LWN.net Weekly Edition for January 31, 2008
Ten-year timeline part 4: the end and the beginning
When your editor started this series, the idea was to have four installments covering the ten-year life (so far) of LWN. Well, this is the fourth installment, and it gets less than halfway there. This is not, it seems, a topic which inspires brevity. So this series will continue past the anniversary, though your editor anticipates picking up the pace a bit for the second five years. There is less to be learned, arguably, by looking at events in the relatively recent past.Anyway, at the end of the third installment, LWN had been unacquired by Tucows and was, once again, on its own. The worst of the dotcom bust may have passed, but it was still a somewhat scary environment in which to be attempting to restart a business. It was, in fact, even scarier than we had thought when we so naively set out to show that we could do a better job of bringing in the cash than Tucows did.
- February 7, 2002: Linus
tries BitKeeper at last.
- February 14, 2002: Sun states that it will "ship a full implementation of the Linux operating system." Dave Whitinger joins LWN.net.
Dave Whitinger was, of course, one of the founders of LinuxToday. He joined LWN with the intent of helping us develop the advertising side of the business. That did not work out as intended, but it is hardly Dave's fault; it was a terrible time to be trying to sell advertising.
- February 28, 2002: Sun cuts off free access to StarOffice, but we had OpenOffice.org by then and didn't mind. BitKeeper starts to settle in as the kernel's source management system.
Linus stuck with BitKeeper after his initial trial, setting a number of things in motion. For the next few years, the use of proprietary software at the core of the kernel development process would be a constant source of unhappiness and worry - and, in fact, the story had just the sort of unhappy ending that some observers had feared. But this was also the move which rationalized the kernel work flow and made the whole system scale; the incredible rate of change we see now would not have been possible without it. The use of BitKeeper also made the community aware of what distributed source control could do and, eventually, inspired the creation of a number of free programs with the same essential features. One could say that the community would have eventually developed these systems on its own without the push from Larry McVoy and BitKeeper, and that's probably true. But the fact is: we didn't do it at that time, so we had no real alternative to BitKeeper.
- March 7, 2002: Martin
Dalecki's "IDE cleanup" patches start to raise concerns among kernel
developers, who have this strange notion that their disks should
actually work. A petition against the use of BitKeeper circulates on
the net. Eric Raymond goes around telling the world that the kernel
development process is "in crisis."
- March 14, 2002: Richard Stallman claims that the GNU HURD will be ready by the end of the year. MandrakeSoft pleads for donations to keep the business alive - and LWN does too. Martin Dalecki officially takes over IDE maintenance - and breaks more systems.
We got about $5,000 from our initial plea for donations. It was a real act of generosity on the part of our readers, but one does not keep a business with five employees going for very long with that sort of money.
- March 28, 2002: The
proposed "consumer broadband and digital television promotion act"
would require DRM technology in all software which touches digital
media. Lineo lays off more staff.
- April 25, 2002: More
BitKeeper flames. Lineo goes through a "recapitalization" effort to be
able to do things like pay its employees.
- May 2, 2002:
OpenOffice.org 1.0 is released.
- June 6, 2002: LWN switches to the "new" site code. Red Hat applies for a few software patents. ADEOS, a real-time system which avoids the RTLinux patent, is released. UnitedLinux launches. Mozilla 1.0 is released.
It is amazing how many readers hated the new code. Certainly there were a lot of silly things in the initial version of the site; we fixed a number of them in a hurry. Many readers disliked the ability to post comments - often posting comments to that effect. The addition of comments was something we thought about carefully for a long time; we were quite concerned that they could ruin the feel of the site. In the end, it seems, trusting our readers has paid off; the quality of the conversation here is often quite good.
UnitedLinux was a cooperative effort between Caldera, Conectiva, SuSE, and Turbolinux; the idea was to join together to create a common base from which each could then craft a separate product. The effort was never all that successful, and the presence of Caldera would, of course, doom it outright in the end. But it was a big deal at the time. It is interesting to see that Mandriva (despite MandrakeSoft's refusal to join UnitedLinux) and Turbolinux are now attempting a very similar sort of arrangement.
- June 13, 2002: Secure
Computing Corporation claims patents on SELinux.
- June 27, 2002: The 2002
kernel summit sets October 31 as the date for the 2.6 feature
freeze. GNOME 2.0 is released.
- July 4, 2002: Darl McBride
takes over at SCO.
- July 25, 2002: LWN announces "the end of the road." The "IDE cleanup" patch series (up to number 100) causes system lockups and file corruption. Debian GNU/Linux 3.0 ("woody") is released. Version 1.0 of the Ogg Vorbis codec is released.
By the end of July, we had come to realize that the advertising business was not going to work out for LWN, and we were short of other ideas. The bank account had reached a point where we could not pay even very small expenses. So we concluded that it was time to throw in the towel and try something else - though we had no clue of what "something else" might be. It was with a heavy heart that we announced our plan to shut down the site.
What happened next is that our donation box, which had sat mostly empty after the initial announcement, was suddenly topped up to the tune of about $35,000. Many of the donations came with notes to the effect of "use this to throw a big party." This, shall we say, got our attention. We decided that, just maybe, the subscription idea was worth a try after all, and decided to make a go of it. It was not the end after all.
- August 1, 2002: A new
beginning. HP tries to use the DMCA to shut down disclosure of
security holes.
- August 15, 2002: Distributions from MandrakeSoft, Red Hat, and SuSE are certified to be compliant with the Linux Standard Base.
This was when our credit card merchant bank at the time decided that all those donations might just be fraudulent. So they seized the money back out of our bank account. That, too, got our attention. It took a few months and some lawyer time to get the money you all had sent in our direction; during that time, it was money from PayPal (the subject of everybody else's horror stories) that kept the lights on while our main source of cash was blocked.
Needless to say, we got a new merchant bank, which we still use to this day. The new bank exhibits a rather higher clue level than the old one did, but we also learned a valuable lesson: don't mess with the credit card money pipeline. Every now and then, somebody asks why we don't accept pure donations; this is why.
- August 22, 2002: Martin
Dalecki quits and the entire series of 115 "IDE cleanup" patches is
deleted from the 2.5 kernel.
- August 29, 2002: British
Telecom's attempt to patent the web dies in court. The BitKeeper
license changes. Caldera becomes the SCO Group.
- September 12, 2002: Some patches get dropped after Linus starts running his mail through a spam filter.
It's hard to believe that, only 5+ years ago, somebody with an email address as well distributed as Linus's could get by without spam filtering. There are a lot of free "productivity" applications, but, arguably, few have actually increased productivity to the extent that SpamAssassin has.
- September 26, 2002: The first development release of the "Phoenix" browser is announced. UnitedLinux upsets the community by releasing a closed beta.
Phoenix was the Mozilla Foundation's answer to (relatively) lightweight browsers like Galeon, which had managed to turn the Gecko engine into something which was truly usable. The Phoenix browser proved popular, and eventually became the tool now known as Firefox.
- October 3, 2002: The first subscriber-only weekly edition. Eldred v. Ashcroft is argued in the U.S. Supreme Court.
Eldred v. Ashcroft, argued by Lawrence Lessig, was an attempt to roll back copyright extension in the US; it eventually was unsuccessful. To this day, there still has not really been a successful challenge to the extensions to copyright passed over the last few decades - though some especially nasty attempts to make things even worse were defeated.
With the October 3, 2002 edition, LWN adopted the new policy of requiring subscriptions in order to read our original content prior to the publication of the weekly edition. That policy has stayed essentially unchanged since then, despite the occasional temptation to increase the subscriber-only period. Subscription rates have also stayed unchanged, even though raising them is also tempting.
Subscriptions have certainly been successful, in that they have kept the operation going in the years since then. And there is a real joy associated with being truly answerable to our readers instead of advertisers. Nonetheless, it is a challenging business; people do not like to pay to read web-based content. The fact that so many of our readers are willing to do so is most gratifying. Trends in other parts of the net are moving away from this approach, though, with formerly subscription sites moving to pure advertising models. So it will be interesting to see how it all plays out in the future.
Meanwhile, next week's installment will look at how things went for Linux (and LWN) starting toward the end of 2002. Stay tuned.
LCA: Bruce Schneier on the two sides of security
The conference portion of linux.conf.au opened on Wednesday morning with a keynote by Bruce Schneier. LCA is a sold-out event; in fact, there are rather more attendees than can be fit into the hall where the keynotes are held. Thus the room was packed, with the second-class citizens - those with yellow badges who put off registration until late - watching a remote feed in a separate room. Those folks may have had a more distant experience, but it was almost certainly a cooler one too.Bruce's key point is that we need to rethink how we try to achieve security, though it took a while to explain just why that is. Security, he says, has two components:
- The feeling of security: that which helps us to sleep well
at night.
- The reality of security: whether we are, in fact, secure.
These two aspects of the problem are entirely separate from each other, but they both have to be addressed if our security goals are to be achieved.
Security is always a set of tradeoffs which we are all making every day. As an example, consider that, in all likelihood, nobody in the audience was wearing a bulletproof vest. It's not that the vests do not work; instead, nobody feels that the cost of wearing a bulletproof vest is justified given the risk. On a bigger scale, the answer to the question of how to prevent more 9/11-like attacks is clear: ban all aircraft. In fact, that was done in the US for a few days after those attacks, but, in the longer term, that is not a tradeoff that people are willing to make.
So the fundamental question for any security tradeoff is: is it worth it? As it happens, we are quite bad at making that decision. We tend to respond to feelings rather than reality. Spectacular risks drive us more than everyday risks. We fear the strange over the familiar and the personified (think Osama bin Laden) over the anonymous. Involuntary risks are seen as being bigger than those entered into voluntarily. In the end, evolution has equipped us quite well for making tradeoffs in the small communities we lived in many, many thousands of years ago. We are less well equipped for the world we live in now.
Since we respond to feelings more than reality, there are strong economic incentives for solutions which address feelings. The result is snake-oil products and security theater. Sometimes people notice that they are being sold bad security (later Bruce mentioned a US survey which indicated that the Transportation Security Agency is now less trusted than the taxation agency), but, all too often, they don't. They have a poor understanding of the risks and the costs involved, and there are plenty of people with strong interests in confusing the issue.
The security market is a lemons market, one where buyers and sellers have asymmetric access to information. Economic research shows that, in such markets, the bad products tend to drive the good ones out of the market. There is no easy way to evaluate the work which has gone into the creation of a truly secure product, so buyers respond to other, less reliable signals. Things like price, sales claims, or the Gartner Group. These signals are sloppy and prone to manipulation. When security is outsourced to outside agencies - governments, say - the problem gets even worse.
In the business world, information eventually brings some order to a lemons market. As businesses learn about what really works, access to information evens out - though there is always a problem with very rare, high-cost events where information is not available. In the individual world, though, it is much harder, because fear plays a much bigger role.
The fact of the matter is that fear is wired deeply into how we work - it is a result of a very old part of our brain. As humans, we have the ability to override our fears when reason indicates that we should, but it is a hard thing to do. The default state is that fear rules. So this is Bruce's core point: the feelings matter. All that security theater out there is not entirely stupid; any security solution must address the fears that people feel. We must address both aspects of security.
The problem is where the feeling of security and the reality of security diverge from each other. If only feelings are addressed, security has not really been achieved. If only the reality of security is addressed, people feel insecure and may make bad decisions. Either way, the full problem has not been solved. Addressing this all-too-common problem is hard, though; Bruce knows of no better way than the spreading of good information.
Your editor's perspective follows - nothing from this point on was said during the talk. It seems that he has a point here. Consider some common situations in the free software world:
- A large number of security updates from a distributor may be an
indication that the reality of security is being achieved: problems
are being found and fixed before they are exploited. But all those
updates can undermine the feeling of security. The seemingly endless
stream of Wireshark updates is a case in point; most of these problems
are found through proactive auditing by the developers and have never
been exploited by the Bad Guys. But the feeling of insecurity
associated with Wireshark can be strong. This feeling can push users
toward other software which, while not having that long history of
security updates, is actually less secure.
- A system running SELinux may, in fact, be highly secure. But many administrators still turn it off. SELinux does not make them feel secure because they do not understand it, and they fear (rightly or wrongly) that it will interfere with the proper operation of the system. But, by turning it off, they undoubtedly expose themselves to a number of attacks which SELinux would block.
We should hear Bruce's point and think a bit more about how we can ensure that free software creates the feeling of security - but a feeling which is backed up by real security. It's a hard problem, one which lacks technical solutions. But we'll find ourselves less secure than we would otherwise be if we do not address that side of the issue.
A ten-year retrospective from LWN's other co-founder
Hello to all LWN readers! For the tenth anniversary of LWN, I've been dragged out of my closet to say a few words. Am I stunned that LWN is still going after 10 years? Not really. Much more stunning to me is the realization that the number of years LWN has been published without me are now almost double the number of years it was published with me. That is much harder to get over. As a result, all new readers from 2002 on have no reason to know who I am or what I've written in the past. For those of you that remember me and have asked about me, thank you and rest assured that I haven't forgotten you either.My name is Elizabeth Coolbaugh (Liz) and I was there for the very first issue as well as many issues that followed in 1998 through 2001. I've always said it was the very best job I ever had. I wish for all of you, if you haven't experienced it yet, a job where your first weeks of work are greeted with happy, enthusiastic letters. As the years went by, letters of praise, though much sparser, never totally ceased. You couldn't have a better incentive to work harder and harder!
Jon has done an excellent job of going over the history of the first few years already, so all I can add is some tidbits or personal viewpoints. I'll mention that for me, the start of LWN was actually back in the early 1980's, when Jon, Becky and I came together as a programming team in the then infamous "Assembly Language Programming" class offered through the Engineering School at CU Boulder. We got a chance to experience lots of late nights, interesting hardware experiences and how to keep going with pizza, chocolate, caffeine, etc. That is a good way to get to know your future business partners. Jon and Becky never let me down and we all found different strengths to add to the mix. Forrest was around, too, though not working with us directly at the time.
Jon mentioned that I was between jobs at the time we began. In fact, I had left NCAR three months pregnant. I loved working at NCAR for many, many years, but I had always said that I would leave it when the work stopped being fun. It actually stopped being fun about two years before that, but I had weathered rough times before and waited to make sure the situation wasn't going to turn-around before choosing to move on. The challenge of a new baby on the way (and the continuing challenge of the Multiple Sclerosis that eventually led to my departure from LWN) finally made it "the right time".
So I'd actually had most of a year off to recuperate, re-organize,
have a baby and test the job market waters. What I wanted was a job
that used my professional skills and yet was part-time, to help me
keep the health I'd regained. What a pipe-dream! Companies that
would have gladly recruited me full-time just tossed my resume into
the nearest recycle bin. The nicer ones told me to go out and find
someone else with identical skills who wanted to job-share a full-time
job and they would be willing to consider the possibility. Not
bloody likely.
So when Jon and I were having lunch and he suggested we might be able to work together to create something giving me what I wanted and allowing him to eventually leave NCAR, it seemed to be the right idea at the right time. I never regretted the decision, but in fact, I had a full-time working spouse to cushion the decision. Brandon's reaction (my husband) to becoming the sole support of the family and a new father in one fell swoop was a little different -- much like a deer full-blinded by headlights.
In the spirit of true confessions, though I had fifteen years experience in the computing field and had worked with many different operating systems, VMS and Solaris being primary, I'd never actually touched a Linux system. Jon's unwavering belief in my ability to pick it all up in a heartbeat was both daunting and encouraging at the same time. So I installed my first Linux system only three or four months before we first started publishing. It did give me a fresh, unbiased view of the whole community, though. Okay, not totally unbiased. I did sit on the emacs side of the whole emacs/vi war.
To get started, I subscribed to say, a hundred different newsgroups and mailing lists full of people I'd never met, topics I'd never heard of and flame wars I didn't care to read. It was truly a new skill to develop to learn to skim through them searching for the topics people cared about, the posts that actually carried real information and gently lift each little kernel of "news" out and place in into the newsletter, then wait to hear how well I'd done.
The response was totally overwhelming. I will never, ever forget the emails we received those first couple of months. New people were finding us each week and so the responses kept coming in. They drove me to try and make my contributions worthy of the praise they sent. It is because of those emails that I'm not surprised LWN is still out there today. People wanted and needed what we had to offer. Jon's vision of what people liked and wanted has always been clear and that is another important piece of why LWN is still going strong.
My take on the Red Hat Support fiasco: I have no hard feelings. Although my work as a systems administrator had always included supporting people and I had enjoyed the interaction, I had no idea what I was getting into offering 24 hour support from my home. Just as my daughter was getting old enough to give me a full-night's sleep, I was getting phone calls at 2am and 3am, having to wake up to a fully alert state and go into emergency fix-it mode. I'm surprised I survived until all the contracts we had sold finally expired. In the long run, Red Hat's ideas gave us the courage to start our own business and since writing for LWN was what I learned to love, I consider the end result to have worked out for the best. I also carefully noted for the future that telephone support work was definite going to be a last resort for any future career moves.
Meanwhile, since the few contracts we had didn't bring in enough to pay the bills, let alone enough to support Jon's full-time entry, I also did contract work as a technical writer, remote or on-site administration of Linux for some local companies and I don't even remember what else. Eventually, Jon had to take the risk, forgo waiting for a reliable income and quit his day job in order to increase the income stream. Note that his early work on LWN was always done in addition to continuing his full-time job and trying to increase our income stream at the same time. No wonder he got grumpy if I was out sick or worse, got to head to a fun Linux conference, leaving him to pick up the slack! Of course, it was terrifying in turn for me when the situation reversed and Jon was unavailable. Picking up the kernel page for the week? Ack! I didn't usually complain. Instead, I kept my head low, worked hard and hoped not to see too many corrections or criticisms come in.
It was wonderful for both Jon and I when we were finally able to add Becky to the mix. I think initially we were only able to scrape up enough to pay her for 10 hours a week, but every hour helped. I haven't forgotten, Becky (okay, it should be Rebecca, but she'll always be Becky to me), the hours you put in at a very low rate of pay. Of course, we did pay you first -- the downside to being the business owners for us.
Over the course of the next couple of years, we continued to bring in our income from other sources. We did actually initiate putting some advertising on our site and it brought in a tiny amount of money, but the bread and butter of the company continued to be contract work done in addition to the weekly publication. That included our most successful side foray, building and teaching Linux classes.
What else did I love about LWN? I so enjoyed the friendships I made throughout so many different communities. Will Rogers once said he never met a man he didn't like. Well, I've met many! But truly, in all the years I worked for LWN, I never met anyone I didn't like. Sometimes people I liked said things or did things that I didn't like, but underneath it, they were all good people, smart, idealistic and very strongly opinionated. That was part of what I liked and enjoyed, so I never held people's opinions against them.
The conferences I attended and at which I spoke were like the icing on the cake. I got to meet in-person people I had only come to know through newsgroups and mailing lists or occasionally personal correspondence. I got to meet even more people and share in the excitement. And yes, I do remember the late nights going out for food, drink and conversation with you -- the Atlanta Showcase, LinuxWorld San Jose, Embedded Systems Conference San Jose, LinuxWorld New York, the Colorado Linux Info Quest and the Singapore Linux Conference. Each one provides me with rich memories. My trip out to Singapore was one high-point. So many good and wonderful people and such a wonderful experience. I thought it was to be the first of many international conferences that I would be attending and I am still so sad that it was my last. I particularly regret never making it out to any of early Linux conferences in India, despite invitations.
Professionally, though, the highlight of the work was actually developing myself as a journalist, rather than a computer expert. I enjoyed researching more in-depth articles. When rumors floated my way, I loved actually going out and contacting the people involved first hand by telephone -- short-circuiting email and the rest, to discuss the issues and get their first-hand viewpoints. Since our community wasn't exactly hounded by the media back then, everybody actually wanted to talk to me and was more than happy to give me the straight scoop, instead of just seeing themselves misquoted elsewhere the next day, with the resultant flames. Best of all, I was occasionally able to get the sources of both sides of a controversy together and talk. I can think of at least twice where problems got resolved as a result, people got together and I got the scoop on a story the next day that had literally changed as a result of my work. Very heady stuff.
Jon has already done an excellent job of covering our experience with the dot-com bubble, so I won't add to his description. It was truly a unique life experience that we enjoyed to the fullest, knowing that another like it was unlikely to come by us again. We were very fortunate in our decisions and I agree that the people at Tucows were extremely good to us.
Well, at this point, all this happened a long time ago. I had a great time and regret nothing I did, only the things I didn't get time to do. For those who have asked after me personally, be assured that health-wise, giving up my job was again the right choice at the right time and I'm doing much, much better than I was in August of 2001. You're still not likely to see me back any time in the near future. I focus my research skills now-a-days on tracking traditional and alternative medical discoveries, implementing what seems good to me and serving as an ad-hoc resource for other family members. Oh yes, and serving as a chauffeur to my daughter, who is now ten years old, just as LWN is. Take care, all of you, remember to be proud of what you are achieving and *always* have fun doing it. I stand by my opinion that when work ceases to be fun, it is time for a change.
Security
Finding bugs lurking in the DOM
The Document Object Model (DOM) for HTML is quite useful for handling a variety of dynamic effects for web pages, but it is complex. It interacts with Javascript and CSS (or they with it) in ways that are sometimes surprising—the DOM has often been the source of browser bugs. A new project, from well-known DOM bug finder Michal Zalewski, seeks to systematically exercise the DOM in browsers to eliminate as many holes as it can.
The project, with the unassuming name of DOM access checker (or dom-checker) was just announced on the full-disclosure mailing list (along with Bugtraq and others). Zalewski and colleague Filipe Almeida, both of Google, describe their tool as follows:
The checker consists of a three HTML files and a Javascript configuration file that can be loaded from the internet via HTTP (a live version is available from the project website) or from the local disk, using the file:// protocol. Ideally, they should be loaded from both places and give the same results. The screenshot for a sample run using Firefox 3 (Fedora/3.0b3pre-0.beta2.12.nightly20080121.fc9 for the curious) is at left.
After pressing the "Click here to begin tests" button, the Javascript test harness runs 15 major tests, each with many separate subtests. Each subtest reports success or failure to the screen as it runs. Firefox 3 failed 15 of the 1500 or so checks in the standard set of tests.
According
to the announcement, "DOM Checker had been used to find a number of
major security bypass and information disclosure problems in several
popular browsers
". Zalewski and Almeida worked with the browser
teams to resolve the most serious issues.
But, common browsers will still fail up to 30 of the
less important tests—for privacy, rather than
security, holes.
The hope is that the browser vendors pick up these tests to use as part of their quality assurance process. They could also be used for regression testing to find problems that have crept in while fixing other bugs or adding new features. The checker is a framework that could easily be extended with additional tests covering other areas of DOM functionality. With the advent of AJAX, DOM manipulations via Javascript are being used more and more by web sites, so tools to discover these kinds of bugs are welcome.
New vulnerabilities
gforge: cross-site scripting
| Package(s): | gforge | CVE #(s): | CVE-2007-0176 | ||||
| Created: | January 28, 2008 | Updated: | January 30, 2008 | ||||
| Description: | From the NVD entry: Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter. | ||||||
| Alerts: |
| ||||||
icu: arbitrary code execution
| Package(s): | icu | CVE #(s): | CVE-2007-4770 CVE-2007-4771 | ||||||||||||||||||||||||||||||||||||||||||||
| Created: | January 25, 2008 | Updated: | May 15, 2008 | ||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Red Hat advisory: Will Drewry reported multiple flaws in the way libicu processed certain malformed regular expressions. If an application linked against ICU, such as OpenOffice.org, processed a carefully crafted regular expression, it may be possible to execute arbitrary code as the user running the application. | ||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||
kernel: several vulnerabilities
| Package(s): | linux-2.6 | CVE #(s): | CVE-2007-2878 CVE-2007-6151 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | January 29, 2008 | Updated: | January 8, 2009 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Debian advisory: Bart Oldeman reported a denial of service (DoS) issue in the VFAT filesystem that allows local users to corrupt a kernel structure resulting in a system crash. This is only an issue for systems which make use of the VFAT compat ioctl interface, such as systems running an 'amd64' flavor kernel. ADLAB discovered a possible memory overrun in the ISDN subsystem that may permit a local user to overwrite kernel memory leading by issuing ioctls with unterminated data. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
mysql: buffer overflows
| Package(s): | mysql-dfsg-5.0 | CVE #(s): | CVE-2008-0226 CVE-2008-0227 | ||||||||||||||||||||
| Created: | January 29, 2008 | Updated: | July 21, 2008 | ||||||||||||||||||||
| Description: | From the Debian advisory: Luigi Auriemma discovered two buffer overflows in YaSSL, an SSL implementation included in the MySQL database package, which could lead to denial of service and possibly the execution of arbitrary code. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
netkit-ftpd: denial of service
| Package(s): | netkit-ftpd | CVE #(s): | CVE-2007-6263 | ||||
| Created: | January 30, 2008 | Updated: | January 30, 2008 | ||||
| Description: | From the Gentoo advisory: A remote attacker can send specially crafted FTP data to a server with passive mode and SSL support, causing the ftpd daemon to crash. | ||||||
| Alerts: |
| ||||||
ngircd: denial of service
| Package(s): | ngircd | CVE #(s): | CVE-2008-0285 | ||||
| Created: | January 28, 2008 | Updated: | January 30, 2008 | ||||
| Description: | From the NVD entry: ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference. | ||||||
| Alerts: |
| ||||||
pulseaudio: ignores setuid() return value
| Package(s): | pulseaudio | CVE #(s): | CVE-2008-0008 | ||||||||||||||||||||||||
| Created: | January 25, 2008 | Updated: | February 14, 2008 | ||||||||||||||||||||||||
| Description: | Pulseaudio ignores setuid() return value. A user can cause the call to fail by exhausting the resources in some cases. | ||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||
tikiwiki: multiple vulnerabilities
| Package(s): | tikiwiki | CVE #(s): | CVE-2007-6528 CVE-2007-6526 CVE-2007-6529 | ||||
| Created: | January 24, 2008 | Updated: | January 30, 2008 | ||||
| Description: | From the Gentoo alert:
Jesus Olmos Gonzalez from isecauditors reported insufficient sanitization of the "movies" parameter in file tiki-listmovies.php (CVE-2007-6528). Mesut Timur from H-Labs discovered that the input passed to the "area_name" parameter in file tiki-special_chars.php is not properly sanitised before being returned to the user (CVE-2007-6526). redflo reported multiple unspecified vulnerabilities in files tiki-edit_css.php, tiki-list_games.php, and tiki-g-admin_shared_source.php (CVE-2007-6529). | ||||||
| Alerts: |
| ||||||
yarssr: arbitrary code execution
| Package(s): | yarssr | CVE #(s): | CVE-2007-5837 | ||||
| Created: | January 28, 2008 | Updated: | January 30, 2008 | ||||
| Description: | From the NVD entry: GUI.pm in yarssr 0.2.2, when Gnome default URL handling is disabled, allows remote attackers to execute arbitrary commands via shell metacharacters in a link element in a feed. | ||||||
| Alerts: |
| ||||||
Page editor: Jake Edge
Kernel development
Brief items
Kernel release status
The current stable 2.6 kernel is 2.6.24, released by Linus on January 24. Highlights of this release include control groups (formerly process containers), the i386/x86_64 architecture merger, group scheduling in the CFS scheduler, network and PID namespaces, kernel markers, the removal of the modular security interface, and much more. See LWN's list of merged patches for more detail, or the always-amazing KernelNewbies Linux Changes page for much more detail.The 2.6.25 merge window is open, but the process of picking up patches is going relatively slowly due to the distractions of linux.conf.au. See the article below for a summary of what has been merged to date.
For older kernels: 2.6.16.60 was released on January 27 with about a dozen fixes.
Kernel development news
Quotes of the week
I'm going to work on getting a unified devel tree operating: one which contains everyone's latest stuff and is updated daily. Basically it'll be -mm without a couple of the quilt trees. People can then prepare patches against that, as it seems that most can't be bothered patching against -mm, let alone building and testing it. More later.
What got into 2.6.25
As of this writing, some 3800 patches have been merged into the mainline git repository since the release of 2.6.24. That is fewer than one might have expected, but Linus's travel to linux.conf.au is slowing the process somewhat. Expect more than the usual amount of interesting stuff to be merged relatively late in the merge window period.User-visible changes include:
- New drivers have been added for Globe Trotter HSDPA wireless cards,
HIFN 795x crypto accelerator chips, Xceive xc2028 and xc5000 tuners,
Cirrus Logic CS5345 analog-to-digital converters, several Beholder TV
tuners, Syntek DC1125 cameras, Silicon Labs Si470x FM radio receivers,
Atmel AT91CAP9 processors, Qualcomm MSM7X00A processors, Marvell Orion
system-on-a-chip devices, Marvell Feroceon processors, SuperH 7203 and
7263 processors, SGI IP28 systems, R6040 Ethernet adapters, Broadcom
NetXtremeII 10Gb network adapters, RTL8180 and 8185-based wireless
network cards, Microchip EN28J60 Ethernet chips, and, finally, Atheros-based
wireless network adapters.
- The Seagate ST-02/Future Domain TMC-8xx and PSI240i SCSI drivers have
been removed due to lack of interest and maintenance.
- Salsa20 stream cipher support has been added to the crypto layer (at
least for the x86 architecture - it's an assembly implementation).
- Some realtime work has gone into the scheduler; in particular, the
kernel will be more aggressive about moving tasks between processors
when multiple realtime tasks are contending for the same CPU. The
implementation of cpusets has been made to work more with the
scheduler domains mechanism. The option to make the big kernel lock
preemptible has been made the default; eventually the non-preemptible
version will go away altogether. High-resolution timers can be used
for preemption, making fair scheduling more accurate. The group
scheduling feature has been enhanced with realtime support.
- The Preemptible
read-copy-update patches have been merged.
- Support for the LatencyTop
utility has been merged.
- Kprobes support for the ARM architecture has been added.
- The new CLONE_IO flag to clone() causes I/O contexts
(used in the CFQ block I/O scheduler) to be shared with the new child
process.
- The idle class for I/O scheduling has been changed to not be 100%
idle when the device is busy; as a result, it is far less likely to
cause priority inversion problems and is no longer limited to
privileged processes.
- A long list of new ext4
features, including large file support, (very) large filesystem
support, journal checksumming, multi-block allocation, and more, has
been added in.
- The splice() system call now supports TCP receive streams.
- Controller area network
protocol support has been merged.
- The network traffic shaper, long obsolete and scheduled for removal,
is gone.
- Quite a bit of work has been done on the network namespace code which was first merged in 2.6.24. Extending namespace awareness through the entire networking subsystem is a big job which is, at this point, mostly complete.
Changes visible to kernel developers include:
- Chinese translations of a number of core kernel development
documents have been added to the tree.
- There have been a great many changes to the low-level device model
APIs dealing with kobjects and ksets. These changes have, in turn,
forced a large number of adjustments throughout the tree. See
Documentation/kobject.txt for an
overview of the new API.
- There is a new set of security module functions for dealing with
filesystem mount and unmount operations.
- The chained scatterlist API has been augmented with the sg_table patches.
- There have been some changes to the block request completion API. See this article for a description of the new way of doing things.
As of this writing, the merging process has just begun, so expect a long list again next week. Among other things, the x86 tree update, with 908 changesets, is waiting on the wings. There is quite a bit of code yet to be merged for this development cycle.
Avoiding the OOM killer with mem_notify
Having applications that use up all the available memory can be a fairly painful experience. For Linux systems, it generally means a visit from the out-of-memory (OOM) killer, which will try to find processes to kill. As one would guess, coming up with rules governing which process to kill is challenging—someone, somewhere, will always be unhappy with a choice the OOM killer makes. Avoiding it altogether is the goal of the mem_notify patch.
When memory gets tight, it is quite possible that applications have memory allocated—often caches for better performance—that they could free. After all, it is generally better to lose some performance than to face the consequences of being chosen by the OOM killer. But, currently, there is no way for a process to know that the kernel is feeling memory pressure. The patch provides a way for interested programs to monitor the /dev/mem_notify file to be notified if memory starts to run low.
/dev/mem_notify is a character device that signals memory pressure by becoming readable. Interested programs can open the file and then use poll() or select() to monitor the file descriptor. Alternatively, signal-driven I/O can be enabled via the FASYNC flag and the system will deliver a SIGIO signal to the process when the device becomes readable. If it becomes readable, the process should free any memory that it can afford to give up. If enough memory is freed this way, the kernel will have no need to call in the OOM killer.
The crux of the patch is how to decide that memory pressure is occurring. mem_notify modifies shrink_active_list() to look for movement of an anonymous page to the inactive list, which is an indication that some will likely be swapped out soon. When that occurs, memory_pressure_notify() (with the pressure flag set to 1) will be called for that zone. When the number of free pages for the zone increase above a threshold—based on pages_high and lowmem_reserve for the zone—memory_pressure_notify() is called again, but with the pressure flag set to 0, effectively ending the memory pressure event for that zone.
If there are numerous processes waiting for a memory pressure notification, it could be counterproductive to wake them all at once—the "thundering herd" problem. To combat this, the patch set adds the ability to wake fewer processes than are waiting on the poll event, by adding the poll_wait_exclusive() function. poll_wait_exclusive() will in turn call add_wait_queue_exclusive() so that a member of the wake_up() family can be used that will limit the number of processes woken up. Previously, only poll_wait() was available, it uses add_wait_queue(), which does not provide this ability. Also, to reduce the frequency of processes waking up to reclaim memory, memory_pressure_notify() will only do that once every five seconds.
The /proc/zoneinfo output has been changed to include the mem_notify status. This can be used by a human for diagnostic purposes or by a program to check the current status of zones for memory pressure.
The embedded community has a lot of interest in seeing this feature get added to the kernel. Devices like phones and PDAs are often running close to their memory limits and the OOM killer is currently unavoidable when the user opens yet another application. With this patch in place, programs that use a lot of memory, but could get by with less, can be changed to free up their caches and the like when memory gets tight. As memory hungry programs get changed, other users will benefit as well.
The patch, submitted by Kosaki Motohiro, has been through several iterations on linux-kernel. The work was originally started by Marcelo Tosatti, with the fifth version recently posted by Kosaki. Previous versions have been well received and with relatively few comments on this iteration, it would seem to be getting close to being merged.
A new block request completion API
The 2.6 block layer has traditionally provided a pair of functions by which a driver could indicate that an I/O request had been completed. A call to end_that_request_first() signaled the transfer of a certain amount of data and would return a value indicating whether the request as a whole was complete. Once all sectors in a request had been transferred, it was up to the driver to pass the request to end_that_request_last() for final cleanup. There was also a function called simply end_request() which might or might not end the entire request, depending on how much data had been transferred. This API has worked for a long time, but it has occasionally proved confusing for driver developers. It was also hard for drivers to communicate useful error information with this interface. So, as of 2.6.25, there will be a new way for drivers to indicate request completion.After a block driver has transferred one or more sectors (or failed in the attempt), it should now make a call to:
int blk_end_request(struct request *rq, int error, int nr_bytes);
Where rq is the I/O request, error is zero or a negative error code, and nr_bytes is the number of bytes successfully transferred. If blk_end_request() returns zero, the request is fully processed and the driver can forget about it. Otherwise there are still sectors to be transferred and the driver should continue with the same request.
blk_end_request() must acquire the queue lock to do its job. If the driver already holds that lock, it should call __blk_end_request() instead.
Block drivers traditionally did a number of housekeeping tasks between calls to end_that_request_first() and end_that_request_last(). These include calling add_disk_randomness() to contribute to the entropy pool, returning any tags used with the request, and removing the request from the queue. All of that stuff is now done within blk_end_request(), so drivers can forget about it. The occasional driver had to carry out other tasks between the completion of the request and its removal from the queue. For drivers with this kind of special need, there is a separate function to call:
int blk_end_request_callback(struct request *rq,
int error,
int nr_bytes,
int (drv_callback)(struct request *));
In this version, drv_callback() will be called (without the queue lock held) between the completion of the request and its final cleanup. If the callback returns a non-zero value, that final cleanup will not be done. This function will always acquire the queue lock - there is no version for drivers which have already taken that lock. In general, though, the use of the callback functionality is likely to be a sign that the driver is being tricker than it really needs to be.
This change was accompanied by a fair number of patches converting all in-tree drivers to the new interface. The old completion functions have been removed, so out-of-tree drivers will need updating before they will work with 2.6.25.
Patches and updates
Kernel trees
Architecture-specific
Core kernel code
Development tools
Device drivers
Filesystems and block I/O
Janitorial
Memory management
Security-related
Virtualization and containers
Benchmarks and bugs
Page editor: Jake Edge
Distributions
News and Editorials
LCA: The state of Debian
The Debian miniconf is one of the oldest of linux.conf.au traditions. This year, Martin Krafft was the person who - with short notice - got to lead off this gathering with the "state of Debian" talk. Debian, as always, is an active project, and it seems that much is going well.
The Debian security team has grown over the last year. Martin noted that
Debian, for all practical purposes, had no security support for a period
after the Etch Sarge release. Those days are over, though, and Debian's security
support is, once again, solid. There is now good security support for the
testing distribution as well; in fact, testing updates often come out
before those for the stable distribution. That result comes from the fact
that testing updates do not need to support all architectures and there are
fewer embargo issues.
The upcoming Lenny release, it was noted, will have implemented most of the
features called for in the security-hardening specification.
The state of translations is good; Debian supports 58 languages now, and may support 77 by the Lenny release. The Smith Review Project has been working through the package base, ensuring that package descriptions are, well, descriptive, in proper English, and easily translatable.
On the ports side, the Sparc32 port has been officially retired; to the dismay of relatively few users. The Lenny release will include a new port: Debian GNU/kFreeBSD, which is based on the FreeBSD kernel. Martin thought this port would appeal to those Debian users who have been complaining about the increasing "multimedia orientation" of the Linux-based distribution.
Much work is going into making the package repository more searchable. The debtags project, which is putting a set of standardized tags onto packages, is relatively advanced. This effort will address a number of longstanding problems, like the fact that a search for "image editor" does not turn up GIMP, which is an "image manipulation program." Debtags will also make it possible to search for packages which are related to other packages. There is also the apt-xapian-index project, which is working toward indexing all package metadata and providing a fast search capability.
Other bits of current status:
- The debian-med
project - building a version of Debian aimed at the
medical industry - is headed toward a 1.0 release.
- The Debian mirror network is growing. There are six new primary
mirrors, and around 100 new secondary mirrors.
- Lenny will use UTF-8 nearly exclusively. Developers are working on
fixing the remaining packages which do not yet support UTF-8.
- The venerable dselect is almost retired. There are still
dselect users out there; Martin suggests that all of those
folks move to aptitude.
- There are a lot of new games coming into the distribution.
- The Etch-and-a-half release will be happening soon. This is a version of Etch which offers a 2.6.24 kernel - needed to make Etch work on newer hardware. The original 2.6.18 kernel will remain an option for Etch users.
Looking forward to 2008, Martin noted that the Lenny release is currently planned for December. Lots of emphasis on "planned" - given Debian's history in this regard, few people actually expect the release to happen on time. Martin did say that things have been getting better in this regard, with Etch being "only" four months behind schedule. A Lenny release which is only a couple months late seems feasible.
Something which is just coming into play is the new "Debian maintainer" status. Unlike full developers, maintainers cannot vote, have no access to the debian-private list, and do not have much access to the wider Debian infrastructure. About all they really can do is upload a specific set of packages. So the "maintainer" designation is good for those who want to maintain a small set of packages, but who are not looking to be an active participant in Debian as a whole, and who do not want to run the "new maintainer" gauntlet.
Martin was asked whether there was any thought of downgrading any existing developers to maintainers. He said that there was some interest in doing that. There are currently just over 1000 developers, all of whom have full access to the repository. Some 400 of those are inactive, but they still possess a key which lets them make changes to the system; this is a clear security issue. The MIA project is looking to identify these people and, eventually, move them to inactive status. On the issue of whether the project would be forcibly downgrading active developers who, for whatever reason, are not entirely welcome in the community, Martin says that will not be happening. There is just no way to do it without bringing massive disruption and flame wars, and nobody wants that.
There was also a question on the role of the debian-private list. The biggest use of debian-private, according to Martin, is vacation announcements; developers need to let the project know that they will not be around, but they do not wish to announce their absence to the wider world. There are some other discussions there too, of course. Current policy says that debian-private discussions will be disclosed after three years in the absence of a request to the contrary. There's an effort afoot to disclose older traffic from before the adoption of that policy, but that requires the assent of all of the participants.
The debian-women project, unfortunately, is currently stalled; the main participants have not had the time to push things forward. The #debian-women channel remains active, though, and is generally a nice and supportive place to be. There are currently about twelve active female contributors to Debian. Martin thinks that women are becoming more present in general, though, and he stated that "the Debian cowboy days are done."
On the packaging front: the packages.qa.debian.org site has been redone in "beautiful CSS." There are now RSS feeds for those who want to follow the status of specific packages. A new "LowThresholdNMU" flag has been added; this is essentially a statement on the part of the maintainer that he will not get offended if others upload fixes to the package. Packages can now use bzip2 compression. There has also been a major rework of the shared library infrastructure, which now looks at actual symbol use when determining shared library dependencies. This change should make it possible to install individual packages from testing into a stable system without having to update all of the libraries that package uses.
There is a growing trend toward team maintenance, especially for the larger package sets. This approach increases the robustness of the system and minimizes problems with MIA maintainers.
Version control systems are working their way into the Debian infrastructure. Packages can now have a set of Vcs-* headers which point to the upstream source repository; these can be used, for example, with the debcheckout command to clone the source repository without having to know anything about the source management system used. Version control systems also offer a solution to the current problem of "hackish packaging tools" being used by many developers. In the future, source packages might just include a shallow repository which can be fed straight to git (or some other system). This project is stalled at the moment, but Martin thinks it will go somewhere; it would be nice if the distributors could come up with a common scheme that they can all use.
The final topic in this session was a question from the audience on whether Debian might ever go to a shorter release cycle. The projected 18 months for Lenny seems like a step in that direction, but 18 months is still quite a bit longer than the cycles used by many other free distributions. Martin thinks that going shorter is unlikely. The fact of the matter is that distribution upgrades are a hassle, requiring a fair amount of administrative attention. Ubuntu may have made some progress with its use of upgrade scripts, but the basic problem remains. On top of that, shorter release cycles would necessarily lead to a shortening of the time for which security updates are available for any specific release. And that, in turn, would force users into more frequent updates whether they want to do that or not. So one should not expect six-month release cycles from Debian anytime soon.
New Releases
Mandriva Linux 2008 Spring Beta 1 "Ophrys" released
The first beta of Mandriva Linux 2008.1 has been released. "The third pre-release of Mandriva Linux 2008 Spring is here. This pre-release brings available KDE 4.0.0 final (in the repositories, not on the discs), a new XML-based package metainformation system, out-of-the-box support for multimedia keys on many common keyboards, new NVIDIA and ATI drivers, kernel 2.6.24 RC8 (with ALSA 1.0.16 RC1), and more."
Fedora Unity releases updated Fedora 7 Re-Spins
The Fedora Unity Project has announced the release of new ISO Re-Spins (DVD and CD Sets) of Fedora 7. These Re-Spin ISOs are based on Fedora 7 and all updates released as of January 18th, 2008. The ISO images are available for i386, x86_64 and PPC architectures via jigdo. CD Image sets have been made available for those in the Fedora community that do not have DVD drives or burners available.
Distribution News
Debian GNU/Linux
preparing sid/lenny to build with GCC-4.3
Matthias Klose reports that GCC-4.3 will be the default compiler for the Lenny release. "Other distributions (Fedora and Novell) are currently preparing their next releases based on the GCC-4.3 compilers, and are heavily involved in upstream development. Test rebuilds for Ubuntu gutsy and hardy were made for amd64, i386, and sparc. On Debian one or more test rebuilds were made for alpha, hppa, i386, ia64, amd64, sparc. In short, 4.3 will become a good release."
Introducing security hardening features for Lenny
Moritz Muehlenhof introduces the security hardening measures that are going into all the packages in Lenny (currently testing).
Fedora
The Red Hat Community Architecture team
Outgoing Fedora leader Max Spevack has sent out a somewhat indirect announcement for the creation of the Red Hat Community Architecture Team, which is intended to help strengthen Red Hat's position within the community. "The Community Architecture team is responsible for all of Red Hat's community efforts, and to achieve its goals by encouraging and developing new leadership within the Fedora community. By its nature, most of this work will take place directly in Fedora, and therefore we 'report' to the Fedora Board, but we will also be responsible for community related activities that are within Red Hat's scope, but outside of Fedora's."
FUDCon video: New face of Fedora
Red Hat Magazine has made a video available for download. The video shows outgoing Fedora Project leader Max Spevack talking with new Fedora Project leader Paul Frields at FUDCon.And the F9 codename winner is...
The codename for Fedora 9 is Sulphur. Click below to see the full election results.Fedora Education Spin
There is a kickstart file available to create Fedora live CD with educational applications. So far, this is an unofficial spin and the package list is still in flux.
Gentoo Linux
Gentoo plans public beta release for 2008.0 release cycle
The Gentoo Project is planning a public beta for the 2008.0 release cycle. "Public beta releases play a major role in the Release Engineering team's revamped plans for 2008.0. Releng lead Chris Gianelloni said he hoped beta releases would increase community participation as well as the quality of the final release. These feature-complete public betas will require the earlier development of release materials, another component of the 2008.0 changes. To ensure sufficient time for beta testing, a mandatory 2-week testing period will follow the beta release." The 2.6.24 kernel is targeted for the 2008.0 release.
SUSE Linux and openSUSE
openSUSE 10.3 PromoDVDs
Promotional DVDs of openSUSE 10.3 are available. "The DVD is made to promote openSUSE, especially on exhibitions and other events, local usergroups, schools, universities and so on." Click below to find out how to get some.
Other distributions
CentOS Projects (Planet CentOS)
Daniël de Kok takes a look at some CentOS subprojects. These include the CentOS Live CD, Project Cranberry (a sysadmin toolkit), Dasha (bringing in more drivers), and Pandora (a package browser for CentOS repositories).CentOS Artwork SIG created
The CentOS team has created the Artwork Special Interest Group (SIG). This SIG will create artwork for each CentOS major release and create and maintain consistent artwork for the official CentOS websites.
New Distributions
EeeDora
EeeDora provides a Fedora 8 spin for the Asus Eee 701 PC. From the project's Google Code page: "This project includes the files necessary to build a custom spin of Fedora (using their excellent tools), put it onto a CD (or USB key) as a Live version to test it out, and then install it as a replacement for the Asus default."
Distribution Newsletters
Fedora Weekly News Issue 117
The most recent issue of Fedora Weekly News is available. Coverage includes the Fedora 9 codename winner (Sulphur for the impatient), a FUDcon survey (both for those who attended and those who didn't), coding project ideas for various Summer of Code style initiatives, Tom "spot" Callaway's new role, and more. Click below for the full issue.Ubuntu Weekly Newsletter #75
The Ubuntu Weekly Newsletter for the weeks January 20th - January 26th, 2008 covers the upcoming Alpha 4 freeze, the release of 6.06.2 LTS, MOTU Council elections, an Ubuntu Demo Day in Swindon, UK, upcoming Hug Day, Full Circle Magazine #9, the Launchpad logo competition, and much more.DistroWatch Weekly, Issue 237
The DistroWatch Weekly for January 28, 2008 is out. "Mobile workers no longer have to carry bulky laptops in order to do their work; with the emergence of free software and live operating systems, a bootable USB Flash drive with Linux is often all that's needed to complete one's task while on the road. In this week's issue we'll take a quick look at Mandriva Flash 2008, a useful "pocket" OS with thousands of applications and several gigabytes of free space for storing your data. In the news section, Gentoo Linux works hard to improve the interaction between the developers and its users, Debian embarks on a major switch to GCC 4.3 as the default compiler, Fedora announces more changes to the project leadership prior to the upcoming release of Fedora 9, and ISP-Planet talks to m0n0wall's Manual Kasper about the importance of small, configurable firewalls. Finally, don't miss the usual bunch of new Linux distributions submitted to DistroWatch, including the promising openmamba GNU/Linux."
Newsletters and articles of interest
Tweaking Hidden Ubuntu Settings With Ubuntu Tweak (HowtoForge)
HowtoForge looks at the Ubuntu Tweak package. "Ubuntu Tweak is a tool that lets you change hidden Ubuntu settings, for example: hide or change the splash screen, show or hide the Computer, Home, Trash, and Network icons, change Metacity, Nautilus, power management, and security settings, etc. Currently Ubuntu Tweak is available only for the Ubuntu GNOME desktop, i.e., it will not work on Kubuntu or Xubuntu. This short guide shows how to install and use Ubuntu Tweak."
Interviews
Interview with RPM Fusion developers
Over at the Fedora wiki, Jonathan Roberts interviews the developers of the RPM Fusion repository. "Hans de Goede: We want to be a one stop place for Fedora add-on packages which cannot be in Fedora proper due to various issues. Currently we are a merger of the dribble, freshrpms and livna repositories, and we invite other repositories to join us."
Page editor: Rebecca Sobol
Development
Gerbv reaches the 2.0 release milestone
Gerbv (Gerber Viewer) is a utility for displaying CAD files that are used in the manufacture of electronic printed circuit boards:
In the 1980s, computer generated Gerber files were used to drive photo-plotter machines made by by the Gerber Systems Corporation. The photo plotters used a mechanically stepped light source and rotating image wheels to optically imprint a image of a circuit board onto a large piece of film. The film was then used to manufacture the printed circuit board. Additionally, PCB manufacturing requires information for defining the size and placement of drill holes (drill files).
The photo plotting machines are now obsolete, but the Gerber standard remains as a standard in the PCB manufacturing business. The output from Gerber file plots can look considerably different than the original CAD drawings, making a visualization tool like Gerbv important.
Gerbv can be used for examining the CAD files generated by such software as CadSoft Eagle, a popular commercial application with a freely downloadable hobby version. Another Linux-compatible printed circuit CAD application is PCB. PCB is less powerful than Eagle, but is open-source software. LWN examined PCB a long time ago.
Version 2.0.0 of Gerbv was recently
announced:
"Gerbv release 2.0.0 represents a a whole new look for gerbv. Most
importantly, the layer control GUI has been made much more powerful through
the outstanding work of Julian Lamb. Julian has also re-worked the GUI's
button and menus to make them more convenient to use. We are certain that
you will find gerbv-2.0.0 even easier to use than before because of Julian's amazing work!
"
The feature list for Gerbv 2.0.0 now includes:
- Display of RS-274x Gerber files.
- The complete implementation of the current Gerber spec.
- Display of Excellon drill files.
- Display of XYRS pick-place files for surface mount technology.
- A completely redesigned GUI.
- Controls for zoom/pan and fit to screen.
- A measure tool for making mouse-controlled distance calculations.
- User selected display of the various layers.
- Support for transparency so that multiple layers can be viewed.
- Report windows showing Gerber and drill code stats and errors.
- A built-in print button.
- Use of the Cairo graphics library, enabling export of PDF, PS, SVG, and PNG files.
- Incorporation of a new unit test suite in the code.
- Improved file-type autodetection.
- Expanded configuration options for the build system.
Installation of Gerbv 2.0.0 was straightforward. The source code was downloaded, uncompressed and untared. The standard Unix configure/make/make install steps were performed on a Ubuntu Feisty Fawn system, no problems were encountered.
Gerbv 2.0.0 was tested on some Eagle CAD files that your author had worked on in the past. Startup was easy, running the command gerbv slc1.* had the desired effect of pulling in all of the various layers for the test project. Moving and zooming around the layers showed the CAD graphics in detail, as expected. The analyze tools produced a lot of useful status information for the various files.
Details in the copper layers that did not show up in Eagle (version 4.16) were easily seen with Gerbv. In the past, your author has encountered problems with Eagle incorrectly displaying the placement and scaling of text on the silk screen layer. This showed up when CAD files were taken to a board manufacturer. Gerbv displayed the text as it appears on the manufacturer's system, which is the desired behavior.
The export functions were experimented with. Export to a png file worked as expected. Export to a PostScript file caused Gerbv to hang up. Export to a PDF file took a very long time to complete, and gpdf took a long time to load the file. When gpdf finished rendering, it only displayed large polygons that were barely visible due to their almost identical colors. Export to svg produced a file that caused the mirage image viewer to hang when reading. An attempt to convert the svg file to a jpg file with convert resulted in this error:
convert: unable to open image `pattern0': No such file or directory. convert: Non-conforming drawing primitive definition `fill'.Clearly, this is still a .0.0 release with some bugs. Despite these problems, Gerbv 2.0.0 is a tool that is useful, if not critical, for performing Linux-based printed circuit board design.
System Applications
Clusters and Grids
Release of rsplib 2.4.0beta1
Version 2.4.0 beta 1 of rsplib has been announced. "rsplib is the Open Source implementation (GPLv3) of the IETF's upcoming standard for Reliable Server Pooling (RSerPool). It provides protocols and functionalities for the management of server pools and sessions between users and pools. In particular, RSerPool takes care for server selection and session failover support among servers of a pool."
Database Software
Firebird 2.1 RC 1 is available
Release Candidate 1 of Firebird Version 2.1 has been announced. "This is the first release candidate of the Firebird version 2.1 series. Its purpose is for FIELD TESTING. Deployment into production systems is not recommended. Cumulative release notes covering both V.2.0.3 and this build of V.2.1 are available both in the build kits and online. Installation notes (updated for Windows) and cumulative bug-fixes for both versions are released in separate documents this time."
MySQL 5.0.51a has been released
Version 5.0.51a of the MySQL DBMS has been announced. "MySQL 5.0.51a is a security hotfix release. We recommend all users of any previous release in the MySQL 5.0 Community Server branch to upgrade to 5.0.51a as soon as possible. Please see below for details."
Postgres Weekly News
The January 27, 2008 edition of the Postgres Weekly News is online with the latest PostgreSQL DBMS articles and resources.
Security
Havp: 0.87 released (SourceForge)
Version 0.87 of Havp has been announced. "HAVP (HTTP Anti-Virus Proxy) is a proxy with a clamav antivirus scanner. The main aims are continuous, non-blocking downloads and smooth scanning of dynamic and password protected homepages. It can be used with squid or standalone."
Metasploit Framework 3.1 released
Version 3.1 of the Metasploit Framework, a development platform for creating security tools and exploits, is available. "The Metasploit Project announced today the free, world-wide availability of version 3.1 of their exploit development and attack framework. The latest version features a graphical user interface, full support for the Windows platform, and over 450 modules, including 265 remote exploits."
Telecom
Activa for Asterisk: New release 1.4.4 (SourceForge)
Version 1.4.4 of Activa for Asterisk has been announced. "Activa brings the Asterisk IP PBX to the call center. Built on top of Asterisk, Activa components enable successful call center implementations adding value in areas such as computer telephony, screenpop & click2dial, agent control, automatic dialing... This is a maintenance release".
Miscellaneous
ALE Server 1.1.2 Released (SourceForge)
Version 1.1.2 of ALE Server has been announced. "logicAlloy ALE is RFID-EPC compliant RFID middleware. ALE collects and processes RFID tag data from RFID readers, then pushes RFID data to ERP apps."
Desktop Applications
Audio Applications
aTunes: Jukebox Power Pack announced (SourceForge)
The first release of the Jukebox Power Pack has been announced. "aTunes is a powerful, full-featured, cross-platform player and manager, with audio cd rip front-end. Currently supported formats are mp3, ogg, wav, wma, flac, mp4, ape, mpc, mac, radio streaming and podcasts. The aTunes, Jajuk and Jukes audio player projects are pleased to announce the start of close collaboration on shared ressources. The three projects aim at providing full-featured cross-platform jukeboxes for advanced users. As a first result, the Jukebox Power Pack has been released. It contains the three applications bundled together."
Desktop Environments
GNOME Software Announcements
The following new GNOME software has been announced this week:- Accerciser 1.1.90 (new features and translation work)
- Agave 0.4.5 (bug fixes)
- Anjuta DevStudio 2.3.3 (bug fixes and translation work)
- Brasero 0.7.1 (bug fixes)
- cairo 1.5.8 (API changes, bug fixes and documentation work)
- cheese 2.21.90 (new features, bug fixes and translation work)
- cheese 2.21.90.1 (new features and bug fixes)
- Deskbar-Applet 2.21.90 (new features, bug fixes and documentation work)
- Deskbar-Applet 2.21.90.1 (bug fix and translation work)
- Evince 2.21.90 (new features, bug fixes and translation work)
- Evolution 2.21.90 and related (new features, bug fixes and translation work)
- gcalctool 5.21.90 (bug fixes and translation work)
- GConf 2.21.90 (bug fixes)
- gdl 0.7.8 (bug fixes and translation work)
- gedit 2.21.1 (new features)
- GLib 2.15.4 (new features, bug fixes and translation work)
- gnome-build 0.2.1 (bug fixes and translation work)
- gnome-control-center 2.21.90 (new features, bug fixes and translation work)
- gnome-keyring 2.21.90 (bug fixes and translation work)
- Gnome-schedule 2.0.0 (new features)
- gnome-settings-daemon 2.21.90.1 (library change)
- Gnumeric 1.8 (stable release, new features)
- GTK+ 2.12.6 (bug fixes and translation work)
- Hotwire 0.700 (new features and bug fixes)
- libbonobo 2.20.4 and libbonoboui 2.21.90 (new features and bug fixes)
- libgnome 2.21.90 and libgnomeui 2.21.90 (new features, bug fixes and translation work)
- libgnomecups 0.2.3 (bug fixes and translation work)
- libgnomeprint 2.18.3 and libgnomeprintui 2.18.2 (bug fixes and code cleanup)
- mousetweaks 2.21.90 (new features, bug fixes, documentation and translation work)
- Orca 2.21.90 (bug fixes and translation work)
- seahorse 2.21.90 (bug fixes and translation work)
- Swfdec 0.5.90 (new features and API changes)
- swfdec-gnome 2.21.90 (new features and bug fixes)
- Tomboy 0.9.5 (bug fixes and translation work)
- Yelp 2.21.90 (new features, bug fixes and translation work)
KDE Software Announcements
The following new KDE software has been announced this week:- KAlarm 1.5.0 / 1.9.10 beta (new features and bug fixes)
- kAnyRemote 4.4 (bug fix)
- kmk 0.23.15.4 (bug fix)
- KNfoViewer 0.3.3 (new features)
- Kwave 0.7.11 (new features and bug fixes)
- Manslide 1.9.9 (bug fixes and translation work)
- PeaZip 1.11 (new features and bug fixes)
- Quimup 0.3.2 (new features and bug fixes)
- Zhu3D 3.4.2 (new features and bug fixes)
Xorg Software Announcements
The following new Xorg software has been announced this week:- xf86-video-amd 2.7.7.6 (bug fixes and code improvements)
- xf86-video-mga 1.4.8 (bug fixes)
- xf86-video-nv 2.1.7 and 2.0.3 (new features and bug fixes)
Educational Software
iTALC: 1.0.5 released (SourceForge)
Version 1.0.5 of iTALC has been announced. "iTALC aims to be an alternative to commercial software for working with computers in school. Features: monitoring student's activities, help students (remote control), show demo, locking student's screens and much more.."
Interoperability
Wine-doors 0.1.2 released (GnomeDesktop)
Version 0.1.2 of Wine-doors, a Windows application management utility for GNOME, has been announced. "Wine-doors 0.1.2 has been released, this release sees vastly improved exception handling thanks to Andrew Stormont who joined the project after 0.1.1, along with some new features tweaks and various other fixes. Were also syncing the repos from SVN nightly, this means that we can release apps faster between now and the finalisation of the new application database which is currently being worked on by Sam Taylor."
Mail Clients
The beginning of Thunderbird 3 planning
Thunderbird users may be interested in this message from David Ascher, who is heading up the newly spun-off "MailCo" company. He wants to get a public "milestone" build of Thunderbird 3 in 2008, with calendaring support, better search, better extensions, and more. "Thunderbird's impact is proportional to its user count. Thus driving adoption is my primary concern. Our current user base is very significant (many millions of mostly quite satisfied users), but the number of possible users of Thunderbird is orders of magnitude greater than our current reach."
Video Applications
Dirac 0.9.1 released
Version 0.9.1 of the Dirac video codec has been announced. "This is a minor release complying with Dirac Bytestream Specification 2.1.0."
On the road to a Dirac standard (Son of Id)
Thomas Davies reports that the Dirac video codec is on its way to becoming an international standard. "First, Dirac (or part of it) is going to be an international standard. Yay! We made a cut-down version doing intra coding only and this has only just been submitted to the SMPTE. If it goes through it will become VC-2 (Windows Media 9 became VC-1 when they standardised it). After a lot of hard work fighting SMPTE's preferred Word format (yuk) it went in just before Christmas and is being voted on as a Committee Draft as I write this." (Thanks to erwbgy)
Announcing Miro 1.1: dramatically faster BitTorrent
Version 1.1 of Miro, a video download/watcher application, has been announced. "First, we have dramatically improved performance for torrent downloading and we offer more settings and control (thanks to libtorrent). With this update, Miro is truly a powerhouse for torrent feeds, if I do say so myself. Torrents are still a difficult and mysterious technology for many users, despite the huge bandwidth savings they provide to publishers. We aim to make your torrent experience seamless at worst and invisible at best." The other major change involves getting results from all five search engines at once.
Web Browsers
Mozilla Links Newsletter
The January 17, 2008 edition of the Mozilla Links Newsletter is online, take a look for the latest news about the Mozilla browser and related projects.Mozilla Links Newsletter
The January 27, 2008 edition of the Mozilla Links Newsletter is online, take a look for the latest news about the Mozilla browser and related projects.
Languages and Tools
C
GCC 4.3.0 Status Report
The January 28, 2008 edition of the GCC 4.3.0 Status Report has been published. "We are in Stage 3 and the trunk is open for regression and documentation fixes only. When we reach zero open P1 regressions, we will create a release candidate for 4.3.0, branch and announce the opening of Stage 1 for 4.4."
Caml
Caml Weekly News
The January 29, 2008 edition of the Caml Weekly News is out with new articles about the Caml language.
Lisp
SBCL 1.0.14 has been released
Version 1.0.14 of SBCL has been announced. "Steel Bank Common Lisp 1.0.14 has been released on 28 January 2007. This version revives OpenBSD support, adds a process exit hook, and fixes many bugs."
Perl
This Week on perl5-porters (use Perl)
The January 13-19, 2008 edition of This Week on perl5-porters is out with the latest Perl 5 news.Perl 6 Design Meeting Minutes (use Perl)
The minutes from the January 23, 2008 Perl 6 Design Meeting have been published. "The Perl 6 design team met by phone on 23 January 2008. Larry, Allison, Patrick, Jerry, Will, Jesse, Nicholas, and chromatic attended."
Python
Python-URL! - weekly Python news and links
The January 28, 2008 edition of the Python-URL! is online with a new collection of Python article links.
Tcl/Tk
Tcl-URL! - weekly Tcl news and links
The January 24, 2008 edition of the Tcl-URL! is online with new Tcl/Tk articles and resources.
Editors
ZEmacs: Version 5.0 (SourceForge)
Version 5.0 of ZEmacs has been announced. ZEmacs is: "A bundle of lisp extensions, largely original, for GNU Emacs with the goal to obtain a more user friendly and powerful interface. The new features include contextual tool bars, new TeX interface and much more. I am happy to announce the new version 5.0 of ZEmacs. The new release contains a huge number of bugfixes, improvements, and new packages."
Libraries
iText: 2.0.8 released (SourceForge)
Version 2.0.8 of iText has been announced. "This library contains classes that generate documents in the Portable Document Format (PDF) and/or HTML. Whenever people think of PDF and Java, they think of iText. That's great, but it also involves a lot of responsibility: we have to keep on working on the product; fixing bugs, adding new functionality, making it a better product. The first thing that jumps in the eye with this new release, is the reorganization of the source code."
Page editor: Forrest Cook
Linux in the news
Recommended Reading
The Non-Revocable GPL (Groklaw)
Groklaw has the scoop on the revocability of the GPL. Someone out there has been claiming that they are revoking the GPL for code that has already been released. "If you change your mind and don't want to use the GPL any more, you can stop and use something else on new code going forward, and you can dual license your own code, but you can't redo the past and pull back GPL'd code. That's one of the beauties of the GPL, actually, that even if some individual gets a bug up his nose, or dies and his copyright is inherited by his wife who doesn't care about the GPL and wants to take it proprietary, or just to imagine for a moment, a Megacorp were to buy off a GPL programmer and get him to pretend to revoke the GPL with threats, and even if it were to initiate a SCO-like bogo-lawsuit, it doesn't matter ultimately as to what you can and can't do with the GPL."
Companies
Barracuda turns to open source users for patent research (LinuxWorld)
LinuxWorld takes a look at Barracuda Networks, and its patent concerns. "Barracuda Networks CEO Dean Drako says his company won't license a virus scanning patent from Trend Micro, and he's going to users to help build Barracuda's case file of prior art—previous software products and documentation that could help invalidate the patent in court. Barracuda is launching a new section of its web site, "Legal Defense of Free and Open Source Software", to document the patent case and the company's prior art research."
The Complex Crux Of Wireless Warfare (washingtonpost.com)
The Washington Post reports on Boeing's development of a Linux-based combat system. "Future Combat Systems, or FCS, is a roughly $200 billion weapons program that military officials consider the most thorough modernization of the Army since World War II. It all depends on the software, under development by the Army's battalion of contractors, led by Boeing. The software is intended to do what military commanders have until now only dreamed about: give soldiers the power to communicate through a wireless network in near real time with hovering drones; remotely control robots to defuse bombs; fire laser-guided missiles at enemies on the move; and conduct a video teleconference in a tank rumbling about 40 mph in the haze of battle." (Thanks to Philip Webb).
More Linux-based laptops from Dell (vnunet)
Vnunet reports that Dell is extending sales of computers with Ubuntu preloaded. "Customers in the UK, Germany, France and Spain can purchase pre-loaded versions of Ubuntu Linux 7.10 with built-in DVD playback on the Dell XPS 1330n, in addition to the previously-released Inspiron 530n desktop system, according to an official Dell blog."
Linux Adoption
23,000 Linux PCs forge education revolution in Philippines (ComputerWorld)
ComputerWorld reports on Linux PCs for high-school students in the Philippines. "Providing high school students with PCs is seen as a first step to preparing them for a technology-literate future, but in the Philippines many schools cannot afford to provide computing facilities so after a successful deployment of 13,000 Fedora Linux systems from a government grant, plans are underway to roll out another 10,000 based on Ubuntu."
Five reasons not to fear a $200 Linux PC (News.com)
News.com covers the recent availability of $200 Linux PCs. "Linux is not just for computer whizzes. In fact, buying Linux and learning how to use it are easier than ever, thanks to the open-source operating system's expanding presence in affordable computers and mainstream retail outlets. In quick succession, the number of mass-market, sub-$200 desktops has tripled--from one to three--in less than three months. At the Consumer Electronics Show in Las Vegas earlier this month, small form-factor PC maker Shuttle debuted its $199 KPC. The catch? It's not preloaded with Windows, but an operating system based on Linux."
Interviews
Beating Colossus: an interview with Joachim Schueth
The NetBSD Project has an interview with Joachim Schueth. "Joachim Schueth has beaten a reconstruction of the famous Colossus Mark II code breaking machine in November 2007. The Colossus computers were used in World War II to break the German encrypted messages. Equipped with a NetBSD-powered laptop and profound knowledge of cryptography and the Ada programming language, Schueth has won the code-cracking challenge. We talked with him about the historical and technical backgrounds of the Cipher Event and the tools he has used."
Reviews
openSUSE Build Service now supports Red Hat and CentOS (Linux-Watch)
Linux-Watch looks at the openSUSE build service. "The build service enables developers to build programs for different hardware platforms without a "compiler farm" of different hardware. It also provides automatic resolving of dependencies to other packages. If a program depends on another package, say a KDE application on a Trolltech Qt library, the KDE application will be rebuilt automatically if its Qt library is changed and rebuilt. This, in turn, takes much of the donkey work out of building applications for Linux."
Toybox: Light-weight Linux box very useful (Computerworld NZ)
Computerworld NZ reviews the Asus EEE 701 PC. "I really like this little Linux-based machine, and I would find it very useful in my everyday life for checking email, updating Computerworlds website and subediting stories from home, and writing quick stories from out in the field. But, sure, the keyboard is not designed for longer stints of typing. Weighing less than a kilogram, the Eee 701 is so small and light it fits in my small-to-medium-sized handbag, and that is a definitive plus. The machine features a 4GB solid-state drive, 512MB of memory and an Intel mobile processor. Storage can be expanded by using the SD card slot."
Page editor: Forrest Cook
Announcements
Non-Commercial announcements
CentOS Artwork SIG created
CentOS has announced the creation of the Artwork Special Interest Group. "The CentOS team is pleased to make computers more useful through the creation of the Artwork Special Interest Group (SIG). A SIG is a smaller group within the CentOS project that focuses on a small set of issues, in order to either create awareness or to focus development along a specific topic."
OSA announces chapter in Europe
The Open Solutions Alliance (OSA) has announced plans to expand the organization's global footprint. The OSA will function under a chapter structure with its first new regional chapter planned to address the European open solutions market.Terra Soft Sponsors Inaugural International Short Film Festival
Terra Soft has announced their sponsorship of a short film festival. "Terra Soft is proud to sponsor the inaugural A3F International Short Film Festival, an exciting addition to the fourth year of the Almost Famous Film Festival 48 Hour Challenges. In Phoenix, Arizona, February 13-14, 2008, 17 independent films will be screened, including the World Premier of "Sympathetic Details," a film by Benjamin Busch from HBO's critically acclaimed series "The Wire.""
Terra Soft requests funds for Kenyan orphanage
Terra Soft is sponsoring children at a Kenyan orphanage. "Following the controversial Presidential elections in December, Kenya is experiencing violence that has left an estimated quarter million people uprooted or homeless and several hundred dead. This week the Pistis Academy & Orphanage has received 30 new children whose parents have been killed or homes destroyed. While the Red Cross is working to sustain an estimated 2,000 people now given shelter in a ball park in Nakuru center, no additional funding has been offered by the Kenyan government to help support those new children at Pistis."
Commercial announcements
Enea LINX Provides TIPC Alternative/Gains Backward-Forward Compatibility
Enea has announced the release of Enea LINX for Linux 2.0, which includes protocol and feature negotiation to enable seamless upgrades of system subsets with newer versions of the protocol. "This addition to the protocol ensures forward and backward compatibility with all future versions of LINX for Linux."
Concurrent announces NightStar LX Tools for Ubuntu
Concurrent has announced a new generation of the NightStar LX debugging and analysis tools for the Ubuntu distribution. "NightStar is a powerful, integrated GUI tool set for developing and tuning time-critical applications on x86-based platforms. NightStar's advanced debugging features enable system builders to solve difficult problems quickly. The NightStar LX suite includes four tools -- the NightView(tm) source-level debugger, the NightTrace(tm) event analyzer, the NightProbe(tm) data monitor, and the NightTune(tm) system and application tuner."
Nokia to acquire Trolltech
Nokia has announced the signing of an agreement to acquire Trolltech. "The acquisition of Trolltech will help Nokia accelerate its cross-platform software strategy for mobile devices and desktop applications, and develop its Internet services business. With Trolltech, Nokia and third party developers can develop applications that work in the Internet, across Nokia's device portfolio and on computers." More information is available on Trolltech's web site.
openSUSE Build Service expands support to Red Hat and CentOS
Novell, Inc. has announced an expansion of the openSUSE Build Service. "The openSUSE(R) Build Service, an innovative framework that provides an infrastructure for software developers to easily create and compile packages for multiple Linux* distributions, has extended its support to now build packages for CentOS and Red Hat* Enterprise Linux. The openSUSE Build Service already supports several Linux distributions including openSUSE, Ubuntu, SUSE(R) Linux Enterprise, Debian and others."
New Books
The Art and Science of JavaScript -- New from SitePoint
SitePoint has published the book The Art & Science of JavaScript by Michael Mahemoff, Cameron Adams, James Edwards, Dan Webb, Simon Willison, Ara Pehlivanian and Christian Heilmann.The Ruby Programming Language -- New from O'Reilly Media
O'Reilly has published the book The Ruby Programming Language by David Flanagan and Yukihiro Matsumoto.The Book of Wireless -- New from No Starch Press
No Starch Press has published the book The Book of Wireless, 2nd Edition by John Ross.
Resources
TIOBE declares Python as programming language of 2007
The TIOBE Programming Community Index report lists Python as the language of the year for 2007. "Python has been declared as programming language of 2007. It was a close finish, but in the end Python appeared to have the largest increase in ratings in one year time (2.04%). There is no clear reason why Python made this huge jump in 2007. Last month Python surpassed Perl for the first time in history, which is an indication that Python has become the "de facto" glue language at system level. It is especially beloved by system administrators and build managers. Chances are high that Python's star will rise further in 2008, thanks to the upcoming release of Python 3."
Contests and Awards
Sun launches OpenOffice.org Community Innovation Program
Sun Microsystems Inc has announced the launch of the OpenOffice.org Community Innovation Program. "On 7 December 2007, Sun Microsystems Inc. announced a new million- dollar fund to foster innovation in six of the open-source projects it sponsors and contributes to. We are pleased to report that OpenOffice.org was included. The contest, which we have titled the OpenOffice.org Community Innovation Program, commences tomorrow, 30 January, and we invite OpenOffice.org Community members to participate."
Surveys
FUDCon F9 Survey available
A FUDCon F9 survey is open until February 7. "The Fedora marketing team has posted a survey regarding FUDCon F9, held January 11-13, 2008 in Raleigh, NC. All community members are invited to participate, whether you attended or not. We expect to use these surveys in the future for additional FUDCon events, to make sure that the events are delivering as much value as possible to attendees and observers."
Meeting Minutes
GNOME Board meeting minutes
The January 2, 2008 GNOME Board meeting minutes have been published.GNOME Board meeting minutes
The January 16, 2008 GNOME Board meeting minutes have been published.
Calls for Presentations
Libre Software Meeting cfp
A call for contributions has gone out for the 2008 Libre Software Meeting. "The LSM (Libre Software Meeting) are an opportunity for all sort of public to come together around the free software. Over 5 days, conferences and workshops welcome everyone. This event is organized each year and for the 9th edition is hosted in the town of Mont de Marsan, from 1 to 5 July 2008." The submission deadline is February 8.
Open for RailsConf Europe 2008 CFP
A call for participation has gone out for the Open for RailsConf Europe 2008, which will be held in Berlin, Germany. "RailsConf Europe taps into the dynamic energy of the growing Rails ecosystem. Co-produced by Ruby Central, Inc. and O'Reilly Media, Inc., the conference takes place September 2-4, 2008. True to the spirit of this community, RailsConf Europe is dedicated to everything Ruby on Rails. In attendance will be over 800 Ruby on Rails enthusiasts, web developers and programmers, IT managers tracking emerging technologies, open source developers and hackers, Tech-savvy entrepreneurs, users at every level (new, power, intermediate, advanced, expert) and others interested in web technologies and strategic implementation. The Call for Participation is open; speaking proposals must be received by March 18, 2008."
OSDC.tw call for papers
A call for papers has gone out for the Open Source Developers' Conference, Taiwan. "The OSDC.tw 2008 will be on 12th-13th, April. The subject is "Innovation and Implementation" in this year. Please submit your papers with subject, extract and user profile." The submission deadline is February 15.
Upcoming Events
Florida Linux Show in Jacksonville
The Florida Linux Show will be held in Jacksonville, Florida on February 11, 2008. "Reminder: Speakers, Exhibitors & Support still needed... time is getting short! They are looking for more Vendors, EDUs & Organizations that would like to setup a Booth. If you know folks in the area that would be interested in speaking or sponsoring an exhibit, please let us know asap. Perhaps a presentation or two could be recycled from FUDcon? There will be Gentoo & Ubuntu exhibits, it would be nice if someone could help represent Fedora, my favorite Laptop distro."
Linux Audio Conference 2008: Registration now open
Registration has opened for the Linux Audio Conference 2008. "The Linux Audio Conference 2008 in Cologne (Feb 28th - Mar 2nd 2008) is just one month away now. The programme is shaping up, concerts are being organized and coffee is about to be ordered. To help us with planning the LAC2008 we kindly ask you to register now at the conference website."
O'Reilly announces the Money:Tech Conference
O'Reilly has announced the Money:Tech Conference "O'Reilly Money:Tech takes place February 6-7, 2008 at the Waldorf-Astoria in New York, NY. The event brings together some of the most pioneering minds in the financial and computing community to frame the future of investing in challenging times." Read further for some news announcements that are planned for the event.
OOoCon 2008 Call for Location - deadline extended
The call for location deadline for the 2008 OOoCon has been extended to February 10. "In response to a number of requests from organising teams, we have agreed to put back the deadline to midnight UTC February 10th. We will aim to open the community voting process a few days later, and announce the winning bid on March 1st."
SCALE weighs in
The final preparations are being made for the Southern California Linux Expo, which begins on February 8. "The SCALE staff continue to put the final touches on SCALE 6x. There are a few places left in the SCALE U classes on Friday, February 8th. The tutorials are: "Open-Source Email Systems: One Approach to Spam Fighting" and "Introduction to Virtualization on Linux with Xen". Register for the tutorials via the regular SCALE registration process, and a SCALE Full Access pass will be included."
Spring VON Conference - San Jose, CA
Pulvermedia has announced The Twelfth annual Spring VON.x Conference & Expo. The event will take place on March 17-20 in San Jose, CA. "The Industry's largest, longest-running, and most respected Internet communications event now adopts the VON.x brand, which signifies the inclusion of technologies such as IP-voice, IP-video, wireless, presence, instant messaging, social media, and many others that have enhanced and evolved the Internet communications industry."
Events: February 7, 2008 to April 7, 2008
The following event listing is taken from the LWN.net Calendar.
| Date(s) | Event | Location |
|---|---|---|
| February 6 February 10 |
O'Reilly Money:Tech Conference | New York, NY, USA |
| February 7 | Frozen Perl 2009 | Minneapolis, United States |
| February 8 February 10 |
Southern California Linux Expo | Los Angeles, USA |
| February 10 February 13 |
NDSS Symposium 2008 | San Diego, CA, USA |
| February 11 | Florida Linux Show 2008 | Jacksonville, Florida, USA |
| February 11 | Open Source Software (OSS) and the U.S. Department of Defense (DoD) | Alexandria, VA, USA |
| February 13 February 15 |
German Perl-Workshop | Regionales Rechenzentrum Erlangen, Germany |
| February 16 | Frozen Perl 2008 Workshop | Minneapolis, USA |
| February 19 February 20 |
Linux Developer Symposium | Beijing, China |
| February 19 February 20 |
Files and Backup | London, UK |
| February 22 February 24 |
freed.in/2008 | Delhi, India |
| February 23 February 24 |
Free/Open Source Developers' European Meeting 2008 | Brussels, Belgium |
| February 23 February 26 |
Linux World Mexico | Mexico City, Mexico |
| February 25 February 26 |
2008 Linux Storage and Filesystem Workshop | San Jose, CA, USA |
| February 25 February 29 |
NEW PHP 5 and PostgreSQL Bootcamp with Mark Fenoglio | Atlanta, Georgia, USA |
| February 25 February 27 |
German Perl Workshop | Frankfurt, Germany |
| February 28 March 1 |
Linux Audio Conference | Cologne, Germany |
| March 1 March 2 |
Chemnitzer Linux-Tage 2008 | Chemnitz, Germany |
| March 3 March 6 |
O'Reilly Emerging Technology Conference | San Diego, CA, USA |
| March 3 March 6 |
Drupalcon Boston 2008 | Boston, MA, USA |
| March 4 March 9 |
CeBIT Germany | Hannover, Germany |
| March 8 March 14 |
Asia OSS Conference & Showcase 2008 | Guangzhou, China |
| March 11 March 12 |
4th AustralAsian Cleantech Forum | Melbourne, Australia |
| March 14 March 16 |
PyCon 2008 | Chicago, IL, USA |
| March 15 | FSF Associate Members Meeting | Cambridge, MA, USA |
| March 16 March 19 |
BossaConference 2008 - International Conference on Open Source Software for Mobile Embedded Platforms | Pernambuco, Brazil |
| March 16 March 21 |
Novell BrainShare 2008 | Salt Lake City, UT, USA |
| March 16 March 20 |
Free Software and Open Source Foundation for Africa | Dakar, Senegal |
| March 17 March 20 |
Eclipse Community Conference | Santa Clara, CA, USA |
| March 17 March 20 |
Spring VON.x Conference | San Jose, CA, USA |
| March 19 March 20 |
LinuxWorld Expo 2008 Brussels | Brussels, Belgium |
| March 24 | SDForum Global Open Source Conference | San Francisco, CA, USA |
| March 26 March 28 |
CanSecWest 2008 | Vancouver, BC, Canada |
| March 26 | Document Freedom Day | Everywhere, Worldwide |
| March 29 March 30 |
PostgreSQL Conference East 2008 | College Park, MD, USA |
| March 31 April 2 |
UKUUG Spring 2008 Conference - Dynamic Languages | Birmingham, England |
| March 31 | 2008 European Workshop on System Security | Glasgow, Scotland |
| March 31 April 2 |
UKUUG Spring 2008 Conference | Birmingham, England |
| March 31 April 2 |
Sharkfest Wireshark Network Analysis Summit | Los Altos Hills, CA, USA |
| April 2 | First meeting UKUUG PostgreSQL SIG | Birmingham, England |
| April 3 April 4 |
E-Mail Systems Conference 2008 (Exim and other mail systems) | Birmingham, England |
| April 4 April 5 |
openSUSE Packaging Days II | IRC, Everywhere |
If your event does not appear here, please tell us about it.
Audio and Video programs
SCALE on the Radio!
Gareth Greenaway, SCALE Operations Chair, and Orv Beach, SCALE Publicity Chair, will be on the Digital Village radio show. Digital Village is carried on KPFK (90.7 FM in the Los Angeles area), and streaming audio at www.kpfk.org. Tune in if you've got a moment!
Page editor: Forrest Cook

![[DOM Checker]](https://static.lwn.net/images/dom-checker_sm.png)