Bug#931126: unblock: enigmail/2:2.0.11+ds1-2

2019-06-26 Thread Daniel Kahn Gillmor
able; urgency=medium + + * minimize legacy-display protected headers for encrypted mails + + -- Daniel Kahn Gillmor Thu, 30 May 2019 15:40:57 -0400 + +enigmail (2:2.0.11+ds1-1) unstable; urgency=medium + + * new upstream release + * refresh patches + * use the older import-show with --dry-run

Bug#928963: [pkg-gnupg-maint] Bug#928963: fixed in gnupg2 2.2.13-2

2019-06-24 Thread Daniel Kahn Gillmor
Hi Paul-- On Sat 2019-06-22 20:51:00 +0200, Paul Gevers wrote: > On Tue, 14 May 2019 06:18:31 +0000 Daniel Kahn Gillmor > wrote: >> gnupg2 (2.2.13-2) unstable; urgency=medium >> . >>* Correct gpg-wks-server manpage (Closes: #927431) Thanks, ju xor! >>

Bug#930735: WireGuard: Add resolvconf as optional dependency

2019-06-19 Thread Daniel Kahn Gillmor
Control: tags 930735 + moreinfo Hi Willem-- On Wed 2019-06-19 15:01:53 +0200, Willem van den Akker wrote: > Add resolvconf as an optional dependency. > If the DNS option is used in the config file and resolvconf is not installed > wg-quick will return an > error and the interface is not created.

Bug#930042: [pkg-gnupg-maint] Bug#930042: FTBFS when building arch-dep only

2019-06-19 Thread Daniel Kahn Gillmor
On Tue 2019-06-18 17:06:42 +, Daniel Baumann wrote: > On 6/18/19 4:55 PM, Daniel Kahn Gillmor wrote: >> I'll probably drop --fix-missing from src:gnupg2 unless >> dh_missing can get cleverer. > > yes, I did come to the same conclusion: > > https://git.progress-linux

Bug#930689: dh_missing --fail-missing should be smarter about -A and -B

2019-06-19 Thread Daniel Kahn Gillmor
On Tue 2019-06-18 18:00:00 +, Niels Thykier wrote: > It was cased by dh_installinfo having an obsolete/invalid optimization > hint for dh (when used with dh_missing). This has now been fixed in git > (master) will be part of the next release. > > If you are curious, you can see the changes in

Bug#930689: dh_missing --fail-missing should be smarter about -A and -B

2019-06-18 Thread Daniel Kahn Gillmor
Package: debhelper Version: 12.1.1 dh_missing(1) says: Remember to test different kinds of builds (dpkg-buildpackage -A/-B/...) as you may experience varying results when only a subset of the packages are built. And i've seen those different results (e.g., #930042, where

Bug#930042: [pkg-gnupg-maint] Bug#930042: FTBFS when building arch-dep only

2019-06-18 Thread Daniel Kahn Gillmor
On Thu 2019-06-06 01:06:22 +0200, Daniel Baumann wrote: > in 2.2.16-1, "dh_missing --fail-missing" was introduced which breaks > building arch-dep packages only: > > ---snip--- > [...] >debian/rules override_dh_missing > make[1]: Entering directory '/build/gnupg2-2.2.16-1_progress5+u1' >

Bug#930665: [pkg-gnupg-maint] Bug#930665: gpg won't import valid self-signatures if no user ids are present in imported transferable public key

2019-06-18 Thread Daniel Kahn Gillmor
Control: forwarded 930665 https://dev.gnupg.org/T4393 Control: severity 930665 important Control: tags 930665 + confirmed Hi Vincent-- On Tue 2019-06-18 01:04:02 +0200, Vincent Breitmoser wrote: > in the current version of GnuPG, signatures will be imported from public key > blocks only if they

Bug#869184: dpkg: source uploads including _amd64.buildinfo cause problems

2019-06-16 Thread Daniel Kahn Gillmor
On Sun 2019-06-16 15:50:55 +0200, Ivo De Decker wrote: > As "--changes-option=-S" creates an upload that is broken from the point of > view of the archive, it might make sense not to recommend (or even allow) this > for now. Just building with "-S" instead should create a buildinfo file with >

Bug#930338: CVE-2019-10155 IKEv1 Informational exchange integrity check failure

2019-06-10 Thread Daniel Kahn Gillmor
Package: libreswan Version: 3.27-5 Severity critical Control: found -1 3.28-1 Control: forwarded -1 https://libreswan.org/security/CVE-2019-10155/ See the attached message from libreswan upstream about this CVE. I'll fix it in unstable shortly. --dkg --- Begin Message --- -BEGIN PGP

Bug#888025: how to integrate ca-certificates with gpgsm (for email s/mime signature verification)

2019-06-10 Thread Daniel Kahn Gillmor
Hi Gregor, everyone-- On Wed 2019-06-05 19:10:57 +0200, Gregor Zattler wrote: > I use notmuch-emacs to read my email and sometimes do use GnuPG, > therefore notmuch-emacs is configured to verify signatures but > does so also for S/MIME signatures. When displaying such emails > I'm asked if I

Bug#929938: linux: please enable CONFIG_XFRM_STATISTICS=y

2019-06-03 Thread Daniel Kahn Gillmor
X-Debbugs-Cc: Paul Wouters Package: linux Version: 4.19.37-3 Control: affects -1 libreswan 0 dkg@alice:~$ grep CONFIG_XFRM_STATISTICS /boot/config-4.19.0-5-amd64 # CONFIG_XFRM_STATISTICS is not set 0 dkg@alice:~$ Paul Wouters, Libreswan upstream developer says: > Still this kernel option is

Bug#929916: libreswan: CVE-2019-12312

2019-06-03 Thread Daniel Kahn Gillmor
On Mon 2019-06-03 06:26:28 +0200, Salvatore Bonaccorso wrote: > Source: libreswan > Version: 3.27-4 > Severity: grave > Tags: patch security upstream fixed-upstream > Justification: user security hole > Forwarded: https://github.com/libreswan/libreswan/issues/246 > Control: fixed -1 3.28-1 > > The

Bug#929930: libreswan: replace xfrm_stats with xfrm_acq_expires

2019-06-03 Thread Daniel Kahn Gillmor
Package: libreswan Version: 3.28-1 libreswan tries to detect XFRM support by lookng at /proc/net/xfrm_stat, but that's only relevant on kernels with CONFIG_XFRM_STATISTICS enabled. /proc/sys/net/core/xfrm_acq_expires is a more robust way to test for xfrm support. This probably needs to be

Bug#909085: Bug#929385: ITP: sequoia -- a modern OpenPGP implementation in Rust

2019-05-23 Thread Daniel Kahn Gillmor
On Thu 2019-05-23 09:47:54 +0800, Paul Wise wrote: > On Wed, May 22, 2019 at 12:05:27PM -0400, Daniel Kahn Gillmor wrote: > >> Sequoia offers an OpenPGP interface in a modern, memory-safe language. >> It offers two command-line utilities (sq and sqv) in addition to i

Bug#929394: rust-libc: please update to 0.2.55

2019-05-22 Thread Daniel Kahn Gillmor
On Wed 2019-05-22 14:22:38 -0400, Daniel Kahn Gillmor wrote: > There are 100 of them -- yikes! I'm not sure how to efficiently and > safely test them all to ensure that the upgrade doesn't break anything, > so rather than just applying the patch below, i'm proposing it here. We

Bug#929393: rust-lazy-static: please upgrade to 1.3.0

2019-05-22 Thread Daniel Kahn Gillmor
Control: retitle 929393 rust-lazy-static: please upgrade to 1.3.0 On Wed 2019-05-22 14:20:11 -0400, Daniel Kahn Gillmor wrote: > sequoia-openpgp wants lazy_static version 0.13.0. we only have 0.11.0 > in debian right now. I mis-wrote this -- it should have said we want lazy_static 1.3.0,

Bug#909085: ispell: Sequoia & ispell's /usr/bin/sq

2019-05-22 Thread Daniel Kahn Gillmor
On Wed 2018-10-31 10:38:06 -0400, Daniel Kahn Gillmor wrote: > fwiw, debian has been shipping a bugfix patch to ispell's sq for over 7 > years, despite several new upstream releases. > debian/patches/0006-Fix-sq-and-unsq.patch also "addresses" that ispell > upstream doesn't

Bug#929394: rust-libc: please update to 0.2.55

2019-05-22 Thread Daniel Kahn Gillmor
17 00:00:00 2001 From: Daniel Kahn Gillmor Date: Tue, 21 May 2019 17:40:35 -0400 Subject: [PATCH] update libc to 0.2.55 --- src/libc/debian/changelog | 7 +++ src/libc/debian/copyright.debcargo.hint | 7 +++ 2 files changed, 14 insertions(+) diff --git a/src/libc/debian

Bug#929393: rust-lazy-static: please upgrade to 0.13.0

2019-05-22 Thread Daniel Kahn Gillmor
1.3.0 from crates.io using debcargo 2.2.10 + + -- Daniel Kahn Gillmor Tue, 21 May 2019 19:24:40 -0400 + rust-lazy-static (1.2.0-1) unstable; urgency=medium * Package lazy_static 1.2.0 from crates.io using debcargo 2.2.9 diff --git a/src/lazy-static/debian/copyright.debcargo.hint b/src/lazy

Bug#929385: ITP: sequoia -- a modern OpenPGP implementation in Rust

2019-05-22 Thread Daniel Kahn Gillmor
Package: wnpp Severity: wishlist Owner: Daniel Kahn Gillmor * Package name: sequoia Version : 0.7.0 Upstream Author : Sequoia Developers * URL : https://www.sequoia-pgp.org/ * License : GPL Programming Lang: Rust Description : A modern OpenPGP

Bug#929337: rust-string-cache-shared debian/copyright is malformed

2019-05-21 Thread Daniel Kahn Gillmor
On Tue 2019-05-21 17:29:23 -0400, Daniel Kahn Gillmor wrote: > I think this particular patch to debcargo-conf is what you want: > > --- a/src/string-cache-shared/debian/copyright > +++ b/src/string-cache-shared/debian/copyright > @@ -1,3 +1,8 @@ > +Format: https://www.debian

Bug#929337: rust-string-cache-shared debian/copyright is malformed

2019-05-21 Thread Daniel Kahn Gillmor
Package: src:rust-string-cache-shared Version: 0.3.0-1 Control: tags -1 + patch https://tracker.debian.org/media/packages/r/rust-string-cache-shared/copyright-0.3.0-1 shows that it does not have the appropriate header stanza. I think this particular patch to debcargo-conf is what you want: ---

Bug#929280: linux-image-4.19.0-5-powerpc-smp: warning when loading ecdh_generic: "alg: ecdh: Party A: generate public key test failed. Invalid output"

2019-05-20 Thread Daniel Kahn Gillmor
Package: src:linux Version: 4.19.37-3 Severity: normal Control: found -1 5.0.2-1~exp1 If, on this 32-bit powerpc machine, i do: # modprobe -v ecdh_generic then the kernel produces two lines of output: alg: ecdh: Party A: generate public key test failed. Invalid output alg: ecdh:

Bug#928963: giveback for monkeysphere 0.43-3 on ppc64, s390x, and sparc64

2019-05-14 Thread Daniel Kahn Gillmor
Hi Debian buildd maintainers for our 64-bit big-endian platforms! monkeysphere 0.43-3 FTBFS on ppc64, s390x, and sparc64. I traced the problem down to https://bugs.debian.org/928963 in GnuPG, which is now fixed upstream (https://dev.gnupg.org/T4501) and patched in debian unstable. This was a

Bug#928964: gpg fails to emit OpenPGP secret keys if the stored keyfile has a comment or a uri

2019-05-13 Thread Daniel Kahn Gillmor
that a (private-key) list can only have one sublist, which is the list for the private key itself. The attached patch fixes the problem by ignoring all sublists after the first in a (private-key) list. --dkg From 29adca88f5f6425f5311c27bb839718a4956ec3a Mon Sep 17 00:00:00 2001 From: Danie

Bug#928963: gpg-agent READKEY emits an invalid S-expression when private key file has comment (on 64-bit big-endian platforms)

2019-05-13 Thread Daniel Kahn Gillmor
resolves the issue when i test it on zelenka.debian.org (s390x), and should also work on the other two platforms. --dkg From e4a158faacd67e15e87183fb48e8bd0cc70f90a8 Mon Sep 17 00:00:00 2001 From: Daniel Kahn Gillmor Date: Tue, 14 May 2019 00:05:42 -0400 Subject: [PATCH] agent: correct length for

Bug#928894: [pkg-gnupg-maint] Bug#928894: custom keyring is not honoured

2019-05-13 Thread Daniel Kahn Gillmor
On Mon 2019-05-13 01:01:57 +0100, Toni Mueller wrote: > I did not do this. This variable is unset in my environment. right, you were working with a pre-existing keyring. I believe that keyring already had a copy of the teabot public key. > Your experiment only shows that the key did *not* end >

Bug#928894: [pkg-gnupg-maint] Bug#928894: custom keyring is not honoured

2019-05-12 Thread Daniel Kahn Gillmor
Control: tags 928894 + moreinfo Hi Toni-- On Sun 2019-05-12 19:46:45 +0100, Toni wrote: > --recv-keys does not seem to honour the keyring options, so the received > key ends up in the wrong keyring: > > $ touch ~/mnt/tools/gitea-keys.gpg > $ gpg --no-default-keyring --keyring

Bug#928776: unblock: monkeysphere/0.43-3

2019-05-10 Thread Daniel Kahn Gillmor
nkeysphere (0.43-3) unstable; urgency=medium + + * fix monkeysphere-host import-key (Closes: #909700) + * update GnuPG dependency + + -- Daniel Kahn Gillmor Fri, 10 May 2019 16:55:04 -0400 + monkeysphere (0.43-2) unstable; urgency=medium * Autopkgtest should cover Ed25519 as well

Bug#928684: [Pkg-privacy-maintainers] Bug#928684: monkeysphere-host import-key broken due to ssh-keygen change

2019-05-08 Thread Daniel Kahn Gillmor
Control: unarchive 909700 Control: forcemerge 909700 928684 Control: severity 909700 grave Hi Andrei-- On Wed 2019-05-08 20:45:24 +, Andrei Morgan wrote: > # monkeysphere-host import-key /etc/ssh/ssh_host_rsa_key > ssh://server.example.net > RSA.xs:194: OpenSSL error: no start line at

Bug#928622: autodep8 integration with dh

2019-05-08 Thread Daniel Kahn Gillmor
On Wed 2019-05-08 21:25:50 +0200, Paul Gevers wrote: > """ > Automatic test control file for known package types > --- > > There are groups of similarly-structured packages for which the contents > of ``debian/tests/control`` would be mostly

Bug#928675: debhelper: dh_dwz fails on /usr/bin/slt (it has no .debug_info section)

2019-05-08 Thread Daniel Kahn Gillmor
Package: debhelper Version: 12.1.1 Severity: normal using debhelper 12 on the slt package, i get the following error: dh_dwz -O--buildsystem=golang dh_dwz: dwz -q -- debian/slt/usr/bin/slt returned exit code 1 make: *** [debian/rules:5: binary] Error 1 dpkg-buildpackage: error: debian/rules

Bug#928547: mailscripts: notmuch utilities should be better integrated into notmuch

2019-05-08 Thread Daniel Kahn Gillmor
On Wed 2019-05-08 09:36:04 -0700, Sean Whitton wrote: > I hope that it will remain possible to write shell scripts repeatedly > (and idempotently) calling `notmuch config` to set config values in the > database. That would be enough for my usecase to continue to work. for sure, i certainly want

Bug#928622: autodep8 integration with dh

2019-05-08 Thread Daniel Kahn Gillmor
On Tue 2019-05-07 22:48:15 +0200, Paul Gevers wrote: > This is not the recommended way of using autodep8, albeit it does fix an > issue that is worrying me a bit [1]. You are supposed to add a > "Testsuite: autopkgtest-pkg-" to the source stanza of your > package and never look back. See $(man

Bug#928547: mailscripts: notmuch utilities should be better integrated into notmuch

2019-05-08 Thread Daniel Kahn Gillmor
On Tue 2019-05-07 11:19:44 -0700, Sean Whitton wrote: > I consider my notmuch database just a cache; I do not store any > nonreproducible data in it. I hope this usecase will continue to be > supported. I'm surprised to hear that -- i think most people use the notmuch database to store at least

Bug#928622: autodep8 integration with dh

2019-05-07 Thread Daniel Kahn Gillmor
Package: autodep8 Version: 0.18 Affects: -1 + debhelper Severity: wishlist It would be nice if debhelper noticed that when autodep8 was in the build-dependencies of a package, it autogenerated the test somehow. That way a developer could just declare the build-dependency and not worry about

Bug#928547: mailscripts: notmuch utilities should be better integrated into notmuch

2019-05-06 Thread Daniel Kahn Gillmor
Package: mailscripts Severity: wishlist Control: affects -1 notmuch notmuch-{import-patch,extract-patch,slurpdebbug} could all be "notmuch" subcommands, similar to the way that notmuch-emacs-mua is. their configuration could also be stored in notmuch's own configuration, rather than in

Bug#928406: revolt fails to show me the terms and conditions (doesn't have browsing tabs)

2019-05-03 Thread Daniel Kahn Gillmor
Package: revolt Version: 0.0+git20180813.6b10d57-1 Severity: normal I'm experimenting with revolt with a new account hosted on matrix.org. when i tried to chat with a different user, and the webapp shows me a dialog box about needing to agree to the terms and service. When i click the button to

Bug#879008: publicsuffix: effective_tld_names.dat is not upgraded

2019-04-30 Thread Daniel Kahn Gillmor
Version: 20190415.1030-0+deb9u1 On Thu 2017-10-19 02:06:27 -0400, Daniel Kahn Gillmor wrote: > Or is this bug report just asking for a new upload of publicsuffix to > stretch-updates to catch the few dozen domains that have been updated > since stretch was released? publicsuffix fo

Bug#927431: [pkg-gnupg-maint] Bug#927431: [gpg-wks-server] Manpage says "/openpgp/" when it should be "/openpgpkey/"

2019-04-24 Thread Daniel Kahn Gillmor
On Fri 2019-04-19 17:23:00 +, ju xor wrote: > according to the Web Key Directory last draft [0], both the "advanced > and the direct method" on how to form the request URI include the string > "/.well-known/openpgpkey/", but gpg-wks-server says "You also need a > webserver configured to

Bug#927764: evince crashes in poppler on unusual pdf document

2019-04-22 Thread Daniel Kahn Gillmor
Control: forcemerge 924029 927764 On Mon 2019-04-22 23:18:10 +0200, Bernhard Übelacker wrote: > the backtrace looks similar to that from this bug: > > https://bugs.debian.org/924029 Thanks, that does look right. I've tested it and i can confirm that it solves the problem for me. I've submitted

Bug#927764: evince crashes in poppler on unusual pdf document

2019-04-22 Thread Daniel Kahn Gillmor
Package: libpoppler-glib8 Version: 0.71.0-3 Control: affects -1 + evince I have a pdf document that i unfortunately cannot share here. however, trying to open the document with evince 3.30.2-3 crashes in this way: 0 dkg@alice:~$ evince test.pdf ! SyncTeX Error : No file? terminate called after

Bug#927336: [pkg-gnupg-maint] Bug#927336: after buster upgrade (2.1.18-8~deb9u3 -> 2.2.12-1) --search-keys stops working due to dirmngr/keyserver/tor problem: add NEWS?

2019-04-19 Thread Daniel Kahn Gillmor
Control: tags 927336 + moreinfo upstream Hi Tomas-- Thanks for all the details in this report, and i'm sorry that you ran into trouble with your upgrade. You've identified a few different interlocking issues here, and I've tried to parse them out separately, and i've documented some of them as

Bug#927160: stretch-pu: package publicsuffix/20190415.1030-0+deb9u1

2019-04-19 Thread Daniel Kahn Gillmor
On Wed 2019-04-17 22:00:23 +0100, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Mon, 2019-04-15 at 14:12 -0400, Daniel Kahn Gillmor wrote: >> Please consider an update to publicsuffix in debian stretch. >> >> This package reflects the state of the network

Bug#927105: [pkg-gnupg-maint] Bug#927105: pinentry-gnome3: No proper curses fallback.

2019-04-17 Thread Daniel Kahn Gillmor
Control: severity 927105 important Control: retitle 927105 pinentry-gnome3: No curses fallback over ssh when graphical console screen is locked On Tue 2019-04-16 21:50:47 -0700, Zephaniah E. Loss-Cutler-Hull wrote: > I need to try and find the time to spin up a Wayland native VM and do > some

Bug#926984: [pkg-gnupg-maint] Bug#926984: Bug#926984: gnupg2 FTBFS with gcc-9: dirmngr/dns.h:1058:24: error: lvalue required as unary '&' operand

2019-04-16 Thread Daniel Kahn Gillmor
Control: fixed 926984 2.2.14-1 On Wed 2019-04-17 10:13:24 +0900, NIIBE Yutaka wrote: > Control: tags 926984 fixed-upstream > > It was fixed in GnuPG 2.2.14. Annotating this properly in the BTS, accordingly. thanks for following up, gniibe! --dkg

Bug#927255: powerpc-utils is uninstallable

2019-04-16 Thread Daniel Kahn Gillmor
Package: powerpc-utils Version: 1.3.2-1.1 Severity: grave Justification: renders package unusable Control: affects -1 grub-ieee1275 powerpc-utils Depends: pmac-utils, but pmac-utils is no longer in debian. This makes powerpc-utils uninstallable, which in turn makes grub-ieee1275 uninstallatble.

Bug#927105: [pkg-gnupg-maint] Bug#927105: pinentry-gnome3: No proper curses fallback.

2019-04-16 Thread Daniel Kahn Gillmor
Control: tags 927105 + upstream moreinfo Hi Zephaniah-- Thanks for your thoughtful report! On Sun 2019-04-14 23:25:14 -0700, Zephaniah E. Loss-Cutler-Hull wrote: > Looking at the code, it sure looks like it tries to handle this, by > checking to see if there is a DBUS_SESSION_BUS_ADDRESS

Bug#927218: trac-tags should use system jquery-ui

2019-04-16 Thread Daniel Kahn Gillmor
Package: src:trac-tags Version: 0.10-1 Control: affects -1 libjs-jquery-ui trac-tags currently ships with a minified blob of jquery-ui: P: trac-tags source: source-contains-prebuilt-javascript-object tractags/htdocs/htdocs/js/jquery-ui-1.8.16.custom.min.js E: trac-tags source: source-is-missing

Bug#920455: followup on bash process substitution and wait

2019-04-15 Thread Daniel Kahn Gillmor
've pushed this to the fix-920455 branch on https://salsa.debian.org/debian/bash as well, if that makes it easier to adopt. --dkg From: Daniel Kahn Gillmor Date: Mon, 15 Apr 2019 18:26:33 -0400 Subject: wait builtin: avoid hanging on inherited children in https://lists.gnu.org/archive/html/bug-ba

Bug#926984: [pkg-gnupg-maint] Bug#926984: gnupg2 FTBFS with gcc-9: dirmngr/dns.h:1058:24: error: lvalue required as unary '&' operand

2019-04-15 Thread Daniel Kahn Gillmor
Control: tags 926984 + moreinfo Hi Helmut-- On Sat 2019-04-13 09:25:50 +0200, Helmut Grohne wrote: > gnupg2 fails to build from source with gcc-9, here is the relevant part > of a cross build log: > > | aarch64-linux-gnu-gcc -DHAVE_CONFIG_H -I. -I../../dirmngr -I.. >

Bug#865967: backport to stretch

2019-04-15 Thread Daniel Kahn Gillmor
On Fri 2019-04-12 09:41:11 -0400, Jamie McClelland wrote: > Is it possible to back port this fix to debian stretch, stretch backports? I've uploaded trac-tags 0.9-3~bpo9+1 to stretch-backports just now. I think it has to go through the backports NEW queue before it's easily available. I've also

Bug#924493: stretch-pu: package publicsuffix/20190221.0923-0+deb9u1

2019-04-15 Thread Daniel Kahn Gillmor
On Sat 2019-04-13 22:04:03 +0100, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Wed, 2019-03-13 at 11:12 -0400, Daniel Kahn Gillmor wrote: >> Please consider an update to publicsuffix in debian stretch. >> >> This package reflects the state of the network

Bug#747400: bash: Vcs-Bzr is out of date

2019-04-15 Thread Daniel Kahn Gillmor
On Thu 2014-05-08 05:57:29 -0400, Anders Kaseorg wrote: > bash’s debian/control lists > > Vcs-Bzr: http://bazaar.launchpad.net/~doko/+junk/pkg-bash-debian > > However, this Bazaar repository doesn’t have any versions newer than > 4.2+dfsg-1. I can confirm that this continues to be the case. i

Bug#927160: stretch-pu: package publicsuffix/20190415.1030-0+deb9u1

2019-04-15 Thread Daniel Kahn Gillmor
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Control: affects -1 src:publicsuffix Please consider an update to publicsuffix in debian stretch. This package reflects the state of the network, and keeping it current is useful

Bug#926817: unblock: publicsuffix/20190329.0756-1

2019-04-15 Thread Daniel Kahn Gillmor
1030-1) unstable; urgency=medium + + * new upstream version + + -- Daniel Kahn Gillmor Mon, 15 Apr 2019 13:47:04 -0400 + +publicsuffix (20190329.0756-1) unstable; urgency=medium + + * new upstream version + + -- Daniel Kahn Gillmor Wed, 03 Apr 2019 22:49:31 -0400 + publicsuffix (20190221.0923-1) un

Bug#920455: followup on bash process substitution and wait

2019-04-12 Thread Daniel Kahn Gillmor
Control: forwarded 920455 https://lists.gnu.org/archive/html/bug-bash/2019-04/msg00076.html https://bugs.debian.org/920455 is being discussed with upstream over on the bug-b...@gnu.org mailing list. --dkg signature.asc Description: PGP signature

Bug#926882: unblock: pymilter/1.0.3-3

2019-04-11 Thread Daniel Kahn Gillmor
@@ -1,3 +1,10 @@ +pymilter (1.0.3-3) unstable; urgency=medium + + * Avoid crashes in Milter.utils.parseaddr (Closes: #922733) + * add myself to uploaders + + -- Daniel Kahn Gillmor Tue, 19 Feb 2019 18:35:31 -0500 + pymilter (1.0.3-2) unstable; urgency=medium * Add preprocessor defines

Bug#922733: python3-milter: Milter.utils.parseaddr() fails: AttributeError: module 'email' has no attribute 'utils'

2019-04-11 Thread Daniel Kahn Gillmor
Control: affects 922733 + src:dkimpy-milter Control: severity 922733 important Control: block 922006 by 922733 Control: forwarded 922733 https://github.com/sdgathman/pymilter/commit/04e0b156400798ab9527385946f632f744ed60d5 > In [2]: Milter.utils.parseaddr('Daniel Kahn Gill

Bug#926771: knot-resolver: Needs to recommend lua-cqueues for automatic detection of changes to RPZ file

2019-04-11 Thread Daniel Kahn Gillmor
On Wed 2019-04-10 09:50:23 +0200, Frederik Himpe wrote: > The package should at least recommend the lua-cqueues package, because > that one is needed for detecting changes to RPZ files. > > https://github.com/CZ-NIC/knot-resolver/blob/master/modules/policy/policy.lua#L430 Thanks for this report!

Bug#926817: unblock: publicsuffix/20190329.0756-1

2019-04-10 Thread Daniel Kahn Gillmor
/changelog +++ publicsuffix-20190329.0756-1/debian/changelog @@ -1,3 +1,9 @@ +publicsuffix (20190329.0756-1) unstable; urgency=medium + + * new upstream version + + -- Daniel Kahn Gillmor Wed, 03 Apr 2019 22:49:31 -0400 + publicsuffix (20190221.0923-1) unstable; urgency=medium * new

Bug#926636: [pkg-gnupg-maint] Bug#926636: marked as done (gpg: connecting dirmngr at '/run/user/1000/gnupg/S.dirmngr' failed: IPC connect call failed)

2019-04-09 Thread Daniel Kahn Gillmor
On Hans-Christoph wrote: > Well, its kind of a bug, but more of an error reporting bug. I had a > bad option in ~/.gnupg/dirmngr.conf from before I upgraded to buster. > Running `dirmngr` bare gave me useful error output: for future reference, you should also see those error messages in:

Bug#924493: stretch-pu: package publicsuffix/20190221.0923-0+deb9u1

2019-04-03 Thread Daniel Kahn Gillmor
On Tue 2019-03-26 10:21:12 +0100, Daniel Kahn Gillmor wrote: > On Wed 2019-03-13 11:12:26 -0400, Daniel Kahn Gillmor wrote: >> Package: release.debian.org >> Severity: normal >> Tags: stretch >> User: release.debian@packages.debian.org >> Usertags: pu >&g

Bug#926196: util-linux: "su --pty" is unusable

2019-04-01 Thread Daniel Kahn Gillmor
Package: util-linux Version: 2.33.1-0.1 Severity: normal Control: tags -1 upstream patch Control: forwarded -1 https://github.com/karelzak/util-linux/issues/767 If i run "su --pty" i expect to get a functional terminal. However, the width of the terminal is not available, and special characters

Bug#925351: stretch-pu: package dns-root-data/2019031302~deb9u1

2019-03-31 Thread Daniel Kahn Gillmor
On Sun 2019-03-31 20:07:06 +0100, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Sat, 2019-03-23 at 16:04 +0100, Daniel Kahn Gillmor wrote: >> Please consider an update to dns-root-data in debian stretch. > > +dns-root-data (2019031302~deb9u1) st

Bug#925905: knot: d/copyright is severely incomplete

2019-03-28 Thread Daniel Kahn Gillmor
Package: 2.8.0-1 Severity: serious Flagging as serious because it's a policy violation. autotools files, and install-sh, in various directories not accounted for in d/copyright. distro/deb presumably is GPL-3+ without the SSL exception. contrib/ does not have the OpenSSL exception either ...

Bug#925596: irssi-plugin-xmpp: ABI mismatch with irssi 1.2.0-2

2019-03-27 Thread Daniel Kahn Gillmor
Package: irssi-plugin-xmpp Version: 0.54-2.1 Severity: grave Justification: renders package unusable I get the following warnings from irssi when trying to use it with irssi-plugin-xmpp: 10:49 -!- Irssi: xmpp/core is ABI version 13 but Irssi is version 20, cannot load

Bug#924493: stretch-pu: package publicsuffix/20190221.0923-0+deb9u1

2019-03-26 Thread Daniel Kahn Gillmor
On Wed 2019-03-13 11:12:26 -0400, Daniel Kahn Gillmor wrote: > Package: release.debian.org > Severity: normal > Tags: stretch > User: release.debian@packages.debian.org > Usertags: pu > Control: affects -1 src:publicsuffix > > Please consider an update to publicsuffix

Bug#925405: ITP: picotls -- library for TLS 1.3 (RFC 8446)

2019-03-24 Thread Daniel Kahn Gillmor
Package: wnpp Severity: wishlist Owner: Daniel Kahn Gillmor * Package name: picotls Version : 0.0.20190320 Upstream Author : Kazuho Oku * URL : https://github.com/h2o/picotls * License : MIT, CC0 Programming Lang: C Description : library for TLS 1.3

Bug#925376: unblock: dns-root-data/2019031302

2019-03-23 Thread Daniel Kahn Gillmor
root data to 2019031302 + * standards-version: bump to 4.3.0 (no changes needed) + * parse-root-anchors.sh: account for validity windows + * check: deliberately skip the TTL generated by ldns-key2ds + * dns-root-data is Multi-Arch: foreign + + -- Daniel Kahn Gillmor Sat, 23 Mar 2019 15:33:17 +0

Bug#925374: dns-root-data: ships an obsolete root zone signing key

2019-03-23 Thread Daniel Kahn Gillmor
Package: dns-root-data Version: 2018091102 Severity: serious Control: found -1 2014060201+2 2017072601~deb8u1 2017072601~deb8u2 2017072601~deb9u1 2017072601~deb9u1 Control: fixed -1 2019031302 The versions of dns-root-data marked as "found" above ship a hash for a root zone key that was retired

Bug#925351: stretch-pu: package dns-root-data/2019031302~deb9u1

2019-03-23 Thread Daniel Kahn Gillmor
ip the TTL generated by ldns-key2ds + * add myself to uploaders + + -- Daniel Kahn Gillmor Sat, 23 Mar 2019 15:43:27 +0100 + dns-root-data (2017072601~deb9u1) stretch; urgency=high * Update root.hints to 2017072601 version diff --git publicsuffix-2017072601~deb9u1/debian/control publicsuff

Bug#902963: dns-root-data: Added entry in /usr/share/dns/root.ds breaks dnsmasq startup

2019-03-23 Thread Daniel Kahn Gillmor
Control: tags 902963 + moreinfo Control: reassign 902963 dnsmasq Control: retitle 902963 dnsmasq startup breaks when more than one entry is present in /usr/share/dns/root.ds Control: affects 902963 + dns-root-data On Wed 2018-07-04 00:45:10 +, Mark Blackburn wrote: >* What led up to the

Bug#925349: src:dns-root-data: Should automate root key transitions (at job? systemd timer?)

2019-03-23 Thread Daniel Kahn Gillmor
Package: src:dns-root-data Severity: wishlist root-anchors.xml (from IANA) contains validity window dates. So the package could effectively know when to add a new key or drop an old key well before it happens. While we can perform such a drop by upgrading the dns-root-data package, getting the

Bug#925148: devscripts: uscan signature verification is too strict

2019-03-20 Thread Daniel Kahn Gillmor
On Wed 2019-03-20 16:02:20 +0100, Mattia Rizzolo wrote: > AFAIK, all uscan does here is invoke gpgv (or gpg) and check its return > code. See Devscripts::Uscan::Keyring. […] > So… can you tell us how to convince gpg here? :) gpg upstream has, on other disucssions, claimed that checking the

Bug#657784: CVE-2005-4890: tty hijacking possible in "sudo" via TIOCSTI ioctl

2019-03-20 Thread Daniel Kahn Gillmor
s/1 Regards, --dkg From 0fc8d1c532f5720c7f5a58f48b7b6eb2cc44c62e Mon Sep 17 00:00:00 2001 From: Daniel Kahn Gillmor Date: Wed, 20 Mar 2019 13:57:11 -0400 Subject: [PATCH] set use_pty by default (Closes: #657784) --- debian/sudoers | 1 + 1 file changed, 1 insertion(+) diff --git a/deb

Bug#925148: devscripts: uscan signature verification is too strict

2019-03-20 Thread Daniel Kahn Gillmor
Package: devscripts Version: 2.19.3 Severity: normal libassuan has only Werner Koch's key listed as a potential signing key in debian/upstream/signing-key.asc. libassuan upstream released a new tarball that is signed by *both* Werner and NIIBE Yutaka (another assuan developer). uscan complains

Bug#925118: gbp import-orig: verify upstream-vcs-tag

2019-03-20 Thread Daniel Kahn Gillmor
On Tue 2019-03-19 17:54:30 -0400, Daniel Kahn Gillmor wrote: > 4) (optionally) confirm that the tag commit message matches some > pattern. For example, if i think i'm verifying version 1.17 of the > Foo project, i might want to confirm that the first line of the > messag

Bug#925118: gbp import-orig: verify upstream-vcs-tag

2019-03-20 Thread Daniel Kahn Gillmor
On Wed 2019-03-20 09:41:02 +0100, Guido Günther wrote: > This sounds all good to me. To add some bikeshedding I'd do it like > > --upstream-vcs-tag-check= > > so we can have things like: > > --upstream-vcs-tag-check=signature,format That sounds totally reasonable to me. The concreteness of

Bug#925118: gbp import-orig: verify upstream-vcs-tag

2019-03-19 Thread Daniel Kahn Gillmor
Package: git-buildpackage Severity: wishlist Hi gbp folks-- I use gbp with upstream-vcs-tag to keep my debian packaging in sync with upstream repositories. It's really great! I'd like to automate my workflow a little bit more, though: one of the common things that i do is to verify the

Bug#925116: posh: use memfd_create(2) for heredocs when available

2019-03-19 Thread Daniel Kahn Gillmor
Package: posh Severity: wishlist Currently posh creates heredocs in the filesystem. This means that heredoc contents will unnecessarily touch the disks, and it also means dealing with risky juggling of tempfile names. It would be nicer, on platforms that support it, if posh could use

Bug#921904: win-iconv: FTBFS (wine: chdir to /tmp/wine-I6miLw/server-29-3583b06 : No such file or directory)

2019-03-18 Thread Daniel Kahn Gillmor
On Mon 2019-03-18 10:55:44 +0100, Tim Rühsen wrote: > Libiconv 1.15 itself from tarball. > > If you are interested in the details, have a look at our CI Dockerfile > where we build/install the dependencies needed for testing: > >

Bug#921904: win-iconv: FTBFS (wine: chdir to /tmp/wine-I6miLw/server-29-3583b06 : No such file or directory)

2019-03-17 Thread Daniel Kahn Gillmor
On Sun 2019-03-17 13:14:54 +0100, Tim Rühsen wrote: > Fixed it by building my own libiconv on MinGW systems. It really is > straight forward and possibly no extra Debian package is needed. Thanks for the feedback, Tim. For your fix, are you building libiconv itself, or win-iconv for MinGW

Bug#924872: unblock: knot-resolver/3.2.1-3

2019-03-17 Thread Daniel Kahn Gillmor
, not arch: any + * Explicitly list all non-arm64 architectures + + -- Daniel Kahn Gillmor Fri, 08 Mar 2019 00:56:09 -0500 + +knot-resolver (3.2.1-2) unstable; urgency=medium + + * Standards-Version: move to 4.3.0 (no changes needed) + * move to debhelper 12 + * Avoid breakage when built against

Bug#874029: /usr/bin/uscan: Re: [uscan] Please support verification against a signed file of hashsums

2019-03-15 Thread Daniel Kahn Gillmor
Control: affects 874029 + src:notmuch On Sat 2017-12-30 15:12:14 +0900, Mike Hommey wrote: > I can't tell you how many, but I can tell you that's how Mozilla does it > too, so this applies to firefox, thunderbird, nspr and nss: notmuch does it as well: https://notmuchmail.org/releases/

Bug#924493: stretch-pu: package publicsuffix/20190221.0923-0+deb9u1

2019-03-13 Thread Daniel Kahn Gillmor
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Control: affects -1 src:publicsuffix Please consider an update to publicsuffix in debian stretch. This package reflects the state of the network, and keeping it current is useful

Bug#918806: version 3.5: mail/mailx discard message body when attachment is supplied

2019-03-13 Thread Daniel Kahn Gillmor
Hi GNU Mailutils developers-- Are you aware of this report in debian about mail discarding stdin when being used to send an e-mail with an attachment? https://bugs.debian.org/918806 I can confirm that it's happening with mailutils 3.5, but have not tested 3.6 against it, and i see no

Bug#918806: /usr/bin/mail.mailutils: Pipe text to mail and attach a csv sets content type to application/octet-stream not multipart/mixed

2019-03-13 Thread Daniel Kahn Gillmor
Message-Id: <20190313144838.daaf420...@fifthhorseman.net> Date: Wed, 13 Mar 2019 10:48:38 -0400 (EDT) From: Daniel Kahn Gillmor --225007733-1552488518=:22450 Content-Type: text/plain; charset=UTF-8 Content-Disposition: attachment Content-ID: <20190313104838.2245...@alice.fifthhorseman.ne

Bug#921904: win-iconv: FTBFS (wine: chdir to /tmp/wine-I6miLw/server-29-3583b06 : No such file or directory)

2019-03-12 Thread Daniel Kahn Gillmor
Control: tags 921904 + help On Sat 2019-02-09 23:50:03 +, Santiago Vila wrote: > Package: src:win-iconv > Version: 0.0.8-2 > Severity: serious > Tags: ftbfs > > Dear maintainer: > > I tried to build this package in buster but it failed: > >

Bug#911768: pinentry-gnome3 fails to open a window with 'No Gcr System Prompter available, falling back to curses'

2019-03-12 Thread Daniel Kahn Gillmor
On Tue 2019-03-12 15:01:26 +, Simon McVittie wrote: > If I understand their position correctly, the Debian systemd maintainers > would consider that to be a misconfiguration, because > Depends: libpam-systemd is the official way for a package to say "I need > a fully working systemd-logind and

Bug#911768: pinentry-gnome3 fails to open a window with 'No Gcr System Prompter available, falling back to curses'

2019-03-12 Thread Daniel Kahn Gillmor
Control: severity 911768 normal Hi Simon -- Thanks for this detailed triage! On Sun 2019-03-10 14:35:04 +, Simon McVittie wrote: > I think this should be considered to be a pinentry-gnome3 bug rather than > nfs-kernel-server. I think the plausible routes forward are to either > escalate

Bug#849308: state of wireguard mainline inclusion?

2019-03-08 Thread Daniel Kahn Gillmor
Hi Mika-- On Thu 2019-03-07 16:16:40 +0100, Michael Prokop wrote: > So sadly wireguard didn't make it into buster. :( yep, frustrating. but that was by design -- it isn't clear to me that the ecosystem will be happy with having a wide distribution of an outdated (2019) version running in 2021

Bug#924021: Avoid embedding a copy of the Epoch javascript library

2019-03-08 Thread Daniel Kahn Gillmor
Package: src:knot-resolver Version: 3.2.1-3 Control: block -1 with 840619 Control: clone -1 -2 Control: retitle -1 knot-resolver: Avoid embedding a copy of the Epoch javascript library Control: reassign -2 src:libminion-perl 9.09+dfsg-1 Control: retitle -2 libminion-perl: Avoid embedding a copy

Bug#924019: RM: libkres9, libkres-dev [arm64] -- ROM; no binaries for src:knot-resolver on arm64

2019-03-08 Thread Daniel Kahn Gillmor
Package: ftp.debian.org Severity: normal Control: affects -1 src:knot-resolver libkres9 libkres-dev NOTE: this is just a request for removal of the libkres9 and libkres-dev binary packages on arm64. please do *not* remove the knot-resolver source package, or the knot-resolver binary package on

Bug#923991: Avoid embedding a copy of dygraphs

2019-03-07 Thread Daniel Kahn Gillmor
Package: src:knot-resolver Version: 3.2.1-2 Control: block -1 with 749603 Control: user p...@debian.org Control: usertag + embed Control: clone -1 -2 -3 -4 Control: retitle -1 knot-resolver: Avoid embedding a copy of dygraphs Control: reassign -2 src:r-cran-dygraphs 1.1.1.6+dfsg-1 Control: retitle

Bug#922120: annoying messages from systemd.unit

2019-03-07 Thread Daniel Kahn Gillmor
On Thu 2019-03-07 21:37:30 +0100, Daniel Baumann wrote: > i've verified this with another vanilla system that wasn't upgraded and > i can reproduce it there: 3.2.0-1 fixed it. Weird! This bug was reported against 3.2.0-1 in the first place, so i'm pretty confused :/ But at least it's gone away

Bug#923970: libkres-dev: cannot build anything meaningful against libkres-dev

2019-03-07 Thread Daniel Kahn Gillmor
Package: libkres-dev Version: 3.2.1-1 Severity: grave Justification: renders package unusable A little over half of the header files shipped in libkres-dev contain an #include line that refers to other files in "lib/…", for example: #include "lib/defines.h" You can see these with: grep -n

Bug#922120: annoying messages from systemd.unit

2019-03-07 Thread Daniel Kahn Gillmor
Control: tags 922120 + moreinfo Hi Daniel-- On Tue 2019-02-12 11:54:55 +0100, Daniel Baumann wrote: > thank you so much for maintaining knot-resolver, it's wonderful. Glad you find it useful! > Unfortunately, whenever *any* service is reladed on my system (vanilla > debian with 'apt install

Bug#920763: lintian: orig-tarball-missing-upstream-signature interacts poorly with mode=git,pgpmode=gittag

2019-03-06 Thread Daniel Kahn Gillmor
On Tue 2019-03-05 10:57:03 -0800, Felix Lechner wrote: > With source format 3.0 (git) that logic even found a way into the packaging > system. Let's flip it around for a moment: Why not validate upstream > signatures when the package is built? sorry, i think i'm still not following. I *do*

<    3   4   5   6   7   8   9   10   11   12   >