delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2024/06/05/13:32:15

DKIM-Filter: OpenDKIM Filter v2.11.0 delorie.com 455HWEaF403757
Authentication-Results: delorie.com;
dkim=pass (1024-bit key, unprotected) header.d=cygwin.com header.i=@cygwin.com header.a=rsa-sha256 header.s=default header.b=qsTkTBtt
X-Recipient: archive-cygwin AT delorie DOT com
DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org B5B3E39D5A72
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cygwin.com;
s=default; t=1717608733;
bh=aygif837GCH/A/LANm0yPkyGhmnzzfmYw3WmdxbqkqM=;
h=Date:To:Subject:List-Id:List-Unsubscribe:List-Archive:List-Post:
List-Help:List-Subscribe:From:Reply-To:From;
b=qsTkTBttvR5V5397logpX04WHoC77pvnNTUn7+74FCUHHJbXMEC5olYoPtTbReDnw
JN5etpuFr0AzLE3JCYeeqIEBHpWUbip/gxavEASilJpXxTd8GATYrm9CVxtTK1leLk
b6LSX3PJCWd3mAADrDou+IrAh243glNWl7TP0mjM=
X-Original-To: cygwin AT cygwin DOT com
Delivered-To: cygwin AT cygwin DOT com
DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 3580C385842D
ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 3580C385842D
ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1717608712; cv=none;
b=Iox/rc9s8PbBObNLNrXb3JsHqiBHUX+1LrShLUHR28s6v98JoUeyF8xQ0qqRRo3nLsFnaEVuCTsK9eRwx8kyKsOuXNb7thRtsK2W7nVK1jBvcaUXkSTzQPNMZH58F/XErpk56iq2oEwOXnXzO1NDBJGU/b7pQArUceWHI9IyWrw=
ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key;
t=1717608712; c=relaxed/simple;
bh=XnN5b7kLVST8dPExv9z3L5nPrKrzPecoKOvqbnc0ea0=;
h=Date:From:To:Subject:Message-ID:MIME-Version;
b=XIsP3myCmwxdWrmzj0dJ3LnDTIqOg7bYFsnTyL2BPyqBAYkvUd1MX03d3fG3MvuFlTCzs3dt/GP0Y/Xuz8agPzBBc+urXa6/k+rR4DVseju9+Ym/+2EcLxJZ2bksf9AkH/DKJYobnDtDsuxeMWi7NCwxeYSNGD3k6VuADpSQRJo=
ARC-Authentication-Results: i=1; server2.sourceware.org
Date: Wed, 5 Jun 2024 19:31:49 +0200
To: cygwin AT cygwin DOT com
Subject: Sourceware infrastructure updates for Q2 2024
Message-ID: <20240605173149.GY12557@gnu.wildebeest.org>
MIME-Version: 1.0
User-Agent: Mutt/1.5.21 (2010-09-15)
X-Spam-Status: No, score=-2.7 required=5.0 tests=BAYES_00, JMQ_SPF_NEUTRAL,
KAM_DMARC_STATUS, SPF_HELO_NONE, SPF_PASS, TXREP,
T_SCC_BODY_TEXT_LINE autolearn=no autolearn_force=no version=3.4.6
X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on
server2.sourceware.org
X-BeenThere: cygwin AT cygwin DOT com
X-Mailman-Version: 2.1.30
List-Id: General Cygwin discussions and problem reports <cygwin.cygwin.com>
List-Archive: <https://cygwin.com/pipermail/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-request AT cygwin DOT com?subject=help>
List-Subscribe: <https://cygwin.com/mailman/listinfo/cygwin>,
<mailto:cygwin-request AT cygwin DOT com?subject=subscribe>
From: Mark Wielaard via Cygwin <cygwin AT cygwin DOT com>
Reply-To: Mark Wielaard <mark AT klomp DOT org>
Sender: "Cygwin" <cygwin-bounces+archive-cygwin=delorie DOT com AT cygwin DOT com>

Sourceware infrastructure community updates for Q2 2024

A summary of news about Sourceware, the Free Software hosting project
for core toolchain and developer tools, from the last 3 months.

- Ongoing rDNS email issue
- Aging inactive users policy
- Sourceware hosts are not affected by the latest xz backdoor
- Sourceware infrastructure security vision
- Upgraded server2
- Sourceware @ Conservancy - Year One
- Sourceware Open Office hours

= Ongoing rDNS email issue

  There are currently issues with rDNS for sourceware.org, cygwin.com,
  gcc.gnu.org and lists.dwarfstd.org which cause email delays for some
  people in Europe.

  If you find something like:
    Client host rejected: cannot find your hostname, [8.43.85.97]
  in your mail.logs you are affected.

  Lumen [CenturyLink, Level3] reports they have isolated this issue to
  their Frankfurt, DE facility but do not have an ETR at this time.

  If you have trouble receiving emails over smtp because of this issue
  note that https://inbox.sourceware.org provides public mailinglists
  through http, imap, nntp and makes it possible to git clone whole
  archives.

  You can get the latest updates from the fediverse:
  https://fosstodon.org/@sourceware

= Aging inactive users policy

  We started on the "aging inactive users" process by sending emails
  to the first batch of users without any activity in the last year
  and disabled accounts that really weren't active (putting them in
  the emeritus group)
  https://inbox.sourceware.org/overseers/ZhQZXogZMozVjIYn AT elastic DOT org/T/

  Various people already replied saying it was OK to disable their
  account. But we also noticed that some of the account contact
  information is no longer valid. Please keep your account details up
  to date so that we always have a way of contacting you.

  Please see the account management page on how to set your current
  email address: https://sourceware.org/sourceware/accountinfo.html

= Sourceware hosts are not affected by the latest xz backdoor

  Sourceware hosts are not affected by the latest xz backdoor. We have
  reset the builder.sourceware.org containers of debian-testing,
  fedora-rawhide and opensuse-tumbleweed. These containers however
  didn't have ssh installed, were running on isolated VMs on separate
  machines from our main hosts, snapshots and backup servers.

= Sourceware infrastructure security vision

  During Q2 2024 we held various open office and public email
  discussions with the community and made plans for Sourceware and all
  the hosted projects.

  https://inbox.sourceware.org/20240325100226 DOT GL5673 AT gnu DOT wildebeest DOT org/
  https://inbox.sourceware.org/libc-alpha/ZiV8e8Xm4GFGbQ2E AT debian/T/
  https://inbox.sourceware.org/libc-alpha/20240423004822 DOT GC4681 AT redhat DOT com/T/

  After the xz-backdoor incident obviously a lot of discussions
  focused on various security aspects. As Sourceware Project
  Leadership Committee we turned those ideas into concrete plans.

  https://sourceware.org/sourceware-security-vision.html

  The Sourceware infrastructure security vision explains what
  Sourceware is, the mission, how the organization works, the secure
  Sourceware project goals and plans. This includes not just
  infrastructure services updates, but also the secure software
  development framework projects use and secure supply chain issues.

  We are currently working with Conservancy staff on funding proposals
  for these plans.

= Upgraded server2

  server2.sourceware.org now has 512GB RAM, thanks Red Hat.

= Sourceware @ Conservancy - Year One

  https://inbox.sourceware.org/20240529190215 DOT GA26515 AT gnu DOT wildebeest DOT org
  https://fosstodon.org/@sourceware/112526024910398811

  Communications (lots, also on the fediverse), New and updated
  services (snapshots server, email, public-inbox, cgit), Security
  (CVEs, git signing, autoregen builders, aging inactive users, secure
  supply chain), New and upgraded hardware (thanks Red Hat OSUOSL
  StarFive), Finances (we spend hundreds and raised thousands of
  dollars), Next year plans (more, bigger and isolated), Conclusion
  (Five Stars, Would Recommend).

= Sourceware Open Office hours

  Every second Friday of the month is the Sourceware Overseers Open
  Office hour in #overseers on irc.libera.chat from 16:00 till 17:00
  UTC. Note this is a new time!

  Please feel free to drop by with any Sourceware services and hosting
  questions. Of course you are welcome to drop into the #overseers
  channel at any time and we can also be reached through email and
  bugzilla: https://sourceware.org/mission.html#organization

  If you aren't already and want to keep up to date on Sourceware
  infrastructure services then please also subscribe to the overseers
  mailinglist. https://sourceware.org/mailman/listinfo/overseers

  The Sourceware Project Leadership Committee also meets once a month
  to discuss all community input. The committee will set priorities
  and decide how to spend any funds, negotiate with hardware and
  service partners, create budgets together with the Conservancy,
  or decide when a new fundraising campaign is needed. The current
  committee is Frank Ch. Eigler, Christopher Faylor, Ian Kelling,
  Ian Lance Taylor, Tom Tromey, Jon Turney, Mark J. Wielaard and
  Elena Zannoni.

-- 
Problem reports:      https://cygwin.com/problems.html
FAQ:                  https://cygwin.com/faq/
Documentation:        https://cygwin.com/docs.html
Unsubscribe info:     https://cygwin.com/ml/#unsubscribe-simple

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019