|
Packages | Any | Freedom Issue | Medium | Low | [webfs]: vague terminology "Content" in description of ... | Deferred | |
Task Description
Description:
community/webfs 1.21-13
Simple and instant http server for mostly static content.
Description is vague because of the word “content”. Why not simply say “files” instead and be more specific.
Even empty files without data inside can be served.
See: https://www.gnu.org/philosophy/words-to-avoid.html#Content
|
|
Packages | Any | Freedom Issue | Medium | Low | [openstreetmap-map-icons-svn]: using vague "public doma... | Deferred | |
Task Description
Description:
community/openstreetmap-map-icons-svn 31588-1 [installed]
A set of public domain licensed map icons for general OSM use
It is questionable if it is “Licensed” or dedicated.
See the file: /usr/share/licenses/openstreetmap-map-icons/svg-twotone/LICENSE.txt
it does not matter if the file is named “LICENSE”, it could be also named anyhow else.
There must be reason why the organization Creative Commons is not using the word “License” in that text, and that is why I propose to simply say in description:
A set of public domain map icons for general OSM use
|
|
Packages | Any | Freedom Issue | Medium | Low | [autoconf-archive]: using vague "freely" term in descr... | Deferred | |
Task Description
community/autoconf-archive 1:2017.03.21-1
A collection of freely re-usable Autoconf macros
See: https://www.gnu.org/philosophy/words-to-avoid.html#FreelyAvailable
Don’t use “freely available software” as a synonym for “free software.” The terms are not equivalent. Software is “freely available” if anyone can easily get a copy. “Free software” is defined in terms of the freedom of users that have a copy of it. These are answers to different questions.
|
|
Packages | Any | Freedom Issue | Medium | Low | [python-biopython]: using vague "freely" term in descri... | Deferred | |
Task Description
community/python-biopython 1.69-1
Freely available Python tools for computational molecular biology
See: https://www.gnu.org/philosophy/words-to-avoid.html#FreelyAvailable
Don’t use “freely available software” as a synonym for “free software.” The terms are not equivalent. Software is “freely available” if anyone can easily get a copy. “Free software” is defined in terms of the freedom of users that have a copy of it. These are answers to different questions.
|
|
Packages | Any | Freedom Issue | Medium | Low | [python2-biopython]: using vague "freely available" ter... | Deferred | |
Task Description
community/python2-biopython 1.69-1
Freely available Python tools for computational molecular biology
See: https://www.gnu.org/philosophy/words-to-avoid.html#FreelyAvailable
Don’t use “freely available software” as a synonym for “free software.” The terms are not equivalent. Software is “freely available” if anyone can easily get a copy. “Free software” is defined in terms of the freedom of users that have a copy of it. These are answers to different questions.
|
|
Packages | Any | Freedom Issue | Medium | Low | [man-pages-de]: using kernel name without operating sys... | Deferred | |
Task Description
Description:
community/man-pages-de 1.22-1
German Linux man pages
See: https://www.gnu.org/philosophy/words-to-avoid.html#Linux
|
|
Packages | Any | Freedom Issue | Medium | Low | [man-pages-ru]: using kernel name without operating sys... | Deferred | |
Task Description
Description:
community/man-pages-ru 4.08_2329_2272_20170321-2
Russian Linux man pages
See: https://www.gnu.org/philosophy/words-to-avoid.html#Linux
|
|
Packages | Any | Freedom Issue | Medium | Low | [man-pages-zh_cn]: using kernel name without operating ... | Deferred | |
Task Description
Description:
community/man-pages-zh_cn 1.6.3.1-1
Simplified Chinese Linux man pages
See: https://www.gnu.org/philosophy/words-to-avoid.html#Linux
|
|
Packages | Any | Freedom Issue | Medium | Low | [man-pages-zh_tw]: using kernel name without operating ... | Deferred | |
Task Description
Description:
community/man-pages-zh_tw 1.6.3.1-1
Traditional Chinese Linux man pages
See: https://www.gnu.org/philosophy/words-to-avoid.html#Linux
|
|
Packages | Any | Bug Report | Medium | Medium | [lxmusic]package needs rebuilding as it fails to run | In Progress | |
Task Description
Rebuilt version (using PKGBUILD from Arch) works fine. Same is true for lxmusic-gtk3 (which the PKGBUILD also builds).
https://git.archlinux.org/svntogit/community.git/tree/trunk?h=packages/lxmusic
|
|
Packages | Any | Security Issue | Medium | Medium | [openssh] CVE-2018-15919 | Researching | |
Task Description
Remotely observable behavior in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states ‘We understand that the OpenSSH developers do not want to treat such a username enumeration (or “oracle”) as a vulnerability.’ https://security-tracker.debian.org/tracker/CVE-2018-15919
|
|
Packages | Any | Drop Request | Medium | Medium | [gksu] is replaced and has to be deleted from our pacma... | Researching | |
Task Description
Description: From the author’s webpage gksu has been replaced.
Additional info: * package version(s) : extra/gksu 2.0.2-5
http://www.nongnu.org/gksu/
|
|
Packages | Testing | Implementation Request | Medium | Medium | linux-libre-lts-hypersec: New package with extra securi... | Deferred | |
Task Description
Description: Per a user request and to better secure the kernel, we can embed the cryptsetup and ciphers in the kernel. This would mean rather than exposed modules, they are built-in to the kernel and ready to use even without an intramfs.
To be embedded: ciphers aes, twofish, serpent; sha256, sha512 - and the necessary modules (don’t forget the block modes xts, lvm and cryptsetup ...)
Additionally, we could include USB Guard and any other features that meet our social contract and security outlook.
|
|
Packages | Any | Bug Report | Medium | High | [notmuch-mutt] missing requirement | Researching | |
Task Description
Description: notmuch-mutt fails to compile without perl-mail-message which is missing in Hyperbola
Steps to reproduce: Install notmuch-mutt and try `notmuch-mutt` at the command line. Then install `perl-mail-message` from Arch and try again.
|
|
Packages | Any | Feature Request | Medium | High | [supervisor] contains systemd unit file | In Progress | |
Task Description
The Arch version of “supervisor” from the snapshot used by Hyperbola comes with systemd support. Since Hyperbola follows the a global ruleset for INIT-freedom, systemd unit files removal is required and adding support for other init-systems (preferred OpenRC for now) to replace it.
|
|
Packages | Stable | Bug Report | Medium | High | opensmtpd: permission problems | In Progress | |
Task Description
Description:
cat msg | /usr/sbin/sendmail – sendmail: No such file or directorycannot create temporary file /var/spool/smtpd/offline/1572544775.XXXXIqNsFX
Additional info: * package version: 6.4.2p1-1.hyperbola2.backports1
It is same problem as here: https://github.com/OpenSMTPD/OpenSMTPD/issues/839
I could solve it with:
sudo chmod g+s /usr/sbin/smtpctl sudo chmod g+s /usr/sbin/smtpctl
and then
sudo rc-service smtpd start
Even though I think I should not need to start it to use only sendmail.
|
|
Packages | Any | Security Issue | Medium | Critical | [libjpeg-turbo] CVE-2019-2201 | Researching | |
Task Description
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation
https://security-tracker.debian.org/tracker/CVE-2019-2201
Patch: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/388
|
|
Packages | Any | Update Request | Medium | High | [php] is out of date/support | Unconfirmed | |
Task Description
Description:
From official PHP page, our php 7.1 is out of support and security
Our package : https://www.hyperbola.info/packages/extra/x86_64/php/
PHP page : https://www.php.net/supported-versions.php
|
|
Services | PunBB Branding | Bug Report | High | High | Forum appearance bugs | In Progress | |
Task Description
Some forum display errors:
preview button with the orange border.
Error message when logging in gray color making it difficult to read
|
|
Packages | Stable | Update Request | High | High | [qt5] upgrade Qt project to the 5.6 LTS version, requir... | Deferred | |
Task Description
Cannot mix incompatible Qt library (version 0×50800) with this library (version 0×50904) Aborted
./Nextcloud-2.3.3-x86_64.AppImage: /usr/lib/libQt5Core.so.5: version `Qt_5.9’ not found (required by /tmp/.mount_NextclpprMnG/usr/bin/../lib/libqt5keychain.so.1
These two packages are directly affected by an older qt5...
Could you update all the qt packages to the LTS version available?
|
|
Software Development | HyperBK | Implementation Request | Very High | Critical | Develop a BSD descendant kernel for HyperbolaBSD | In Progress | |
Task Description
Develop HyperBK (Hyper Berkeley Kernel), a BSD descendant kernel with GPL-compatible licenses preserved, non-compatible ones removed, and new code written under GPL-3 for HyperbolaBSD.
TODO:
Download OpenBSD kernel source code from OpenBSD site → DONE
Download LibertyBSD scripts to deblob and rebrand kernel from their scripts. → DONE
Remove files under non GPL-compatible licenses → DONE
Import code from another BSD systems under GPL-compatible licenses → IN PROGRESS
Write new code under GPL-3 → IN PROGRESS
PATCHING NOTE
When the check concerns kernel, we obviously want to match with HyperbolaBSD.
Example of triplet check: hyperbolabsd)
Example of uname -s check: HyperbolaBSD)
Example of uname -r check: 0.1)
Example of C macro check: defined(__HyperbolaBSD__)
|
|
Packages | Any | Feature Request | Very High | High | [sage-notebook] contains systemd unit file | In Progress | |
Task Description
Description:
The Arch version of Sage-notebook from the snapshot used by Hyperbola comes with systemd support. Since Hyperbola follows the Init Freedom Campaign , systemd unit files removal is required. OpenRC init script replacement isn’t possible here because Sage-notebook is using a systemd unit file adapted for users instead of system users.
Additional info: * package version(s) * config and/or log files etc.
Repository : community
Name : sage-notebook
Version : 0.13-4
Description : Browser-based notebook interface for SageMath
Architecture : any
URL : http://www.sagemath.org
Licenses : GPL3
Groups : None
Provides : None
Depends On : sagemath python2-twisted python2-flask-oldsessions python2-flask-openid python2-flask-autoindex python2-flask-babel mathjax
Optional Deps : python2-pyopenssl: to use the notebook in secure mode
Conflicts With : None
Replaces : None
Download Size : 1625.00 KiB
Installed Size : 9154.00 KiB
Packager : Antonio Rojas <arojas@archlinux.org>
Build Date : Thu 04 May 2017 06:12:28 PM -03
Validated By : MD5 Sum SHA-256 Sum Signature
/usr/lib/systemd/user/sage.service is owned by sage-notebook 0.13-4
Steps to reproduce:
|
|
Packages | Any | Security Issue | Very High | Critical | [avahi] blacklist package since it's a zeroconf impleme... | In Progress | |
Task Description
Avahi is a zero-configuration networking implementation that contains critical security issues because mDNS operates under a different trust model than unicast DNS trusting the entire network rather than a designated DNS server, it is vulnerable to spoofing attacks by any system within the multicast IP range. Like SNMP and many other network management protocols, it can also be used by attackers to quickly gain detailed knowledge of the network and its machines. [0]
Since it violates the Hyperbola Social Contract , Avahi should be blacklisted.
|
|
Packages | Any | Feature Request | Very High | High | [erlang-nox] contains systemd unit files | In Progress | |
Task Description
Description:
The Arch version of Erlang (headless version) from the snapshot used by Hyperbola comes with systemd support. Since Hyperbola follows the Init Freedom Campaign , systemd unit files removal is required or add OpenRC init scripts to replace it.
Additional info: * package version(s) * config and/or log files etc.
Repository : community
Name : erlang-nox
Version : 19.3-3
Description : General-purpose concurrent functional programming language developed by Ericsson (headless version)
Architecture : x86_64
URL : http://www.erlang.org/
Licenses : Apache
Groups : None
Provides : None
Depends On : ncurses openssl
Optional Deps : erlang-unixodbc: database support
java-environment: for Java support
lksctp-tools: for SCTP support
Conflicts With : erlang
Replaces : None
Download Size : 39.01 MiB
Installed Size : 106.73 MiB
Packager : Jan de Groot <jgc@archlinux.org>
Build Date : Fri 28 Apr 2017 08:44:33 AM -03
Validated By : MD5 Sum SHA-256 Sum Signature
/usr/lib/systemd/system/epmd.service is owned by erlang-nox 19.3-3
/usr/lib/systemd/system/epmd.socket is owned by erlang-nox 19.3-3
Steps to reproduce:
|
|
Packages | Any | Feature Request | Very High | High | [motion] contains systemd unit file | In Progress | |
Task Description
Description:
The Arch version of Motion from the snapshot used by Hyperbola comes with systemd support. Since Hyperbola follows the Init Freedom Campaign , systemd unit files removal is required or add OpenRC init scripts to replace it.
Additional info: * package version(s) * config and/or log files etc.
Repository : community
Name : motion
Version : 4.0.1-2
Description : A software motion detector which grabs images from video4linux devices and/or from webcams
Architecture : x86_64
URL : http://www.lavrsen.dk/foswiki/bin/view/Motion/WebHome
Licenses : GPL
Groups : None
Provides : None
Depends On : libjpeg v4l-utils ffmpeg
Optional Deps : None
Conflicts With : None
Replaces : None
Download Size : 235.61 KiB
Installed Size : 923.00 KiB
Packager : Sergej Pupykin <pupykin.s+arch@gmail.com>
Build Date : Mon 14 Nov 2016 02:17:55 PM -03
Validated By : MD5 Sum SHA-256 Sum Signature
/usr/lib/systemd/system/motion.service is owned by motion 4.0.1-2
Steps to reproduce:
|
|
Packages | Any | Feature Request | Very High | High | [tinc] contains systemd unit files | In Progress | |
Task Description
Description:
The Arch version of tinc from the snapshot used by Hyperbola comes with systemd support. Since Hyperbola follows the Init Freedom Campaign , systemd unit files removal is required or add OpenRC init scripts to replace it.
Additional info: * package version(s) * config and/or log files etc.
Repository : community
Name : tinc
Version : 1.0.31-2
Description : VPN (Virtual Private Network) daemon
Architecture : x86_64
URL : http://www.tinc-vpn.org/
Licenses : GPL
Groups : None
Provides : None
Depends On : lzo openssl zlib
Optional Deps : None
Conflicts With : None
Replaces : None
Download Size : 107.42 KiB
Installed Size : 194.00 KiB
Packager : Evangelos Foutras <evangelos@foutrelis.com>
Build Date : Mon 13 Mar 2017 01:06:11 AM -03
Validated By : MD5 Sum SHA-256 Sum Signature
/usr/lib/systemd/system/tinc.service is owned by tinc 1.0.31-2
/usr/lib/systemd/system/tinc@.service is owned by tinc 1.0.31-2
Steps to reproduce:
|
|
Packages | Any | Feature Request | Very High | High | [netdata] contains systemd unit files | In Progress | |
Task Description
Description:
The Arch version of tinc from the snapshot used by Hyperbola comes with systemd support. Since Hyperbola follows the Init Freedom Campaign , systemd unit files removal is required or add OpenRC init scripts to replace it.
Additional info: * package version(s) * config and/or log files etc.
Repositorio : community
Nombre : netdata
Versión : 1.6.0-3
Descripción : Real-time performance monitoring, in the greatest possible detail, over the web.
Arquitectura : x86_64
URL : https://github.com/firehol/netdata/wiki
Licencias : GPL
Grupos : Nada
Provee : Nada
Depende de : libmnl libnetfilter_acct zlib
Dependencias opcionales : nodejs: Webbox plugin
lm_sensors: sensors module
En conflicto con : Nada
Remplaza a : Nada
Tamaño de la descarga : 1778,98 KiB
Tamaño de la instalación : 6515,00 KiB
Encargado : Sven-Hendrik Haase <sh@lutzhaase.com>
Fecha de creación : dom 23 abr 2017 16:24:38 -05
Validado por : Suma MD5 Suma SHA-256 Firma
community/netdata /usr/lib/systemd/
community/netdata /usr/lib/systemd/system/
community/netdata /usr/lib/systemd/system/netdata.service
Steps to reproduce:
|
|
Packages | Any | Feature Request | Very High | High | [backuppc]: contains systemd files | Researching | |
Task Description
Description:
Since Hyperbola follows the Init Freedom Campaign, systemd unit files removal is required or add OpenRC init scripts to replace it.
Additional info: * package version(s)
community/backuppc 4.1.2-1 [installed]
Enterprise-grade system for backing up Linux, Windows and MacOS PCs
* config and/or log files etc.
Additional info:
Steps to reproduce: install it
|
|
Packages | Any | Feature Request | Very High | High | [gpsd]: contains systemd files | Researching | |
Task Description
Since Hyperbola follows the Init Freedom Campaign, systemd unit files removal is required or add OpenRC init scripts to replace it.
Additional info: * package version(s)
extra/gpsd 3.16-3 [installed]
GPS daemon and library to support USB/serial GPS devices
* config and/or log files etc.
Additional info:
Steps to reproduce: install it
|
|
Packages | Stable | Feature Request | Very High | High | [hiawatha]: remove systemd files, provide openrc | Researching | |
Task Description
Description:
Hiawatha contains only systemd files.
It shall be removed and openrc shall be provided
|
|
Packages | Any | Feature Request | Very High | High | [onioncat] needs OpenRC init script | Assigned | |
Task Description
Description:
Additional info:
Steps to reproduce:
|
|
Packages | Any | Feature Request | Very High | High | [umurmur] needs OpenRC init script and contains systemd... | Assigned | |
Task Description
Description:
Additional info:
umurmur /usr/lib/systemd/system/umurmur.service
Steps to reproduce:
|
|
Packages | Any | Feature Request | Very High | High | [prosody] needs OpenRC init script and contains systemd... | Assigned | |
Task Description
Description:
Additional info:
prosody /usr/lib/systemd/system/prosody.service
prosody /usr/lib/sysusers.d/prosody.conf
prosody /usr/lib/tmpfiles.d/prosody.conf
Steps to reproduce:
|
|
Packages | Any | Feature Request | Very High | High | [unrealircd] needs OpenRC init script and contains syst... | Assigned | |
Task Description
Description:
Additional info:
unrealircd /usr/lib/systemd/system/unrealircd.service
unrealircd /usr/lib/tmpfiles.d/unrealircd.conf
Steps to reproduce:
|
|
Packages | Any | Feature Request | Very High | High | [mcelog] needs OpenRC init script and contains systemd ... | Assigned | |
Task Description
Description:
Additional info:
mcelog /usr/lib/systemd/system/mcelog.service
Steps to reproduce:
|
|
Packages | Any | Feature Request | Very High | High | [bzr] needs OpenRC init script (bzr serve) | Assigned | |
Task Description
Description:
Additional info:
Note: needs a provide: bazaar
Steps to reproduce:
|
|
Packages | Any | Feature Request | Very High | High | [mercurial] needs OpenRC init scripts (hg serve and chg... | Assigned | |
Task Description
Description:
Additional info:
Note: needs a provide: hg
Steps to reproduce:
|
|
Packages | Any | Implementation Request | Very High | High | [murmur-headless] add a Murmur package capable of worki... | In Progress | |
Task Description
Description:
Add new a Murmur package capable of working without a graphical user interface. It’s common on servers and embedded devices that requires only interfaces like network (eg. SSH) or serial port to handle services.
Additional info:
Steps to reproduce:
|
|
Packages | Any | Implementation Request | Very High | High | [asterisk-headless] add an Asterisk package capable of ... | In Progress | |
Task Description
Description:
Add an Asterisk package capable of working without a graphical user interface. It’s common on servers and embedded devices that requires only interfaces like network (eg. SSH) or serial port to handle services.
Additional info:
Steps to reproduce:
|
|
Packages | Any | Implementation Request | Very High | Medium | [coturn] add new package | Unconfirmed | |
Task Description
Description:
Additional info:
Steps to reproduce:
|
|
Packages | Any | Implementation Request | Very High | Medium | [mediagoblin] add GNU MediaGoblin package | Unconfirmed | |
Task Description
Description:
Additional info:
Steps to reproduce:
|
|
Software Development | General | Implementation Request | Very High | Critical | POWER (ppc64le) porting | Deferred | |
Task Description
The unfortunate reality is that x86 computers come encumbered with built-in low-level backdoors like the Intel Management Engine , as well as nonfree boot firmware. This means that users can’t gain full control over their computers, even if they install a free operating system such as Hyperbola GNU/Linux-libre .
Hyperbola is working hard to fix these issues and getting closer every day, but for the time being, this is why many current Respects Your Freedom (RYF) offerings are refurbished older devices.
For the future of free computing, we need support architectures that do not come with such malware pre-installed, and the Power9-based Talos II promises to be a great architecture example for workstations and servers environments where Hyperbola is focused since is a fully free long-term support distribution.
Devices like this are the future of computing that Respects Your Freedom and for that reason it’s a high priority for Hyperbola port all packages for the POWER architecture (power64le).
NOTE: POWER porting is focused only for Hyperbola GNU/Linux-libre .
|
|
Software Development | General | Implementation Request | Very High | Critical | ARM (aarch and armv7h) porting | Deferred | |
Task Description
The unfortunate reality is that x86 computers come encumbered with built-in low-level backdoors like the Intel Management Engine , as well as nonfree boot firmware. This means that users can’t gain full control over their computers, even if they install a free operating system such as Hyperbola GNU/Linux-libre .
Hyperbola is working hard to fix these issues and getting closer every day, but for the time being, this is why many current Respects Your Freedom (RYF) offerings are refurbished older devices.
For the future of free computing, we need support architectures that do not come with such malware pre-installed, and ARM A7/A53 promises to be a great architecture example for low-power computers, laptops and embedded systems.
NOTE: ARM porting is focused only for HyperbolaBSD .
|
|
Packages | Any | Security Issue | Very High | Critical | [grub2] UEFI SecureBoot vulnerability + multiple flaws ... | Unconfirmed | |
Task Description
https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot/
https://9to5linux.com/grub2-boot-failure-issues-fixed-in-debian-and-ubuntu-update-now
|