Bug#1064797: Mediawiki ships with .htaccess files containing outdated access control configuration

2024-02-25 Thread Alain Knaff
Package: mediawiki Version: 1:1.39.5-1~deb12u1 Hi, Mediawiki ships with .htaccess files which contain outdated access control directives. for instance, /usr/share/mediawiki/vendor/.htaccess contains: Deny from all rather than the more current Require all denied The new syntax was

Bug#1059323: mount.cifs fails to mount a share which smbclient can access all right

2023-12-22 Thread Alain Knaff
hom it breaks has an underscore in his name, and is 12 characters long (vs the other with just 6 characters and nothing special), could this be a factor? Thanks, -- Alain Knaff Service Informatique LE GOUVERNEMENT DU GRAND-DUCHÉ DE LUXEMBOURG Ministère de l'Environnement, du Climat et de

Bug#1058067: Mimedefang's relay_is_blacklisted_multi removes the wrong filedescriptor from its IO::Select set resulting in SERVFAIL

2023-12-11 Thread Alain Knaff
Package: mimedefang Version: 3.3-1 Hi, relay_is_blacklisted_multi sends out its multiple DNS requests at once, and then uses IO::Select to wait for the various answers as they come in. It has a loop in which it intends to remove each socket from the IO::Select set as soon as it is done with it

Bug#1055450: Plocate's database easily becomes corrupted, resulting in locate finding nothing

2023-11-06 Thread Alain Knaff
Den 06/11/2023 19:07 huet de(n) Steinar H. Gunderson geschriwwen: On Mon, Nov 06, 2023 at 06:43:33PM +0100, Alain Knaff wrote: Nov 06 18:33:15 hitchhiker updatedb.plocate[98659]: => adding `/home' (duplicate of mount point `/run/schroot/mount/buster-53c7e4fc-0416-4408-8421-959dc1fdaa1d/h

Bug#1055450: Plocate's database easily becomes corrupted, resulting in locate finding nothing

2023-11-06 Thread Alain Knaff
Den 06/11/2023 15:57 huet de(n) Steinar H. Gunderson geschriwwen: On Mon, Nov 06, 2023 at 03:41:50PM +0100, Alain Knaff wrote: On the box where plocate.db is currently corrupted, /home is a btrfs. It it by any chance a subvolume? (If so, known btrfs bug/design issue; see the updatedb.conf man

Bug#1055450: Plocate's database easily becomes corrupted, resulting in locate finding nothing

2023-11-06 Thread Alain Knaff
Den 06/11/2023 15:31 huet de(n) Steinar H. Gunderson geschriwwen: On Mon, Nov 06, 2023 at 03:09:48PM +0100, Alain Knaff wrote: On 2 separate Debian 12 machines, I'm observing the following issue: Search for a file that obviously exists returns nothing. Running updatedb and then locate doesn't

Bug#1055450: Plocate's database easily becomes corrupted, resulting in locate finding nothing

2023-11-06 Thread Alain Knaff
Package: plocate Version: 1.1.18-1 Hi, On 2 separate Debian 12 machines, I'm observing the following issue: Search for a file that obviously exists returns nothing. Running updatedb and then locate doesn't fix this. Removing /var/lib/plocate/plocate.db, and then re-running updatedb does fix

Bug#1040996: Davical defines a Content-Security-Policy without scoping it to its own resources

2023-07-13 Thread Alain Knaff
Package: davical Version: 1.1.12-2 Hi, At the end of its example / reference configuration file /etc/apache2/sites-available/davical.conf, davical defines a Content-Security-Policy, but forgets to bracket it with instructions to scope it to its own resources. Should be: Header set

Bug#1040525: Lighttpd disregards ssl.dh-file setting

2023-07-10 Thread Alain Knaff
Hi, On 08/07/2023 00:51, gs-bugs.debian@gluelogic.com wrote: > ⚠ Expéditeur externe au réseau de l'Etat. Voir les consignes de sécurité sur > ctie.etat.lu. > > > > On Fri, Jul 07, 2023 at 09:28:24AM +, Alain Knaff wrote: >> Package: lighttpd >> Ver

Bug#1040525: Lighttpd disregards ssl.dh-file setting

2023-07-07 Thread Alain Knaff
ssl.dh-file to a self generated dh param file, as described in https://weakdh.org/sysadmin.html In Debian 11, an identical configuration was using our locally generated secure dh parameters. Thanks, -- Alain Knaff Ingénieur Informaticien LE GOUVERNEMENT DU GRAND-DUCHÉ DE LUXEMBOURG Ministère

Bug#1040325: Network drives other than NFS are no longer automatically mounted after boot

2023-07-04 Thread Alain Knaff
service fixes the issue, however I have a feeling that on a future Debian upgrade, mountnfs.service might get masked again. Thanks for looking into this, -- Alain Knaff Ingénieur Informaticien LE GOUVERNEMENT DU GRAND-DUCHÉ DE LUXEMBOURG Ministère de l'Environnement, du Climat et du Développement

Bug#1039703: With dhcpcd version 9.4.1 interfaces cannot be brought down and up again, please ship at least 9.5.0

2023-07-03 Thread Alain Knaff
Hi, On 03/07/2023 13:13, Martin-Éric Racine wrote: > On Thu, 29 Jun 2023 14:50:16 +0000 Alain Knaff > wrote: [...] >> What fixes it, is disabling the dhcpcd service in systemd. This works >> even with 9.4.1: interfaces are brought up all right after boot even >> witho

Bug#1039703: With dhcpcd version 9.4.1 interfaces cannot be brought down and up again, please ship at least 9.5.0

2023-06-29 Thread Alain Knaff
Hi, On 28/06/2023 14:01, Alain Knaff wrote: > Package: dhcpcd > Version: 9.4.1-22 > > Hi, > > With the dhcpcd shipped with Debian 12, it is no longer possible to > bring an interface down and up again: > > ifdown eth0 ; sleep 1 ; ifup eth0 > [...] >

Bug#1039704: Sendmail does not notice when /etc/resolv.conf changes

2023-06-28 Thread Alain Knaff
after upgrade, and which would only do the reload, without preceding config recompilation? Thanks, Alain -- Alain Knaff Ingénieur Informaticien LE GOUVERNEMENT DU GRAND-DUCHÉ DE LUXEMBOURG Ministère de l'Environnement, du Climat et du Développement durable Administration de l'environnement 1,

Bug#1039703: With dhcpcd version 9.4.1 interfaces cannot be brought down and up again, please ship at least 9.5.0

2023-06-28 Thread Alain Knaff
[572]: ps_ctl_dispatch: cannot handle another client 2023-06-28T13:53:56.138312+02:00 build dhcpcd[572]: control_free: No such file or directory According to https://github.com/NetworkConfiguration/dhcpcd/issues/159, a bug with a similar error message is fixed in dhcpcd-9.5.0 Thanks, -- Alain

Bug#1039696: Confusing header message in /etc/resolvconf/resolv.conf.d/head

2023-06-28 Thread Alain Knaff
Hi, On 28/06/2023 13:09, Andrej Shadura wrote: > ⚠ Expéditeur externe au réseau de l'Etat. Voir les consignes de sécurité sur > ctie.etat.lu. > > > > Hi, > > On Wed, 28 Jun 2023, at 12:35, Alain Knaff wrote: >> The current resolvconf leaves a confusing header

Bug#1039696: Confusing header message in /etc/resolvconf/resolv.conf.d/head

2023-06-28 Thread Alain Knaff
different approach. Thanks, Alain -- Alain Knaff Ingénieur Informaticien LE GOUVERNEMENT DU GRAND-DUCHÉ DE LUXEMBOURG Ministère de l'Environnement, du Climat et du Développement durable Administration de l'environnement 1, avenue du Rock'n'Roll . L-4361 Esch-sur-Alzette Tél. (+352) 40 56 56-

Bug#1038441: Horde uses obsolete each() function throughout its code.

2023-06-18 Thread Alain Knaff
Package: php-horde-imp Version: 6.2.27-3 Hi, Horde still uses the obsolete each() function. https://www.php.net/manual/en/function.each.php Example from /usr/share/horde/imp/lib/Ajax/Application/ListMessages.php, line 438: while (list(,$ob) = each($overview['overview'])) {

Bug#1034500: Nheko crashes after a few seconds after launch, bug fixed upstream

2023-04-17 Thread Alain Knaff
Package: nheko Version: 0.8.0+really0.7.2-4 Hi, After a couple of seconds, and after displaying its UI correctly, nheko crashes with the following messages: terminate called after throwing an instance of 'std::invalid_argument' what(): v1.1: invalid version Aborted Apparently, this bug is

Bug#1033320: HTML5 "autofocus" tag for input element in dillo

2023-03-22 Thread Alain Knaff
fields as soon as the page with the form loads. We're using this to implement a barcode scanner on a raspberry pi 3, so that the browser is immediately ready to scan, without a need to touch into the input field first. Thanks, -- Alain Knaff Ingénieur Informaticien LE GOUVERNEMENT DU GRAND-DUCHÉ

Bug#1030688: Davmail's caldav port lists DELETE in http OPTIONS command, even when user is not yet authenticated

2023-02-06 Thread Alain Knaff
header has been sent by client. Thanks, -- Alain Knaff Ingénieur Informaticien LE GOUVERNEMENT DU GRAND-DUCHÉ DE LUXEMBOURG Ministère de l'Environnement, du Climat et du Développement durable Administration de l'environnement 1, avenue du Rock'n'Roll . L-4361 Esch-sur-Alzette Tél. (+352) 40 56 56-

Bug#1029421: Websocketd strips adds extraneous newlines in other direction from client to server, and strips out newlines in the other direction

2023-01-22 Thread Alain Knaff
Package: websocketd Version: 0.4.1-1+b5 In order to do some tests with web services, and eventually set up a tunnel for ssh, I used websocketd with a simple script. Here I noticed that the script's input and output are not faithfully received from/sent to the socket. Indeed, from client to

Bug#1028100: Anbox's README.Debian points to a defunct website for downloading images

2023-01-06 Thread Alain Knaff
Package: anbox Version: 0.0~git20210106-1 Hi, In order to use the anbox android emulator, you first need to download an android image, and put it into /var/lib/anbox/android.img. /usr/share/doc/anbox/README.Debian gives a source URL for these images: https://build.anbox.io/android-images but

Bug#1023491: ovmf-ia32 lacks non-secboot firmware images, but qemu does not (yet) support secboot

2022-11-05 Thread Alain Knaff
Package: ovmf-ia32 Version: 2020.11-2+deb11u1 Hi, Recently I wanted to analyze behavior of a 32-bit EFI OS bootfile, and wanted to setup a KVM with 32 bit UEFI to do this. However, qemu/kvm apparently does not (yet) support .secboot.fd UEFI images, but these are the only ones available in

Bug#1001684: Davmail should use log4j 2.16 rather than 1.2

2021-12-14 Thread Alain Knaff
ould be less and less reason to use potentially unsafe third-party logging libraries (but switching to java's internal logging might be more difficult to do in the short run than just upgrading to a newer version). > > Thanks, > > Alex > Regards, -- Alain Knaff Ingénieur Informatic

Bug#1001684: Davmail should use log4j 2.16 rather than 1.2

2021-12-14 Thread Alain Knaff
Package: davmail Version: 5.1.0.2891-2 Hi, According to https://github.com/jagornet/dhcp/issues/20 , log4j 1.2 is vulnerable to CVE-2019-17571, so davmail should use log4j 2.15 or 2.16 instead. Thanks, -- Alain Knaff Ingénieur Informaticien LE GOUVERNEMENT DU GRAND-DUCHÉ DE LUXEMBOURG

Bug#1000985: Mailman web interface shows Fedora icon on login page, which errors when clicked on

2021-12-01 Thread Alain Knaff
Package: mailman3-web Version: 0+20200530-2 Hi, Mailman3-web ships with a /usr/share/mailman3-web/settings_local.py.sample file that has django_mailman3.lib.auth.fedora included in INSTALLED_APPS This causes appearance of a fedora logo on the mailing lists' login page. However, clicking on that

Bug#1000908: procps ships with a file in /usr/lib/sysctl.d/ that does not start with a pair of digits

2021-11-30 Thread Alain Knaff
Package: procps Version: 2:3.3.17-5 Hi, Procps includes a sysctl configuration file in /usr/lib/sysctl.d/ that disallows root from overwriting group-writable files in setgid directories. As this interferes with our backup script, we initially tried to override it with a local file in

Bug#997060: [Pkg-mailman-hackers] Bug#997060: Bring back mailing list support to Debian

2021-10-26 Thread Alain Knaff
Hi, On 10/24/21 12:27 AM, Pierre-Elliott Bécue wrote: [...] > mailman removal is the decision of the mailman maintainer, Thijs, due to > the fact it relies on python2 which got removed from Debian. > > Regarding mailman3, I did the nginx integration, Jonas the Apache2 one, > from upstream

Bug#997060: Bring back mailing list support to Debian

2021-10-23 Thread Alain Knaff
Package: mailman3-web Version: 0+20200530-2 Hi, After I recently upgraded my server to Debian 11, I was rather appalled that mailman was dropped without a clear migration path. I figured out that this is now replaced by mailman3-full, but apparently that package is still pretty much work in

Bug#994696: Bind9's systemd .service says named available before it actually is, which makes services which depend on it fail

2021-09-19 Thread Alain Knaff
Package: bind9 Version: 1:9.16.15-1 Hi, Bind9's systemd service file /lib/systemd/system/named.service marks bind service as available before it actually is. This allows systemd to proceed with starting other services which depend on bind's availability (i.e. with After=nss-lookup.target). These

Bug#994158: bt-adapter (and other bluetooth tools) throws assertions failed rather than user-understandable errors if bluetoothd not running or no host adapter present

2021-09-12 Thread Alain Knaff
Package: bluez-tools Version: 2.0~20170911.0.7cb788c-4 Hi, bt-adapter -i fails assertions when attempting to start it without bluetoothd running, or no host adapter present. If bluetoothd is not running, it waits a long while (why? It's a TCP connection, which should fail immediately), and

Bug#982670: wetransfer is incompletely disabled in thunderbird

2021-02-13 Thread Alain Knaff
Package: thunderbird Version: 1:78.7.0-1~deb10u1 Hi, In its attempt to stay afloat, thunderbird bundles a number of unwanted extensions with its standard build. Debian has disabled these, which is a good thing. However, unfortunately the wetransfer extension has been disabled in an incomplete

Bug#974026: On upgrade, sddm clobbers /usr/share/sddm/scripts/Xsetup

2020-11-09 Thread Alain Knaff
Package: sddm Version: 0.18.0-1+deb10u1 Hi, sddm contains a file /usr/share/sddm/scripts/Xsetup intended to be customized... such as for setting up a displayLink hub. Indeed, as shipped the file is empty, except for the hashbang line and a single line comment ("Xsetup - run as root before the

Bug#972387: [Info-mtools] mtools does not work in Turkish locale

2020-10-24 Thread Alain Knaff
Hi, Thanks for the details, this is now fixed in 4.0.25 Regards, Alain On 22/10/2020 19:01, Pali Rohár wrote: Hello! On Thursday 22 October 2020 16:55:04 Chris Lamb wrote: $ LC_CTYPE=tr_TR.UTF-8 mtools Syntax error at line 5 for drive A: column 9 in file /etc/mtools.conf:

Bug#972326: thunderbird extensions no longer work

2020-10-17 Thread Alain Knaff
Hi, On 17/10/2020 08:35, Alain Knaff wrote: [...] However, when I checked this morning, most add-ons are back now, Please disregard this. I accidentally tried on a computer which has not yet been "up"graded, and is still on 68.12.0 On 78.3.1, all add-ons are still pretty m

Bug#972326: thunderbird extensions no longer work

2020-10-17 Thread Alain Knaff
Hi, On 17/10/2020 00:57, Brett Gilio wrote: Alain Knaff writes: Extensions no longer work since recent update. Examples: QuickFolders, Toggle Word Wrap, DOM Instepctor Plus!, Dorando keyconfig, ... Please only push new thunderbird versions once it is clear that they work. Could you

Bug#972326: thunderbird extensions no longer work

2020-10-16 Thread Alain Knaff
Package: thunderbird Version: 1:78.3.1-2~deb10u2 Extensions no longer work since recent update. Examples: QuickFolders, Toggle Word Wrap, DOM Instepctor Plus!, Dorando keyconfig, ... Please only push new thunderbird versions once it is clear that they work. Thanks, Alain

Bug#971985: $validFooterLinks flattened without checking it is non-empty

2020-10-11 Thread Alain Knaff
Package: mediawiki Version: 1:1.31.10-1~deb10u1 Hi, In /usr/share/mediawiki/includes/skins/BaseTemplate.php after line 601, the $validFooterLinks is "flattened" without checking that it is non-empty. This results in an unsightly warning in the web server log: [Sun Oct 11 09:19:03.631271

Bug#971986: $wgRedirectOnLogin ignored

2020-10-11 Thread Alain Knaff
Package: mediawiki Version: 1:1.31.10-1~deb10u1 Hi, The localSettings variable $wgRedirectOnLogin is ignored, apparently because the showReturnToPage function forgot to declare it global. This results in an unsightly warning in the web server log: [Sun Oct 11 09:29:12.186114 2020]

Bug#968888: vsftpd silently botches pasv_address setting if listen_ipv6 has been left to its default value

2020-08-23 Thread Alain Knaff
Package: vsftpd Version: 3.0.3-12 Hi, The pasv_address setting in vsftpd does not work if listen_ipv6 is set, with no clear error message anywhere in the log about what is going on. This setting is used for ftp servers behind a reverse NAT. If used while listen_ipv6=YES (as in default sample

Bug#964935: Zoneminder camera zma crashes since zoneminder_1.35.5~20200707.77

2020-07-12 Thread Alain Knaff
Package: zoneminder Version: 1.35.5~20200707.77-buster Severity: critical Since a recent upgrade, we found the following message in the log repeatedly: Jul 12 07:59:12 felix zma_m6[19229]: ERR [zma_m6] [Got empty memory map file size 0, is the zmc process for this monitor running?] ... and

Bug#964336: Mimedefang's relay_is_blacklisted_multi function gets confused if Net::DNS::Resolver falls back to TCP in order to retry queries with truncated UDP response packets

2020-07-05 Thread Alain Knaff
Package: mimedefang Version: 2.84-3 Severity: important Tags: patch Dear maintainer, The relay_is_blacklisted_multi function seems to be unaware that Net::DNS::Resolver->bgread (and bgbusy) may change their $handle parameter in the caller's scope via the $_[1] = $newvalue idiom under certain

Bug#959730: libgtk-3-0-dbgsym (3.22.11-1) out of phase with libgtk-3-0 (3.24.5-1)

2020-05-04 Thread Alain Knaff
On 04/05/2020 19:50, Simon McVittie wrote: On Mon, 04 May 2020 at 19:05:36 +0200, Alain Knaff wrote: While investigating a focus stealing bug in Firefox, which uses libgtk-3.0, I noticed that the debug symbol package is out of phase with the main package, preventing it from being installed

Bug#959730: libgtk-3-0-dbgsym (3.22.11-1) out of phase with libgtk-3-0 (3.24.5-1)

2020-05-04 Thread Alain Knaff
Package: libgtk-3-0-dbgsym Version: 3.22.11-1 Hi, While investigating a focus stealing bug in Firefox, which uses libgtk-3.0, I noticed that the debug symbol package is out of phase with the main package, preventing it from being installed: # apt install libgtk-3-0-dbgsym Reading package

Bug#955362: Emacs steals focus

2020-03-30 Thread Alain Knaff
Package: emacs Version: 1:26.1+1-3.2+deb10u1 Hi, Since Debian 10, I've noticed that on occasion Emacs steals focus. It doesn't happen always, but often enough to be annoying when working with 2 applications and an emacs sitting in between both. To reproduce, just quickly move the cursor

Bug#931830: Debian 10 includes known bad version of digikam => please make available .DEB of newer / more stable version

2019-07-10 Thread Alain Knaff
Package: digikam:amd64 Version: 4:5.9.0-1+b1 Hi, Buster includes a known bad version of digikam, which freezes on internal database access (409686) and makes it cumbersome to invoke its image editor (395875). Bug reported to upstream, they say it's an obsolete version which should no longer be

Bug#900625: Bug still present in stretch: [Bug#865987: libpcre3: Drop hard-coded Pre-Depends on deprecated multiarch-support]

2018-06-02 Thread Alain Knaff
Package: libpcre3:amd64 Version: 2:8.39-3 Hi, A broken version of libpcre3 is still included in stretch, unfortunately :-( Please fix this in stretch as well. Moreover, the following packages are affected as well: # dpkg -r multiarch-support dpkg: dependency problems prevent removal of

Bug#898536: Fail2ban is very slow to shut down

2018-05-13 Thread Alain Knaff
Package: fail2ban Version: 0.9.6-2 Hi, The version of fail2ban included in stretch (0.9.6-2) is very slow to shut down. root@lll:~# time service fail2ban stop real3m1.331s user0m0.004s sys 0m0.000s Thanks for fixing this, Alain

Bug#898469: Squid waits on shutdown even though there are no active clients

2018-05-11 Thread Alain Knaff
Package: squid Version: 3.5.23-5+deb9u1 Hi, The comment about on shutdown_lifetime in the sample squid.conf file says the following: # TAG: shutdown_lifetime time-units # When SIGTERM or SIGHUP is received, the cache is put into # "shutdown pending" mode until all active

Bug#898328: Missing sgid bit on /usr/lib/squid/basic_pam_auth

2018-05-10 Thread Alain Knaff
Package: squid Version: 3.5.23-5+deb9u1 In the Debian package, /usr/lib/squid/basic_pam_auth lacks its shadow group and associated s-gid bit, and thus cannot fulfill its sole purpose of authenticating users, as it cannot read the /etc/shadow file. Manually adding fixes this for a while, but such

Bug#893962: Acknowledgement (Modsecurity ignores phase 2 rules in Debian Stretch)

2018-03-24 Thread Alain Knaff
Found it: this was happening whenever the URL was redirecting. Apparently, when a redirect using "Redirect permanent" happens, mod-security's phase 2 is not called. The Ubuntu host that I used for comparison had other configuration differences which would cause the same URL to be served directly

Bug#893962: Modsecurity ignores phase 2 rules in Debian Stretch

2018-03-24 Thread Alain Knaff
Package: libapache2-mod-security2 Version: 2.9.1-2 Modsecurity in stretch seems to ignore rules in phase 2. I've defined the following test case: SecResponseBodyAccess on SecRuleEngine On # Does not work SecRule ARGS "/proc/(.*/)?self/(.*/)?environ" "phase:2,id:1420001,t:none,log,deny" #

Bug#890585: davmail doesn't cleanly close sessions (to Exchange) on exit, or when client leaves?

2018-02-16 Thread Alain Knaff
Package: davmail Version: 4.8.3.2554-1 Hi, When shutting down davmail, and restarting it, we often get Microsoft.Exchange.Data.Storage.TooManyObjectsOpenedExceptions when the client (Thunderbird) reconnects. This even happens when exiting Thunderbird before killing davmail. ==> Apparently

Bug#887840: Otrs blocks on receipt of a mail with too long headers

2018-01-20 Thread Alain Knaff
Package: otrs2 Version: 3.3.18-1+deb8u4 Hi, Recently a spammer sent a mail to our otrs address with way too many recipients in To: and Cc:. This had the effect of completely stalling otrs' mail processing. Rather than just skip over this faulty mail, and move on to the other mails, the

Bug#865036: Installing something into a KVM guest via pass-thru USB triggers USB resets on host, slows down guest

2017-06-19 Thread Alain Knaff
On 19/06/17 09:42, Alain Knaff wrote: > On 19/06/17 09:27, Michael Tokarev wrote: >> 18.06.2017 22:32, Alain Knaff wrote: > [...] >>> kvm -usb -device usb-host,hostbus=1,hostport=1 \ >>> -netdev user,id=net0 -device ne2k_pci,netdev=net0 \ >>> -m 2G -

Bug#865036: Installing something into a KVM guest via pass-thru USB triggers USB resets on host, slows down guest

2017-06-18 Thread Alain Knaff
Package: qemu-kvm Version: 1:2.8+dfsg-3~bpo8+1 Hi, When installing something from a Kingston USB stick (13fe:4100) via pass-through into a KVM guest, there's a never ending stream of USB resets on the host, which slows down USB access in the guest tremendously: Jun 18 21:20:14 hitchhiker

Bug#859270: OpenSSH should make it possible to explicitly chose public (long-lived) IPv6 address over temporary (anti-tracking) IPv6 address

2017-04-01 Thread Alain Knaff
Package: openssh-client Version: 1:6.7p1-5+deb8u3 Executive summary: Browsers need short-lived addresses which can't be tracked whereas ssh needs long-lived addresses which ensure that connections aren't cut after a couple of hours. Long explanation: By default, IPv6 creates client addresses

Bug#859062: Apache2 segfaults when using ProxySet in a ProxyMatch block

2017-03-29 Thread Alain Knaff
Package: apache2 Version: 2.4.10-10+deb8u8 Hi, The following config causes a segmentation fault: ProxySet connectiontimeout=86400 timeout=86400 ... ==> # systemctl status apache2.service -l ... Mar 29 07:35:02 mysite systemd[1]: Reloaded LSB: Apache2 web server. Mar 29 23:47:46 mysite

Bug#857550: Owncloud in Debian 8 is way outdated (7.0.4), and can no longer be easily upgraded to now-current version (9.1.4)

2017-03-12 Thread Alain Knaff
Package: owncloud Version: 7.0.4+dfsg-4~deb8u4 Hi, Following a security report at our owncloud installation, I attempted to upgrade, but I noticed that I could only upgrade to 7.0.4 (from 7.0.3), as that was the most recent version in the Debian repositories. Fortunately, I located a

Bug#856169: Chromium installs a setuid binary without obvious need nor warning

2017-02-25 Thread Alain Knaff
Package: chromium Version: 56.0.2924.76-1~deb8u1 Chromium's .deb install a suid root binary (/usr/lib/chromium/chrome-sandbox), potentially exposing the user's system to hostile javascripts downloaded from the untrusted web. This has already been exploited in the past:

Bug#843242: solved (Was: Acknowledgement (When dealing with PDF files in another application, icedove frequently crashes with message "*** buffer overflow detected ***"))

2017-01-22 Thread Alain Knaff
Hi, In the meantime, I found the real reason: a broken GTK2 "oxygen" Engine (as hinted already by the stack trace... d'oh). After switching to qtcurve, the issue disappeared. Sorry for suspecting the wrong package at first, Alain On 11/05/2016 13:33, Debian Bug Tracking System wrote: > Thank

Bug#852206: Oxygen2 GTK engines make mozilla software unstable

2017-01-22 Thread Alain Knaff
Package: gtk2-engines-oxygen Version: 1.4.6-1 Hi, The oxygen theme seems to make Mozilla software misbehave. - Text is shown garbled in lightning tasks: https://bugzilla.mozilla.org/show_bug.cgi?id=1325854 - Text is shown garbled in firefox in edition textareas of mediawiki:

Bug#852058: Coreutils corrupts its own error messages with "smart" quotes

2017-01-21 Thread Alain Knaff
Package: coreutils Version: 8.23-4 The version of coreutils included in Debian generates error messages containing "smart" quotes. According to coreutils developers, the issue is fixed in coreutils 8.25 in order to make it easier to cut and paste file names from diagnostics into shells. Please

Bug#841135: Debian/Ubuntu multiboot USB sticks (Was: Re: Bug#841135: Acknowledgement (iso-scan/filename ignored in Debian 8.6.0 => cannot put it on multiboot USB stick))

2016-12-04 Thread Alain Knaff
Hi, I had a little bit of time, so I continued to investigate the issue. >From what I understand now, iso-scan is not meant to use any iso filename supplied to it via grub command line, but it rather prefers to scan the USB stick for usable images itself, and then present the user with a

Bug#843822: KDE binaries (ksplashqml) *silently* fail if they cannot allocate memory, causing a hang at startup

2016-11-09 Thread Alain Knaff
Package: kde-workspace-bin Version: 4:4.11.13-2 When attempting to start kde with a too low ulimit -d applied, kde just hangs, without displaying its splash screen, nor popping up any error dialog, nor printing any error message to stderr (.xsession-errors) This makes diagnosing such

Bug#841669: MAP_NORESERVE vs. ulimit (was: Re: Bug#841669: Acknowledgement (KDE fails to start on kernel 4.7.0-0.bpo.1))

2016-11-08 Thread Alain Knaff
Hi, After using logging in in "failsafe" mode, and using strace on kde, I found out what was going on. The following call now fails with ENOMEM: mmap(NULL, 2147483648, PROT_READ|PROT_WRITE|PROT_EXEC, MAP_PRIVATE|MAP_ANONYMOUS|MAP_NORESERVE, -1, 0) Older kernels did not enforce ulimit -d with

Bug#843242: When dealing with PDF files in another application, icedove frequently crashes with message "*** buffer overflow detected ***"

2016-11-05 Thread Alain Knaff
Package: icedove Version: 1:45.4.0-1~deb8u1 Hi, When dealing with PDF files in another application, icedove frequently crashes. This happens with applications unrelated to icedove apart from sharing the same X-window screen (i.e. the apps have *not* been launched from icedove after clicking a

Bug#841669: Acknowledgement (KDE fails to start on kernel 4.7.0-0.bpo.1)

2016-10-21 Thread Alain Knaff
On 10/21/2016 23:51, Debian Bug Tracking System wrote: > Thank you for filing a new Bug report with Debian. > > This is an automatically generated reply to let you know your message > has been received. > > Your message is being forwarded to the package maintainers and other > interested

Bug#841669: KDE fails to start on kernel 4.7.0-0.bpo.1

2016-10-21 Thread Alain Knaff
Package: linux-image Version: 4.7.0-0.bpo.1 Hi, Just upgraded my kernel from 4.6.0-1 to 4.7.0-1, and after this, KDE failed to start. It just hung forever at start without even the progress banner displaying. After downgrading again to 4.6.0-1, everything was fine (but I have a suspicion that

Bug#841135: iso-scan/filename ignored in Debian 8.6.0 => cannot put it on multiboot USB stick

2016-10-17 Thread Alain Knaff
Package: iso-scan Version: 1.53 Hi, I'm trying to set up a multiboot USB stick (containing bootable Debian, Ubuntu, Redhat, etc. distributions on one media) For this, I am following the instructions at https://wiki.archlinux.org/index.php/Multiboot_USB_drive#Debian However, despite all

Bug#548434: [Fdutils] Cannot format floppies under kernel 2.6.*?

2009-12-15 Thread Alain Knaff
On 15/12/09 15:59, ael wrote: For what it is worth, here are the results from my debian testing box under 2.6.32_exact-55846-gf405425 $ lsmod |grep floppy floppy 45327 0 # setfdprm /dev/fd0 HD # fdformat /dev/fd0 Double-sided, 80 tracks, 18 sec/track. Total capacity

Bug#548434: [Fdutils] Cannot format floppies under kernel 2.6.*?

2009-12-15 Thread Alain Knaff
ael wrote: Mark Hounschell wrote: On 12/15/2009 10:08 AM, Alain Knaff wrote: I mentioned I had multiple machines with this problem. Some running different versions of SuSE. Mainly 11.0, which is where all the info I've provided came from thus far. This machine also has a SuSE-11.2 disk

Bug#548434: [Fdutils] Cannot format floppies under kernel 2.6.*? repeat=40

2009-12-15 Thread Alain Knaff
ael wrote: Alain Knaff wrote: Could you try the same with a higher repetition count: On same floppy (medium) as before: [...] All sector ids seem to be present (although occasionally they are skipped during read...), and track is correct everywhere... but if I remember correctly, you got

Bug#548434: [Fdutils] Cannot format floppies under kernel 2.6.*?

2009-12-15 Thread Alain Knaff
ael wrote: Is that what you wanted? ael Yes. All sectors are there, ... so I wonder why you are getting errors. So, next round of tests: trying to read these sectors: fdrawcmd recalibrate 0 fdrawcmd read 0 0 0 1 2 18 1 1 length=18432 /dev/null Alain -- To UNSUBSCRIBE, email to

Bug#548434: [Fdutils] Cannot format floppies under kernel 2.6.*?

2009-12-15 Thread Alain Knaff
A.E.Lawrence wrote: Alain Knaff wrote: ael wrote: Is that what you wanted? ael Yes. All sectors are there, ... so I wonder why you are getting errors. So, next round of tests: trying to read these sectors: fdrawcmd recalibrate 0 fdrawcmd read 0 0 0 1 2 18 1 1 length=18432 /dev/null

Bug#548434: [Fdutils] Cannot format floppies under kernel 2.6.*?

2009-12-15 Thread Alain Knaff
ael wrote: A.E.Lawrence wrote: # fdrawcmd read 0 0 0 1 2 18 1 1 length=18432 /dev/null remaining= 17920 0: 40 == So this is Abnormal termination? 1: 20 == CRC error? (id or data) 2: 20 == CRC error? (data) Did I decode them correctly? ael Yes, that's correct. Alain -- To

Bug#548434: [Fdutils] Cannot format floppies under kernel 2.6.*?

2009-12-14 Thread Alain Knaff
On 14/12/09 12:27, ael wrote: # getfdprm -o /dev/fd0u1440 2880 18 2 80 0 0x1b 0x00 0xcf 0x6c # fdrawcmd drive=/dev/fd0u1440 readid 0 repeat=18 raw cmd: Invalid argument ... and if you try with /dev/fd0 instead? Alain -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org

Bug#548434: [Fdutils] Cannot format floppies under kernel 2.6.*?

2009-12-14 Thread Alain Knaff
On 14/12/09 15:58, ael wrote: Any point in running under strace? Yes, this would be useful, especially for analyzing the Invalid argument issue. Regards, Alain -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#548434: [Fdutils] Cannot format floppies under kernel 2.6.*?

2009-12-14 Thread Alain Knaff
On 14/12/09 16:24, ael wrote: Alain Knaff wrote: On 14/12/09 15:58, ael wrote: Any point in running under strace? Yes, this would be useful, especially for analyzing the Invalid argument issue. Looks as if that was something to do with my command line. Below is the strace giving the IO

Bug#548434: floppy: fdformat fails completely with current kernel

2009-12-03 Thread Alain Knaff
On 14/10/09 05:27, Aníbal Monsalve Salazar wrote: Sending this bug report to alain @ linux.lu You can see the discussion about this bug at: http://bugs.debian.org/548434 I tested both fdformat and superformat (from fdutils 5.5-20060227-3, and then also from 20081027) with kernel

Bug#548434: ftutils so util-linux?

2009-12-03 Thread Alain Knaff
On 10/11/09 17:42, ael wrote: I tried setting the density to dd instead of hd -- something that I had also tried on fdformat without success. gfloppy managed to This is indeed very useful information, sorry to have not spotted this earlier. Double density disks cannot be formatted as high

Bug#548434: ftutils so util-linux?

2009-12-03 Thread Alain Knaff
On 03/12/09 16:28, ael wrote: I tested both fdformat and superformat (from fdutils 5.5-20060227-3, and then also from 20081027) with kernel 2.6.32-rc6 and on Kubuntu 9.04, and both worked fine. Could it be a bad drive or a bad disk? No. I have used several known good discs and on several