Bug#898470: openssl says "Can't load /root/.rnd into RNG"

2018-05-11 Thread Sander Jonkers
Package: openssl Version: 1.1.1~~pre6-2 Severity: important Dear Maintainer, Situation: debian experimental, clean install (docker container), openssl (version 1.1.1, via "install -t experimental) First command (goes well): # openssl genrsa -out example.com.key 2048 Second command (goed

Bug#897138: O: anacron -- cron-like program that doesn't go by time

2018-05-11 Thread Michael Biebl
On Fri, 4 May 2018 16:55:07 -0700 Sean Whitton wrote: > Hello Peter, > > On Sat, Apr 28, 2018 at 11:03:07PM +, Peter Eisentraut wrote: > > The package is no longer maintained upstream, > > Oh dear :( Would switching to cronie [0] (which also provides an anacron

Bug#898469: Squid waits on shutdown even though there are no active clients

2018-05-11 Thread Alain Knaff
Package: squid Version: 3.5.23-5+deb9u1 Hi, The comment about on shutdown_lifetime in the sample squid.conf file says the following: # TAG: shutdown_lifetime time-units # When SIGTERM or SIGHUP is received, the cache is put into # "shutdown pending" mode until all active

Bug#898468: debian-installer: black screen/long delay in graphical installer after switching from linux 4.15 to 4.16

2018-05-11 Thread Cyril Brulebois
Package: debian-installer Severity: serious Justification: graphical installer regression Hi, Ever since we switched from linux 4.15 to 4.16, the graphical installer gets a black screen. Comparing Xorg logs, everything is exactly the same except for the kernel version and timestamps. syslog has

Bug#898467: RM: kvkbd -- RoQA; unmaintained; better alternative exist

2018-05-11 Thread Jeremy Bicha
Package: ftp.debian.org X-Debbugs-Cc: kv...@packages.debian.org kvkbd was orphaned in 2011. It had an upload in 2016 to update the packaging. Its last upstream release was apparently a decade ago. It was removed from Ubuntu in 2014 because KDE Plasma includes maintained virtual keyboards.

Bug#897238: Re: Bits about Intel MKL packaging -- Higher Priority than OpenBLAS

2018-05-11 Thread Lumin
Hi Sébastien, > Using a Pre-Depends here is IMO wrong. Quoting Policy §7.2: Thanks. I didn't notice that when considering ways to avoid corner cases. > I also think that removing the Provides is not a good idea. The alternative is > provided by the package, and that should be made clear in the

Bug#896658: qtbase-opensource-src FTBFS on alpha: ambiguous call of atime()

2018-05-11 Thread Michael Cree
On Tue, May 01, 2018 at 10:21:11AM -0300, Lisandro Damián Nicanor Pérez Meyer wrote: > > qtbase-opensource-src FTBFS on Alpha [1] due to an ambiguous > > Thanks for the very clear explanation! There are two possible ways out here: > > 1) Preferred by us Qt maintainers: file a bug in

Bug#898310: [Pkg-pascal-devel] Bug#898310: lcl-units-1.8 unusable due to file permissions

2018-05-11 Thread Chris Dryburgh
Hi,  This does look like a duplicate problem to 896702. Has it been confirmed that adding the missing files solves 896702 ? Lazarus does not put all of the possible binaries in the deb file. If extra packages are needed then they can be compiled as needed using the source code. Have looked

Bug#898466: wdg-html-validator: “validate” command-line script fails due to calling obsolete Perl routine

2018-05-11 Thread Lawrence D'Oliveiro
Package: wdg-html-validator Version: 1.6.2-8 Severity: important Tags: patch Dear Maintainer, Attempting to use the “validate” command to validate an HTML file produces the error message: Unimplemented: POSIX::tmpnam(): use File::Temp instead at /usr/bin/validate line 662. I was able to

Bug#898017: ncurses abi change.

2018-05-11 Thread peter green
On 07/05/18 08:28, Paul Gevers wrote: I guess check all the reverse build-depends on fpc and/or lazarus for linking against libncurses? Does any of the reverse build-depends show up in the transition tracker? I extracted the build-rdeps for fpc, fp-compiler, lazarus, lazarus-ide and lcl-utils

Bug#845297: Migration to Salsa - reorganization of webmaster-team and repos

2018-05-11 Thread Paul Wise
On Sat, May 12, 2018 at 1:35 AM, Laura Arjona Reina wrote: > After some interchange of ideas in #debian-www, looks like it's simpler > not to have the webwml subgroup in Salsa. We can set members/permissions > per repo, so we can put all the different git repos at the same level, > as "direct

Bug#898465: symbol lookup error: /usr/lib/libmapnik.so.3.0: undefined symbol

2018-05-11 Thread 積丹尼 Dan Jacobson
Package: viking Version: 1.6.2-3+b1 Severity: grave $ viking viking: symbol lookup error: /usr/lib/libmapnik.so.3.0: undefined symbol: _ZNK5boost16re_detail_10620031icu_regex_traits_implementation12do_transformEPKiS3_PKN6icu_578CollatorE -- System Information: Debian Release: buster/sid APT

Bug#898464: Had to downgrade to install

2018-05-11 Thread 積丹尼 Dan Jacobson
Package: libmapnik3.0 Version: 3.0.20+ds-1 Had to downgrade to install... libmapnik3.0 : Depends: gdal-abi-2-2-3 which is a virtual package, provided by: - libgdal20 (2.2.4+dfsg-1+b1), but 2.3.0+dfsg-1~exp1 is installed Keep the following packages at their

Bug#832161: can't run

2018-05-11 Thread 積丹尼 Dan Jacobson
To run the program, after downloading, do $ java -jar GpsMaster_*.jar (But this did not seem to work. So maybe do something else) Exception in thread "main" java.lang.NoClassDefFoundError: javax/xml/bind/JAXBException

Bug#893268: libjbzip2-java now in Java team, libnanoxml2-java remains buggy (Was: Bug#893268: Intend to take over libjbzip2-java and libnanoxml2-java into Debian Med team)

2018-05-11 Thread Emmanuel Bourg
Le 10/05/2018 à 05:52, Thorsten Glaser a écrit : > You summoned? Thank you for the quick help! It works perfectly. @Andreas: I pushed the fixes, could you complete the upload please?

Bug#822989: HTTP 500 error after logging in to alioth SSO

2018-05-11 Thread James Lu
Dear SSO team / server admins, When I try to sign on to sso.debian.org with my Alioth (-guest) account, I am redirected to https://sso.debian.org/alioth/certs/ where I get a HTTP 500 error. The contents are as follows: Internal Server Error The server encountered an internal error or

Bug#898017: ncurses abi change.

2018-05-11 Thread peter green
On 07/05/18 08:28, Paul Gevers wrote: Hi Peter, On 07-05-18 03:54, peter green wrote: I have asked the release team not to binnmu fpc and I would suggest avoiding uploads of the fpc package until we have looked at this. Ok, it appears I was a little mistaken, I thought the freepascal IDE uses

Bug#898463: bsdmainutils: cal -h returns an error instead the unhighlited version of the calendar

2018-05-11 Thread Andres Culasso
Package: bsdmainutils Version: 9.0.12+nmu1 Severity: normal Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? trying to get a plain text version of the calendar * What exactly did you do (or not do) that

Bug#898310: [Pkg-pascal-devel] Bug#898310: lcl-units-1.8 unusable due to file permissions

2018-05-11 Thread Abou Al Montacir
Hi, > You can use the Lazarus IDE without recompiling. To use many of the  > packages that come with lcl-units-1.8 you must install them and  > recompile the IDE. The issue comes from the fact that many of the packages are no more built. I tried to reproduce the issue by installing fpdebug

Bug#898462: apt-listdifferences: [INTL:pt_BR] Brazilian Portuguese debconf templates translation

2018-05-11 Thread Adriano Rafael Gomes
Package: apt-listdifferences Tags: l10n patch Severity: wishlist Hello, Please, Could you update the Brazilian Portuguese Translation? Attached you will find the file pt_BR.po. It is UTF-8 encoded and it is tested with msgfmt and podebconf-display-po. Kind regards. pt_BR.po.gz Description:

Bug#898461: nodm: [INTL:pt_BR] Brazilian Portuguese debconf templates translation

2018-05-11 Thread Adriano Rafael Gomes
Package: nodm Tags: l10n patch Severity: wishlist Hello, Please, Could you update the Brazilian Portuguese Translation? Attached you will find the file pt_BR.po. It is UTF-8 encoded and it is tested with msgfmt and podebconf-display-po. Kind regards. pt_BR.po.gz Description:

Bug#898434: gajim: Recommends NBS gir1.2-networkmanager-1.0

2018-05-11 Thread W. Martin Borgert
Control: tag -1 pending It seems, that neither package is needed anymore! Thanks, Jeremy!

Bug#898418: dpkg-depcheck: support for openat

2018-05-11 Thread Mattia Rizzolo
Control: tag -1 pending On Fri, May 11, 2018 at 02:30:34PM +0200, Bill Allombert wrote: > glibc now use the new syscall 'openat' instead of 'open' most of the time. > > Please update dpkg-depcheck to strace openat too. > The attached patch should do that. Thanks for the patch, this was already

Bug#824449: firefox: FTBFS on sparc64 due to wrong platform definitions

2018-05-11 Thread Mike Hommey
On Fri, May 11, 2018 at 08:49:41PM +0200, John Paul Adrian Glaubitz wrote: > Hi! > > With Firefox 60.0 ESR now in experimental, most of the sparc64-related patches > are now part of the upstream source. > > The only patches we actually need are the one to fix skia on big-endian > targets > (I

Bug#898402: ntpsec: Please provide a way to disable the DHCP hook.

2018-05-11 Thread Richard Laager
On 05/11/2018 02:56 AM, Julien Goodwin wrote: > Please either add a method to disable the entire hook (I'd prefer this > to avoid additional service restarts), or at least add a variable to > /etc/default/ntp that will cause /run/ntp.conf.dhcp to not be used. For the ntp package, there's a

Bug#766595: Gnome-shell leaks memory

2018-05-11 Thread fmneto
I have news regarding this bug (or at least I believe this is the same bug). GNOME devs have found a "memory leak" in gnome-shell's garbage collection, when related to GJS. They have merged the fix into the development branch (GNOME 3.30) and are going to (probably) merge into the 3.28 version as

Bug#679147: Confirmed in current vinagre

2018-05-11 Thread Josh Triplett
On Fri, May 11, 2018 at 03:38:27PM -0400, Jeremy Bicha wrote: > On Fri, May 11, 2018 at 3:03 PM, Josh Triplett wrote: > > I can confirm that this still exists with vinagre 3.22.0-5. > > Could you please keep the subject line when you reply to bugs? It > takes some work for

Bug#824449: firefox: FTBFS on sparc64 due to wrong platform definitions

2018-05-11 Thread John Paul Adrian Glaubitz
On 05/11/2018 11:20 PM, Mike Hommey wrote: >> The only patches we actually need are the one to fix skia on big-endian >> targets >> (I am currently in the process of upstreaming this one) and one tiny patch >> to fix an alignment issue on sparc64. > > For the record, the latter was explicitly

Bug#755185: update from upstream

2018-05-11 Thread Mario Frasca
I'm still the current developer/maintainer of the upstream desktop software.  [1] There never came a web app out of it, there were three separate attempts, the last one 2 1/5 years ago.  [2] There is a new web data server, but it's a collection aggregator, not the main collection manager.  [3]

Bug#898351: streamlink: recommend none or more video player

2018-05-11 Thread Alexis Murzeau
Le 10/05/2018 à 19:02, Amy Kos a écrit : > Package: streamlink > Version: 0.12.1+dfsg-1 > Severity: wishlist > > Please don't use recommends or add more video player, > e.g. mplayer and mpv, to avoid vlc auto installation. > > https://github.com/streamlink/streamlink/blob/master/docs/players.rst

Bug#898458: debsecan reports packages as vulnerbale after upgarde to newer/higher release

2018-05-11 Thread Florian Weimer
* Tomasz Ciolek: > This has been bugging me for a while. debsecan shows the following > package as being vulnerable and having updates available to fix the > issue: > > *** Available security updates > > CVE-2017-15908 In systemd 223 through 235, a remote DNS server can... >

Bug#898458: debsecan reports packages as vulnerbale after upgarde to newer/higher release

2018-05-11 Thread TMC
Florian Thanks for the explanation. I guess I will have to do some manual due-diligence until this is resolved. Tomasz

Bug#898460: RM: tesseract-ocr-kur-ara -- ROM package renamed to tesseract-ocr-kmr

2018-05-11 Thread Александр Поздняков
Package: ftp.debian.org Severity: normal Please remove the tesseract-ocr-kur-ara package. Language file correction for tesseract (Open Source OCR Engine) from kur_ara.traineddata to kmr.traineddata (https://github.com/tesseract-ocr/langdata/issues/124) was made at git repository

Bug#898459: libjna-java: FTBFS with Java 10 due to javah removal

2018-05-11 Thread Emmanuel Bourg
Package: libjna-java Severity: serious Tags: sid buster User: debian-j...@lists.debian.org Usertags: default-java10 libjna-java fails to build with Java 10 due to the removal of javah: compile: [javac] Using javac -source 1.6 is no longer supported, switching to 1.7 [javac] Using

Bug#898458: debsecan reports packages as vulnerbale after upgarde to newer/higher release

2018-05-11 Thread TMC
Salvatore Thanks for the swift reply. Looks like I will just have to do manual due diligence on some of these pesky bugs until the functionality is merged into stable and stable-security. Is there a projected timeline when the fucntionality will be pushed in stable? Tomasz On 12 May 2018 at

Bug#898458: debsecan reports packages as vulnerbale after upgarde to newer/higher release

2018-05-11 Thread Salvatore Bonaccorso
Control: forcemerge 823664 898458 Hi Tomasz, On Sat, May 12, 2018 at 06:36:39AM +1000, Tomasz Ciolek wrote: > Package: debsecan > Version: 0.4.19~deb9u1 > Severity: normal > > Dear Maintainer, > > This has been bugging me for a while. debsecan shows the following package as > being vulnerable

Bug#898310: lcl-units-1.8 unusable due to file permissions

2018-05-11 Thread Chris Dryburgh
Hi Paul, You can use the Lazarus IDE without recompiling. To use many of the packages that come with lcl-units-1.8 you must install them and recompile the IDE. 1. Under the Lazarus menu select Package -> Install / Uninstall Packages ... 2. Select a package "Available for installation" and

Bug#898458: debsecan reports packages as vulnerbale after upgarde to newer/higher release

2018-05-11 Thread Tomasz Ciolek
Package: debsecan Version: 0.4.19~deb9u1 Severity: normal Dear Maintainer, This has been bugging me for a while. debsecan shows the following package as being vulnerable and having updates available to fix the issue: *** Available security updates CVE-2017-15908 In systemd 223 through 235, a

Bug#898320: kdeconnect: 1.3.0 does not work with 1.8.2 android version

2018-05-11 Thread Eric Valette
Le 11 mai 2018 20:37:06 GMT+02:00, Diederik de Haas a écrit : >On vrijdag 11 mei 2018 10:18:06 CEST Eric Valette wrote: >> It can be on the client side (android both and 1.8.2 android version >> both) but I have two differents. It could be network but no firewall >and >>

Bug#898457: Depends on non-existent package node-mkdir

2018-05-11 Thread Andreas Moog
Source: node-mocha Severity: serious Tags: patch Hi there, it appears that the latest commits and uploads have introduced a wrong dependency on node-mkdir, which doesn't exist. I pushed the attached diff to the salsa repository, but since I'm only a DM, I can't upload the package. I will

Bug#876780: libvorbis: CVE-2017-14160

2018-05-11 Thread Salvatore Bonaccorso
Control: retitle -1 libvorbis: CVE-2017-14160 (+ CVE-2018-10392 CVE-2018-10393) Control: tags -1 + fixed-upstream Hi This issue (cf. https://gitlab.xiph.org/xiph/vorbis/issues/2330) was adressed upstream by https://gitlab.xiph.org/xiph/vorbis/commit/018ca26dece618457dd13585cad52941193c4a25 .

Bug#898371: octave-ltfat: autopkgtest times out since 25 April 2018

2018-05-11 Thread Rafael Laboissière
* Paul Gevers [2018-05-10 23:32]: Source: octave-ltfat Version: 2.2.0+dfsg-8 Severity: normal User: debian...@lists.debian.org Usertags: regression timeout Since the run of 25 April 2018, the autopkgtests¹ are timing out (~ 3 hours) while previous runs tested in about 20

Bug#898402: ntpsec: Please provide a way to disable the DHCP hook.

2018-05-11 Thread Richard Laager
On 05/11/2018 02:56 AM, Julien Goodwin wrote: > I also think the test in the init script should probably change to > if -e /run/ntp.conf.dhcp, since /run is created on boot, otherwise > there's surprising behaviour if the admin edits ntp.conf, restarts the > service, then discovers a DHCP

Bug#898456: desktop-base: Please offer emblem-vendor alternative

2018-05-11 Thread Jeremy Bicha
Source: desktop-base Version: 9.0.5 Severity: wishlist X-Debbugs-CC: hert...@debian.org Please use the Debian alternatives system to offer a new 'emblem-vendor' alternative (provided by emblem-debian in desktop-base). I am not familiar with setting up alternatives, but based on a quick look at

Bug#898455: python-pyeclib: Move python3-six to python3-pyeclib's Depends

2018-05-11 Thread Corey Bryant
Package: python-pyeclib Version: 1.5.0-1 Severity: normal Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu cosmic ubuntu-patch Dear Maintainer, In Ubuntu, the attached patch was applied to achieve the following: * d/control: Move python3-six from python-pyeclib Depends

Bug#898377: lintian: overly generic header name: /usr/include/util.h

2018-05-11 Thread Andreas Beckmann
On 2018-05-11 13:49, Chris Lamb wrote: > Hi Andreas, > >> after the overly generic python module names, I now came across util.h >> in two packages: libduo-dev, quaternion. > > Were these found by piuparts, or..? Just out of interest... I have some scripts based on Ralf Treinen's work to

Bug#898453: vncterm: CVE-2018-7226: integer overflow in vcSetXCutTextProc in VNConsole.c

2018-05-11 Thread Salvatore Bonaccorso
Source: vncterm Version: 0.9.10-1 Severity: important Tags: security upstream Forwarded: https://github.com/LibVNC/vncterm/issues/6 Hi, The following vulnerability was published for vncterm. CVE-2018-7226[0]: | An issue was discovered in vcSetXCutTextProc() in VNConsole.c in | LinuxVNC and

Bug#898454: RFS: libbinio/1.4+dfsg1-6

2018-05-11 Thread Andreas Moog
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "libbinio" * Package name : libbinio Version : 1.4+dfsg1-6 Section : libs It builds those binary packages: libbinio-dev - Binary I/O stream class library (development

Bug#898452: ITP: node-html5shiv -- enable use of HTML5 sectioning elements in legacy browser

2018-05-11 Thread Bastien ROUCARIES
Package: wnpp Severity: wishlist Owner: Bastien Roucariès X-Debbugs-CC: debian-de...@lists.debian.org * Package name: node-html5shiv Version : 3.7.3 Upstream Author : 2014 Alexander Farkas (aFarkas). * URL :

Bug#898451: lrzip: CVE-2018-5747: use-after-free in ucompthread (src/stream.c)

2018-05-11 Thread Salvatore Bonaccorso
Source: lrzip Version: 0.631-1 Severity: important Tags: security upstream Forwarded: https://github.com/ckolivas/lrzip/issues/90 Hi, The following vulnerability was published for lrzip. CVE-2018-5747[0]: | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the | ucompthread

Bug#679147: Confirmed in current vinagre

2018-05-11 Thread Jeremy Bicha
On Fri, May 11, 2018 at 3:03 PM, Josh Triplett wrote: > I can confirm that this still exists with vinagre 3.22.0-5. Could you please keep the subject line when you reply to bugs? It takes some work for those subscribed to bugs for the package to look up what bug you're

Bug#898450: devscripts: debian/tests/control missing dependency on python3-pyftpdlib

2018-05-11 Thread Adam Conrad
Package: devscripts Version: 2.18.2 Severity: normal Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu cosmic ubuntu-patch In Ubuntu, the attached patch was applied to achieve the following: * debian/tests/control: Depend on python3-pyftpdlib for the ftp tests.

Bug#679147: Confirmed in current vinagre

2018-05-11 Thread Josh Triplett
I can confirm that this still exists with vinagre 3.22.0-5.

Bug#898449: v4.1.2 package does not correspond to upstream v4.1.2

2018-05-11 Thread Xavier Delaruelle
Package: environment-modules Version: 4.1.2-2 Looking at the modules v4.1.2 debian package and it seems modules source in there corresponds to v4.1.1 not v4.1.2.

Bug#825488: ci.debian.net: Please run tests for contrib packages too

2018-05-11 Thread Paul Gevers
Hi Petter, On 22-03-18 22:34, Paul Gevers wrote: > So, albeit not automatically in the ci.d.n framework yet, you as a DD > can at least trigger the tests (e.g. after uploading). The migration software is now triggering those tests in testing (whereas ci.d.n itself only triggers tests in

Bug#895364: iptables: using conntrack prevents dropping ip fragments

2018-05-11 Thread Jim Pirzyk
This issue has been solved by using the 4.16 kernel (from debian-9 backports) and adding the following file (with contents): cat /etc/modprobe.d/iptable_raw.conf options iptable_raw raw_before_defrag=1

Bug#898439: leptonlib: CVE-2018-7442

2018-05-11 Thread Salvatore Bonaccorso
Hi, On Fri, May 11, 2018 at 12:01:02PM -0700, Jeff Breidenbach wrote: > Believed fixed in Debian package 1.76.0-1 > > Status of various vulnerabilities, as per upstream: > > * CVE-2018-7442: potential injection attack because '/' is allowed > in gplot rootdir. >

Bug#898448: Makes vinagre segfault on authentication failure

2018-05-11 Thread Josh Triplett
Package: libfreerdp2-2 Version: 2.0.0~git20180411.1.7a7b1802+dfsg1-1 Severity: important After upgrading libfreerdp2-2, authentication failures (mistyped password) started causing segfaults: May 11 11:41:29 jtriplet-mobl2 vinagre.desktop[9277]: [11:41:29:080] [9277:9277]

Bug#898439: leptonlib: CVE-2018-7442

2018-05-11 Thread Jeff Breidenbach
Believed fixed in Debian package 1.76.0-1 Status of various vulnerabilities, as per upstream: * CVE-2018-7442: potential injection attack because '/' is allowed in gplot rootdir. Functions using this command have been disabled by default in the

Bug#891687: postgresql-common: user-specific cluster management

2018-05-11 Thread Daniel Kahn Gillmor
On Fri 2018-03-16 13:13:16 +, Daniel Kahn Gillmor wrote: > anyway, let me know if there are things i can do that would make you > feel more comfortable adopting this user-specific cluster management > idea. users can already do it, but it'd be nice to smooth out bumps in > the road for them a

Bug#898447: [kwin-x11] Windows with Client-Side Decorations look badly and not resizeable

2018-05-11 Thread Alexander Kernozhitsky
Package: kwin-x11 Version: 4:5.12.4-1+b1 Severity: normal I tried some apps with CSD (e. g. GNOME apps) on KDE. Their windows cannot be resized by dragging the borders and their decorations don't respect the KWin theme. I know that there is a KWin script that fixes such issues. It's installed

Bug#824449: firefox: FTBFS on sparc64 due to wrong platform definitions

2018-05-11 Thread John Paul Adrian Glaubitz
Hi! With Firefox 60.0 ESR now in experimental, most of the sparc64-related patches are now part of the upstream source. The only patches we actually need are the one to fix skia on big-endian targets (I am currently in the process of upstreaming this one) and one tiny patch to fix an alignment

Bug#898446: Please reconsider enabling the user namespaces by default

2018-05-11 Thread Laurent Bigonville
Source: linux Version: 4.16.5-1 Severity: normal Hi, Firefox (and probably other applications) are using user namespaces these days to enhance the security. Debian is disabling these since 2013, the original patch states it's a short term solution, but we are here 5 years later and they are

Bug#898445: mariadb-10.1: CVE-2018-2782 CVE-2018-2784 CVE-2018-2787 CVE-2018-2766 CVE-2018-2755 CVE-2018-2819 CVE-2018-2817 CVE-2018-2761 CVE-2018-2781 CVE-2018-2771 CVE-2018-2813 (fixed in 10.1.33)

2018-05-11 Thread Salvatore Bonaccorso
Source: mariadb-10.1 Version: 10.1.20-1 Severity: grave Tags: security upstream fixed-upstream >From https://mariadb.com/kb/en/library/mariadb-10133-release-notes/ and fixed in 10.1.33: Fixes for the following security vulnerabilities: CVE-2018-2782 CVE-2018-2784 CVE-2018-2787

Bug#898444: mariadb-10.1: CVE-2018-2562 CVE-2018-2622 CVE-2018-2640 CVE-2018-2665 CVE-2018-2668 CVE-2018-2612 (fixed in 10.1.31)

2018-05-11 Thread Salvatore Bonaccorso
Source: mariadb-10.1 Version: 10.1.20-1 Severity: grave Tags: security upstream fixed-upstream >From https://mariadb.com/kb/en/library/mariadb-10131-release-notes/ and fixed in 10.1.31: Fixes for the following security vulnerabilities: CVE-2018-2562 CVE-2018-2622 CVE-2018-2640

Bug#898320: kdeconnect: 1.3.0 does not work with 1.8.2 android version

2018-05-11 Thread Diederik de Haas
On vrijdag 11 mei 2018 10:18:06 CEST Eric Valette wrote: > It can be on the client side (android both and 1.8.2 android version > both) but I have two differents. It could be network but no firewall and > both machines do see each other using ssh, upnp, ... With me it also fails from time to time

Bug#853043: status update

2018-05-11 Thread Paolo Greppi
The repo for this package is now on salsa. The pkg-javascript-devel team will prepare shortly a new upload with the updated Vcs-* fields. Paolo

Bug#898310: lcl-units-1.8 unusable due to file permissions

2018-05-11 Thread Paul Gevers
Hi Chris Thanks for reporting issues. They are an enormous important way to contribute. On 10-05-18 02:14, Chris Dryburgh wrote: > To use these packages with the Lazarus IDE they must be installed and > the IDE must be recompiled. When doing this the following compile error > is displayed. Can

Bug#898015: iproute2: 'ip addr add' drops capabilities, breaking VirtualBox

2018-05-11 Thread Luca Boccassi
On 11 May 2018 19:05:34 BST, Jon DeVree wrote: >On Fri, May 11, 2018 at 10:37:32 -0400, Jon DeVree wrote: >> >> Virtualbox works with the iproute2_4.16.0-3~git1_amd64.deb with the >> additional 'setcap -r /bin/ip' fix described by Mantas. >> > >I played around with this a

Bug#898216: unattended-upgrades: flaky autopkgtest

2018-05-11 Thread Antonio Terceiro
On Fri, May 11, 2018 at 04:41:11PM +0200, Bálint Réczey wrote: > Control: tags -1 wontfix > > Hi Paul, > > 2018-05-08 21:48 GMT+02:00 Paul Gevers : > > Source: unattended-upgrades > > Version: 1.0 > > Severity: important > > User: debian...@lists.debian.org > > Usertags: flaky

Bug#898015: iproute2: 'ip addr add' drops capabilities, breaking VirtualBox

2018-05-11 Thread Jon DeVree
On Fri, May 11, 2018 at 10:37:32 -0400, Jon DeVree wrote: > > Virtualbox works with the iproute2_4.16.0-3~git1_amd64.deb with the > additional 'setcap -r /bin/ip' fix described by Mantas. > I played around with this a little more. Its actually the 'setcap -r /bin/ls' which fixes virtualbox.

Bug#854572: status update

2018-05-11 Thread Paolo Greppi
The repo for this package is now on salsa. The pkg-javascript-devel team will prepare shortly a new upload with the updated Vcs-* fields. Paolo

Bug#898437: RFS: retroshare-0.6.4 -- Secure/decentralized communication

2018-05-11 Thread Andrey Rahmatullin
Control: tags -1 + moreinfo On Fri, May 11, 2018 at 06:02:40PM +0200, Cyril Soler wrote: > Subject: RFS: retroshare/0.6.4 You should have mentioned this is an ITP. > To access further information about this package, please visit the following > URL: > >

Bug#881159: status update

2018-05-11 Thread Paolo Greppi
The repo for this package is now on salsa. The pkg-javascript-devel team will prepare shortly a new upload with the updated Vcs-* fields. Paolo

Bug#898175: dwarf-fortress: The shortcut of Dwarf Fortress does not work

2018-05-11 Thread Serge Le Tyrant
Package: dwarf-fortress Version: 0.44.10-1 Followup-For: Bug #898175 I imagine I'm not alone in using the i386 architecture (even though we are fewer and fewer). Thank you for your time and your work. Greetings Serge. -- System Information: Debian Release: buster/sid APT prefers unstable

Bug#898443: kpackage: flaky autopkgtest

2018-05-11 Thread Paul Gevers
Source: kpackage Version: 5.42.0-2 Severity: important User: debian...@lists.debian.org Usertags: flaky While inspecting regressions in autopkgtest results¹, I noticed that your package kpackage fails regularly (5.45.0-1 hasn't even passed once yet), without obvious changes. As far as I checked,

Bug#898412: Re : Bug#898412: childsplay: Can’t upgrade

2018-05-11 Thread nicolas . patrois
Le 11/05/2018 13:38:33, Markus Koschany a écrit : > Hello, > The alphabet-sounds are now included in childsplay itself and the > extra packages are no longer required. Does apt dist-upgrade not work for > you? > They should be automatically removed. They were not automagically removed, just

Bug#894510: debhelper: Because it is listing tmpfiles in systemd's only, conf overriding is not working

2018-05-11 Thread Niels Thykier
Seyeong Kim: > Hello > > I tested them but symptom is still there > > so I put “print “#TMPFILES#” on autoscripts/postinst-init-tmpfiles like below > > ### > if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ]; then > # In case this system is running systemd, we need to

Bug#897535: openafs: FTBFS: dh_auto_test: make -j1 test VERBOSE=1 returned exit code 2

2018-05-11 Thread Benjamin Kaduk
ping? I cannot reproduce locally either on bare metal or in schroot. -Ben On Fri, May 04, 2018 at 09:15:51AM -0500, Benjamin Kaduk wrote: > Hi Lucas, > > On Wed, May 02, 2018 at 10:52:53PM +0200, Lucas Nussbaum wrote: > > > > During a rebuild of all packages in sid, your package failed to

Bug#845297: Migration to Salsa - reorganization of webmaster-team and repos

2018-05-11 Thread Laura Arjona Reina
Hello all El 26/04/18 a las 14:39, Laura Arjona Reina escribió: > Hello > > I have migrated to Salsa the following repos: > > webwml/debbugstheming for bugs.debian.org > Now it lives in https://salsa.debian.org/webmaster-team/webwml/debbugs > > webwml/gitweb theming for gitweb >

Bug#883944: ejabberd: Upstream AppArmor profile

2018-05-11 Thread Vincas Dargis
On 5/8/18 10:31 PM, Philipp Huebner wrote: Hi, what's the status here? Regards, Sorry, I have this task still on hold, because I'm having too much TODO's in my AppArmor contribution list already, and I considered other tasks being higher priority. Although anyone could just create pull

Bug#765854: Can we patch this?

2018-05-11 Thread Benjamin Crawford
Still can't get my home directory to unmount reliably. The pam module is present in common-session-noninteractive and the .service hack doesn't seem to work. Checking journalctl, there are a few directory not found errors suggesting the unmount is firing at the wrong time? Also, it requires

Bug#889135: [request-tracker-maintainers] Bug#889135: Bug#889135: rt4-fcgi: Missing dep

2018-05-11 Thread Satoru KURASHIKI
hi, On Fri, Feb 2, 2018 at 10:37 PM, Dominic Hargreaves wrote: > On Fri, Feb 02, 2018 at 10:12:53AM +0100, A. LE GALL wrote: >> root@vm-rt:~# /usr/share/request-tracker4/libexec/rt-server.fcgi --socket >> /var/run/rt4-fcgi.sock >> [3501] [Fri Feb 2 08:57:31 2018] [critical]:

Bug#862766: Remove libsocialweb from Debian? Was: Re: Port from libnm-glib to libnm

2018-05-11 Thread Michael Biebl
Am 11.05.2018 um 17:37 schrieb Jeremy Bicha: > libsocialweb depends on libnm-glib4 which is no longer built from > source. libsocialweb has no reverse dependencies and has been > abandoned upstream for years. Can we remove it from Debian now? bisho was the only rdep of libsocialweb and it was

Bug#898442: r-cran-epi: autopkgtest regression

2018-05-11 Thread Graham Inggs
Source: r-cran-epi Version: 2.24-1 User: debian...@lists.debian.org Usertags: regression X-Debbugs-CC: r-pkg-t...@alioth-lists.debian.net Hi R Package Team Since the upload of 2.24-1, r-cran-epi has been failing its own autopkgtest [1] with the following error: > library(popEpi) Error in

Bug#898441: r-cran-afex: autopkgtest regression

2018-05-11 Thread Graham Inggs
Source: r-cran-afex Version: 0.20-2-1 User: debian...@lists.debian.org Usertags: regression X-Debbugs-CC: r-pkg-t...@alioth-lists.debian.net Hi R Package Team Since the upload of 0.20-2-1, r-cran-afex has been failing its own autopkgtest [1] with the following error: Attaching package: 'afex'

Bug#898431: lintian.debian.org should emit source-contains-prebuilt-wasm-binary (backport file?)

2018-05-11 Thread Niels Thykier
Chris Lamb: > retitle 898431 please update version of file(1) on lindsay.debian.org to > detect .wasm files > thanks > > Bastien, > >> source-contains-prebuilt-wasm-binary source tag is not emitted due to >> too old file. > > To clarify anyone else who had difficult parsing this, "file" here >

Bug#898440: r-cran-truncnorm: autopkgtest regression

2018-05-11 Thread Graham Inggs
Source: r-cran-truncnorm Version: 1.0-8-1 User: debian...@lists.debian.org Usertags: regression X-Debbugs-CC: r-pkg-t...@alioth-lists.debian.net Hi R Package Team Since the upload of 1.0-8-1, r-cran-truncnorm has been failing its own autopkgtest [1] with the following error: autopkgtest

Bug#898439: leptonlib: CVE-2018-7442

2018-05-11 Thread Salvatore Bonaccorso
Source: leptonlib Version: 1.75.3-1 Severity: important Tags: security upstream Hi, The following vulnerability was published for leptonlib, I think this one was never reported yet directly to the BTS (nor upstream?). CVE-2018-7442[0]: | An issue was discovered in Leptonica through 1.75.3. The

Bug#898438: r-cran-yaml: autopkgtest regression

2018-05-11 Thread Graham Inggs
Source: r-cran-yaml Version: 2.1.18-1 User: debian...@lists.debian.org Usertags: regression Hi R Package Team Since the upload of 2.1.18-1, r-cran-yaml has been failing its own autopkgtest [1] with the following error: autopkgtest [11:06:13]: test run-unit-test: [--- cp:

Bug#898398: Fails with "incompatible character encodings: ASCII-8BIT and UTF-8"

2018-05-11 Thread Francesco Poli
On Fri, 11 May 2018 07:54:51 +0200 Stéphane Glondu wrote: > Package: apt-listbugs > Version: 0.1.24 > Severity: important > > Dear Maintainer, > > Since a few days, the cron.daily job of apt-listbugs fails with the following > message: > > /etc/cron.daily/apt-listbugs: >

Bug#898437: RFS: retroshare-0.6.4 -- Secure/decentralized communication

2018-05-11 Thread Cyril Soler
Package: sponsorship-requests Severity: normal Tags: newcomer From: Cyril Soler To: sub...@bugs.debian.org Subject: RFS: retroshare/0.6.4 Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "retroshare"

Bug#898431: lintian.debian.org should emit source-contains-prebuilt-wasm-binary (backport file?)

2018-05-11 Thread Bastien ROUCARIES
On Fri, May 11, 2018 at 5:27 PM, Chris Lamb wrote: > retitle 898431 please update version of file(1) on lindsay.debian.org to > detect .wasm files > thanks > > Bastien, > >> source-contains-prebuilt-wasm-binary source tag is not emitted due to >> too old file. > > To clarify

Bug#897690: [Pkg-matrix-maintainers] Bug#897690: Inline Etherpad widget does not work

2018-05-11 Thread Hubert Chathi
On Fri, 4 May 2018 22:59:16 +1200, martin f krafft said: > The Etherpad widget that I can add to a room seems to load forever, > but never actually works. This might be this upstream issue: https://github.com/aperezdc/revolt/issues/76 -- Hubert Chathi

Bug#898436: O: trac-subtickets -- sub-ticket feature for Trac tickets

2018-05-11 Thread W. Martin Borgert
Package: wnpp Severity: normal I intend to orphan trac-subtickets, because I dont' use it anymore. The package description is: This Trac plugin adds a sub-ticket feature to the Trac ticket tracker. Every ticket can have other tickets as parents or children.

Bug#898434: gajim: Recommends NBS gir1.2-networkmanager-1.0

2018-05-11 Thread Jeremy Bicha
Source: gajim Version: 1.0.2-1 Severity: important User: pkg-utopia-maintain...@lists.alioth.debian.org Usertags: libnm gajim recommends gir1.2-networkmanager-1.0 but that package is no longer built from source. The replacement is gir1.2-nm-1.0 but that may require changes in gajim's source code

Bug#898435: O: trac-mastertickets -- adds inter-ticket dependencies to Trac

2018-05-11 Thread W. Martin Borgert
Package: wnpp Severity: normal I intend to orphan trac-mastertickets, because I dont' use it anymore. The package description is: This Trac plugin adds "blocks" and "blocked by" fields to each ticket, enabling you to express dependencies between tickets. It also provides a

Bug#898433: FTBFS: README.md -> README.rst

2018-05-11 Thread Daniel Baumann
tag 898433 + patch thanks From: Daniel Baumann Date: Fri, 11 May 2018 17:15:19 +0200 Subject: Updating docs to fix FTBFS (Closes: #898433). --- debian/docs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/debian/docs b/debian/docs index

Bug#862766: Remove libsocialweb from Debian? Was: Re: Port from libnm-glib to libnm

2018-05-11 Thread Jeremy Bicha
libsocialweb depends on libnm-glib4 which is no longer built from source. libsocialweb has no reverse dependencies and has been abandoned upstream for years. Can we remove it from Debian now? Thanks, Jeremy Bicha

Bug#898273: [lintian] Detect conflict between package.json version and debian control version

2018-05-11 Thread Chris Lamb
Dear Bastien, > >> - for every depends in package.json check debian control depends > > ^^^ > > Do you mean in the "devDependencies" key? > > no the Dependencies key, the devDependencies should be checked against > source package depends Getcha, I think. (to clarify, all

  1   2   3   >