Re: Security concerns with minified javascript code

2015-08-31 Thread Guido Günther
Hi, On Mon, Aug 31, 2015 at 09:50:05AM +0200, Raphael Hertzog wrote: > On Mon, 31 Aug 2015, Simon Josefsson wrote: > > How would someone rebuild the minified javascript files from the > > missing-sources files? > > They would not? > > The modified non-minified files are perfectly usable even if t

Re: system upgrade by systemd

2015-08-31 Thread Dimitri John Ledkov
On 1 September 2015 at 03:43, Marco d'Itri wrote: > On Aug 31, Dimitri John Ledkov wrote: > >> Ideally the update generators, targets and units should be split into >> a separate package and not installed by default. Since those are >> really unexpected on Debian. > No, because the system update

Re: system upgrade by systemd

2015-08-31 Thread Marco d'Itri
On Aug 31, Dimitri John Ledkov wrote: > Ideally the update generators, targets and units should be split into > a separate package and not installed by default. Since those are > really unexpected on Debian. No, because the system update infrastructure stays idle until some other package tells i

Bug#797627: ITP: fonts-hack -- Typeface designed for source code

2015-08-31 Thread Paride Legovini
Package: wnpp Severity: wishlist Owner: Paride Legovini * Package name: fonts-hack Version : 2.010 Upstream Author : Christopher Simpkins * URL : https://github.com/chrissimpkins/Hack * License : Modified SIL Open Font License, Version 1.1 Programming Lang:

Bug#796464: marked as done (general: there is no auto crash reporting)

2015-08-31 Thread Debian Bug Tracking System
Your message dated Mon, 31 Aug 2015 22:20:58 +0100 with message-id <20150831212058.ga9...@lupin.home.powdarrmonkey.net> and subject line Re: Bug#796464: general: there is no auto crash reporting has caused the Debian Bug report #796464, regarding general: there is no auto crash reporting to be mark

Processed: closing 796467

2015-08-31 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > close 796467 Bug #796467 [general] general: if user has mail then how do we tell them if in GUI mode? Marked Bug as done > thanks Stopping processing here. Please contact me if you need assistance. -- 796467: http://bugs.debian.org/cgi-bin/bugr

Re: Security concerns with minified javascript code

2015-08-31 Thread Bas Wijnen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Mon, Aug 31, 2015 at 08:49:53AM +0200, Raphael Hertzog wrote: > On Sun, 30 Aug 2015, Bas Wijnen wrote: > > Why do you care that software is in main, if you evidently do not care about > > any of the rules we have for it? > > I don't think that impl

Bug#797583: ITP: python-subprocess32 -- Py2 backport of Py3 stdlib subprocess module

2015-08-31 Thread Daniel Stender
Package: wnpp Severity: wishlist Owner: Daniel Stender * Package name: python-subprocess32 Version : 3.6.2 Upstream Author : Gregory P. Smith * URL : https://pypi.python.org/pypi/subprocess32/ * License : PSF Programming Lang: Python Description : Py2

Re: How to read mail addressed to "root" from "root" user?

2015-08-31 Thread Jayson Willson
Thank you very much for your answer! Could you please tell me, why is it recommended to forward root's mail to regular user? I sometimes log in as root on tty or via sudo to administer system, and thus I would be able to have root's and user's mailboxes separated, while still reading root's mai

Re: system upgrade by GNOME (was: system upgrade by systemd)

2015-08-31 Thread Matthias Klumpp
2015-08-31 17:45 GMT+02:00 Russ Allbery : > Philip Hands writes: > > > Is it not the case that we're actually witnessing is: > > > Option e): get updates applied only at reboot, with no prior > > notification that they are available, such that people who always > > suspend, or simply leave

Re: system upgrade by GNOME

2015-08-31 Thread Michael Meskes
> That this would happen with no prior notification or user approval is > absolutely a bug, which I believe everyone involved in this thread has > agreed about. I think I saw a message go by indicating that the bug was > already located and fixed. Not exactly, the bug that was fixed was the insta

Re: How to read mail addressed to "root" from "root" user?

2015-08-31 Thread Marc Haber
On Mon, 31 Aug 2015 19:08:20 +0300, Jayson Willson wrote: >I would like to be able to read mail, which is addressed to "root" as >"root" user. When I configured exim4-config, I have set "root" as user, >which all the mail sent to "root" will be forwarded to. But now all the >mail sent to root c

Re: system upgrade by systemd

2015-08-31 Thread Marc Haber
On Mon, 31 Aug 2015 11:04:02 +0100, Dimitri John Ledkov wrote: >Ideally the update generators, targets and units should be split into >a separate package and not installed by default. Since those are >really unexpected on Debian. I would be fine with them being installed but disabled by default.

Bug#797575: ITP: r-cran-rinside -- GNU R package providing C++ classes to embed R in C++ applications

2015-08-31 Thread Jonathon
Package: wnpp Severity: wishlist Owner: Jonathon * Package name: r-cran-rinside Version : 0.2.13 Upstream Author : Dirk Eddelbuettel * URL : http://dirk.eddelbuettel.com/code/rinside.html * License : GPL Programming Lang: R, C Description : GNU R packa

How to read mail addressed to "root" from "root" user?

2015-08-31 Thread Jayson Willson
I would like to be able to read mail, which is addressed to "root" as "root" user. When I configured exim4-config, I have set "root" as user, which all the mail sent to "root" will be forwarded to. But now all the mail sent to root comes to /var/mail/mail, and when I run "mail" as root, I get m

Re: system upgrade by GNOME (was: system upgrade by systemd)

2015-08-31 Thread Russ Allbery
Philip Hands writes: > Is it not the case that we're actually witnessing is: > Option e): get updates applied only at reboot, with no prior > notification that they are available, such that people who always > suspend, or simply leave systems running all the time get no updates > until s

Re: system upgrade by systemd

2015-08-31 Thread Philip Hands
Philipp Kern writes: > On Sun, Aug 30, 2015 at 06:00:50PM +0100, Philip Hands wrote: >> I have been told by several newbies that the "updates available" >> notification, and them subsequently following the prompts to update >> their own system, was the first time they'd ever felt like they were i

Re: Security concerns with minified javascript code

2015-08-31 Thread Marvin Renich
First, let me make it clear that I am firmly in the camp that believes minified JS cannot be distributed in main unless the tools to recreate it are also in main. It bothers me that there appears to be a not-insignificant number of people with upload rights who do not believe this. This message i

Re: Security concerns with minified javascript code

2015-08-31 Thread Helmut Grohne
On Thu, Aug 27, 2015 at 04:14:53PM -0700, Russ Allbery wrote: > Last time I checked, Doxygen includes minified Javascript in all of its > generated output. Would we have to move every piece of Doxygen-generated > documentation into a separate package so that we could put it in contrib, > or strip

Re: Security concerns with minified javascript code

2015-08-31 Thread Helmut Grohne
On Tue, Aug 25, 2015 at 07:08:06PM +0100, Ian Jackson wrote: > Not regenerating configure doesn't pose any significant risk that > we're shipping a configure script that we can't regenerate (or, at > least, regenerate an equivalent or better one). I've not heard of > people (for example) using pri

Re: system upgrade by systemd

2015-08-31 Thread Michael Meskes
On Mon, Aug 31, 2015 at 03:47:19PM +0200, Josselin Mouette wrote: > An user does probably not need an “automatic updates” feature if she > wants such a level of manual control. In which case she can just disable > the updates and do her thing. Absolutely agreed. That's why I'd like to see the use

Re: Minutes from the "32bit architectures in Debian"-bof

2015-08-31 Thread Helmut Grohne
On Thu, Aug 20, 2015 at 03:04:17PM +0200, Andreas Barth wrote: > minutes from the "32bit architectures in Debian" bof right now. It is my understanding that it was also agreed that mips and mipsel would be dropped as release architectures after stretch. Yet it seems this was missing from the minut

Re: system upgrade by systemd

2015-08-31 Thread Josselin Mouette
Michael Meskes wrote: > In that case, the WLAN access point ("FooAP" or so) should be tagged as > "modem", not sure if n-m can do that. Am trying to file a wishlist > bug for that by BCCing submit@. And? How's that supposed to solve the problem?

Bug#797553: ITP: golang-github-google-btree -- BTree implementation for Go

2015-08-31 Thread Dmitry Smirnov
Package: wnpp Severity: wishlist X-Debbugs-CC: debian-devel@lists.debian.org pkg-go-maintain...@lists.alioth.debian.org Owner: Dmitry Smirnov Control: affects -1 etcd * Package name: golang-github-google-btree Version : 0.0~git20150413.0.cc6329d-1 Upstream Author : Google * URL

Re: system upgrade by systemd

2015-08-31 Thread Dimitri John Ledkov
On 31 August 2015 at 10:43, Michael Meskes wrote: >> This is getting ridiculous, are you now claiming the Debian Gnome team >> or Gnome upstream was tracking the Windows 10 betas? > > If anything is getting ridiculous then it's people believing we know better > hen the user when a line is to be us

Re: system upgrade by systemd

2015-08-31 Thread Michael Meskes
On Sun, Aug 30, 2015 at 10:41:16PM +0200, Philipp Kern wrote: > On the other hand I don't see why I, as a user, need to care about the > constant churn of updates myself. Why do I have to spend brain cycles on > that? What are my options? Am I going to inform myself on each and every Right, every

Re: system upgrade by systemd

2015-08-31 Thread Michael Meskes
> This is getting ridiculous, are you now claiming the Debian Gnome team > or Gnome upstream was tracking the Windows 10 betas? If anything is getting ridiculous then it's people believing we know better hen the user when a line is to be used for update ans when not. This is simply impossible. As

Re: system upgrade by systemd

2015-08-31 Thread Michael Meskes
> In that case, the WLAN access point ("FooAP" or so) should be tagged as > "modem", not sure if n-m can do that. Am trying to file a wishlist > bug for that by BCCing submit@. And? How's that supposed to solve the problem? I may be just fine using my cell for updates at home, but not while trav

Re: Security concerns with minified javascript code

2015-08-31 Thread Simon Josefsson
Raphael Hertzog writes: > On Mon, 31 Aug 2015, Simon Josefsson wrote: >> How would someone rebuild the minified javascript files from the >> missing-sources files? > > They would not? > > The modified non-minified files are perfectly usable even if they are a > bit larger than the minified ones.

Re: Security concerns with minified javascript code

2015-08-31 Thread Raphael Hertzog
On Mon, 31 Aug 2015, Simon Josefsson wrote: > How would someone rebuild the minified javascript files from the > missing-sources files? They would not? The modified non-minified files are perfectly usable even if they are a bit larger than the minified ones. > The included JavaScript file is m

Re: Security concerns with minified javascript code

2015-08-31 Thread Brian May
On Mon, 31 Aug 2015 at 16:50 Raphael Hertzog wrote: > In both cases, I worked around the problem by shipping the upstream > sources in debian/missing-sources/ but I did not support doing changes > there and did not rebuild the embedded libraries. > I haven't been paying lots of attention to this

Re: Summary of the DebConf firmware discussion

2015-08-31 Thread Raphael Hertzog
Hi, On Sun, 30 Aug 2015, Johannes Schauer wrote: > Allowing apt to pin (or otherwise filter) packages using debtags, for example, > sounds like a solution that would solve this problem while at the same time > allowing a wide range of other uses as well. Agreed. While the split looks like an easy

Bug#797503: ITP: tzlocal -- tzinfo object for the local timezone

2015-08-31 Thread Edward Betts
Package: wnpp Severity: wishlist Owner: Edward Betts * Package name: tzlocal Version : 1.2 Upstream Author : Lennart Regebro * URL : https://github.com/regebro/tzlocal * License : CC0 Programming Lang: Python Description : tzinfo object for the local t

Re: Security concerns with minified javascript code

2015-08-31 Thread Simon Josefsson
Raphael Hertzog writes: > In both cases, I worked around the problem by shipping the upstream > sources in debian/missing-sources/ but I did not support doing changes > there and did not rebuild the embedded libraries. > > In some cases, I do replace the embedded library with a symlink to the > p