/srv/irclogs.ubuntu.com/2008/06/12/#ubuntu-x.txt

jcristaukees: actually, i think it doesn't matter. if width*height overflows, you don't really know if the error value is height or width00:26
jcristauso choosing width makes as much sense as the other one00:26
keesjcristau: heh, yeah, fair point00:38
jcristaukees: you had me worried for a while ;)00:39
tjaalton"GEM merging to master"...09:24
tjaaltonbryce: btw, should we branch xorg/xorg-server for hardy?19:11
tjaaltonand merge the current branch with experimental19:11
bryceperhaps, although I'm not sure if we'll have a lot of changes for the hardy xserver19:13
bryce(I also find having to give my password 3x to do a git pull to be irritating, but anyway) :-)19:14
brycemerging the current branch with experimental is a good idea19:14
bryceat yesterday's meeting, doko and slangasek were talking about giving MoM an ability to do merges of not just Unstable, but also the option of Testing and Experimental.  But I'm guessing that'll be a while.19:15
tjaaltonput an RSA key there, DSA keys don't work :)19:15
brycewell I don't think I can ssh in anyway19:16
tjaaltonto alioth? you should be able to19:16
tjaaltonyou can add the key from the web interface19:17
bryceah ok19:17
brycelast I tried was a couple weeks ago, maybe things have changed19:17
bryceyeah it just hangs.  I'll try the web interface19:19
tjaaltonhmm that's weird, mine keeps asking for the password without a key19:20
tjaaltontseliot: I haven't had a chance to look at the package yet :/19:27
Q-FUNKhowdy20:06
Q-FUNKhas there been any report of the -intel that just entered hardy-updates disturbing suspend/hibernate?20:06
Q-FUNKboth pm-utils and -intel received new packages over the last couple of days.20:07
bryceheya Q-FUNK20:08
Q-FUNKheya :)20:08
tseliottjaalton:no problem, superm1 reported a few problems but I haven't had the time to fix them today20:10
bryceQ-FUNK: btw yesterday I was looking again at the -geode pci id fix to xserver and noticed the patch wasn't actually enabled20:22
bryceQ-FUNK: it's enabled properly on intrepid though.  Have you had a chance to test against intrepid?20:22
Q-FUNKhm?!20:23
Q-FUNKnot enabled?20:23
Q-FUNKoh, to x server20:23
Q-FUNKyes, it turns out that debian completely skips xf86config and instead uses the pic id provided by each driver20:24
Q-FUNKat least, that's how it appears to me20:24
brycesounds right20:24
Q-FUNK(others are welcome to correct me if I'm wrong)20:24
bryceok, so the patch in ubuntu9.1 is irrelevant?20:24
Q-FUNKprobably20:25
bryceyeah that sounds right to me20:25
bryceok cool, I'll update the sru request20:25
Q-FUNKI haven't entirely figured out whether debian completely skips the content of that file or wheter it complements it with the driver.ids that comes in each chip driver20:25
Q-FUNKjcristau probably knows better than me, on that issue20:26
Q-FUNKas for the -nsc fix, pitti pointed out that he'd rather have someone figure out a way to revert the Makefile.am patch that generates nsc.ids and replace it with my static list, rather than accept my completely overhauled package20:27
Q-FUNKI guess it makes sense.  the delta would be a lot smaller.20:27
Q-FUNKwhoever manages to do it, we can also contribute it to debian.  it would save bgoglin the trouble of figuring out how to do this on his way back from vacations.20:28
bryceQ-FUNK: ok, then sounds like there should be new bugs opened for those two issues20:36
Q-FUNKfor -geode, though, we pretty much have to move forward and adopt what I have in my PPA as-is.  trying to force-fit the update into the 2.8.0 packaging paradigm won't work.20:43
Q-FUNKand we cannot upload this without the fixed -nsc being uploaded first, becuase of the versioned conflit20:44
brycehmm, in that case maybe it just can't be sru'd to hardy at all20:45
Q-FUNKpitti tells me that it might be a though case.  however, either we do it or we end up with a broken LTSP in LTS for the next 3 years.20:47
Q-FUNKand yes, moving those symbolic links to the transtional -amd package is the only clean way to do this20:47
bryce-geode uploaded20:49
Q-FUNKerm..... which one?20:49
brycethe one in your ppa20:50
Q-FUNKif we don't first upload the fixed -nsc, we actually break what little operativity we had20:50
bryceI'm doing that one next20:50
Q-FUNKthe -geode in my PPA depends upon the fixed -nsc having been uploaded first20:50
bryceit seemed to build fine20:52
Q-FUNKyup, but it deviates from the XSF framework, which is why pitti found it totally unacceptable as an SRU20:52
brycehowso does it deviate?20:52
bryceok, -nsc built... uploading20:53
bryceok uploaded20:53
Q-FUNKdebian has the same reservations about my cdbs-based refactoring, which is why both pitti and bgoglin would prefer simply removing the makefile.am patch and replacing it with a simple install of the static nsc.ids I produced20:53
keesbryce: can you confirm on i386 that the DBE-DoS PoC is fixed in intrepid?  so far it's unfixed for me in hardy and gutsy.20:54
brycewhoops, you had hardy listed there... need to set that to intrepid20:54
keesjcristau: did you confirm that DBE-DoS was fixed in your builds?  I'm still seeing a DoS with it20:54
bryceQ-FUNK: ok well once you have that let me know and we can re-upload the fixed version to intrepid20:55
brycekees: unfortunately my intrepid testing box is amd6420:56
brycekees: (at your recommendation ironically enough ;-))20:56
bryceooh, new -ati release20:56
bryceerf, first need to finish up the -intel 2.3.1 upload though...20:57
keesbryce: sure, but you can run an i386 kvm on it, yes?20:57
brycedunno, I don't have kvm set up on it at all20:57
brycekees: anyway since we're running the same version of xserver, if you can't verify it on hardy it almost certainly is also busted on intrepid.20:58
keesbryce: well it seems that the DBE stuff isn't fixed, so I'd like to figure out how to get it fixed.20:58
keesbryce, jcristau: err... it seems actually that there was no fix made for the DBE stuff?21:05
brycekees, hrm, I'm not sure what I could do to help there21:05
bryceI'm not sure what you mean by 'DBE'.  There isn't a reference to "DBE" in the advisory?21:12
keesbryce: yeah, that's what I'm seeing too.  Perhaps it was skipped for now?21:12
keesI'll assume so, and get these updates tested for regressions.21:12
brycewell, what is DBE?21:13
keeseverything else looks great in them -- all the PoCs fail now.  :)21:13
keesnotes in the PoC say: DOUBLE-BUFFER extension21:13
bryceok maybe jcristau knows more21:21
keesyeah, I assume it's an unaddressed issue.21:25
=== mnem0 is now known as mnemo
jcristaukees: the dbe dos wasn't considered a security problem23:18
keesjcristau: okay, cool.  it certainly is a DoS though.  ;)  owchy on my VMs23:20
keesfilled / before I figured out what was going on.  hehe23:20
jcristauheh23:21
jcristauthe fix on master is at http://cgit.freedesktop.org/xorg/xserver/commit/?id=23e71ef71a178505494d4b410f9314acfff8152423:23
jcristaubut, it won't apply directly on previous versions, and when an attacker has access to your x server you have other problems anyway23:23
keesjcristau: yeah, I'm fine with that getting skipped.  :)23:25

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!