<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Gentoo on Home of Jeremy Olexa</title>
    <link>https://blog.jolexa.net/categories/gentoo/</link>
    <description>Recent content in Gentoo on Home of Jeremy Olexa</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <copyright>&amp;copy; Copyright 2008-2016 | jolexa.net</copyright>
    <lastBuildDate>Wed, 28 Nov 2012 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://blog.jolexa.net/categories/gentoo/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>Gentoo: Graphing the Developer Web of Trust</title>
      <link>https://blog.jolexa.net/post/gentoo-graphing-the-developer-web-of-trust/</link>
      <pubDate>Wed, 28 Nov 2012 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/gentoo-graphing-the-developer-web-of-trust/</guid>
      <description>&lt;p&gt;&lt;em&gt;&amp;ldquo;Nothing gets people&amp;rsquo;s interest peaked like colorful graphics. Therefore, graphing the web of trust in your local area as you build it can help motivate people to participate as well as giving everyone a clear sense of what&amp;rsquo;s being accomplished as things progress.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;I graphed the &lt;a href=&#34;http://qa-reports.gentoo.org/output/wot-graph.png&#34;&gt;Gentoo Developer Web of Trust&lt;/a&gt;, as motivated by the (outdated) [Debian Web of Trust][2].&lt;/p&gt;

&lt;p&gt;Graph (same as link above) &amp;ndash; Redrawn weekly : &lt;a href=&#34;http://qa-reports.gentoo.org/output/wot-graph.png&#34;&gt;http://qa-reports.gentoo.org/output/wot-graph.png&lt;/a&gt;&lt;br /&gt;
Stats per Node : &lt;a href=&#34;http://qa-reports.gentoo.org/output/wot-stats.html&#34;&gt;http://qa-reports.gentoo.org/output/wot-stats.html&lt;/a&gt;&lt;br /&gt;
Source : &lt;a href=&#34;http://git.overlays.gentoo.org/gitweb/?p=proj/qa-scripts.git;a=blob;f=gen-dev-wot.sh;hb=HEAD&#34;&gt;http://git.overlays.gentoo.org/gitweb/?p=proj/qa-scripts.git;a=blob;f=gen-dev-wot.sh;hb=HEAD&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Enjoy.&lt;/p&gt;

&lt;p&gt;[2]: &lt;a href=&#34;http://www.chaosreigns.com/code/sig2dot/debian.html&#34;&gt;http://www.chaosreigns.com/code/sig2dot/debian.html&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Gentoo Miniconf 2012</title>
      <link>https://blog.jolexa.net/post/gentoo-miniconf-2012/</link>
      <pubDate>Wed, 24 Oct 2012 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/gentoo-miniconf-2012/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://www.gentoo.org/proj/en/miniconf/&#34;&gt;Gentoo Miniconf&lt;/a&gt; is over now but it was a great success. There was 30+ developers that went and I met quite some users too. Thanks to Theo (tampakrap) and Michal (miska) for organizing the event (and others), thanks to &lt;a href=&#34;http://www.opensuse.org/en/&#34;&gt;openSUSE&lt;/a&gt; for sponsoring and letting the Gentoo Linux guys hangout there. Thanks to the other sponsors too, Google, Aeroaccess, et al.&lt;/p&gt;

&lt;p&gt;More pics at the [Google+ event][3] page.&lt;/p&gt;

&lt;p&gt;It was excellent to meet all of you.&lt;/p&gt;

&lt;p&gt;[3]: &lt;a href=&#34;https://plus.google.com/u/0/events/c0fn547i01b94gae3v9tkn2umqc&#34;&gt;https://plus.google.com/u/0/events/c0fn547i01b94gae3v9tkn2umqc&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Gentoo: IPSec, L2TP VPN for iOS</title>
      <link>https://blog.jolexa.net/post/gentoo-ipsec-l2tp-vpn-for-ios/</link>
      <pubDate>Tue, 18 Sep 2012 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/gentoo-ipsec-l2tp-vpn-for-ios/</guid>
      <description>&lt;p&gt;There are &lt;a href=&#34;https://www.google.com/search?hl=en&amp;amp;q=ipsec%20openswan%20ios&amp;amp;aq=f&amp;amp;oq=undefined&#34;&gt;thousands&lt;/a&gt; of guides out there on this &lt;a href=&#34;https://www.google.com/search?hl=en&amp;amp;q=openswan%20site%3Aforums.gentoo.org&amp;amp;aq=f&amp;amp;oq=undefined&#34;&gt;subject&lt;/a&gt;, however I still struggled to set up an IPSEC VPN at first. This is a HOWTO for my own benefit &amp;ndash; maybe someone else will use it too. I struggled because most of the guides involved setting up the VPN on a NAT&amp;rsquo;d host and connecting to the VPN inside the network. I didn&amp;rsquo;t do that on my &lt;a href=&#34;http://blog.jolexa.net/tag/linode/&#34;&gt;linode&lt;/a&gt;, which has a static public IP.&lt;/p&gt;

&lt;p&gt;My objectives were clear:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Create a connection point that was semi-secure while connecting to open wifi networks&lt;/li&gt;
&lt;li&gt;Bypass some &amp;ldquo;You are not in the US&amp;rdquo; restrictions while on the &lt;a href=&#34;http://blog.jolexa.net/2012/08/announcing-my-long-term-travel-plans/&#34;&gt;road&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Step 1&lt;/strong&gt;: Install applications, net-misc/openswan, net-dialup/xl2tpd&lt;br /&gt;
&lt;strong&gt;Step 2&lt;/strong&gt;: Configure openswan:&lt;/p&gt;

&lt;pre&gt;# cat /etc/ipsec.conf 
config setup
    nat_traversal=yes
    virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:!10.152.2.0/24
    oe=off
    protostack=auto

conn L2TP-PSK-NAT
    rightsubnet=vhost:%priv
    also=L2TP-PSK-noNAT

conn L2TP-PSK-noNAT
    authby=secret
    pfs=no
    auto=add
    keyingtries=3
    rekey=no
    ikelifetime=8h
    keylife=1h
    type=transport
    left=1.1.1.1
    leftprotoport=17/1701
    right=%any
    rightprotoport=17/%any
    dpddelay=15
    dpdtimeout=30
    dpdaction=clear
&lt;/pre&gt;

&lt;pre&gt;# cat /etc/ipsec.secrets
1.1.1.1 %any: PSK &#34;TestSecret&#34;
&lt;/pre&gt;

&lt;p&gt;Where 1.1.1.1 is your public eth0 address and 10.152.2.0 is the subnet that xl2tpd will assign IPs from (can be anything, I picked this at the advice of a guide because it is unlikely to be assigned from a router on a public network)&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 3&lt;/strong&gt;: Configure xl2tpd:&lt;/p&gt;

&lt;pre&gt;# cat /etc/xl2tpd/xl2tpd.conf
[global]
ipsec saref = no

[lns default]
ip range = 10.152.2.2-10.152.2.254
local ip = 10.152.2.1
require chap = yes
refuse pap = yes
require authentication = yes
ppp debug = yes
pppoptfile = /etc/ppp/options.xl2tpd
length bit = yes
&lt;/pre&gt;

&lt;p&gt;The local IP must be inside the subnet but outside the IP range above.&lt;/p&gt;

&lt;pre&gt;# cat /etc/ppp/options.xl2tpd
refuse-mschap-v2
refuse-mschap
ms-dns 8.8.8.8
ms-dns 8.8.4.4
asyncmap 0
auth
lock
hide-password
local
#debug
name l2tpd
proxyarp
lcp-echo-interval 30
lcp-echo-failure 4
&lt;/pre&gt;

&lt;p&gt;The ms-dns lines are configurable to any DNS server you have access to.&lt;/p&gt;

&lt;pre&gt;# cat /etc/ppp/chap-secrets
# Format:
# client server secret IP-addresses
#
# Two lines are needed since it is two-sided auth
test l2tpd testpass *
l2tpd test testpass *
&lt;/pre&gt;

&lt;p&gt;&lt;strong&gt;Step 4&lt;/strong&gt;: Configure kernel parameters (sysctl)&lt;/p&gt;

&lt;pre&gt;# cat /etc/sysctl.conf
# only values specific for ipsec/l2tp functioning are shown here. merge with
# existing file
# iPad VPN
net.ipv4.ip_forward = 1
net.ipv4.conf.default.rp_filter = 0
net.ipv4.conf.default.accept_source_route = 0
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
net.ipv4.icmp_ignore_bogus_error_responses = 1
&lt;/pre&gt;

&lt;p&gt;Remember that sysctl.conf is evaluated at boot so run &lt;code&gt;sysctl -p&lt;/code&gt; to get the settings enabled now as well.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 5&lt;/strong&gt;: Configure firewall (iptables):&lt;br /&gt;
This is the &lt;strong&gt;critical step&lt;/strong&gt; that I wasn&amp;rsquo;t grokking from the existing guides in the wild. &lt;em&gt;Even when bringing the firewall down to test&lt;/em&gt;, you need the NAT/forwarding rules:&lt;/p&gt;

&lt;pre&gt;# iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
# iptables -A FORWARD -s 10.152.2.0/24 -j ACCEPT
# iptables -A FORWARD -j REJECT
# iptables -t nat -A POSTROUTING -s 10.152.2.0/24 -o eth0 -j MASQUERADE
&lt;/pre&gt;

&lt;p&gt;&lt;strong&gt;Step 6&lt;/strong&gt;: Configure the device/client:&lt;br /&gt;
Settings -&amp;gt; General -&amp;gt; Network -&amp;gt; VPN -&amp;gt; Add VPN Configuration&lt;/p&gt;

&lt;p&gt;L2TP&lt;br /&gt;
Description: &lt;em&gt;Description&lt;/em&gt;&lt;br /&gt;
Server: &lt;em&gt;1.1.1.1&lt;/em&gt; (or the hostname)&lt;br /&gt;
Account: &lt;em&gt;test&lt;/em&gt;&lt;br /&gt;
RSA SecurID=OFF&lt;br /&gt;
Password: &lt;em&gt;testpass&lt;/em&gt;&lt;br /&gt;
Secret: &lt;em&gt;TestSecret&lt;/em&gt;&lt;br /&gt;
Send All Traffic=On&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 7&lt;/strong&gt;: Verify it works by going to some &lt;a href=&#34;http://myipaddress.com/show-my-ip-address/&#34;&gt;IP display webpage&lt;/a&gt; and it should show &lt;em&gt;1.1.1.1&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Conclusion&lt;/strong&gt;: The above examples should be enough to get the VPN working. There are some tweaking oppurtunities that I didn&amp;rsquo;t document or elaborate on. There is plenty of examples out there to look at or research, however. This was all setup without the firewall configuration and the client would connect but there would be no onward internet activity. It acted just like there was a invalid DNS server configured, at that point I looked into setting up a NAT, dnsmasq on the local interface, and other wierd things. In the end, just needed to forward the traffic properly.&lt;/p&gt;

&lt;p&gt;With that knowledge of the firewall issue, the ultimate instructions would probably be this page: [&lt;a href=&#34;https://www.openswan.org/projects/openswan/wiki/L2TPIPsec_configuration_using_openswan_and_xl2tpd][6&#34;&gt;https://www.openswan.org/projects/openswan/wiki/L2TPIPsec_configuration_using_openswan_and_xl2tpd][6&lt;/a&gt;]&lt;/p&gt;

&lt;p&gt;[6]: &lt;a href=&#34;https://www.openswan.org/projects/openswan/wiki/L2TPIPsec_configuration_using_openswan_and_xl2tpd&#34;&gt;https://www.openswan.org/projects/openswan/wiki/L2TPIPsec_configuration_using_openswan_and_xl2tpd&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Linux: Easy/Free CLI Cloud Backup (box.com)</title>
      <link>https://blog.jolexa.net/post/linux-easyfree-cli-cloud-backup-box-com/</link>
      <pubDate>Fri, 10 Aug 2012 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/linux-easyfree-cli-cloud-backup-box-com/</guid>
      <description>&lt;p&gt;&lt;em&gt;Preface: I use to use &lt;a href=&#34;http://rsync.net/&#34;&gt;rsync.net&lt;/a&gt; for my offsite backup needs. They offer a nice solution, especially with the F/OSS contributor discount, but my needs were lesser than their offerings and I didn&amp;rsquo;t quite feel comfortable paying monthly for such needs. That is, get my critical (but small) backups off my host, MySQL, a few important files, etc. Most of my online world is now externally hosted (cloud) or easily rebuilt with key pieces of info.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;My current free 5G offsite backup solution is with &lt;a href=&#34;https://www.box.com/&#34;&gt;box.com&lt;/a&gt;. I don&amp;rsquo;t really use box.com as intended &amp;ndash; &amp;lsquo;a collaborative file sharing platform&amp;rsquo; but instead take advantage of the [WebDAV][3] access that they provide. So, a quick walk-through:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;code&gt;emerge davfs2&lt;/code&gt; (I pushed fixes in version &amp;gt;=1.4.7 in Gentoo Linux, I recommend that version)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;echo &amp;quot;https://www.box.com/dav /mnt/box.com davfs rw,user,noauto 0 0&amp;quot; &amp;gt;&amp;gt; /etc/fstab&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Mount the mountpoint as your user (enter your box.com credentials), copy files to the mounted filesystem.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;(&lt;em&gt;There are some finer details, like modifying $HOME/.davfs2/secrets and turning off use_locks, but I&amp;rsquo;m sure you smart people can figure that out via google.&lt;/em&gt;)&lt;/p&gt;

&lt;p&gt;Personally, I have a simple cron job that mounts, rsyncs, umounts that runs daily. Now, I have an accessible location to restore critical files as needed, just don&amp;rsquo;t look at the webui since it doesn&amp;rsquo;t understand compressed tarballs that well and is useless, heh.&lt;/p&gt;

&lt;p&gt;[3]: &lt;a href=&#34;http://en.wikipedia.org/wiki/Webdav&#34;&gt;http://en.wikipedia.org/wiki/Webdav&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Gentoo Miniconf / Linux Days 2012</title>
      <link>https://blog.jolexa.net/post/gentoo-miniconf-linux-days-2012/</link>
      <pubDate>Wed, 18 Jul 2012 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/gentoo-miniconf-linux-days-2012/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ll be there.&lt;/p&gt;

&lt;p&gt;[&lt;img class=&#34;alignnone&#34; title=&#34;bootstrapping-awesome-2012.png&#34; src=&#34;http://www.gentoo.org/proj/en/miniconf/banners/2012/07-bootstrapping-awesome-2012.png&#34; alt=&#34;&#34; width=&#34;400&#34; height=&#34;240&#34; /&gt;][1]&lt;/p&gt;

&lt;p&gt;[1]: &lt;a href=&#34;http://www.linuxdays.cz/en/&#34;&gt;http://www.linuxdays.cz/en/&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Linode don&#39;t use barriers and ext-4</title>
      <link>https://blog.jolexa.net/post/linode-dont-use-barriers-and-ext-4/</link>
      <pubDate>Tue, 14 Feb 2012 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/linode-dont-use-barriers-and-ext-4/</guid>
      <description>&lt;p&gt;On my &lt;a href=&#34;http://www.linode.com/?r=b4fa70eb87c890e08baf7b0c7852fb7cecd8963b&#34;&gt;Linode&lt;/a&gt; running &lt;a href=&#34;http://www.gentoo.org/&#34;&gt;Gentoo Linux&lt;/a&gt;, I converted to ext4 some time ago and didn&amp;rsquo;t have any issues until now for some reason, mostly because I don&amp;rsquo;t reboot &lt;em&gt;that&lt;/em&gt; often to notice. The symptoms are :&lt;/p&gt;

&lt;p&gt;Every reboot, you will see:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;EXT4-fs error (device xvda): ext4_journal_start_sb:296: Detected aborted journal&amp;lt;br /&amp;gt;
EXT4-fs (xvda): Remounting filesystem read-only&amp;lt;br /&amp;gt;
&lt;/code&gt;&lt;br /&gt;
and a subsequent reboot fixes this by a forced run of fsck. Now that is an annoying one, every other reboot results in a crippled system and otherwise a fsck &amp;ldquo;fixes&amp;rdquo; it and you have no issues.&lt;/p&gt;

&lt;p&gt;So, after some research I found that &lt;a href=&#34;http://kernelnewbies.org/Ext4#head-25c0a1275a571f7332fa196d4437c38e79f39f63&#34;&gt;barriers are enabled by default&lt;/a&gt; and they don&amp;rsquo;t really make sense on a hosted vm guest. I qualify the last statement by google research, not an expert but it seems that the common knowledge is that disabling barriers is safe for battery backed up storage, and Linode disabled barriers completly.&lt;/p&gt;

&lt;p&gt;The solution to the above problem is simply disabling barriers. Like so:&lt;/p&gt;

&lt;p&gt;In /etc/fstab:&lt;br /&gt;
&lt;code&gt;/dev/xvda   /            ext4    noatime,barrier=0              0 1&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Source: &lt;a href=&#34;http://forum.linode.com/viewtopic.php?t=8259&#34;&gt;Linode Forums&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Gentoo: Colemak keymap support</title>
      <link>https://blog.jolexa.net/post/gentoo-colemak-keymap-support/</link>
      <pubDate>Fri, 11 Nov 2011 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/gentoo-colemak-keymap-support/</guid>
      <description>

&lt;p&gt;&lt;a href=&#34;http://colemak.com/&#34;&gt;Colemak&lt;/a&gt; is my new keymap of choice. Luckily, Gentoo Linux supports it well. Unlike some of the crazy instructions people have &lt;a href=&#34;http://siavashs.org/blog:dvorak_and_colemak_keyboard_layouts_on_gentoo&#34;&gt;posted&lt;/a&gt; out [there][3], you only need to edit &lt;em&gt;2 files&lt;/em&gt; to convert your console and Xorg server. Note, I&amp;rsquo;m taking the time to write this because I &lt;strong&gt;couldn&amp;rsquo;t&lt;/strong&gt; find easy instructions out there&amp;hellip;&lt;/p&gt;

&lt;p&gt;`&lt;br /&gt;
% cat /etc/conf.d/keymaps&lt;br /&gt;&lt;/p&gt;

&lt;h1 id=&#34;use-keymap-to-specify-the-default-console-keymap-there-is-a-complete-tree-br:5d25139ee440b3aee1a06bb448b35fef&#34;&gt;Use keymap to specify the default console keymap.  There is a complete tree&lt;br /&gt;&lt;/h1&gt;

&lt;h1 id=&#34;of-keymaps-in-usr-share-keymaps-to-choose-from-br:5d25139ee440b3aee1a06bb448b35fef&#34;&gt;of keymaps in /usr/share/keymaps to choose from.&lt;br /&gt;&lt;/h1&gt;

&lt;p&gt;keymap=&amp;ldquo;en-latin9&amp;rdquo;&lt;br /&gt;
&amp;lt;&amp;hellip;&amp;gt;&lt;br /&gt;
`&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;% cat /etc/X11/xorg.conf.d/30-keyboard.conf 
Section &amp;quot;InputClass&amp;quot;
        Identifier &amp;quot;keyboard-all&amp;quot;
        Option &amp;quot;XkbVariant&amp;quot; &amp;quot;colemak&amp;quot;
EndSection
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;[3]: &lt;a href=&#34;http://forums.gentoo.org/viewtopic-t-639368-start-0.html&#34;&gt;http://forums.gentoo.org/viewtopic-t-639368-start-0.html&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Tip: &#34;Intelligent&#34; bugzilla mail threading in GMail using procmail</title>
      <link>https://blog.jolexa.net/post/tip-intelligent-bugzilla-mail-threading-in-gmail-using-procmail/</link>
      <pubDate>Mon, 24 Oct 2011 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/tip-intelligent-bugzilla-mail-threading-in-gmail-using-procmail/</guid>
      <description>&lt;p&gt;&lt;em&gt;(Preface: Target audience for this post is Gentoo Devs + GMail WebUI users, however, anyone that forwards bugmail to GMail and has procmail between them could also use this.)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;I find it annoying that the GMail web interface chooses to thread messages based on subject name alone, this creates &lt;strong&gt;two&lt;/strong&gt; threads for every new bug report sent to you from bugzilla. Sadly, we can&amp;rsquo;t control the threading that Google tells us is &amp;ldquo;the only way&amp;rdquo; (subject based threading or email header based threading, which bugzilla does correctly). If you want to &lt;a href=&#34;http://blog.mozilla.com/nnethercote/2011/06/09/gmail-and-bugzilla/&#34; target=&#34;_blank&#34;&gt;follow&lt;/a&gt; the &lt;a href=&#34;http://blog.mozilla.com/nnethercote/2011/06/10/gmail-and-bugzilla-an-update/&#34; target=&#34;_blank&#34;&gt;rabbit&lt;/a&gt; &lt;a href=&#34;https://bugzilla.mozilla.org/show_bug.cgi?id=650575&#34; target=&#34;_blank&#34;&gt;trail&lt;/a&gt; &lt;a href=&#34;https://bugzilla.mozilla.org/show_bug.cgi?id=528889&#34; target=&#34;_blank&#34;&gt;that&lt;/a&gt; I &lt;a href=&#34;https://bugzilla.mozilla.org/show_bug.cgi?id=650575#c23&#34; target=&#34;_blank&#34;&gt;went&lt;/a&gt; &lt;a href=&#34;https://bugs.gentoo.org/370977&#34; target=&#34;_blank&#34;&gt;on&lt;/a&gt; &lt;a href=&#34;https://bugzilla.mozilla.org/show_bug.cgi?id=663747&#34; target=&#34;_blank&#34;&gt;regarding&lt;/a&gt; this subject, I won&amp;rsquo;t &lt;a href=&#34;https://bugzilla.mozilla.org/show_bug.cgi?id=589128&#34; target=&#34;_blank&#34;&gt;stop&lt;/a&gt; you&amp;hellip;&lt;/p&gt;

&lt;p&gt;Or you can use procmail to rewrite the subject, that is, remove &amp;ldquo;New: &amp;ldquo; from the first email:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;# Remove &amp;quot;New: &amp;quot; from the subject so threading in gmail works
SUBJ_=`formail -xSubject: | expand | tr -d &#39;\n&#39; | sed -e &#39;s/^[ ]*//g&#39; -e &#39;s/New: //&#39;`
:0
* ^From: bugzilla-daemon@gentoo.org
{
    :0 fwh
    | formail -i&amp;quot;Subject: ${SUBJ_}&amp;quot;
}
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Tangentially related that may be useful, is this rule that kills duplicate messages when you report a bug and are assigned the same bug (or in CC). The bugzilla software has no way of knowing what email aliases you may be in.&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;# Kill duplicate messages. If I am the reporter *and* the bug is assigned to a
# team I am in, delete the mail to me directly
:0
* ^To: username@gentoo.org
* ^From: bugzilla-daemon@gentoo.org
* ^X-Bugzilla-Reporter: username@gentoo.org
* ^X-Bugzilla-(Assigned-To|CC):.*(team1|team2)@gentoo.org
/dev/null&amp;lt;/pre&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;/p&amp;gt;


*I like the GMail WebUI. I use it. Please don&#39;t suggest that I should use other clients, I already know that other clients can handle the threading fine.*
&lt;/code&gt;&lt;/pre&gt;
</description>
    </item>
    
    <item>
      <title>Gentoo: Removing USE=&#34;python perl&#34; from the default profile</title>
      <link>https://blog.jolexa.net/post/gentoo-removing-usepython-perl-from-the-default-profile/</link>
      <pubDate>Wed, 05 Oct 2011 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/gentoo-removing-usepython-perl-from-the-default-profile/</guid>
      <description>&lt;p&gt;Well, I got sick of setting &lt;code&gt;-python -perl&lt;/code&gt; on my Gentoo hosts, I even consider them &amp;ldquo;questionable defaults&amp;rdquo; for a majority of Gentoo users..&lt;/p&gt;

&lt;p&gt;So, let this be an advanced notice that you may see some rebuilds for useflag changes. There has been sufficient testing such that there should be few to nil problems, but we can&amp;rsquo;t test everything. Please file bug reports, if needed.&lt;/p&gt;

&lt;p&gt;See also:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;http://archives.gentoo.org/gentoo-announce/msg_f869d4b5ec1d06beb681b5c268699058.xml&#34;&gt;Gentoo Announce Message&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://archives.gentoo.org/gentoo-dev-announce/msg_ae405bb743eeda9dc66773998ee50759.xml&#34;&gt;Gentoo Developer Announce Message&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[Bug 250179][3]&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;[3]: &lt;a href=&#34;https://bugs.gentoo.org/250179&#34;&gt;https://bugs.gentoo.org/250179&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Gentoo: per-package PORTAGE_TMPDIR settings</title>
      <link>https://blog.jolexa.net/post/gentoo-per-package-portage_tmpdir-settings/</link>
      <pubDate>Fri, 16 Sep 2011 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/gentoo-per-package-portage_tmpdir-settings/</guid>
      <description>&lt;p&gt;I don&amp;rsquo;t know how many people know about per-package environment variables in portage since 2.1.9 or so. (ref: &lt;a href=&#34;https://bugs.gentoo.org/show_bug.cgi?id=44796&#34; target=&#34;_blank&#34;&gt;bug 44796&lt;/a&gt;) It is a worthwhile enhancement to know about, regardless. Like most people, I have my PORTAGE_TMPDIR on tmpfs to speed up compilation times and reduce I/O usage. My 2G tmpfs mounted on /var/tmp/portage is large enough for almost all packages, even multiple jobs at once, however, not all. Solution:&lt;/p&gt;

&lt;p&gt;% cat /etc/portage/package.env&lt;br /&gt;
app-office/libreoffice notmpfs.conf&lt;br /&gt;
% cat /etc/portage/env/notmpfs.conf&lt;br /&gt;
PORTAGE_TMPDIR=&amp;ldquo;/var/tmp/notmpfs&amp;rdquo;&lt;/p&gt;

&lt;p&gt;(More info available in the portage man page)&lt;/p&gt;

&lt;p&gt;Now, when I find my next package that needs notmpfs, it is as easy as: &lt;code&gt;echo &amp;quot;cat-egory/pkg notmpfs.conf&amp;quot; &amp;gt;&amp;gt; /etc/portage/package.env&lt;/code&gt; which is much easier than bashrc hacks or something else insane that I have seen. Of course you can extend that to most &lt;code&gt;make.conf&lt;/code&gt; settings, hope that helps someone.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Gentoo: Infra team update</title>
      <link>https://blog.jolexa.net/post/gentoo-infra-team-update/</link>
      <pubDate>Sun, 10 Apr 2011 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/gentoo-infra-team-update/</guid>
      <description>&lt;p&gt;It has been awhile since I&amp;rsquo;ve posted about what I&amp;rsquo;ve been doing with Gentoo Linux. So, here is a general update for the team that I have been spending most of my time with.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;You may have seen the &lt;a href=&#34;http://bugs.gentoo.org&#34;&gt;Bugzilla&lt;/a&gt; upgrade that Christian was working on. Gentoo moved from the bottom of the &lt;a href=&#34;http://lpsolit.wordpress.com/bugzilla-usage-worldwide/&#34;&gt;list&lt;/a&gt; provided from one of the upstream devs to the top of the list. (As of April 2011)&lt;/li&gt;
&lt;li&gt;I finally put an idea of mine into reality of graphing the number of &amp;ldquo;emerge &amp;ndash;sync&amp;rsquo;s&amp;rdquo; against the rsync.gentoo.org rotation. &lt;a href=&#34;http://mirrorstats.gentoo.org/rsync/rsync-usage.png&#34;&gt;Full graph&lt;/a&gt; and &lt;a href=&#34;http://mirrorstats.gentoo.org/rsync/rsync-usage-last4weeks.png&#34;&gt;last 4 weeks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A new reporting website was born: &lt;a href=&#34;http://qa-reports.gentoo.org/&#34;&gt;http://qa-reports.gentoo.org/&lt;/a&gt; &amp;ndash; The vision was: &amp;ldquo;Many Gentoo devs have useful scripts and many people complain that there is not a central place to see all the output.&amp;rdquo; This site is a solution, and open for all. repo: &lt;a href=&#34;http://git.overlays.gentoo.org/gitweb/?p=proj/qa-scripts.git;a=summary&#34;&gt;qa-scripts.git&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A new &amp;ldquo;Get Gentoo at a glance&amp;rdquo; website was born: &lt;a href=&#34;http://get.gentoo.org/&#34;&gt;http://get.gentoo.org/&lt;/a&gt; that Matthew is still working on, so maybe expect some layout changes &amp;ndash; The motivation for this was inspired from &lt;a href=&#34;https://bugs.gentoo.org/show_bug.cgi?id=350271&#34;&gt;bug 350271&lt;/a&gt;, repo: &lt;a href=&#34;http://git.overlays.gentoo.org/gitweb/?p=proj/get-gentoo.git;a=summary&#34;&gt;get-gentoo.git&lt;/a&gt;

&lt;ul&gt;
&lt;li&gt;Some behind the scenes work involving our mastermirror service. The current hardware running this important service is one of the oldest hosts we have.&lt;/ul&gt;
Of course, there is always the untold hours to keep Gentoo Linux infrastructure running happily for all customers. As a final note, if you have a good idea, feel free to propose it via bugs or IRC. We will listen and definately avoid [NIH][8] syndrome if we can. Cheers.&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;[8]: &lt;a href=&#34;http://en.wikipedia.org/wiki/NIH_syndrome&#34;&gt;http://en.wikipedia.org/wiki/NIH_syndrome&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Tip: Single Purpose Password-less SSH Key</title>
      <link>https://blog.jolexa.net/post/tip-single-purpose-password-less-ssh-key/</link>
      <pubDate>Fri, 11 Feb 2011 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/tip-single-purpose-password-less-ssh-key/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Scenario&lt;/strong&gt;: You need to setup a service that requires ssh access to a remote host, possibly/probably by the root user. This service needs to run at regular intervals and it is critical that it works without a human entering a passphrase (even &lt;em&gt;once&lt;/em&gt;).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;: The obvious solution that comes to mind is a ssh key. But a password-less key that allows root login? &lt;strong&gt;RED FLAG&lt;/strong&gt;. However, there is a way to accomplish this without allowing a root login completely. That is to create, what I call, a single purpose key. I feel like this &lt;u&gt;not&lt;/u&gt; a widely known trick, so I am archiving it so I don&amp;rsquo;t forget myself.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Details:&lt;/strong&gt;&lt;br /&gt;
(Where local host is the host that needs ssh access and remote host is the host that you are &amp;ldquo;opening&amp;rdquo; up or allowing ssh access to)&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;On the local host, create a ssh key without a passphrase for the root user, this is widely documented via other sources&lt;/li&gt;
&lt;li&gt;On the remote host, add the key to the &lt;code&gt;/root/.ssh/authorized_keys&lt;/code&gt; file. However, start the line in that file with &lt;code&gt;command=&amp;quot;/root/bin/validate-ssh.sh&amp;quot;&lt;/code&gt;&lt;/li&gt;

&lt;li&gt;&lt;p&gt;On the remote host, the &lt;code&gt;/root/bin/validate-ssh.sh&lt;/code&gt; script is a simple script that allows access to your service and exits for anything else. An example of allowing rsync access [only]:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;% cat /root/bin/validate-ssh.sh 
#!/bin/bash
case &amp;quot;$SSH_ORIGINAL_COMMAND&amp;quot; in
    rsync\ --server*)
        # uncomment for debug
        # echo &amp;quot;$(date +%Y%m%d): $SSH_ORIGINAL_COMMAND&amp;quot; &amp;gt;&amp;gt; /var/log/ssh-cmd.log
        $SSH_ORIGINAL_COMMAND
        ;;
    # debug
    testconnect)
        echo &amp;quot;You successfully connected to $(hostname)&amp;quot;
        ;;
    *)
        echo &amp;quot;Sorry, command &#39;$SSH_ORIGINAL_COMMAND&#39; is not allowed&amp;quot;
        exit 1
        ;;
esac
&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;

&lt;li&gt;&lt;p&gt;Optional, if you only want to allow this access from a small set of hosts add &lt;code&gt;from=&amp;quot;192.168.1.11,10.80.80.1&amp;quot;&lt;/code&gt; to the same line in &lt;code&gt;/root/.ssh/authorized_keys&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;So, now, you can use that password-less ssh key as root (assuming the remote host &lt;em&gt;allows&lt;/em&gt; root logins via ssh) and you should see something. &lt;code&gt;ssh root@remote testconnect&lt;/code&gt; will return that string. &lt;code&gt;rsync root@remote:/file&lt;/code&gt; will work. Everything else will get the message that indicates it wasn&amp;rsquo;t allowed. This is expandable to just about everything provided that you know the &amp;ldquo;$SSH_ORIGINAL_COMMAND&amp;rdquo; &amp;ndash; on another host I use it to allow password-less sshfs access, so &lt;code&gt;SSH_ORIGINAL_COMMAND=/usr/lib/misc/sftp-server&lt;/code&gt; and so-forth.&lt;/p&gt;

&lt;p&gt;Naturally, this will work for other users/uses as well. I&amp;rsquo;ve seen references that some admins are using this to allow access if and only if they enter a sekrit token, etc. I&amp;rsquo;ll also say that you should be smart with this, opening up root access is a hole &amp;ndash; if anyone compromises the local host, I suppose they could get access to the remote host if they knew how.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Updating Intel Atom processor microcode</title>
      <link>https://blog.jolexa.net/post/updating-intel-atom-processor-microcode/</link>
      <pubDate>Tue, 25 Jan 2011 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/updating-intel-atom-processor-microcode/</guid>
      <description>&lt;p&gt;The problem:&lt;/p&gt;

&lt;pre&gt;% dmesg | grep -i micro
Atom PSE erratum detected, BIOS microcode update recommended
Atom PSE erratum detected, BIOS microcode update recommended
microcode: CPU0 sig=0x106c2, pf=0x4, revision=0x208
microcode: CPU1 sig=0x106c2, pf=0x4, revision=0x208
microcode: Microcode Update Driver: v2.00 , Peter Oruba&lt;/pre&gt;

&lt;p&gt;I found out that some recent kernel that I loaded at an unknown time, was able to point out that I had &amp;lsquo;old&amp;rsquo; microcode for my processor on my &lt;a href=&#34;http://blog.jolexa.net/tag/aspire1/&#34;&gt;Aspire1 ZG5&lt;/a&gt;. I searched around for a BIOS upgrade, but since this is an older generation netbook, I quickly gave up when my searching yielded nothing useful. There is a userspace tool that you can use to &amp;lsquo;upgrade&amp;rsquo; the microcode provided by Intel on every boot. In Gentoo Linux, that is called &lt;code&gt;sys-apps/microcode-ctl&lt;/code&gt;. Simply install that and enable the init script on boot.&lt;/p&gt;

&lt;p&gt;The output after:&lt;/p&gt;

&lt;pre&gt;% dmesg | grep -i micro
Atom PSE erratum detected, BIOS microcode update recommended
Atom PSE erratum detected, BIOS microcode update recommended
microcode: CPU0 sig=0x106c2, pf=0x4, revision=0x208
microcode: CPU1 sig=0x106c2, pf=0x4, revision=0x208
microcode: Microcode Update Driver: v2.00 , Peter Oruba
microcode: CPU0 updated to revision 0x218, date = 2009-04-10
microcode: CPU1 updated to revision 0x218, date = 2009-04-10&lt;/pre&gt;

&lt;p&gt;References:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://wiki.archlinux.org/index.php/Microcode&#34;&gt;https://wiki.archlinux.org/index.php/Microcode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;[Flameeyes&amp;rsquo;s Weblog : Microupdates for microcodes][2]&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Edit: Added a reference&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;[2]: &lt;a href=&#34;http://blog.flameeyes.eu/2011/01/17/microupdates-for-microcodes&#34;&gt;http://blog.flameeyes.eu/2011/01/17/microupdates-for-microcodes&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Gentoo: A critical look at the QA process</title>
      <link>https://blog.jolexa.net/post/gentoo-a-critical-look-at-the-qa-process/</link>
      <pubDate>Wed, 29 Dec 2010 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/gentoo-a-critical-look-at-the-qa-process/</guid>
      <description>&lt;p&gt;&lt;em&gt;This post will probably annoy some people, or bring bad &amp;ldquo;spotlight&amp;rdquo; to Gentoo Linux. I call it a case study, but it is just my opinions&amp;hellip;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The QA team has said that there is some sort of &amp;ldquo;policy&amp;rdquo; on masking packages that break reverse dependencies. I&amp;rsquo;ll subscribe that that policy for the sake of not breaking users machines on purpose, however, let&amp;rsquo;s take a look at the current case study: &lt;strong&gt;poppler-0.16&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;package.mask (in context, name removed because it isn&amp;rsquo;t needed):&lt;br /&gt;
+# Masked because of ABI change, breaks&lt;br /&gt;
+# depending packages. Keep masked until depended packages&lt;br /&gt;
+# got fixed (adjusted dependency or fixing version bump).&lt;br /&gt;
+# tracer bug 349918&lt;br /&gt;
+=app-text/poppler-0.16.0&lt;/p&gt;

&lt;p&gt;&amp;hellip;and there was some discussion on IRC. The QA team (at least a few members) says that the &lt;em&gt;&amp;ldquo;tree is broken&amp;rdquo;&lt;/em&gt; with poppler-0.16. At time of this writing, 7 packages were reported on the tracker bug and 2 were fixed already. So, it is my opinion that progress for Gentoo is hampered because of this masking. I&amp;rsquo;ll explain why but first the different theories to package testing that I have observed.&lt;/p&gt;

&lt;p&gt;&lt;u&gt;Theory 1:&lt;/u&gt;&lt;br /&gt;
Run full arch for stability. The problem with this theory is that some group of people/machines need to test ~arch packages first and report issues, otherwise they will hit the stable users and the concept of the arch/~arch tree will break down. The advantage being less compilation in general, and the goal being stability or less breakage. I consider this theory for people that are new to Gentoo.&lt;/p&gt;

&lt;p&gt;&lt;u&gt;Theory 2:&lt;/u&gt;&lt;br /&gt;
Run full ~arch to find interaction issues. This is a fine theory, but not for me. Even though I am a Gentoo dev, I don&amp;rsquo;t have copious amounts of free time to contribute how I want if I am running ~arch. It is my personal opinion that users should &lt;strong&gt;not&lt;/strong&gt; run full ~arch if they do not want to be bothered contributing back to gentoo/upstream, via bug reports, patches, etc. The advantage here, is that full ~arch users/machines will be able to find issues with the package before it is deemed &amp;ldquo;stable&amp;rdquo; &amp;ndash; in theory, finding issues fast and being fixed fast. The downside being more compilation, occasional breakage, and/or random mistakes (devs are human, after-all). The Gentoo Handbook &lt;a href=&#34;http://www.gentoo.org/doc/en/handbook/handbook-x86.xml?part=2&amp;amp;chap=1#doc_chap5&#34;&gt;says&lt;/a&gt; that ~arch needs more testing and isn&amp;rsquo;t enabled by default. I&amp;rsquo;d consider this theory for power users. &amp;ldquo;I only want the latest packages&amp;rdquo; is no excuse for using this theory if you are going to complain about the above mentioned downsides.&lt;/p&gt;

&lt;p&gt;&lt;u&gt;Theory 3:&lt;/u&gt;&lt;br /&gt;
Run mostly arch and a few ~arch packages. This is what most of my machines run. That is, arch (stable) system and ~arch for packages that I maintain (or help maintain). The advantage here is what I consider &lt;em&gt;real&lt;/em&gt; integration testing. The theory is that everything in ~arch will become arch, at one point. These ~arch packages are coming in one-by-one, so it makes no sense to &lt;em&gt;only&lt;/em&gt; test a full ~arch tree if the package will be entering the arch tree. This is what the arch team does when they mark packages stable. The downside being, more management, maybe some dependency issues if they aren&amp;rsquo;t stated properly, etc. I&amp;rsquo;d consider this theory for people that prefer stability but enjoy the latest packages for some apps.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;I think it is valuable to have a user base that is doing all of those theories. &amp;hellip;back to poppler.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;As we have seen in the past, once a package is &amp;ldquo;masked for testing&amp;rdquo; &amp;ndash; it may take years to lift that mask because no one actually tests it. And why should you? It is masked and therefore not even in the &lt;em&gt;testing&lt;/em&gt; category (~arch)!! Bingo, the crux of this case study. Technically speaking, there is nothing wrong with poppler-0.16.0, it is perfectly fine to be in ~arch by its own criteria. On the other hand, it&amp;rsquo;s ABI change breaks packages that haven&amp;rsquo;t been fixed to work with the new ABI yet. By masking a package that changes ABI with a soname change, it could (and should, in my opinion) be considered slowing progress for Gentoo. It should &lt;strong&gt;not&lt;/strong&gt; be considered that the &amp;ldquo;[whole] tree is broken&amp;rdquo; &amp;ndash; these 7 packages may just be the tip of the iceberg in the breakage category, but we won&amp;rsquo;t know if it is masked and users are not contributing. Let&amp;rsquo;s remind ourselves that the arch tree is still functioning properly at this point and &amp;ldquo;stable&amp;rdquo; users won&amp;rsquo;t see any issues&amp;hellip;now. For them, thankfully, the ~arch users (including devs) are contributing to Gentoo via bug reports &amp;amp; patches. It should also be noted that nothing is being broke &amp;ldquo;on purpose&amp;rdquo; here, bugs are being filed and bugs are being fixed &amp;ndash; this is the goal of a software project, right?&lt;/p&gt;

&lt;p&gt;So, the way I see it, is a chain reaction.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Package enters the tree that causes a slight nuisance. &lt;sup&gt;7&lt;/sup&gt;&amp;frasl;&lt;sub&gt;14205&lt;/sub&gt; known packages affected or 0.04 % of the tree.&lt;/li&gt;
&lt;li&gt;The QA team deems this problem package as too severe to allow in ~arch and masks it. (Personal opinion is the 0.04% of the tree is not a servere problem)&lt;/li&gt;
&lt;li&gt;The maintainer of the problem package is trying to identify breakages by leaving it in ~arch (and relying on the power users)&lt;/li&gt;
&lt;li&gt;Since the package is masked, the effects of this problem package will be prolonged because &amp;ldquo;no one&amp;rdquo; will be testing it in ~arch.&lt;/li&gt;
&lt;li&gt;The 7 affected packages are fixed, the problem package is unmasked&lt;/li&gt;
&lt;li&gt;A new set of affected packages are found&lt;/li&gt;
&lt;li&gt;repeat above&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;And now for some hard questions:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;How should Gentoo make it easier to add packages that break reverse dependencies if ~arch isn&amp;rsquo;t appropriate and nothing really happens when package.mask&amp;rsquo;d?&lt;/li&gt;
&lt;li&gt;Is ~arch becoming a second stable tree and thus losing value in general?&lt;/li&gt;
&lt;li&gt;Related, are overlays hurting Gentoo? The Xfce team subscribes to the theory that ~arch is &lt;em&gt;the&lt;/em&gt; place to get useful testing feedback. The Xfce pre releases are in ~arch so the final release is ready for arch asap. This means that we have less work in the long run because we are maintaining less versions sooner and in better quality. The GNOME team subscribes to the theory that their overlay is for new releases and it takes longer to get packages in ~arch and thus longer to arch (my observation only, not official)&lt;/li&gt;
&lt;li&gt;portage-2.2 has this cool &amp;ldquo;preserved-libs&amp;rdquo; feature that wouldn&amp;rsquo;t help compilation issues in this case but might help runtime issues by keeping the old lib(s) around. I like this feature but it is still masked for majority of the users, even though many devs are using it &amp;ndash; is it time to release it to the world with all the [bugs][2] it has?&lt;/li&gt;
&lt;li&gt;Related, does masking a feature block contributors? I want to say yes simply due to exposure.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Disclaimer: This was in NO WAY meant to be a personal attack against anyone. I can live with agreeing to disagree with people. But I can&amp;rsquo;t agree with not bringing something up because it is a controversial topic.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;[2]: &lt;a href=&#34;http://bugs.gentoo.org/240323&#34;&gt;http://bugs.gentoo.org/240323&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Gentoo: Xfce 4.8pre2 Released</title>
      <link>https://blog.jolexa.net/post/gentoo-xfce-4-8pre2-released/</link>
      <pubDate>Mon, 06 Dec 2010 00:00:00 +0000</pubDate>
      
      <guid>https://blog.jolexa.net/post/gentoo-xfce-4-8pre2-released/</guid>
      <description>&lt;p&gt;Xfce-4.8pre2 was &lt;a href=&#34;http://www.xfce.org/about/news?id=25&#34;&gt;announced&lt;/a&gt; yesterday. Gentoo has it available already thanks to the work of Samuli (ssuominen). The pre1 version was available with 0day bumps too, that proved to have the normal beta release &amp;ldquo;issues&amp;rdquo;, there are many bugs fixed in pre2 (&lt;a href=&#34;http://www.xfce.org/documentation/changelogs/4.8pre2&#34;&gt;ChangeLog&lt;/a&gt;). I saw several Gentoo users participating on the Xfce bugtracker, thanks. If you are of the type to test and report bugs, feel free to upgrade to 4.8pre2 and help make 4.8 final a solid release by participating upstream ([bug tracker][3]).&lt;/p&gt;

&lt;p&gt;The final 4.8 release is scheduled for January 16th, 2011. The Gentoo Xfce team will continue to bring you 0day bumps if possible. The 4.8 series will not hit the Gentoo stable tree until after the final release.&lt;/p&gt;

&lt;p&gt;[3]: &lt;a href=&#34;http://bugzilla.xfce.org/&#34;&gt;http://bugzilla.xfce.org/&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
  </channel>
</rss>