Bug#1052561: bookworm-pu: package nfdump/1.7.3-1 (pre-discussion)

2024-04-07 Thread Bernhard Schmidt
On 08/10/23 10:19 PM, Bernhard Schmidt wrote: Hi, > > On Sun, Sep 24, 2023 at 09:36:00PM +0200, Bernhard Schmidt wrote: > > > [ Other info ] > > > I did not attach the debdiff because it would be too large and only > > > consist > > > of upstream chang

Bug#1055966: bookworm-pu: package openvpn-dco-dkms/0.0+git20230324-1+deb12u1 (or 0.0+git20231103-0+deb12u1?)

2024-04-07 Thread Bernhard Schmidt
@@ +openvpn-dco-dkms (0.0+git20231103-1~deb12u1) bookworm; urgency=medium + + * Upload 0.0+git20231103-1 to Debian Bookworm + * Add d/gbp.conf for debian/bookworm branch + + -- Bernhard Schmidt Sun, 07 Apr 2024 15:20:37 +0200 + +openvpn-dco-dkms (0.0+git20231103-1) unstable; urgency=medi

Bug#1065879: openvpn: protocol configs have contradictory and confusing meanings in the man page + broken link + links to walled gardens

2024-03-17 Thread Bernhard Schmidt
Hi, Many of the man page URLs link into an access-restricted walled garden. E.g. all openvpn.net links go to a Cloudflare site that is not open to all people. It’s an injustice for a Debian man page to refer users to exclusive resources that may exclude them. This is perhaps something that

Bug#1065879: openvpn: protocol configs have contradictory and confusing meanings in the man page + broken link + links to walled gardens

2024-03-17 Thread Bernhard Schmidt
Control: tags -1 upstream Hi, Users can perhaps experiment to work out which of the various possible behaviors result, but the man page should be written unambiguously. I completely agree, but this is not something the Debian OpenVPN maintainers can do. Please check the latest version at

Bug#1055966: bookworm-pu: package openvpn-dco-dkms/0.0+git20230324-1+deb12u1 (or 0.0+git20231103-0+deb12u1?)

2024-02-10 Thread Bernhard Schmidt
Hi, Considering the version in unstable is currently 0.0+git20231103-1 should the upload be versioned 0.0+git20231103-0+deb12u1 (like originally proposed) or 0.0+git20231103-1~deb12u1 As originally proposed please. You're not backporting 0.0+git20231103-1 directly as far as I know, because

Bug#1055966: bookworm-pu: package openvpn-dco-dkms/0.0+git20230324-1+deb12u1 (or 0.0+git20231103-0+deb12u1?)

2024-02-06 Thread Bernhard Schmidt
Hi Jonathan, On Tue, Nov 14, 2023 at 11:26:54PM +0100, Bernhard Schmidt wrote: [ Reason ] openvpn-dco-dkms packages an accelerator kernel module for OpenVPN (OpenVPN data channel offload). There is one annoying bug tracked as Bug#1055809 where on heavily loaded TCP servers a refcount issue

Bug#1056984: bind9: regression: the branch 9.19 misses some commits from the branch 9.18

2023-12-19 Thread Bernhard Schmidt
Control: forwarded -1 https://salsa.debian.org/dns-team/bind9/-/merge_requests/26 On 27/11/23 09:12 PM, Arnaud Rebillout wrote: Hi, > In https://bugs.debian.org/1025519 was reported a bug in bind9 apparmor > configuration. It was fixed on the branch `debian/9.18`, with commit >

Bug#1055966: bookworm-pu: package openvpn-dco-dkms/0.0+git20230324-1+deb12u1 (or 0.0+git20231103-0+deb12u1?)

2023-11-14 Thread Bernhard Schmidt
4-1+deb12u1) bookworm; urgency=medium + + * Import upstream patch to fix refcount imbalance (Closes: 1055809) +- fixes "waiting for tunxxx to become free" seen on heavy loaded TCP + servers + * Add d/gbp.conf for debian/bookworm branch + + -- Bernhard Schmidt Tue, 14 Nov 2023 2

Bug#1055809: Kernel module hangs with "waiting for tunxxx to become free"

2023-11-11 Thread Bernhard Schmidt
Source: openvpn-dco-dkms Version: 0.0+git20230324-1 Severity: important Tags: upstream The dco module sometimes hangs on stopping/crashing OpenVPN processes with unregister_netdevice: waiting for tun321 to become free. Usage count = 1 This has been tracked in

Bug#1052561: bookworm-pu: package nfdump/1.7.3-1 (pre-discussion)

2023-10-08 Thread Bernhard Schmidt
Am 07.10.23 um 13:14 schrieb Jonathan Wiltshire: Hi, On Sun, Sep 24, 2023 at 09:36:00PM +0200, Bernhard Schmidt wrote: [ Other info ] I did not attach the debdiff because it would be too large and only consist of upstream changes. No changes to debian/ (except dropping a backported fix

Bug#1053142: chromium cannot startup after libfreetype6 upgrade to 2.12.1+dfsg-5+deb12u1

2023-09-28 Thread Bernhard Schmidt
Control: affects -1 src:freetype Technically it probably should be the other way around, but I fear this will be missed otherwise. Marking freetype as affected to at least it shows up there.

Bug#1052561: bookworm-pu: package nfdump/1.7.3-1 (pre-discussion)

2023-09-24 Thread Bernhard Schmidt
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: nfd...@packages.debian.org Control: affects -1 + src:nfdump [ Reason ] I am proposing updating updating the nfdump package to a new _upstream_ release in bookworm.

Bug#904044: OpenVPN3

2023-09-19 Thread Bernhard Schmidt
Hi Marc, Because our company decided "there will be no impact" to use multifactor authentication, I was forced to package openvpn3. I don't know if you were planning anything in that direction, but my current work can be found here: https://salsa.debian.org/televic-team/openvpn3

Bug#1050180: bookworm-pu: package freeradius/3.2.1+dfsg-4+deb12u1

2023-09-11 Thread Bernhard Schmidt
Hi, Control: tag -1 confirmed On Mon, Aug 21, 2023 at 04:16:12PM +0200, Bernhard Schmidt wrote: [ Reason ] I would like to fix a regression in the bookworm release of FreeRADIUS where the TLS-Client-Cert-Common-Name attribute contains the wrong value, breaking some use-cases (Bug#1043282

Bug#1050180: bookworm-pu: package freeradius/3.2.1+dfsg-4+deb12u1

2023-08-21 Thread Bernhard Schmidt
upstream commits to fix TLS-Client-Cert-Common-Name +contains incorrect value (Closes: #1043282) + + -- Bernhard Schmidt Sat, 19 Aug 2023 00:26:34 +0200 + freeradius (3.2.1+dfsg-4) unstable; urgency=medium * Don't install symlink for cache_eap module no longer shipped diff -Nru freeradius

Bug#1043282: freeradius: TLS-Client-Cert-Common-Name contains incorrect value

2023-08-18 Thread Bernhard Schmidt
Control: forward -1 https://github.com/FreeRADIUS/freeradius-server/issues/4785 Control: fixed -1 3.2.3+dfsg-1 On 08/08/23 02:59 PM, Åke Holmlund wrote: > We have a setup with TLS authentication where we use the CN of the > client certificate ti check in LDAP if that CN has access to our VPN >

Bug#1042535: Acknowledgement (nfdump doesn't work with profiles using nfsen 1.3.9)

2023-08-18 Thread Bernhard Schmidt
Control: tags -1 confirmed upstream Control: forward -1 https://github.com/phaag/nfsen/issues/19 Control: found -1 1.7.1-1 On 31/07/23 08:16 AM, Marcelo Gondim wrote: Hi, > > The commit you mention is quite intrusive (a lot of source cleanup mixed > > with the bugfix) and does not apply to

Bug#1024129: ITP: tacacs+ -- TACACS+ authentication daemon

2023-08-17 Thread Bernhard Schmidt
On 28/06/23 11:01 PM, Daniel Gröber wrote: Hi, > I'm also interested in having tacacs+ available in Debian. I wanted to test > your packages but unfortunately mentors removes packages after a while and > so they are gone from there now. > > The git repo you linked to doesn't seem to contain

Bug#1040447: odbc-mariadb cannot set up odcb-mariadb

2023-08-08 Thread Bernhard Schmidt
Control: severity -1 important Control: tags -1 unreproducible Same as Tuukka I cannot reproduce this.

Bug#1041349: transition: linphone-stack

2023-07-31 Thread Bernhard Schmidt
Am 31.07.23 um 21:25 schrieb Sebastian Ramacher: Hi On 2023-07-30 11:09:08 +0200, Bernhard Schmidt wrote: We need a rebuild of src:libosmo-abis against the new version of libortp and trx will be removed, see Bug#1026042 Why is the rebuild of libosmo-abis required? https

Bug#1042535: Acknowledgement (nfdump doesn't work with profiles using nfsen 1.3.9)

2023-07-30 Thread Bernhard Schmidt
Hi Marcelo, I asked Peter which commit solved the problem and I'm waiting for a response from him. While waiting for his response, I looked at the 1.7.2 release commits at https://github.com/phaag/nfdump/compare/v1.7.2...master and saw this line: Update nfprofile: phaag committed on May 5

Bug#1041349: transition: linphone-stack

2023-07-30 Thread Bernhard Schmidt
Control: block -1 by 1026042 Am 27.07.23 um 00:33 schrieb Sebastian Ramacher: Control: tags -1 confirmed On 2023-07-17 21:38:47 +0200, Bernhard Schmidt wrote: Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition Hi, I would like

Bug#1042535: Acknowledgement (nfdump doesn't work with profiles using nfsen 1.3.9)

2023-07-30 Thread Bernhard Schmidt
Hi Marcelo, Just to complement, using the recent version of nfdump from github, the bug does not occur. Thanks for the report. Do you by any chance know which exact commit fixes this issue? Is the fix in 1.7.2 or post-1.7.2 (only in git master)? I can update unstable to 1.7.2 or even the

Bug#1026042: trx: License is incompatible with that of up-coming ortp 5.2.0

2023-07-29 Thread Bernhard Schmidt
Control: severity -1 serious On 08/02/23 08:55 AM, Kyle Robbertze wrote: Hi Kyle, > > With the recently released version 5.2 ortp has been relicensed to GNU > > AGPL-3+. Since your package is GPL-2 it is my understanding that it > > may not link in ortp 5.2 until it is relicensed to either

Bug#1041349: transition: linphone-stack

2023-07-17 Thread Bernhard Schmidt
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition Hi, I would like to upload a new release of the linphone-stack to unstable. It consists of a number of packages that have been staged in experimental bctoolbox belr bcmatroska2

Bug#1040830: ESNET-SECADV-2023-0001: iperf3 memory allocation hazard and crash

2023-07-11 Thread Bernhard Schmidt
Source: iperf3 Version: 3.13-2 Severity: serious Tags: security upstream X-Debbugs-Cc: Debian Security Team A security advisory for iperf3 has been issued. https://downloads.es.net/pub/iperf/esnet-secadv-2023-0001.txt.asc -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 ESnet Software Security

Bug#1038899: bookworm-pu: package nfdump/1.7.1-2+deb12u1

2023-06-22 Thread Bernhard Schmidt
started. +Thanks to Yury Shevchuk + * [c9d7e789] Fix segfault in getopt parsing for -R (Closes: #1038644) + * [eb140f97] d/gbp.conf: set debian branch + + -- Bernhard Schmidt Thu, 22 Jun 2023 22:18:53 +0200 + nfdump (1.7.1-2) unstable; urgency=medium * [64bef089] Add tzdata build

Bug#1038824: bookworm-pu: package openvpn/2.6.3-1+deb12u1

2023-06-21 Thread Bernhard Schmidt
for Linux +- dangling pointer passed to pkcs11-helper + * d/gbp.conf: set branch to bookworm + + -- Bernhard Schmidt Wed, 21 Jun 2023 21:41:33 +0200 + openvpn (2.6.3-1) unstable; urgency=medium * New upstream version 2.6.2 diff -Nru openvpn-2.6.3/debian/gbp.conf openvpn-2.6.3/debian

Bug#1038644: nfdump: segfault if started with -R option

2023-06-21 Thread Bernhard Schmidt
On 19/06/23 05:25 PM, Yury Shevchuk wrote: > # /usr/bin/nfcapd -D -P /var/run/nfcapd/default.pid -w /var/cache/nfdump -S1 > -b 120.0.1 -p 2055 -R 127.0.0.2 2055 > Segmentation fault > The patch (trivial) is attached. Thanks. For the record, this is included in the much larger

Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

2023-06-08 Thread Bernhard Schmidt
Hi Utkarsh, I've actually managed to prepare a final update that I'm ready to upload - this has quite some fixes plus 2 new CVE fixes. Would you please test the new resulting binaries and make sure they look sane enough? :) The binaries can be found at

Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

2023-06-07 Thread Bernhard Schmidt
Package: libruby2.5 Version: 2.5.5-3+deb10u5 Severity: grave Hi, I can't quite figure out why, but the latest security upload of ruby2.5 in Buster breaks the ability of the puppet agent to pull files from the master With 2.5.5-3+deb10u4: # puppet agent --onetime --server puppet-kom.srv.lrz.de

Bug#1034661: twinkle: Please update twinkle to latest release

2023-05-16 Thread Bernhard Schmidt
Control: tags -1 + patch Control: severity -1 serious Control: forwarded -1 https://github.com/LubosD/twinkle/commit/da274607aa835a2735dcf9b9a7ba550910f9d03e On 15/05/23 11:34 PM, Frédéric Brière wrote: > On Fri, Apr 21, 2023 at 04:46:20PM +1000, Jason Lewis wrote: > > Please can you update

Bug#1034336: unblock: openvpn/2.6.3-1 and openvpn-dco-dkms/0.0+git20230324-1 (pre-approval)

2023-05-02 Thread Bernhard Schmidt
Control: tags -1 - moreinfo > > in order to reduce the deviation from an upstream tag I'd like to skip > > 2.6.2 and go for 2.6.3. Updated debdiff attached. > > Please go ahead and remove the moreinfo tag once the packages are > available in unstable. Uploaded, accepted and built on all

Bug#1000793: bind9-dnsutils: dig command fails with "`fd > STDERR_FILENO' failed" when run from a XFCE4 desktop applet

2023-04-24 Thread Bernhard Schmidt
Control: reassign -1 xfce4-genmon-plugin Control: tags -1 = upstream fixed-upstream patch Control: affects -1 bind9-dnsutils Control: forwarded -1 https://gitlab.xfce.org/panel-plugins/xfce4-genmon-plugin/-/issues/19 Hi Cesar, On 24/04/23 12:04 AM, Cesar Enrique Garcia Dabo wrote: > This turned

Bug#1034317: unblock: linphone-desktop/4.4.10-3

2023-04-12 Thread Bernhard Schmidt
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: linphone-desk...@packages.debian.org Control: affects -1 + src:linphone-desktop Please unblock package linphone-desktop [ Reason ] It fixes the RC bug #1033868 where you had

Bug#1033006: unblock: openvpn/2.6.1-1 (preapproval)

2023-03-26 Thread Bernhard Schmidt
On 25/03/23 10:17 PM, Sebastian Ramacher wrote: > > - upload 2.6.1 from experimental to unstable, then stage 2.6.2 and the > > new DCO in experimental for the second review round > > > > I would prefer the last option. > > Let's go ahead with the last option. Please let us know once openvpn >

Bug#1033006: unblock: openvpn/2.6.1-1 (preapproval)

2023-03-24 Thread Bernhard Schmidt
On 15/03/23 04:57 PM, Bernhard Schmidt wrote: Hi, > The upcoming DCO change will involve a new version of src:openvpn and a new > version > of src:openvpn-dco-dkms. The list of changes on the kernel side is already > visible > on https://github.com/OpenVPN/ovpn-dco

Bug#1033317: unblock: linphone/5.1.65-4

2023-03-22 Thread Bernhard Schmidt
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: linph...@packages.debian.org Control: affects -1 + src:linphone Please unblock package linphone [ Reason ] Two important bugs have been resolved * Disable behind-the-scenes

Bug#1033050: amdgpu output on USB-C docking station fails (after screen suspend?)

2023-03-16 Thread Bernhard Schmidt
Package: src:linux Version: 6.1.15-1 Severity: important Hi, I run a Lenovo T14s Gen2 with a Lenovo Dockingstation and two DP-connected external displays, with KDE on Wayland. Every few days, after an extended coffee break/lunch, I find my previously locked session unusable. The displays stay

Bug#1033006: unblock: openvpn/2.6.1-1 (preapproval)

2023-03-15 Thread Bernhard Schmidt
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please give permission to upload OpenVPN 2.6.1-1 to unstable and let it migrate to testing (currently in experimental as 2.6.1-1~exp1 [ Reason ] Upstream has released the first minor

Bug#1032590: Intermediate certficate support

2023-03-13 Thread Bernhard Schmidt
Am 13.03.23 um 16:29 schrieb Sakirnth Nagarasa: Hi, On 3/13/23 15:02, Bernhard Schmidt wrote: Humm .. but there IS a change fixing intermediate CA support in 3.2.2... Yes the intermediate CA support works now on version 3.2.2. I tested that in my setup. So, if I understand you correctly

Bug#1032590: Intermediate certficate support

2023-03-13 Thread Bernhard Schmidt
Am 13.03.23 um 14:48 schrieb Sakirnth Nagarasa: Hi, On 3/11/23 22:01, Bernhard Schmidt wrote: Just to make sure, could you quickly verify which of these versions are broken as well in your setup? - 3.2.1-1 from testing - 3.2.1-2 from http://snapshot.debian.org/package/freeradius/3.2.1%2Bdfsg

Bug#1032590: Intermediate certficate support

2023-03-11 Thread Bernhard Schmidt
Am 11.03.23 um 14:51 schrieb Sakirnth Nagarasa: Hi, On 3/10/23 08:55, Bernhard Schmidt wrote: I will upload a 3.2.1-3 within the next hours to cherry-pick this, could you please test the resulting binary and report back? I will then apply for a freeze exception. Thank you for uploading

Bug#1032572: new upstream (3.2.2)

2023-03-10 Thread Bernhard Schmidt
On 09/03/23 11:09 AM, Daniel Baumann wrote: Hi Daniel, > the latest upstream release (3.2.2) fixes some important bugs for us, > e.g. the fact that using an intermediate CA for which EAP-TLS, upstream > writes: > > "It's also worth mentioning that FreeRADIUS 3.2.1 has an issue with >

Bug#1032590: Intermediate certficate support

2023-03-09 Thread Bernhard Schmidt
Control: forwarded -1 https://github.com/FreeRADIUS/freeradius-server/issues/4753 Control: priority -1 important Control: found -1 3.0.25+dfsg-1 On 09/03/23 05:29 PM, Sakirnth Nagarasa wrote: Hi, > It would be great if you could upgrade freeradius version 3.2.2 to > Debian. With that

Bug#919234: ttls fails with tls 1.3, enabled by default

2023-03-07 Thread Bernhard Schmidt
Control: tags -1 + pending Hi Fabio, Am 07.03.23 um 17:00 schrieb Fabio PEDRETTI: Hi, 3.2.1 currently in testing fixed most issues, however there is still an issue preventing freeradius working with TLS 1.3. The issue was reported upstream at:

Bug#1029205: openvpn: Backporting openvpn 2.6.0~rc1 to bullseye-backports breaks network-manager-openvpn connections to older servers

2023-01-19 Thread Bernhard Schmidt
Am 19.01.23 um 16:47 schrieb René Krell: Hi Rene, IMHO, in each case it is not a idea to backport openvpn 2.6 unless network-manager-openvpn supports to override also --data-ciphers. Packages are not upgraded to backports-versions by default. You have to opt-in (either manually or by

Bug#1011538: RM: bind9-libs -- ROM; end-of-life, not needed anymore for isc-dhcp

2023-01-09 Thread Bernhard Schmidt
Control: affects -1 src:bind9-libs Hi, > src:isc-dhcp has switched to bundled libraries in #942502, so this package can > finally be removed. > > The only unsolved thing is #942501 in orphaned milter-greylist, so I bumped > the > severity to serious. I can do the NMU, but the package is

Bug#1011437: Should bind9-libs be shipped in bookworm?

2023-01-09 Thread Bernhard Schmidt
Hi, not about src:bind9, building the bind9-libs binary package (yes, this is totally confusing, even to Debian tooling) I though that had been already removed: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1011538 But I

Bug#1011437: Should bind9-libs be shipped in bookworm?

2023-01-09 Thread Bernhard Schmidt
Am 09.01.23 um 14:30 schrieb Ondřej Surý: Hi Ondrej, Looking at #942501 and #942502, the intention seems to be to not ship bind9-libs in bookworm. I agree, Ccing Ondrej who has done the heavy lifting on this package. AFAICT there is no binary reverse dependency in unstable, and #942501

Bug#1011437: Should bind9-libs be shipped in bookworm?

2023-01-08 Thread Bernhard Schmidt
On 22/05/22 11:47 PM, Adrian Bunk wrote: > Looking at #942501 and #942502, the intention seems to be to not > ship bind9-libs in bookworm. I agree, Ccing Ondrej who has done the heavy lifting on this package. AFAICT there is no binary reverse dependency in unstable, and #942501 "just" needs a

Bug#1028149: bookworm: ntp has been replaced by ntpsec

2023-01-07 Thread Bernhard Schmidt
Package: release-notes Severity: minor src:ntp (the ntp suite from ntp.org, including ntpd, ntpdate and sntp) has been dropped from bookworm and superseded by src:ntpsec, the much improved fork from ntpsec.org . Transitional packages are in place and for 99% of the users this should have no

Bug#1027918: Copy from remote RDP to local KDE Wayland session does not work

2023-01-04 Thread Bernhard Schmidt
Package: remmina-plugin-rdp Version: 1.4.27+dfsg-2+b1 Severity: important Tags: patch upstream On an Wayland KDE session copy from a remote RDP session to the local clipboard does not work. Upstream has an extensive bugreport and already provided a patch for it, see

Bug#1027379: nfdump: FTBFS in bullseye (missing build-depends on tzdata)

2023-01-02 Thread Bernhard Schmidt
Control: tags -1 + pending Control: tags -1 - moreinfo Hi, I have no problem fixing this up in unstable, but I think this does not warrant a stable update. That would be unfortunate, as it means we will probably never have a stable release without FTBFS bugs. "Never" is too hard, I will

Bug#1027379: nfdump: FTBFS in bullseye (missing build-depends on tzdata)

2023-01-02 Thread Bernhard Schmidt
Hi, That's an odd one. I cannot reproduce it in any version, because in all my attempts (1.6.22-2 in a bullseye sbuild, in an sid sbuild, as well as in the build logs of the official buildds for all of 1.6.22-2, 1.6.25-1 and 1.7.1-1) tzdata is actually installed in the build environment,

Bug#1027379: nfdump: FTBFS in bullseye (missing build-depends on tzdata)

2023-01-02 Thread Bernhard Schmidt
Control: tags -1 + moreinfo Hi Santiago, During a rebuild of all packages in bullseye, your package failed to build: [...] Note: I'm using the "patch" tag because there is an obvious fix > (indicated in the subject). That's an odd one. I cannot reproduce it in any version, because in

Bug#1011473: 2.5 clients cannot connect to a 2.6 server

2022-12-28 Thread Bernhard Schmidt
On 25/05/22 04:20 PM, Wolfgang Walter wrote: Hi Wolfgang, > opt-verify > > on the server side allows 2.5.6 clients to connect again. So it seems that > 2.5 and 2.6 disagree on tun-mtu (as the warning is not logged if both sides > are either 2.5.6 or 2.6). Could you try again with the just

Bug#1027094: FTBFS against bind9 9.18.10

2022-12-27 Thread Bernhard Schmidt
Control: forwarded -1 https://pagure.io/bind-dyndb-ldap/issue/216 On 27/12/22 06:16 PM, Bernhard Schmidt wrote: Hi, so this is really massively broken :-( > ../../src/log.h:21:9: error: too few arguments to function ‘isc_error_fatal’ >21 | isc_error_fatal(__FILE__, __

Bug#1027094: FTBFS against bind9 9.18.10

2022-12-27 Thread Bernhard Schmidt
On 27/12/22 09:43 PM, Santiago Vila wrote: > > bind-dyndb-ldap has a tight dependency on the upstream version of bind9-libs > > (built by src:bind9) and needs to be rebuilt on every new upstream version > > until https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1014503 is fixed. > > Hello. I

Bug#1027094: FTBFS against bind9 9.18.10

2022-12-27 Thread Bernhard Schmidt
Source: bind-dyndb-ldap Version: 11.10-1 Severity: serious Tags: ftbfs Justification: fails to build from source (but built successfully in the past) X-Debbugs-Cc: team+...@tracker.debian.org bind-dyndb-ldap has a tight dependency on the upstream version of bind9-libs (built by src:bind9) and

Bug#994235: bind9-dnsutils: Exiting the nslookup tool with ^C causes termainl echo to disappear until reset command is run

2022-12-23 Thread Bernhard Schmidt
Control: tags -1 + confirmed upstream On 14/09/21 06:19 PM, Gavin Rogers wrote: > > After upgrading from Debian 10 to 11, the nslookup command misbehaves > if it is exited with ^C rather than using the exit command, causing > local echo to appear to be switched off. Running /usr/bin/reset >

Bug#861923: openvpn: arbitrary process limit

2022-12-23 Thread Bernhard Schmidt
On 10/10/17 04:02 PM, Bernhard Schmidt wrote: > I think what we actually want is > >TasksMax=N >Specify the maximum number of tasks that may be created in the >unit. This ensures that the number of tasks accounted for the >unit (see

Bug#1026903: nmu: bind-dyndb-ldap_11.10-1

2022-12-23 Thread Bernhard Schmidt
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: binnmu Hi, while Bug#1014503 is not fixed we need another binNMU of bind-dyndb-ldap against the new version of bind9 in unstable. This should be the last time before the release. nmu

Bug#1024846: Does not start because it cannot create the control socket

2022-11-26 Thread Bernhard Schmidt
Package: openbgpd Version: 7.7-1 Severity: normal Hi Marco, I'm filing this as severity normal because I stumbled across it on a local bullseye backport, and I haven't tested it on sid yet. But I think it should be affected as well. After upgrading from 7.2 to 7.7 openbgpd does not start

Bug#1024845: transition: linphone-stack

2022-11-26 Thread Bernhard Schmidt
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition Dear release team, once again, hopefully for the last time before the release, I'm asking for permission for a small mostly self-contained transition of the whole linphone stack. It has

Bug#994696: Bind9's systemd .service says named available before it actually is, which makes services which depend on it fail

2022-11-08 Thread Bernhard Schmidt
Control: reopen -1 = Control: fixed -1 1:9.19.6-2 Reopening because we don't have that fix in unstable yet (needs to be backported)

Bug#1023594: nmu: bind-dyndb-ldap_11.10-1

2022-11-07 Thread Bernhard Schmidt
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: binnmu Hi, while Bug#1014503 is not fixed we need another binNMU of bind-dyndb-ldap against the new version of bind9 in unstable. nmu bind-dyndb-ldap_11.10-1 . ANY . unstable . -m "Rebuild for

Bug#1021125: Bug#1021576: linphone-desktop: Core dumped: Program terminated with signal SIGABRT, Aborted.

2022-11-03 Thread Bernhard Schmidt
Hi, I think this Bug can be downgraded and/or closed. We've rebuilt both dependencies in Debian (liblime and linphone). Since soci is not using shlibs the generated dependency is on the 4.0.3 anyway. I don't see a way to fix this without breaking lime/linphone again. Bernhard

Bug#994696: Bind9's systemd .service says named available before it actually is, which makes services which depend on it fail

2022-10-29 Thread Bernhard Schmidt
Am 29.10.22 um 10:44 schrieb Bernhard Schmidt: Hi Ondrej, I think it would be best if someone has finished the upstream systemd support. I am currently busy with other more important stuff, but if there was a working MR I would be happy to do the review and also do the backport to 9.18

Bug#994696: Bind9's systemd .service says named available before it actually is, which makes services which depend on it fail

2022-10-29 Thread Bernhard Schmidt
Hi Ondrej, I think it would be best if someone has finished the upstream systemd support. I am currently busy with other more important stuff, but if there was a working MR I would be happy to do the review and also do the backport to 9.18. The change is isolated, so it won't create any fuzz.

Bug#1019233: conserver FTBFS on IPV6-only buildds

2022-10-24 Thread Bernhard Schmidt
After some thoughts on it I've decided to make the test-suite non-fatal in the pending 8.2.7-2 upload. The root cause of the test-suite error appears to be that conserver is using AI_ADDRCONFIG, and fails to resolve localhost to 127.0.0.1 on machines that do not have non-local IPv4 connectivity.

Bug#1021125: Bug#1021576: linphone-desktop: Core dumped: Program terminated with signal SIGABRT, Aborted.

2022-10-12 Thread Bernhard Schmidt
Am 11.10.22 um 18:19 schrieb Dennis Filder: The change in 5.0.37-6 was tiny and I doubt it broke something. But maybe you're running into #1021125: liblinphone10:amd64 5.0.37-6 is already linked against soci/4.0.3-1, but liblime0 5.0.37+dfsg-4 is still linked against soci/4.0.1-5 and there was

Bug#1019284: transition: linphone-stack

2022-09-13 Thread Bernhard Schmidt
Hi, only ortp has reverse dependencies outside of the linphone stack that will need >> a binNMU. They have been successfully built against the version in experimental. bcg729 trx libosmo-abis libosmo-netif osmo-bts Please go ahead All uploaded and built on all release architectures. As

Bug#994696: Bind9's systemd .service says named available before it actually is, which makes services which depend on it fail

2022-09-09 Thread Bernhard Schmidt
On 09/09/22 10:33 AM, Bernhard Schmidt wrote: > I'm sceptical about this myself. OTOH, I just saw that Ubuntu has done > this change a year ago > > https://bugs.launchpad.net/ubuntu/+source/bind9/+bug/1899902 > https://salsa.debian.org/dns-team/bind9/-/merge_requests/17 Reading

Bug#994696: Bind9's systemd .service says named available before it actually is, which makes services which depend on it fail

2022-09-09 Thread Bernhard Schmidt
On 09/09/22 09:52 AM, Ondřej Surý wrote: Hi, > I think it would be best if someone has finished the upstream systemd > support. I am currently busy with other more important stuff, but if there > was a working MR I would be happy to do the review and also do the > backport to 9.18. The change is

Bug#994696: Bind9's systemd .service says named available before it actually is, which makes services which depend on it fail

2022-09-09 Thread Bernhard Schmidt
On 19/09/21 05:22 PM, Alain Knaff wrote: > Bind9's systemd service file /lib/systemd/system/named.service marks > bind service as available before it actually is. > This allows systemd to proceed with starting other services which depend > on bind's availability (i.e. with

Bug#1019284: transition: linphone-stack

2022-09-06 Thread Bernhard Schmidt
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition Dear release team, I'm asking for permission for a small mostly self-contained transition of the whole linphone stack. It has been staged in experimental. Most of these libraries don't

Bug#1017148: soci: FTBFS: catch.hpp:6490:33: error: size of array ‘altStackMem’ is not an integral constant-expression

2022-09-05 Thread Bernhard Schmidt
Control: tags -1 + patch upstream fixed-upstream Control: forwarded -1 https://github.com/SOCI/soci/pull/886 On 14/08/22 09:18 AM, Lucas Nussbaum wrote: > During a rebuild of all packages in sid, your package failed to build > on amd64. > > > /<>/tests/catch.hpp:6490:33: error: size of array >

Bug#1018016: bind9-libs not found for sid

2022-09-05 Thread Bernhard Schmidt
Hi, I’ve recently moved, so everything is in but of disarray including my builder machine. The git repository should be up to date, so if this cannot wait a day or two until I connect rest of my network, anybody should be able to build and upload new upstream version using git-buildpackage.

Bug#1019220: nmu: bind-dyndb-ldap_11.10-1

2022-09-05 Thread Bernhard Schmidt
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: binnmu Hi, while Bug#1014503 is not fixed we need another binNMU of bind-dyndb-ldap against the new version of bind9 in unstable (accepted a few minutes ago) nmu bind-dyndb-ldap_11.10-1 . ANY .

Bug#1017379: nm-openvpn: capng_change_id() failed applying capabilities: Operation not permitted (errno=1)

2022-08-15 Thread Bernhard Schmidt
Control: severity -1 serious Control: forwarded -1 https://sourceforge.net/p/openvpn/mailman/message/37693662/ Control: tags -1 confirmed upstream On 15/08/22 09:36 AM, Benjamin Eikel wrote: > Aug 15 09:24:46 myhostname nm-openvpn[11804]: capng_change_id() failed > applying capabilities:

Bug#989218: openvpn: the lack of down update-resolv-conf script

2022-08-12 Thread Bernhard Schmidt
On 29/05/21 04:14 AM, sergio wrote: > resolv.conf left configured after tunnel down due to lack of down script No, the Debian supplied script is supposed to be used for both --- $ head /etc/openvpn/update-resolv-conf #!/bin/bash # # Parses DHCP options from openvpn to update resolv.conf # To

Bug#976070: openvpn fails with iproute option

2022-08-12 Thread Bernhard Schmidt
On 29/11/20 11:05 AM, Glennie Vignarajah wrote: > In order to use openvpn with non root priviliges, iproute is need as > state in openvpn's howto document [1]. By default, iproute is disabled > on compile time and needs to enabled with ``--enable-iproute2``. Upstream has now added the option for

Bug#908559: openvpn: Openvpn cannot run /sbin/ip if started from systemd

2022-08-12 Thread Bernhard Schmidt
Version: 2.5.0-1 > The openvpn systemd unit cannot start because it cannot call the /sbin/ip > script. If I run the same script by hand it starts, so the problem should be > in the system unit file. I have been using the same config file for a while > (~8-10 years) and changed nothing, it

Bug#1004054: /usr/bin/nslookup: Re: bind9-host: host crashes in netmgr.c

2022-07-22 Thread Bernhard Schmidt
Control: fixed -1 1:9.18.2-1 Hi, > this is already reported in the upstream issue tracker, but since there’s no > reliable reproducer, we (as in the BIND 9 upstream team) were not able > to prepare the fix. as far as I understand, this has been fixed upstream in 9.18.2

Bug#1000447: netmgr/netmgr.c:1737: (...) failed

2022-07-22 Thread Bernhard Schmidt
Control: fixed -1 1:9.18.2-1 Hi, as far as I understand, this has been fixed upstream in 9.18.2 https://gitlab.isc.org/isc-projects/bind9/-/issues/3020 https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/5998 5831. [bug] When resending a UDP request in the result of a

Bug#987927: bind9: unreasonable resource use and slow startup with lots of IP addresses

2022-07-22 Thread Bernhard Schmidt
On 11/05/21 02:30 PM, Ondřej Surý wrote: > Control: forwarded -1 > https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/5012 > > Hi, > > coincidentally, I’ve been working (well, experimenting would be better word) > with > reducing the contention in the memory allocator and the first

Bug#1012567: openvpn --mktun --dev-type tap --dev tap2 fails

2022-07-06 Thread Bernhard Schmidt
Control: forward -1 https://sourceforge.net/p/openvpn/mailman/message/37665283/ Control: tags -1 upstream Hi Wolfgang, > Since 2.6.0~git20220518+dco-2 the following command fails: > > openvpn --mktun --dev-type tap --dev tap2 > > with > > Assertion failed at dco_linux.c:442 (tt-type ==

Bug#1014376: openvpn: Using unreleased version with backwards incompatible changes is not a good idea

2022-07-06 Thread Bernhard Schmidt
Am 05.07.22 um 09:23 schrieb Raphaël Hertzog: as Kali is based on Debian testing, our users started to experience the git snapshot of OpenVPN that you uploaded. Unfortunately, we got multiple reports that their VPN break because many VPN services ship .opvn files that rely on --cipher. At the

Bug#1014133: asterisk: Asterisk fails to build from source

2022-07-01 Thread Bernhard Schmidt
Control: severity -1 important Control: found -1 1:16.16.1~dfsg-1 Control: fixed -1 1:16.16.1~dfsg+~2.10-1 Hi Ralf, I am not very familiar with asterisk as packaged for Bullseye - only know that it was pretty unusually done. Maybe try build in a pristine build-environment. What do you mean

Bug#1012059: bind9: autopkgtest regression on amd64 and armhf: connection refused

2022-06-26 Thread Bernhard Schmidt
Control: tags -1 pending Hi, With a recent upload of bind9 the autopkgtest of bind9 fails in testing on amd64 and armhf when that autopkgtest is run with the binary packages of bind9 from unstable. It passes when run with only packages from testing. In tabular form: I have had a brief look

Bug#1012059: bind9: autopkgtest regression on amd64 and armhf: connection refused

2022-06-26 Thread Bernhard Schmidt
Control: tags -1 pending Hi, With a recent upload of bind9 the autopkgtest of bind9 fails in testing on amd64 and armhf when that autopkgtest is run with the binary packages of bind9 from unstable. It passes when run with only packages from testing. In tabular form: I have had a brief look

Bug#1012129: openvpn: 2.6 client fails authentication against older server

2022-05-30 Thread Bernhard Schmidt
Control: tags -1 + moreinfo Hi Guillem, Just upgraded openvpn the other day and could not connect anymore to the VPN. Reverting back to 2.5.6-1 makes it work again. I checked #1011473 and nothing there seemed relevant. Here's an (edited) excerpt from the log (from today's retry):

Bug#1012059: bind9: autopkgtest regression on amd64 and armhf: connection refused

2022-05-30 Thread Bernhard Schmidt
Hi Ondrej, With a recent upload of bind9 the autopkgtest of bind9 fails in testing on amd64 and armhf when that autopkgtest is run with the binary packages of bind9 from unstable. It passes when run with only packages from testing. In tabular form: I have had a brief look and it seems we

Bug#1012075: openvpn: OpenVPN - Debian/SID release '2.6.0~git20220518+dco-1' breaks connection buildup

2022-05-30 Thread Bernhard Schmidt
Control: tags -1 moreinfo Hi Henrik, The latest version of OpenVPN in Debian/SID repo '2.6.0~git20220518+dco-1' won't connect due to TLS errors during connection attempts. Only downgrade to version '2.5.6-1' solves the issue. Have you followed up on the multiple warnings and notes from the

Bug#961021: ITP: python-easysnmp -- A blazingly fast and Pythonic SNMP library based on the official Net-SNMP bindings

2022-05-27 Thread Bernhard Schmidt
Control: tags -1 pending Hi, Note that the upstream project is looking for a new maintainer and appears to be quite dormant. There are issues with Python 3.7+, but a pull request is available and has been verified to work. I don't intend to upload to Debian until these issues have been

Bug#1011473: 2.5 clients cannot connect to a 2.6 server

2022-05-25 Thread Bernhard Schmidt
Am 25.05.22 um 13:39 schrieb Wolfgang Walter: Hi, Could you please check the release notes at https://github.com/OpenVPN/openvpn/blob/dco/Changes.rst  for relevant changes and post logs/redacted config to this bug? I read them and I found nothing problematic. There is no problem with a

Bug#1011473: 2.5 clients cannot connect to a 2.6 server

2022-05-25 Thread Bernhard Schmidt
Control: tags -1 moreinfo Hi Wolfgang, openvpn 2.5.6 with openssl 1.1 seem unable to establish a connection to a sid openvpn-server upgraded to 2.6.0~git20220518+dco-1. I checked the configs. They work if both sides are 2.5.6 or both sides are 2.6 with openssl 3. I also see the following

Bug#1008015: Bugfix might break some setups

2022-05-23 Thread Bernhard Schmidt
Hi, this is definitely not an issue with the fix for Bug#1008015, which was a very minor security bugfix targeted for You are running unstable, therefor you have been upgraded to OpenVPN 2.6 and OpenSSL 3.0. Could you please file a new bug about this with as much information as available

Bug#1011372: openvpn 2.6 fails to communicate due to auth errors

2022-05-22 Thread Bernhard Schmidt
Hi Antti, > Upgrading to openvpn 2.6 breaks communication in a tunnel I'm using. > Downgrading back to openvpn 2.5 fixes the problem. > > Openvpn brings up the tunnel interface but cannot receive data. Syslog > reports auth algo inconsistency when initializing and auth errors when > receiving

  1   2   3   4   5   6   7   8   9   10   >