Linux gains "embedded" maintainers  

Posted by Daniela Mehler

Linux gains

Andrew Morton finally has his wish -- times two -- as there are now two official "Embedded Linux" maintainers listed in the Linux kernel "Maintainers" file. David Woodhouse and Paul Gortmaker have volunteered to act as embedded Linux maintainers, and there is now a linux-embedded@vger.kernel.org list.


Morton (pictured at left), who is the maintainer of Linux 2.6 and among the top five contributors to the kernel by lines of code, called for a full-time, architecture-independent "embedded maintainer" at CELF's Embedded Linux Conference in April. At the time, he reminded everyone that things "can and do break" in embedded Linux kernel development, and suggested that a dedicated person to oversee the process might help limit the damage. It was recently reported that both the number of kernel developers and number of code lines changed in each kernel release is growing rapidly (see chart below).

Linux gains


The number of changes per Linux kernel release has grown considerably
[Source: The Linux Foundation]

After the conference, Morton privately sent out an RFC looking into creating an Embedded Linux maintainer, and Paul Gortmaker and David Woodhouse volunteered, explained Tim Bird, CELF's Architecture Group chairman. Gortmaker of Wind River is also the maintainer of the Network Drivers section, and the Real Time Clock Driver. David Woodhouse is in charge of Journalling Flash File System V2 (JFFS2), Memory Technology Devices, and Power Supply Class/Subsystem and Drivers.

So far, the new Linux-embedded@vger.kernel.org list has attracted over 90 subscribers, said Bird. "Hopefully, this will snowball into more focused development efforts on embedded-specific problems and features for the Linux kernel," he added.

Linux is the number one OS in the embedded and device market, according to research from VDC. Yet, most Linux development is funded by enterprise companies, Morton observed in his ELC speech. "I don't expect that to change," he said, while at the same time suggesting that someone close to the kernel development process ought to be looking out for embedded Linux interests. Morton formerly worked as an embedded systems engineer for digital set-top box supplier Digeo.

A complete list of kernel mailing lists can be found here. Developers can subscribe to the new linux-embedded list by sending an email with "subscribe linux-embedded" in the subject body to majordomo@vger.kernel.org.


Wind River, Intel tag-team “infotainment” Linux

Banshee 1.0 Beta 2 (0.99.2) Released  

Posted by Daniela Mehler

Banshee 1.0 Beta 2 (0.99.2) has been released

"We've released Banshee 1.0 Beta 2 (0.99.2), a bit over two weeks after 1.0 Beta 1 release. It brings some great new features and lots of bug fixes and performance improvements.

New in this release:

* Podcast extension
* CD Burning
* Auto Rip feature
* Over 28 bugs fixed since the last release

Remember, Banshee 1.0 beta releases can be safely installed and used in parallel with older Banshee releases, so there should be nothing stopping you from giving it a try!

Release notes with screenshots, ChangeLog, and updated list of deps:
http://banshee-project.org/Releases/0.99.2

Download the source code: http://banshee-project.org/files/banshee/banshee-1-0.99.2.tar.bz2
sha1sum: 8de316f88717e405e4bb37d3c49cd452623fd923

And the official blog announcement:
http://gburt.blogspot.com/2008/05/banshee-10-beta-2-released.html

Enjoy!"
>>Banshee 1.0 Beta 2 (0.99.2) Released


openSUSE 11.0 Beta 3
Debian adding low-power NAS devices

Orca v2.22.2  

Posted by Daniela Mehler

Orca v2.22.2 has been released

"Orca is a free, open source, flexible, and extensible screen reader that provides access to the graphical desktop via user-customizable combinations of speech, braille, and/or magnification. Orca development has been led by the Sun Microsystems, Inc., Accessibility Program Office via continued engagement with its end users and generous contributions from the Mozilla Foundation and wonderful community members.

The Orca v2.22.2 release is targeted for the GNOME v2.22.2 release and requires the latest at-spi/pyatspi infrastructure from GNOME v2.22.2, including atk and gail."
>>Orca v2.22.2


Orca v2.23.2

DSA 1587-1: New mtr packages fix execution of arbitrary code  

Posted by Daniela Mehler

The Debian Security Team published a new security update for Debian GNU/Linux. Here the announcement:
"-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1587-1 security@debian.org
http://www.debian.org/security/ Steve Kemp
May 26, 2008 http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package : mtr
Vulnerability : buffer overflow
Problem type : remote
Debian-specific: no
CVE Id(s) : CVE-2008-2357

Adam Zabrocki discovered that under certain circumstances mtr, a full
screen ncurses and X11 traceroute tool, could be tricked into executing
arbitrary code via overly long reverse DNS records.

For the stable distribution (etch), this problem has been fixed in version
0.71-2etch1.

For the unstable distribution (sid), this problem has been fixed in
version 0.73-1.

We recommend that you upgrade your mtr package.


Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

Source archives:

http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1.diff.gz
Size/MD5 checksum: 49648 1f32f54087c5cab59d13418277c33959
http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1.dsc
Size/MD5 checksum: 594 4dae747ffc1de0170d2578b1b09261ed
http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71.orig.tar.gz
Size/MD5 checksum: 205442 8c1c9f5db2c599eea3b12bfed8b80618

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updates/main/m/mtr/mtr-tiny_0.71-2etch1_alpha.deb
Size/MD5 checksum: 42128 48a8e95d395b07e57852b0005e5225ff
http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1_alpha.deb
Size/MD5 checksum: 57194 bd922b8c1a5891f71abbb4777faf4e63

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1_amd64.deb
Size/MD5 checksum: 52320 0d2aa3398184633044d21bdd70e23073
http://security.debian.org/pool/updates/main/m/mtr/mtr-tiny_0.71-2etch1_amd64.deb
Size/MD5 checksum: 37766 7513344c840d47a8dca23e1e51d6a0cc

arm architecture (ARM)

http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1_arm.deb
Size/MD5 checksum: 49510 a361681ebc93d48e24d7cca0086b6090
http://security.debian.org/pool/updates/main/m/mtr/mtr-tiny_0.71-2etch1_arm.deb
Size/MD5 checksum: 35560 69a3c71e6471813882c63e8201c34b80

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1_hppa.deb
Size/MD5 checksum: 54772 4c92f110415d9ef79b54fe91624d892c
http://security.debian.org/pool/updates/main/m/mtr/mtr-tiny_0.71-2etch1_hppa.deb
Size/MD5 checksum: 39920 fff799aabfd4b1fbd313f6512e02f765

i386 architecture (Intel ia32)

http://security.debian.org/pool/updates/main/m/mtr/mtr-tiny_0.71-2etch1_i386.deb
Size/MD5 checksum: 34832 46c37b88fbaead1b97685aef100bdff3
http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1_i386.deb
Size/MD5 checksum: 49498 429bf4027e3adc7a6c65739972f3637e

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updates/main/m/mtr/mtr-tiny_0.71-2etch1_ia64.deb
Size/MD5 checksum: 51828 52fa9d983e98c382259f844869ce2a9c
http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1_ia64.deb
Size/MD5 checksum: 68066 389cccac0ec00cbd3e1b32b8372f299b

mips architecture (MIPS (Big Endian))

http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1_mips.deb
Size/MD5 checksum: 56592 a4706a9a26ded557a35179be774cc4c2
http://security.debian.org/pool/updates/main/m/mtr/mtr-tiny_0.71-2etch1_mips.deb
Size/MD5 checksum: 42158 40220a8cc23ea78e02e63899379d9211

mipsel architecture (MIPS (Little Endian))

http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1_mipsel.deb
Size/MD5 checksum: 56468 e422aaae12583d2213208ea93bbf789b
http://security.debian.org/pool/updates/main/m/mtr/mtr-tiny_0.71-2etch1_mipsel.deb
Size/MD5 checksum: 42014 8965536180263c10a21cd19f621c2f67

powerpc architecture (PowerPC)

http://security.debian.org/pool/updates/main/m/mtr/mtr-tiny_0.71-2etch1_powerpc.deb
Size/MD5 checksum: 39388 40bfc501ea9369f583d17094e5afe106
http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1_powerpc.deb
Size/MD5 checksum: 53204 084b6accfd9f629b940b3100329e9569

s390 architecture (IBM S/390)

http://security.debian.org/pool/updates/main/m/mtr/mtr-tiny_0.71-2etch1_s390.deb
Size/MD5 checksum: 38036 f4f59a3761e2bbc202471ad64f4aa479
http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1_s390.deb
Size/MD5 checksum: 52968 23670acdeae3170a5c9d9041b9785f32

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updates/main/m/mtr/mtr_0.71-2etch1_sparc.deb
Size/MD5 checksum: 49746 ccfde335d99f424062f5594160c7c584
http://security.debian.org/pool/updates/main/m/mtr/mtr-tiny_0.71-2etch1_sparc.deb
Size/MD5 checksum: 35560 0e8e7a514058ec63dc283d4bb13b67cb


These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show ' and http://packages.debian.org/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFIOq7xwM/Gs81MDZ0RAm1TAJ96gxBalQgU/+K71oHkKaFiPshJwwCfeyU8
Aq/daY88/bHqqdHunaSJBao=
=Sf2d
-----END PGP SIGNATURE-----
"


DSA 1577-1: New gforge packages fix insecure temporary files
DSA 1576-2: New openssh packages fix predictable randomness

CEEA-2008:0274 CentOS 5 i386 xenpv Update  

Posted by Daniela Mehler

CentOS Errata and Enhancement Advisory 2008:0274

Upstream details at : https://rhn.redhat.com/errata/RHEA-2008-0274.html

The following updated files have been uploaded and are currently syncing to the mirrors: ( md5sum Filename )

i386:
478ae0ee8579ef930b92d966f55915f1 kmod-xenpv-0.1-9.el5.i686.rpm
e46e1df0f5f1f9ad25db97126e3c6f25 kmod-xenpv-PAE-0.1-9.el5.i686.rpm

Source:
4e9d7cad6dd2ad7c1b31669d404df7a9 xenpv-0.1-9.el5.src.rpm


CESA-2008:0287-01: Important CentOS 2 i386 libxslt security update

Ubuntu 8.04 LTS vs. Windows XP SP3: Application Performance Benchmark  

Posted by Daniela Mehler

Mohammed Saleh compared the application performance of Ubuntu 8.04 LTS and Windows XP SP3

"Two months ago, I wanted to compare Windows XP to Ubuntu Linux in terms of applications performance. I thought that since most of Linux programs are cross-platform and available for Windows, it could be a good idea to see how only platform change can affect the performance of a particular application. One of my reasons was also to verify whether or not Linux is capable of getting the most out of new hardware technologies. However, I only had a Pentium 4 HT machine, and even though I went ahead with the test, I knew it was not going to answer that.

A lot has happened since; Ubuntu 8.04 came out, and I was happy with it. Microsoft finalized their third service pack for Windows XP, and best of all I upgraded my PC with an AMD Athlon64 X2 5600+ CPU, 2GB DDR2-800 RAM and a GeForce 8600GT VGA card."
>>Ubuntu 8.04 LTS vs. Windows XP SP3: Application Performance Benchmark


Wind River, Intel tag-team “infotainment” Linux
World’s cheapest Linux-based laptop?

CESA-2008:0287 Important CentOS 3 s390(x) libxslt - security update  

Posted by Daniela Mehler

CentOS Errata and Security Advisory 2008:0287

https://rhn.redhat.com/errata/RHSA-2008-0287.html

The following updated files have been uploaded and are currently syncing to the mirrors:

s390:
updates/s390/RPMS/libxslt-1.0.33-6.s390.rpm
updates/s390/RPMS/libxslt-devel-1.0.33-6.s390.rpm
updates/s390/RPMS/libxslt-python-1.0.33-6.s390.rpm

s390x:
updates/s390x/RPMS/libxslt-1.0.33-6.s390x.rpm
updates/s390x/RPMS/libxslt-devel-1.0.33-6.s390x.rpm
updates/s390x/RPMS/libxslt-python-1.0.33-6.s390x.rpm


CESA-2008:0287 Important CentOS 4 s390(x) libxslt - security update
CESA-2008:0287-01: Important CentOS 2 i386 libxslt security update