You are not logged in.
Hello:
How does anyone in their right mind not scream bloody murder ...
Well ...
This thread could go on for weeks on end with the hows/whys/etcs.
No sense doing that.
The very ugly truth is that most people these days are basically stupid/ignorant dickheads that think IoTs, internet enabled toasters/washing machines/refrigerators/TVs, automated lightbulbs, intelligent [whatevers], internet enabled baby cams and doorbells, cars and snoop-phones with incorporated AI and crap like that are oh! soooo convenient.
Unbelievable.
But that is where we are at in 2024 and it will only get worse.
Much worse.
We are only seeing the tip of the crapberg.
Best,
A.
It is a harvester of info from I understand.
An huge understatement.
See https://web.archive.org/web/20090418021 … eZeitgeist
And that bit is from back in 2009, imagine where it is now ... 8^°
Mark my words: sooner than later we will see zeitgeist code merged into systemd.
Best,
A.
Hello:
... having issues with clipit, replaced by Diodon and laced with zeitgeist.
If I were you, I'd get rid of that zeitgeist crap ASAP.
There was a lot written about it in late 2022.
But after that, nothing else.
One day, it will be too late to say anything much.
Best,
A.
Hello:
... convince him not to use a proprietary software.
Convince who?
The court?
Surely you jest ...
I expect that AK will be lucky if he gets a proper hearing.
Best,
A.
Hello:
Just got this in my box.
Best,
A.
---
This release contains fixes for the issues reported in today's security
advisory: https://lists.x.org/archives/xorg/2024- … 61525.html
* CVE-2023-6816
* CVE-2024-0229
* CVE-2024-21885
* CVE-2024-21886
* CVE-2024-0408
* CVE-2024-0409
Additionally, it also contains several other fixes for glamor, libEI support,
and FreeBSD.
Jan Beich (2):
os: Use LOCAL_PEERCRED to determine local client PID on FreeBSD
os: Use KERN_PROC_ARGS to determine client command on DragonFly and FreeBSD
José Expósito (2):
Xi: do not keep linked list pointer during recursion
Bump version to 23.2.4
Michel Dänzer (3):
glamor: Don't override source alpha to 1.0 if it's used for blending
glamor: Make glamor_set_alu take a DrawablePtr
glamor: Fall back for mixed depth 24/32 in glamor_set_alu
Olivier Fourdan (3):
xwayland: Pass the correct oeffis device types
glx: Call XACE hooks on the GLX buffer
ephyr,xwayland: Use the proper private key for cursor
Peter Hutterer (10):
Xi: require a pointer and keyboard device for XIAttachToMaster
dix: don't allow for devices with 0 axes
xwayland: override the XTest sendEventsProc for all devices
dix: initialize the XTest sendEventsProc for all devices
dix: allocate enough space for logical button maps
dix: Allocate sufficient xEvents for our DeviceStateNotify
dix: fix DeviceStateNotify event calculation
Xi: when creating a new ButtonClass, set the number of buttons
Xi: flush hierarchy events after adding/removing master devices
dix: when disabling a master, float disabled slaved devices too
git tag: xwayland-23.2.4
https://xorg.freedesktop.org/archive/in … 2.4.tar.xz
SHA256: a99e159b6d0d33098b3b6ab22a88bfcece23c8b9d0ca72c535c55dcb0681b46b xwayland-23.2.4.tar.xz
SHA512: ac3ff208cbef5bbe4637c335cfda226489c93b0a3768f2f4fb0201c588485ede38262fbce77ef1425b3d2a0be61b6580df53341c7b95e6072c8b6371ad29d187 xwayland-23.2.4.tar.xz
PGP: https://xorg.freedesktop.org/archive/in … tar.xz.sig
---
Best,
A.
Hello:
Just got this in my box.
---
This release contains fixes for the issues reported in today's security
advisory: https://lists.x.org/archives/xorg/2024- … 61525.html
* CVE-2023-6816
* CVE-2024-0229
* CVE-2024-21885
* CVE-2024-21886
* CVE-2024-0408
* CVE-2024-0409
Additionally, it also contains a fix for XRandR to allow for multiple virtual
monitors on a physical display.
José Expósito (2):
Xi: do not keep linked list pointer during recursion
xserver 21.1.11
Michael Wyraz (1):
Removing the code that deletes an existing monitor in RRMonitorAdd
Olivier Fourdan (2):
glx: Call XACE hooks on the GLX buffer
ephyr,xwayland: Use the proper private key for cursor
Peter Hutterer (6):
dix: allocate enough space for logical button maps
dix: Allocate sufficient xEvents for our DeviceStateNotify
dix: fix DeviceStateNotify event calculation
Xi: when creating a new ButtonClass, set the number of buttons
Xi: flush hierarchy events after adding/removing master devices
dix: when disabling a master, float disabled slaved devices too
git tag: xorg-server-21.1.11
https://xorg.freedesktop.org/archive/in … .11.tar.gz
SHA256: 1aa0ee1adad0b2db7f291f3823a4ab240c7f4aea710e89f5ef4aa232b6833403 xorg-server-21.1.11.tar.gz
SHA512: e41bf71955691e66084a67fc20643632087f0326d5eddc31e6edd118d05005b8ab536738c181f4c352f331ec8fc8f23ae1b45f237592fa5d7eddbffe43638b08 xorg-server-21.1.11.tar.gz
PGP: https://xorg.freedesktop.org/archive/in … tar.gz.sig
---
Best,
A.
Hello:
Just got this in my box.
Good to see X.Org at work.
---
Issues in X.Org X server prior to 21.1.11 and Xwayland prior to 23.2.4
=====================================================
Multiple issues have been found in the X server and Xwayland implementations
published by X.Org for which we are releasing security fixes for in
xorg-server-21.1.11 and xwayland-23.2.4.
1) CVE-2023-6816 can be triggered by passing an invalid array index to DeviceFocusEvent or ProcXIQueryPointer.
2) CVE-2024-0229 can be triggered if a device has both a button and a key class and zero buttons.
3) CVE-2024-21885 can be triggered if a device with a given ID was removed and a new device with the same ID added both in the same operation.
4) CVE-2024-21886 can be triggered by disabling a master device with disabled slave devices.
5) CVE-2024-0409 can be triggered by enabling SELinux xserver_object_manager and running a client.
6) CVE-2024-0408 can be triggered by enabling SELinux xserver_object_manager and creating a GLX PBuffer.
------------------------------------------------------------------------
1) CVE-2023-6816: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
Introduced in: xorg-server-1.13.0 (2012)
Fixed in: xorg-server-21.1.11 and xwayland-23.2.4
Fix: https://gitlab.freedesktop.org/xorg/xse … 3c58a9e7e3
Found by: Jan-Niklas Sohn working with Trend Micro Zero Day Initiative
Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for
each logical button currently down. Buttons can be arbitrarily mapped to
any value up to 255 but the X.Org Server was only allocating space for the
device's number of buttons, leading to a heap overflow if a bigger value
was used.
xorg-server-21.1.11 and xwayland-23.2.4 have been patched to fix this issue.
2) CVE-2024-0229: Reattaching to different master device may lead to out-of-bounds memory access
Introduced in: xorg-server-1.1.1 (2006)
Fixed in: xorg-server-21.1.11 and xwayland-23.2.4
Fixes:
- https://gitlab.freedesktop.org/xorg/xse … 636109d6a5
- https://gitlab.freedesktop.org/xorg/xse … cde53553d5
- https://gitlab.freedesktop.org/xorg/xse … e0d5981b74
Found by: Jan-Niklas Sohn working with Trend Micro Zero Day Initiative
If a device has both a button class and a key class and numButtons is
zero, we can get an out-of-bounds write due to event under-allocation in
the DeliverStateNotifyEvent function.
xorg-server-21.1.11 and xwayland-23.2.4 have been patched to fix this issue.
3) CVE-2024-21885: Heap buffer overflow in XISendDeviceHierarchyEvent
Introduced in: xorg-server-1.10.0 (2011)
Fixed in: xorg-server-21.1.11 and xwayland-23.2.4
Fix: https://gitlab.freedesktop.org/xorg/xse … dce503cbd1
Found by: Jan-Niklas Sohn working with Trend Micro Zero Day Initiative
The XISendDeviceHierarchyEvent() function allocates space to store up
to MAXDEVICES (256) xXIHierarchyInfo structures in info.
If a device with a given ID was removed and a new device with the same
ID added both in the same operation, the single device ID will lead to
two info structures being written to info.
Since this case can occur for every device ID at once, a total of two
times MAXDEVICES info structures might be written to the allocation,
leading to a heap buffer overflow.
xorg-server-21.1.11 and xwayland-23.2.4 have been patched to fix this issue.
4) CVE-2024-21886: Heap buffer overflow in DisableDevice
Introduced in: xorg-server-1.13.0 (2012)
Fixed in: xorg-server-21.1.11 and xwayland-23.2.4
Fixes:
- https://gitlab.freedesktop.org/xorg/xse … 54dd0ce36b
- https://gitlab.freedesktop.org/xorg/xse … 10cc07c3a8
Found by: Jan-Niklas Sohn working with Trend Micro Zero Day Initiative
The DisableDevice() function is called whenever an enabled device
is disabled and it moves the device from the inputInfo.devices linked
list to the inputInfo.off_devices linked list.
However, its link/unlink operation has an issue during the recursive
call to DisableDevice() due to the prev pointer pointing to a
removed device.
This issue leads to a length mismatch between the total number of
devices and the number of device in the list, leading to a heap
overflow and, possibly, to local privilege escalation.
xorg-server-21.1.11 and xwayland-23.2.4 have been patched to fix this issue.
5) CVE-2024-0409: SELinux context corruption
Introduced in: xorg-server-1.16.0 (2014)
Fixed in: xorg-server-21.1.11 and xwayland-23.2.4
Fix: https://gitlab.freedesktop.org/xorg/xse … ea702c94f7
Found by: Olivier Fourdan
The Xserver uses the mechanism of "privates" to store additional data to its
own objects, each private has an associate "type". Each private is allocated
for the relevant size of memory that is declared at creation.
The cursor structure in the Xserver goes as far as having two keys, one for
the cursor itself and another one for the bits that make the cursor shape.
XSELINUX also uses privates but it's a bit of a special case because it uses
the same privates keys for all different objects.
What happens here is that the cursor code in both Xephyr and Xwayland uses the
wrong type of private at creation, using the cursor bits type with the cursor
private and when initiating the cursor, the overwrites the XSELINUX context.
xorg-server-21.1.11 and xwayland-23.2.4 have been patched to fix this issue.
6) CVE-2024-0408: SELinux unlabeled GLX PBuffer
Introduced in: xorg-server-1.10.0 (2011)
Fixed in: xorg-server-21.1.11 and xwayland-23.2.4
Fix: https://gitlab.freedesktop.org/xorg/xse … fe5e15dac3
Found by: Olivier Fourdan and Donn Seeley
The XSELINUX code in the Xserver labels the X resources based on a hook. What
happens here is that the GLX PBuffer code does not call that XACE hook when
creating the buffer, so it remains unlabeled, and when the client issues
another request to access that resource (as here with a GetGeometry) or even
when it creates another resource which needs to access that buffer (such as a
GC), the XSELINUX code will try to use an object that was never labeled and
crash because the SID is NULL.
xorg-server-21.1.11 and xwayland-23.2.4 have been patched to fix this issue.
---
Best,
A.
Hello:
What is systemctl in Devuan? Can it imitate systemd services management?
See here.
Description-en:
daemonless "systemctl" command to manage services without systemd "systemctl" is a replacement command to control system daemons without systemd. "systemctl" is useful in application containers where systemd is not available to start/stop services.This script can also be run as init of an application container (i.e. the main "CMD" on PID 1) where it will automatically bring up all enabled services in the "multi-user.target" and where it will reap all zombies from background processes in the container. When stopping such a container it will also bring down all configured services correctly before exit.
Best,
A.
Hello:
I have finally made progress with xarchiver and encryption.
For better or worse, the process of adding a password to protect a compressed file using xarchiver is not too at all intuitive.
To wit:
If you open PCManFM, point to select a file and right-click/select 'Compress ...' and save it, you get exactly that.
A compressed file.
/rant start
Now ...
Do you want an extra serving of password with that?
Forget it, not on the menu.
/rant end
You have to do it the proper way:
Step 1.
Open up the xarchiver application
Applications -> Accesories -> xarchiver
Archive -> New
Step 2.
Add a name, a location to save to and and hit 'Create'
You now you have an empty *.zip file* with a name and the xarchiver UI open.
* this provided you have chosen the default compression file type as zip in Preferences -> Preferred archive format.
Step 3.
Now ...
Action -> Add gets you the 'Add files' window where in the 'Selection' tab you can choose a file and whether to store full paths or not.
Right next to it is the 'Options' tab with the 'Actions' | 'Compression' | 'Encryption Options'.
The rest is straightforward.
Cannot imagine why pointing to select a file in PCManFM and right-clicking/selecting 'Compress ...' does not take you directly Step 3.
Maybe it is a PacManFM thing?
Right ...
Have you seen any evidence that xarchiver can do anything with encryption?
The answer is yes.
Pity that finding out how it had to be done proved to be an ordeal worthy of a much better cause.
But make no mistake, this may probably be the fastest/lightest and most versatile archiving utility for Linux.
It is mature and still works a wonder, which is why I have insisted on using it.
Problem solved.
Best,
A.
Hello:
... interesting for the larger community
Indeed.
https://docs.ceph.com/en/latest/start/o … endations/
the above claims ceph can use sysvinit or systemd
Does it?
Or is it open to interpretation?
... any distribution that includes a supported kernel and supported system startup framework ...Does the Daedalus kernel actually fit into that definition?
ie: is sysvinit a supported system startup framework for Debian?
the below says systemd is required for cephadm
https://docs.ceph.com/en/latest/cephadm/install/
Yes.
BUT at the top of the page it has a banner that reads:
This document is for a development version of Ceph.That said, maybe it is just showing, as with many other packages, the road to be taken as of sysvinit's demise?
Also see https://pkginfo.devuan.org/cgi-bin/pack … .2.11+ds-2
Package: cephadm
Version: 16.2.11+ds-2
--- snip ---
Depends:
adduser, lvm2, python3:any
--- snip ---
Description-en:
utility to bootstrap ceph daemons with systemd and containers
Ceph is a massively scalable, open-source, distributed
storage system that runs on commodity hardware and delivers object,
block and file system storage.
The cephadm utility is used to bootstrap a Ceph cluster and to manage
ceph daemons deployed with systemd and containers.According to the Devuan Package information page, there is no systemd dependency in that package.
Maybe there is some detail that our (overworked) Devuan maintainers missed.
Best,
A.
Hello:
No too bad!;
No ...
Not at all.
10. Devuan
If you are still a fan of the old sysvinit, then Devuan might ...
These dicks are mixing potatoes with oranges, with a marked tendency to patronise to boot.
"... still a fan of the old sysvinit ... "
Really? 8^°
Why not say it like it really is:
"If, like a great many Linux users out there, you are not fan of systemd then Devuan will ..."
Best,
A.
Hello:
Old time favourite Memtest86+ has just released version 7.0.
https://www.theregister.com/2024/01/11/ … _released/
Version 7.0 has gained the ability to interrogate the integrated memory controller in Intel Core PCs (first to 14th generations) to find live memory timing information, as well as some preliminary support for obtaining error correction code (ECC) info on some models of AMD Ryzen.
Best,
A.
Hello HB:
... examine the DNS entry for topoi.pooq.com from outside ...
I guess it is this:
~$ nslookup -type=A topoi.pooq.com
Non-authoritative answer:
Name: topoi.pooq.com
Address: 69.165.131.134~$ nslookup -type=MX topoi.pooq.com
Non-authoritative answer:
topoi.pooq.com mail exchanger = 4 b.mx.pooq.com.
topoi.pooq.com mail exchanger = 2 w.mx.pooq.com.~$ nslookup -type=NS topoi.pooq.com
Non-authoritative answer:
*** Can't find topoi.pooq.com: No answer
Authoritative answers can be found from:
pooq.com
origin = b.ns.pooq.com
mail addr = hostmaster.pooq.com
serial = 1703367291
refresh = 16384
retry = 2048
expire = 1048576
minimum = 2560If you need something other than that, let me know.
Best,
A.
Hello HB:
... look into the SMTP configuration of the laptop I pressed into service ...
... trouble sending to gmail as well ...
Ah ...
Config trouble.
Sorry to have bothered ...
No bother at all.
... will provide a success message when I finally do succeed.
Please do.
I'm sure we'll learn something new.
... yet to receive a bounce notice ...
... post again when I receive it.
I have still not received anything.
Probably by tomorrow, when 24hrs. have passed. (?)
Edit:
Seems posts crossed paths ...
... landed in moderation and I deleted it as you instructed ...
At least it did arrive so something else is broken ...
Best,
A.
Hello HB:
... list software examine the DNS information of the sender ...
... capable of *sending* me the usual stream ...
... my DNS information better for sending me a message ...
... does it check for an incoming message ...
Just a guess ...
Could it be that the dyne.org system/software checks the sender's credentials ie: registered, etc. and if not rejects the message?
To be able to reject it, it has to be able to reply to the sender's email address which is why you are getting the error message.
I have sent a test message from an email account that is not registered at dng[at]lists.dyne.org.
That was roughtly 30' ago and it has not yet appeared on the list of 'newest messages'.
That is something that usually happens within one or two minutes if I send a message from the usual email address.
I have yet to receive a bounce notice from the that other email provider.
I will post again when I receive it.
Best,
A.
Hello:
xarchiver is very fast, very lean and still works.
Seems I have made some progress ...
See this bug report against PCManFM from long ago, aparently overlooked:
https://bugs.debian.org/cgi-bin/bugrepo … bug=932461
ie: File -> Compress would not work in PCManFM 1.3.1-1
So I followed the workaround instructions and edited /usr/share/libfm/archivers.list:
[xarchiver]
# create=xarchiver --add-to %F # create command is wrong
create=xarchiver --compress %F
extract=xarchiver --extract %F
extract_to=xarchiver --extract-to %d %FNow compress works and I can choose from a boatload of file types.
Talk about options. 8^°
But still no joy with Action -> Enter password, which remains greyed out.
Cannot find any information on that.
Maybe I would have to see if there is a PCManFM backport for beowulf?
Best,
A.
Hello:
What's wrong with 7z
I have not looked at it, but I was looking for a front end to the applications I have installed.
Thanks for your input.
Best,
A.
Hello:
... was about to ask you the same ...
Ahh ...
I had a look but found more or less the same.
Not at all convinced for the same reason.
ie: bloat
xarchiver is very fast, very lean and still works.
Not many abandoned applications can say the same.
eg: WiCD
I then came across ib/xarchiver:
Seems it is a ... continuation of the Xfce master branch.
But not a fork? Rather confusing, at least for me.
https://www.linuxlinks.com/xarchiver-fr … ing-tools/
https://github.com/ib/xarchiver#readme
There is no .deb package so has to be compiled, something 'ordinary' Dev1ers such as I will have to get used to soon enough.
I'd appreciate it if you could have a look and let me know what you think.
Thanks in advance.
Best,
A.
Hello:
... any evidence that xarchiver can do anything with encryption?
Yes.
What I meant was encryption or password.
Sorry if I expressed myself incorrectly.
https://xarchiver.sourceforge.net/doc/ch04s02.html
For the time being, I made a *.pdf in Acrobat 7 (XPSP3 VM) with a strong password.
Edit:
It would seem that xarchiver is (and has been) definitely abandoned for the longest while.
There are open bugs from 2008 and then there is this:
https://sourceforge.net/p/xarchiver/bugs/97/#e700
Thank you for your email but Xarchiver is definitely abandoned as there are
better archivers out there.
Giuseppe Torelli is the author.
https://xarchiver.sourceforge.net/
Any suggestions for a small footprint front end like xarchiver?
Thanks in advance.
Best,
A.
Hello:
I am attempting to use xarchiver 0.5.4.14 to create an encrypted / password protected file containing a QR image but the application has no option for doing that, no matter what file extension I chose.
From what I can see, all dependencies are met.
I'd appreciate any pointers.
Thanks in advance.
Best,
A.
Hello:
Just got this in my inbox.
Things 'X11' continue to roll along steadily. 8^)
Best,
A.
----
Announce: xterm-389 - 2024/01/01
Files:
https://invisible-island.net/archives/x … rm-389.tgz
https://invisible-island.net/archives/x … 89.tgz.asc
https://invisible-island.net/archives/x … 9.patch.gz
https://invisible-island.net/archives/x … tch.gz.asc
https://invisible-island.net/archives/x … rm-389.tgz
https://invisible-island.net/archives/x … 89.tgz.asc
Patch #389 - 2024/01/01
* interchange variables in subparameter parsing, fixing a bug where
subparameters after the first parameter could be misidentified
(patch by Adam Saponara).
* correct popping of icon/window titles in a case where only one was
pushed from patch #385 changes.
* add XTQMODKEYS response in DECRQSS, as alternative for vim.
* correct DECCIR encoded information on character set size, handle a
VT525 quirk, and add DECST8C (Windows Terminal #14984).
* improve DECRQCRA (prompted by discussion with James Holderness,
Windows Terminal #14974).
* add part of VT525 color controls:
+ DECAC, to update default foreground/background, respond to
DECRQSS
+ DECATC, to respond with DECRQSS
* prevent Unicode non-characters from being printed (prompted by
patch by Grady Martin).
* modify send_SGR() to avoid modifying colors 16 to 255 in printed
output (patch by Grady Martin).
* minor cleanup of miscellaneous error-codes with ERROR_MISC.
* remove legacy CSI 53 for locator status, corrected in patch #294.
* modify DECRQUPSS and DECAUPSS feature to support VT5xx character
sets (report by Thomas Wolff).
* improve configure script:
+ reduce configure-check compiler warnings (prompted by Florian
Weimer, Redhat #2251945)
+ improve usage messages in configure script to make it clearer
when an option value is optional.
* improve EWMH handling (report/analysis by Edward Rosten)
+ reset _NET_WM_STATE_HIDDEN flag from _NET_WM_STATE before
mapping the window to deiconify.
+ cache X properties to reduce latency (adapted from patch by
Edward Rosten).
----
Hello:
.. fully admit his days are indeed numbered ...
It is an undeniable trait of humanity the failure to acknowledge that the days of each one of us are indeed numbered.
Eons go by and it remains the same, unchanged.
Literature of all kinds, from all ages, civilizations and beliefs attest to that.
So worry not and enjoy+thank life for the wonderful gift you have been bestowed.
Merry [fill in] and a Happy [fill in] for you and your father.
Best,
A.
Hello:
... 100yr-old father computing for another year
Great!
Good for you. 8^D
But ...
Why just another year?
... beowulf and evolution mail client version 3.30.5
And?
I use Devuan Beowulf on a backported kernel on a Sun U24 box from 2007 (Intel Q9550/8Gb).
~$ uname -a
Linux devuan 5.10.0-0.deb10.16-amd64 #1 SMP Debian 5.10.127-2~bpo10+1 (2022-07-28) x86_64 GNU/Linux
~$ Both the box and I run perfectly well, for the time being.
I have no need for Daedalus or one of those newfangled webmail clients (wft invented that crap, MS?).
I have used Pegasus Mail (POP3/SMTP) for the last 25+ years and don't plan to stop using it.
... hates any/all change ...
I can very easily relate to that.
And I still have 30 to go till I reach 100.
... thoughts?
My thoughts, YMMV:
I lost my father when he turned 82 back in 2010, would have turned 95 next June.
Your still having yours at 100 and using a computer is a luxury life is very generously gifting you with.
Learn to appreciate it
Bottom line?
Do not fuck around with a 100 year old chap's OS or email client.
Just do proper maintenance, help him out when needed and otherwise leave him and his box to their doings.
Best,
A.
Hello:
I have no intention of bringing such a controversial (and OT) subject to the forum.
So I will limit my comment to this and nothing more:
The laws of the market work.
Surely you jest ... 8^°
Or are totally unaware of what the 'market' and its supposed 'laws' have done to/with the world's economy since the early 80's.
A.
Hello:
I suggest you install xrestop to see exactly what is going on and maybe find the source of the issue.
https://www.freedesktop.org/wiki/Software/xrestop/
That said, do you by chance have conky running?
If so, it could be causing a memory leak.
Check here.
Best,
A.