(→Running As Root: fix link#4. Conversion from LaTeX to ASCII erroneously substitues periods for underscores)
m (added category)
|Line 377:||Line 377:|
Revision as of 10:53, 14 April 2009
Fedora Weekly News Issue 133
Welcome to Fedora Weekly News Issue 133 for the week ending July 5, 2008.
If you are interested in contributing to Fedora Weekly News, please see our 'join' page. Being a Fedora Weekly News beat writer gives you a chance to work on one of our community's most important sources of news, and can be done in only about 1 hour per week of your time.
We are still looking for beat writers to cover the highlights of Fedora Marketing and summarize the Fedora Events and Meetings that happened during each week.
In this section, we cover the highlights of Planet Fedora - an aggregation of blogs from Fedora contributors worldwide.
Contributing Writer: Max Spevack
Func and Certmaster 0.20 Released
Michael DeHaan announced on his blog that Func and Certmaster have both just seen new releases.
"This showcases significantly improved asynchronous support as well as the future of Funcweb. We should also have multi-overlord delegation for extra-large (read: global) setups implemented pretty soon. More releases short start following at greater frequency."
He also included links to the official project pages, for anyone who desires more information.
Transifex receives some updates
Diego Búrigo Zacarão wrote on his blog about two improvements to Transifex.
"We have a quite stable version of Transifex using:
* SQLAlchemy 0.4.6 * Genshi 0.5 * ToscaWidgets 0.9.2 * TurboGears 188.8.131.52"
Also, i18n support in Transifex has been split into two different potfiles. "All strings related with the source code will be stored in the 'po/view/' directory and strings coming from database, into the 'po/data/'."
Ryan Lerch has posted three new Inkscape tutorials on his blog.
"After a month or so of laziness, i have finally updated the inkscape tutorials blog with 3 fresh tutorials for all to try!"
New Fedora business cards
Ian Weller has been working on a new design for Fedora business cards.
"List of changes:
* Added “infinity | freedom | voice” to front * Added “fedoraproject.org” to front * Removed GPG key fingerprint * Moved Fedora logo to top and inverse on blue bar * Created blue bars at top and bottom * Removed back"
Bug Triage meeting
John Poelstra wrote on his blog:
"Our weekly bug triage meeting hasn't happened for several weeks and we'd like to resume them again. Some of us were tied up with other things and some people were unable to make the time. Also after having a few meetings with one or two people it seemed unclear how best to proceed.
So... we know there are a lot of people interested in bug triage but past meeting attendance hasn't been good so we'd like to try and fix that. At least two or three people sign up for the 'fedorabugs' group every day so there is a disconnect there somewhere we need to fix. And if you think weekly meetings aren’t the way to go and there is a better way to proceed please put it forward."
In this section, we cover the Fedora Marketing Project.
Contributing Writer: Pascal Calarco
Fedora 9 & KDE 4 review
Rahul Sundaram forwarded a recent review of Fedora 9 with KDE 4, which summarized, "[w]e recommend Fedora 9 and the KDE that comes with it, not to the average user, people switching to Fedora or to Linux itself for that matter, but to past Fedora and KDE users, that would like to play around with the latest and greatest to the Fedora Linux distribution."
Acer's Linpus Linux Lite Features Fedora
Rahul Sundaram forwarded a review of Acer's new ultraportable, who's operating system is based on Fedora 8. The article notes, "Fedora has managed to avoid shabby deals with Microsoft and playing fast and loose with Kernel source code and the GPL. At last, a version of GNU/Linux on an ultra portable you can use with a clear conscience."
FedoraTV is Ready To Go!
Jonathan Roberts announced this week that the FedoraTV hosted site is ready for further review and content submissions. He added, "Any FAS account holders can login, file a ticket with information about a video/audio they want to submit for the feed, and we can respond openly and hold any discussions about whether to include the file or not." Kushal Das responded, encouraging everyone to submit their Fedora-related screencasts, podcasts and other video to the new site.
Software Freedom T-Shirts
Jayme Ayres announced a new graphic design for Software Freedom Day, inspired by discussions amongst Brazilian Fedora Ambassadors, and also pointed to the video produced after the recent Fórum Internacional Software Livre (FISL) meeting in Brazil that recently appeared in Red Hat Magazine, and the polo shirts also designed for the event
In this section, we cover Fedora Ambassadors Project.
Contributing Writer: JeffreyTadlock
Help Wanted: Utah Open Source Conference 2008
Clint Savage posted asking for ambassador help with the Utah Open Source Conference 2008 (August 28 to August 30) at the Salt Lake Community College. If you are in the area, and able to help, please check the mailing list post for additional information.
New LATAM Administrator
Francesco Ugolini announced that Rodrigo Padula has been acknowledged as the LATAM Ambassadors administrator. Rodrigo is a long time Fedora Ambassador and a current member of the Fedora Ambassador Steering Committee. The role includes acting as a bridge for the LATAM community for ambassador resources.
 Latin-American Fedora Ambassadors
Contributing writer Osin Feeley
SELinux Eats Babies, Confines Wives, Gives Birth
JonMasters plunged his head into the lion's mouth with a request to "re-add" the option to disable SELinux (or change to permissive mode) during or shortly after installation of the OS. His reasons included the apparent random breaking of currently working applications due to policy changes and the lack of support via gnome-vfs for relabeling of files to fix context problems. He finished off by claiming that "unsuspecting Desktop users" should not have something as complex as SELinux forced on them without an easy way to disable it.
Jon's examples of stuff that broke included attempting to use an ISO in virtmanager and running vpnc. He was at pains to point out that he had been running SELinux in "enforcing" for a long time and that he was reporting these problems because he thought that average "Desktop" users would be unable to use chcon to fix them.
Responses mostly emphasized that Jon was far from a typical user. SimoSorce argued that, as a fellow developer, he had learned to expect labeling problems due to his non-standard usage and also how to fix them including changing policy for some of his commonly used packages. He noted that DanWalsh was very helpful in this regard. A brief discussion between SethVidal and MatthiasClasen suggested[2a] that nautilus has been fixed in rawhide to allow the labelling of files through gnome-vfs via the right-click "properties" dialog.
DanWalsh wrote a detailed response in which he commented that Jon had run vpnc from the command-line instead of from NetworkManager, this latter being standard usage. Dan thought that this contradicted Jon's claim that this problem would be typically faced by an ordinary desktop user without access to, or knowledge of, chcon. He further argued that the virt-manager problem was unlikely to be faced by such desktop users and went on to explain that "libvirtd is not unconfined whereas running qemu as a user is unconfined. Running qemu from libvirtd is still confined and is fixed by correct labeling. Hopefully the virt-manager people will assign an appropriate context at creation time, and/or default virtual machines to /var/lib/libvirt/images where they will be labeled correctly automatically."
Dan then commented that Desktop users are currently only confined with respect to executable memory checks in order to stop poorly written programs offering a means to execute buffer overflows. The use of PolicyKit, HAL and D-BUS to improve the user's desktop experience by running applications as root was mentioned by Dan as a further arena in which user confinement was necessary in order to prevent root exploits. He alluded to his recent presentations (e.g. ,) on confining users on Fedora 9 and rawhide as ways in which user types can be confined in customized ways to prevent such problems.
DanielBerrange added that the libvirt problem should be permanently fixed in Fedora 10 due to new storage management capabilities.
Much of the rest of the discussion focused on the general problem of whether or not it was appropriate to offer uneducated users the option to disable intrinsic security. JesseKeating and AlanCox thought that a lack of knowledge precluded a meaningful choice and JamesMorris agreed, and referenced BruceSchneier on risk evaluation and security. He concluded that "Punting the decision to the end user during installation is possibly the worst option. It's our responsibility as the developers of the OS to both get security right and make it usable. It's difficult, indeed, but not impossible."
ColinWalters added his voice to the chorus of those that believed that it was inappropriate to offer such options during installation. He suggested that system-config-selinux post-installation was available for those that really needed it and that the paths to solve this problem were not restricted to a binary "enabled or disabled by default" but included other possibilities such as: rawhide defaults to permissive; automatic reporting of denials to the Fedora developers; shifting more objects into unconfined_t in the default while confining network-facing services; and finally, using a regression test suite to ensure updates are not problems. Jon was largely in agreement and again wanted to emphasize that he was appreciative of both Dan's rapid fixing of problems and the usefulness of SELinux itself, but he thought that the "tuning down of default policy" was the best option to enable "Desktops where people can just get stuff done." AlanCox did not buy this and argued that no progress would be made without exposing us all to the problems which would then get fixed. He likened the discussion to the years-old one which had taken place concerning firewalls being enabled by default: "Sorry if I sound fed up of all of this but I spent 9 months fighting people years back to get firewalling enabled by default, and that had all the same arguments. Today nobody (even Microsoft) would propose otherwise." Alan added that setroubleshoot should be a bit more user friendly.
Apparent agreement on this last point exposed a further problem with several posters suggesting, that a Windows Vista-like prompt to run a program which had been flagged as dangerous would be useful. SimoSorce and AndrewFarris highlighted, the potential flaw of such an approach. SurenKarapetyan argued that he and others were capable of making an informed choice to disable SELinux and that Fedora was becoming increasingly restricted in such freedoms. SimoSorce retorted that re-adding the "disable SELinux" option during installation was wrong from a usability perspective and that if was both selfish and incompetent for Fedora developers to simply disable SELinux instead of dogfooding it. Suryen referenced Smolt statistics to bolster his case and argued that it was wrong to decide "for the user" what to do. AlanCox responded that such statistics were meaningless because it was impossible to know how many of the users disabling SELinux had made an informed, correct choice.
Several other posters expressed frustration with the repetition of such objections to SELinux and there the thread would have lain, flogged senseless except that StewartAdam volunteered to help write an "setroubleshoot" plugin that "allowed users to report audit denials similar to how kerneloops does. setroubleshoot then bridges the gap between new users and fixing the policy, and it could be done with stats to see what areas need work on. Naturally it would only report the denials the user requests to be submitted, so no "calling home" stuff." This proposal seemed to draw general approval,.
Help Wanted: Samba4, Heimdahl, OpenChange
An exciting promise of increased interoperability with Microsoft Exchange was wafted in front of us when AndrewBartlett requested help in packaging OpenChange and its dependencies. This would result in "evolution" and "kdepim" being able to use the native MAPI protocol and free them from relying upon fragile WebDAV access to the server.
JesseBarnes was excited enough to start helping out and after some pointers from RahulSundaram and Andrew on how to get started he very quickly got going. AlexanderBoström and MarceloGobelli also expressed willingness to help.
Java, So Many Free Choices
PeterLemenkov requested that the current wiki be updated to summarize the status of the four available implementations of Java: GCJ, OpenJDK/IcedTea, ecj, java-1.6.0-sun (this latter for EPEL only). His interest had been sparked by the observation that some packages were built with GCJ and had not been rebuilt with OpenJDK which he presumed to be superseding GCJ/ecj.
3. Strictly speaking although these all share some features it's a bit misleading to lump them together. OpenJDK is Sun Microsystems' open-sourced implementation of the Java Platform (SE). This includes classes, an interpreter, compiler etc., whereas ecj was solely a bytecode compiler from the Eclipse project. GCJ can compile Java to bytecode or to native machine code and provides a linkable runtime which can interpret bytecode. IcedTea was a project which replaced non-Free parts of OpenJDK with GNU implementations.
AndrewHaley promised to update the wiki and commented that due to limited people resources it was difficult to say exactly what the future of GCJ/ecj would be and that OpenJDK support needed to be extended across more platforms. He explained that there was no need to use OpenJDK to rebuild packages which already compiled with GCJ and expanded on his earlier comment with the information that most non-x86 platforms were currently not fully supported by OpenJDK.
When MattBooth suggested that GCJ would be needed until OpenJDK could support AOT compilation AndrewOverholt responded that JIT compilation (as implemented by OpenJDK's Hotspot virtual machine) removed this need. AndrewHaley disagreed  for at least the case of lower-powered boxes which would benefit from AOT.
After all this talk about the many Free choices available in Java KevinKoffler wondered whether some of the other virtual machines, such as ChristianThalinger's cacao or GaryBenson's shark, both of which attempt to re-implement Hotspot in more portable ways, would be receiving attention. AndrewHaley responded that help was welcome, "building Cacao + OpenJDK on one of the secondary arches and reporting back on how well it works would be massively useful."
Fedora 9 Now Officially Supported On Itanium/IA64
An announcement by PraritBhargava of the availability of Fedora 9 on the ia64 "itanium" platform is the first fruit of the work done (see FWN#90, FWN#92) to open up the Fedora project to "secondary architectures."
This means that it is now possible to run Fedora on an expanded range of high end hardware (from HP, SGI, NEC, Fujitsu, Unisys, Hitachi and Bull according to the architecture maintainers. The release notes inaccurately describe this as a "beta" but DougChapman clarified that it is a GA release.
Prarit warned that there were a few important points of which to be aware including some slight source differences from stock Fedora 9. Consequently attempts to use yumdownloader will pull in SRPMS which do not match the actual source used to produce the ia64 binaries. MichaelSchwendt wanted to know why the ia64 release was out of sync with the other architectures and exactly what patches had been applied to stock Fedora. DougChapman answered that future releases would hopefully reflect the experience gained in this very first "secondary architecture" and result in near perfect synchronization. He added that the changes to stock Fedora 9 source were in Fedora CVS so there were "no special ia64 patches floating around" and that the ia64 Everything repository had about 98% of the packages available on other arches. The builds are conducted on a separate Koji server using an identical method to the other architectures.
DavidWoodhouse asked why the download URL was so different to that of other supported architectures. BillNottingham responded that ia64 was intentionally left off the Fedora master mirror due to space constraints.
RichardJones wanted to know how to build Rawhide packages against ia64 using Koji and PaulHowarth provided some sample Koji commands. DanHorak thought that fedora-packager-setup should provide some default configs in ~/.koji.
Running As Root
A tired JerryWilliams asked that the prompt which warns users that they have logged in as root to a session should have a means to easily disable it: "People login as root and have to keep clicking "Continue" and it slows things down."
TomCallaway disagreed, likening this to "using a loaded shotgun as a golf club, and what you're suggesting is that we take the safety off, because it interferes with your golf game." He suggested that the preferred behavior was to login as a normal user and then use sudo or su to elevate privileges to those of root only when necessary. Jerry decided to re-think why he needed such root privileges and consequently drew attention to the lack of a non-root account setup on install, the presence of applications such as browsers in the root GUI profile, and the need to know the root password to use some configuration tools anyway.
Some of these points have received prior developer attention (see FWN#103 "Root Login And Display Managers In Rawhide") and were specifically discussed with reference to the Desktop Live spin.Tom acknowledged that Jerry's questions were valid and wondered what had happened to "making the root GUI session a super-minimal session." DougLedford also mounted a spirited defense of the occasional need to log in as root, although he conceded that it should not be made too easy to do so. His reasons included scenarios in which network-provided accounts and authentication are unavailable.
This section contains the discussion happening on the fedora-infrastructure-list
Contributing Writer: HuzaifaSidhpurwala
Advice on deploying wsgi app using jsonfas
Robin Norwood writes for fedora-infrastructure-list 
Robin is working to get amber packaged and deployable as a wsgi app so he can run a demo on publictest10. A fair progress has been made getting things up and running (on his local system first to make sure it works), but has ran into issues.
Red Hat (Fedora) Bugzilla 3.2 Upgrade on July 26th, 2008
John Poelstra writes for fedora-infrastructure-list 
The Red Hat bugzilla, which fedora uses too will be updated to 3.2 on 26th July 2008. The next release can be previewed at 
In this section, we cover the Fedora Artwork Project.
Contributing Writer: NicuBuculei
More Echo Icons
This week the focus on the Fedora Art list was development for the Echo Icon theme with new icons created by Martin Sourada and Luya Tshimbalanga.
Martin also started a debate about the best shape for icons for package install and update. The points of discussion included whether or not to use a package visual, to show an optical disc or just an arrow and various kind of colors.
An interesting touch made by Luya was noticed, the inclusion of a sketch of the current release wallpaper in any icons which have a computer display as a design component. However, this would require refreshing a number of icons twice a year and also may not be that useful for other distros shipping the theme.
Starting with a rude complaint from another contributor, Mark, about some icons which supposedly "have that shit color", Marin proposed a color change in the default palette and after a favourable reaction actually implemented the changes and submitted them for discussion.