Bug#1068250: Switch to 'ng', but calling it 'dracut', don't add 'ng'?

2024-05-23 Thread Patrick Schleizer
Fedora, Arch kept calling the package dracut. They did not add the "-ng" appendix. Would it be an option for Debian to keep calling it dracut even though the git upstream repository will be changed to dracut-ng? If permissible, that might be easier. It seems unlikely that the dracut without

Bug#1065545: RFP: AppArmor.d - Full set of AppArmor profiles (~ 1500 profiles)

2024-03-06 Thread Patrick Schleizer
Package: wnpp Severity: wishlist X-Debbugs-CC: pkg-privacy-maintain...@lists.alioth.debian.org * Package name: AppArmor.d Version : 583aa2a119afdb0cd2e916eb618bc9bf48b98814 Upstream Author : Alexandre Pujol * URL : https://github.com/roddhjav/apparmor.d * License

Bug#1062756: reported upstream

2024-02-22 Thread Patrick Schleizer
https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/2053153/

Bug#1064044: change Debian's default umask to a more secure value such as umask 0077

2024-02-16 Thread Patrick Schleizer
Package: general Severity: wishlist Feature request: Change Debian's default umask to a more secure value such as umask 0077. Why? Quote Securing Debian Manual [1] > Debian's default umask setting is 022 this means that files (and directories) can be read and accessed by the user's group and

Bug#1062756: initramfs-tools: fix compatibility with libpam-tmpdir and /tmp mounted with noexec

2024-02-14 Thread Patrick Schleizer
bug report / feature request: Dear maintainer, could you fix initramfs-tools compatibility with libpam-tmpdir and /tmp mounted with noexec please? Cheers, Patrick

Bug#1062756: cryptsetup-initramfs Debian bug with libpam-tmpdir and /tmp mounted with noexec

2024-02-14 Thread Patrick Schleizer
Ok, not a bug in cryptsetup-initramfs. Let's reassign to initramfs-tools-core as a bug or feature request? (Depending on how one wanted to look at it.) Would that be appropriate? And also forward to upstream, which has its issue tracker hosted at launchpad initramfs-tools?

Bug#1062756: cryptsetup-initramfs Debian bug with libpam-tmpdir and /tmp mounted with noexec

2024-02-14 Thread Patrick Schleizer
This is not a bug in a downstream distribution. To reproduce this bug in Debian: 1) sudo apt install libpam-tmpdir 2) Mount /tmp with noexec. Could this be fixed in Debian please?

Bug#1037299: debian-live-12.0.0-amd64-xfce.iso: "Install Debian" -> "Untrusted application launcher"

2024-01-03 Thread Patrick Schleizer
f=~/Desktop/install-debian.desktop gio set -t string "$f" metadata::xfce-exe-checksum "$(sha256sum "$f" | awk '{print $1}')"

Bug#686817: grub-pc: Add option to change keyboard layout

2024-01-03 Thread Patrick Schleizer
This bug is assigned to grub-pc (legacy BIOS). grub-efi (and probably others) are however equally affected. Should this bug therefore be re-assigned to grub? I haven't found any bug report for grub-efi. Is this bug report the reason why non-US keyboard layouts result in broken password

Bug#1037299: (no subject)

2024-01-03 Thread Patrick Schleizer
Didn't work for me but this did: https://forum.xfce.org/viewtopic.php?id=16357

Bug#1017039: (no subject)

2023-12-21 Thread Patrick Schleizer
Hi Thomas, understood. Thank you for your elaboration and maintaining dracut in Debian! Cheers, Patrick

Bug#1059221: outdated package description - mkosi is no longer legacy-free (and that's okay)

2023-12-21 Thread Patrick Schleizer
Package: mkosi Severity: low Dear maintainer, as for the headline, I know "create legacy-free OS images" was the original branding of the project. mkosi know supports legacy BIOS booting. I see you already updated the package description to reflect that. Images are no longer

Bug#1017039: (no subject)

2023-12-17 Thread Patrick Schleizer
https://salsa.debian.org/debian/dracut/-/merge_requests/20 was not merged but will Debian get this change from upstream dracut when a new version is uploaded to Debian?

Bug#1056382: missing dependency on init / systemd-sysv / libpam-systemd

2023-11-21 Thread Patrick Schleizer
Package: dracut-core Severity: normal When attempting to install dracut inside a chroot while libpam-systemd wasn't installed, dracut showed an error message and the resulting image was unbootable. > ``` > dracut-install: ERROR: installing 'poweroff' > dracut-install: ERROR: installing

Bug#1055433: key enrollment on non-EFI systems for `module.sig_enforce=1` kernel parameter

2023-11-05 Thread Patrick Schleizer
Package: src:linux Severity: normal Kernel module signature verification can be enabled using the `module.sig_enforce=1` kernel parameter on non-EFI systems. On non-EFI systems, `mokutil` won't work. But then how could one enroll the key without needing to recompile grub or the kernel? Can

Bug#823651: sudo apt install libpam-tmpdir breaks cowbuilder

2023-11-03 Thread Patrick Schleizer
On Debian bookworm: sudo apt install libpam-tmpdir is enough to break cowbuilder, which then calls pbuilder. I: Installing the build-deps -> Attempting to satisfy build-dependencies -> Creating pbuilder-satisfydepends-dummy package Package: pbuilder-satisfydepends-dummy Version: 0.invalid.0

Bug#1054343: add support for "apt install fp-units-win-rtl" instead of "apt install fp-units-win-rtl-3.2.2"

2023-10-22 Thread Patrick Schleizer
Package: fpc Severity: wishlist apt install fp-units-win-rtl Reading package lists... Done Building dependency tree... Done Reading state information... Done E: Unable to locate package fp-units-win-rtl fp-units-win-rtl is a virtual package. It is provided by real package

Bug#962311: (no subject)

2023-10-09 Thread Patrick Schleizer
Any update?

Bug#1050862: ship systemd-tmpfiles /usr/lib/tmpfiles.d/tor.conf to fix permission issues

2023-08-30 Thread Patrick Schleizer
, then the Tor systemd unit should be able to restore it without needing to re-install the tor package. I would suggest the following /usr/lib/tmpfiles.d/tor.conf file contents: d /var/lib/tor 02700 debian-tor debian-tor - Z /var/lib/tor/* 0660 debian-tor debian-tor - Kind regards, Patrick

Bug#1037254: extrepo apt-transport-tor and onion support

2023-08-05 Thread Patrick Schleizer
The design looks great! I posted several comments here: https://salsa.debian.org/extrepo-team/extrepo-data/-/merge_requests/240 Cheers, Patrick

Bug#938929: (no subject)

2023-07-26 Thread Patrick Schleizer
libvirt upstream no longer depends on iptables for years. source: https://gitlab.com/libvirt/libvirt/-/issues/406#note_1176654618 Should be trivial and safe to switch to nftables?

Bug#1029324: (no subject)

2023-07-22 Thread Patrick Schleizer
Thanks to Laszlo Gombos, this has been reported upstream. Generic initrd does not work with encrypted root FS without further configuration https://github.com/dracutdevs/dracut/issues/2437

Bug#1041614: Acknowledgement (unbootable system after installing dracut on a standard Debian installation)

2023-07-22 Thread Patrick Schleizer
This might be duplicate of: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1029324

Bug#1041614: Acknowledgement (unbootable system after installing dracut on a standard Debian installation)

2023-07-22 Thread Patrick Schleizer
I've checked with 'sudo lsinitrd' and I can see that usr/lib/systemd/systemd-cryptsetup is there but cryptsetup is missing. File /usr/lib/dracut/modules.d/90crypt/module-setup.sh check() { local fs # if cryptsetup is not installed, then we cannot support encrypted devices.

Bug#1041614: (no subject)

2023-07-22 Thread Patrick Schleizer
This is happening with legacy BIOS boot. I didn't test it with EFI booting. This is reproducible with both, - Debian installed using debian-installer (that can be started from the ISO boot menu) (which sets up an encrypted LVM), - as well as with Debian installed using calamares (which uses

Bug#1041614: unbootable system after installing dracut on a standard Debian installation

2023-07-21 Thread Patrick Schleizer
initramfs. /usr/lib/dracut/modules.d/90crypt/module-setup.sh > inst_multiple cryptsetup rmdir readlink umount But since it's unavailable inside the dracut rescue shell it seems to be missing for some reason. Kind regards, Patrick Schleizer

Bug#1037254: extrepo apt-transport-tor and onion support

2023-07-18 Thread Patrick Schleizer
One thing to consider: A few onions are tor+https but most are tor+http. But I guess that's not an issue because http vs https is declared in the repository configuration files. I think this would be a nice feature to have, indeed. Thank you for your interest in this feature! However,

Bug#1040928: (no subject)

2023-07-13 Thread Patrick Schleizer
duplicate of https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1032408

Bug#1040928: live-build fails ln: failed to create symbolic link '/etc/mtab': File exists caused by --chroot-filesystem ext4

2023-07-12 Thread Patrick Schleizer
e this case. Why am I interested to use '--chroot-filesystem ext4'? Because it saves a lot time during testing to skip squashfs creation. Making the scripts resilient against this seems useful to me either way as such as situation might also happen through other kinds of customization. Kind regards, Patrick Schleizer

Bug#1038886: /usr/share/initramfs-tools/hooks/udev fails in chroot

2023-06-22 Thread Patrick Schleizer
Dear maintainer, this was my mistake. (A build script had a workaround leftover for a bug that was now fixed in bookworm.) Not a bug in udev. Sorry for the noise! Please close. Thank you! Kind regards, Patrick

Bug#1038886: /usr/share/initramfs-tools/hooks/udev fails in chroot

2023-06-22 Thread Patrick Schleizer
Package: udev Severity: important Dear maintainer, there's an issue in file /usr/share/initramfs-tools/hooks/udev During installation inside chroot: update-initramfs: Generating /boot/initrd.img-6.1.0-9-amd64 W: No zstd in /usr/bin:/sbin:/bin, using gzip E:

Bug#1037254: extrepo apt-transport-tor and onion support

2023-06-09 Thread Patrick Schleizer
Package: extrepo Severity: wishlist Dear maintainer, - most clearnet repositories are reachable over Tor. This is simple to accomplish by using the apt-transport-tor package (in packages.debian.org for a long time already) by using the tor+https syntax in sources.list. - More and more

Bug#1037137: add fp-units-*-win64_*.deb dependency packages required for Windows cross-compilation

2023-06-06 Thread Patrick Schleizer
Package: fpc Severity: wishlist Dear maintainer, when compiling fpc from upstream, folder /usr/lib/fpc/3.2.2/units/x86_64-win64 would contain dependencies required for cross-compilation. (source: Building on Debian, target: compilation for Windows 64 bit) However, Debian lacks the

Bug#1031932: mmdebstrap: fix debootstrap, live-boot compatibility / support --download-only, --foreign, --second-stage, --no-check-gpg

2023-03-13 Thread Patrick Schleizer
Johannes Schauer Marin Rodrigues: It's currently broken because `lb` uses (at least) the following parameters which are unsupported by mmdebstrap: * --download-only By looking at the source code of live-build I am reasonably sure, this might only be happening because I previously set: `lh

Bug#1031932: mmdebstrap: fix debootstrap, live-boot compatibility / support --download-only, --foreign, --second-stage, --no-check-gpg

2023-02-25 Thread Patrick Schleizer
Package: mmdebstrap Severity: normal Dear maintainer, live-build's `lb build` uses some command line options which are unsupported by mmdebstrap. live-build currently doesn't support configuration of the debootstrap program [1] but until/if it does, I simply used "sudo cp

Bug#1031929: support configuration of debootstrap binary

2023-02-25 Thread Patrick Schleizer
Package: live-build Severity: wishlist Dear maintainer, currently scripts/build/bootstrap_debootstrap hardcodes `debootstrap`. debootstrap ${DEBOOTSTRAP_OPTIONS} "${LB_PARENT_DISTRIBUTION_CHROOT}" chroot "${LB_PARENT_MIRROR_BOOTSTRAP}" ${DEBOOTSTRAP_SCRIPT} There are however other

Bug#1031903: live-build: add dracut support

2023-02-24 Thread Patrick Schleizer
Package: live-build Severity: normal Dear maintainer, could you please add support for dracut? related: - live-build: netboot IPv6 only and NFSv4 → dracut https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1006612 - https://packages.debian.org/dracut-live -

Bug#1029554: Tor fails to start a few times before succeeding to start

2023-01-24 Thread Patrick Schleizer
Package: tor Severity: normal Dear maintainer, Tor fails to start a few times before succeeding to start. This is likely because the tor@default.service systemd unit does not wait for 'network.target.' symptom: [FAILED] to start Anonymizing overlay network for TCP This only started

Bug#919320: big update

2022-12-07 Thread Patrick Schleizer
A ton of progress was made thanks to Jan Mojzis and Jérémy Lal. https://alioth-lists.debian.net/pipermail/pkg-nginx-maintainers/2022q4/002051.html libnginx-mod-http-brotli has entered Debian sid: https://packages.debian.org/search?keywords=libnginx-mod-http-brotli

Bug#1022746: please provide linux-image-generic / linux-headers-generic

2022-10-24 Thread Patrick Schleizer
Package: linux Severity: normal Dear maintainer, In Debian, linux-headers-generic is a virtual package. https://packages.debian.org/bullseye/linux-headers-generic In Ubuntu, linux-headers-generic is a real package. https://packages.ubuntu.com/linux-headers-generic It depends at time of

Bug#994138: kernel command line (grub) UUID=... and PARTUUID=... Can not mount on filesystem /run/live/rootfs/filesystem since Debian bullseye

2021-09-12 Thread Patrick Schleizer
Package: live-boot Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, the following is a regression in Debian bullseye. No such issue in Debian buster. Kernel command line 'debug=1' shows that live-boot attempts to run the following mount command: mount -t -o ro,noatime

Bug#991276: grub-live dracut support

2021-09-01 Thread Patrick Schleizer
grub-live dracut support has been implemented.

Bug#991276: Boot existing Host Operating System or VM into Live Mode (grub-live)

2021-07-19 Thread Patrick Schleizer
Package: live-boot Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org This is a feature request to adopt / re-implement grub-live. It provides functionality to "Boot existing Host Operating System or VM into Live Mode". 1. install Debian normally. 2. install grub-live 3. choose in grub

Bug#961884: [Pkg-clamav-devel] Bug#961884: add init script / systemd unit for clamonacc background scanner

2021-06-29 Thread Patrick Schleizer
Perhaps a disabled by default $initscript?

Bug#987876: Gajim update invalidates encryption settings

2021-05-01 Thread Patrick Schleizer
Package: gajim Severity: important X-Debbugs-CC: whonix-de...@whonix.org Quote https://dev.gajim.org/gajim/gajim/-/issues/10527 > Steps to reproduce: > > Configure gajim to encrypt messages using OMEMO to a specific contact > Update Gajim to 1.3.1 > Restart Gajim, update the plugins > Try to

Bug#984690: phased updates support

2021-03-07 Thread Patrick Schleizer
Package: reprepro Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, could you please add phased updates support? https://blog.jak-linux.org/2021/02/18/apt-2.2/ > APT now implements phased updates. Phasing is used in Ubuntu to slow down and control the roll out of

Bug#981370: CVE - critical security bug - Exploitable overflow in Libgcrypt 1.9.0

2021-01-29 Thread Patrick Schleizer
Package: libgcrypt20 Severity: important X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, Quote Werner Koch [1]: > We have to announce the availability of Libgcrypt version 1.9.1. This version fixes a *critical security bug* in the recently released version 1.9.0. If you are already

Bug#838416: alternative roughtime client

2021-01-29 Thread Patrick Schleizer
Dear Debian Developer, thank you for your consideration of packaging roughtime for Debian! Would an (alternative) roughtime client be more suitable, easier for packaging? I've created a simple list with information about roughtime including a roughtime client list. Will expand that list as

Bug#978642: (no subject)

2020-12-29 Thread Patrick Schleizer
Great, so we have this feature request for cryptsetup-initramfs side. Created a separate feature requests for Debian dracut side: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978644 Also reported against dracut upstream: https://github.com/dracutdevs/dracut/issues/997 Cheers, Patrick

Bug#978644: upstream feature request

2020-12-29 Thread Patrick Schleizer
Posted a feature request against upstream dracut just now: https://github.com/dracutdevs/dracut/issues/997

Bug#978644: Wipe LUKS Disk Encryption Key for Root Disk from RAM during Shutdown to defeat Cold Boot Attacks from Dracut Initramfs

2020-12-29 Thread Patrick Schleizer
Package: dracut-core Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, systemd does not wipe the LUKS disk encryption key for root disk from RAM during shutdown. Quote myself [0]: > Avoiding all sidelines, keeping this simple, for my understanding and for the record and

Bug#978642: Wipe LUKS Disk Encryption Key for Root Disk from RAM during Shutdown to defeat Cold Boot Attacks from Initial Ramdisk (initramfs-tools or dracut)

2020-12-29 Thread Patrick Schleizer
Package: cryptsetup Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, systemd does not wipe the LUKS disk encryption key for root disk from RAM during shutdown. Quote myself [0]: > Avoiding all sidelines, keeping this simple, for my understanding and for the record and

Bug#778357: (no subject)

2020-12-28 Thread Patrick Schleizer
Recently there has been some related activity here: https://github.com/Debian/apt/pull/124 https://salsa.debian.org/apt-team/apt/-/merge_requests/141

Bug#977758: org.chromium.Chromium broken in Debian buster

2020-12-20 Thread Patrick Schleizer
Package: flatpak Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, as already reported upstream, org.chromium.Chromium does not work out of the box in Debian buster. https://github.com/flathub/org.chromium.Chromium/issues/31 As the ticket mentions, sysctl

Bug#962311: VirtualBox Guest Additions ISO is Open Source

2020-09-07 Thread Patrick Schleizer
Asked about this on VirtualBox issue tracker. https://www.virtualbox.org/ticket/19751 Answered by arudnev, Oracle Corporation: > A part of Guest Additions source code is the part of OSE repository and > licensed under GPLv2. Guest Additions build also includes big list of 3rd > party files

Bug#962311: move virtualbox-guest-additions-iso from non-free to contrib

2020-06-05 Thread Patrick Schleizer
Package: virtualbox-guest-additions-iso Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, package virtualbox-guest-additions-iso is currently in Debian non-free repository. I believe this is might be a mistake. Copyright file [1] of the package is saying > Disclaimer:

Bug#961884: add init script / systemd unit for clamonacc background scanner

2020-05-30 Thread Patrick Schleizer
Package: clamav-daemon Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, package clamav-daemon ships a file /usr/bin/clamonacc which is a background virus scaning guard / real-time protection. It's currently non-trivial to use. sudo clamonacc ERROR: Clamonacc: at least

Bug#961827: please add openssl-rsync script for use of encrypted rsync over TLS

2020-05-29 Thread Patrick Schleizer
Package: rsync Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, could you please add the openssl-rsync script to the rsync package? To test: wget https://download.samba.org/pub/rsync/openssl-rsync chmod +x openssl-rsync rsync --rsh=./openssl-rsync --dry-run

Bug#956626: dhcpcanon systemd unit fails at boot due to missing debhelper apparmor integration

2020-04-13 Thread Patrick Schleizer
Package: dhcpcanon Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Debian buster dhcpcanon_0.8.5-2_all.deb debian/postinst lacks apparmor integration which should be auto added by debhelper. sudo aa-enforce /etc/apparmor.d/sbin.dhcpcanon ERROR: Include file

Bug#822693: stackable wrappers convention proposal

2020-02-29 Thread Patrick Schleizer
Could you please provide feedback for this stackable wrappers proposal? * https://github.com/Whonix/proposals/blob/master/634-stackable-wrappers.txt * https://phabricator.whonix.org/T634 Kind regards, Patrick

Bug#948975: vanguards is for Tor clients too; vanguards is not only for Tor onion services

2020-02-29 Thread Patrick Schleizer
> This is a deliberate choice that we have made, as there is no reason to use vanguards unless onion services are being hosted. I believe this is wrong. source: https://blog.torproject.org/announcing-vanguards-add-onion-services Quote: (Underline is mine.) "The add-on uses our Control Port

Bug#951331: merge HexChat AppArmor profile

2020-02-15 Thread Patrick Schleizer
Mattia Rizzolo: >> The profile is tested with HexChat. >> >> https://github.com/Whonix/apparmor-profile-xchat > > What would you think of properly integreting it into the upstream > package at https://github.com/hexchat/hexchat ? That would be better indeed but I was sent here. :)

Bug#951331: merge HexChat AppArmor profile

2020-02-14 Thread Patrick Schleizer
Package: hexchat Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, could you please review and merge the following AppArmor profile? Called "XChat" but the package name was just not renamed to "HexChat". The profile is tested with HexChat.

Bug#951315: linux-image-amd64 vs linux-headers-amd64 Debian buster-backports version mismatch bpo.2 vs bpo.3

2020-02-14 Thread Patrick Schleizer
Package: linux-image-amd64 Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, package linux-image-amd64 seems to have an outdated dependency. https://packages.debian.org/buster-backports/linux-image-amd64 shows dep: linux-image-5.4.0-0.bpo.2-amd64 (= 5.4.8-1~bpo10+1)

Bug#944476: stable security support

2020-02-13 Thread Patrick Schleizer
Talked to upstream about stable security support. To make Debian stable distribution support possible, upstream offered to backport security patches from newer versions to whatever version is frozen in Debian stable should that be required. Mariusz Zaborski osho...@vexillium.org would do that.

Bug#948975: enable vanguards systemd unit file by default

2020-01-15 Thread Patrick Schleizer
Package: vanguards Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, on Debian buster after "sudo apt install vanguards" it is not enabled by default. sudo systemctl status vanguards ● vanguards.service - Additional protections for Tor onion services Loaded: loaded

Bug#942873: (no subject)

2019-12-29 Thread Patrick Schleizer
Same issue. I've changed to building in a cowbuilder chroot to exclude host issues. Also excluded it being a full disk issue. kmk_builtin_append -n "/home/user/whonix_binary/temp_packages_virtualbox/virtualbox-6.1.0-dfsg/out/obj/UICommon/gen/qtrcc/VirtualBox2_x3.gen.o.dep" ""

Bug#947601: (no subject)

2019-12-28 Thread Patrick Schleizer
Would it make sense to add a git fasttrack branch to https://salsa.debian.org/pkg-virtualbox-team/virtualbox/ ?

Bug#947601: upload to Debian fasttrack

2019-12-28 Thread Patrick Schleizer
Package: virtualbox Severity: wishlist X-Debbugs-CC: lu...@debian.org Dear maintainer, please kindly consider Debian fasttrack: http://fasttrack.debian.net And coordinating with it: https://salsa.debian.org/fasttrack-team/support/issues/10 Thank you for maintaining VirtualBox in Debian!

Bug#935961: (no subject)

2019-12-06 Thread Patrick Schleizer
Some scripts that might help: - https://github.com/ivan-californias/vbox-sign-modules - https://github.com/Majal/maj-scripts/blob/master/vboxsign Or better a more generic solution of signing all DKMS modules: https://gist.github.com/dop3j0e/2a9e2dddca982c4f679552fc1ebb18df New versions of DKMS

Bug#945457: consider using hardened malloc (hardened memory allocator)

2019-11-25 Thread Patrick Schleizer
Package: glibc Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org https://github.com/GrapheneOS/hardened_malloc > RFP: hardened-malloc -- hardened memory allocator > * Package name: hardened-malloc > Version : 2.0 > Upstream Author : Daniel Micay > * URL :

Bug#945455: RFP: hardened-malloc -- hardened memory allocator

2019-11-24 Thread Patrick Schleizer
Package: wnpp Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org * Package name: hardened-malloc Version : 2.0 Upstream Author : Daniel Micay * URL : https://github.com/GrapheneOS/hardened_malloc * License : MIT Programming Lang: C Description :

Bug#944476: LKRG Debian packaging completed

2019-11-18 Thread Patrick Schleizer
Linux Kernel Runtime Guard (LKRG) protects the kernel. It provides security through diversity. Similar to running an uncommon operating system (kernel) would. It renders whole classes of kernel exploits ineffective. Makes other exploits less reliable and more difficult to write (see features and

Bug#944476: Linux Kernel Runtime Guard - LKRG

2019-11-10 Thread Patrick Schleizer
Package: wnpp Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org * Package name: lkrg Version : 0.7 Upstream Author : Adam 'pi3' Zabrocki * URL : https://www.openwall.com/lkrg/ * License : GPL-2 Programming Lang: C Description : Linux Kernel

Bug#942873: build failing on Debian buster at kmk_builtin_append out/obj/VBoxGlobal/qtrcc/VirtualBox2_x4.gen.cpp

2019-10-22 Thread Patrick Schleizer
Package: virtualbox Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org Fetched the source package from sid. Trying to compile on buster. kmk_builtin_append -n "/home/user/sourcesother/vbox/virtualbox-6.0.14-dfsg/out/obj/VBoxGlobal/gen/qtrcc/VirtualBox2_x4.gen.o.dep" ""

Bug#942303: Weak-Depends - something in the middle between 'Recommends:' and 'Depends:'

2019-10-14 Thread Patrick Schleizer
Package: dpkg Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org It would be useful if there was something in between of 'Recommends:' and 'Depends:'. “Weak-Depends” Similar to “Depends”. It lists packages that get installed when using 'apt --no-install-recommends meta-package', but any

Bug#940311: merge with lockdown / security-misc?

2019-09-21 Thread Patrick Schleizer
> I'm not sure what security-misc exactly is Inspired by Kernel Self Protection Project (KSPP) Implements most if not all recommended Linux kernel settings (sysctl) and kernel parameters by KSPP. https://kernsec.org/wiki/index.php/Kernel_Self_Protection_Project On top of that does other

Bug#940188: compatibility with grml-debootstrap, pbuilder and cowbuilder

2019-09-16 Thread Patrick Schleizer
Johannes Schauer: > 1. file wishlist bugs against the wrappers, asking them to allow passing > additional options to their $DEBOOTSTRAP invocation I guess this is the cleaner way and should be attempted first. That might also help to, - make programs that use of $DEBOOTSTRAP switch to use

Bug#940310: merge with lockdown / security-misc?

2019-09-15 Thread Patrick Schleizer
Package: lockdown Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org Let's join forces before we independently reinvent everything. :) * https://packages.debian.org/buster/lockdown * https://packages.debian.org/buster/hardening-runtime * https://github.com/Whonix/security-misc

Bug#940311: merge with lockdown / security-misc?

2019-09-15 Thread Patrick Schleizer
Package: hardening-runtime Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org We now have (at least) three very similar packages. * https://packages.debian.org/buster/lockdown * https://packages.debian.org/buster/hardening-runtime * https://github.com/Whonix/security-misc Let's join

Bug#940188: compatibility with grml-debootstrap, pbuilder and cowbuilder

2019-09-15 Thread Patrick Schleizer
Happy to report that both invocations of grml-debootstrap and pbuilder / cowbuilder are compatible with mmdebstrap. Johannes Schauer: > you seem to claim that mmdebstrap does not support the --arch argument. But it > does. It does so by configuring Getopt::Long with auto_abbrev. This means that >

Bug#940188: compatibility with grml-debootstrap, pbuilder and cowbuilder

2019-09-14 Thread Patrick Schleizer
Awesome! Great to know you're interested in this! Good question. I am not sure what I meant with that either. :) Will look into it again. First thing: debootstrap: --arch=ARCH mmdebstrap: --architectures=native[,foreign1,...] In other words, grml-debootstrap calls debootstrap

Bug#940188: compatibility with grml-debootstrap, pbuilder and cowbuilder

2019-09-13 Thread Patrick Schleizer
Package: mmdebstrap Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, could you please make mmdebstrap compatible with grml-debootstrap, pbuilder and cowbuilder? These applications support setting a custom debootstrap but mmdebstrap cannot yet serve as a drop-in

Bug#939188: feature requested upstream

2019-09-13 Thread Patrick Schleizer
https://savannah.gnu.org/bugs/index.php?56887

Bug#939188: grub-PC check_signatures=enforce support (non-EFI)

2019-09-01 Thread Patrick Schleizer
Package: grub2 Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org Could you please make it possible to do signature verification with grub-pc too? Rationale: We, the maintainers of Linux distributions that primarily run inside VMs (Whonix; Kicksecure) would like to implement verified

Bug#934457: installation in chroot failing with Unknown device "/dev/fuse": No such device

2019-08-29 Thread Patrick Schleizer
Thank you very much for looking into this! Does the following information help to make head or tail of this? Otherwise, I will provide better instruction for reproduction. László Böszörményi (GCS): > How did you create that Buster chroot? #!/bin/bash set -x set -e img=/home/user/test.img

Bug#934820: consider review and merge of linux-hardened patches (free, Libre alternative to grsecurity)

2019-08-15 Thread Patrick Schleizer
Package: linux Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, Could you please consider review and merge of linux-hardened patches (free, Libre alternative to grsecurity). https://github.com/anthraxx/linux-hardened Alternatively perhaps as a separate package. RFP:

Bug#934751: RFP: linux-hardened - hardened Linux kernel

2019-08-14 Thread Patrick Schleizer
Package: wnpp Severity: wishlist X-Debbugs-CC: debian-ker...@lists.debian.org * Package name: linux-hardened Version : 5.2 Upstream Author : linux-hardened * URL : https://github.com/anthraxx/linux-hardened * License : GPL-2 Programming Lang: C Description

Bug#934457: installation in chroot failing with Unknown device "/dev/fuse": No such device

2019-08-11 Thread Patrick Schleizer
Package: fuse Severity: grave X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, The following code from /var/lib/dpkg/info/fuse.postinst is failing. if [ -e /dev/fuse ] then udevadm test --action -p $(udevadm info -q path -n /dev/fuse) > /dev/null 2>&1 fi + [ -e /dev/fuse ] +

Bug#932552: (no subject)

2019-07-20 Thread Patrick Schleizer
Actually, not an mmdebstrap issue. My /etc/apt/apt.conf.d/99mmdebstrap contained: Dpkg::Options force-confnew; It should have been: Dpkg::Options --force-confnew; This caused the aptitude issue. So this is rather an aptitude issue of non-helpful error messages and not an mmdebstrap issue.

Bug#932552: [Whonix-devel] Bug#932552: empty /var/lib/dpkg/available causing pbuilder to fail

2019-07-20 Thread Patrick Schleizer
Would like to clarify this bug report. mmdebstrap currently creates a chroot which is incompatible with aptitude. [Creating follow-up issues with cowbuilder / pbuilder.] Actually the workaround "/usr/lib/dpkg/methods/apt/update /var/lib/dpkg apt apt" generates /var/lib/dpkg/available but is

Bug#932552: empty /var/lib/dpkg/available causing pbuilder to fail

2019-07-20 Thread Patrick Schleizer
Package: mmdebstrap Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, I am using mmdebstrap in combination with cowbuilder / pbuilder. Initially a chroot created using mmdebstrap comes with an empty file /var/lib/dpkg/available. This confuses aptitude which I wouldn't

Bug#931994: improve key strengthening, add rounds=65536 to /etc/pam.d/common-password

2019-07-13 Thread Patrick Schleizer
Package: libpam-runtime Severity: wishlist X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, could you please append 'rounds=65536' to 'password [success=1 default=ignore] pam_unix.so obscure sha512' in file /usr/share/pam/common-password ? In other words:

Bug#928546: replies by upstream util-linux and systemd

2019-05-07 Thread Patrick Schleizer
util-linux Karel Zak @karelzak replied: https://github.com/karelzak/util-linux/issues/790 > The libmount allows to read fstab stuff from directory, for example > > ``` > mount --fstab /etc/fstab.d/ > ``` > > but this feature is not enabled by default and it does not check for fstab.d/ by

Bug#928546: [feature request] /etc/fstab.d

2019-05-07 Thread Patrick Schleizer
Asked upstream about it. [feature request] /etc/fstab.d https://github.com/karelzak/util-linux/issues/790

Bug#927972: jitterentropy_rng.ko never loads

2019-04-30 Thread Patrick Schleizer
On https://www.whonix.org/pipermail/whonix-devel/2019-April/001371.html its developer wrote: > [...] > - the in-kernel crypto API has an RNG framework that provides a DRBG. This DRBG is used for in-kernel crypto API purposes. It may be accessed from user space via AF_ALG [2]. Yet, this is not

Bug#927974: jitterentropy_rng.ko never loads: jitternentropy-rngd doesn't complain

2019-04-30 Thread Patrick Schleizer
Luca Boccassi: > As far as I know, the kernel module and the userspace daemon are > separate and independent, and serve different purposes. > It's developer wrote about it here: https://www.whonix.org/pipermail/whonix-devel/2019-April/001371.html

Bug#927290: CoyIM in buster freeze up

2019-04-17 Thread Patrick Schleizer
Package: coyim Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, CoyIM freezes during account creation in Debian buster. More details were already submitted upstream but this might be a Debian only bug. https://github.com/coyim/coyim/issues/527 Kind regards, Patrick

Bug#926116: cross build failing - update-binfmts: warning: qemu-i386 not in database of installed binary formats.

2019-04-04 Thread Patrick Schleizer
No more issues since I upgraded to buster. mmdebstrap is awesome! Thank you! Cheers, Patrick

Bug#926116: cross build failing - update-binfmts: warning: qemu-i386 not in database of installed binary formats.

2019-03-31 Thread Patrick Schleizer
Package: mmdebstrap Severity: normal X-Debbugs-CC: whonix-de...@whonix.org Dear maintainer, # How to reproduce: sudo /home/user/whonix_dot/Whonix/help-steps/mmdebstrap --verbose --architectures=i386 stretch /var/cache/pbuilder/base.cow_i386

  1   2   >