Bug#632631: jwchat: strange and insecure file permission

2011-07-04 Thread Helmut Grohne
Package: jwchat Version: 1.0beta3-3 Severity: important Tags: security The postinst of jwchat has some strange ideas about file permission. 1) It assigns /etc/jwchat/config.js to www-data:www-data. The file is to be considered static configuration. I see no reason for why www-data should

Bug#641629: twinkle: reliably segfaults when accepting a call

2011-09-14 Thread Helmut Grohne
Package: twinkle Version: 1:1.4.2-2+b4 Severity: important Tags: security I can reproducably segfault twinkle by accepting a call. First of all I removed my ~/.twinkle. Then I did a wizard-setup for a standard sipgate.de account. I used another sipgate.de account with ekiga to call my account.

Bug#642049: gnucash: missing dependency on libgoffice-something

2011-09-18 Thread Helmut Grohne
Package: gnucash Version: 1:2.4.7-2 Severity: important Starting with version 1:2.4.7-2 gnucash dropped the dependency on libgoffice-0.8-8. Since no other package on my system depends on this library, it got removed during the upgrade. Even though I like having a smaller footprint this should not

Bug#643312: openssh-client: IPQoS option ignored for AF_INET since 5.9p1-1

2011-09-27 Thread Helmut Grohne
Package: openssh-client Version: 1:5.9p1-1 Severity: normal Since version 1:5.9p1-1 the IPQoS option is ignored for AF_INET sockets. Running ssh -F /dev/null -vvv -o IPQoS=lowdelay somehost true gives this. debug2: client_session2_setup: id 0 debug2: fd 3 setting TCP_NODELAY debug1: Sending

Bug#627669: linux-image-2.6.38-2-amd64: [brcm80211] oops on iwlist wlan0 scanning

2011-05-23 Thread Helmut Grohne
Package: linux-image-2.6.38-2-amd64 Version: 2.6.38-5 Severity: normal I do know that brcm80211 comes from the staging tree. Nevertheless I hereby document one of its problems. firmware-brcm80211 version is 0.29 # lspci -v -s 05:00.0 05:00.0 Network controller: Broadcom Corporation BCM4313

Bug#627669: linux-image-2.6.38-2-amd64: [brcm80211] oops on iwlist wlan0 scanning

2011-05-24 Thread Helmut Grohne
Hi Moritz, On Tue, May 24, 2011 at 06:46:58PM +0200, Moritz Mühlenhoff wrote: Please retest with 2.6.39-1 from unstable. I just did that while you wrote this mail and it at least no longer oopses on either iwlist wlan0 scanning or iwlist wlan0 essid something. Thanks for the work (or forward

Bug#634071: foxyproxy: extension is disabled with iceweasel 5.0 (sid)

2011-07-16 Thread Helmut Grohne
Package: foxyproxy Version: 2.22.6-1 Severity: grave Justification: renders package unusable After upgrading iceweasel the foxyproxy extension is disabled in iceweasel. Since most users of foxyproxy will be using this version of iceweasel soon it will affect most users and thus warrants severity

Bug#634075: iceweasel: please add breaks for xul-ext-firebug and foxyproxy

2011-07-16 Thread Helmut Grohne
Package: iceweasel Version: 5.0-3 Severity: wishlist Please add Breaks: xul-ext-firebugs ( 1.8.0~b5-1), foxyproxy (= 2.22.6-1) to the debian/control, because this version of iceweasel disables these extensions. For xul-ext-firebug the problem is fixed in experimental version 1.8.0~b5-1. I filed

Bug#635648: /usr/share/man/man8/monkeysphere-host.8.gz: http://web.monkeysphere.info/signing-host-keys/ is 404

2011-07-27 Thread Helmut Grohne
Package: monkeysphere Version: 0.35-2 Severity: normal File: /usr/share/man/man8/monkeysphere-host.8.gz The manual page for monkeysphere-host references http://web.monkeysphere.info/signing-host-keys/ in the PUBLISHING AND CERTIFYING MONKEYSPHERE SERVICE CERTIFICATES section. Unfortunately that

Bug#676717: dh_installcatalogs transition and w3c-dtd-xhtml removal bugs

2012-06-23 Thread Helmut Grohne
and postinst, to avoid warnings for +packages in rc state. + + -- Helmut Grohne hel...@subdivi.de Thu, 21 Jun 2012 16:09:07 +0200 + sgml-base (1.26+nmu3) unstable; urgency=low * Non-maintainer upload. diff -Nru sgml-base-1.26+nmu3/debian/sgml-base.postinst sgml-base-1.26+nmu4/debian/sgml

Bug#678468: RFS: sgml-data/2.0.7 [RC] [QA] -- common SGML and XML data

2012-06-23 Thread Helmut Grohne
On Fri, Jun 22, 2012 at 03:07:43AM +0300, Boris Pek wrote: I am looking for a sponsor for my package sgml-data. You say QA upload below, I guess you don't mean to adopt the package, right? Thanks for taking care of this package. This upload fixes at least one RC bug.

Bug#678468: RFS: sgml-data/2.0.7 [RC] [QA] -- common SGML and XML data

2012-06-23 Thread Helmut Grohne
On Sat, Jun 23, 2012 at 02:55:40PM +0300, Boris Pek wrote: * The description still contains the homepage. Hmm, is it a problem? I don't see nothing about it in the Debian Policy [1]. That lintian note was about missed homepage field which is possibly present in description. [1]

Bug#676717: dh_installcatalogs transition and w3c-dtd-xhtml removal bugs

2012-06-23 Thread Helmut Grohne
On Sat, Jun 23, 2012 at 10:29:29PM +0900, Osamu Aoki wrote: This is non-essential but I thought it may be good idea not to make postinst script robust. As it is written now, any non-zero exit code of update-catalog will break postinst script. This is somewhat intentional. If update-catalog

Bug#676717: dh_installcatalogs transition and w3c-dtd-xhtml removal bugs

2012-06-24 Thread Helmut Grohne
On Sun, Jun 24, 2012 at 02:22:06AM +0900, Osamu Aoki wrote: So you mean --quiet and error exit is good? I see. I still worry about being too quiet to hide source of the trouble. Do you think we need As far as I can see --quiet never hides error conditions. After all --quiet is not that

Bug#676653: tor: please add Multi-Arch: foreign to the tor package

2012-06-25 Thread Helmut Grohne
On Mon, Jun 25, 2012 at 12:46:16AM +0200, Carsten Hey wrote: weasel noted that tor-dbg exists and depends on tor. Since dpkg currently handles arch all packages as if they were native for dependency resolution [1], this leads to this situation: Oh right. Thanks for looking into the details

Bug#678902: catalog registration disappeared during upgrade

2012-06-27 Thread Helmut Grohne
reassign 678902 sgml-base found 678902 sgml-base/1.16+nmu2 retitle 678902 sgml-base needs to Pre-Depend on dpkg 1.16.4 thanks On Wed, Jun 27, 2012 at 12:15:45PM +0200, Mathieu Malaterre wrote: Helmut could you please comment on #678902 ? Thanks for bringing this to my attention. The most

Bug#676717: proposed sgml-base 1.16+nmu4 fixing #676717 and #678902

2012-06-27 Thread Helmut Grohne
processing. + + -- Helmut Grohne hel...@subdivi.de Thu, 21 Jun 2012 16:09:07 +0200 + sgml-base (1.26+nmu3) unstable; urgency=low * Non-maintainer upload. diff -Nru sgml-base-1.26+nmu3/debian/control sgml-base-1.26+nmu4/debian/control --- sgml-base-1.26+nmu3/debian/control 2012-05-28 13:58

Bug#676615: libsystemd-login0: please convert to Multi-Arch: same

2012-06-28 Thread Helmut Grohne
Hi Michael, On Thu, Jun 28, 2012 at 06:53:53AM +0200, Michael Biebl wrote: attached is a patch which converts the (library) packages to m-a:same Thanks for doing the multiarch work for systemd! Please review and apply. I was wondering why you converted the paths for libpam-systemd and

Bug#678902: proposed sgml-base 1.16+nmu4 fixing #676717 and #678902

2012-06-28 Thread Helmut Grohne
Dear dpkg maintainers, On Thu, Jun 28, 2012 at 02:05:56AM +0100, Ian Jackson wrote: I'm not convinced that a Pre-Depends is the best answer here. I think a better answer would be for the new dpkg to activate all file triggers when it first starts, and for sgml-base to simply use Depends.

Bug#680121: splint: the splint-internal definition for struct timespec has wrong members ts_* instead of tv_*

2012-07-03 Thread Helmut Grohne
Package: splint-data Version: 3.1.2.dfsg1-2 Severity: normal In /usr/share/splint/lib/unix.h there is this definition: | struct timespec { | long ts_sec; | long ts_nsec; | } ; The file is used when specifying +unixlib. In contrast man time.h (from package manpages-posix-dev) says that

Bug#544013: closed by Debian FTP Masters ftpmas...@ftp-master.debian.org (Bug#680362: Removed package(s) from unstable)

2012-07-05 Thread Helmut Grohne
found 544013 mysql-server-5.5/5.5.24+dfsg-4 thanks On Thu, Jul 05, 2012 at 03:57:36PM +, Debian Bug Tracking System wrote: #544013: mysql-server-5.1: logrotate script cannot handle stopped mysqld It has been closed by Debian FTP Masters ftpmas...@ftp-master.debian.org. Normally bugs

Bug#667023: 2.15 brings x32 support

2012-05-27 Thread Helmut Grohne
block 667023 by 672934 thanks x32 support has been merged into the 2.15 version of glibc. Since carrying x32 patches ourselves seems like a useless waste of time, I mark the x32 bug as being blocked by the new upstream version. Helmut -- To UNSUBSCRIBE, email to

Bug#674898: sgml-base: diff for NMU version 1.26+nmu2

2012-05-28 Thread Helmut Grohne
changes will solve +that bug based on this work. + * Do not truncate the manual pages during build. + + -- Helmut Grohne hel...@subdivi.de Mon, 30 Apr 2012 17:15:48 +0200 + sgml-base (1.26+nmu1) unstable; urgency=low * Non-maintainer upload diff -Nru sgml-base-1.26+nmu1/debian/control

Bug#477751: tackling this bug

2012-05-28 Thread Helmut Grohne
Hi Joey, sgml-base 1.26+nmu2 has been accepted in sid. Can you go ahead and upload debhelper? I talked to the release team and will take care of the binnmus. Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#674911: xml2rfc: do not call update-catalog

2012-05-28 Thread Helmut Grohne
Package: xml2rfc Version: 1.36-2 Severity: important Your package manually calls update-catalog. Due to an RC bug on sgml-base the interface has radically changed and you should no longer call update-catalog but instead rely on a dpkg-trigger. If you were using dh_installcatalogs this would

Bug#674913: sgml-data: do not call update-catalog

2012-05-28 Thread Helmut Grohne
Package: sgml-data Version: 2.0.6 Severity: important Your package calls update-catalog on /etc/sgml/$PACKAGE.cat. The latter file will transition to a conffile, so changing that file induces questions to the user. Please remove the old and no longer needed call to update-catalog. Helmut --

Bug#674914: sgmltools-lite: do not call update-catalog

2012-05-28 Thread Helmut Grohne
Package: sgmltools-lite Version: 3.0.3.0.cvs.20010909-15.1 Severity: important Your postinst calls update-catalog --remove --super. These calls are deprecated, because /etc/sgml/$PACKAGE.cat is turned into a dpkg-triggered conffile. Please remove the no longer needed update-catalog call. Helmut

Bug#674898: sgml-base: diff for NMU version 1.26+nmu2

2012-05-28 Thread Helmut Grohne
+0200 +++ sgml-base-1.26+nmu3/debian/changelog2012-05-28 20:55:04.0 +0200 @@ -1,3 +1,10 @@ +sgml-base (1.26+nmu3) unstable; urgency=low + + * Non-maintainer upload. + * -- may not appear in comments. (Closes: #674933) + + -- Helmut Grohne hel...@subdivi.de Mon, 28 May 2012 20:51:56

Bug#649275: unreproducible

2012-05-29 Thread Helmut Grohne
I fail to reproduce the issue using linux 3.4 and xorg and nouveau from sid. Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#675320: libevent-2.0-5: please convert libevent-2.0-5 to multiarch

2012-05-31 Thread Helmut Grohne
Package: libevent-2.0-5 Version: 2.0.19-stable-2 Severity: important The package libevent-2.0-5 is a good candidate for multiarch conversion, because it has a number of different reverse dependencies. So after moving libraries to /usr/lib/triplet it should be possible to mark libevent-2.0-5 as

Bug#550479: libgnome2-0: The library depends on a daemon?!

2012-05-31 Thread Helmut Grohne
Package: libgnome2-0 Followup-For: Bug #550479 Josselin Mouette wrote: Some functions, like gnome_url_show, do not work at all without gvfs installed. That may be true, but not every application needs this functionality. In addition it gets worse, because gvfs pulls in udisks. Can you explain

Bug#675323: libmnl0: uninstallable due to typo in pre-depends

2012-05-31 Thread Helmut Grohne
Package: libmnl0 Version: 1.0.3-2 Severity: grave Justification: renders package unusable Please have a look at debian/control: Package: libmnl0 ... Pre-Depends: i${misc:Pre-Depends}, multiarch-support This results in: Pre-Depends: imultiarch-support, multiarch-support Since there is no

Bug#675324: libmnl0: please convert to multiarch

2012-05-31 Thread Helmut Grohne
Package: libmnl0 Version: 1.0.3-2 Severity: important Your package is the only dependency of libipset2 which is not Multi-Arch: same. This renders the multi arch support of libipset2 useless. Severity important, since this is a release goal. Helmut -- To UNSUBSCRIBE, email to

Bug#675613: debiandoc-sgml: Does not register itself in /etc/sgml/catalog

2012-06-02 Thread Helmut Grohne
reassign 675613 dpkg affects 675613 + debiandoc-sgml docbook docbook-dsssl docbook-ebnf docbook-html-forms docbook-mathml docbook-simple docbook-slides docbook-website docbook-xml dtd-ead libcommons-validator-java python-docutils sgml-data sgml2x w3c-dtd-xhtml xml-core thanks Hi Osamu, Thanks

Bug#675613: debiandoc-sgml: Does not register itself in /etc/sgml/catalog

2012-06-03 Thread Helmut Grohne
Hi Guillem, Thanks for your quick and helpful response. On Sat, Jun 02, 2012 at 11:55:48PM +0200, Guillem Jover wrote: So on first thought, I think the solution would be to make dpkg activate file triggers for the parent directories on configure so that this case is handled correctly. In fact

Bug#675767: src:libav: check CVE-2011-4031 (integer underflow in asfrtp_parse_packet)

2012-06-03 Thread Helmut Grohne
Package: src:libav Version: 6:0.8.2-2 Severity: important Tags: security Dear multimedia maintainers, Please determine whether libav is affected by CVE-2011-4031: | Integer underflow in the asfrtp_parse_packet function in | libavformat/rtpdec_asf.c in FFmpeg before 0.8.3 allows remote attackers

Bug#675909: liblqr-1-0: please convert to multiarch

2012-06-04 Thread Helmut Grohne
Package: liblqr-1-0 Version: 0.4.1-1.1 Severity: important The liblqr-1-0 package currently does not have any multiarch tagging. It is the only package left that blocks libmagickwand5 from exercising full multiarch capabilities. Since the package only contains a single shared library it seems

Bug#674911: xml2rfc: do not call update-catalog

2012-06-15 Thread Helmut Grohne
to debhelper 9. + * Especially use dh_installcatalogs. (Closes: #674911, #656170) + + -- Helmut Grohne hel...@subdivi.de Fri, 15 Jun 2012 16:53:42 +0200 + xml2rfc (1.36-2) unstable; urgency=low * added postrm script to purge /etc/sgml/xml2rfc.cat{,.old} diff -Nru xml2rfc-1.36/debian/compat xml2rfc

Bug#678127: should sgml-base be orphaned?

2012-06-19 Thread Helmut Grohne
Package: sgml-base Version: 1.26 Severity: important User: debian...@lists.debian.org Usertags: proposed-orphan Dear maintainers of sgml-base, The sgml-base package hasn't seen a maintainer upload for six years (put into perspective: two stable releases) despite having a RC bug. Clearly the

Bug#676717: dh_installcatalogs transition and w3c-dtd-xhtml removal bugs

2012-06-19 Thread Helmut Grohne
Pulled in Joey Hess since we might need further changes to debhelper. On Tue, Jun 19, 2012 at 11:20:46PM +0900, Osamu Aoki wrote: === bug 477751 : dh_installcatalogs transition with removed package == Helmut, The closure of dh_installcatalogs bug initiated by the

Bug#676717: dh_installcatalogs transition and w3c-dtd-xhtml removal bugs

2012-06-20 Thread Helmut Grohne
Hi Norbert, Thanks for your thoughts. Pulling in Daniel Leidert as he seems to be the most active sgml related maintainer. On Wed, Jun 20, 2012 at 08:30:25AM +0900, Norbert Preining wrote: * I checked the update-catalogue script, and it simply interates over all .cat files in /etc/sgml.

Bug#678127: should sgml-base be orphaned?

2012-06-21 Thread Helmut Grohne
Hi Daniel, Thanks for speaking up here. On Tue, Jun 19, 2012 at 10:33:18PM +0200, Daniel Leidert wrote: Am Dienstag, den 19.06.2012, 13:50 +0200 schrieb Helmut Grohne: The sgml-base package hasn't seen a maintainer upload for six years (put into perspective: two stable releases) despite

Bug#674911: xml2rfc: do not call update-catalog

2012-06-21 Thread Helmut Grohne
Hi Daniel, On Fri, Jun 15, 2012 at 06:10:02PM +0200, Helmut Grohne wrote: Please review my changes. Can I also ask you to upload them? I updated the .debdiff with some remarks from Jakub Wilk. In the absence of any further response from you I will seek a sponsor to NMU this. Helmut diff -Nru

Bug#676717: dh_installcatalogs transition and w3c-dtd-xhtml removal bugs

2012-06-21 Thread Helmut Grohne
+0200 @@ -1,3 +1,12 @@ +sgml-base (1.26+nmu4) experimental; urgency=low + + * Non-maintainer upload. + * update-catalog --update-super ignores catalogs referencing non-existent +files. (Closes: #676717) + * Remove warning about rebuilding packages as it may confuse users. + + -- Helmut Grohne

Bug#679889: mpd: MPD 0.17 + MAD decoder = noise only with MP3s

2012-07-14 Thread Helmut Grohne
Package: mpd Version: 0.17.1 Followup-For: Bug #679889 Unfortunately I can reproduce this bug in all detail. I suggest to mark this bug release critical, because it renders the package unusable for some users. Here is the log output produced during mpc play: Jul 14 11:39 : client: [1] process

Bug#679889: [Pkg-mpd-maintainers] Bug#679889: mpd: MPD 0.17 + MAD decoder = noise only with MP3s

2012-07-16 Thread Helmut Grohne
Control: severity 679889 serious On Sat, Jul 14, 2012 at 10:24:36PM +0200, Alexander Wirt wrote: On Sat, 14 Jul 2012, Max Kellermann wrote: This is caused by a bug in the software volume code. Fix is in the MPD git repository:

Bug#681814: libprophet-perl: do not mess with $LESS (or make it optional)

2012-07-16 Thread Helmut Grohne
Package: libprophet-perl Version: 0.743-1 Severity: minor I noticed that less behaves strangely when invoked from sd. This is due to it using libprophet-perl's start_pager which sets LESS=-FXe and thereby overwrites my own $LESS configuration. I appreciate that you care about sane defaults, but

Bug#681815: sd server completely broken due to strict refs usage

2012-07-16 Thread Helmut Grohne
Package: sd Version: 0.74-1 Severity: important $ sd server --port 8800 Prototype mismatch: sub Prophet::Server::View::nav (;$) vs none at /usr/share/perl5/Prophet/Server/View.pm line 49. Subroutine nav redefined at /usr/share/perl5/Prophet/Server/View.pm line 45. Publisher backend is not

Bug#477751: tackling this bug

2012-04-26 Thread Helmut Grohne
On Thu, Apr 26, 2012 at 01:57:33PM -0400, Joey Hess wrote: While I'm leaning toward just putting the code in debhelper, I am worried about another issue in the patch. It makes update-catalog be called only on new install, not upgrade ([-z $2]). But then, if a catalog is added to an existing

Bug#477751: tackling this bug

2012-04-27 Thread Helmut Grohne
On Thu, Apr 26, 2012 at 06:18:40PM -0400, Joey Hess wrote: This is why I originally recommended that the registration process be converted to use triggers. A [directory full] of catalogs, and a root catalog file automatically generated from them (which need not be a config file in /etc) is a

Bug#668778: 668778 qmailscan CVE?

2012-04-28 Thread Helmut Grohne
CCing bug report, because others might be interested as well. This issue is also known as CVE-2012-2103. See https://bugzilla.redhat.com/show_bug.cgi?id=812889 for details. Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble?

Bug#477751: tackling this bug

2012-04-30 Thread Helmut Grohne
catalog from /etc/sgml directory contents. +This does not solve #477751, but the upcoming debhelper changes will solve +that bug based on this work. + * Do not truncate the manual pages during build. + + -- Helmut Grohne hel...@subdivi.de Mon, 30 Apr 2012 17:15:48 +0200 + sgml-base (1.26+nmu1

Bug#477751: tackling this bug

2012-04-30 Thread Helmut Grohne
On Mon, Apr 30, 2012 at 12:24:52PM -0400, Joey Hess wrote: Helmut Grohne wrote: On the debhelper side it should be enough to remove all remaining calls to update-catalog and introduce a dependency on the changed sgml-base. I did not test this thus far. Won't dh_installcatalogs also need

Bug#671727: CVE-2012-2396: divide-by-zero on crafted mp4 file

2012-05-06 Thread Helmut Grohne
Package: src:vlc Version: 2.0.1-4 Severity: important Tags: security Dear VLC maintainers, Please check which versions of vlc (if any) are affected by CVE-2012-2396[1]. The description is: | VideoLAN VLC media player 2.0.1 allows remote attackers to cause a | denial of service (divide-by-zero

Bug#554387: traceback

2012-05-07 Thread Helmut Grohne
I got a core file for this segfault running 0.9.2. (gdb) bt full #0 *__GI___libc_free (mem=0x24a1db0) at malloc.c:3709 ar_ptr = optimized out p = optimized out #1 0x7ffd666f31ea in inflateEnd () from /usr/lib/x86_64-linux-gnu/libz.so.1 No symbol table info available. #2

Bug#644591: breaks agda-stdlib too

2011-10-18 Thread Helmut Grohne
affects 644591 + agda-stdlib thanks $ ghci -package Agda GHCi, version 7.0.4: http://www.haskell.org/ghc/ :? for help Loading package ghc-prim ... linking ... done. Loading package integer-gmp ... linking ... done. Loading package base ... linking ... done. Loading package

Bug#646674: calibre: please install manual pages in a way man can find

2011-10-25 Thread Helmut Grohne
Package: calibre Version: 0.8.21+dfsg-1 Severity: normal I would like to read manual pages for calibre without specifying their full path. $ man web2disk No manual entry for web2disk See 'man 7 undocumented' for help when manual pages are not available. $ dpkg -L calibre | grep man.*web2disk

Bug#647556: acpid: please include systemd .service and .socket files

2011-11-03 Thread Helmut Grohne
Package: acpid Version: 1:2.0.11-1 Severity: wishlist Tags: patch Please support systemd in acpid. Thankfully upstream has already added basic support. Quoting man 8 acpid: | For faster startup, this socket can be passed in as stdin so that | acpid need not create the socket. In addition, if a

Bug#687620: RFS: udpxy/1.0.23-1 [ITP]

2012-10-25 Thread Helmut Grohne
On Fri, Sep 14, 2012 at 09:22:46PM +1100, Alex 'AdUser' Z wrote: WNPP request are here : http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=687543 Package uploaded just now : https://mentors.debian.net/package/udpxy So I had a look at your package version 1.0.23-1 as found on

Bug#691562: tcp port conflict in default configuration of approx and kgb-bot

2012-10-27 Thread Helmut Grohne
Package: approx kgb-bot Severity: normal Both packages use tcp port by default. This is a conflict. Please resolve. Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#691562: tcp port conflict in default configuration of approx and kgb-bot

2012-10-27 Thread Helmut Grohne
On Sat, Oct 27, 2012 at 08:15:21AM -0400, Eric Cooper wrote: On Sat, Oct 27, 2012 at 11:08:23AM +0200, Helmut Grohne wrote: Both packages use tcp port by default. This is a conflict. Please resolve. Is this really a problem? I suspect both packages' users would mainly

Bug#689917: new upstream version: 0.7.1

2012-10-28 Thread Helmut Grohne
Control: retitle -1 New upstream version: 0.7.1 http://bitcoin.org/releases/2012/10/19/v0.7.1.html This is a minor bug-fix release. My best guess would be that #688813 (grave) is addressed this new upstream version. What is blocking the new release? As far as I can see bitcoind will not be part

Bug#632438: popcon wrongly claims to be anonymous

2012-10-29 Thread Helmut Grohne
I think the problem is worse than Paul Wise outlines. The package description claims anonymity. This is only true if it cannot be trivially defeated. The common use case for equivs is to create a package based on the hostname. Gladly popcon gives us numbers[1]. So about 8% of the submitters are

Bug#692035: CVE-2012-3155: vulnerability in the CORBA ORB component

2012-11-01 Thread Helmut Grohne
Package: src:glassfish Version: 1:2.1.1-b31g-3 Severity: serious Tags: security Dear glassfish maintainers, Please determine whether and how glassfish as present in Debian is affected by CVE-2012-3155. Please adjust the severity of this bug accordingly. | Unspecified vulnerability in the CORBA

Bug#692229: denyhosts: bad default SSHD_FORMAT_REGEX truncates messages

2012-11-03 Thread Helmut Grohne
Package: denyhosts Version: 2.6-10 Severity: important Tags: security The default for SSHD_FORMAT_REGEX is the following regex. .* (sshd.*:|\[sshd\]) (?Pmessage.*) On Debian systems the first alternative will be preferred, because all log lines contain colons. So let us apply this regex to the

Bug#630581: fix for #682964 is incomplete, maybe related to #630581

2012-11-07 Thread Helmut Grohne
reopen 630581 found 630581 dropbear/2012.55-1.2 severity 630581 grave thanks Justification for grave: A system upgraded from squeeze to wheezy is unbootable. So let me give more insight into this after being bitten by the issue. The initial issue #630581 was libnss_something being missing from

Bug#682964: fix for #682964 is incomplete, maybe related to #630581

2012-11-08 Thread Helmut Grohne
So I had a further look into the dropbear initramfs issue. The code where the breakage occurs is dropbear's hook: | LIBC_DIR=$(ldd /usr/sbin/dropbear | sed -n -e 's,.* = \(/lib.*\)/libc\.so\..*,\1,p') | for so in $(find ${LIBC_DIR} -name 'libnss_compat*'); do | copy_exec ${so} ${LIBC_DIR}

Bug#630581: fix for #682964 is incomplete, maybe related to #630581

2012-11-08 Thread Helmut Grohne
On Thu, Nov 08, 2012 at 11:03:20AM +0100, Jérémy Bobbio wrote: Do you confirm that leaving out the second parameter creates a correct initramfs when libc6-i686 is installed? Using pbuilder and a plain sid i386 chroot I verified the following: 1) With libc6-i686 installed the nss_compat files do

Bug#630581: fix for #682964 is incomplete, maybe related to #630581

2012-11-08 Thread Helmut Grohne
On Thu, Nov 08, 2012 at 12:23:37PM +0100, Jérémy Bobbio wrote: Just to make it clear, your workaround and removing the second parameter both result in having libnss_compat in `/lib/i686/cmov`? Thanks for your attention to detail. My workaround used the non-i686 versions of those files. The

Bug#690143: RFP: accel-pptp -- kernel accelerated pptp and l2tp implementation

2012-10-10 Thread Helmut Grohne
Package: wnpp Severity: wishlist * Package name: accel-pptp Version : 0.8.3 Upstream Author : Dmitry Kozlov x...@mail.ru * URL : http://accel-pptp.sf.net/ * License : GPL-2+ Programming Lang: C Description : kernel accelerated pptp and l2tp

Bug#680291: patch for xml2rfc #680291

2012-10-14 Thread Helmut Grohne
+0200 @@ -1,3 +1,11 @@ +xml2rfc (1.36-4.1) UNRELEASED; urgency=low + + * Non-maintainer upload. + * Always remove /etc/sgml/xml2rfc.cat when it is not a conffile. +(Closes: #680291) + + -- Helmut Grohne hel...@subdivi.de Sun, 14 Oct 2012 21:11:45 +0200 + xml2rfc (1.36-4) unstable; urgency=low

Bug#690524: denyhosts: fails to block hosts when PasswordAuthentication no

2012-10-15 Thread Helmut Grohne
Package: denyhosts Version: 2.6-10 Severity: normal I observed that denyhosts repeatedly fails to block abusers on one of my systems. Basically the reason is that I use denyhosts even though PasswordAuthentication is disabled in ssh. For this reason there are no failed login entries in my

Bug#690528: unblock: xml2rfc/1.36-5

2012-10-15 Thread Helmut Grohne
; urgency=low + + [ Helmut Grohne ] + * Always remove /etc/sgml/xml2rfc.cat when it is not a conffile. +(Closes: #680291) + + -- Daniel Kahn Gillmor d...@fifthhorseman.net Sun, 14 Oct 2012 19:30:24 -0400 + xml2rfc (1.36-4) unstable; urgency=low * Bump Standards-Version to 3.9.3 (no changes

Bug#690689: /usr/share/man/man1/evince.1.gz: man page contains duplicate description of -p, should be -i

2012-10-16 Thread Helmut Grohne
Package: evince-common Version: 3.4.0-3 Severity: minor File: /usr/share/man/man1/evince.1.gz The following is an excerpt of man 1 evince: | -p, --page-label=PAGE |Open the document on the page with the specified page label (or page number). | | -p, --page-index=NUMBER |Open the

Bug#691025: tt-rss: strange javascript error after login

2012-10-20 Thread Helmut Grohne
Package: tt-rss Version: 1.5.11+dfsg2-1 Severity: normal After logging in using chromium I receive a Loading, please wait... and then an alert window with the following content: Exception: TypeError: Object function (_37d,_37e){var _37f=on(_37d,keydown,function(evt){var k=evt.keyCode;var

Bug#691025: tt-rss: strange javascript error after login

2012-10-20 Thread Helmut Grohne
Thanks for your quick response. On Sat, Oct 20, 2012 at 08:34:57PM +0200, Sebastian Reichel wrote: You should check if the PHP option display_errors is disabled for TT-RSS: That is indeed the case and it is also the default for php. # grep ^display_errors -r /etc/php5/

Bug#691025: tt-rss: strange javascript error after login

2012-10-21 Thread Helmut Grohne
On Sun, Oct 21, 2012 at 09:42:06AM +0200, Sebastian Reichel wrote: I tried to find out more about your problem. It seems dojo 1.7.x does not work together with prototype 1.7. The upstream bug for this can be found at [0]. I still use libjs-prototype 1.6.1-1 on my test instance, but I will try

Bug#682648: status of the python-gnupg ftbfs

2012-10-22 Thread Helmut Grohne
+ + * Non-maintainer upload. + * Work around test suite hangs by adding --quick-random when generating +keys. Closes: #682648 + + -- Helmut Grohne hel...@subdivi.de Mon, 22 Oct 2012 23:30:19 +0200 + python-gnupg (0.3.0-1) unstable; urgency=low * New upstream release diff -Nru python-gnupg

Bug#691222: unblock: python-gnupg/0.3.0-1.1

2012-10-23 Thread Helmut Grohne
generating +keys. Closes: #682648 + + -- Helmut Grohne hel...@subdivi.de Mon, 22 Oct 2012 23:30:19 +0200 + python-gnupg (0.3.0-1) unstable; urgency=low * New upstream release diff -Nru python-gnupg-0.3.0/debian/rules python-gnupg-0.3.0/debian/rules --- python-gnupg-0.3.0/debian/rules

Bug#691250: [debdiff] support source format 3.0 containing executables and symbolic links in debian/

2012-10-23 Thread Helmut Grohne
Package: devscripts Version: 2.12.4 Severity: wishlist File: /usr/bin/debdiff With the introduction of the 3.0 source format the debian directory may be shipped as a .debian.tar.gz. This allows adding executable scripts and symbolic links to the debian directory. See dh-exec for a use case.

Bug#691315: libquvi-scripts: please support German television (ARD, ZDF)

2012-10-24 Thread Helmut Grohne
Package: libquvi-scripts Version: 0.4.8-3 Severity: wishlist Please support the German television services ARD and ZDF. For starters I attached some ideas on how to do that. The attached webscripts are still incomplete: 1) They only provide the best quality stream even though there are

Bug#691341: git-annex: please support git annex get from read-only media

2012-10-24 Thread Helmut Grohne
Package: git-annex Version: 3.20121017 Severity: wishlist I tried to fetch a file from a read-only file system. This resulted in the following output. $ git annex get somefile get somefile (from someremote...) Unable to access these remotes: someremote Try making some of these repositories

Bug#674898: sgml-base: diff for NMU version 1.26+nmu2

2012-10-24 Thread Helmut Grohne
= 1.16.4 (Closes: #678902). Removed dependency on +dpkg = 1.14.18. sgml-base highlights a bug in dpkg's trigger processing. + + -- Helmut Grohne hel...@subdivi.de Thu, 21 Jun 2012 16:09:07 +0200 + sgml-base (1.26+nmu3) unstable; urgency=low * Non-maintainer upload. diff -Nru sgml-base-1.26

Bug#648616: gitosis: breaks post-update hook during upgrade lenny - squeeze

2011-11-13 Thread Helmut Grohne
Package: gitosis Version: 0.2+20090917-11 Severity: important Tags: security After upgrading a system from lenny to squeeze the post-update hook is a dangling symbolic link: # readlink ~gitosis/repositories/gitosis-admin.git/hooks/post-update

Bug#678902: +nmu4 isn't final

2012-08-27 Thread Helmut Grohne
+nmu5) unstable; urgency=low + + * Non-maintainer upload. + * Raise perl dependency to avoid upgrade failures from squeeze. The way we +use readdir does not work on squeeze. +http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=678902#62 + + -- Helmut Grohne hel...@subdivi.de Mon, 27 Aug 2012 21

Bug#683061: [pkg-ntp-maintainers] Bug#683061: ntp: diff for NMU version 1:4.2.6.p5+dfsg-2.1

2012-08-28 Thread Helmut Grohne
Control: severity 683061 serious First of all something clearly is broken. The immediately visible symptom is that ntp does not synchronize time at all. If you believe that ntp is not the cause, then the course to take is not to downgrade the severity, but to ask for further information or

Bug#686062: approx-gc clears entire cache

2012-08-28 Thread Helmut Grohne
Package: approx Version: 5.2-1 Severity: important Running approx-gc clears the entire pool hierarchy on my system. It seems very unlikely that this holds for every system, so are likely some preconditions. I guess that the causing precondition is that there are no package lists in the dists

Bug#683061: [pkg-ntp-maintainers] Bug#683061: ntp: diff for NMU version 1:4.2.6.p5+dfsg-2.1

2012-08-28 Thread Helmut Grohne
On Tue, Aug 28, 2012 at 09:22:41AM +0200, Kurt Roeckx wrote: There are existing bugs to relevant software already about how they misbehave where I know about it. Please add affects indications to those bugs, to make it easier to catch duplicates. Not responding is fine, responding with a

Bug#683061: [pkg-ntp-maintainers] Bug#683061: ntp: diff for NMU version 1:4.2.6.p5+dfsg-2.1

2012-08-29 Thread Helmut Grohne
Control: tags 683061 + moreinfo Hi Kurt, On Tue, Aug 28, 2012 at 06:37:41PM +0200, Kurt Roeckx wrote: I'm using bind9 with resolvconf on my laptop without issues. so I don't think it's related to resolvconf. There is one noticeable difference between bind9 and unbound. The alphabetical

Bug#680291: xml2rfc: fails to install, remove, distupgrade, and install again

2012-08-29 Thread Helmut Grohne
Control: block 680291 by 681194 Hi Emanuele, Thank you very much for notifying me of this issue. Also sorry for not having answered earlier. On Mon, Aug 13, 2012 at 11:52:30AM +0200, Emanuele Rocca wrote: This seems to be related to the changes introduced to dh_installcatalogs (see #477751).

Bug#686236: isc-dhcp-client: please support a policy-compliant method for other packages to request additional dhcp options

2012-08-30 Thread Helmut Grohne
Package: isc-dhcp-client Version: 4.2.2.dfsg.1-5 Severity: wishlist Control: block 611438 by -1 As can be seen in #611438 for example there is a desire for other packages to request additional options. Once dhclient requests them they are easily processed, because dhclient provides a directory

Bug#681194: PING debhelper #681194

2012-08-30 Thread Helmut Grohne
Hi Joey, According to the release team (Julien Cristau on IRC), bug #681194 must be fixed in time for wheezy. I attached a patch[1] almost a month ago. Please do one of the following: 1) Upload a new version of debhelper including my patch. 2) Give me a reason for not including that particular

Bug#682869: munin: insecure/misleading apache configuration (authentication bypass)

2012-07-26 Thread Helmut Grohne
Package: munin Version: 2.0.2-1 Severity: grave Tags: security Justification: user security hole The default apache configuration shipped and automatically enabled by munin is insecure, because it includes an authentication bypass. The config intends to restrict access to the graphs to localhost:

Bug#683061: ntp: missing init script dependency on $named

2012-07-28 Thread Helmut Grohne
Package: ntp Version: 1:4.2.6.p2+dfsg-1+b1 Severity: serious Justification: dependency based boot release goal User: initscripts-ng-de...@lists.alioth.debian.org Usertags: missing-dependency I was trying to run ntp with unbound and noticed that in /etc/rc2.d they are linked as S02ntp and

Bug#683064: munin-cgi-graph regression: does not cache any graph

2012-07-28 Thread Helmut Grohne
Package: munin Version: 2.0.1-1 Severity: important I guess this change was introduced to fix one of the many security issues I reported. The problem in /usr/lib/cgi-bin/munin-cgi-graph is the following lines: | # Having some QUERY_STRING disables the cache. | if

Bug#683112: munin: default apache.conf includes outdated references to mod_fastcgi

2012-07-28 Thread Helmut Grohne
Package: munin Version: 2.0.2-1 Severity: normal Debian attempts to ship a nice default configuration for apache which is great. However these defaults target ancient apache versions and are no longer useful. Instead they may mislead users who assume that things would just work. | # Enables

Bug#683145: /usr/bin/git-bug: git-bug: not documented at all

2012-07-29 Thread Helmut Grohne
Package: git-extras Version: 1.7.0-1 Severity: important File: /usr/bin/git-bug $ man git-bug No manual entry for git-bug See 'man 7 undocumented' for help when manual pages are not available. $ git-bug --help $ echo $? 0 $ git branch * bug/--help master $ This behaviour violates a should in

Bug#573329: unbound: please include scripts from contrib/

2012-07-30 Thread Helmut Grohne
Package: unbound Followup-For: Bug #573329 Please install contrib/unbound_munin_ to /usr/share/munin/plugins/unbound_munin_. Optionally add Enhances: munin-node to debian/control. Thanks Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of

Bug#681194: dh_installcatalogs: catalog is now a conffile prompt if the old (pre-conffile) package was removed, but not purged

2012-08-02 Thread Helmut Grohne
+ * Preserve old sgml catalogs as .old files to a void data loss. + + -- Helmut Grohne hel...@subdivi.de Thu, 02 Aug 2012 21:55:41 +0200 + debhelper (9.20120608) unstable; urgency=low * dh: When there's an -indep override target without -arch, or vice versa,

Bug#683817: /usr/share/doc/texmf/pgf/pgfmanual.pdf.gz: texdoc pgfmanual.pdf.gz - Sorry, no documentation found

2012-08-04 Thread Helmut Grohne
Package: pgf Version: 2.10-1 Severity: important File: /usr/share/doc/texmf/pgf/pgfmanual.pdf.gz X-Debbugs-CC: Debian TeX Maintainers debian-tex-ma...@lists.debian.org Dear pgf and texlive-base maintainers, I observe the following behaviour: $ grep texdoc pgf /usr/share/doc/pgf/README.Debian

<    1   2   3   4   5   6   7   8   9   10   >