You are here

Agreguesi i feed

Michael Catanzaro: Don’t Forget: Unset Confidentiality on Private Issue Reports

Planet GNOME - Hën, 31/08/2026 - 9:21md

It’s hard to evaluate the security of open source projects when security bug reports remain private forever. Users deserve to see security bug reports, so please remember to unset issue report confidentiality when you’re done handling an issue. There are very few good reasons to keep an issue report confidential forever. If you’re not planning to disclose the issue report within the next few months, it should probably already already be public.

For GNOME, I disclose issues whenever a merge request has been created or a fix lands in the git repo, or 30 days after the issue was reported, whichever comes first. Your project might prefer to wait until the fix is released before disclosing, especially if you fear that a vulnerability might actually be exploited during the window between the fix and release. Whatever you choose, please don’t forget about it and leave the issue report confidential forever. That’s not fair to your project’s users. Even if not many people will take the time to look, users should at least have a chance to see reported issues.

Bank of England Chief Warns New AI Models Threaten Global Financial Stability

Slashdot - Hën, 31/08/2026 - 9:00md
Bank of England Governor Andrew Bailey is warning that advanced "frontier" AI models could materially increase cyber risk across the global financial system by making attacks faster, cheaper, and more scalable. In a letter to G20 finance officials, he said financial firms need stronger defenses and contingency plans for simultaneous disruptions. CNBC reports: Writing in his capacity as chair of the Financial Stability Board, an international body that coordinates policy and makes recommendations to national authorities, Bailey identified the potential impact of frontier AI -- which refers to the most advanced AI models -- on cyber risk as "the most immediate concern" for the financial system. "Frontier AI may have the ability materially to alter the speed, scale and economics of cyber risk, which could undermine market confidence system-wide, especially due to highly concentrated third-party service providers," Bailey said. "Recent developments have also highlighted to me that many jurisdictions do not have the protocols in place to manage the development, release, and deployment of advanced frontier AI models, heightening risks for the financial sector and beyond," he added. [...] Financial institutions and technology providers will need to improve vulnerability management, response and recovery capabilities -- "and prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies," Bailey said. Alongside new AI models, Bailey cited "fragilities" in sovereign debt markets, the growing use of debt by investors in equity markets and stretched asset valuations, particularly AI-related investments, as among his concerns.

Read more of this story at Slashdot.

Tim Cook's Last Day As CEO of Apple

Slashdot - Hën, 31/08/2026 - 8:00md
An anonymous reader quotes a report from 9to5Mac: Today is Tim Cook's last day as Apple CEO, with John Ternus set to take over tomorrow. To mark his last day in the role, Cook penned an emotional memo to Apple employees today. In the memo sent to employees this morning and obtained by 9to5Mac, Cook reflects on his time at Apple and thanks employees for all of their work. He also says he takes "enormous comfort in handing the helm to someone as brilliant and wonderful and capable" as John Ternus. "Few people understand what it takes to build products that change the world the way John does and I could not be more excited for his leadership," Cook writes. "There is something truly special about Apple," writes Cook. "I am most proud of what an annual report could never capture. This place is proof that culture triumphs over everything. We share a belief that what we build matters, and that we have both the opportunity and the responsibility to leave the world better than we found it. That purpose is part of what makes this place extraordinary. Apple helps nurture it, but I believe it lived within each of you long before you arrived here. It is what brought you to this company and what continues to drive the work you do every day." He continues: "Together, we have created something far greater than any one of us could have imagined or accomplished alone. And that's the secret to our success. We bring out the best in each other. We lift each other up. We have made it possible to leave our 'dent in the universe,' as Steve once described it, because of who we are and what we believe, because of what we value and how we see the world. How fortunate we are. How fortunate I am..." Cook also thanked the Apple community in a post on social media, writing: "Sending lots of love to the Apple community on my last day as CEO. My title changes tomorrow, but the love I have for the Apple community never will. Thank you for being a constant source of inspiration. My gratitude is endless, and I'm excited for the next chapter!"

Read more of this story at Slashdot.

MapQuest's App Surges to No. 1 In Navigation After Refusing to Rename Lake Ontario

Slashdot - Hën, 31/08/2026 - 7:00md
MapQuest's refusal to rename Lake Ontario as "Lake America" has sent its app surging up the charts, making it the No. 1 navigation app in the U.S. and driving "hundreds of thousands" of new downloads. In contrast, Google Maps announced on Saturday that it was complying with the Trump administration's name change. TechCrunch reports: The "OG of online mapping," as the company calls itself, announced on Thursday that it would not change the name of Lake Ontario on its maps to Lake America, despite Trump's executive order directing the U.S. Department of the Interior to update the lake's name in the U.S. geographic naming service. As a result, MapQuest's mobile app downloads soared, sending the iOS app to the No. 4 position on the U.S. App Store's Top Charts for apps (not including games) as of Monday morning on the U.S. east coast. MapQuest also reached the No. 8 position overall in the U.S. App Store across both apps and games, and it became the No. 1 Navigation app in the United States. In Canada's App Store, the app reached No. 2 overall as of Sunday evening. The 30-year-old company remarked that it received "hundreds of thousands" of new downloads since its decision to keep the name Lake Ontario in place, and saw its app's usage climb to 50 times above its normal levels. "We took the same approach we did with the Gulf of Mexico: be part of the conversation, and give people an app that keeps the names they're familiar with," said Doug Berger, general manager of MapQuest, in a statement. "Hundreds of thousands of people signaled to us this weekend that we got it right by downloading our app."

Read more of this story at Slashdot.

A 12TB Steam 'Teraleak' Spills More Than a Decade of Lost PC Gaming History

Slashdot - Hën, 31/08/2026 - 6:00md
A massive 12TB archive of old Steam2 content has surfaced online, apparently containing nearly every version of games uploaded to Valve's servers between 2003 and 2013, including unreleased prototypes, playtest builds, and cut content. Early discoveries include deleted Portal 2 material, files tied to Half-Life 2: Episode 3, and beta builds of games like Left 4 Dead 2, CS: GO, Spore, and Dragon Age: Origins. Researchers claim much of the material was once accessible through an unsecured public API. Ars Technica reports: The reason this weekend's leaked content cuts off abruptly in 2013 is because that's when Valve updated its content distribution system from "Steam2" to the current SteamPipe system. In moving from a proprietary file distribution format to standard HTTP file trees, the new system removed various update approval bottlenecks on Valve's end and streamlined update and patch downloads so they only reflected file differentials. Publicly accessible early versions of some games released before this SteamPipe transition had been considered lost content by archivists, no longer accessible from Valve itself and living on only as local downloads on aging machines. Apparently all that content wasn't as lost as many thought, though. Longtime Valve watcher and data miner Gabe Follower (previously) wrote on social media this weekend that he had "verified that everything in Steam2 Teraleak was obtained via a publicly accessible [API] endpoint. It's Valve's fault..." Spanish-language Valve streamer and analyst Scolcer also said on social media (via machine translation) that the teraleak was "obtained from a site that was 100% accessible to the public. It was there for everyone to download. No passwords. Nothing. Hidden in plain sight, but with no protection whatsoever." What's unclear right now if that API and publicly available Steam2 server content were accessed recently or if this weekend's leak represents content that was privately archived before the 2013 server transition and is just now being made public. "It could more-so be a collection of different people that knew about it and accumulated whatever people had downloaded back then into this massive archive," said The One Epicplayer, a moderator on the Valve Cut Content (VCC) Discord, which has long followed Valve betas and leaks. "I haven't been filled in on the full details but my suspicion is that these depot [files] were downloaded a long time ago and sat in a private collection," CrazyBubba, another VCC Discord moderator, told Ars. "There were a lot of leaks a few years back and many folks hoarded files for years. ... historically there have been issues with people lording content over other members." A readme file included with the leak offers "warm n good wishes to all hoarders who had stuff from this collection" and encourages users to mirror and share it as widely as possible. On the VCC Discord, a user purporting to be the original uploader of the teraleak (who offered screenshots of a 22TB server upload log among their evidence) wrote that "getting this out really took a significant amount of effort from me and I would like it if it didn't go to waste."

Read more of this story at Slashdot.

next-20260831: linux-next

Kernel Linux - Hën, 31/08/2026 - 5:43md
Version:next-20260831 (linux-next) Released:2026-08-31

Berlin Is Being Blackmailed By Hackers

Slashdot - Hën, 31/08/2026 - 5:00md
An anonymous reader quotes a report from the BBC: Berlin is being blackmailed by hackers who were able to compromise city systems and steal data earlier this month, its mayor has said. Kai Wegner said officials would not cave in to the ransom demand, which came on Thursday evening. He did not say how much was being sought, though Der Spiegel reports the hackers are demanding 30 bitcoin, worth around 2 million euros. Some of the German capital's online systems were forced to close down as a result of the attack, while investigators were working to understand what data had been taken. The Rhysida group, which is thought to operate from Russia and eastern Europe, and was behind a previous attack on the British Museum, has reportedly taken responsibility. It has said on its website it intends to begin auctioning the 5.79 terabytes of data it was able to steal from Berlin in seven days' time, according to news agency Reuters. [...] Officials for the city-state said an initial data leak occurred between August 7 and 12. Then, on August 14, two department networks were shut down, making applications for housing benefits and payments impossible for several days. "Berlin will not be blackmailed," Wegner said on Friday. He said state police, prosecutors and federal security services were working to investigate the suspected perpetrators "with the utmost urgency," adding that inquiries into the "content and scope of the compromised data are being pursued with great intensity."

Read more of this story at Slashdot.

Thibault Martin: TIL that Deleting files is better than hoarding them

Planet GNOME - Hën, 31/08/2026 - 2:00md

I realized that deleting local copies of files early and often is better than keeping them forever.

I'm the kind of person who will work on something, share their work, and then just let the file I had linger around indefinitely. You never know, it's better to have a local copy, it can save the day. Or you keep it at hand when you're offline. And do I really need a reason to keep a copy of the file I was working on anyway? Hoarding files and keeping them forever is tempting.

The one thing I've overlook in the past is context. When I produce or get a file, I do so in a specific context. But if I want to do some cleanup later I will certainly have lost that context, or have fragments of it. I won’t know if I can delete it safely or not, so I will keep it forever. The longer a file has been around, the more difficult it becomes to delete it.

The best thing I can do in a work context is to make it not a me-problem. Whenever I get or produce a file, I make sure there is a copy of it in a company shared drive, and I delete it from my machine as soon as possible.

Throwing it over the fence is bad behavior of course, so I make sure it’s stored somewhere with as much context as possible for people who need to use it. My machine stays decluttered, and if it’s stolen I "just" lose hardware, I have a safe copy of my work data, and there is little to leak on my (encrypted) disk.

Note: this is true for documents because all versioning systems are terrible. This is not true for code thanks to git and the like.

California's Age Verification Bill Passes with Linux Exemption Intact

Slashdot - Hën, 31/08/2026 - 1:34md
California's age-verification bill has passed in its legislature — but with its open-source carve-out intact, reports the blog Linuxiac: Back in May, we reported that California lawmakers amended Assembly Bill 1856 to carve open-source operating systems out of the state's upcoming age verification requirements. Three months later, that exemption survived the legislative process intact, and the bill has cleared both chambers of the California Legislature... sending the measure to Engrossing and Enrolling, the final legislative preparation stage before it can be presented to Governor Gavin Newsom... For operating systems that are covered, AB 1856 builds on California's Digital Age Assurance Act, which is scheduled to take effect on January 1, 2027. Under the current text, when an operating system runs on a device and includes an account setup feature, its provider must offer an interface that asks the account holder for the birth date, age, or both, of the device's primary user during account setup. The operating system must then be capable of providing a digital age signal to covered application stores and application developers through a reasonably consistent real-time API. Instead of exposing a precise birth date, the signal identifies one of four age ranges: under 13, 13 through 15, 16 through 17, or 18 and older... Covered application stores must request the signal from the operating system and make it available to developers.

Read more of this story at Slashdot.

Felipe Borges: Modernizing Fingerprint Management in GNOME Settings

Planet GNOME - Hën, 31/08/2026 - 11:57pd

For a while now, the fingerprint management UI in GNOME Settings (gnome-control-center) has felt outdated. While it worked, the layout and enrollment flow hadn’t kept up with the rest of GNOME’s modern interface updates.

I am happy that during the GNOME 51 development cycle we managed to address that. Allan Day, Marco Trevisan, and myself worked on modernizing the interface. There’s still more work to do in the UI and in fprintd, but what we will ship in 51 is already a great step forward.

Historically, the fingerprint dialog in User Settings was stuck on a GTK3-style design. Even after being ported to GTK4, conceptually it remained unchanged. Beyond looking out of place alongside Libadwaita-based settings panels, it suffered from responsiveness and accessibility issues that made it difficult for some users to enroll their prints.

Screenshot of the Fingerprint Authentication dialog

The new fingerprint management dialog uses a standard boxed list displaying your enrolled fingers. From here, each enrolled finger can be removed individually.

Clicking the “Add Fingerprint” button starts the finger enrollment process. First, you choose one of the unused finger options to enroll. From there, an assistant guides you through the scanning process. As you place your finger on the reader, the UI detects the touch and provides feedback on whether it was read correctly. You continue touching the reader until enough samples have been collected (the exact number depends on your reader’s driver). Once the progress bar fills, your finger is ready for authentication.

Screenshot of a fingerprint enrollment

This is only one of the improvements that GNOME 51 is bringing. As with everything in GNOME, we will continue gathering user feedback and making iterations over time. There are already more fingerprint features in the pipeline, such as renaming enrolled fingers and verifying individual prints. Stay tuned!

KubeCap Finds Excess Linux Capabilities in Kubernetes Workloads

LinuxSecurity.com - Pre, 28/08/2026 - 9:45md
A Kubernetes workload can run with more Linux capabilities than its code needs. When capability settings are missing or broad, that excess authority may remain invisible because the application still works.

Linux Kernel 7.1-rc5 Tracing Reader Use-After-Free Bug Discovery

LinuxSecurity.com - Pre, 28/08/2026 - 9:15md
Removing a Linux trace instance should end its lifetime. An open tracefs reader can currently keep using that instance after another task removes it, creating a kernel use-after-free path in the tracing subsystem.

eBPF Security Research Adds State-Aware Syscall Filtering

LinuxSecurity.com - Pre, 28/08/2026 - 9:05md
A Linux service may need broad system-call access while it starts, then only a smaller set while it handles requests. A single policy loaded before startup often has to keep every required call available for the service's entire lifetime.

Looking for the artwork for Trixie the next Debian release

Bits from Debian - Pre, 21/06/2024 - 12:00md

Each release of Debian has a shiny new theme, which is visible on the boot screen, the login screen and, most prominently, on the desktop wallpaper. Debian plans to release Trixie, the next release, next year. As ever, we need your help in creating its theme! You have the opportunity to design a theme that will inspire thousands of people while working in their Debian systems.

For the most up to date details, please refer to the wiki.

We would also like to take this opportunity to thank Juliette Taka Belin for doing the Emerald theme for bookworm.

The deadlines for submissions is: 2024-09-19

The artwork is usually picked based on which themes look the most:

  • ''Debian'': admittedly not the most defined concept, since everyone has their own take on what Debian means to them.
  • ''plausible to integrate without patching core software'': as much as we love some of the insanely hot looking themes, some would require heavy GTK+ theming and patching GDM/GNOME.
  • ''clean / well designed'': without becoming something that gets annoying to look at a year down the road. Examples of good themes include Joy, Lines, Softwaves and futurePrototype.

If you'd like more information or details, please post to the Debian Desktop mailing list.

New Debian Developers and Maintainers (March and April 2024)

Bits from Debian - Pre, 31/05/2024 - 6:00md

The following contributors got their Debian Developer accounts in the last two months:

  • Patrick Winnertz (winnie)
  • Fabian Gruenbichler (fabiang)

The following contributors were added as Debian Maintainers in the last two months:

  • Juri Grabowski
  • Tobias Heider
  • Jean Charles Delépine
  • Guilherme Puida Moreira
  • Antoine Le Gonidec
  • Arthur Barbosa Diniz

Congratulations!

Bits from the DPL

Bits from Debian - Enj, 02/05/2024 - 3:00pd

Hi,

Keeping my promise for monthly bits, here's a quick snapshot of my first ten days as DPL.

Special thanks to Jonathan for an insightful introduction that left less room for questions. His introduction covered my first tasks like expense approval and CTTE member appointments thoroughly. Although I made a visible oversight by forgetting to exclude Simon McVittie <smcv> from the list, whose term has ended , I'm committed to learning from this mistake. In future I'll prioritize thorough proofreading to ensure accuracy.

Part of my "work" was learning what channels I need to subscribe and adjust my .procmailrc and .muttrc took some time.

Recently I had my first press interview. I had to answer a couple of prepared questions for Business IT News. It seems journalists are always on the lookout for unique angles. When asked if humility is a new trait for DPLs, my response would be a resounding "No." In my experience, humility is a common quality among DPLs I've encountered, including Jonathan.

One of my top priorities is reaching out to all our dedicated and appointed teams, including those managing critical infrastructure. I've begun with the CTTE, Salsa Admins and Debian Snapshot. Everything appears to be in order with the CTTE team. I'm waiting for response from Salsa and Snapshot, which is fine given the recent contact.

I was pointed out to the fact that lintian is in an unfortunate state as Axel Beckert confirmed on the lintian maintainers list. It turns out that bug #1069745 of magics-python should not have been undetected for a long time if lintian bug #677078 would have been fixed. It seems obvious to me that lintian needs more work to fulfill its role as reliably policy checker to ensure our high level of packaging quality.

In any case thanks a lot to Axel who is doing his best but it seems urgent to me to find some more person-power for this task. Any volunteer to lend some helping hand in the lintian maintainers team?

On 2024-04-30 I gave my first talk "Bits from greenhorn DPL" online at MiniDebConf Brasil in Belo Horizonte. The Q&A afterwards stired some flavours of the question: "What can Debian Brasil do better?" My answer was always in a way: Given your great activity in now organising the fifth MiniDebConf you are doing pretty well and I have no additional hints for the moment.

Kind regards Andreas.

Debian welcomes the 2024 GSOC contributors/students

Bits from Debian - Mër, 01/05/2024 - 11:56md

We are very excited to announce that Debian has selected seven contributors to work under mentorship on a variety of projects with us during the Google Summer of Code.

Here are the list of the projects, students, and details of the tasks to be performed.

Project: Android SDK Tools in Debian

  • Student: anuragxone

Deliverables of the project: Make the entire Android toolchain, Android Target Platform Framework, and SDK tools available in the Debian archives.

Project: Benchmarking Parallel Performance of Numerical MPI Packages

  • Student: Nikolaos

Deliverables of the project: Deliver an automated method for Debian maintainers to test selected numerical Debian packages for their parallel performance in clusters, in particular to catch performance regressions from updates, and to verify expected performance gains, such as Amdahl’s and Gufstafson’s law, from increased cluster resources.

Project: Debian MobCom

  • Student: Nathan D

Deliverables of the project: Update the outdated mobile packages and recreate aged packages due to new dependencies. Bring in more mobile communication tools by adding about 5 new packages.

Project: Improve support of the Rust coreutils in Debian

  • Student: Sreehari Prasad TM

Deliverables of the project: Make uutils behave more like GNU’s coreutils by improving compatibility with GNU coreutils test suit.

Project: Improve support of the Rust findutils in Debian

  • Student: hanbings

Deliverables of the project: A safer and more performant implementation of the GNU suite's xargs, find, locate and updatedb tools in rust.

Project: Expanding ROCm support within Debian and derivatives

  • Student: xuantengh

Deliverables of the project: Building, packaging, and uploading missing ROCm software into Debian repositories, starting with simple tools and progressing to high-level applications like PyTorch, with the final deliverables comprising a series of ROCm packages meeting community quality assurance standards.

Project: procps: Development of System Monitoring, Statistics and Information Tools in Rust

  • Student: Krysztal Huang

Deliverables of the project: Improve the usability of the entire Rust-based implementation of the procps utility on Linux.

Congratulations and welcome to all the contributors!

The Google Summer of Code program is possible in Debian thanks to the efforts of Debian Developers and Debian Contributors that dedicate part of their free time to mentor contributors and outreach tasks.

Join us and help extend Debian! You can follow the contributors' weekly reports on the [debian-outreach mailing-list][debian-outreach-ml], chat with us on our [IRC channel][debian-outreach-irc] or reach out to the individual projects' team mailing lists.

[debian-outreach-ml]: http://lists.debian.org/debian-outreach/ (debian-outreach AT lists.debian.org) [debian-outreach-irc]: irc://irc.debian.org/debian-outreach (#debian-outreach on irc.debian.org)

Infomaniak Platinum Sponsor of DebConf24

Bits from Debian - Mër, 01/05/2024 - 12:08md

We are pleased to announce that Infomaniak has committed to sponsor DebConf24 as a Platinum Sponsor.

Infomaniak is an independent cloud service provider recognised throughout Europe for its commitment to privacy, the local economy and the environment. Recording growth of 18% in 2023, the company is developing a suite of online collaborative tools and cloud hosting, streaming, marketing and events solutions.

Infomaniak uses exclusively renewable energy, builds its own data centers and develops its solutions in Switzerland at the heart of Europe, without relocating. The company powers the website of the Belgian radio and TV service (RTBF) and provides streaming for more than 3,000 TV and radio stations in Europe.

With this commitment as Platinum Sponsor, Infomaniak is contributing to the Debian annual Developers' conference, directly supporting the progress of Debian and Free Software. Infomaniak contributes to strengthen the community that collaborates on Debian projects from all around the world throughout all of the year.

Thank you very much, Infomaniak, for your support of DebConf24!

Become a sponsor too!

DebConf24 will take place from 28th July to 4th August 2024 in Busan, South Korea, and will be preceded by DebCamp, from 21st to 27th July 2024.

DebConf24 is accepting sponsors! Interested companies and organizations should contact the DebConf team through sponsors@debconf.org, or viisit the DebConf24 website at https://debconf24.debconf.org/sponsors/become-a-sponsor/.

Debian Project Leader Election 2024, Andreas Tille elected.

Bits from Debian - Hën, 22/04/2024 - 2:00md

The voting period for the Debian Project Leader election has ended. Please join us in congratulating Andreas Tille as the new Debian Project Leader.

The new term for the project leader started on 2024-04-21.

369 of 1,010 Debian Developers voted using the Condorcet method.

More information about the results of the voting are available on the Debian Project Leader Elections 2024 page.

Many thanks all of our Developers for voting.

apt install dpl-candidate: Andreas Tille

Bits from Debian - Pre, 05/04/2024 - 8:36md

The Debian Project Developers will shortly vote for a new Debian Project Leader known as the DPL.

The Project Leader is the official representative of The Debian Project tasked with managing the overall project, its vision, direction, and finances.

The DPL is also responsible for the selection of Delegates, defining areas of responsibility within the project, the coordination of Developers, and making decisions required for the project.

Our outgoing and present DPL Jonathan Carter served 4 terms, from 2020 through 2024. Jonathan shared his last Bits from the DPL post to Debian recently and his hopes for the future of Debian.

Recently, we sat with the two present candidates for the DPL position asking questions to find out who they really are in a series of interviews about their platforms, visions for Debian, lives, and even their favorite text editors. The interviews were conducted by disaster2life (Yashraj Moghe) and made available from video and audio transcriptions:

  • Andreas Tille [this document]
  • Sruthi Chandran [Interview]

Voting for the position starts on April 6, 2024.

Editors' note: This is our official return to Debian interviews, readers should stay tuned for more upcoming interviews with Developers and other important figures in Debian as part of our "Meet your Debian Developer" series. We used the following tools and services: Turboscribe.ai for the transcription from the audio and video files, IRC: Oftc.net for communication, Jitsi meet for interviews, and Open Broadcaster Software (OBS) for editing and video. While we encountered many technical difficulties in the return to this process, we are still able and proud to present the transcripts of the interviews edited only in a few areas for readability.

2024 Debian Project Leader Candidate: Andrea Tille

Andreas' Interview

Who are you? Tell us a little about yourself.

[Andreas]:

How am I? Well, I'm, as I wrote in my platform, I'm a proud grandfather doing a lot of free software stuff, doing a lot of sports, have some goals in mind which I like to do and hopefully for the best of Debian.

And How are you today?

[Andreas]:

How I'm doing today? Well, actually I have some headaches but it's fine for the interview.

So, usually I feel very good. Spring was coming here and today it's raining and I plan to do a bicycle tour tomorrow and hope that I do not get really sick but yeah, for the interview it's fine.

What do you do in Debian? Could you mention your story here?

[Andreas]:

Yeah, well, I started with Debian kind of an accident because I wanted to have some package salvaged which is called WordNet. It's a monolingual dictionary and I did not really plan to do more than maybe 10 packages or so. I had some kind of training with xTeddy which is totally unimportant, a cute teddy you can put on your desktop.

So, and then well, more or less I thought how can I make Debian attractive for my employer which is a medical institute and so on. It could make sense to package bioinformatics and medicine software and it somehow evolved in a direction I did neither expect it nor wanted to do, that I'm currently the most busy uploader in Debian, created several teams around it.

DebianMate is very well known from me. I created the Blends team to create teams and techniques around what we are doing which was Debian TIS, Debian Edu, Debian Science and so on and I also created the packaging team for R, for the statistics package R which is technically based and not topic based. All these blends are covering a certain topic and R is just needed by lots of these blends.

So, yeah, and to cope with all this I have written a script which is routing an update to manage all these uploads more or less automatically. So, I think I had one day where I uploaded 21 new packages but it's just automatically generated, right? So, it's on one day more than I ever planned to do.

What is the first thing you think of when you think of Debian?

Editors' note: The question was misunderstood as the “worst thing you think of when you think of Debian”

[Andreas]:

The worst thing I think about Debian, it's complicated. I think today on Debian board I was asked about the technical progress I want to make and in my opinion we need to standardize things inside Debian. For instance, bringing all the packages to salsa, follow some common standards, some common workflow which is extremely helpful.

As I said, if I'm that productive with my own packages we can adopt this in general, at least in most cases I think. I made a lot of good experience by the support of well-formed teams. Well-formed teams are those teams where people support each other, help each other.

For instance, how to say, I'm a physicist by profession so I'm not an IT expert. I can tell apart what works and what not but I'm not an expert in those packages. I do and the amount of packages is so high that I do not even understand all the techniques they are covering like Go, Rust and something like this.

And I also don't speak Java and I had a problem once in the middle of the night and I've sent the email to the list and was a Java problem and I woke up in the morning and it was solved. This is what I call a team. I don't call a team some common repository that is used by random people for different packages also but it's working together, don't hesitate to solve other people's problems and permit people to get active.

This is what I call a team and this is also something I observed in, it's hard to give a percentage, in a lot of other teams but we have other people who do not even understand the concept of the team. Why is working together make some advantage and this is also a tough thing. I [would] like to tackle in my term if I get elected to form solid teams using the common workflow. This is one thing.

The other thing is that we have a lot of good people in our infrastructure like FTP masters, DSA and so on. I have the feeling they have a lot of work and are working more or less on their limits, and I like to talk to them [to ask] what kind of change we could do to move that limits or move their personal health to the better side.

The DPL term lasts for a year, What would you do during that you couldn't do now?

[Andreas]:

Yeah, well this is basically what I said are my main issues. I need to admit I have no really clear imagination what kind of tasks will come to me as a DPL because all these financial issues and law issues possible and issues [that] people who are not really friendly to Debian might create. I'm afraid these things might occupy a lot of time and I can't say much about this because I simply don't know.

What are three key terms about you and your candidacy?

[Andreas]:

As I said, I like to work on standards, I’d like to make Debian try [to get it right so] that people don't get overworked, this third key point is be inviting to newcomers, to everybody who wants to come. Yeah, I also mentioned in my term this diversity issue, geographical and from gender point of view. This may be the three points I consider most important.

Preferred text editor?

[Andreas]:

Yeah, my preferred one? Ah, well, I have no preferred text editor. I'm using the Midnight Commander very frequently which has an internal editor which is convenient for small text. For other things, I usually use VI but I also use Emacs from time to time. So, no, I have not preferred text editor. Whatever works nicely for me.

What is the importance of the community in the Debian Project? How would like to see it evolving over the next few years?

[Andreas]:

Yeah, I think the community is extremely important. So, I was on a lot of DebConfs. I think it's not really 20 but 17 or 18 DebCons and I really enjoyed these events every year because I met so many friends and met so many interesting people that it's really enriching my life and those who I never met in person but have read interesting things and yeah, Debian community makes really a part of my life.

And how do you think it should evolve specifically?

[Andreas]:

Yeah, for instance, last year in Kochi, it became even clearer to me that the geographical diversity is a really strong point. Just discussing with some women from India who is afraid about not coming next year to Busan because there's a problem with Shanghai and so on. I'm not really sure how we can solve this but I think this is a problem at least I wish to tackle and yeah, this is an interesting point, the geographical diversity and I'm running the so-called mentoring of the month.

This is a small project to attract newcomers for the Debian Med team which has the focus on medical packages and I learned that we had always men applying for this and so I said, okay, I dropped the constraint of medical packages.

Any topic is fine, I teach you packaging but it must be someone who does not consider himself a man. I got only two applicants, no, actually, I got one applicant and one response which was kind of strange if I'm hunting for women or so.

I did not understand but I got one response and interestingly, it was for me one of the least expected counters. It was from Iran and I met a very nice woman, very open, very skilled and gifted and did a good job or have even lose contact today and maybe we need more actively approach groups that are underrepresented. I don't know if what's a good means which I did but at least I tried and so I try to think about these kind of things.

What part of Debian has made you smile? What part of the project has kept you going all through the years?

[Andreas]:

Well, the card game which is called Mao on the DebConf made me smile all the time. I admit I joined only two or three times even if I really love this kind of games but I was occupied by other stuff so this made me really smile. I also think the first online DebConf in 2020 made me smile because we had this kind of short video sequences and I tried to make a funny video sequence about every DebConf I attended before. This is really funny moments but yeah, it's not only smile but yeah.

One thing maybe it's totally unconnected to Debian but I learned personally something in Debian that we have a do-ocracy and you can do things which you think that are right if not going in between someone else, right? So respect everybody else but otherwise you can do so.

And in 2020 I also started to take trees which are growing widely in my garden and plant them into the woods because in our woods a lot of trees are dying and so I just do something because I can. I have the resource to do something, take the small tree and bring it into the woods because it does not harm anybody. I asked the forester if it is okay, yes, yes, okay. So everybody can do so but I think the idea to do something like this came also because of the free software idea. You have the resources, you have the computer, you can do something and you do something productive, right? And when thinking about this I think it was also my Debian work.

Meanwhile I have planted more than 3,000 trees so it's not a small number but yeah, I enjoy this.

What part of Debian would you have some criticisms for?

[Andreas]:

Yeah, it's basically the same as I said before. We need more standards to work together. I do not want to repeat this but this is what I think, yeah.

What field in Free Software generally do you think requires the most work to be put into it? What do you think is Debian's part in the field?

[Andreas]:

It's also in general, the thing is the fact that I'm maintaining packages which are usually as modern software is maintained in Git, which is fine but we have some software which is at Sourceport, we have software laying around somewhere, we have software where Debian somehow became Upstream because nobody is caring anymore and free software is very different in several things, ways and well, I in principle like freedom of choice which is the basic of all our work.

Sometimes this freedom goes in the way of productivity because everybody is free to re-implement. You asked me for the most favorite editor. In principle one really good working editor would be great to have and would work and we have maybe 500 in Debian or so, I don't know.

I could imagine if people would concentrate and say five instead of 500 editors, we could get more productive, right? But I know this will not happen, right? But I think this is one thing which goes in the way of making things smooth and productive and we could have more manpower to replace one person who's [having] children, doing some other stuff and can't continue working on something and maybe this is a problem I will not solve, definitely not, but which I see.

What do you think is Debian's part in the field?

[Andreas]:

Yeah, well, okay, we can bring together different Upstreams, so we are building some packages and have some general overview about similar things and can say, oh, you are doing this and some other person is doing more or less the same, do you want to join each other or so, but this is kind of a channel we have to our Upstreams which is probably not very successful.

It starts with code copies of some libraries which are changed a little bit, which is fine license-wise, but not so helpful for different things and so I've tried to convince those Upstreams to forward their patches to the original one, but for this and I think we could do some kind of, yeah, [find] someone who brings Upstream together or to make them stop their forking stuff, but it costs a lot of energy and we probably don't have this and it's also not realistic that we can really help with this problem.

Do you have any questions for me?

[Andreas]:

I enjoyed the interview, I enjoyed seeing you again after half a year or so. Yeah, actually I've seen you in the eating room or cheese and wine party or so, I do not remember we had to really talk together, but yeah, people around, yeah, for sure. Yeah.


Faqet

Subscribe to AlbLinux agreguesi