IRC log for #devuan on 20161103

08:39.04aitorhi all
08:41.00aitorrrq: are you there?
08:44.31aitori'm doing some improvements on the packaging of Vdev
08:45.01aitori recommended to use an unique kernel when choosing between udev or vdev
08:45.19aitorthe default option for initramfs-tools is to regenerate the latest kernel version
08:45.32aitorthe argument -r is optional for update...
08:45.59aitorbut the use of "-k all" for the version string specifies update-initramfs to execute the chosen action for all kernel versions
08:46.07aitorso, one issue solved
08:46.47aitoron the other hand, i did another change in the vdev-initramfs script
08:47.42aitor"vdev-initramfs vdev" compares the installed version of libudev1 with 215-17+deb8u5
08:47.55aitorthat is, the version provided by the empty package libvdev
08:48.16aitorif they are different, then libudev1 and udev will be reinstalled, doing again the above comparison
08:50.24aitorif they are still different, then the version of libudev1 is higher than 215-17+deb8u5 and there is nothing to do
08:50.36aitorexiting with the following message:
08:50.52aitorecho "*** NOTE: libvdev provides libudev1-215-17+deb8u5, and the installed version is $version - The of libvdev is deprecated !! "
08:51.27aitordoing these two changes, there is no risk of breaking the system
09:00.31aitorneed to go
11:46.26*** join/#devuan rrq (
11:46.54*** join/#devuan kelsoo (~kelsoo@dragora/developer/kelsoo)
11:47.08rrqaitor: cheers. I've adopted "-k all".
11:47.58rrqaitor: slightly heistant about locking the competition control to the particular udev version though.
15:27.36*** join/#devuan aitor (
15:27.48aitorhi rrq
15:29.15aitori'm not sure to understand your hesitant attitude...
15:30.08aitorwhen a package provides another package, it provides a concrete version of this package
15:30.50aitorfor example, the following case is not valid:
15:31.27aitorProvides: libudev1 (>=215-17+deb8u5)
15:37.09aitoron the other hand, if you don't specify any version, it will not be usefull
15:49.37aitorfor example: gvfs depends on libudev1 (>=183)
15:52.06aitorand if you don't specify the version of the provided package, it'll not be higher than 183, neither lower, neither equal
15:54.34aitorsee you :)
16:38.54somerandomnickLooks like the security repository is now more than 45 hours behind.
16:44.20VenkerI'm a facing a problem regarding libcrypt, supposely inherited from a Debian bug
16:44.57Venkerthe cryptodisk isn't unmounting properly at shutdown and reboot
16:47.10Venkerand I don't find any logs in where it would this message be stored
17:29.57poogieall: evening, would anyone spare a minute or two on my newbie questions please?
17:30.37poogiejust need to decide what wm to pick...
17:40.20furrywolfthat is not an easy question.  everyone has opinions, generally very widely opposed.  I suggest icewm.  :)
17:41.34poogiefurrywolf: thanks. I was wondering if I it is feasible to use gnome on devuan, I mean future-wise as it seems getting more and more dependent on systemd
17:43.16furrywolfgnome sucks.  if it goes way, that's ok.  :P
17:43.25furrywolf(remember what I said about opinions...)
17:44.13poogieso most not-so-advanced users would stick with xface and those advanced ones with tilling wms...
17:44.25stevelittpoogie, your question is more ontopic on #debianfork. Go there, and I'll give you my opinion. #devuan is more for serious development discussions.
17:44.58poogieok stevelitt see you there
18:37.40somerandomnickI note right now #devuan is currently the only advertised channel for Devuan.
18:38.59somerandomnickOthers seem to read as of historic note, not necessarily in active use.
18:40.19fsmithreddebianfork is still active
20:24.14*** join/#devuan Besnik (
22:51.59somerandomnickOr did I get lucky and it updated a few minutes ago.  :-/
22:53.16somerandomnickNope, still an emergency situation (grr! brains, check things first).
23:00.51golinuxsomerandomnick: Yawn . . .
23:06.50gci_adminIs there a "zero day" of which I am unaware?
23:07.31somerandomnickNo, but once an exploit is out the update is too late.
23:09.38gci_adminSo there is a remote exploit for something you need to update? What is the exploit and the software that has this problem?
23:10.44somerandomnickBIND and tar have holes, while I'm not planning to do stupid stuff, that doesn't mean some luser isn't going to.
23:12.14gci_adminwonders ... when has BIND *not* had holes? ;)
23:13.55somerandomnickI believe it is currently better than Sendmail used to be, though yes it is pretty bad; this one looks to be DoS-only, but that is still a *problem*.
23:15.06gci_adminThe only thing I have seen about BIND lately is a possibility of a DoS. While that could suck, it does not imply one could do more with it from what I just read.
23:17.13gci_adminI cannot find anything about a current tar vulnerability. Do you have a CVE for that somerandomnick?
23:21.48gci_adminThe only thing I can find is a CVE about libarchive, which is used by tar and cpio. Is that the one you mean, somerandomnick?
23:26.51golinuxgci_admin: The sky is not falling
23:28.35somerandomnickWhich could be libarchive.
23:29.40somerandomnickHmm, not libarchive (though could be someone found a similar bug in both).
23:33.00gci_adminSounds the same to me based on this: "Flaws in libarchive's handling of symlinks and hard links allow overwriting files outside the extraction directory, or permission changes to a directory outside the extraction directory."
23:33.10gci_admingolinux, yeah, I know. ;)
23:33.53gci_adminis not too concerned about these flaws at this point
23:36.08gci_adminMeh, rereading these, they are not the same. But have similar problems.
