Bug#678902: the patch is there

2012-08-04 Thread Helmut Grohne
tags 678902 + patch thanks http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=678902#33 Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#675462: duplicate of #676717

2012-08-04 Thread Helmut Grohne
forcemerge 676717 675462 thanks Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#683844: RFS: sgml-base/1.26+nmu4

2012-08-04 Thread Helmut Grohne
on dpkg = 1.16.4 (Closes: #678902). Removed dependency on +dpkg = 1.14.18. sgml-base highlights a bug in dpkg's trigger processing. + + -- Helmut Grohne hel...@subdivi.de Thu, 21 Jun 2012 16:09:07 +0200 + sgml-base (1.26+nmu3) unstable; urgency=low * Non-maintainer upload. diff -Nru sgml

Bug#683847: unblock: sgml-base/1.26+nmu4

2012-08-04 Thread Helmut Grohne
trigger processing. + + -- Helmut Grohne hel...@subdivi.de Thu, 21 Jun 2012 16:09:07 +0200 + sgml-base (1.26+nmu3) unstable; urgency=low * Non-maintainer upload. diff -Nru sgml-base-1.26+nmu3/debian/control sgml-base-1.26+nmu4/debian/control --- sgml-base-1.26+nmu3/debian/control 2012-05-28

Bug#683817: /usr/share/doc/texmf/pgf/pgfmanual.pdf.gz: texdoc pgfmanual.pdf.gz - Sorry, no documentation found

2012-08-05 Thread Helmut Grohne
Control: severity 683817 normal Hi Norbert, Thanks for your quick and insightful response. On Sun, Aug 05, 2012 at 10:32:52PM +0900, Norbert Preining wrote: On Sa, 04 Aug 2012, Helmut Grohne wrote: Severity: important Nanananana, important??? out of which reasoning? I was a bit overeager

Bug#687812: vnstat --live: min avg

2012-09-16 Thread Helmut Grohne
Package: vnstat Version: 1.11-1 Severity: normal Here is a sample output of vnstat --live. |rx | tx | --+-- | bytes 1.97 MiB |2.05 MiB |

Bug#680291: dh_installcatalogs: catalog is now a conffile prompt if the old (pre-conffile) package was removed, but not purged

2012-09-17 Thread Helmut Grohne
On Fri, Sep 14, 2012 at 01:43:31PM +0200, Andreas Beckmann wrote: Control: found 681194 debhelper/9.20120830 Countrol: found 680291 xml2rfc/1.36-4 Hi Helmut, we missed one case: If the package contained neither conffiles nor a postrm script (example: xml2rfc in squeeze/non-free),

Bug#680291: xml2rfc: fails to install, remove, distupgrade, and install again

2012-09-17 Thread Helmut Grohne
Hi Gregor, I took a bit longer to respond, but I have not forgotten about this issue. On Fri, Aug 31, 2012 at 05:44:07PM +0200, gregor herrmann wrote: On Wed, 29 Aug 2012 22:17:13 +0200, Helmut Grohne wrote: Helmut, I took the liberty to put you in CC as you probably have some hints

Bug#681685: RFS: homealoned/0.4.1-1

2012-09-18 Thread Helmut Grohne
On Sun, Jul 15, 2012 at 05:42:12PM +0200, alberto fuentes wrote: dget -x http://mentors.debian.net/debian/pool/main/h/homealoned/homealoned_0.4.1-1.dsc Nobody seems to care for this package at all. What a shame. Now I had a look. First and foremost, the upstream source hides the licensing

Bug#680291: dh_installcatalogs: catalog is now a conffile prompt if the old (pre-conffile) package was removed, but not purged

2012-09-18 Thread Helmut Grohne
Control: notfound 681194 debhelper/9.20120830 On Mon, Sep 17, 2012 at 11:13:43AM +0200, Andreas Beckmann wrote: Any opposition to closing the debhelper issue again? Tanks for te analysis. Please go aead! Done. In case of xml2rfc I see no other option that to forcefully remove the

Bug#681685: RFS: homealoned/0.4.1-1

2012-09-19 Thread Helmut Grohne
On Tue, Sep 18, 2012 at 07:53:40PM +0200, alberto fuentes wrote: On Tue, Sep 18, 2012 at 3:44 PM, Helmut Grohne hel...@subdivi.de wrote: That said, I believe that the package is not being a good fit for the Debian project due to its limited applicability (/24 networks only), lack

Bug#561970: libdate-manip-perl: cannot be used in taint (-T) mode

2012-09-20 Thread Helmut Grohne
Control: found 561970 libdate-manip-perl/6.32-1 Control: notfound 561970 libdate-manip-perl/6.34-1 Thanks for pinging me on this issue. On Wed, Sep 19, 2012 at 06:34:27PM +0200, gregor herrmann wrote: On Thu, 12 Apr 2012 17:05:27 +0200, Helmut Grohne wrote: $ perl -T -e 'use Date::Manip

Bug#561970: libdate-manip-perl: cannot be used in taint (-T) mode

2012-09-20 Thread Helmut Grohne
Control: fixed 561970 libdate-manip-perl/6.34-1 Control: close 561970 On Thu, Sep 20, 2012 at 04:49:00PM +0200, gregor herrmann wrote: I'm inclined to close this bug with 6.34-1; OTOH we might as well leave it open until someone comes along the next time and close it unless there's a new sign

Bug#688765: FTBFS if built twice in a row

2012-09-25 Thread Helmut Grohne
Source: libpri Version: 1.4.12-2 Severity: serious Justification: fails to build from source The upstream Makefile creates a version.c which is not removed during (make) clean. Thus the second attempt to build the package fails with a message from dpkg-source saying that local changes (to

Bug#693430: gitg: off-by-one in line numbering of diff in Changes tab

2012-11-16 Thread Helmut Grohne
Package: gitg Version: 0.2.4-1.1 Severity: minor A typical content of the Changes tab looks like this in ascii art: diff --git a/foo b/foo index abcde..12345 100644 3 5 @@ -3,8 +5,7 @@ context 4 6 common context 5 7 common context 6 common context 7 -line only in

Bug#693430: gitg: off-by-one in line numbering of diff in Changes tab

2012-11-18 Thread Helmut Grohne
Control: found -1 gitg/0.2.5-1~exp0 On Sat, Nov 17, 2012 at 11:07:05PM +1100, Dmitry Smirnov wrote: I'm not sure if I understand the problem. How shall I reproduce it? Please change the working directory to a git repository containing at least two non-trivial commits. Start gitg. Click on a

Bug#693872: sed: binary package sed lacks Multi-Arch: foreign declaration

2012-11-21 Thread Helmut Grohne
Package: sed Version: 4.2.1-10 Severity: normal The sed binary package provides an architecture independent interface to other packages. That makes it a good candidate for Multi-Arch: foreign. This change helps with cross building, because a number of packages build depend on sed. Similar

Bug#693926: binary package make lacks Multi-Arch: foreign declaration

2012-11-21 Thread Helmut Grohne
Package: make Version: 3.81-8.2 Severity: normal Control: found -1 make/3.82-1 The make binary package provides an architecture independent command line interface to its reverse dependencies. As such the package should be marked as Multi-Arch: foreign to make installation of packages from

Bug#693961: realpath: binary package realpath lacks Multi-Arch: foreign declaration

2012-11-22 Thread Helmut Grohne
Package: realpath Version: 1.17 Severity: normal The realpath package provides an architecture independent command line interface to its reverse dependencies. As such it should be marked as Multi-Arch: foreign. Similar utilities such as tar have already gained such a declaration. Adding it will

Bug#693964: pwgen: binary package pwgen lacks Multi-Arch: foreign declaration

2012-11-22 Thread Helmut Grohne
Package: pwgen Version: 2.06-1+b2 Severity: normal User: multiarch-de...@lists.alioth.debian.org Usertags: multiarch The pwgen binary package provides an architecture independent command line interface to its reverse dependencies. Therefore it should be marked as Multi-Arch: foreign. Helmut --

Bug#683998: munin: allows creation of sockets at arbitrary locations (/tmp file vulnerability)

2012-08-06 Thread Helmut Grohne
Package: munin Version: 1.4.5-3 Severity: serious Tags: security I wondered where a socket /tmp/munin-master-processmanager-12345.sock would come from and whether it was created in a secure way. In the presence of this bug report you may have guessed, that it is not. The corresponding code can be

Bug#683998: munin: allows creation of sockets at arbitrary locations (/tmp file vulnerability)

2012-08-06 Thread Helmut Grohne
Control: fixed 683998 2.0.1-1 Control: tags 683998 + patch As said in my previous mail the issue stems from the rundir default. This variable is set in /usr/share/perl5/Munin/Master/Config.pm. In the wheezy version rundir is changed to MUNIN_STATEDIR, so wheezy is not affected. I would assume

Bug#684153: puppetmaster must be upgraded before upgrading puppet

2012-08-07 Thread Helmut Grohne
of the upcoming release notes. Helmut Grohne [1] Well not that obvious. http://bitcube.co.uk/content/puppet-errors-explained -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#584952: gitg debian bugs: 584952

2012-08-08 Thread Helmut Grohne
On Wed, Aug 08, 2012 at 09:26:39AM +1000, Imran Azeezullah wrote: I follow this recipe to crash gitg: touch blah.txt git add blah.txt gitg # now switch focus to the terminal and remove the added file git reset HEAD blah.txt # now switch focus to the gitg window # hit Ctrl-R to refresh.

Bug#683064: fixed in git

2012-08-08 Thread Helmut Grohne
On Wed, Aug 08, 2012 at 12:24:28PM +0200, Holger Levsen wrote: $ git show 29f4223 commit 29f422377e710dfb19cff5a29af2344ae6203203 Author: Christoph Biedl munin.i...@manchmal.in-ulm.de Date: Tue Jul 3 17:44:04 2012 +0200 fix bug that disabled gfx CGI caching Apache and

Bug#684075: munin: insecure state file handling, munin-root

2012-08-09 Thread Helmut Grohne
I investigated whether just fixing the smart_ plugin would be enough of a workaround for stable. We only have a finite amount of plugins that can instantiate this vulnerability. Just how many do? Basically we are interested in those plugins that run with elevated privileges and use state files.

Bug#676155: libustr-1.0-1: please convert to multiarch

2012-06-04 Thread Helmut Grohne
Package: libustr-1.0-1 Version: 1.0.4-2 Severity: important The libustr-1.0-1 package does currently (correctly) not have any Multi-Arch tags. It therefore prevents libsemanage1 and therefore passwd from exercising their multiarch capabilities. Since your package contains only a single shared

Bug#676155: libustr-1.0-1: please convert to multiarch

2012-06-05 Thread Helmut Grohne
Thanks for your quick response. On Tue, Jun 05, 2012 at 08:35:14AM +0200, Václav Ovsík wrote: There is already prepared a version 1.0.4-3 waiting for the sponsor. The previous releases sponsored Kees Cook. I sent him an email about a week ago. I'm waiting to his response now. In the case he

Bug#676175: iproute: is it possible to mark iproute as Multi-Arch: foreign?

2012-06-05 Thread Helmut Grohne
Package: iproute Version: 20120319-1 Severity: important The iproute package has a large number of reverse dependencies (~ 60). This makes it a good candidate for multiarch conversion. The interface to the iproute package appears to be command line. This makes it a Multi-Arch: foreign candidate.

Bug#675613: merging FTBFS bugs into dpkg-trigger bug

2012-06-05 Thread Helmut Grohne
# processing 676062 reassign 676062 dpkg forcemerge 675613 676062 affects 675613 + src:debiandoc-sgml-doc-pt-br # processing 676061 affects 675613 + src:doc-base # processing 676107 affects 675613 + src:debian-faq # processing 676122 affects 675613 + src:debian-history # processing 676118 reassign

Bug#676175: iproute: is it possible to mark iproute as Multi-Arch: foreign?

2012-06-05 Thread Helmut Grohne
: #676175) + + -- Helmut Grohne hel...@subdivi.de Tue, 05 Jun 2012 20:38:22 +0200 + iproute (20120521-2) unstable; urgency=low * Revert Apply hardening build flags diff -Nru iproute-20120521/debian/control iproute-20120521/debian/control --- iproute-20120521/debian/control 2012-05-28 12

Bug#676477: libnetcdfc7: pleace convert to Multi-Arch: same

2012-06-07 Thread Helmut Grohne
Package: libnetcdfc7 Version: 1:4.1.3-6 Severity: important The libnetcdfc7 has about 40 reverse dependencies of which 7 (libnemesis3 libcdi0 libcmor2 libminc2-1 libexodusii5 libadios-dev python-cmor) already have Multi-Arch headers. So libnetcdfc7 blocks a number of packages from exercising

Bug#676611: libnl-3-200: please convert to Multi-Arch: same

2012-06-08 Thread Helmut Grohne
Package: libnl-3-200 Version: 3.2.7-2 Severity: important The libnl-3-200 package has about 20 reverse dependencies of which 7 are multiarch aware. It currently blocks those seven packages from exercising their multiarch capabilities. The package only contains a single shared library. To make the

Bug#676615: libsystemd-login0: please convert to Multi-Arch: same

2012-06-08 Thread Helmut Grohne
Package: libsystemd-login0 Version: 44-2 Severity: important One of the reverse dependencies of libsystemd-login0 is the multiarch aware dbus package. However dbus cannot be cross graded, because libsystemd-login0 is not multiarch aware. Since libsystemd-login0 only contains a single shared

Bug#676653: tor: please add Multi-Arch: foreign to the tor package

2012-06-08 Thread Helmut Grohne
Package: tor Version: 0.2.2.36-1 Severity: wishlist The tor package seems to provide an architecture independent interface (i.e. command line and architecture independent network protocols such as socks and ssl). As such it should be marked as Multi-Arch: foreign. In practise that would allow

Bug#676780: eject: please mark package eject as Multi-Arch: foreign

2012-06-09 Thread Helmut Grohne
Package: eject Version: 2.1.5+deb1+cvs20081104-10 Severity: normal The eject package seems to provide an architecture independent command line interface. That makes it a candidate for adding Multi-Arch: same to the eject binary package in debian/control. About 15 reverse dependencies could

Bug#676782: at: please mark the at binary package as Multi-Arch: foreign

2012-06-09 Thread Helmut Grohne
Package: at Version: 3.1.13-1 Severity: normal The at package seems to provide an architecture independent command line interface. By adding a Multi-Arch: foreign line to the at binary package you make dependency resolution easier in a multiarch environment, because at has about 5 reverse

Bug#676780: eject: please mark package eject as Multi-Arch: foreign

2012-06-10 Thread Helmut Grohne
Hi Frank, On Sun, Jun 10, 2012 at 12:07:34PM +0200, Frank Lichtenheld wrote: You mean foreign here, like you wrote in the subject, right? Thanks for spotting. Foreign of course. I don't know if foreign is really correct, though. It would be correct certainly if we only had Linux kernels. But

Bug#676915: photon: fails to keep aspect ration when scaling down in some cases

2012-06-10 Thread Helmut Grohne
Package: photon Version: 0.4.6-3 Severity: normal First of all big thanks this tool to both upstream and the maintainer. It is one of the tools, that just works without having to specify megabytes of configuration. Unfortunately I hit an aspect that doesn't just work. Consider the following two

Bug#676915: photon: fails to keep aspect ration when scaling down in some cases

2012-06-10 Thread Helmut Grohne
On Sun, Jun 10, 2012 at 03:48:01PM +0200, Helmut Grohne wrote: If you happen to know a workaround, please let me know. I deemed it more work to look at another (possibly broken) gallery generator than to work around this bug by myself. You can find a patch attached, that solves the issue for me

Bug#675481: docbook-website: please rebuild to fix your copy of #477751

2012-06-12 Thread Helmut Grohne
. (Closes: #675481) + * Update transitional code in postinst to play well with new sgml-base. + + -- Helmut Grohne hel...@subdivi.de Tue, 12 Jun 2012 11:24:49 +0200 + docbook-website (2.5.0.0-7.2) unstable; urgency=low * NMU. diff -u docbook-website-2.5.0.0/debian/docbook-website.postinst

Bug#674914: sgmltools-lite: do not call update-catalog

2012-06-12 Thread Helmut Grohne
tags 674914 + patch severity 674914 serious thanks I attached a patch that removes the transitional code. Additionally the severity is now serious, because this package needs to be rebuilt to avoid a policy violation (overwriting user configuration). Helmut -- To UNSUBSCRIBE, email to

Bug#674913: sgml-data: do not call update-catalog

2012-06-12 Thread Helmut Grohne
tags 674913 + patch tags 675488 + patch thanks On Mon, May 28, 2012 at 05:06:18PM +0200, Helmut Grohne wrote: Your package calls update-catalog on /etc/sgml/$PACKAGE.cat. The latter file will transition to a conffile, so changing that file induces questions to the user. Please remove the old

Bug#674911: xml2rfc: do not call update-catalog

2012-06-12 Thread Helmut Grohne
severity 674911 serious thanks Setting severity to serious, because xml2rfc's prerm overwrites user configuration (similar to #477751). On Mon, May 28, 2012 at 05:01:32PM +0200, Helmut Grohne wrote: Your package manually calls update-catalog. Due to an RC bug on sgml-base the interface has

Bug#674914: sgmltools-lite: do not call update-catalog

2012-06-12 Thread Helmut Grohne
@@ +sgmltools-lite (3.0.3.0.cvs.20010909-15.2) unstable; urgency=low + + * Non-maintainer upload. + * Remove transitional call to update-catalog from postinst. The call is a +noop since the new sgml-base version. (Closes: #674914) + + -- Helmut Grohne hel...@subdivi.de Tue, 12 Jun 2012 11:39:39

Bug#477751: tackling this bug

2012-01-07 Thread Helmut Grohne
Hi Joey, thanks for your response. On Sat, Jan 07, 2012 at 01:01:56PM -0400, Joey Hess wrote: Helmut Grohne wrote: * preinst will do the tricky transition part. If it is called during an upgrade and /etc/sgml/$package.cat is not owned by any package (this is currently the case

Bug#477751: tackling this bug

2012-01-07 Thread Helmut Grohne
Hi Joey, On Sat, Jan 07, 2012 at 02:53:46PM -0400, Joey Hess wrote: But update-catalog can get new switches that handle the transition, and debhelper can update the code to use them. Ok. Let's evaulate what could be changed about update-catalog. 1) package catalog. As per Daniel's request

Bug#655442: src:gnunet: Vcs-Git points to git.debian-maintainers.org which is NXDOMAIN

2012-01-11 Thread Helmut Grohne
Package: src:gnunet Version: 0.8.1b-5 Severity: normal The URLS referenced in the Vcs-Browser and Vcs-Git headers do not work. $ apt-cache showsrc gnunet ... Vcs-Browser: http://git.debian-maintainers.org/?p=gnunet/gnunet.git Vcs-Git: git://git.debian-maintainers.org/git/gnunet/gnunet.git $

Bug#477751: reassigning #477751 to debhelper

2012-01-12 Thread Helmut Grohne
reassign 477751 debhelper affects 477751 sgml-base thanks Reasons: * The debhelper templates are mainly responsible for this issue. * Any solution that fixes this issue requires changes to debhelper. * There exists a solution (attached to this bug log), that solves the issue by just

Bug#655855: pypy: please support installed python modules

2012-01-14 Thread Helmut Grohne
Package: pypy Version: 1.7+dfsg-2 Severity: wishlist First of all big thanks for packaging pypy! It seems way more mature than the previous attempt to getting it into Debian. It would be nice to be able to use python module packages directly with pypy. For instance an import werkzeug currently

Bug#655855: closed by Debian FTP Masters ftpmas...@ftp-master.debian.org (Bug#655914: Removed package(s) from unstable)

2012-01-15 Thread Helmut Grohne
reopen 655855 thanks Dear ftp team, On Sun, Jan 15, 2012 at 03:06:04AM +, Debian Bug Tracking System wrote: as the package pypy has just been removed from the Debian archive unstable we hereby close the associated bug reports. We are sorry that we couldn't deal with your issue properly.

Bug#663685: RFS: openvpn-auth-radius/2.1-4 -- updated packaging, hardening release goal

2012-03-13 Thread Helmut Grohne
to machine readable specification 1.0. * Support dpkg-buildflags. * Switch to debhelper 8 and use overrides. -- Helmut Grohne h.gro...@cygnusnetworks.de Tue, 06 Mar 2012 16:31:05 +0100 Note that support for dpkg-buildflags is a way to meet the hardening release goal. Please refrain from

Bug#663685: Acknowledgement (RFS: openvpn-auth-radius/2.1-4 -- updated packaging, hardening release goal)

2012-03-13 Thread Helmut Grohne
openvpn-auth-radius-2.1/debian/control --- openvpn-auth-radius-2.1/debian/control +++ openvpn-auth-radius-2.1/debian/control @@ -1,10 +1,10 @@ Source: openvpn-auth-radius Maintainer: Cygnus Networks GmbH deb...@cygnusnetworks.de Uploaders: Helmut Grohne h.gro...@cygnusnetworks.de -Standards

Bug#649860: RFP: wwwoffle -- World Wide Web OFFline Explorer

2011-11-24 Thread Helmut Grohne
Package: wnpp Severity: wishlist * Package name: wwwoffle Version : 2.9h Upstream Author : Andrew M. Bishop amb at gedanken.demon.co.uk * URL : http://www.gedanken.demon.co.uk/wwwoffle/ * License : GPL2 Programming Lang: C Description : World Wide Web

Bug#650077: dpkg: The Installed-Size estimate can be wrong by a factor of 8 or a difference of 100MB

2011-11-26 Thread Helmut Grohne
Package: dpkg Version: 1.16.1.2 Severity: wishlist Symptom ~~~ I just installed libjs-mathjax. According to its Installed-Size this would just consume 16512KB. Now according to policy this is just an estimate of course. But how accurate is it actually? So I installed said package on ext3.

Bug#649175: Please raise severity to serious to warn apt-listbugs users

2011-11-29 Thread Helmut Grohne
Please raise severity of this bug to serious to warn users of apt-listbugs. That would have saved me half an hour. Another benefit would have been that this bug would not have hit testing users. rantSo this is the quality that Debian intends to sell as a rolling release? Full breakage included I

Bug#650377: ibam --plotdeviations causes a syntax error in gnuplot

2011-11-29 Thread Helmut Grohne
Package: ibam Version: 1:0.5.2-2 Severity: minor $ ibam --plotdeviations gnuplot plot /home/helmut/.ibam/battery.rc using 1:2 title Battery with lines 1, /home/helmut/.ibam/battery.rc using 1:($2+$3) notitle with lines 3, /home/helmut/.ibam/battery.rc using 1:($2-$3) notitle with lines

Bug#558784: status of this bug?

2012-03-02 Thread Helmut Grohne
Hi, First of all let me give a summary (corrections welcome): /etc/apt/trusted.gpg is a binary gpg keyring that by default contains the keys used to verify the release files. It is changed by apt-key during upgrades of either apt or debian-archive-keyring. This change may overwrite user changes

Bug#637940: fixed

2012-03-02 Thread Helmut Grohne
notfound 637940 haskell-leksah/0.10.0.4-2 thanks The bug was only present in haskell-leksah-server and fixed by Joachim Breitner. This should finally close the bug report. Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble?

Bug#610333: downgrading

2012-03-02 Thread Helmut Grohne
severity 610333 wishlist thanks The general consensus seems to be that this issue is clearly not release critical. It is known that a partly upgraded system may fail to boot. Thus the default of preventing hibernation during system upgrades seems reasonable. It is actually configurable by

Bug#634538: any progress?

2012-03-02 Thread Helmut Grohne
Hi Noèl, Can you give a status on this package? Your last upload seems to be 2.5 years ago. It is rc buggy with a patch for almost half a year. How to proceed with it? Will you upload a fix any time soon? Should BSP MG upload doko's fix? Should the package be removed from the archive? Some facts

Bug#579028: workaround

2012-03-02 Thread Helmut Grohne
As Ansgar Burchard pointed out the default pbuilder configuration does not enforce usage of signed packages. If you are quick, you can spot a warning about an unverified signature. Since version 0.199 there is a way to turn on enforced signature verification. The method is documented both in man

Bug#661993: CVE-2011-2191: persistent CSRF on admin interface

2012-03-03 Thread Helmut Grohne
Source: cherokee Version: 1.2.101-1 Severity: serious Tags: security References: CVE-2011-2191 https://bugs.launchpad.net/ubuntu/+source/cherokee/+bug/784632 https://bugzilla.redhat.com/show_bug.cgi?id=713304 Please verify whether the issue is still present in the package. A quick look at

Bug#661994: hwinfo: dbus assertion failure

2012-03-03 Thread Helmut Grohne
Package: hwinfo Version: 16.0-2.2 Severity: minor When running hwinfo the output starts with the following lines. | process 7762: arguments to dbus_move_error() were incorrect, assertion (dest) == NULL || !dbus_error_is_set ((dest)) failed in file ../../dbus/dbus-errors.c line 282. | This is

Bug#584952: attempted to reproduce

2012-03-03 Thread Helmut Grohne
Hi, I was bugged by Jan Hauke Rahm to triage this bug. He is occasionally able to reproduce it and gave me access to a repository where the issue did show up on his machine. No matter what I tried (changing preferences, clicking around, committing, stashing, etc.) I was unable to reproduce the

Bug#620960: RFS: inspircd

2012-03-03 Thread Helmut Grohne
On Wed, Dec 14, 2011 at 10:25:37PM +0100, Guillaume Delacour wrote: Le samedi 03 décembre 2011 à 11:39 +0100, Jan Lübbe a écrit : On Tue, 2011-11-01 at 22:00 +0100, Guillaume Delacour wrote: To access further information about this package, please visit the following URL:

Bug#662029: systemd: local denial of login or local users can create arbitrary services

2012-03-03 Thread Helmut Grohne
Package: systemd Version: 37-1 Severity: important Tags: security Forwarded: https://bugzilla.redhat.com/show_bug.cgi?id=680122 By invoking systemctl status somename.service any user can create an entry in systemd's service list. If this list gets too large the login procedure can fail. It is not

Bug#628237: proposed fix for slapd upgrades

2012-03-04 Thread Helmut Grohne
. (Closes: #628237) + + -- Helmut Grohne hel...@subdivi.de Sat, 03 Mar 2012 22:42:42 +0100 + cyrus-sasl2 (2.1.25.dfsg1-3) unstable; urgency=low [ Thomas Preud'homme ] diff -Nru cyrus-sasl2-2.1.25.dfsg1/debian/control cyrus-sasl2-2.1.25.dfsg1/debian/control --- cyrus-sasl2-2.1.25.dfsg1/debian

Bug#662029: [Secure-testing-team] Bug#662029: systemd: local denial of login or local users can create arbitrary services

2012-03-04 Thread Helmut Grohne
On Sun, Mar 04, 2012 at 10:08:47AM +0200, Henri Salo wrote: On Sat, Mar 03, 2012 at 06:39:57PM +0100, Helmut Grohne wrote: Forwarded: https://bugzilla.redhat.com/show_bug.cgi?id=680122 Does this security issue have CVE-identifier assigned? I can request one if needed. I don't think so

Bug#645810: valgrind

2012-03-04 Thread Helmut Grohne
I reproduced the problem with valgrind and debug symbols. The output is likely helpful for anyone interested in tracking down this issue. This is sid i386, slapd version 2.4.28-1.1, gnutls version 2.12.16-1. ==9140== Memcheck, a memory error detector ==9140== Copyright (C) 2002-2011, and GNU

Bug#663048: src:agda: FTBFS with ghc 7.4 due to versioned dependencies in configure

2012-03-08 Thread Helmut Grohne
Package: src:agda Version: 2.3.0-1+b3 Severity: serious Justification: FTBFS Excerpt from the build log[1]: | for setup in Setup.lhs Setup.hs; do if test -e $setup; then ghc --make $setup -o debian/hlibrary.setup; exit 0; fi; done | [1 of 1] Compiling Main ( Setup.hs, Setup.o ) |

Bug#650524: insserv: please include +pdnsd in $named in /etc/insserv.conf

2011-11-30 Thread Helmut Grohne
Package: insserv Version: 1.14.0-2 Severity: normal Tags: patch I noticed that pdnsd would be started late on some machines. Since it provides name resolution this should have been caught by Required-Start: $named listed by many packages. The cause is that pdnsd is not listed as $named in

Bug#650524: insserv: please include +pdnsd in $named in /etc/insserv.conf

2011-11-30 Thread Helmut Grohne
reassign 650524 pdnsd 1.2.7-par-1.2 found 650524 1.2.8-par-2 severity 650524 serious user initscripts-ng-de...@lists.alioth.debian.org usertags 650524 incorrect-dependency thanks Thanks for your quick and insightful answer! On Wed, Nov 30, 2011 at 07:02:41PM +0100, Petter Reinholdtsen wrote:

Bug#650538: bind9: please ship a file /etc/insserv.conf.d/bind9 containing $named bind9

2011-11-30 Thread Helmut Grohne
Source: bind9 Version: 1:9.8.1.dfsg-1 Severity: wishlist Tags: patch User: initscripts-ng-de...@lists.alioth.debian.org Usertags: incorrect-dependency The bind9 package does not yet explain that it provides a resolver. This information is currently encoded in /etc/insserv.conf in the insserv

Bug#650539: lwresd: please ship a file /etc/insserv.conf.d/lwresd containing $named lwresd

2011-11-30 Thread Helmut Grohne
Source: lwresd Version: 1:9.8.1.dfsg-1 Severity: wishlist Tags: patch User: initscripts-ng-de...@lists.alioth.debian.org Usertags: incorrect-dependency The lwresd package does not yet explain that it provides a resolver. This information is currently encoded in /etc/insserv.conf in the insserv

Bug#650540: dnsmasq: please ship a file /etc/insserv.conf.d/dnsmasq containing $named dnsmasq

2011-11-30 Thread Helmut Grohne
Source: dnsmasq Version: 2.59-3 Severity: wishlist Tags: patch User: initscripts-ng-de...@lists.alioth.debian.org Usertags: incorrect-dependency The dnsmasq package does not yet explain that it provides a resolver. This information is currently encoded in /etc/insserv.conf in the insserv package,

Bug#650544: onak: does not rotate /var/log/onak.log

2011-11-30 Thread Helmut Grohne
Package: onak Version: 0.3.8-1 Severity: serious Justification: Policy 10.8 The onak package creates /var/log/onak.log, but this file is never rotated. Instead it grows indefinitely. Rotation is a must according to policy section 10.8. The policy also lists an example logrotate config file.

Bug#650544: onak: does not rotate /var/log/onak.log

2011-11-30 Thread Helmut Grohne
On Wed, Nov 30, 2011 at 11:55:19AM -0800, Jonathan McDowell wrote: The version of onak in testing/unstable is 0.4.0-1 and already has a logrotate config file in /etc/logrotate.d/onak. Thanks for your quick reply. I will take that logrotate file then. Helmut -- To UNSUBSCRIBE, email to

Bug#650557: onak: race condition in onak-mail.pl

2011-11-30 Thread Helmut Grohne
Package: onak Version: 0.4.0-1 Severity: minor I discovered a race condition in onak-mail.pl. Let me summarize what the script does: 1) Read configuration. 2) Open a unique spool file for the arriving mail. 3) Write that mail to the file and close it. 4) Try to acquire a lock on the spool

Bug#650747: w3m https://non-existent.example reliably segfaults on some systems

2011-12-02 Thread Helmut Grohne
Package: w3m Version: 0.5.3-4 Severity: minor I just wanted to visit an https site using w3m and found a segmentation fault. It dereferences a NULL pointer, but the traceback is not useful without debugging symbols. Looking at strace I can see that it happens during (or after) DNS resolution. Oh

Bug#644121: dovecot-core: destroys user configuration from dovecot-common

2011-12-02 Thread Helmut Grohne
tags 644121 +unreproducible thanks Hi Ian, On Sun, Oct 02, 2011 at 06:59:46PM -0700, Ian Zimmerman wrote: I was upgrading via aptitude: [REMOVE, NOT USED] dovecot-common [INSTALL, DEPENDENCIES] dovecot-core [UPGRADE] dovecot-imapd 1:2.0.13-1.1 - 1:2.0.15-1 This resulted in all my local

Bug#411019: pidentd does not work with /var/run mounted as a tmpfs file system

2011-12-02 Thread Helmut Grohne
: #411019) + + -- Helmut Grohne hel...@subdivi.de Fri, 02 Dec 2011 19:13:18 +0100 + pidentd (3.0.19.ds1-5) unstable; urgency=low * Priority is optional; closes: #416570, #492060 diff -u pidentd-3.0.19.ds1/debian/rules pidentd-3.0.19.ds1/debian/rules --- pidentd-3.0.19.ds1/debian/rules

Bug#411019: pidentd does not work with /var/run mounted as a tmpfs file system

2011-12-02 Thread Helmut Grohne
On Fri, Dec 02, 2011 at 09:28:02PM +0100, Helmut Grohne wrote: The script needs to be a bit longer. NMU attached. As it turns out even that was too simple. Thanks to Jan Luebbe for the pointers. Updated NMU diff. Helmut diff -u pidentd-3.0.19.ds1/debian/changelog pidentd-3.0.19.ds1/debian

Bug#411019: pidentd does not work with /var/run mounted as a tmpfs file system

2011-12-02 Thread Helmut Grohne
On Fri, Dec 02, 2011 at 10:28:00PM +0100, Helmut Grohne wrote: As it turns out even that was too simple. Thanks to Jan Luebbe for the pointers. Updated NMU diff. Also silence that warning about update-rc.d for legacy systems. See http://piuparts.debian.org/sid/initdscript_lsb_header_issue.html

Bug#650783: snapshot.debian.org: please list deb ... lines for sources.list on http://snapshot.d.o/package/$package/$version/

2011-12-02 Thread Helmut Grohne
Package: snapshot.debian.org Severity: wishlist It would be nice if the pages for individual package versions http://snapshot.d.o/package/$package/$version/ would also list easy to add deb ... lines for a sources.list. They can be deduced from the binary download urls by removing anything after

Bug#633433: slidentd: FTBFS after package change of libowfat

2011-12-03 Thread Helmut Grohne
On Sun, Jul 10, 2011 at 11:49:50AM +0200, Roland Stigge wrote: Build-Depends: libowfat-dietlibc-dev Build-Conflicts: libowfat-dev Thanks for the fix. Tested. NMU attached. Also solves #634416. Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of

Bug#633433: slidentd: FTBFS after package change of libowfat

2011-12-03 Thread Helmut Grohne
On Sat, Dec 03, 2011 at 10:42:08AM +0100, Helmut Grohne wrote: Thanks for the fix. Tested. NMU attached. Also solves #634416. Now with th patch. %-) Helmut diff -u slidentd-1.0.0/debian/control slidentd-1.0.0/debian/control --- slidentd-1.0.0/debian/control +++ slidentd-1.0.0/debian/control

Bug#650798: /var/run is now on tmpfs

2011-12-03 Thread Helmut Grohne
Package: slidentd Version: 1.0.0-6.1 Severity: serious Justification: 9.3.2 Exactly the same thing as http://bugs.debian.org/411019 Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#633433: slidentd: FTBFS after package change of libowfat

2011-12-03 Thread Helmut Grohne
reference to `__ctype_b_loc' +unreproducible after previous fix (Closes: #634416) + * Fix: /var/run is now on tmpfs add init script (Closes: #650798) + + -- Helmut Grohne hel...@subdivi.de Sat, 03 Dec 2011 11:16:33 +0100 + slidentd (1.0.0-6.1) unstable; urgency=medium * Non-maintainer upload

Bug#387756: 387756 is a policy violation

2011-12-03 Thread Helmut Grohne
severity 387756 serious thanks This is a policy violation. See section 9.3.2. Helmut -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#650808: frown: OOM on compiling any remotely valid grammer

2011-12-03 Thread Helmut Grohne
Package: frown Version: 0.6.1-11 Severity: grave Justification: renders package unusable I noticed that frown would no longer translate my projects, because it would eat too much memory. So I tried to come up with smaller grammers. I arrived at $ cat test.lg %{ } $ Now this didn't eat any

Bug#650815: src:xtrs: FTBFS (sparc): debug.c:695:11: error: lvalue required as left operand of assignment

2011-12-03 Thread Helmut Grohne
Package: src:xtrs Version: 4.9c-3.3 Severity: serious Justification: FTBFS Excerpt from build log: | debian/rules build | html2text -nobs -style pretty cpmutil.html cpmutil.txt | html2text -nobs -style pretty dskspec.html dskspec.txt | html2text -nobs -style pretty debian/trs80faq.html

Bug#623623: upgrade 623623

2011-12-03 Thread Helmut Grohne
severity 623623 serious thanks pbuilder cannot be used without pbuilder --create and pbuilder --create uses dpkg-architecture which is contained in dpkg-dev. So this is a missing dependency which should be serious according to policy 7.2: | The Depends field should be used if the depended-on

Bug#607267: /usr/bin/scp: fails to notice close() errors

2011-12-03 Thread Helmut Grohne
Hi, On Sun, Jan 02, 2011 at 03:48:05PM +0100, Michal Suchanek wrote: This same issue also happens with cp(1) from coreutils. I verified that this statement is wrong. 1) The coreutils actually check the return value of close which can be seen on copy.c. It has precisely two calls to close and

Bug#609851: summary

2011-12-03 Thread Helmut Grohne
This is a summary for those attempting to squash rc bugs. As of 4.2.2-1 /sbin/dhclient-script implements a set_hostname function that unconditionally updates the host name if request host-name is set in /etc/dhcp/dhclient.conf which is the default. This means that in a default setup of dhcp any

Bug#477751: tackling this bug

2011-12-04 Thread Helmut Grohne
update-catalog in a way that empowers debhelper to fix #477751. + + -- Helmut Grohne hel...@subdivi.de Sun, 04 Dec 2011 12:49:07 +0100 + sgml-base (1.26+nmu1) unstable; urgency=low * Non-maintainer upload diff -Nru sgml-base-1.26+nmu1/tools/update-catalog sgml-base-1.26+nmu2/tools/update

Bug#600777: attempt to help

2011-12-04 Thread Helmut Grohne
Hi, I looked into this RFH. After digging through the various places, I can give some pointers to prospective helpers. The package is maintained in svn. You can check it out at: svn co svn://svn.debian.org/svn/pkg-cryptsetup/trunk cryptsetup This will give you the debian directory of the for

Bug#477751: tackling this bug

2011-12-04 Thread Helmut Grohne
Hi Joey, thanks for your quick answer. On Sun, Dec 04, 2011 at 05:25:42PM -0400, Joey Hess wrote: I haven't considered all the implications... Will the new sgml-base work ok with the old postinst? With mixtures of the new and old postinsts? Good question! Let's look at them individually. The

Bug#607267: /usr/bin/scp: fails to notice close() errors

2011-12-05 Thread Helmut Grohne
Hi Michal, On Mon, Dec 05, 2011 at 12:41:21AM +0100, Michal Suchanek wrote: Excerpts from Helmut Grohne's message of Sat Dec 03 17:33:04 +0100 2011: Hi, On Sun, Jan 02, 2011 at 03:48:05PM +0100, Michal Suchanek wrote: This same issue also happens with cp(1) from coreutils. I

Bug#477751: tackling this bug

2011-12-05 Thread Helmut Grohne
Hi Daniel, On Mon, Dec 05, 2011 at 12:05:26AM +0100, Daniel Leidert wrote: My thoughts on this are pretty easy. There are IMO three mechanisms to use: (1) Register the catalog, if it exists (and unregister any registered catalog, if it doesn't exist anymore). So users can remove the package

<    1   2   3   4   5   6   7   8   9   10   >