Re: Bug#992692: general: Use https for {deb,security}.debian.org by default

2021-09-10 Thread Helmut Grohne
On Wed, Sep 08, 2021 at 07:12:18PM -0400, Michael Stone wrote: > Why not simply automate setting it at install time using preseed? I'm > honestly not sure who the target audience for auto-apt-proxy is--apparently > someone who has an infrastructure including a proxy, possibly the ability to > set d

Bug#992692: general: Use https for {deb,security}.debian.org by default

2021-09-10 Thread Ansgar
On Fri, 2021-09-10 at 09:33 +0200, Helmut Grohne wrote: > If > we installed auto-apt-proxy by default, much of the local caching > would > just work. If you push for a local caching method to be used by default, apt should always request (In)Release.gpg from a regular mirror (not auto- discovered

Re: Require packages to build without any configured DNS

2021-09-10 Thread Josh Triplett
Thomas Goirand wrote: > On 9/8/21 6:01 PM, Josh Triplett wrote: > > Now, that said, if the build process actually wants a DNS server to > > run tests against, it should provide or depend on such a DNS server, > > and configure it for such tests. > > Just to be 100% sure we're on the same page: tha

Re: Bug#992692: general: Use https for {deb,security}.debian.org by default

2021-09-10 Thread Eduard Bloch
Hallo, * Michael Stone [Wed, Sep 08 2021, 07:25:26PM]: > On Wed, Sep 08, 2021 at 03:56:14PM +0200, Ansgar wrote: > > On Wed, 2021-09-08 at 15:41 +0200, Helmut Grohne wrote: > > > On Wed, Sep 08, 2021 at 02:01:03PM +0200, Ansgar wrote: > > > > So what do you suggest then? Tech-ctte as with merged-/u

Re: Wine MinGW system libraries

2021-09-10 Thread Bastien ROUCARIES
Le jeu. 9 sept. 2021 à 07:32, Paul Wise a écrit : > > On Thu, 2021-09-09 at 00:59 -0500, Zebediah Figura wrote: > > > Unfortunately, no. We have no way of knowing the caller. > > Can the PE loading mechanism do something like inject a fake dlopen > function available only in the Wine namespace tha

Re: Bug#992692: general: Use https for {deb,security}.debian.org by default

2021-09-10 Thread Timo Röhling
* Michael Stone [2021-09-08 19:25]: I think the issue isn't certificate validation, it's that https proxy requests are made via CONNECT rather than GET. You could theoretically rewrite the proxy mechanism to MITM the CONNECT, but that wouldn't be a drop-in replacement. I suppose you could inst

Re: Bug#992692: general: Use https for {deb,security}.debian.org by default

2021-09-10 Thread Michael Stone
On Fri, Sep 10, 2021 at 12:00:57PM +0200, Timo Röhling wrote: * Michael Stone [2021-09-08 19:25]: I think the issue isn't certificate validation, it's that https proxy requests are made via CONNECT rather than GET. You could theoretically rewrite the proxy mechanism to MITM the CONNECT, but t

Re: Bug#992692: general: Use https for {deb,security}.debian.org by default

2021-09-10 Thread Michael Stone
On Fri, Sep 10, 2021 at 09:33:56AM +0200, Helmut Grohne wrote: Laptops of end-user systems are the target, but also developers. When people gather at a place (conference, hackspace, private meetup, etc.) downloading of .debs should just work quickly by default. Many such sites could easily provid

Epoch bump request for ksh

2021-09-10 Thread Anuradha Weeraman
Hi As a result of a revert of v2020 of ksh last year, the current version on sid for ksh is as follows: 2020.0.0+really93u+20120801-10 With the next upgrade, we're looking to move to the 93u+m community maintained distribution that has a different versioning scheme (starting with 1.0.0-beta.1).

Re: Epoch bump request for ksh

2021-09-10 Thread Phil Morrell
On Fri, Sep 10, 2021 at 05:18:13PM +0530, Anuradha Weeraman wrote: > As a result of a revert of v2020 of ksh last year, the current version > on sid for ksh is as follows: > > 2020.0.0+really93u+20120801-10 > > With the next upgrade, we're looking to move to the 93u+m community > maintained distr

Bug#994039: ITP: mirrorbits -- Geographical download redirector for distributing files efficiently across a set of mirrors.

2021-09-10 Thread Arnaud Rebillout
Package: wnpp Severity: wishlist Owner: Arnaud Rebillout * Package name: mirrorbits Version : 0.5.1+git20210123.eeea0e0-1 Upstream Author : Ludovic Fauvet * URL : https://github.com/etix/mirrorbits * License : Expat Programming Lang: Go Description : Ge

Re: Epoch bump request for ksh

2021-09-10 Thread Anuradha Weeraman
On Fri, Sep 10, 2021 at 02:25:32PM +0100, Phil Morrell wrote: > On Fri, Sep 10, 2021 at 05:18:13PM +0530, Anuradha Weeraman wrote: > Then there appears to be this 93u+m project publishing essentially v2020 > as 1.0.0 beta, tagged as 'v1.0.0-beta.1'. It's release notes say "This > new fork is called

Re: Bug#992692: general: Use https for {deb,security}.debian.org by default

2021-09-10 Thread David Kalnischkies
On Thu, Sep 09, 2021 at 08:53:21AM -0400, Michael Stone wrote: > The only thing I could see that would be a net gain would be to generalizes > sources.list more. Instead of having a user select a specific protocol and > path, allow the user to just select high-level objects. Make this a new > pseud

Bug#992692: general: Use https for {deb,security}.debian.org by default

2021-09-10 Thread Simon Richter
Hi, On 10.09.21 01:46, Paul Wise wrote: Another important argument is that it creates a dependency on third-party commercial CDNs, and their *continued* sponsorship. This dependency on external providers is unavoidable, Debian definitely cannot afford to run our own CDN at the scale needed t

Re: Bug#992692: general: Use https for {deb,security}.debian.org by default

2021-09-10 Thread Michael Stone
On Fri, Sep 10, 2021 at 04:33:42PM +0200, David Kalnischkies wrote: On Thu, Sep 09, 2021 at 08:53:21AM -0400, Michael Stone wrote: The only thing I could see that would be a net gain would be to generalizes sources.list more. Instead of having a user select a specific protocol and path, allow th

Re: Epoch bump request for ksh

2021-09-10 Thread Anuradha Weeraman
On Fri, Sep 10, 2021 at 07:37:55PM +0530, Anuradha Weeraman wrote: > > 2) If you do go ahead with switching to the community distribution, then > > "93u+m" is part of the name, not the version number, so I'd suggest: > > > > 1:1.0.0~beta.1-1 > > It does make sense to differentiate with the 93u+m

Re: Bug#992692: general: Use https for {deb,security}.debian.org by default

2021-09-10 Thread David Kalnischkies
On Fri, Sep 10, 2021 at 11:08:38AM -0400, Michael Stone wrote: > On Fri, Sep 10, 2021 at 04:33:42PM +0200, David Kalnischkies wrote: > > On Thu, Sep 09, 2021 at 08:53:21AM -0400, Michael Stone wrote: > > > The only thing I could see that would be a net gain would be to > > > generalizes > > > sour

Re: Bug#992692: general: Use https for {deb,security}.debian.org by default

2021-09-10 Thread Michael Stone
On Fri, Sep 10, 2021 at 08:02:42PM +0200, David Kalnischkies wrote: On Fri, Sep 10, 2021 at 11:08:38AM -0400, Michael Stone wrote: On Fri, Sep 10, 2021 at 04:33:42PM +0200, David Kalnischkies wrote: > On Thu, Sep 09, 2021 at 08:53:21AM -0400, Michael Stone wrote: > > The only thing I could see t

Re: Require packages to build without any configured DNS

2021-09-10 Thread Adrian Bunk
On Wed, Sep 08, 2021 at 09:01:31AM -0700, Josh Triplett wrote: >... > I think dnspython's previous approach was correct: just like glibc, musl, and > other libraries, if /etc/resolv.conf is missing they should treat that as > though it specified a nameserver on localhost. How libraries implement a

Re: Epoch bump request for ksh

2021-09-10 Thread Phil Morrell
On Fri, Sep 10, 2021 at 07:37:55PM +0530, Anuradha Weeraman wrote: > ksh93u+m was a reboot attempt by Martijn Dekker et al. to build upon > the last stable 93u+ release (not on v2020, apart from some cherry > picked patches). This work has been taking place for over a year at this > point, with the

Bug#994071: ITP: aws-nuke -- Nuke a whole AWS account and delete all its resources.

2021-09-10 Thread Arthur Diniz
Package: wnpp Severity: wishlist Owner: Arthur Diniz * Package name: aws-nuke Version : 2.16.0-1 Upstream Author : reBuy reCommerce GmbH * URL : https://github.com/rebuy-de/aws-nuke * License : Expat Programming Lang: Go Description : Nuke a whole AWS a

Bug#994074: ITP: kubernetes-split-yaml -- Split a giant yaml file into one file per Kubernetes resource

2021-09-10 Thread Arthur Diniz
Package: wnpp Severity: wishlist Owner: Arthur Diniz * Package name: kubernetes-split-yaml Version : 0.3.0-1 Upstream Author : Frederik Mogensen * URL : https://github.com/mogensen/kubernetes-split-yaml * License : Expat Programming Lang: Go Description

Re: Wine MinGW system libraries

2021-09-10 Thread Paul Wise
Disclaimer: I know precisely zero of the details here nor if the PE loader can support any of the below features. On Fri, 2021-09-10 at 09:23 +, Bastien ROUCARIES wrote: > The problem is that windows apps particularly games try to check if > mapped ram exec pages are from dll from disk and no