Fedora 15 updates-testing report

updates at fedoraproject.org updates at fedoraproject.org
Fri Feb 17 01:01:58 UTC 2012


The following Fedora 15 Security updates need testing:

    https://admin.fedoraproject.org/updates/FEDORA-2012-1539/xen-4.1.2-6.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1534/glpi-0.78.5-3.svn17464.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1213/usbmuxd-1.0.7-3.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1283/drupal6-6.24-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1553/rocksndiamonds-3.3.0.1-5.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1583/nagios-3.3.1-3.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-0752/jetty-6.1.26-7.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1250/drupal7-7.12-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1656/apr-1.4.6-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1606/thunderbird-10.0.1-1.fc15,xulrunner-10.0.1-1.fc15,firefox-10.0.1-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1642/httpd-2.2.22-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1677/seamonkey-2.7.1-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1721/java-1.6.0-openjdk-1.6.0.0-63.1.10.6.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1845/xulrunner-10.0.1-3.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1838/thunderbird-10.0.1-2.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1390/drupal7-field_permissions-1.0-0.2.beta2.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2011-17233/tor-0.2.1.32-1500.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2011-16980/asterisk-1.8.7.2-1.fc15


The following Fedora 15 Critical Path updates have yet to be approved:

    https://admin.fedoraproject.org/updates/FEDORA-2012-1835/cups-1.4.8-9.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1843/mdadm-3.2.3-5.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1838/thunderbird-10.0.1-2.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1845/xulrunner-10.0.1-3.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1697/python-kitchen-1.1.1-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1673/openssh-5.6p1-35.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1656/apr-1.4.6-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1670/kernel-2.6.42.6-3.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1642/httpd-2.2.22-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1606/thunderbird-10.0.1-1.fc15,xulrunner-10.0.1-1.fc15,firefox-10.0.1-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1587/xfce4-session-4.8.3-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1556/xorg-x11-drv-openchrome-0.2.905-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1432/perl-5.12.4-165.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2012-1430/libgee-0.6.4-1.fc15
    https://admin.fedoraproject.org/updates/FEDORA-2011-13190/phonon-backend-gstreamer-4.5.90-2.fc15,phonon-4.5.57-1.20110914.fc15


The following builds have been pushed to Fedora 15 updates-testing

    bacula-5.0.3-28.fc15
    btkbdd-1.2-1.fc15
    clalsadrv-2.0.0-3.fc15
    cptutils-1.42-2.fc15
    cups-1.4.8-9.fc15
    cyphesis-0.5.26-6.fc15
    drupal6-features-1.2-1.fc15
    drupal7-calendar-3.0-0.1.rc1.fc15
    drupal7-calendar-3.0-0.4.rc1.fc15
    facter-1.6.5-4.fc15
    fetchmail-6.3.21-1.fc15
    kradio4-4.0.3-1.fc15
    mdadm-3.2.3-5.fc15
    mingw32-dlfcn-0-0.10.r11.fc15
    monochrome-icon-theme-0.0.39-1.fc15
    oxygen-gtk3-1.0.1-1.fc15
    perl-Net-Amazon-EC2-Metadata-0.10-4.fc15
    perl-Path-Class-0.25-1.fc15
    python-oauth2-1.5.211-1.fc15
    ql2400-firmware-5.06.05-1.fc15
    ql2500-firmware-5.06.05-1.fc15
    thunderbird-10.0.1-2.fc15
    transifex-client-0.7-1.fc15
    xulrunner-10.0.1-3.fc15

Details about builds:


================================================================================
 bacula-5.0.3-28.fc15 (FEDORA-2012-1857)
 Cross platform network backup for Linux, Unix, Mac and Windows
--------------------------------------------------------------------------------
Update Information:

Remove stale fedora-usermgmt requirement and fix bat help button
--------------------------------------------------------------------------------
ChangeLog:

* Wed Feb  1 2012 Simone Caronni <negativo17 at gmail.com> - 5.0.3-28
- Add bat html docs so the help button works.
* Wed Feb  1 2012 Lukas Nykryn <lnykryn at redhat.com> - 5.0.3-27
- Remove dependency on fedora-usermgmt.
--------------------------------------------------------------------------------


================================================================================
 btkbdd-1.2-1.fc15 (FEDORA-2012-1868)
 Bluetooth keyboard service
--------------------------------------------------------------------------------
Update Information:

New package.
--------------------------------------------------------------------------------


================================================================================
 clalsadrv-2.0.0-3.fc15 (FEDORA-2012-1866)
 ALSA driver C++ Library
--------------------------------------------------------------------------------
Update Information:

clalsadrv ia an ALSA driver C++ access library, previously residing in CCRMA

--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #788718 - Review Request: clalsadrv - An ALSA driver C++ library
        https://bugzilla.redhat.com/show_bug.cgi?id=788718
--------------------------------------------------------------------------------


================================================================================
 cptutils-1.42-2.fc15 (FEDORA-2012-1854)
 Utilities to manipulate and translate color gradients
--------------------------------------------------------------------------------
Update Information:

This package is new to Fedora.

The cptutils package contains a number of utilities for the manipulation of color gradients; mainly for translating between different formats. Formats supported include ggr (GIMP gradient), cpt (GMT color palette table), avl (Arcview Legend), lut (xmedcon), svg, and version 3 of the grd format. 

The cptutils package was written to aid the construction of the cpt archive cpt-city http://soliton.vm.bytemark.co.uk/pub/cpt-city where thousands of gradients can be downloaded.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #783683 - Review Request: cptutils - Utilities to manipulate and translate color gradients
        https://bugzilla.redhat.com/show_bug.cgi?id=783683
--------------------------------------------------------------------------------


================================================================================
 cups-1.4.8-9.fc15 (FEDORA-2012-1835)
 Common Unix Printing System
--------------------------------------------------------------------------------
Update Information:

This update fixes a problem with encrypted connections.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Tim Waugh <twaugh at redhat.com> 1:1.4.8-9
- Apply patch from upstream revision 9974 to fix encryption upgrades
  (bug #748988).
* Tue Jan 17 2012 Tim Waugh <twaugh at redhat.com> 1:1.4.8-8
- Replace newline characters with spaces in reported Device IDs
  (bug #782129, STR #4005).
- Don't accept Device URIs of '\0' from SNMP devices
  (bug #770646, STR #4004).
* Wed Dec 21 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.8-7
- Fixed textonly filter to work with single copies (bug #738412).
* Fri Dec  9 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.8-6
- Detangle cups-serverbin-compat.patch from cups-lspp.patch.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #748988 - cupsdisable or cupsenable does not work on fedora 15.
        https://bugzilla.redhat.com/show_bug.cgi?id=748988
--------------------------------------------------------------------------------


================================================================================
 cyphesis-0.5.26-6.fc15 (FEDORA-2012-1851)
 WorldForge game server
--------------------------------------------------------------------------------
Update Information:

Changed the spec file to use tmpfiles.d and ghost macro on /var/run/cyphesis, needed because f15 and f16 use tmpfs for /var/run
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Martin Preisler <mpreisle at redhat.com> 0.5.26-6
- %ghost for /var/run/cyphesis, added tmpfiles.d
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #656567 - Please Update Spec File to use %ghost on files in /var/run and /var/lock
        https://bugzilla.redhat.com/show_bug.cgi?id=656567
--------------------------------------------------------------------------------


================================================================================
 drupal6-features-1.2-1.fc15 (FEDORA-2012-1873)
 Provides feature management for Drupal
--------------------------------------------------------------------------------
Update Information:

New upstream version, http://drupal.org/node/1371924.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Peter Borsa <peter.borsa at gmail.com> - 1.2-1
- Update to upstream 1.2
* Fri Jan 13 2012 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.1-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
--------------------------------------------------------------------------------


================================================================================
 drupal7-calendar-3.0-0.1.rc1.fc15 (FEDORA-2012-1850)
 This module will display any Views date field in calendar formats
--------------------------------------------------------------------------------
Update Information:

http://drupal.org/node/1439710
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #791154 - drupal7-calendar-3.0-rc1 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=791154
--------------------------------------------------------------------------------


================================================================================
 drupal7-calendar-3.0-0.4.rc1.fc15 (FEDORA-2012-1860)
 This module will display any Views date field in calendar formats
--------------------------------------------------------------------------------
Update Information:

http://drupal.org/node/1439710.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Peter Borsa <peter.borsa at gmail.com> - 3.0-0.4.rc1
- Fixed release number
* Thu Feb 16 2012 Peter Borsa <peter.borsa at gmail.com> - 3.0-0.1.rc1
- New upstream version.
* Fri Jan 13 2012 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 3.0-0.3.alpha2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #791154 - drupal7-calendar-3.0-rc1 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=791154
--------------------------------------------------------------------------------


================================================================================
 facter-1.6.5-4.fc15 (FEDORA-2012-1848)
 Ruby module for collecting simple facts about a host operating system
--------------------------------------------------------------------------------
Update Information:

Previous facter packages added requirements on dmidecode and pciutils.  These are not available on all architectures supported by Fedora and EPEL.  To remedy this, facter is no longer a noarch package and the dependencies are only included on architectures where they are available.

Additionally, a regression in processing ec2 facts is corrected, with thanks to Jeremy Katz for the patch.

Lastly, timestamps are now preserved by the install script.  This avoids many spurious changes when the package is updated.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Feb 15 2012 Todd Zullinger <tmz at pobox.com> - 1.6.5-4
- Only run rspec checks on Fedora >= 17
* Mon Feb 13 2012 Todd Zullinger <tmz at pobox.com> - 1.6.5-3
- Make spec file work for EPEL and Fedora
- Drop BuildArch: noarch and make dmidecode/pciutils deps arch-specific
- Make ec2 facts work on CentOS again (#790849, thanks to Jeremy Katz)
- Preserve timestamps when installing files
* Thu Feb  2 2012 Bohuslav Kabrda <bkabrda at redhat.com> - 1.6.5-2
- Rebuilt for Ruby 1.9.3.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #790849 - facter 1.6.5 breaks ec2 facts on el5
        https://bugzilla.redhat.com/show_bug.cgi?id=790849
--------------------------------------------------------------------------------


================================================================================
 fetchmail-6.3.21-1.fc15 (FEDORA-2012-1885)
 A remote mail retrieval and forwarding utility
--------------------------------------------------------------------------------
Update Information:

Critical bug fix: NUL-byte-insertion bug in the IMAP client that occurs when the last line of the input has no LF- and no CRLF-termination.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Vitezslav Crhonek <vcrhonek at redhat.com> - 6.3.21-1
- Update to fetchmail-6.3.21
  Resolves: #789776
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #789776 - fetchmail-6.3.21 not available for Fedora 16/15
        https://bugzilla.redhat.com/show_bug.cgi?id=789776
--------------------------------------------------------------------------------


================================================================================
 kradio4-4.0.3-1.fc15 (FEDORA-2012-1883)
 V4L/V4L2-Radio Application for KDE4
--------------------------------------------------------------------------------
Update Information:

Updated to 4.0.3
--------------------------------------------------------------------------------
ChangeLog:

* Wed Feb 15 2012 Paulo Roma <roma at lcg.ufrj.br> - 4.0.3-1
- Updated to 4.0.3.
--------------------------------------------------------------------------------


================================================================================
 mdadm-3.2.3-5.fc15 (FEDORA-2012-1843)
 The mdadm program controls Linux md devices (software RAID arrays)
--------------------------------------------------------------------------------
Update Information:

This is an update to the mdadm package.

This update fixes a problem where raids using bitmaps would fail to add some of the devices in the raid, due to mdadm attempting to write to a mis-aligned buffer using O_DIRECT.

In addition it contains the mdadm portion of the fixes needed to unroll mounts back to the initramfs, in be able to reboot when the root devices is on an IMSM raid. Note this change requires corresponding updates to systemd and dracut to resolve the unroll reboot problem.

If your root device is located on an IMSM RAID, please make sure to rebuild your initramfs, before rebooting the system.

All users of mdadm RAIDs are encouraged to upgrade.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Jes Sorensen <Jes.Sorensen at redhat.com> - 3.2.3-5
- Fix issue with devices failing to be added to a raid using bitmaps,
  due to trying to write the bitmap with mis-aligned buffers using
  O_DIRECT 
- Resolves: bz789898 (f16) bz791189 (f15)
* Mon Jan 30 2012 Jes Sorensen <Jes.Sorensen at redhat.com> - 3.2.3-4
- Add support for --offroot to mdadm/mdmon
- Resolves: bz785739 (rawhide) bz785737 (f16) bz771405 (f15)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #791189 - mdadm silently fails to add devices to a degraded array with bitmaps
        https://bugzilla.redhat.com/show_bug.cgi?id=791189
  [ 2 ] Bug #771405 - update mdadm/mdmon to work with systemd unrolling mounts to initramfs mount on shutdown
        https://bugzilla.redhat.com/show_bug.cgi?id=771405
--------------------------------------------------------------------------------


================================================================================
 mingw32-dlfcn-0-0.10.r11.fc15 (FEDORA-2012-1875)
 Implements a wrapper for dlfcn (dlopen dlclose dlsym dlerror)
--------------------------------------------------------------------------------
Update Information:

Make sure the static lib is compiled correctly
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Erik van Pienbroek <epienbro at fedoraproject.org> - 0-0.10.r11
- Make sure the static lib is compiled correctly (RHBZ #791191)
- Various cleanups
* Fri Jan 13 2012 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 0-0.9.r11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #791191 - Static linking against mingw32-dlfcn seems broken
        https://bugzilla.redhat.com/show_bug.cgi?id=791191
--------------------------------------------------------------------------------


================================================================================
 monochrome-icon-theme-0.0.39-1.fc15 (FEDORA-2012-1870)
 Icons for the panel, designed in a simplified monochrome style
--------------------------------------------------------------------------------
Update Information:

Add icons for gnome-control-center category headers
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Mohamed El Morabity <melmorabity at fedoraproject.org> - 0.0.39-1
- Update to 0.0.39
--------------------------------------------------------------------------------


================================================================================
 oxygen-gtk3-1.0.1-1.fc15 (FEDORA-2012-1668)
 Oxygen GTK+3 theme
--------------------------------------------------------------------------------
Update Information:

oxygen-gtk3 1.0.1

 First bugfix release of the gtk3-1.0 series. Fixes include:

 - email list in evolution
 - warnings when parsing CSS style sheet
 - icon background with gtk3.3
 - high memory allocation for cached pixmaps
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Alexey Kurov <nucleo at fedoraproject.org> - 1:1.0.1-1
- oxygen-gtk3-1.0.1
- drop blacklist patch
* Mon Feb 13 2012 Alexey Kurov <nucleo at fedoraproject.org> - 1:1.0.0-2
- Blacklist Evolution's MessageList from Inner Shadow hack (kde#292278)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #790631 - Evolution Message List in KDE 4.8  is blank
        https://bugzilla.redhat.com/show_bug.cgi?id=790631
--------------------------------------------------------------------------------


================================================================================
 perl-Net-Amazon-EC2-Metadata-0.10-4.fc15 (FEDORA-2012-1842)
 Retrieves data from EC2 Metadata service
--------------------------------------------------------------------------------
Update Information:

New package.
--------------------------------------------------------------------------------


================================================================================
 perl-Path-Class-0.25-1.fc15 (FEDORA-2012-1833)
 Cross-platform path specification manipulation
--------------------------------------------------------------------------------
Update Information:

This update, to the current upstream release, contains a host of additional methods, bug-fixes and documentation improvements.

See the Changes file for full details.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Paul Howarth <paul at city-fan.org> - 0.25-1
- Update to 0.25:
  - resolve() now croak()s instead of die()s on non-existent file
  - Added a traverse() method for directories, based on the fmap_cont() method
    of Forest::Tree::Pure; it's an alternative to ->recurse, which allows for
    more control over how the recursion happens
  - Fixed a grammar error in the docs
  - Added a tempfile() method for Dir objects, which provides an interface to
    File::Temp (CPAN RT#60485)
  - Fixed a non-helpful fatal error message when calling resolve() on a path
    that doesn't exist; now dies with the proper "No such file or directory"
    message and exit status
- BR: perl(Test::Perl::Critic) and run author tests where possible
- Add patch to support building with Module::Build < 0.3601
* Thu Feb 16 2012 Paul Howarth <paul at city-fan.org> - 0.23-4
- Spec clean-up:
  - Add buildreqs for Perl core modules that might be dual-lived
  - Tidy %description
  - Make %files list more explicit
  - Don't use macros for commands
  - Use search.cpan.org source URL
  - BR: at least version 0.87 of File::Spec
* Fri Jan 13 2012 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 0.23-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
* Fri Jun 17 2011 Marcela Mašláňová <mmaslano at redhat.com> - 0.23-2
- Perl mass rebuild
--------------------------------------------------------------------------------


================================================================================
 python-oauth2-1.5.211-1.fc15 (FEDORA-2012-1877)
 Python support for improved oauth
--------------------------------------------------------------------------------
Update Information:

Update to 1.5.211, and apply fix for handling multiple GET params.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Tom Callaway <spot at fedoraproject.org> - 1.5.211-1
- update to 1.5.211
- add multiple GET fix from Jason Connor (bz 784426)
* Sat Jan 14 2012 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.5.170-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #784426 - multiple GET parameters are lost when creating Request using Request.from_request factory
        https://bugzilla.redhat.com/show_bug.cgi?id=784426
--------------------------------------------------------------------------------


================================================================================
 ql2400-firmware-5.06.05-1.fc15 (FEDORA-2012-1863)
 Firmware for qlogic 2400 devices
--------------------------------------------------------------------------------
Update Information:

The note said to come to the QLogic underground parking garage at 2:30 AM, and in my business, when notes like that land in your mailbox, well, you come. It was poorly lit, with low ceilings, and crumbling pillars scattered about. There were no cars, just shadows hiding oil spills and other unidentifiable stains. I heard a whispering summons from behind a corner pillar, so I cautiously approached. A hand emerged from the darkness and thrust a USB key at me. "Here", he said forcefully, "your users need to have this". I asked him what it was, but he just laughed. "They're firmware updates for the Linux kernel drivers for QLogic fibrechannel adaptors, but that's not the question you should be asking." I rubbed the USB key between my fingers, then took the bait. "Okay, mysterious person, what is the question I should be asking?" I saw a flicker of flame as a cigarette was lit, then smoke danced into the damp air. "You should be asking, what does the firmware do and what does it fix in this revision", the smoking man whispered, before coughing loudly.

I sighed loudly. "Look man, I'm sure it fixes bugs, or enables some new hardware features. Did this really merit dragging me out here in the middle of the night? I don't even know who you are." The cigarette flared as the man took another pull. "Call me, Deep Bloat. And you have no idea what this firmware really does. They don't want to you to know. They don't think you can handle the truth." Now, I was curious. "What could it possibly do? It's just a set of assembly code that is loaded via the kernel driver to be executed directly by the fibrechannel adaptor!" Deep Bloat sighed. "You're not seeing the big picture. This conspiracy is huge, it touches so many different things, this is just the tip of the iceberg!" I waited silently, I had suspected something big was happening, but I never thought it would involve a simple firmware update.

Suddenly, his voice raised and he spewed forth his words like an assault: "Why do you think QLogic is so secretive about their firmware updates? They push these firmware updates out, insist that they be updated, but they won't tell you anything about what they do or why they're necessary! Forget the source code, they don't want you to pull back the curtain to see how deep the rabbit hole goes." More cigarette smoke flowed as he regained his composure. "I'm going to stop that today. I'm going to tell you what this firmware does, and you will tell the world."

I leaned towards the shadowy informant, carefully preparing to hear his next words, but the next sound was that of a gunshot, violently echoing through the garage and my ears. I saw Deep Bloat slump to the ground, his cigarette butt at his side, as I rushed towards him. He gurgled and sputtered, but pulled me close to his mouth. My hands were hot and sticky with his blood, my heart pounding out of my chest, as he whispered his final word to me... "rosebud".

Another shot rang out, and I heard a steam pipe burst. Somehow, I found the courage to run through the scalding mist and found my way outside. I didn't stop running for what felt like an eternity, but when my feet couldn't carry me anymore, I looked at the bloody USB key in my hands and knew what I had to do. I owed Deep Bloat that much, even if I had no idea what rosebud meant, at least, not yet.

*****
Please note: QLogic refuses to disclose what changes between revisions of their firmware, but insists that the updates are mandatory. Your guess is as good as mine as to what goes in them, so I let my imagination run wild. The above update text is fiction, or is it?

--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Tom Callaway <spot at fedoraproject.org> - 5.06.05-1
- update to 5.06.05
* Sat Jan 14 2012 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 5.06.02-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
--------------------------------------------------------------------------------


================================================================================
 ql2500-firmware-5.06.05-1.fc15 (FEDORA-2012-1863)
 Firmware for qlogic 2500 devices
--------------------------------------------------------------------------------
Update Information:

The note said to come to the QLogic underground parking garage at 2:30 AM, and in my business, when notes like that land in your mailbox, well, you come. It was poorly lit, with low ceilings, and crumbling pillars scattered about. There were no cars, just shadows hiding oil spills and other unidentifiable stains. I heard a whispering summons from behind a corner pillar, so I cautiously approached. A hand emerged from the darkness and thrust a USB key at me. "Here", he said forcefully, "your users need to have this". I asked him what it was, but he just laughed. "They're firmware updates for the Linux kernel drivers for QLogic fibrechannel adaptors, but that's not the question you should be asking." I rubbed the USB key between my fingers, then took the bait. "Okay, mysterious person, what is the question I should be asking?" I saw a flicker of flame as a cigarette was lit, then smoke danced into the damp air. "You should be asking, what does the firmware do and what does it fix in this revision", the smoking man whispered, before coughing loudly.

I sighed loudly. "Look man, I'm sure it fixes bugs, or enables some new hardware features. Did this really merit dragging me out here in the middle of the night? I don't even know who you are." The cigarette flared as the man took another pull. "Call me, Deep Bloat. And you have no idea what this firmware really does. They don't want to you to know. They don't think you can handle the truth." Now, I was curious. "What could it possibly do? It's just a set of assembly code that is loaded via the kernel driver to be executed directly by the fibrechannel adaptor!" Deep Bloat sighed. "You're not seeing the big picture. This conspiracy is huge, it touches so many different things, this is just the tip of the iceberg!" I waited silently, I had suspected something big was happening, but I never thought it would involve a simple firmware update.

Suddenly, his voice raised and he spewed forth his words like an assault: "Why do you think QLogic is so secretive about their firmware updates? They push these firmware updates out, insist that they be updated, but they won't tell you anything about what they do or why they're necessary! Forget the source code, they don't want you to pull back the curtain to see how deep the rabbit hole goes." More cigarette smoke flowed as he regained his composure. "I'm going to stop that today. I'm going to tell you what this firmware does, and you will tell the world."

I leaned towards the shadowy informant, carefully preparing to hear his next words, but the next sound was that of a gunshot, violently echoing through the garage and my ears. I saw Deep Bloat slump to the ground, his cigarette butt at his side, as I rushed towards him. He gurgled and sputtered, but pulled me close to his mouth. My hands were hot and sticky with his blood, my heart pounding out of my chest, as he whispered his final word to me... "rosebud".

Another shot rang out, and I heard a steam pipe burst. Somehow, I found the courage to run through the scalding mist and found my way outside. I didn't stop running for what felt like an eternity, but when my feet couldn't carry me anymore, I looked at the bloody USB key in my hands and knew what I had to do. I owed Deep Bloat that much, even if I had no idea what rosebud meant, at least, not yet.

*****
Please note: QLogic refuses to disclose what changes between revisions of their firmware, but insists that the updates are mandatory. Your guess is as good as mine as to what goes in them, so I let my imagination run wild. The above update text is fiction, or is it?

--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Tom Callaway <spot at fedoraproject.org> - 5.06.05-1
- update to 5.06.05
* Sat Jan 14 2012 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 5.06.02-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
--------------------------------------------------------------------------------


================================================================================
 thunderbird-10.0.1-2.fc15 (FEDORA-2012-1838)
 Mozilla Thunderbird mail/newsgroup client
--------------------------------------------------------------------------------
Update Information:

Fixes a libpng flaw.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Martin Stransky <stransky at redhat.com> - 10.0.1-2
- Added fix for mozbz#727401
* Thu Feb  9 2012 Jan Horak <jhorak at redhat.com> - 10.0.1-1
- Update to 10.0.1
* Mon Feb  6 2012 Martin Stransky <stransky at redhat.com> - 10.0-2
- gcc 4.7 build fixes
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #791185 - CVE-2011-3026 thunderbird: libpng: Heap-buffer-overflow in png_decompress_chunk [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=791185
--------------------------------------------------------------------------------


================================================================================
 transifex-client-0.7-1.fc15 (FEDORA-2012-1879)
 Command line tool for Transifex translation management
--------------------------------------------------------------------------------
Update Information:

update to new upstream
version.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Domingo Becker <domingobecker at gmail.com> - 0.7-1
- Update to new upstream version.
--------------------------------------------------------------------------------


================================================================================
 xulrunner-10.0.1-3.fc15 (FEDORA-2012-1845)
 XUL Runtime for Gecko Applications
--------------------------------------------------------------------------------
Update Information:

Fix for the libpng security flaw.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 16 2012 Martin Stransky <stransky at redhat.com> - 10.0.1-3
- Added fix for mozbz#727401
* Tue Feb 14 2012 Martin Stransky <stransky at redhat.com> - 10.0.1-2
- Allow network manager to handle the offline status
* Thu Feb  9 2012 Jan Horak <jhorak at redhat.com> - 10.0.1-1
- Update to 10.0.1
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #791184 - CVE-2011-3026 firefox: libpng: Heap-buffer-overflow in png_decompress_chunk [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=791184
--------------------------------------------------------------------------------



More information about the test mailing list