anyway. Users are allowed to unmount filesystems they own, again without privilege, but cannot unmount any others. Another new mount flag (MNT_NOMNT) marks a specific filesystem as being the end of the line - no unprivileged submounts are allowed below it. The end result of [PULL QUOTE: One might well wonder why this change to the mount() system call is called for, given that users have been able to do unprivileged mounts for years. END QUOTE] all this should be a mechanism by which users can organize their filesystem hierarchies without any need for administrative privileges, and without the risk of compromising system security.
One might well wonder why this change to the mount() system call is called for, given that users have been able to do unprivileged mounts for years. The answer is that the current mechanism has a couple of shortcomings. Every potential unprivileged mount must be explicitly enabled via a line in /etc/fstab. That works well for simple situations, such as allowing a user to mount a CD or a USB storage device. When users start wanting to do more complicated things, like mounting their own special fuse filesystems, the /etc/fstab mechanism breaks down. There is a separate, setuid program which grants the right to make unprivileged fuse mounts, but it represents a workaround rather than a proper solution.
The current user mount mechanism also requires that the mount utility be installed setuid root. Every setuid binary is a potential security hole, so there is value in eliminating privileged programs when possible. The unprivileged mount patch offers the possibility of eliminating the setuid mount program while simultaneously leaving policy control in the hands of the system administrator. So, unless something surprising comes up, chances are good that this capability will appear in the 2.6.25 kernel.
ext3 metaclustering
The ext3 system uses the classic Unix block pointer method for keeping track of the blocks in each file. For a given file, the on-disk inode structure contains space for twelve block numbers; they point to the first twelve blocks in the file - the first 48KB of space. If the file is larger than that, a 13th pointer contains the address of the first indirect block; this block contains another 1024 (on a 4K block filesystem) block pointers. Should that not suffice, there's a 14th pointer for the double-indirect block - each entry in that block is the address of an indirect block. And if even that is not enough, there's a 15th entry pointing to a triple-indirect block full of pointers to double-indirect blocks.This is a very efficient representation for small files - the kinds of files Unix systems typically held, once upon a time. In current times, when one can forget about that directory full of DVD images and never even notice the lost space, it does not work quite as well - there is a lot of overhead for all of those individual block pointers, and a large data structure to manage. That is why removing a large file on an ext3 filesystem can take a long time - the system has to chase down all of those indirect blocks, which, in turn, forces a lot of disk activity and head seeks. For this reason, contemporary filesystems tend to use extent-based mechanisms to associate blocks with files, but that is not really an option for ext3.
An additional problem with all those indirect blocks is that filesystem checkers must locate and verify them all. That, again, causes a lot of head seeking and makes fsck run slowly. Slow filesystem checking was the motivation behind this patch from Abhishek Rai which attempts to improve performance on filesystems with a lot of indirect blocks.
The approach taken is relatively simple: the patch just tries to group indirect block allocations together on the disk. The current ext3 code will allocate indirect blocks when they are needed to account for data blocks being added to the file; they are usually placed adjacent to those data blocks. One might think that this placement would speed subsequent accesses to the file, but that is not necessarily so; the reading or writing of the indirect block will tend to happen at a different time than operations on the data blocks. What this placement does accomplish, though, is the distribution of the indirect blocks all over the disk. So a process which must examine all of the indirect blocks associated with a file must cause the disk to do a lot of head seeks.
The "metaclustering" approach works by reserving a set of contiguous blocks at the end of each block group. Whenever an indirect block is needed, the filesystem tries to get one from this dedicated area first. The end result is that all of the indirect blocks are located next to each other. Should somebody need to read a number of those blocks without being interested in the contents of the data blocks, they can grab them all quickly with minimal seeking. Filesystem checkers, as it happens, need to do exactly that - as does the file removal process. The patch did not come with benchmarks, but the speedup that comes from the elimination of all those seeks should be significant.
Even so, Andrew Morton questioned the need for this patch, worrying that its benefits do not justify the risks that comes with modifying an established, heavily-used filesystem:
Others disagreed, though, noting that it's the unplanned filesystem checks which are often the most time-critical. That includes the delightful "maximal mount count" boot-time check which, in your editor's experience, always happens when one is trying to get set up to give a talk somewhere. So this patch might just find eventual acceptance - it should be relatively low-risk and does not require any on-disk format changes. This is a filesystem patch, though, so nobody will be in any hurry to get it into the mainline before a lot of testing and review has been done.
State of the unionfs
LWN last looked at the unionfs filesystem almost exactly one year ago. Things have been relatively quiet on the unionfs front during much of that time, but unionfs has not gone away. Now the unionfs developers are back with an improved version and a determined push to get the code into 2.6.25. So another look seems indicated.The core idea behind unionfs is to allow multiple, independent filesystems to be merged into a single, coherent whole. As an example, consider a user with a distribution install DVD full of packages, a small disk, and painfully slow bandwidth. It would be nice to keep the DVD-stored packages around for future installation. What is also nice, though, is to be able to keep a directory full of updates from the distributor and use those, when they exist, in favor of the read-only DVD version. Using unionfs, this user could mount the DVD read-only, then mount a writable filesystem (for the updates) on top of the DVD. Updated packages go into the writable filesystem, but all of the available packages are visible, together, in the unified view. To avoid confusion, the user could delete obsoleted packages, at which point they would no longer be visible in the unionfs filesystem, even though they cannot actually be deleted from the underlying DVD. Thus unionfs allows the creation of an apparently writable filesystem on a read-only base; many other applications are possible as well.
If a user rewrites a file which is stored on a read-only "branch" of a union filesystem, the response is relatively straightforward: the newly-written file is stored on a higher-priority, writable branch. If no such branch exists, the operation fails. Dealing with the deletion of a file from a read-only branch is trickier, though. In this case, unionfs will create a "whiteout" in the form of a special file (starting with .wh.) on a writable branch. Some reviewers have disliked this approach since it will clutter the upper branch with those special files over time. But it is hard to come up with another way to handle deletion, especially if (as is the case here) your goal is to keep core VFS changes to an absolute minimum.
That hasn't kept the unionfs developers from trying, though. Off to the side, they have a version of unionfs which maintains a small, special-purpose partition of its own (on writable storage). Metadata (whiteouts, in particular) is stored to this special unionfs partition and no longer clutters the component filesystems. There are other advantages to the dedicated partition scheme, including the ability to include one unionfs as a branch in a second union; see the unionfs ODF document for more information on this approach, which the developers hope to slowly migrate into the version they are currently proposing for the mainline.
Another persistent problem with unionfs has been coping with modifications made directly to the component branches without going through the union. The January, 2007 version of the patch came packaged with some dire warnings: direct modification of unionfs branches could lead to system crashes and data loss. Given that filesystems which have been bundled into a union still exist independently, they will always present a tempting target for modification, even when there is not a specific reason (wanting to put files onto a specific component filesystem, for example). So a unionfs implementation which cannot handle such modifications sets a trap for every user who uses it.
The developers claim to have solved this problem in the current version of the patch. Now, almost every entry into the unionfs code causes it to check the modification times for the relevant file in all layers of the union. If the file turns out to have been changed, unionfs will forget about the file and reload the information from scratch, causing the most current version of the file (or directory) to be visible to the user. This approach solves the problem in a relatively efficient manner, with one exception: unionfs cannot tell when a process modifies a file which it has mapped into its address space with mmap(). So, in that case, changes may not be visible to processes accessing the affected file through the unionfs.
In both cases, the unionfs developers would really prefer to have better support from the VFS. Some operating systems have provided native support for whiteouts, but Linux lacks that support. There is also no way for a filesystem at the bottom of a stack of filesystems to notify the higher layers that something has been changed. Fixing either of these would require significant VFS modifications, though, and the changes might propagate down into the individual filesystem implementations as well. So nobody is expecting them to happen anytime soon.
Another significant change in unionfs is the elimination of the ioctl() interface for the management of branches. All changes to an existing unionfs are now done using the remount option of the mount command. This change eliminates the need for a separate utility for unionfs configuration and makes it possible to do complicated changes in an atomic manner.
The end result of all this is that the unionfs hackers think that the time has come to put the code into the mainline. There, it would become the second supported stacking filesystem (the first being eCryptfs), and would help toward the long-term goal of making the VFS layer work better with stacking. Some people speak as if the merging of unionfs into 2.6.25 is a done deal, but that is not yet guaranteed. Christoph Hellwig, whose opinion on such things carries a heavy weight, is opposed to the unionfs idea:
Unionfs hacker Erez Zadok responds that unionfs is working - and used - now, while getting union support into the VFS is a distant prospect. So he recommends:
When one looks at a recent posting of the union mount patch, it's hard to see them as a near-term solution. As described by its author (Bharata Rao), this work is in an early, exploratory state; there are a number of problems for which solutions are not really in sight. The union mount approach, which does the hard work in the VFS layer, may well be the right long-term approach, but it will not be in a state where it can be shipped to users anytime soon.
In the end, the problem is a hard one, and unionfs has a considerable lead toward being a real solution. That, alone, is not enough to guarantee that unionfs will make it into the 2.6.25 kernel, but it does help that cause considerably. Anybody opposing the merger of unionfs will have to explain why the union filesystem capability should not be available to Linux users in 2008.
Patches and updates
Kernel trees
Architecture-specific
Core kernel code
Development tools
Device drivers
Documentation
Filesystems and block I/O
Memory management
Networking
Virtualization and containers
Benchmarks and bugs
Miscellaneous
Page editor: Jonathan Corbet
Distributions
News and Editorials
Is Gentoo in crisis?
It all started with a blog post by Daniel Robbins. That was on January 11. But of course, it didn't really start there. That's just when the internal furor over the revocation of the Gentoo Foundation's corporate license became public. Developers had been trying to figure out what to do in the internal gentoo-core mailing list for about a week, and as such things do, it leaked.
The larger-scale problems didn't even start there. The Gentoo Weekly Newsletter hasn't been posted for 13 weeks, and the Gentoo homepage hadn't seen any changes in the same amount of time. Furthermore, Gentoo's second release of 2007, dubbed 2007.1, never happened and on Monday was announced canceled.
What do these problems mean? Is Gentoo collapsing? Another blog post by Daniel Robbins suggests part of the answer—serious communication problems exist between developers and the rest of the Gentoo community. The relevant aspect here is that developers are so focused on working in their little areas that they fail to tell the world what they're doing. Everyone wants to develop, and nobody wants to spend time telling the world what's being developed. Most developers don't want to spend time doing anything but develop. In the same way, developers don't enjoy spending time dealing with "boring" issues like donations, copyright, tax returns, etc., nor are they generally any good at it.
Development remains active in the background—new versions of packages appear, bugs are fixed, the gentoo-dev mailing list is quite active, and so is IRC. Developers continue to blog on Planet Gentoo. But none of that is apparent to Gentoo users, who go to the homepage, read the weekly newsletter, and wait for the next release. To users, things can look like they're in stasis.
That's where Gentoo needs to concentrate its efforts: telling the world what developers are doing. To accomplish that, the project will either need to find new contributors interested in doing this or streamline its processes so that less effort is required to communicate (for example, automatically including Planet information or new versions from packages.gentoo.org on the homepage). Specifically, one hope with the foundation is to hand off the work to people who enjoy dealing with it, so developers can concentrate on development—people at Software in the Public Interest, or the Software Freedom Conservancy. An announcement on the Gentoo homepage proposing a move to a monthly newsletter brought nearly 20 offers of help in only 2 days, so it may be that the project hasn't been looking for non-development help in all the right places.
Gentoo isn't dying, but its developers need to tell that to the world.
New Releases
DesktopBSD 1.6
DesktopBSD, a project that uses both FreeBSD and the KDE desktop, has released version 1.6.Mandriva Linux 2008 Spring Alpha 2 "Neottia" released
Mandriva has released the second alpha of Mandriva Linux 2008.1, the spring edition. "This pre-release brings a near-final snapshot of KDE 4.0 (final 4.0 packages are currently being uploaded to the Cooker repositories), new NVIDIA and ATI drivers, the chance to test the experimental nouveau open source driver for NVIDIA cards, kernel 2.6.24rc7, and more."
Hardy Alpha 3 released
Hardy Heron Alpha-3 has been released. Hardy will become Ubuntu 8.04. This release can be downloaded as Ubuntu, Kubuntu, Edubuntu, Ubuntu JeOS, Xubuntu and Gobuntu.
Distribution News
Debian GNU/Linux
Bits from the Debian i18n Meeting (Extremadura 2007)
Debian's i18n team met Caceres, Spain last month, thanks to the Junta de Extremadura. Click below for a summary of the meeting.Bits from the Qt/KDE team
Debian's Qt/KDE team also benefited from the meetings sponsored by the Government of Extremadura. During the meeting they decided that Lenny will ship with KDE 3. "However, we will close bugs filed against applications declared dead by upstream, such as aRts." A KDE 4 development platform will also ship with Lenny.
Report from FOSS.in participation, Bangalore, India, Dec 2007
Christian Perrier has a report from FOSS.in which took place last month in Bangalore, India. "Sam Hocevar was attending the conference, as DPL, on behalf of Debian (travel expenses covered by Debian funds). Christian Perrier, wearing his i18n hat, proposed self as a speaker as well after sollicitations from the Debian-in community (travel expenses sponsored by FOSS.in organizers)."
Fedora
Paul Frields to be Fedora project leader
Outgoing Fedora leader Max Spevack has sent a goodbye letter of sorts from FUDCon and announced that the new project leader will be Paul Frields. "Many of you already know Paul. He has been part of the Fedora community since 2003, not long after the Red Hat Linux Project officially merged with the original Fedora.us. Paul has worked with Fedora's documentation, packaging, marketing, news, and artwork teams. He also served as one of the inaugural members of the Fedora Project Board."
Gentoo Linux
Gentoo loses charter; Robbins offers to return
The Gentoo Foundation lost its charter a few weeks ago, causing Daniel Robbins, founder of Gentoo, to offer to return as President of the foundation. His offer comes with a number of conditions, not least of which is that the current trustees resign in favor of those he chooses. "If I return as President, I will preserve the not-for-profit aspect of Gentoo. Beyond this, you can expect everything to be very, very different than how things are today." No word yet on a response from the current trustees.
Mandriva Linux
Mandriva and Turbolinux create Manbo-Labs
Mandriva and Turbolinux have announced the creation of a joint venture called "Manbo-Labs," the purpose of which is to create a common base distribution that both can build their products on. "Manbo-Labs' team is composed of more than ten developers from France, Japan, Brazil and also includes developers from the community. Altogether, they have been working on building a common Linux base system to be released in April 2008. Mandriva Linux 2008 Spring will be based on this system."
Slackware Linux
GNOME.SlackBuild (GSB) RC1 ready for testing
The first release candidate of GNOME.SlackBuild (GSB) is available for testing by Slackware 12.0 users. "Originally based on the Freerock GNOME project, GNOME.SlackBuild (GSB) provides the latest GNOME stable (2.20.3) binary packages and complete source build system for Slackware Linux."
SUSE Linux and openSUSE
openSUSE Roadmap to 11.0
The openSUSE project has roadmap and schedule of the milestones in the journey to version 11.0. According to the schedule openSUSE 11.0 Alpha 1 will be out later this week.
Distribution Newsletters
Fedora Weekly News Issue 115
The Fedora Weekly News for January 7, 2008 includes "Fedora's way forward" by Max Spevack, Planet Fedora articles on "Transition", "Fedora marketing revitalization", "To all FUDCon attendees", "FUDCon 2008 - Day 2" and "FUDCon 2008 - Day 1", and much more.openSUSE Weekly News, Issue 5
The openSUSE Weekly News covers KDE 4.0 Released with openSUSE Packages and openSUSE-based live CD, openSUSE Shop Now Live, Lenovo delivers preloaded SUSE Linux Enterprise Desktop 10, Temporary Download Failure, In Tips and Tricks: Webpin: Package Search from the Web or from your Shell, and several other topics.PCLinuxOS Magazine - Issue 17
The January 2008 edition of PCLinuxOS Magazine is out. Articles include Throwing Windows Out The Window, Common Information Commands, Help With Documentation, Howto Repair kdeinit Problems, It's Magic - PMagic, PCLinuxOS Based Distros - Update, Squeeze Your Data - A New Compression Strategy, and much more.Ubuntu Weekly Newsletter #73
The Ubuntu Weekly Newsletter for January 12, 2008 looks at Hardy Alpha 3 released, Ubuntu 7.10 Desktop Course, KDE 4.0, a new member and MOTUs, MOTU Council election, an upcoming Hug Day, Forums tutorial of the week, and much more.DistroWatch Weekly, Issue 235
The DistroWatch Weekly for January 14, 2008 is out. "The release of KDE 4.0.0, the deepening crisis in Gentoo Linux and a series of announcements from the Fedora User and Developer Conference (FUDCon) dominated the headlines last week. As expected, the major new version from the popular desktop environment project received mixed reaction from distribution makers and users; while some distros were quick to release binary packages and special KDE 4 live CDs for users to sample the new code, it's clear that the first KDE 4 release is far from ready to take over our desktops. Also in this issue, openSUSE has published a roadmap leading towards the upcoming release of version 11.0 and VectorLinux has announced the first 64-bit edition of its Slackware-based distribution."
Page editor: Rebecca Sobol
Development
Use Ubuntu Tweak to adjust hidden GNOME options
Ubuntu Tweak is a GNOME desktop configuration tool that works with versions 7.04 and 7.10 of the Ubuntu distribution. From the application's splash screen:
Version 0.2.4 of Ubuntu tweak was
announced in December, 2007:
"With many bugs fixed and two language added, the stable version of Ubuntu Tweak 0.2.4 released!
"
Installation was trivial, the .deb file was downloaded in the Firefox web browser; that, in turn, allowed the installer application to be run. A minute later, the software was ready to go. The application was automatically added to the GNOME Applications/System Tools pulldown menu.
So, what can Ubuntu Tweak do? There are a number of top-level icons, some with multiple sub-icons. Top-level categories include: Computer, Startup, Desktop, System and Security. Clicking on the Computer icon reveals useful information such as the hostname, distribution version, kernel rev, platform, CPU type and speed and memory capacity. The username, home directory, shell and default language are also displayed. The Startup icon allows the user to toggle features such as the automatic saving of session changes, the logout prompt, remote TCP connections and the splash screen.
The Desktop icon allows numerous features to be adjusted on the Desktop Icon Settings, the Metacity window manager, Compiz Fusion, the GNOME panel and menu and the Nautilus file browser. The System icon has toggles and sliders for controlling various power management parameters. Lastly, the Security option has toggles for disabling the Run Application dialog, the Lock Screen, Printing, Printer Setup, Save to Disk and User Switching.
That's about all there is to this version of Ubuntu Tweak, there is room to add many more control options. Ubuntu Tweak seems like a useful tool for managing options that don't really fit anywhere else on the desktop environment. The only surprise is that this is, by name, only useful for the Ubuntu distribution. It seems as though making a multi-distribution GNOME-tweak would not require many changes to the code.
System Applications
Database Software
eXist: 1.2 released (SourceForge)
Version 1.2 of eXist has been announced. "eXist is a native XML database featuring efficient, index-based XQuery processing, extensions for keyword search, XUpdate support, and tight integration with existing XML development tools."
phpMyAdmin: 2.11.4 is released (SourceForge)
Version 2.11.4 of phpMyAdmin has been announced. "phpMyAdmin is a tool written in PHP intended to handle the administration of MySQL over the Web. Currently it can create and drop databases, create/drop/alter tables, delete/edit/add fields, execute any SQL statement, manage keys on fields. Welcome to phpMyAdmin 2.11.4, a bugfix-only version."
Postgres Weekly News
The January 13, 2008 edition of the Postgres Weekly News is online with the latest PostgreSQL DBMS articles and resources.
Web Site Development
BitNami RubyStack 1.0 released
Version 1.0 of BitNami RubyStack is available. "It is a free, all-in-one binary installer for Apache, MySQL, Ruby and the Rails framework. You basically click-click-finish your way to a complete Rails installation, including third-party modules such a Mongrel and ImageMagick. It runs on Windows, Linux and OS X and is distributed under the Apache license. If you have been curious about Rails and wanted to try it out, this is your opportunity."
JAMWiki: 0.6.3 Released (SourceForge)
Version 0.6.3 of JAMWiki has been announced. "JAMWiki is a Wiki engine implemented using Java/JSP that attempts to provide much of the functionality of MediaWiki. It can be run with or without a database and is designed to be fast and easy to set up. Please visit jamwiki.org for further details. JAMWiki 0.6.3 (code name "Foodscapes") is now available for download. The 0.6.3 release is a minor release that includes several enhancements and minor fixes."
Desktop Applications
Audio Applications
Ardour 2.2 released
Version 2.2 of Ardour, a multi-track audio recording system, has been announced. "Ardour version 2.2 has been released, filled with several significant new features and lots of helpful bugfixes. The editing model has been significantly improved for much faster workflow, and Ardour now uses the Rubber Band library for timestretching (and offers pitchshifting as well)."
JACK 0.109.0 released
Version 0.109.0 of the JACK Audio Connection Kit has been announced. Changes include nuerous API changes, some new capabilities and bug fixes.LV2 Released
The first stable release of the LV2 specification has been announced. "LV2 is a simple but extensible successor of LADSPA, intended to address the limitations of LADSPA which many applications have outgrown. By creating LV2 "extensions" (which can be done independently), virtually any feature is possible for LV2 plugins and hosts. This release (revision 1) has been in active use by many projects for several months, including several extensions for advanced features beyond the capabilities of LADSPA or DSSI."
First versions of lv2dynparam extension and helper announced libraries for it
The initial release of lv2dynparam extension and helper have been announced. "lv2dynparam is LV2 extension for dynamic parameters. The extension consists of a header describing the extension interface and libraries, one for plugins and one for hosts, to expose functionality in more usable, from programmer point of view, interface."
lv2vocoder plugin version 1 released
Version 1 of lv2vocoder plugin has been announced. "Perhaps you don't know what a vocoder is, but I'm sure you have heard one before. Vocoders are often used to add a robotic effect to vocals in music."
SLV2 0.4.2 Released
Version 0.4.2 of SLV2 has been announced. "SLV2 is a C library to make the use of LV2 plugins as simple as possible for host applications. Unlike LADSPA, LV2 is (more or less) designed with the assumption that hosts will use a library to discover/load/use plugins. SLV2 is one such library, which does the Right Thing with as little burden on host authors as possible. This release corresponds to the new stable LV2 release, Revision 1."
New version of ssg announced
Release 20080109 of ssg, the Simple Sine Generator, is out. "It now requires lv2core. Simple Sine Generator is very simple instrument/generator plugin with midi in and audio out ports. It expected to be useful for testing LV2 hosts and as base for writing your own plugins."
zynadd plugin version 1
Version 1 of zynadd plugin has been announced. "The zyn project main goal is to extract synth engines from ZynAddSubFX and pack them in LV2 plugin format. Resulting plugin(s) are heavily based on work made by Nasca Octavian Paul."
zynjacku version 1 released
Version 1 of zynjacku has been announced. "zynjacku is JACK based, GTK (2.x) host for LV2 synths. It has one JACK MIDI input port (routed to all hosted synths) and one (two for stereo synths) JACK audio output port per plugin. Such design provides multi-timbral sound by running several synth plugins. zynjacku is a nunchaku weapon for JACK audio synthesis. You have solid parts for synthesis itself and you have flexible part that allows synthesis to suit your needs."
Patchage 0.4.0 released
Version 0.4.0 of Patchage has been announced. "After ages of SVN-only development, Patchage 0.4.0 released. This release is essentially a complete rewrite of the last stable release (ancient history, but still in distributions). Released in parallel are my libraries RAUL (Realtime Audio Utility Library) and FlowCanvas (the canvas widget for Patchage, Ingen, etc), which Patchage depends on. If you're a C++ LAD hacker, these might be useful on their own."
Business Applications
JasperReports: 2.0.4 released (SourceForge)
Version 2.0.4 of JasperReports, an open source business intelligence and reporting engine, has been announced. The changes include: "support for Dotted and Double line style added; - warning messages added to signal the use of deprecated pen and box attributes and tags in JRXML; all samples refactored; - minor bug fixes and improvements".
Data Visualization
videoIO Toolbox for Matlab: 0.5 Beta 3 (SourceForge)
The 0.5 Beta 3 version of videoIO Toolbox for Matlab has been announced. The software is: "A library providing easy, flexible, and efficient read/write access to video files using a wide variety of codecs in MATLAB on Windows and GNU/Linux platforms, using DirectShow and ffmpeg backends, respectively. The 0.5-beta3 version has been released. It includes full 64-bit support, new imread and load plugins, and numerous fixes and improvements."
Desktop Environments
GNOME 2.20.3 released
Stable version 2.20.3 of GNOME has been announced. "This is the final release in a series of point releases for the stable 2.20 branch. Come and see all the bug fixing, all the new translations and all the updated documentation brought to you by the wonderful team of GNOME contributors! While development is underway on the GNOME 2.21/2.22 road, work on the stable branch continued to make it even more solid."
GARNOME 2.20.3 announced
Version 2.20.3 of GARNOME has been announced. "This release incorporates the GNOME 2.20.3 Desktop and Developer Platform, fine-tuned and updated with love by the GARNOME Team. Come and see all the bug fixing, all the new translations and all the updated documentation brought to you by the wonderful team of GNOME contributors! This is the fourth release of the current stable GNOME branch, and the third bug-fixing release, which ships with the latest and greatest stable releases."
GNOME Software Announcements
The following new GNOME software has been announced this week:- Accerciser 1.1.5 (new feature, bug fix and translation work)
- Agave 0.4.4 (new feature and translation work)
- Anjuta DevStudio 2.3.2 (new features, bug fixes and translation work)
- atk 1.21.5 (bug fixes)
- cairo 1.4.14 (bug fixes)
- cheese 2.21.5 (new features, bug fixes and translation work)
- Clutter 0.5.2 (new features and bug fixes)
- Conduit 0.3.5 (new features and bug fixes)
- Deskbar-Applet 2.21.5 (new features, bug fixes and translation work)
- Empathy 0.21.5.1 (bug fixes and ABI change)
- Empathy 0.21.5.2 (new features, bug fixes and translation work)
- eog 2.21.4 (new features, bug fixes and translation work)
- Evolution 2.21.5 and related (new features, bug fixes and translation work)
- gbrainy 0.5 (new features and bug fixes)
- gcalctool v5.21.5 (bug fixes, documentation and translation work)
- GLib 2.15.2 (new features, bug fixes and translation work)
- gnome-applets 2.21.4 (support for latest libgweather)
- gnome-control-center 2.21.5 (new features, bug fixes and translation work)
- Gnome-games 2.21.5 (new features, bug fixes, documentation and translation work)
- gnome-keyring 2.21.5 (new features, bug fixes and translation work)
- gnome-settings-daemon 2.21.5 (new features and bug fixes)
- gnome-settings-daemon 2.21.5.2 (new feature, bug fix and translation work)
- gnome-speech 0.4.18 (bug fix)
- Gtk2-Perl 2.21.5 (new features and bug fixes)
- libepc 0.3.2 (bug fix)
- libepc 0.3.3 (bug fix)
- Libgweather 2.21.2 (unstable testing release)
- Mousetweaks 2.21.5 (new features and translation work)
- nautilus-python 0.5.0 (new features and bug fixes)
- Orca 2.21.5 (bug fixes and translation work)
- ScroogLyrics 0.11 (new features and code rewrite)
- TaskJuggler 2.4.1-beta1 (bug fixes)
- Tinymail 0.0.7 (bug fixes)
- Tomboy 0.9.4 (new features, bug fixes and translation work)
KDE 4.0 Released
As expected, the KDE 4.0 release is now available. See the full announcement for details, screenshots, and download information, or the visual guide for even more screenshots.The Start of Something Amazing with KDE 4.0 Release (KDE.News)
KDE.News covers the release of KDE 4.0. "Several years of design, development and testing came together today for the release of KDE 4.0. This is our most significant release in our 11 year history and marks both the end of the long and intensive development cycle leading up to KDE 4.0 and the start of the KDE 4 era."
KDE Commit-Digest (KDE.News)
The January 6, 2008 edition of the KDE Commit-Digest has been announced. The content summary says: "Final commits for KDE 4.0 Final before the tagging freeze. KDE 4.0 Final tagged for release. Lots of optimisations and bugs fixed across KDE. Kickoff menu items can now be added to the Plasma desktop or panel. Improved resize and rotate for Plasma applets. Document list sorting in Kate. Various progress in KDevelop. Mailody moves towards using Akonadi for its IMAP functionality, various improvements in Akonadi. Start of a KHotNewStuff2 implementation in Kalzium for downloading molecular files. Experimental IVTV support in the Kalva video player..."
KDE Software Announcements
The following new KDE software has been announced this week:- Amarok Atom Syndication 0.1.5 (unspecified)
- cueIt .08 (code rewrite, new features and bug fixes)
- KBib 0.6.4 (new features and bug fixes)
- KBlogger 0.1-alpha1 (new features and code cleanup)
- KDelicious 3.1 (new features, bug fixes and translation work)
- KDE2Wine Colorsync 0.9 (unspecified)
- KMDAlert 0.1 (unspecified)
- KMess 1.5 (new features)
- ktiny 1.0.0-beta1 (unspecified)
- Kvkbd 0.4.8 (bug fixes)
- Manslide 1.9.6 (new features and bug fixes)
- nmapsi4 0.1~rc1 (new features and bug fixes)
- plasma-mpc 0.2 (unspecified)
- PlayCDG 0.5.1 (new feature and bug fix)
- Prayertimes Plasmoid 0.1 (initial release)
- 'Q' DVD-Author 1.0 final (new features and bug fixes)
- qombinatorics 0.2 (new feature)
- rkward 0.4.9 (new features and bug fixes)
- Soprano 2.0 final (completely revamped stable version)
- Umbrello UML Modeller 2.0.0 (first KDE 4 version)
Xorg Software Announcements
The following new Xorg software has been announced this week:- libXmu 1.0.4 (new features and bug fix)
- xf86-video-amd 2.7.7.4 (bug fixes)
- xf86-video-amd 2.7.7.5 (OLPC support and bug fix)
- xinput 1.3.0 (new features and documentation work)
- xsel 1.0.0 (new features and bug fixes)
Desktop Publishing
Scribus 1.3.3.10 released
Version 1.3.3.10 of Scribus, a desktop publishing system, has been announced. "This stable release adds the following: Several fixes and improvements to text frames and the Story Editor. New Arabic Translation. More translation and documentation updates. Many improvements to PDF Forms exporting and non-Latin script handling in PDFs. Several fixes to protect against possible crashes. Improved Color Managed Display in some cases. Some fixes to the Scripting plugin. One of the major additions to this release is the final complete German translation of the Scribus documentation by Christoph Schäfer and Volker Ribbert."
Electronics
gEDA/gaf development version 1.3.1.20080110
Version 1.3.1.20080110 of gEDA/gaf, an electronic EDA suite, has been announced. "This release rolls a bunch of fixes, updates, and translations that occurred over the past 10 days. Many thanks to everybody involved including all the contributers and language translators!"
gerbv 2.0 released
Version 2.0 of gerbv, a Gerber CAD file viewer, has been announced. "Gerbv release 2.0.0 represents a a whole new look for gerbv. Most importantly, the layer control GUI has been made much more powerful through the outstanding work of Julian Lamb. Julian has also re-worked the GUI's button and menus to make them more convenient to use."
Fonts and Images
Relicensing HarfBuzz
The HarfBuzz font project has adopted a new, simplified license for portions of its ftlayout code. "Between 1998 and 2004 the FreeType project developed an implementation of the OpenType Layout specification (formerly TrueType Open), called ftlayout, that eventually was ripped out of FreeType 2 and was salvaged by Pango and Qt developers and integrated into their layout engines. The code was further developed by the two projects separately and was merged back and renamed to HarfBuzz. The ftlayout code, like the rest of FreeType, was dual-licensed under GPL+FTL. The license, while quite liberal, posed delicate incompatibility issues with Pango's LGPL license because of the so-called advertisement clause in the FTL."
Games
ScummVM: 0.11.0 released (SourceForge)
Version 0.11.0 of ScummVM has been announced. "ScummVM is a program which allows you to run certain classic graphical point-and-click adventure games, provided you already have their data files. The clever part about this: ScummVM just replaces the executables shipped with the games, allowing you to play them on systems for which they were never designed. This release adds support for 8 new games, including freeware Lure of the Temptress as well as I Have no Mouth, and I Must Scream, Elvira 1 and 2, Waxworks and Sierra pre-AGI games. Also iPhone and Maemo ports are distributed officially. Many bugfixes, more non-English versions of the games are supported, and much much more."
UFO:Alien Invasion: 2.2 released (SourceForge)
Version 2.2 of UFO:Alien has been announced. "It is the year 2084. You control a secret organisation charged with defending Earth from a brutal alien enemy. Build up your bases, prepare your team, and dive head-first into the fast and flowing turn-based combat. The UFO:AI development team is proud to announce the release of UFO:Alien Invasion Version 2.2 We worked hard on this new stunning version for more than half a year. Now it's here for you to play it."
Interoperability
Wine 0.9.53 released
Version 0.9.53 of Wine has been announced. Changes include: "RunOnce and Run entries now executed on startup, Beginnings of support for emulated disk devices, Many Richedit improvements, Nicer looking color dialog and Lots of bug fixes."
Web Browsers
Lobo Browser: 0.97.5 Released (SourceForge)
Version 0.97.5 of Lobo Browser has been announced. "Lobo is an open source web browser that is written entirely in Java. It is being developed with the aim to support HTML 4, Javascript and CSS2. The general goal of the project is to produce a browser that is fast, easy to extend, secure and feature-rich. Lobo is being released along with its pure Java rendering engine, Cobra. Version 0.97.5 introduces a BrowserPanel class, improved float layout and many bug fixes. Several patches contributed by user guenze are also included with this release."
Mozilla Links Newsletter
The January 10, 2008 edition of the Mozilla Links Newsletter is online, take a look for the latest news about the Mozilla browser and related projects.
Miscellaneous
wfyd: 0.5 released (SourceForge)
Version 0.5 of wfyd has been announced. The software is a: "Minimalistic time tracking program with nag capabilities. After more than two years of inactivity, wfyd project has moved to SourceForge.net. New release contains some small bug fixes."
Languages and Tools
C
GCC 4.3.0 Status Report (2008-01-11)
The January 11, 2008 edition of the GCC 4.3.0 Status Report has been published. "We are in Stage 3. When we reach 100 open regressions, we will go to regression-only mode. When we approach the 4.3.0 release, we will create a branch, and open Stage 1 for 4.4.0."
Caml
Caml Weekly News
The January 15, 2008 edition of the Caml Weekly News is out with new articles about the Caml language.
Lisp
ECL 0.9i released
Version 0.9i of Embeddable Common Lisp is available. "This version fixes a lot of bugs and contains some improvements, such as finalization, an implementation of serve-event, and condition variables."
SBCL 1.0.13 released
Version 1.0.13 of Steel Bank Common Lisp (SBCL) has been released. "This version speeds up sequence functions, supports executing external programs with Unicode input/output, and fixes many bugs."
Perl
This Week on perl5-porters (use Perl)
The December 30, 2007 to January 5, 2008 edition of This Week on perl5-porters is out with the latest Perl 5 news.
Shells
Announcing fish 1.23.0
Version 1.23.0 of fish, the friendly interactive shell, has been released. Changes include: "Case insesitive tab completions: If no completions can be found with an exact case match, fish attempts to use case insensitive matching as a fall back. Better navigation in multi line commands. The up/down keys are now used to move up and down in a multi line command. They are still used to search the history when used to go 'beyond the end'. A new key binding system that makes it very easy to edit the key bindings interactively, new binding modes are written in shell script."
IDEs
XPL Editor 0.0.4 released (SourceForge)
Version 0.0.4 of XPL editor has been announced. "The XPL editor is an RCP Eclipse application based on the eXtensible Presentation Language, an xml-based presentation language built on top of Visual Design Patterns."
Libraries
libfishsound 0.9.0 released
Version 0.9.0 of libfishsound, an interface for decoding and encoding audio data using Xiph.Org codecs, has been announced. "This release introduces support for the FLAC lossless audio codec, originally contributed by Tobias Gehrig."
liboggz 0.9.6 released
Version 0.9.6 of liboggz, an interface for reading and writing ogg streams, is available. "This release adds a new oggz-comment tool, and improvements to liboggz's determination of timestamps and seeking. Specifically, liboggz now inspects the encoded data in order reconstruct the expected granulepos (corresponding to a timestamp) for every packet in an Ogg stream. This allows applications to use reliable timestamps, even though these are only sparsely recorded in most Ogg streams."
Version Control
git version 1.5.4-rc3 released
Version 1.5.4-rc3 of the git distributed version control system has been announced. "In any case, we managed to keep the changes only to fixes (both code and documentation) this round, aside from the promised gitk i18n enhancements. This should be pretty much the same as what we will have in final, hopefully due by the end of the month. Please give it a good beating."
Push Me Pull You 0.2 announced
Technical preview release version 0.2 of Push Me Pull You, a GUI for distributed revision control systems, is available. "PMPU supports plain hg, hg forest repositories, bzr, git and darcs asunderlying repositories. It aims to provide a powerful graphical interface to the underlying functionality, based around the workflow of incoming and outgoing changesets. PMPU is implemented in Python and PyQt4 and is tested on Linux, though it should work on other Unix platforms."
Page editor: Forrest Cook
Linux in the news
Recommended Reading
OLPC Project Working on Windows and Linux Dual-boot System (TMCnet)
TMCnet covers comments by Nicholas Negroponte about dual-booting the OLPC. "Negroponte told IDG News Service that OLPC working with Microsoft very closely to make a dual-boot system so that, like on an Apple, you can boot either one up. The version thats up and running of Windows on the XO is very fast, it's very, very successful, Negroponte said. We're working very hard to do both. He pointed out that this is a brand-new development for the XO laptops, as the low-cost notebooks are known, and came about because of Microsofts friendlier attitude toward open source software."
Why Microsoft Must Control One Laptop Per Child (Technocrat.net)
Bruce Perens examines Microsoft's reaction to the OLPC. "It's a threat Microsoft can't let stand: the entire third world learning Linux as children, and growing up to use it. And Microsoft is going to get its way. It comes after a sudden wave of SCO-like problems for the OLPC project. A specious patent lawsuit over keyboards. Board-member Intel thrown out of the project for attempting to convince national governments to drop OLPC purchases and go with its own (Windows) product. First, OLPC is shown what its problems will be if it doesn't cooperate with Microsoft. Then, Microsoft approaches with money and technical help - you just have to run Windows to get it."
Business
Broadcom and Trolltech announce VoIP partnership (InformationWeek)
InformationWeek covers a partnership between Broadcom and Trolltech. "Chipmaker Broadcom and software developer Trolltech this week formed a partnership to create a multimedia voice over IP development platform based on Linux. The development platform is intended for original equipment manufacturers that want to build what the companies call "next-generation" IP phones. It combines Broadcom's VoIP technology and Trolltech's Qtopia Linux platform and user interface for mobile devices."
Linux Adoption
Linux PC Models Multiply As Vista Struggles (InformationWeek)
InformationWeek has an overview of the recent proliferation of "mainstream" Linux systems. The article highlights various machines, targeted at regular consumers, that run Linux. "What's behind the growing interest in open source computing, long the preserve of self-styled computer geeks? Linux's increasing popularity among mainstream PC users may in part reflect a backlash against Microsoft. The company's new Windows Vista OS has failed to capture users' hearts and minds, let alone their wallets."
Interviews
Linux guru offers sneak peek at Kernel Report (ComputerWorld)
ComputerWorld interviews LWN editor Jonathan Corbet about his upcoming linux.conf.au talk. Your editor promises that he had nothing to do with the title they chose for this article.
Resources
Linux phone stack bonds with Android (LinuxDevices)
LinuxDevices looks at A la Mobile's Linux phone stack. "A la Mobile demonstrated its Linux phone stack working with Google's Android APIs (application programming interfaces). The demonstration is intended to show how the Linux kernel, drivers, and middleware in a la Mobile's Convergent Linux Platform (CLP) can accelerate Android development, the company said."
Web Services Without Pain: gSOAP Writes Your XML, SOAP, and RPC. (Technocrat)
Technocrat looks at gSOAP. "[gSOAP] takes a header defining C or C++ functions, or a URL for someone else's web service definition, and automatically writes both clients and servers in C or C++. The impact of this program on a programmer's task is as great as that of a compiler converting a high-level-language to assembly code."
Reviews
Shuttleworth on Bazaar and open-source project development (Linux-Watch)
Linux-Watch takes a look at Bazaar. "In a blog posting, Canonical CEO and Ubuntu founder Mark Shuttleworth observed that the new version has many "small but useful branches with bug fixes for various corner cases, operating systems and integrations with other tools." In particular, Shuttleworth noted the rapid development of the Bazaar Plugin for the Eclipse IDE (Integrated Development Environment). Since Eclipse, according to the 2007 Linux Foundation survey is the single most important Linux desktop application development platform, this integration effort is likely to be well used by Linux programmers."
Two-pound Linux UMPC on sale Jan. 25th (Linux Devices)
Linux Devices takes a peek at the Everex CloudBook Ultra-Mobile PC, which was officially announced at the Consumer Electronics Show. "As reported, the two-pound laptop is equipped with a Via C7-M ULV processor clocked at 1.2GHz, plus 512MB RAM, a 4-in-1 memory card reader, and a 30GB hard drive. The laptop features a 7-inch, 800x480-pixel screen, plus WiFi, Ethernet, two USB ports, and DVI-Out. The story adds new details such as the CloudBook's 1.3M-bps Ezonics webcam and its touted ability to average five hours of battery life."
Shuttle's $199 Linux PC (News.com)
News.com covers Shuttle's new KPC line of inexpensive Linux PCs that were unveiled at CES. "It'll have an Intel Celeron processor, a 945GC chipset, 512MB of memory and either a 60GB or 80GB hard drive. What it won't have: an optical drive or a PCI Express slot. Despite that, it's a pretty good-looking box, and comes in red, blue, white, and black, each with a different icon stamped on the front. Shuttle(Credit: Shuttle) Shuttle also says there will be a $99 barebones version of the KPC."
Lightzone: A Powerful Camera RAW Editor for Linux (Wired)
Wired takes a look at LightZone, a commercial photo editor package. "If you're finding DigiKam or F-Spot, two of the many photo organization and editing tools for Linux, a bit limiting you may want to give Lightzone a try. The software isn't free, and curiously, isn't available for purchase either, but judging by the 20-day demo version currently available, it could end up a serious contender in the hybrid photo editing/managing market."
Page editor: Forrest Cook
Announcements
Non-Commercial announcements
Apache Software Foundation Wraps Up 2007
The Apache Software Foundation has announced the highlights of 2007, it's strongest year to date. "The Apache Software Foundation (ASF) -- stewards, incubators, and developers of leading Open Source projects, including Apache HTTP Server, the world's most popular Web server software for twelve years running -- today announced the 2007 year finished as its strongest ever, reinforcing the broad-reaching success of "The Apache Way." Lauded as one of the most compelling communities in Open Source, the all-volunteer Foundation looked back on milestones achieved during 2007, with ASF activities having grown at a steady rate."
The Creative Commons CC0 project
The Creative Commons has announced CC0, "a Creative Commons project designed to promote and protect the public domain by 1) enabling authors to easily waive their copyrights in particular works and to communicate that waiver to others, and 2) providing a means by which any person can assert that there are no copyrights in a particular work, in a way that allows others to judge the reliability of that assertion." There is a great deal of uncertainty around how the public domain works all over the world, so any additional light on the subject should be a good thing.
Commercial announcements
Engine Yard raises $3.5 Million from Benchmark Capital
Engine Yard has announced the receipt of $3.5 million in funding. "Engine Yard, a leading provider of Ruby on Rails application deployment and support, today announced the closing of a $3.5 million Series A investment from Benchmark Capital. The funds will be used to expand the company's global operations, to strengthen its customer service organization worldwide, and to enhance the core technologies that underlie Ruby on Rails applications."
Ohloh goes Open Source
Ohloh has announced a decision to release its technology as open-source software. "Ohloh, an open source network for people who create and use open source software, today announced that it is open sourcing its technology. The development community can access Ohloh source code and contribute to Ohloh via a new part of the Ohloh web site, Ohloh Labs. This means Ohloh tools and the Ohloh website itself will be freely available and modifiable by the community."
OpenMoko signs deal with Pulster
OpenMoko and Pulster have announced a partnership. "OpenMoko, creator of the first completely integrated open source mobile platform, today announced it has inked a deal with mobile device distributor, Pulster, in Germany. The agreement comes fresh on the heels of Openmoko's announcement that it has become an independent subsidiary of Taiwan powerhouse, FIC. Pulster specializes in online sales of mobile devices, selling into the industrial and education markets with focus on Linux-based solutions."
OpenVZ virtual appliance for Ubuntu
The OpenVZ project has released new virtual appliance software for Ubuntu 7.10. "Users simply download a file and then can use OpenVZ software to create a virtual server running Ubuntu 7.10 in about one minute. "This combination of open source technologies enables someone new to Ubuntu a really easy way to get up and running, while current users have alternative method of running Ubuntu with negligible -- if any -- impact on their system resources," said Malcolm Yates, ISV Alliances Manager at Canonical, the commercial sponsor of the Ubuntu project."
Virgin Mobile Implements MySQL Enterprise
MySQL AB has announced the use of MySQL Enterprise by Virgin Mobile. "Virgin Mobile, a leading Mobile Virtual Network Operator (MVNO), has implemented a MySQL Enterprise Platinum subscription to manage its data using the world's most popular open source database. The mobile phone operator has become very popular thanks to a particularly attractive offer: unlimited outgoing SMS text messages towards all operators, for an unlimited time. In terms of mobile applications, SMS remains the most commonly used medium. The considerable storage and processing requirements for SMS require a highly available database management system."
New Books
Advanced Rails--New from O'Reilly Media
O'Reilly has published the book Advanced Rails by Brad Ediger.Apache Cookbook, Second Edition--New from O'Reilly Media
O'Reilly has published the book Apache Cookbook, Second Edition by Ken Coar and Rich Bowen.
Calls for Presentations
EuroSec Workshop cfp
A call for papers has gone out for the EuroSec Workshop. The event takes place on March 31, 2008, submissions are due by February 15. "EuroSec (http://www.cs.vu.nl/eurosec08/) is a new workshop associated with the Annual ACM SIGOPS EuroSys conference. The workshop aims to bring together researchers, practitioners, system administrators, system programmers, and others interested in the latest advances in the security of computer systems and networks. The focus of the workshop is on novel, practical, systems-oriented work. EuroSec will be held on the 31st of March, 2008, in Glasgow, Scotland."
Call for Participation Open for OSCON 2008
O'Reilly has announced the call for participation for the 2008 O'Reilly Open Source Convention (OSCON), which will take place July 21 - 25, 2008 in Portland, Oregon. The deadline for proposals is February 4, 2008. "Program co-chairs Edd Dumbill and Allison Randal are keen to focus on what the next ten years of open source development will bring to the industry. "On the tenth anniversary of OSCON," noted Randal, "we're looking ahead to the next ten years. We want to hear about the disruptive technologies and revolutionary solutions that are changing the game of open source. If the first ten years of OSCON were about opening the minds of big business to the philosophy of open source, is the next ten years about opening the minds of the open source community to the possibilities of its future?""
sambaXP 2008 - call for papers
A call for papers has gone out for sambaXP 2008. "From April 17th to 18th 2008 developers and users will meet again in Goettingen, Germany at the seventh international Samba conference, the "samba eXPerience 2008". The sambaXP is the leading event with focus on the most important free alternative to proprietary SMB/CIFS servers. The call for papers and early bird registration are open until January 28th 2008."
Upcoming Events
XMMS2 developers at FOSDEM '08
The XMMS2 audio player developers will attend the 2008 FOSDEM conference. "This years FOSDEM will take place in Brussels, Belgium the 23-24 of February. We have been talking about this event on the mail-list for a while now and it seems like a couple of XMMS2 developers will now show up."
Linux Installfest workshop in Davis, CA
The Linux Users' Group of Davis will hold another free Linux Installfest workshop in Davis, California on January 26.SCALE Finalizes Plans
The Southern California Linux Expo schedule has been finalized. "The commercial booths have all been filled. Several non-profit groups have recently been added to the SCALE expo floor: Enlightenment, which will be showcasing the work going into E17. Enlightenment is rarely seen at conferences, so this is your opportunity to learn about the desktop that first defined the term "eye candy". Also added were OpenMoko and Damn Small Linux. And for the first time all three of the major BSDs, OpenBSD, NetBSD, and FreeBSD will have booths at SCALE."
SCALE adds training classes
The Southern California Linux Expo (SCALE) has announced the addition of two half-day training classes. The morning class is "Open-Source Email Systems: One Approach to Spam Fighting" taught by Austin Godber, while the afternoon class is "Introduction to Virtualization on Linux with Xen" taught by Chris St. Pierre. The classes will be held on the first day of SCALE, 8 February 2008 at the Los Angeles airport Westin. Click below for more information.YAPC::Asia 2008 announced
The YAPC::Asia 2008 Perl conference has been announced. "YAPC::Asia 2008 is announced to be held on May 15-16th in Tokyo. More detailed information from the organizers will follow."
Events: January 24, 2008 to March 24, 2008
The following event listing is taken from the LWN.net Calendar.
| Date(s) | Event | Location |
|---|---|---|
| January 24 | Federal DBA Day | Washington DC, USA |
| January 28 February 2 |
Linux.conf.au 2008 | Melbourne, Australia |
| January 28 February 1 |
Ruby on Rails Bootcamp with Charles B. Quinn | Atlanta, Georgia, USA |
| January 29 January 31 |
Solution Linux 2008 | Paris, France |
| February 1 | Open Island | Belfast, United Kingdom |
| February 6 February 10 |
O'Reilly Money:Tech Conference | New York, NY, USA |
| February 7 | Frozen Perl 2009 | Minneapolis, United States |
| February 8 February 10 |
Southern California Linux Expo | Los Angeles, USA |
| February 10 February 13 |
NDSS Symposium 2008 | San Diego, CA, USA |
| February 11 | Florida Linux Show 2008 | Jacksonville, Florida, USA |
| February 11 | Open Source Software (OSS) and the U.S. Department of Defense (DoD) | Alexandria, VA, USA |
| February 13 February 15 |
German Perl-Workshop | Regionales Rechenzentrum Erlangen, Germany |
| February 16 | Frozen Perl 2008 Workshop | Minneapolis, USA |
| February 19 February 20 |
Linux Developer Symposium | Beijing, China |
| February 19 February 20 |
Files and Backup | London, UK |
| February 22 February 24 |
freed.in/2008 | Delhi, India |
| February 23 February 24 |
Free/Open Source Developers' European Meeting 2008 | Brussels, Belgium |
| February 23 February 26 |
Linux World Mexico | Mexico City, Mexico |
| February 25 February 26 |
2008 Linux Storage and Filesystem Workshop | San Jose, CA, USA |
| February 25 February 29 |
NEW PHP 5 and PostgreSQL Bootcamp with Mark Fenoglio | Atlanta, Georgia, USA |
| February 25 February 27 |
German Perl Workshop | Frankfurt, Germany |
| February 28 March 1 |
Linux Audio Conference | Cologne, Germany |
| March 1 March 2 |
Chemnitzer Linux-Tage 2008 | Chemnitz, Germany |
| March 3 March 6 |
O'Reilly Emerging Technology Conference | San Diego, CA, USA |
| March 3 March 6 |
Drupalcon Boston 2008 | Boston, MA, USA |
| March 4 March 9 |
CeBIT Germany | Hannover, Germany |
| March 8 March 14 |
Asia OSS Conference & Showcase 2008 | Guangzhou, China |
| March 11 March 12 |
4th AustralAsian Cleantech Forum | Melbourne, Australia |
| March 14 March 16 |
PyCon 2008 | Chicago, IL, USA |
| March 15 | FSF Associate Members Meeting | Cambridge, MA, USA |
| March 16 March 19 |
BossaConference 2008 - International Conference on Open Source Software for Mobile Embedded Platforms | Pernambuco, Brazil |
| March 16 March 21 |
Novell BrainShare 2008 | Salt Lake City, UT, USA |
| March 16 March 20 |
Free Software and Open Source Foundation for Africa | Dakar, Senegal |
| March 17 March 20 |
Eclipse Community Conference | Santa Clara, CA, USA |
| March 17 March 20 |
Spring VON.x Conference | San Jose, CA, USA |
| March 19 March 20 |
LinuxWorld Expo 2008 Brussels | Brussels, Belgium |
If your event does not appear here, please tell us about it.
Page editor: Forrest Cook
