| DistroWatch Weekly
|DistroWatch Weekly, Issue 30, 5 January 2004
- Hardened Linux From Scratch
- JAMD and Xdefine Linux
- Most visited pages in 2003
- Released last week
- Upcoming releases: Knoppix 3.4
- New additions: Tilix, Shabdix, SCI.Linux, Overclockix, Tao, ZENIX, Polar Bear, Slix, WOMP!
- New on the waiting list: Litrux, Lineox, Rocks Cluster, Vermillion, Routix, Kanotix, LIVUX, Dave/Dina, Bluewall
- Reader feedback: TurboUpdate
Welcome to this year's first edition of DistroWatch Weekly. If pages seem to load slower than usual, that's because the Knoppix review published here yesterday proved extremely popular with the Slashdot crowd for much of today. Things should be slowly coming back to normal now, so let's get on with the programme.
Hardened Linux From Scratch
The 4th quarter of 2003 brought us a surprisingly high number of successful attacks on servers hosting high-profile Linux projects. Some of the compromised machines included servers running the Debian project, GNU, MPlayer, Savannah and others, and there was even an attempt to sneak a Trojan Horse into the Linux kernel development tree. While none of these attacks caused any serious damage to the affected projects, they have succeeded in making parts of the projects' web sites inaccessible for a prolonged period of time, causing annoyance to many of us. They have also highlighted the need to take security issues more seriously than ever.
One of the new projects aiming to educate Linux users about various methods of preventing common exploits is the newly launched Hardened Linux From Scratch (HLFS) project. This is part of the growing family of Linux From Scratch (LFS) projects, which includes the original LFS, as well as Automated Linux From Scratch (ALFS), Beyond Linux From Scratch (BLFS) and other subprojects. What is HLFS all about? Let the developers explain:
"Over the past few weeks, a discussion about a security-oriented LFS book has dominated the lfs-security list. Some clear ideas about the form and content of this initiative are crystalizing, and it was decided to give the initiators of this project a decent platform to work on. So far, a mailinglist (hlfs-dev)
has been created for Hardened Linux From Scratch, as it was dubbed. HLFS will become a book that provides the reader with a fundamental understanding of security that can be used as a base for further research. Part of the process in teaching this will be to build a hardened system step-by-step."
The security of Linux servers is something that, quite frankly, most of us would rather not deal with: an unexciting world of buffer overflows, hardened kernel patches and mandatory access control policies. Yet, that's the price to pay for the convenience of the World Wide Web of interconnected computers. And if the other LFS projects are anything to go by, Hardened Linux From Scratch will not only provide great educational value for absolutely free, it will do so in a hands-on and fun way for the benefit of all of us. Interested? Then join the mailing list and start learning.
JAMD and Xdefine Linux
Some of you might recall the good words we have put in for the JAMD Linux project, based on positive reviews and user feedback on the distribution's forums. Unfortunately, the project's future has become somewhat uncertain, due to the continued absence of the project's developer Jim Lucha from the forums, as well as a lack of any development roadmap. Upon some investigation, it turned out that Jim's name had resurfaced somewhere else, on a web site belonging to a new commercial Linux company called Xdefine. This is from the Xdefine's about pages:
"James Lucha, Chief Technical Officer, Xdefine, Inc. Graduated from University of California, Mr. Lucha who has extensive knowledge of Linux operating system joined Xdefine to take over the whole development of Xdefine Linux 2003. His feeling was that the customer has to always get 100% satisfaction and know they got a fair deal. Mr. Lucha met Mr. Sultani online, after talking for a while, he decided to join Xdefine as Chief Technical Officer."
The above note has since been removed from Xdefine's web site, but you can find a discussion about it on the JAMD Linux forums.
This brings up a question: do Free Software developers have some kind of responsibility towards the users of their products? Should they inform us about the project's status and any major changes to it? After all, many of them make no money from it and we are not paying customers, so why bother? On the other hand, there are human considerations - honesty and openness, especially in what we often perceive as our more honest and open world of Linux development, free of commercial considerations. Or is it all a lie? If a successful developer of Free Software is suddenly offered a regular paycheck to continue his or her work for a commercial company, can we really complain that we, the non-paying users, are suddenly abandoned?
If you are using one of the smaller distributions, how do you feel about it? Do you have a backup plan in case the developer gives up? Do you feel comfortable using one of the "one-man" distributions? Please discuss below.
Most visited pages in 2003
With the year 2003 behind us, let's take a quick look at the ranking of 20 most visited distribution-specific pages on this site and compare it to year 2002. The figures represent HPD or "Hits Per Day". Mandrake and Red Hat have retained their top two spots for the second year in a row, while some might be surprised by a rapid climb of Knoppix to the third position. You can view the 100 most visited pages of 2003 on the right column of the main index page.
|Released Last Week
LRs GNU/Linux Creme-13
A new version, Creme-13, of the recently revived LRs GNU/Linux distribution is out: "Merry Christmas and happy LRs with our brand new release Creme-13. Includes LFS-5.0, Linux-2.4.23, KDE-3.1.4 and much more. Some people don't need a full-blown LRs, so we will release three more ISO images in the next few days: LRs_with_X_and X-stuff (without KDE); LRs_Only_Console_tools; LRs_Pure_LFS." Visit the distribution's web site to learn more.
The long awaited CollegeLinux 2.5 has been released: "We are glad to announce the long awaited release of CollegeLinux 2.5 'Obi Wan'. Once again we did a release taking the necessary 6 months to bring something new, exclusive and never seen within the Linux community. Whilst there is a growing trend to release as often as possible, we have chosen to implement some important and innovative features and release only when there is something worth your time and bandwidth." Among the more interesting new features are a server robot which automatically installs and configures Apache, PHP, MySQL, SQLite, Webmin and PHPMyAdmin, and a slapt-get based auto-update engine integrated into Konqueror. See the full announcement for details. CollegeLinux is a Slackware-compatible Linux distribution designed for desktop and development workstations with many user-friendly enhancements.
Gibraltar Firewall 1.1
A new version of the Debian-based Gibraltar Firewall has been released. From the changelog: "Version 1.1, published 2003-12-23. This is the Christmas release, with only a few new features, but being a lot more resistant against buffer overflows and thus more secure due to the use of the PAX kernel patch. Updated the kernel to 2.4.23, which fixed the recently discovered brk() vulnerability. In addition to the update, the context patch (for virtual servers), the PAX patch and support for the zorp transparent proxy suite were added. Minor additions are an AES optimization and cryptoloop." Read the rest of the changelog for full details.
Openwall GNU/*/Linux 1.1
Openwall GNU/*/Linux 1.1 has been released: "After another year of development and many public Owl-current snapshots, Openwall GNU/*/Linux (Owl) release 1.1 is finally out. Owl 1.1 is currently available for purchase on a CD and will also be available for download after January 7, 2004. The major changes made since 1.0 are documented." Read the announcement on the distribution's web site and the complete changelog for further details. The product can be ordered from the distribution's online store for US$9.35. Openwall GNU/*/Linux is a security-enhanced operating system with Linux and GNU software as its core, intended as a server platform.
Ankur Bangla 1.0
FootNotes reports that Ankur Bangla 1.0 has been officially released: "The Ankur Bangla Project is proud to release version 1.0 final of the Ankur Bangla Live CD, running GNOME 2.4 localized into the Bangla (Bengali). The Live CD is based on Morphix and runs off the CD drive itself with little invasiveness to the existing setup. It is designed to be primarily a tool for collecting end user feedback on usability (especially of the translations of the GUI messages)." Read the rest of the announcement and release notes.
Aurox Live 1.2.0
This is a new release of Aurox Live CD, based on Aurox Linux 9.2. Changes: "This edition has NVIDIA binary drivers 44.96 and Macromedia Flash plugin installed. Aurox Live 1.2.0 contains: KDE 3.1.4 (default graphical desktop); web browsers Mozilla 1.5 and KDE's Konqueror; Office suites (KOffice 1.2.1, OpenOffice.org 1.1.0); multimedia support: sound and movie players Kaboodle, Xine (libs 1.0.0 RC2), non-accelerated games (KDE games); examples of games using hardware acceleration (Chromium, GLaxium); graphical e-mail clients (KMail, Evolution 1.4.5)..." Read the rest of the release notes.
Buffalo Linux 1.0.5
A new version of Buffalo Linux has been released: "This is a new bug-fix/update release in the 1.0.x series. Current version 1.0.5. Changes include: more cleanup of install procedure, includes patch for some hangs in AUTOSETUP. Improved integration with Codeweavers Crossover Office. Upgraded to latest version of Sylpheed (0.9.8a) mail client. Added more internal help files. Bug squashing and file cleanup." Buffalo Linux is a derivative distribution based on Vector and Slackware; it is targeted at the small business workstation market.
Damn Small Linux 0.5.2
Version 0.5.2 of Damn Small Linux has been released. From the changelog: "New for 0.5.2: mkisofs; cdrecord; bashburn (easy to use text mode CD burning utility); gTuxnes (interactive GUI for tuxness); smbclient; smbtree; a working /opt that is writable from the CD; midnight commander (many features stripped); skel now works for root when installed."
SLAX - Live CD 3.0.24
The honour of the first release of 2004 goes to SLAX - Live CD (formerly known as Slackware - Live CD), with the release of version 3.0.24 only a few hours into the new year. From the changelog: "v 3.0.24 (1th of January 2004): SLAX is the new name for Slackware-Live; now created by Linux Live scripts. Using KDE 3.2beta2 and KOffice 1.3beta2; removed quanta; configsave and configrestore doesn't work; added glut, libid3tag; added Linux kernel 2.4.23; removed printing and PDF/PS applications; sound volume is set to 88% automatically; rc.6 script modified, removed swap unmounting because of ovlfs..." Find out more on the distribution's new web site at slax.org.
Feather Linux 0.3.0 and 0.3.1
Feather Linux 0.3.1 has been released. From the distribution's changelog: "Fixed a known bug of LinNeighborhood; fixed HD install so that X starts automatically; removed mkcfm and mkfontdir, both extraneous with Kdrive; added script to save configuration to a USB pendrive and some bootup code to restore it." Feather Linux is a light-weight desktop Linux distribution based on Knoppix.
CRUX 1.3 (PowerPC edition)
A PowerPC edition of CRUX 1.3 is now available for download: "Port for PowerPC platform of CRUX 1.3. Uses kernel 2.4.23-ben1 with improved support for iBook G4 PowerMAC G5 and CPU Frequency Scaling. The distribution is source-based and uses the same ports tree from CRUX Linux Community available for CRUX x86." The project's web site has more information about the release (in Italian).
|Upcoming Releases and Announcements
Klaus Knopper has published information about the upcoming releases of the Knoppix live CD, with an updated version 3.3 expected this week and a brand new version 3.4 with kernel 2.6 before the end of March: "Preliminary release plan: update to Kernel 2.4.23 for the download edition of Knoppix 3.3, should be finished next week. ... Parallel working on version 3.4 with some major changes: switching to ISOLinux plus a 2 floppy boot option in order to allow inclusion of more drivers in the kernel and initrd (USB and Firewire, possibly), since the space on the 1.44 MB floppy is used up by the kernel 2.6 alone." Read the rest of the plan on the developers' mailing list.
|Web Site News
New on the waiting list
Removed from the waiting list
- Litrux. "What is Litrux? Litrux is a brand new Linux distribution, running completely from CD. No installation needed, just boot from CD. It automatically recognizes all supported types of network cards, graphic cards, sound cards, SCSI devices and other hardware devices."
- Lineox Enterprise Linux. "Lineox Enterprise Linux 3.0 contains all freely distributable packages from Red Hat Enterprise Linux 3.0 Advanced Server ($1499), Red Hat Cluster Suite ($499), and Red Hat Developer Suite (free as an introductory offer for RHEL subscribers). Lineox Enterprise Linux 3.0 does not contain any support. Lineox is however preparing a separately offered program package update option. Support option pricing and availability will be announced later."
- Rocks Cluster Distribution. Rocks is a specialist Linux distribution designed for clustering and cluster management.
- Routix. Routix is a Linux-based distribution for routers (web site in German).
- Vermillion. Vermillion is a custom Linux distribution based on Red Hat Linux.
- KANOTIX is a new Linux live CD based on Knoppix.
- Fermi Linux is a Linux distribution based on Red Hat Linux.
- LIVUX is a new Linux live CD based on Knoppix (web site in Spanish).
- The Dave/Dina Project. "The Dave/Dina Project was created to satisfy all the home entertainment needs of the average hacker. A Dave/Dina box is a computer connected to your TV screen, stereo, phone, and other stuff, running open-source software."
- Bluewall GNU/Linux. "Bluewall is a GNU/Linux distribution that allows you to install a system from a small set of preconfigured binary packages based on Debian Linux. Bluewall doesn't have any specific installation procedure, the idea behind it is that you can get installed Linux in the way you want, using command line tools."
DistroWatch database summary
- Zynot Linux. Zynot was a high-profile Gentoo fork when it started over 6 months ago, but now it seems to concentrate on development of embedded Linux solutions, rather than a general purpose distribution. As such, Zynot has been listed under Embedded Linux Distributions on the links page. Please let me know if my conclusion is incorrect.
- Momonga Linux. This is one of those never ending development projects, sprouted from the ashes of the discontinued Kondara MNU/Linux in July 2002. But despite its having been around for over 16 months and a promised final release by October 2002, we have yet to see any release.
- Number of distributions in the database: 230
- Number of discontinued distributions: 26
- Number of distributions on the waiting list: 66
On Turbolinux's TurboUpdate
"Turbolinux update utility seems to try to go to ftp.turbolinux.com. It has been down since I purchased the desktop 10D two weeks ago. Just thought I'd let someone know."
I have Turbolinux 10D installed and have had no problems using the TurboUpdate program to download and install all updates since the product release. Is there anybody else having the same problem as the reader above?
That's all for this week, see you next Monday :-)
If you've enjoyed this week's issue of DistroWatch Weekly, please consider sending us a tip.
(Tips this week: 0, value: US$0.00)
|Linux Foundation Training
|• Issue 739 (2017-11-20): Fedora 27, cross-distro software ports, Ubuntu on Samsung phones, Red Hat supports ARM, Parabola continues 32-bit support|
|• Issue 738 (2017-11-13): SparkyLinux 5.1, rumours about spyware, Slax considers init software, Arch drops 32-bit packages, overview of LineageOS|
|• Issue 737 (2017-11-06): BeeFree OS 18.1.2, quick tips to fix common problems, Slax returning, Solus plans MATE and software management improvements|
|• Issue 736 (2017-10-30): Ubuntu 17.10, "what if" security questions, Linux Mint to support Flatpak, NetBSD kernel memory protection|
|• Issue 735 (2017-10-23): ArchLabs Minimo, building software with Ravenports, WPA security patch, Parabola creates OpenRC spin|
|• Issue 734 (2017-10-16): Star 1.0.1, running the Linux-libre kernel, Ubuntu MATE experiments with snaps, Debian releases new install media, Purism reaches funding goal|
|• Issue 733 (2017-10-09): KaOS 2017.09, 32-bit prematurely obsoleted, Qubes security features, IPFire updates Apache|
|• Issue 732 (2017-10-02): ClonOS, reducing Snap package size, Ubuntu dropping 32-bit Desktop, partitioning disks for ZFS|
|• Issue 731 (2017-09-25): BackSlash Linux Olaf, W3C adding DRM to web standards, Wayland support arrives in Mir, Debian experimenting with AppArmor|
|• Issue 730 (2017-09-18): Mageia 6, running a completely free OS, HAMMER2 file system in DragonFly BSD's installer, Manjaro to ship pre-installed on laptops|
|• Issue 729 (2017-09-11): Parabola GNU/Linux-libre, running Plex Media Server on a Raspberry Pi, Tails feature roadmap, a cross-platform ports build system|
|• Issue 728 (2017-09-04): Nitrux 1.0.2, SUSE creates new community repository, remote desktop tools for GNOME on Wayland, using Void source packages|
|• Issue 727 (2017-08-28): Cucumber Linux 1.0, using Flatpak vs Snap, GNOME previews Settings panel, SUSE reaffirms commitment to Btrfs|
|• Issue 726 (2017-08-21): Redcore Linux 1706, Solus adds Snap support, KaOS getting hardened kernel, rolling releases and BSD|
|• Issue 725 (2017-08-14): openSUSE 42.3, Debian considers Flatpak for backports, changes coming to Ubuntu 17.10, the state of gaming on Linux|
|• Issue 724 (2017-08-07): SwagArch 2017.06, Myths about Unity, Mir and Ubuntu Touch, Manjaro OpenRC becomes its own distro, Debian debates future of live ISOs|
|• Issue 723 (2017-07-31): UBOS 11, transferring packages between systems, Ubuntu MATE's HUD, GNUstep releases first update in seven years|
|• Issue 722 (2017-07-24): Calculate Linux 17.6, logging sudo usage, Remix OS discontinued, interview with Chris Lamb, Debian 9.1 released|
|• Issue 721 (2017-07-17): Fedora 26, finding source based distributions, installing DragonFly BSD using Orca, Yunit packages ported to Ubuntu 16.04|
|• Issue 720 (2017-07-10): Peppermint OS 8, gathering system information with osquery, new features coming to openSUSE, Tails fixes networking bug|
|• Issue 719 (2017-07-03): Manjaro 17.0.2, tracking ISO files, Ubuntu MATE unveils new features, Qubes tests Admin API, Fedora's Atomic Host gets new life cycle|
|• Issue 718 (2017-06-26): Debian 9, support for older hardware, Debian updates live media, Ubuntu's new networking tool, openSUSE gains MP3 support|
|• Issue 717 (2017-06-19): SharkLinux, combining commands in the shell, Debian 9 flavours released, OpenBSD improving kernel security, UBports releases first OTA update|
|• Issue 716 (2017-06-12): Slackel 7.0, Ubuntu working with GNOME on HiDPI, openSUSE 42.3 using rolling development model, exploring kernel blobs|
|• Issue 715 (2017-06-05): Devuan 1.0.0, answering questions on systemd, Linux Mint plans 18.2 beta, Yunit/Unity 8 ported to Debian|
|• Issue 714 (2017-05-29): Void, enabling Wake-on-LAN, Solus packages KDE, Debian 9 release date, Ubuntu automated bug reports|
|• Issue 713 (2017-05-22): ROSA Fresh R9, Fedora's new networking features, FreeBSD's Quarterly Report, UBports opens app store, Parsix to shut down, SELinux overview|
|• Issue 712 (2017-05-15): NixOS 17.03, Alpha Litebook running elementary OS, Canonical considers going public, Solus improves Bluetooth support|
|• Issue 711 (2017-05-08): 4MLinux 21.0, checking file system fragmentation, new Mint and Haiku features, pfSense roadmap, OpenBSD offers first syspatch updates|
|• Issue 710 (2017-05-01): TrueOS 2017-02-22, Debian ported to RISC-V, Halium to unify mobile GNU/Linux, Anbox runs Android apps on GNU/Linux, using ZFS on the root file system|
|• Issue 709 (2017-04-24): Ubuntu 17.04, Korora testing new software manager, Ubuntu migrates to Wayland, running Nix package manager on alternative distributions|
|• Issue 708 (2017-04-17): Maui Linux 17.03, Snaps run on Fedora, Void adopts Flatpak, running Android apps on GNU/Linux, Debian elects Project Leader|
|• Issue 707 (2017-04-10): PCLinuxOS 2017.03, Canonical stops Unity development, OpenBSD on a Raspberry Pi, setting up a VPN for privacy|
|• Issue 706 (2017-04-03): Super Grub2 Disk, Snap packages of deepin applications, Subgraph OS routes network traffic for one application, announcements from Linux Mint|
|• Issue 705 (2017-03-27): Minimal Linux Live, sharing control of the operating system, new KaOS features, Uplos32 provides 32-bit fork of PCLinuxOS|
|• Issue 704 (2017-03-20): ToarusOS 1.0.4, Linux Mint's security record, Debian starts Project Leader election, Ubuntu 12.04 reaches end-of-life|
|• Issue 703 (2017-03-13): SolydXK 201701, CloudReady, Solus announces new features, KDE Connect sends text messages from desktop, openSUSE's YaST module for Let's Encrypt|
|• Issue 702 (2017-03-06): Fatdog64 Linux, elementary OS bundled with new netbook, Haiku announces new features, security and the size of a distro's development team|
|• Issue 701 (2017-02-27): OBRevenge 2017.02, Mageia 6 delays, NetBSD reproducible builds, questions about swap space, trying to steam video on a Raspberry Pi|
|• Issue 700 (2017-02-20): RaspBSD, Debian replaces Icedove with Thunderbird, Fedora's licensing guidlines, tips for switching shells, finding battery charge, getting IP address and killing processes|
|• Issue 699 (2017-02-13): Clear Linux, GhostBSD network utility ported to FreeBSD, Ubuntu coming to Fairphone, elementary OS crowd funding an app store|
|• Issue 698 (2017-02-06): Solus 2017.01.01, comparing containers with portable applicatins, Tails dropping 32-bit support, Debian Stretch enters freeze|
|• Issue 697 (2017-01-30): Subgraph OS 2016.12.30, running Ubuntu on an Android phone, Arch Linux phasing out 32-bit support, Linux Mint testing updated LMDE media|
|• Issue 696 (2017-01-23): GoboLinux 016, remotely running desktop applications, Solus adopting Flatpak, KDE neon using Calamares, TrueOS tests OpenRC|
|• Issue 695 (2017-01-16): Zorin OS 12, Peppermint team fixes installer bug, Debian refreshes Jessie media, Ubuntu improves low graphics mode, Exciting things coming in 2017|
|• Issue 694 (2017-01-09): MX Linux 16, Fedora considers systemd security features, DragonFly BSD to support massive swap space, Ubuntu Touch roadmap, Puppy's newsletter, sudo's password prompt|
|• Issue 693 (2017-01-02): Comparing small distros, fig language, video driver comparsion, Debian+PIXEL, Wayland on FreeBSD|
|• Issue 692 (2016-12-19): Bodhi Linux 4.0.0, Cappsule containers, Calculate's new Utilities package, Solus and Ubuntu MATE build new application menu|
|• Issue 691 (2016-12-12): SalentOS 1.0, openSUSE improves YaST, Fedora considers slower release cycle, KDE neon gets LTS branch|
|• Issue 690 (2016-12-05): Fedora 25, Ubuntu adopts rolling HWE kernel, running Android apps on GNU/Linux, Haiku working toward EFI support|
|• Issue 689 (2016-11-28): openSUSE 42.2, Fedora's upgrade path, plans for Korora 25, transitioning from PC-BSD to TrueOS, Webconverger's reproducible builds|
|• Issue 688 (2016-11-21): Endless OS 3.0.5, KDE neon fixes security hole, FreeBSD's Quarterly Status Report, Rolling release trial #2 concludes|
|• Full list of all issues|
|Random Distribution |
Zencafe GNU/Linux was a desktop Linux distribution designed specifically for public Internet cafés. Based on Slackware and Zenwalk Linux, it includes auto-recovery features, Internet café billing and management software, and other graphical system administration tools. Zencafe's default edition uses Xfce as the main desktop, while its "Lite" edition, designed for older or less powerful computers, installs the IceWM window manager.
DistroWatch.com is hosted at Copenhagen.
Contact, corrections and suggestions: Jesse Smith
Tips: BTC 1HVdyGfP8s37z19wmbcsnwSPSvFnssu5Mu • PayPal.me/distrowatchweekly